United Data
  • Home
  • SmartKPI
  • Privacy
  • Terms
  • Delete account
Your data, explained clearly

Privacy Policy

This policy explains how United Data handles personal data through our website, services and SmartKPI platform.

Effective date: 10 August 2026  •  Last updated: 10 August 2026

On this page1. Scope and roles2. Data we collect3. How we collect it4. How we use it5. Device permissions6. Sharing7. International transfers8. Security9. Retention10. Your rights11. Account deletion12. Children13. AI and analytics14. Website cookies15. Changes16. Contact
Plain-language summary: We collect only the data needed to provide, secure and improve our services. We do not sell personal data. SmartKPI customer organisations control most employee and workplace records; United Data processes that information to provide the service.

1. Scope and our role

This Privacy Policy applies to United Data Centre (MY) Sdn. Bhd. (“United Data”, “we”, “us” or “our”), a company registered in Malaysia, and to our websites, products and services, including SmartKPI.

For information collected directly through this website, sales enquiries, contracts and our own business operations, United Data generally acts as the data controller.

SmartKPI is primarily a business-to-business service. Where an employer, customer or other subscribing organisation creates or manages accounts and workplace records, that organisation generally decides why and how the data is used and acts as the data controller. United Data acts as its service provider or data processor and handles data according to the customer’s instructions, our agreement and applicable law.

2. Personal data we may collect

The exact information depends on how you use the service and which SmartKPI features your organisation enables.

Account and identity information

  • Name, username, employee or staff identifier, email address, phone number and profile photo.
  • Organisation, branch, department, position, reporting line and assigned role or access level.
  • Authentication information such as encrypted passwords, login records and security tokens. We do not store passwords in readable form.

Work, attendance and performance information

  • Clock-in and clock-out records, timestamps, attendance status, schedules and approved work locations.
  • Location information used to confirm attendance within an authorised geofence, when enabled and permitted by the user’s device.
  • Attendance or work-verification photos, notes and supporting attachments, when required by the organisation.
  • Projects, jobs, tasks, acceptance or rejection, completion status, work evidence, comments and activity history.
  • KPI inputs, scores, adjustments, rewards, recognitions, leave-related records and reports configured by the customer organisation.

Device, usage and technical information

  • Device type, operating system, app version, language, IP address, login time and general diagnostic information.
  • App interactions and technical logs needed for security, troubleshooting and service improvement.
  • Push-notification tokens used to deliver service notifications.

Enquiries and commercial information

  • Messages, support requests and feedback you send to us.
  • Business contact, quotation, contract, subscription and payment administration records for customer organisations.

3. How we collect personal data

We may receive personal data:

  • directly from you when you use SmartKPI, contact us or submit information;
  • from your employer or subscribing organisation when it creates an account, uploads records or manages its workforce;
  • automatically from the app, device or browser when needed to operate and secure the service; and
  • from service providers supporting hosting, notifications, security, diagnostics or customer support.

4. Why we use personal data

We process personal data only for appropriate business and service purposes, including to:

  • create, authenticate and administer accounts;
  • provide SmartKPI attendance, task, performance, reward, notification and reporting functions;
  • display information to authorised users within the relevant customer organisation;
  • verify attendance or work activity when the customer has enabled those features;
  • deliver support, respond to enquiries and communicate service information;
  • protect accounts, prevent misuse, maintain logs and investigate security incidents;
  • maintain, troubleshoot, measure and improve our services;
  • administer contracts, billing and customer relationships; and
  • comply with legal obligations and enforce applicable agreements.

Where consent is required, we will request it through an appropriate notice or device permission. In an employment context, your organisation may rely on other lawful grounds available under applicable law and should provide its own employee privacy notice.

5. Mobile device permissions

Depending on enabled SmartKPI functions, the app may request access to:

  • Location: to confirm that an attendance action occurs within an authorised work area. SmartKPI should use location only when relevant to the attendance function and according to your device permission.
  • Camera or photos: to capture or upload attendance verification, task evidence or profile images chosen by the user.
  • Notifications: to deliver job, task, approval, announcement and other service updates.

You may manage permissions in your device settings. Some functions may not work where a permission is necessary for that function. Where practical, the app or your organisation may provide another verification process.

6. When we share personal data

We do not sell personal data. We may disclose information only as needed to:

  • Your organisation: authorised administrators, managers and users may access data according to assigned roles and the customer’s configuration.
  • Service providers: trusted providers may support cloud hosting, storage, email, push notifications, diagnostics, security, backups and customer support. They may process data only for the services they provide and under appropriate obligations.
  • Professional advisers: auditors, lawyers, insurers or advisers where reasonably necessary.
  • Authorities or legal parties: where disclosure is required by law, court order, regulatory request, or to protect rights, safety and security.
  • Business changes: in connection with a genuine merger, acquisition, financing or transfer, subject to appropriate confidentiality and legal safeguards.

If a feature shares personal data with a third-party AI provider, we will identify the purpose and obtain permission where required. Customer or user data is not used to train public AI models unless this is clearly disclosed and expressly authorised.

7. International data transfers

Our services may use technology providers that store or process information outside Malaysia. Where this occurs, we take reasonable steps to use reputable providers and appropriate contractual, technical and organisational safeguards in line with applicable Malaysian data-protection requirements.

8. Data security

We use reasonable administrative, technical and organisational measures designed to protect personal data, which may include role-based access, authentication controls, encryption in transit, protected infrastructure, logging, backups, vulnerability management and staff confidentiality controls. No internet service is completely risk-free, and we cannot guarantee absolute security.

If we become aware of a personal-data breach, we will assess and respond to it and make notifications where required by applicable law and our obligations to the relevant customer.

9. Data retention

We retain personal data only for as long as reasonably necessary for the purposes described in this policy, the customer agreement, legitimate business records and applicable legal obligations. Retention may depend on the type of information, the customer organisation’s instructions, active disputes, security needs, backup cycles and statutory record-keeping periods.

When data is no longer required, we delete, anonymise or securely isolate it according to our retention processes. Residual copies may remain in protected backups until those backups are overwritten or expire.

10. Your choices and rights

Subject to the Malaysian Personal Data Protection Act 2010, its amendments and other applicable law, you may have the right to:

  • be informed about the processing of your personal data;
  • request access to personal data held about you;
  • request correction of inaccurate, incomplete or outdated data;
  • withdraw consent where processing relies on consent;
  • object to or prevent certain processing, including direct marketing;
  • request deletion where applicable; and
  • request data portability where the right applies.

For SmartKPI workplace records, please first contact your employer or the administrator of your organisation’s SmartKPI account. We will support the organisation in responding where we act as its processor. You may also contact us using the details below.

11. Account and data deletion

You may request deletion of your SmartKPI account and associated personal data. Some records may need to be retained by your organisation or by us where required for legal, security, employment, contractual or dispute-resolution purposes. Where retention is required, the data will be limited and protected.

Visit our SmartKPI Account & Data Deletion page for the current steps and request channel. If the app supports account creation, the app should also provide an easy-to-find way to initiate full account deletion from its account settings.

12. Children’s privacy

Our business services and SmartKPI are not directed to children. We do not knowingly offer individual accounts to children below the age permitted by applicable law. If you believe a child’s information has been provided improperly, contact us so we can investigate and take appropriate action.

13. AI-assisted features and analytics

Some services may use analytics or AI-assisted functions to summarise information, identify patterns or help authorised users work with business data. These tools are intended to support—not replace—human judgment. Customer organisations remain responsible for employment and management decisions, reviewing outputs and applying appropriate oversight.

We will describe materially different AI data uses before introducing them and will update app-store privacy disclosures when required.

14. Website cookies and links

Our public website may use essential technical storage needed for security or basic operation. If we introduce non-essential analytics or marketing cookies, we will update this notice and provide choices where required. Our site may link to third-party websites; their privacy practices are governed by their own policies.

15. Changes to this policy

We may update this policy when our products, data practices or legal obligations change. We will publish the revised policy on this page and update the “Last updated” date. Where a change materially affects your rights or how we use personal data, we will provide additional notice when appropriate.

16. Contact us

For privacy questions, rights requests or complaints, contact:

United Data Centre (MY) Sdn. Bhd.
Kuala Lumpur, Malaysia
privacy@united-data.my
https://united-data.my

Please include enough information for us to understand and verify your request, but do not send passwords or unnecessary sensitive information by email.

United Data

United Data Centre (MY) Sdn. Bhd.

Kuala Lumpur, Malaysia

Company

HomeSmartKPIContact

Legal

Privacy PolicyTerms & ConditionsDelete Account

© United Data Centre (MY) Sdn. Bhd. All rights reserved.