Last updated: 20 July 2026
This policy explains how Hadir (“the Service”), operated by [Your Registered Business Name] ([SSM Registration No.]), handles personal data, in line with Malaysia's Personal Data Protection Act 2010 (PDPA).
The business that subscribes to Hadir (“the Employer”) is the data controller of its employees' personal data. We act as the data processor, processing that data only to provide the Service on the Employer's instructions.
Face images and GPS location are only collected when the Employer switches on those clock-in methods. Employers are responsible for obtaining their employees' consent before enabling them, as required by the PDPA.
Data is used solely to operate attendance, leave, scheduling, payroll and reporting features. We do not sell personal data. We do not disclose it to third parties except as needed to run the Service (e.g. email delivery) or where required by law.
Data is stored on access-controlled infrastructure and transmitted over HTTPS. Passwords and PINs are hashed. Data is retained while the Employer's account is active and deleted on request after account closure.
Employees may request access to or correction of their data through their Employer. Employers may export or request deletion of their account data by contacting us.
[Your Registered Business Name]
Email: muhammadshafiq457@gmail.com
WhatsApp: [Your WhatsApp number]
[Your business address, Malaysia]
This document is a template provided for convenience and is not legal advice. Have it reviewed by a qualified professional before relying on it commercially.