Privacy Policy and PDPA Notice
Last updated: 12 July 2026
Effective date: 12 July 2026.
This Privacy Policy and Personal Data Protection Notice ("Privacy Policy", "PDPA Notice" or "Notice") explains how Launch48, a digital launch initiative operated by Kr8iv Sdn Bhd, with technical and hosting infrastructure powered by Stratagile Sdn Bhd ("Launch48", "we", "us" or "our"), collects, uses, processes, stores, discloses, protects and manages personal data in connection with our website, chatbot, demo websites, website creation services, the Launch48 Portal, hosting, Care Plans, domain assistance, add-on services, support, communications, payment processing and related services.
This Notice is issued pursuant to the Personal Data Protection Act 2010 of Malaysia ("PDPA"), including the Personal Data Protection (Amendment) Act 2024 and any applicable regulations, standards, codes of practice and guidelines issued thereunder, including applicable Data Protection by Design guidance. For the purposes of the PDPA, Kr8iv Sdn Bhd is the data controller in respect of the personal data described in this Notice, and Stratagile Sdn Bhd and other service providers act as data processors where they process personal data on our behalf.
By accessing our website, interacting with our chatbot, submitting an enquiry, communicating with us, viewing a demo website, making payment, using the Portal, providing business information, engaging our services or continuing to use our services, you acknowledge that you have read and understood this Privacy Policy and PDPA Notice.
1. Scope of This Notice
This Notice applies to personal data that we collect or process in connection with:
- the official Launch48 website and its chatbot;
- demo websites prepared for potential or confirmed clients;
- client websites created, hosted, maintained or managed under the Launch48 service;
- the Launch48 Portal, including account credentials and activity records;
- enquiries submitted through forms, WhatsApp, email, telephone, social media or other channels;
- website setup, customisation, staging review and go-live;
- domain registration, transfer and DNS assistance;
- hosting, security, backup and Care Plan services;
- payment, billing, subscriptions and account administration;
- client support and communications;
- marketing, promotions and follow-up communications; and
- any other related services provided by Launch48.
This Notice applies to clients, potential clients, business owners, company representatives, authorised personnel, suppliers, partners, website visitors and any person whose personal data is provided to or processed by us.
Important: personal data on client websites. Where a client publishes personal data on its own website through the Portal (for example customer testimonials, staff names or photographs), or collects personal data from its own customers through its website forms, the client is the data controller of that personal data, not Launch48, Kr8iv or Stratagile. Section 16 explains this in detail.
2. Meaning of Personal Data
For the purpose of this Notice, "personal data" means any information in respect of commercial transactions that relates directly or indirectly to a living individual who is identified or identifiable from that information or from that information combined with other information in our possession, as defined under the PDPA.
Personal data may include, but is not limited to: name; phone number; WhatsApp number; email address; company or business name; job title or role; business address; billing address; identification or registration details where required (including SSM documents provided for domain verification); payment and transaction details; domain ownership and registrar details; Portal login credentials; images, logos, videos or personal profiles supplied for website use; messages, enquiries, chatbot conversations, instructions and approvals; IP address; device and browser information; website usage data; cookies and tracking information; and any other information you provide to us.
"Sensitive personal data" includes information relating to physical or mental health, political opinions, religious or other similar beliefs, the commission or alleged commission of any offence, biometric data and any other category prescribed under the PDPA. We generally do not request sensitive personal data. If you provide it, you confirm that you have the right and authority to do so and, where required, have obtained the necessary consent from the relevant individual.
3. Personal Data We May Collect
3.1 Enquiry, Chatbot and Contact Data
Name, phone number, WhatsApp number, email address, company or business name, enquiry details, chatbot conversation records, preferred contact method, communication history and appointment or call details.
3.2 Business and Website Content Data
Business profile and description, owner or founder profile, team member names and photos, contact details, addresses and map locations, opening hours, products, services, menus and pricing, testimonials, social media links, images, videos, logos and brand assets, Public Information (as described in Section 6), Google Business Profile information and other website content supplied, confirmed or published by you.
3.3 Payment and Billing Data
Invoice details, billing name and address, payment amount and status, transaction references, subscription and recurring payment details and payment gateway records. Card payments are processed by Stripe or another third-party payment processor; we do not usually store full credit or debit card numbers, which are processed by the payment processor under its own terms and privacy policy.
3.4 Domain, Hosting, Portal and Technical Data
Domain name and registrar information, SSM documents where provided for .my or .com.my verification, DNS records, hosting information, Portal login credentials and account records, Portal activity and edit logs, go-live records, server logs, IP address, security logs, backup records (including nightly database backups of Portal edits and periodic codebase snapshots) and other technical information required to provide the services.
3.5 Website Usage and Analytics Data
Our website uses privacy-focused analytics designed to measure visits and interactions without building personal profiles. Data processed may include IP address, device type, browser type, operating system, referring website, pages visited, time spent, click activity, form submissions, cookies and similar usage data.
4. How We Collect Personal Data
We may collect personal data: when you visit our website or use our chatbot; when you submit an enquiry or contact us through WhatsApp, telephone, email or social media; when you view or respond to a demo website; when you confirm content for your website; when you make payment or subscribe to a Care Plan; when you use the Portal; when you provide domain, DNS or SSM verification documents; when you request support; when you press go-live; when you interact with our advertising or marketing; through third-party tools, platforms, payment processors, hosting providers and analytics services; and from publicly available sources as described in Section 6.
Where we collect personal data through forms, consent is obtained through clear, affirmative, opt-in mechanisms. Consent checkboxes are never pre-ticked, in line with applicable Data Protection by Design guidance under the PDPA.
5. Chatbot
Our website chatbot answers questions about Launch48 services. Conversations with the chatbot may be recorded and processed to respond to your queries, improve service quality and maintain enquiry records. Please do not submit sensitive personal data, full payment card numbers or passwords through the chatbot. Chatbot responses are general information only and are not legal, financial or professional advice.
6. Public Information Used for Demo Websites and Builds
Launch48 may prepare demo websites, and build client websites, using publicly available business information, including information from Google Business Profile, social media pages, existing websites, public directories, public reviews and public photos. This is done for demonstration, proposal and service delivery purposes.
A demo website may contain assumptions, placeholder content or publicly available information that may not be complete, current or accurate. The client is responsible for reviewing, correcting and confirming all information before pressing go-live.
If you believe that a demo website contains incorrect, outdated, sensitive, private, unauthorised or unsuitable information, please contact us and we will review the matter and, where appropriate, correct or remove the material.
7. Purposes of Processing Personal Data
We may collect, use and process personal data to: respond to enquiries and chatbot conversations; contact you about Launch48 services; prepare and present demo websites; assess website requirements; create, customise, stage, launch, host and manage client websites; provide Portal access and process Portal edits, publishing actions and backups; provide domain registration, transfer and DNS assistance (including registrar verification); provide hosting, security, maintenance and Care Plan services; process payments, invoices, subscriptions and billing through our payment processors; manage accounts and client records; provide support; troubleshoot technical issues; maintain security, prevent fraud and investigate misuse; monitor performance; communicate service, billing and legal notices; send marketing and promotional communications where permitted; improve our services and processes; maintain internal records; comply with legal, regulatory, tax and accounting requirements; enforce our Terms and Conditions, Refund Policy and other policies; protect the rights, property and safety of Launch48, Kr8iv, Stratagile, our clients and others; and for any other purpose reasonably related to the provision of our services.
8. Legal Basis and Consent
Where required by applicable law, we process personal data based on your consent, contractual necessity, legal obligations, legitimate business purposes or other lawful grounds recognised under the PDPA.
By providing personal data to us, engaging our services, confirming website content, using the Portal or continuing to use our services, you consent to the collection, use, processing, disclosure and retention of your personal data in accordance with this Notice.
Providing personal data is voluntary, but if you do not provide the data requested, or later withdraw consent, we may be unable to provide or continue providing certain services.
9. Disclosure of Personal Data
We may disclose personal data, where necessary and for the purposes stated in this Notice, to:
- employees, directors, contractors and authorised personnel of Kr8iv Sdn Bhd;
- Stratagile Sdn Bhd, acting as our technology and infrastructure partner and data processor for hosting, security, firewall management, backups and technical operations;
- designers, developers, copywriters, project coordinators and technical support personnel engaged in delivering the services;
- hosting, cloud, domain registrar, registry and DNS providers (including MYNIC and registrars requiring SSM verification for .my and .com.my domains);
- payment processors and gateways (including Stripe), banks and financial institutions;
- email, communication and messaging platform providers, including WhatsApp and related Meta services;
- analytics, chatbot, security and monitoring service providers;
- professional advisers, including lawyers, accountants, auditors and insurers;
- government authorities, regulators, enforcement bodies or courts where required or permitted by law;
- third parties involved in a business transfer, merger, restructuring or acquisition, subject to appropriate safeguards; and
- any other party authorised by you or necessary for service delivery.
We take reasonable steps to ensure that third parties who process personal data on our behalf handle it appropriately and only for permitted purposes. Personal data is not sold to third parties.
10. Cross-Border Transfer of Personal Data
Our hosting infrastructure operates across global server locations, and some of our service providers, payment gateways, communication tools, analytics tools and cloud services may store or process data outside Malaysia. Stratagile operates internationally across multiple countries.
By using our services, you acknowledge that your personal data may be transferred, stored or processed outside Malaysia where necessary for service delivery. Where personal data is transferred outside Malaysia, we take reasonable steps to ensure the transfer complies with the PDPA and applicable cross-border personal data transfer guidelines, and that the data receives adequate protection.
11. Cookies and Tracking Technologies
Our website may use cookies and similar technologies to operate the website, remember preferences (including language selection), improve performance, understand visitor behaviour through privacy-focused analytics, measure marketing effectiveness and support security and fraud prevention.
Cookies may be set by Launch48 or by third-party services such as analytics, embedded maps, video platforms, chatbot tools or social media features, which operate under their own privacy policies. You may disable cookies through your browser settings, though some features may not work properly if you do.
12. Marketing Communications
We may contact you with service updates, offers, reminders, promotions and Launch48 news through email, WhatsApp, phone, SMS, social media or other channels, where you have consented or where otherwise permitted by law.
You may opt out of marketing communications at any time by contacting us or using any unsubscribe or opt-out method provided. We may still send important service, billing, legal or account-related communications.
13. Retention of Personal Data
We retain personal data only as long as necessary for the purposes stated in this Notice, including service delivery, account management, legal compliance, tax and accounting, dispute resolution, security and audit. In general: enquiry and chatbot records are retained for a reasonable period after the enquiry; client account and service records for the duration of the relationship and a reasonable period after; payment, invoice and tax records for the periods required by law; Portal activity, go-live and hosting records while the service is active and a reasonable period after (including for chargeback and dispute evidence); backup data for limited technical retention periods; and dispute-related data for as long as necessary to protect legal rights.
When personal data is no longer required, we take reasonable steps to delete, anonymise, archive or securely dispose of it, subject to technical, legal and operational requirements.
14. Security of Personal Data
We take reasonable administrative, technical and organisational measures to protect personal data, in accordance with the security principle under the PDPA. These measures include SSL encryption, an application-level security firewall managed by Stratagile (malware and bad-link filtering and bot blocking), dual-layer backups, access controls, password protection, restricted team access on a need-to-know basis, confidentiality obligations and the use of reputable service providers. Stratagile is an ISO 27001-certified company.
However, no online system is completely secure, and we cannot guarantee absolute security of personal data transmitted or stored online. You are responsible for keeping your Portal and other credentials confidential and for notifying us immediately of any suspected compromise.
15. Personal Data Breach
In the event of a personal data breach affecting personal data under our control, we will take reasonable steps to assess, contain, investigate and respond to the incident. Where required under the PDPA and applicable guidelines, we will notify the Personal Data Protection Commissioner as soon as practicable and, where the breach is likely to cause significant harm, notify affected individuals in accordance with applicable legal requirements.
Clients must notify us immediately if they suspect unauthorised access, compromised credentials, malware or any security issue affecting their website, Portal account, domain or related service.
16. Client Websites: The Client Is the Data Controller
Where a client collects personal data through its own website (for example contact forms, reservation features or checkout forms), or publishes personal data on its website through the Portal (for example staff names and photographs, customer testimonials or personal profiles), the client is the data controller of that personal data under the PDPA and is solely responsible for its own compliance, including obtaining consents, issuing privacy notices, handling access and correction requests from its own customers and complying with marketing rules.
Launch48, Kr8iv and Stratagile act, at most, as technical service providers and data processors in respect of such data (for example by hosting the website and maintaining automated backups), and do not use it for their own purposes.
Websites built by Launch48 include a bilingual (English and Bahasa Malaysia) privacy notice on pages that collect personal data, and unticked opt-in consent checkboxes on forms. These are technical features provided for the client's convenience; they do not constitute legal advice and do not transfer the client's PDPA obligations to Launch48, Kr8iv or Stratagile.
If you provide personal data of your customers, employees, partners or any third party to us, or publish it through the Portal, you confirm that you have the authority to do so, have obtained all necessary consents, and will indemnify Launch48, Kr8iv Sdn Bhd and Stratagile Sdn Bhd against any claim arising from unauthorised or unlawful provision, publication or disclosure of such data.
17. Access and Correction Rights
Subject to the PDPA, you may request access to your personal data held by us or request correction of personal data that is inaccurate, incomplete, misleading or not up to date. To make a request, contact us using the details at the end of this Notice. We may request proof of identity or authority before processing a request, may charge a reasonable fee where permitted, and may refuse or limit a request where permitted or required by law, giving reasons where required.
18. Withdrawal of Consent, Direct Marketing and Data Portability
You may withdraw your consent to processing by written notice, require us to stop processing your personal data for direct marketing purposes, and object to processing likely to cause unwarranted substantial damage or distress. Withdrawal of consent may affect our ability to provide services, and does not affect processing already carried out or processing required for legal, contractual, accounting or dispute purposes.
Where applicable under the PDPA, you may request that your personal data be transmitted to another data controller, subject to technical feasibility and compatibility of data formats. Portability requests do not extend to proprietary systems, templates, internal records, security logs or data that cannot reasonably be transferred in the requested format.
19. Accuracy of Personal Data
You are responsible for ensuring that the personal data you provide is accurate, complete and up to date, and for notifying us promptly of changes, including contact details, billing information, domain ownership details and authorised representatives. We are not responsible for issues caused by inaccurate, outdated or incomplete information provided by you.
20. Children and Minors
Our services are intended for businesses and their authorised representatives. We do not knowingly collect personal data from children without appropriate consent. If personal data of a minor is provided or published for website content, the client is responsible for ensuring proper parental, guardian or legal consent has been obtained.
21. Third-Party Websites, Platforms and Payment Processing
Our website and client websites may contain links to or integrate third-party websites, platforms and services. We are not responsible for the privacy practices of third parties, and you should review their privacy policies. If you communicate with us through WhatsApp, social media or other platforms, your use of those platforms is subject to their own terms and privacy policies.
Payments are processed by third-party payment processors (including Stripe), which collect and process payment information under their own terms and privacy policies. We receive payment confirmations, transaction status and limited payment-related information necessary for billing and service activation.
22. Domain and Registrar Information
Where we assist with domain registration, transfer, renewal or DNS setup, we may process domain-related personal data such as registrant name, company name, contact details, SSM verification documents (for .my and .com.my domains) and registrar records. Domain information may be processed by registrars, registries (including MYNIC) and DNS providers subject to their own terms, privacy policies and legal requirements. The client is responsible for ensuring domain ownership information is accurate and authorised.
23. Business Transfer
If Kr8iv, Launch48, Stratagile or any relevant part of the business is involved in a merger, acquisition, restructuring, sale or other corporate transaction, personal data may be transferred as part of that transaction, with reasonable steps taken to ensure the receiving party handles it in accordance with applicable legal requirements.
24. Legal and Regulatory Disclosure
We may disclose personal data where required or permitted by law, including to comply with legal obligations and court orders, respond to lawful requests from authorities, enforce our legal rights and agreements, protect our business, systems, clients and users, investigate fraud, abuse or security incidents, recover unpaid amounts and defend against claims or disputes.
25. Limitation of Liability
While we take reasonable steps to protect personal data, to the maximum extent permitted by law, neither Launch48, Kr8iv Sdn Bhd nor Stratagile Sdn Bhd shall be liable for any loss, damage, claim, cost or expense arising from unauthorised access, disclosure, loss or misuse of personal data caused by: client negligence; weak or shared passwords; compromised email, Portal or domain accounts not attributable to our negligence; personal data published on a client website by or with the approval of the client; third-party platform or provider failure; cyberattacks despite reasonable safeguards; inaccurate information provided by you; or events outside our reasonable control.
Nothing in this Notice excludes liability that cannot be excluded under applicable law.
26. Updates to This Notice
We may update this Privacy Policy and PDPA Notice from time to time to reflect changes in our services, legal requirements, technology or data protection practices. The updated version will be published on our website with a revised "Last Updated" date. Continued use of our website or services after an update constitutes acknowledgement of the updated Notice.
27. Language
In accordance with the PDPA, this Notice is issued in English and in Bahasa Malaysia. The Bahasa Malaysia version is available on our website or upon request. In the event of any inconsistency, the English version shall prevail to the extent permitted by law.
28. Contact Us
If you have any questions about this Privacy Policy and PDPA Notice, or wish to make a request relating to access, correction, withdrawal of consent, direct marketing, data portability or any other personal data matter, please contact:
Launch48, operated by Kr8iv Sdn Bhd, with technical infrastructure powered by Stratagile Sdn Bhd.
- Email: hello@launch48.my
- WhatsApp: +60 11-5448 4866
- Address: D2-04-03 Tamarind Square, Persiaran Multimedia, Cyber 10, 63000 Cyberjaya, Selangor, Malaysia
- Company Registration No.: 201801038578 (1300609-V)
Where a data protection officer has been appointed under the PDPA, requests will be directed to that officer.
29. Acknowledgement
By accessing the Launch48 website, interacting with our chatbot, submitting an enquiry, viewing a demo website, making payment, using the Portal, providing personal data, confirming website content or using our services, you acknowledge that you have read and understood this Privacy Policy and PDPA Notice.