Legal

Privacy Policy

This policy describes what KSKILL INTEGRA SDN BHD (“KSKILL”, “we”) collects when you use the KSKILL Integra Training Centre platform (the “Service”), what we do with it, and the rights you have over it.

Last updated: 15 August 2026

Who we are

KSKILL INTEGRA SDN BHD is a company registered in Malaysia. When you use the Service, we act as the data controller for prospect, applicant, and platform-administrator data, and as a data processor for learner and content data on behalf of the workspace (tenant) that provisioned you an account. Data controllership is spelled out in the Data Processing Agreement.

What we collect

We collect three broad categories of data:

  • Account data — name, email, workspace role, hashed password material (held by our identity provider, not us directly), preferred language, and locale.
  • Activity data — courses viewed, lessons completed, assessment attempts, uploads (assignments, portfolio items), messages sent through the platform, and events written to the tenant audit log.
  • Technical data — IP address, user agent, session identifiers, and cookies strictly necessary to run the Service. See the Cookie Policy for the full list.

We do not knowingly collect personal data from anyone under 13. If a workspace admin needs to enrol under-13 learners, contact us — that is a separate agreement with a parent or guardian.

Lawful basis

We process personal data on the following bases, depending on where you are and what the processing is:

  • Malaysia PDPA 2010 — consent for account creation, performance of contract for delivering the Service, and legitimate interest for security and abuse prevention.
  • EU GDPR (where applicable) — Article 6(1)(b) contract, Article 6(1)(f) legitimate interest, and Article 6(1)(a) consent for optional communications. Standard Contractual Clauses are available for cross-border transfers via our DPA.

How we use it

We use personal data to:

  • provision and operate your account and workspace,
  • deliver courses, assessments, and certificates you enrol in,
  • send transactional messages (password resets, receipts, course reminders),
  • investigate abuse, spam, and security incidents,
  • meet legal, tax, and audit obligations,
  • improve the Service in aggregate (never by selling data).

We do not sell personal data. We do not train third-party AI models on your content. AI features that call an external provider (see “Third parties” below) run under contracts that prohibit training on our data.

Third parties

We rely on a small set of processors to run the Service:

  • Cloudflare — content delivery, DDoS mitigation, and Zero Trust access to admin surfaces. Cloudflare may briefly see request metadata (IP, URL) at its edge.
  • Keycloak — identity and access management. Passwords and MFA secrets never enter our application database.
  • Payment providers (currently Billplz for Malaysian FPX/e-wallet payments; more may be added) — receive the amount, currency, buyer name, buyer email, and the tenant reference for a transaction. Card and bank credentials go directly to the provider, never to us.
  • AI providers (Anthropic, OpenAI, Google Gemini, DeepSeek, or a self-hosted model) — whichever your workspace admin selects. Prompts and completions transit these providers only when an AI feature is invoked, and the provider is contractually barred from training on the content.
  • Resend — outbound transactional email delivery.
  • Object storage (MinIO / S3-compatible) — file uploads, SCORM packages, and recordings. Storage can be self-hosted by the tenant.

The full, current sub-processor list is maintained in the DPA and is updated at least 30 days before a new sub-processor takes on regulated processing.

Your rights

Under Malaysia PDPA 2010 and, where it applies, GDPR, you have the right to:

  • access the personal data we hold about you,
  • rectify inaccurate or incomplete data,
  • delete your account and its associated personal data (subject to legal retention windows for finance and audit records),
  • port your data in a machine-readable format (JSON export),
  • object to processing based on legitimate interest,
  • withdraw consent where consent was the basis for the processing.

To exercise a right, email [email protected]. If the data is held by us as a processor on behalf of a workspace, we will route the request to that workspace’s admin and copy you on the forward. We respond within 21 days.

Retention

We keep your account and activity data for as long as your account is active. When you delete your account, personal data is removed within 30 days, except for records we are required to keep for tax, audit, or dispute-resolution purposes, which are retained for up to 7 years as required by Malaysian law. Audit-log entries that reference your actions may be retained in a de-identified form (with your name replaced by an internal ID) to preserve the integrity of the log.

Cross-border transfer

The primary application database sits in Malaysia. Some technical data (request headers, cache entries) is processed at Cloudflare’s global edge, which may include locations outside Malaysia and the EEA. For EU customers, transfers rely on Standard Contractual Clauses attached to the DPA.

Security

We encrypt data in transit with TLS 1.3, at rest at the database layer, and enforce tenant isolation with PostgreSQL row-level security as the primary boundary. MFA is available on every account. See the Security page for the full technical summary.

Changes to this policy

We version this policy. Material changes are announced by email to every admin account and shown on this page for at least 14 days before taking effect. The date at the top of this page always reflects the current version.

Contact

Data-protection questions: [email protected]. General support: [email protected] or the contact page. Postal address available on request.

Privacy Policy — KSKILL Integra Training Centre