General Information
This Privacy Policy explains how Elythra collects, uses, discloses and protects personal data in connection with our software development services, websites and client engagements. We focus on lawful, transparent processing and operational security measures appropriate to the scale and sensitivity of the data we handle. If you have questions about our practices, contact our data protection point of contact listed below.
Definitions
Key terms used in this Policy are defined to help clarify our data practices and the scope of the rights and obligations described herein.
Data We Collect
We collect information necessary to deliver services, maintain secure systems, and comply with contractual and legal obligations. Collection is limited to data types relevant to specified processing purposes.
Data You Provide
When engaging with Elythra or using products we develop, you or your organization may provide personal data required for service delivery, communication, and account management.
- Contact information (name, business email, job title, phone number) for client representatives and technical contacts.
- Account credentials and authentication information required to access client portals or project management tools.
- Project materials and content uploaded for development, such as documents, images, and business process descriptions.
- Billing and invoicing details, including organizational billing addresses and tax identifiers where required for payment processing.
- Support and feedback communications submitted to Elythra via email, ticketing systems or contact forms.
- Consents and preferences you provide for marketing communications or data-sharing choices where applicable.
Automatically Collected Data
We also collect technical and usage data automatically to operate and improve our services, prevent misuse, and analyze performance.
- Device and browser metadata such as IP address, user agent, screen resolution and operating system.
- Usage metrics including page views, feature usage, session duration and error logs related to service operation.
- Performance telemetry and diagnostic data generated by software applications for monitoring stability and resource utilization.
- Cookies and similar local storage identifiers used to maintain sessions and preferences on tvorra.info and Elythra-managed applications.
- Analytics data collected via third-party analytics services where enabled on public-facing sites and demo environments.
- Security logs such as authentication attempts, IP access history and other indicators used for threat detection and incident response.
Third-Party Sources
In certain cases we receive data from trusted third parties to fulfill service requirements or enrich records for legitimate operational purposes.
- Payment processors and invoicing services providing transaction confirmations and payment metadata.
- Identity and authentication providers used for single sign-on and federated access to client systems.
- Professional service partners and sub-processors engaged to deliver parts of a contracted project under written agreements.
Purposes of Processing
We process personal data only for specified, explicit and legitimate purposes. Processing activities are aligned to client contracts and operational needs.
- To provide, maintain and improve software development services and client deployments.
- To manage client relationships, project communication and technical support.
- To process payments, invoices and related business administration.
- To ensure security of systems, detect and respond to incidents and maintain data integrity.
- To comply with legal obligations, contractual commitments and lawful requests from authorities where applicable.
- To perform analytics and product improvement tasks using aggregated and anonymized usage data.
- To implement access controls, authentication and identity management for client environments.
- To provide marketing communications where consent has been expressly provided by the recipient.
Legal Bases for Processing
Where relevant law requires identification of a legal basis for processing, Elythra relies on the following bases according to the specific processing activity.
- Performance of a contract: processing necessary to perform our obligations under client agreements.
- Legal compliance: processing necessary to comply with applicable laws or regulatory requirements.
- Legitimate interests: processing for operational security, fraud prevention, and infrastructure management where balanced against individual rights.
- Consent: processing for optional services such as marketing communications, where consent is collected and recorded.
GDPR and Related Rights
For residents of jurisdictions covered by GDPR-like frameworks, Elythra implements data subject rights and protections in line with applicable requirements.
- Right of access: individuals may request information about personal data we hold about them and processing activities.
- Right to rectification: individuals can request correction of inaccurate or incomplete personal data.
- Right to erasure: where applicable, requests to delete personal data will be assessed against legal and contractual retention obligations.
- Right to restriction or objection: individuals may request restriction of processing or object where legitimate interest grounds apply.
- Right to data portability: where processing is based on consent or contract and uses automated means, data portability may be available.
- Right to lodge a complaint with a supervisory authority if you consider your rights have been breached.
Data Sharing and Disclosure
Elythra shares personal data only when necessary to fulfill service obligations, to comply with law, or with authorized third-party providers under contractual safeguards.
- Service providers and sub-processors engaged to perform hosting, analytics, payment processing or support functions under NDAs and data processing agreements.
- Clients and client-authorized parties when data is processed on behalf of a client in accordance with the client contract.
- Law enforcement or regulatory authorities in response to lawful requests or to protect legal rights and safety.
- Acquirers or advisors in the event of a corporate transaction, subject to confidentiality commitments and applicable law.
- Aggregated or anonymized datasets that cannot reasonably be re-identified, used for product improvement and research.
- Other parties where you have provided explicit consent for sharing as part of a service feature.
International Data Transfers
Data processed by Elythra may be stored or processed in jurisdictions outside your country. Transfers are managed with appropriate safeguards such as standard contractual clauses, data processing agreements, or other authorized mechanisms.
When transferring data internationally, Elythra relies on contractual protections, encryption, access controls and risk assessments to maintain an adequate level of protection consistent with applicable legal requirements.
Data Retention
We retain personal data only as long as necessary for the purposes for which it was collected, for legal compliance, or to satisfy contractual obligations.
Account records and billing information are retained for the duration of the contractual relationship and for a limited period afterward to meet accounting and legal requirements.
Support tickets, correspondence and project communication are retained for a period aligned with project lifecycle and dispute resolution needs, typically not exceeding business-necessary timeframes.
System logs and security telemetry are retained according to operational needs and security policy, with routine purging or anonymization applied to older records.
Upon termination of services or at your request where applicable, Elythra will delete or anonymize personal data in line with contractual terms and legal obligations, subject to any necessary exceptions.
Security Measures
Elythra applies administrative, technical and physical measures to protect personal data against unauthorized access, alteration, disclosure and destruction. Security practices are reviewed regularly and updated in line with industry standards.
- Access controls and role-based permissions to limit data access to authorized personnel only.
- Encryption in transit and at rest for sensitive data, combined with secure key management practices.
- Regular vulnerability assessments, patch management and logging to detect and respond to security events.
User Rights
Individuals may exercise their rights regarding personal data by contacting Elythra. Requests will be processed in accordance with applicable law, with identity verification where necessary.
- To exercise rights such as access, rectification, erasure, restriction, objection or portability, contact elythra@tvorra.info or send a request to the address at 2, Jalan USJ Sentral 3, Sungai Penaga Industrial Park, 47600 Subang Jaya, Selangor, Malaysia. Include sufficient details to locate the data and proof of identity where required.
- Request correction of inaccurate or incomplete personal data that Elythra holds about you.
- Request deletion of personal data where processing is no longer necessary or lawful, subject to legal retention requirements.
- Request restriction of processing where accuracy is contested or where processing is unlawful but you oppose deletion.
- Object to processing for direct marketing or profiling based on legitimate interests, where applicable.
- Request portability of personal data you have provided in a structured, commonly used, machine-readable format where eligibility criteria are met.
- Withdraw consent to processing at any time for processing activities based solely on consent without affecting prior lawful processing.
- Lodge a complaint with a supervisory authority in Malaysia if you believe your privacy rights have been violated.
How to exercise your privacy rights
To exercise any of the privacy rights listed, contact Elythra using the contact details below. Please specify which right you wish to exercise and provide sufficient information to identify yourself and the data in question. We will respond to rights requests in accordance with applicable law after verifying your identity. Complex requests or ones requiring coordination with third parties may require additional time; in such cases we will explain any necessary extensions and the reasons for them.
contact@tvorra.info
Elythra aims to acknowledge receipt of rights requests within 7 business days and provide a substantive response within 30 calendar days where permitted by law. If additional time is necessary due to the complexity or volume of requests, we will notify you of an extension and the expected response timeframe.
Marketing communications
Elythra may send you marketing communications about services, case studies, or events where you have consented to receive them or where we have a legitimate interest and you have not opted out. Marketing messages are tailored to professional audiences and focus on topics such as bespoke software development, integration services, and operational improvement for businesses in Malaysia.
You can opt out of marketing communications at any time by using the unsubscribe link in the message or by contacting Elythra at the address below. Opting out will not affect transactional or service-related messages necessary for provision of contracted services.
Children's privacy
Elythra offers services to businesses and professional clients. We do not knowingly collect personal data from children under 16 years of age. If we become aware that personal data of a child has been collected without appropriate consent, we will take steps to delete such data in accordance with applicable law.
Third-party links
Our website and communications may contain links to third-party sites, tools, or resources. Elythra is not responsible for the privacy practices or content of those third parties. We encourage you to review the privacy policies of any external site before submitting personal information.
Changes to this privacy policy
Elythra may update this privacy policy to reflect changes in our practices, legal requirements, or service offerings. Material changes will be posted on our website with an updated effective date. Continued use of our services after such updates constitutes acceptance of the revised policy.