POISUM’s Privacy Policy

This Privacy Policy explains how Gosum Consulting Group Sdn. Bhd. (“Gosum”, “we”, “our”, or “us”) collects, uses, and protects your personal data when you use the POISUM platform, in accordance with the Personal Data Protection Act 2010 (PDPA) of Malaysia.

By accessing or using POISUM, you acknowledge and agree to the data practices described in this policy.

1. What Personal Data We Collect

We may collect the following categories of personal data:

  • Full Name

  • Work Email Address

  • Job Title and Department

  • Company Name

  • Employee Engagement and Performance Data (e.g., Missions completed, Points earned, Campaign scores)

  • Device and login information (for security and analytics)


2. How We Use Your Data

Your data is used for the following purposes:

  • To create and manage your account

  • To track and analyze task performance and engagement

  • To generate performance-based reports for team leaders or HR

  • To support internal recognition and reward programs

  • To communicate system updates, campaign notifications, or support

  • To improve our service and enhance user experience


3. Legal Basis for Processing

We process your personal data based on:

  • Your explicit consent

  • The legitimate interest of your employer (POISUM’s client) in improving employee engagement and alignment

  • Compliance with applicable laws and regulations


4. Disclosure of Data

We do not sell or rent your data. Data may be shared with:

  • Your employer (POISUM’s client) for legitimate operational use

  • Third-party service providers (e.g., cloud hosting, analytics) under strict confidentiality agreements

  • Authorities where required by law


5. Cross-Border Data Transfers

POISUM may store data on secure servers located outside Malaysia (e.g., Singapore or other regions). All cross-border transfers comply with PDPA regulations and ensure equivalent data protection standards.


6. Data Retention

We retain your personal data only as long as necessary:

  • For account and system functionality

  • To fulfill reporting requirements

  • Or as required by law

 

Data may be anonymized and aggregated for analytics upon account closure.


7. Your Rights

Under the PDPA, you have the right to:

  • Access your personal data

  • Correct inaccurate or outdated data

  • Withdraw consent (where applicable)

  • Request deletion of your data (subject to business and legal requirements)

To exercise these rights, please contact: privacy@poisum.com


8. Data Security

We apply appropriate technical and organizational measures to:

  • Encrypt data at rest and in transit

  • Restrict access via role-based controls

  • Monitor and audit access logs


9. Changes to This Policy

We may revise this Privacy Policy periodically. Users will be notified through the platform or email of any significant changes.


10. Contact Us

For questions or concerns regarding your personal data, contact our Data Protection Officer:

📧 privacy@poisum.com