Privacy Policy
Effective Date: 21 June 2026
1. Introduction
HyperDEF ("HyperDEF", "we", "our", or "us") is committed to protecting your privacy and handling your personal data responsibly. This Privacy Policy explains how we collect, use, disclose, store, and protect your personal data when you access our websites, applications, and cybersecurity assessment services.
This Privacy Policy is intended to align with the principles of the Personal Data Protection Act 2010 ("PDPA") of Malaysia.
By using our services, you acknowledge that you have read and understood this Privacy Policy.
2. Scope
This Privacy Policy applies to:
* https://hyperdef.io
* https://app.hyperdef.io
* HyperDEF's Cybersecurity Health Check platform
* Related communications and support services provided by HyperDEF
3. Personal Data We Collect
We may collect the following information:
### 3.1 Information You Provide
* Name
* Email address
* Job title
* Contact number (if provided)
* Account credentials
* Information submitted through contact forms
* Information submitted when requesting support
### 3.2 Assessment Information
* Assessment responses
* Asset counts and related security information
* Assessment scores
* Generated reports
* Historical assessment records
### 3.3 Technical Information
We may automatically collect:
* IP addresses
* Browser type and version
* Device information
* Operating system
* Access timestamps
* Authentication events
* Security and audit logs
* Usage information necessary to maintain service security
4. How We Use Your Information
We use personal data to:
* Create and manage your account;
* Authenticate users and secure access;
* Generate cybersecurity assessment reports;
* Maintain assessment history;
* Provide customer support;
* Improve and maintain our services;
* Detect, investigate, and prevent fraud or misuse;
* Comply with legal obligations;
* Contact you regarding your account or requested services;
* Send service-related notifications;
* Provide marketing communications only where you have requested or consented to receive them.
5. AI-Assisted Recommendations
HyperDEF may use third-party artificial intelligence services to assist in generating narrative recommendations included within assessment reports.
To protect your privacy:
* HyperDEF does not provide personally identifiable information to AI providers.
* HyperDEF does not provide company-identifying information to AI providers.
* Only anonymised assessment findings, scores, category results, and generic security observations may be processed.
* The underlying assessment logic, scoring methodology, and findings remain determined by HyperDEF.
Examples of information that will NOT be shared with AI providers include:
* Company names;
* Names of individuals;
* Email addresses;
* Phone numbers;
* User identifiers;
* Database identifiers;
* IP addresses;
* Asset names;
* Device names;
* Free-text responses capable of identifying a customer.
6. Disclosure of Personal Data
We do not sell your personal data.
We may disclose personal data to trusted service providers who assist us in operating our services, including providers involved in:
* Website and application hosting;
* Cloud infrastructure;
* Database hosting;
* Authentication services;
* Email delivery services;
* Security monitoring;
* Analytics;
* AI-assisted recommendation generation using anonymised findings.
Such providers are expected to process information only for authorised purposes and subject to appropriate safeguards.
7. Cross-Border Transfers
Certain service providers engaged by HyperDEF may process information outside Malaysia.
Where personal data is transferred outside Malaysia, HyperDEF will take reasonable steps to ensure that appropriate safeguards are implemented to protect such data.
8. Cookies and Similar Technologies
HyperDEF may use cookies and similar technologies to:
* Maintain secure login sessions;
* Enable essential platform functionality;
* Improve user experience;
* Support security and fraud prevention.
You may control cookies through your browser settings. Disabling certain cookies may affect platform functionality.
9. Data Retention
HyperDEF retains personal data only for as long as necessary to fulfil the purposes described in this Privacy Policy.
Unless otherwise required by applicable law:
* User account information and associated assessment records will generally be retained until the user requests account deletion;
* Following an account deletion request, personal data will generally be deleted or anonymised within thirty (30) days;
* Security and access logs may be retained for a limited period where necessary to investigate incidents, maintain security, or comply with legal obligations.
Where retention is no longer necessary, HyperDEF will securely delete or anonymise the relevant information.
10. Security Measures
HyperDEF implements reasonable administrative, technical, and organisational safeguards designed to protect personal data against unauthorised access, disclosure, alteration, misuse, or destruction.
These measures may include:
* Encryption of data in transit;
* Secure password hashing;
* Access controls and role-based permissions;
* Multi-factor authentication where applicable;
* Audit logging;
* Monitoring and security review processes;
* Principle of least privilege.
However, no method of transmission or storage can be guaranteed to be completely secure.
11. Your Rights
Subject to applicable laws, you may have the right to:
* Request access to your personal data;
* Request correction of inaccurate or incomplete personal data;
* Request deletion of your personal data;
* Withdraw consent where processing is based on consent;
* Opt out of marketing communications.
Requests may be submitted using the contact information below.
HyperDEF may require reasonable verification of identity before processing such requests.
12. Marketing Communications
HyperDEF will only send marketing communications where permitted by law or where you have consented to receive them.
You may unsubscribe from marketing communications at any time.
Service-related communications regarding your account or requested services will continue to be sent where necessary.
13. Children's Privacy
HyperDEF's services are intended for businesses and working professionals.
Our services are not directed toward individuals under the age of 18, and we do not knowingly collect personal data from children.
14. Changes to This Privacy Policy
HyperDEF may update this Privacy Policy from time to time.
Any changes will be published on our website and application together with the updated effective date.
Continued use of our services after such updates constitutes acceptance of the revised Privacy Policy.
15. Contact Us
If you have questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact us at:
Email: secure@hyperdef.io
Website: https://hyperdef.io
Assessment: https://app.hyperdef.io