LEGAL | PRIVACY NOTICE

Privacy Policy.

Marketing Lancers Consultancy Sdn Bhd (SSM 1460628-X) · Last updated 23 August 2026. This notice describes our operating approach and does not replace an executed customer agreement or legal advice.

POLICY · 8 SECTIONS

The full text.

01

Who we are

ONSET (operated by Marketing Lancers Consultancy Sdn Bhd, SSM 1460628-X) is an AI back-office platform for Malaysian and Singaporean SMEs. We are the data controller for information collected via app.onset.my.
02

Data we collect

  • Account: email address, name (required for authentication)
  • Usage: dashboard activity, page views, feature interactions
  • Service data: approved messages, documents or call records used by purchased services
  • Provider data: identifiers and delivery records returned by configured customer or ONSET providers
  • Telemetry: error, usage, security and performance records needed to operate and support the service
03

PDPA compliance (Malaysia)

Depending on the applicable law and request, you may be able to:
  • Request access to personal data held about you
  • Request correction of inaccurate personal data
  • Withdraw consent where consent is the applicable basis
  • Request another action available under the applicable law
  • Lodge a complaint with the Personal Data Protection Commissioner

DPO contact: compliance@onset.my

04

Sub-processors

The providers used for an account depend on its purchased services and configured connections. The current list, purpose, processing region where confirmed, and contract status are kept at /trust/subprocessors. A service order identifies the provider categories relevant to that customer before production activation.
05

Data retention

Data is retained only for the account, legal, security and service-delivery purposes stated in the applicable agreement. The service order or data-processing addendum records any service-specific retention period. Deletion requests remain subject to legal holds, payment records and backup expiry.
06

Data security

  • Account-scoped access controls are required before customer data is exposed through an application route.
  • Privileged service credentials are restricted to server-side operations and are not rendered to customers.
  • Provider connections and data flows are reviewed for the purchased service before activation.
  • Current control evidence and known limitations are published in the Trust Centre.
07

AI governance disclosures

ONSET uses internal governance classes to record how an AI-enabled change may be reviewed:
  • Class A — Auto-evolvable with owner approval (chat tones, intent detection)
  • Class B — Manual-only changes (proposals, contracts, regulatory text)
  • Class C — Frozen by owner memo (foundation models, pricing floor)

Current operational controls and disclosures are available in the Trust Centre.

08

Your rights & contact

To exercise PDPA rights or report a security concern:

MARKETING LANCERS CONSULTANCY SDN BHD · KUALA LUMPUR, MALAYSIA