Version: 3.3 Effective Date: November 2025
Applies To: iWoWSoft HRMS — SaaS, IaaS and On-Premises Deployments
iWoWSoft Sdn. Bhd. (“iWoWSoft”, “we”, “our”, or “us”) is committed to protecting the privacy and security of all personal data processed through our Human Resource Management System (HRMS).
This statement describes how iWoWSoft complies with the Malaysian Personal Data Protection Act 2010 (PDPA) across all service models — Software-as-a-Service (SaaS), Infrastructure-as-a-Service (IaaS) and on-premises installations.
This statement applies to all personal data collected, processed, transmitted, or stored through iWoWSoft HRMS solutions, regardless of deployment type or client location.
| Deployment Model | Data Controller | Data Processor | Infrastructure Ownership |
|---|---|---|---|
| SaaS (Cloud HRMS) | Client | iWoWSoft | iWoWSoft-managed Tier-3-equivalent facility |
| IaaS (Private Cloud in iWoWSoft Data Centre) | Client | iWoWSoft (infrastructure) / Client (application) | iWoWSoft-owned infrastructure |
| On-Premises Deployment | Client | Client | Client-owned infrastructure |
Employee information — including identifiers, employment records, and payroll details — constitutes personal data under the PDPA because it relates directly to an identifiable individual.
Accordingly, all employee records processed through the HRMS are protected as personal data, and iWoWSoft applies the same PDPA principles to such data as to any other personal information.
Personal data is processed lawfully and only for legitimate business purposes such as HR administration, payroll, leave management, statutory reporting, authentication, and system maintenance.
Clients can view and update employee records within the HRMS to ensure data remains accurate and up to date, satisfying PDPA’s Data Integrity Principle.
Core processing occurs within Malaysia. Where encrypted traffic or backups traverse global infrastructure, PDPA Section 129(3) safeguards apply — end-to-end encryption, limited purpose, and equivalent protection by all providers.
iWoWSoft may change or upgrade its data-centre or technology providers to enhance performance and security. Any change will maintain equal or higher levels of PDPA compliance. Clients will be notified of material changes that affect data residency or protection.
iWoWSoft supports clients in fulfilling PDPA rights — access, correction, and withdrawal of consent — via the HRMS interface or formal support requests through authorised administrators.
Third-party service providers engaged by iWoWSoft are contractually required to implement confidentiality, security, and PDPA-equivalent controls. Vendors may change from time to time; equivalent or stronger safeguards will always apply.
All iWoWSoft employees, contractors, and authorised service providers are bound by confidentiality and non-disclosure agreements (NDAs) that prohibit unauthorised access, use, or disclosure of client information.
These obligations apply to all forms of data handled through our platform, including employee and corporate records, and remain in effect during and after the engagement period.
Clients operating their own or dedicated infrastructure must:
iWoWSoft provides guidance and support but does not control client-managed systems.
Clients are responsible for retaining employee and payroll data in accordance with applicable statutory requirements.
Examples include payroll, tax, and contribution records that must generally be kept for a minimum of seven (7) years under Malaysian employment and taxation laws.
iWoWSoft provides secure retention, backup, and deletion features within the HRMS to support compliance with these obligations; however, clients determine their own record-keeping periods.
Upon expiry of the statutory or contractual period, clients should securely delete or archive data in accordance with PDPA’s Retention Principle.
Data Protection Officer (DPO)
📧 dpo@iwowsoft.com.my
🌐 https://www.iwowsoft.com/contact-us
Our official contact page is kept up to date to ensure accuracy even if office locations change.
This statement reflects iWoWSoft’s data-protection practices as of the effective date. Our infrastructure and processes may evolve, but we will continue to uphold PDPA and equivalent international standards. This document is for informational purposes and does not constitute a binding contract or warranty.
| Version | Date | Summary of Updates |
|---|---|---|
| 3.3 | Nov 2025 | Added statutory data-retention requirements; finalized for SaaS, IaaS & On-Prem deployments with NDA and employee-data clarification |