BLOX

Personal Data Protection Notice


Version Effective Date: 1st April 2025

This Personal Data Protection Notice (“Notice”) applies to all interactions and/or dealing with BLOX BLOCKCHAIN SDN. BHD. (“Licensor”, “Us”, “We”, “Our” and "Company"), including but not limited to any official website, mobile application, platform, or other electronic communications, regardless of the method or medium through which they are accessed.


This Notice outlines how the Company collects, records, holds, stores, discloses, shares, uses and protects your Personal Data (as defined below), and additionally this Notice further encompasses information collected or processed in relation to the Company’s business operations, including data from employees, customers, partners, and any other stakeholders who have vested interest in the Company’s business activities or services across all operational regions.


By dealing or engaging with the Company, whether by registering for or using our platform, accessing or utilising our services, or dealing or engaging with us in any other capacity (such as a customer, employee, partner, or any stakeholder) (collectively referred to as “our Services”), you acknowledge and agree to the collection, processing, storage, sharing, use, and protection of your Personal Data, as described in this Notice.


Unless otherwise expressly provided in this Notice, all capitalised terms used herein shall have the same meaning as set forth in the User Agreement.


1. Introduction


We are committed to protecting the privacy and Personal Data of individuals and businesses who interact through our Company’s Platform and use our Services.


2. Personal Data Collection


2.1 We may collect, use, store, process, retain and transfer different kinds of Personal Data about you directly from you when you register to use our Services through the Company’s Platform or submit as part for the purposes and process of know-your-client (“KYC”) or automatically sent through your browser whenever you visit or use our Company’s Platform consisting of but not limited to the following:

(a) Personal Identification Information: Information including names, identity document number and details, nationality, email addresses, phone or mobile numbers, and business contact details provided when you register an account with us through Company’s Platform or use Company’s Platform.

(b) Financial Data: Bank account details.

(c) Technical Information or Log Data: Device information (including address, login data, browser type and version, time zone setting and location, browser plug-in types and versions), internet protocol (IP) addresses, browsing details collected through cookies and similar technologies, operating system and platform and other technology on the devices you use to access our Services.

(d) Profile Data: Information including username or similar identifier, password, your preferences, feedback and any survey responses (if applicable).

(e) Transaction Data: Blockchain transactions, digital assets, and activities related to the direct-to-customer ecosystems that Company’s Platform supports and facilitates.

(f) Cookies and Usage Data: Data collected from cookies and similar tracking tools, used to optimise Users’ experience and enhance security.

(g) Communications with us: All data or information provided and shared with us during any support and feedback communications via email or when you contact us through contact forms on Company’s Platform. We use this information to respond to your inquiries, provide support, facilitate transactions, and improve our platform or services.

(h) Marketing and Communications Data: Information including your preferences in receiving marketing from us and our third parties and your communication preferences.

(i) Location Data: Information about your device(s) location.

(j) Other required information: Such other additional or specific information which we may require to fulfill our KYC procedure or comply with applicable legal requirements.


2.2 We may collect your personal data directly from you, as well as from third parties, including but not limited to other clients, your employer, your advisers, or from publicly available sources. This may encompass information derived from public registries, regulatory agencies, and other relevant platforms, as part of our comprehensive data-gathering process.


3. How We Use Your Personal Data


3.1 We may use and process your data information including the Personal Data to provide, personalise, maintain and improve Company’s Platform or service provisions, including but not limited to the following purposes:

(a) Service Provision: To provide Company’s Platform and make our Services available, e.g. enabling the transformation of Web 2 businesses from traditional dealership models into direct-to-customer ecosystems using Web 3 technologies.

(b) Customer Support: To facilitate communications and transactions on the Company’s Platform, respond to your inquiries, fulfill your order or instructions, offer customer support, and provide assistance and other customer service supports to use and access to our Services.

(c) Regulatory Compliance: We may also use your Personal Data when we are required, advised, recommended, expected or requested to do so by our legal advisors or any local or foreign legal, regulatory, governmental or other authority.

(d) Security: To secure blockchain transactions, safeguard data within decentralized systems, and monitor for fraud or unauthorised access.

(e) Marketing and Communications: To send Users updates about any new product or service information, industry news and other information we think relevant or which may interest you through your email addresses or contact details registered or recorded with us.

(f) Customised Contents: To identify and direct content and information that we may send or display to you, and personalise help and instructions and your experiences while using our Company’s Platform.

(g) Internal Operations: To perform internal operations necessary to provide our Services, including troubleshooting software bugs and operational problems, conducting data analysis, testing and research, monitoring and analysing usage and activity trends, and to enable our partners to manage and allocate fleet resources (including GPS tracking systems, fleet management software, and electronic monitoring devices).

(h) KYC Compliance: we may use your Personal Data to perform necessary verification and compliance checks. This may include conducting searches through public and private databases to determine whether you have engaged in, attempted, or are suspected of engaging in any unlawful or fraudulent activities, or if you have been charged with or convicted of any criminal offenses or are subject to any legal claims.

(i) Improvement of Products and Services: To analyse usage data and feedback in order to improve the features, functionality, and performance of the Company’s Platform and Services. This may involve developing new features or enhancing existing ones to meet user needs and improve overall user satisfaction.

(j) Business Analytics and Reporting: To aggregate, anonymise, and analyse data for internal business insights, including performance metrics, trends, and customer behaviour. This helps in strategic decision-making, resource allocation, and reporting for operational, financial, and marketing purposes.

(k) General Service Provision: In order to effectively deliver, manage, and enhance the quality of our Services, it is necessary for us to process your Personal Data. This enables us to ensure a seamless experience, provide support, and maintain the functionality of our Platform, all tailored to meet your needs.


3.2 You acknowledge and agree that we may use both manual and automated methods, including AI-powered tools, to enhance and fulfill Users’ experiences on Company’s Platforms.


4. Disclosure and Transfer of Personal Data


4.1 We may disclose and transfer your Personal Data to the following classes of third parties (within or outside of Malaysia) as required under the law or pursuant to relevant contractual relationships:

(a) Our business affiliates, subsidiaries, and parent company;

(b) Third-party merchants, service providers, contractors or agents who perform functions on our behalf or support activities essential to the provision and performance of our Services, including but not limited to, services such as cloud hosting, security audits, and analytics to ensure the effective operation of our Web 3 solutions or our Services;

(c) Financial institutions, including banks, payment processors, and other parties involved in the facilitation of payment transactions, fraud detection, and credit checks;

(d) Regulatory authorities, law enforcement agencies, courts, tribunals, and other government bodies, where required for compliance with legal obligations, dispute resolution, or the protection of our rights and interests;

(e) Government departments, ministries, or agencies;

(f) Auditors, consultants, or other professional advisors who assist us in complying with legal, accounting, and financial reporting requirements;

(g) Our business partners or collaborators;

(h) Any acquirer of our business, assets, or shares, in the event of a merger, acquisition, or sale of the business;

(i) Our legal representatives, agents, or external counsel;

(j) Service providers involved in marketing, advertising, or communications who may process Personal Data; and

(k) Other third parties where permitted by law or with your consent.


4.2 We may store your Personal Data on servers located in the countries where our businesses are located, such including Malaysia and other identified jurisdictions. If such jurisdiction is outside your jurisdiction of residence, you consent to the transfer of your Personal Data to such jurisdiction for purposes of making available our Services to you.


5. Data Retention


5.1 We may retain to process your data information including Personal Data for as long as it is necessary to fulfill the purposes as described in this Notice, or as required by applicable laws. When such personal data is no longer required for the stated purposes, the same will be destroyed and permanently deleted in accordance with relevant laws.


6. Your Rights as Data Subject


6.1 As data subject, you are given access to and right to update, rectify or delete your Personal Data we have collected at any time by accessing your account setting or emailing to us, and we shall not later than the statutorily prescribed timeframe from the date of receipt of data correction request make necessary amendments or changes to update any Personal Data that is inaccurate, incomplete, misleading or not up-to date, and your rights include:

(a) Data Access: Subject always with your qualification as data subject at law, you are entitled to request for information of your Personal Data that is being processed by or on behalf of us.

(b) Data Correction & Rectification: You may request to correct any Personal Data that you think inaccurate, incomplete, misleading or outdated.

(c) Optional/Limited Consent: Unless specifically requested by applicable laws, you may limit the processing of your Personal Data including personal data relating to other persons who may be identified from you.

(d) Right to Data Portability: You can request that your Personal Data be transferred to a third party data controller in relation to the performance of a contract between you and the identified third party.

(e) Option Principle: You have the right to accept or reject, wholly or partially, the processing of your Personal Data. Notwithstanding that you have provided your consent allowing us to use, process and retain your Personal Data, you can withdraw it at any time provided always that your withdrawal shall not apply retrospective nor prejudice our rights to use, store, process, retain and transfer any of your data information including Personal Data prior to our receipt of your withdrawal notice.


6.2 To the extent permissible by applicable laws, please take note that there may be circumstances in which we are unable to accommodate your request to edit, update, access, or delete an account profile or Personal Data.


6.3 As a condition of using our Services, you are obligated to provide us with accurate and complete Personal Data. Failure to do so may prevent us from delivering our Services to you. You acknowledge and consent that if you refuse to provide such necessary Personal Data or exercise any right that limits our ability to process your Personal Data, to the extent such limitation, in our opinion, restricts us from effectively delivering our Services, we reserve the right to terminate our relationship and discontinue all Services provided to you. By using our Services, you agree to waive any right to claim, contest, or initiate action against us in connection with our decision to terminate Services due to such limitations. Furthermore, you agree to indemnify us against any and all losses, damages, or costs arising out of your refusal to provide Personal Data or any limitations placed on its processing.


7. Changes/Updates to this Notice


This Notice is current as of its Effective Date stated at the beginning of this Notice. We reserve our absolute right to change, modify, update, revise or amend this Notice or any part thereof, from time to time, including to incorporate necessary changes in law, technology or business practices. All updates will be posted on our website, and where applicable, we will notify Users of material changes that may impact on our handling and processing of Personal Data. We encourage you to periodically review this Notice for updates on our platform. In the event of any conflict between the English version and the Bahasa Malaysia version of this Notice, the English version shall prevail.


8. Contact Information


If you have any questions, inquiries, complaints, concerns or require any actions or further steps regarding about this Notice or your Personal Data, you can contact our data protection officer at support@blox.my.