Digi Telecommunications Sdn Bhd (and the Telenor Group, which we are part of) (referred to “Digi”, “us” or “we”) is committed to protecting and respecting your privacy.
Digi is a mobile connectivity, internet services provider, business and digital solutions provider. Our office is located at Lot 10, Jalan Delima 1/1, Subang Hi-Tech Industrial Park, 40000 Subang Jaya, Selangor Darul Ehsan.
altHR is a cloud-based human resources solution available on mobile applications (“App”) and on the web (“Web App”), which encompasses features such as leave management, expense claims, travel requests, payroll services, and employee management. In this Privacy Notice, “Customer” shall mean the organisation (company or legal entity) that subscribes to altHR, and “End User” shall mean any individuals who has access to our App and/or Web App. Customers and End Users may also be referred to as “you” in the appropriate context.
This Privacy Notice sets out the basis on which we collect, use, process and store personal information when our Customers and/or End Users subscribe to altHR and use its features, or visit our altHR website (collectively referred to as “Services”). Please read this Notice in context with the Terms & Conditions and altHR Privacy & Security Whitepaper.
Digi will process your personal information based on:
2.1 The performance of your contract and to act on your requests. For example, performing Services that Customers have subscribed to, allowing End Users to submit expense claims and leave applications, and offer technical support required by Customers.
2.2 Legitimate business interests, for example, fraud prevention, maintaining the security of our services, direct marketing, and the improvement of our Services. Whenever we rely on this lawful basis to process your data, we assess our business interests to make sure they do not override your rights. For more information on your rights, visit the 'What Are Your Rights' section below.
2.3 Compliance with a mandatory legal obligation, including accounting and tax requirements, and any lawful request from the government or law enforcement officials.
2.4 Consent which you provided where Digi does not rely on other legal basis. The Customer will ensure that it has obtained/ will obtain all necessary consents and comply with all applicable requirements under applicable laws for the processing of personal information by Digi in accordance with this Privacy Notice. When you give your consent, you may withdraw it at any time. For more information on your rights, visit the ‘What Are Your Rights' section below.
We collect your personal information in three ways:
3.1 Information you give us
Digi will collect your personal information when you:
(i) Register or use any of our Services,
(ii) Contact us through various channels or ask for information about a Service,
(iii) Take part in a survey,
(iv) Publish your information publicly, and
(v) Are the customer of a business that we acquire.
3.2 Information we collect automatically
(i) When you use our Services,
3.3 Information from other sources
(i) We may collect information from third-party sources before initiating your Services, or get background information with regards to the organisation, or where you have given permission to other companies to share information about you. The third-party sources include fraud-prevention agencies, business directories, credit check reference and vetting agencies, payment providers, business partners, and connected network providers.
The types of information we collect depend on the subscription, use of our Services, and the ways that you interact with us. This may include:
4.1 Customer’s contact, billing and other information provided
This includes your:
(i) Company name,
(ii) Business Registration Number,
(iii) Contact number,
(iv) Email address,
(v) Company size,
(vi) Industry information
(vii) Payment information,
(viii) Security information used for authentication,
(ix) Access to accounts and services information, and
(x) Information you provide in surveys, or Digi-sponsored promotions.
4.2 End User’s contact information, and other information provided
(ii) Email address,
(iv) Voice recordings,
(v) Security information used for authentication,
(vi) Access to accounts and services information, and
(vii) Information you provide in any correspondence, surveys, or Digi-sponsored promotions.
4.3 How you use our Services and your devices
(i) Application and feature usage such as app version and purchase history,
(ii) Device-specific information and identifiers,
(iii) IP address, and
(iv) GPS location for certain features of the Services.
We will only collect and process information that is necessary to facilitate the features you have subscribed to. We may not be able to process your application and/or provide you with our Services for reasons such as:
(i) If you fail to supply us with the necessary personal information;
(ii) If the personal information supplied is incomplete and not accurate; and/or
(iii) If you withdraw your consent for us to process your personal information.
Our Services may contain links to third party websites, or access to third party services (such as Insurance providers). We have no control over how third-party websites and services process your personal information and we are not responsible for their privacy practices. Please read the privacy policies of any third-party websites or services that you access from our websites or services.
Digi may use and process your personal information for the following purposes:
5.1. To provide you with our Services
(i) Processing your application and providing you with our Services
• To keep you updated on your subscription.
• To provide relevant information about the Services.
• To fulfil your requests such as account management and deliver other products or services related to your subscription.
(ii) Billing and customer care
• To issue you the bill statement for using our Services and payment collection.
• To recover debts or trace those who owe us money resulting from the use of our Services.
• To respond to any questions or concerns you may have about our Services.
• To monitor and record our communications with you for training purposes and quality assurance.
(iii) Service messages
• To send you latest information that relates to your subscribed Services.
• To notify changes to our terms and conditions or service interruptions.
5.2 To manage and improve our Services
(i) To provide technical support, troubleshooting, and other uses of our Services for a better customer experience.
(ii) To develop more interesting and relevant Services.
5.3 To send marketing materials and personalise our Services to you
• Depending on the extent of consent obtained from you, to send you promotional materials relating to our Services, or promote the Services of our partners or such third parties which we think may be of interest to you.
• We tailor these messages based on the Services you’ve subscribed from us in the past, or information we have from third parties.
• You can control your marketing permissions and the data we use to tailor these communications at any time. For more details on this and how to prevent processing of your personal information, visit the 'What Are Your Rights' section below.
(ii) Online advertising
• With consent, we may display testimonials of satisfied Customers on our site, along with other endorsements.
• To target our marketing and advertising campaigns [and those of our partners] more effectively and personalised, and to make your online experience more efficient and enjoyable. This is known as interest-based advertising. It can be on websites belonging to Digi, other organisations as well as other online media channels such as social media sites. We may also combine data collected via the cookies with other data we have collected about you.
• To prevent any processing of information, you can change your cookies settings. Refer to the ‘Cookie Notice’ for more information.
• Opting out of interest-based advertising does not stop advertisements from being displayed – it is just that they would not be tailored to your interest. To stop receiving advertising on your social media, go to the relevant platform’s ad settings.
5.4 To conduct research and analytics
(i) To conduct research, monitor and analyse the use of our Services on an anonymous or personalised basis, in order to identify general trends, conduct market research or surveys, internal marketing analysis, customer segmentation, develop new Services, and improve our understanding of our customers’ patterns, behaviours and choices.
(ii) To create aggregated statistics about our sales, customer network traffic, location patterns and customer demographics. Such aggregated statistics do not include information that can personally identify you.
5.5 To carry out credit checks, fraud prevention and security measures
(i) Credit checks
• To carry out a credit check when Customers apply for any Services with us.
• To exchange information about Customers with credit reference agencies while you have a relationship with us. This includes your settled accounts or any outstanding debt you have with us. This information may be supplied to other organisations by the credit reference agencies.
(ii) Fraud prevention and security
• To verify your identity when you request access to your account and for general account management purposes.
• To protect your account from unauthorised access, fraud, misuse, or damage to our Services.
• To prevent illegal activities, suspected fraud, and potential threats to our Services, Customers, and End Users.
• To detect and stop cyber security threats to our internal systems and Services.
We use partners and service providers for a variety of business purposes. In such cases, where applicable, we share information about our Customers and End Users with:
6.1 Affiliates: We may share your personal information with Telenor Group for processing activities listed in ‘How Do We Use’ section above.
6.2 Data Processors: We engage third party to process your personal information on our behalf and on our instructions, such as IT vendors.
6.3 Business Partners: We work with partners to deliver services you have subscribed to, including in-app purchases and package delivery on our behalf.
6.4 Service Providers: We share your information to services providers such as payment processors or insurance providers that is linked to our Services, to the extent of enabling you of using these Services.
6.5 Marketing Partners: We may share your information with marketing and advertising partners to provide you with more tailored content and better service.
6.6 Researchers: We may share your personal information to third parties for research or statistical analytics purposes to help us understand how you use our Services.
6.7 Professional Advisors: We engage professional advisors on matters relating to our Services, including debt collection agencies, credit reporting agencies, legal advisors, accountants, and auditors.
6.8 Fraud Management: We will release information if it is reasonable for the purpose of protecting us against fraud, defending our rights or property, or to protect the interests of our Customers.
6.9 Law Enforcement: We may also need to release your information to comply with our legal obligations and to respond to the authorities’ lawful demands. Your personal information shall only be provided in good faith, when we are obliged to do so in accordance with the law and pursuant to an exhaustive evaluation of all legal requirements.
6.10 Other Organisations: If our company is reorganised or sold to another organisation, we will provide your information to that organisation.
Where you buy a third-party product or service through your altHR account, the contract is with the party selling that product or service. As part of this, you are agreeing that Digi may pass certain personal information (for instance, to verify your information) to such parties to complete your purchase. The seller’s terms and conditions, privacy and cookie notice will apply to how it uses your personal information – please read them carefully.
When we share your personal information, we will take steps to ensure that the recipient will protect your privacy, keep your personal information secure and process it in accordance with applicable law and this privacy notice.
We will not sell the personal information that we process about you to third parties without your consent
We will keep your personal information as long asnecessary for the purposes for which we collect and process it unless a longerretention period is required by the Malaysian law. Your information will bedeleted in accordance with our Retention Schedule below.
We have a specialised security team who constantly review and improve our measures to protect your personal information from any loss, misuse, modification, unauthorised or accidental access or disclosure, alteration, or destruction.
We will never ask for your secured personal or account information through an unsolicited means of communication. You are responsible for keeping your personal and account information secure and to not share it with others. Please refer to our altHR Privacy & Security Whitepaper for more information.
Our website may provide links to third-party websites. We are not responsible for the security and content of such third-party websites. Make sure you read the respective organisation’s privacy and cookie notice before using or putting your personal information on their sites.
You have rights in relation to the personal information that we hold about you. Your privacy rights include:
10.1 Right to withdraw consent: At any point of time, you have the right to withdraw your consent to us to use, process or share your personal information by contacting us. However, withdrawing your consent will result in us not being able to process your application and/or provide you with our services.
10.2 Right to access your information: At any point of time, you can request a copy of the personal information that we hold about you by contacting us or access the information directly through your altHR account.
10.3 Right to correct personal information: At any point of time, you can request to correct or amend your personal information that is inaccurate by contacting us or through your altHR account.
10.4 Right to prevent processing:
(i) You can request for us to temporarily suspend processing activities of your personal information when you believe that there are concerns over the accuracy, legitimacy, and lawfulness of the processing. During the temporary suspension period, we may not be able to process your application and/or provide you with our Services.
(ii) You can request for us to cease processing activities of your personal information for marketing purposes. If you no longer want to receive personalised content and marketing messages from Digi, you can choose to opt-out at any time.
Please note: You may still receive marketing messages for a short period after opting out while we update our records.
(iii) You can request for us to cease or not to begin processing your personal information if the processing causes or is likely to cause you unwarranted substantial damage or distress. If you exercise this right, we will not be able to process your application and/or provide services to you.
To ensure that the personal information we hold about you is correct and up to date, we may from time to time contact you to verify the accuracy of your personal information in our record. However, it is your responsibility to ensure that you provide us with true, accurate and complete information.
Our Services are not meant for children.
Digi reserves its right to amend this Privacy Notice from time to time based on changes as per the business, legal and regulatory requirements, and applicable laws. We encourage you to revisit this notice periodically, allowing you to see any changes made by checking the effective date below.
If we decide to use or disclose information that identifies you personally in a way that is materially different from what we stated in our Privacy Notice at the time we collected that information from you, we will give you a choice about the new use or disclosure by appropriate means, which may include an opportunity to opt-out.
Updated March 2021
In accordance with the requirement of Malaysian data protection and privacy law, this Privacy Notice is issued in both English and Bahasa Malaysia. In the event of any inconsistencies or discrepancies between the English version and the Bahasa Malaysia version, the English version shall prevail.
Should you have any queries, concerns or complaints in relation to this Privacy Notice, kindly send to: