PROCERT ASIA™ PRIVACY POLICY

Effective Date: 23 June 2026
Last Updated: 22 July 2026

1. Introduction

ProCert Asia™ (“ProCert Asia™”, “we”, “our”, or “us”) respects your privacy and is committed to protecting your personal data in accordance with the Personal Data Protection Act 2010 (Act 709) of Malaysia (“PDPA”), together with any applicable data protection laws in jurisdictions where we operate.

This Privacy Policy explains how we collect, use, disclose, store, protect, and process your personal data when you use:

  • The ProCert Asia™ website;
  • Our Learning Management System (LMS);
  • Professional certification services;
  • Accreditation services;
  • Training programmes;
  • AI-powered learning tools;
  • Digital certificate verification services;
  • Mobile applications (where applicable);
  • Events, webinars, conferences, and workshops;
  • Any other services offered by ProCert Asia™.

By accessing or using our Services, you acknowledge that you have read and understood this Privacy Policy.


2. Definitions

For the purposes of this Policy:

Personal Data means any information relating directly or indirectly to an identified or identifiable individual.

Sensitive Personal Data includes information relating to health, religious beliefs, biometric information, criminal records, or any other data classified under applicable law.

Processing means collecting, recording, storing, organising, adapting, retrieving, using, disclosing, transmitting, deleting, or destroying personal data.


3. Personal Data We Collect

Depending on the services you use, we may collect the following categories of personal data:

Identity Information

  • Full name
  • NRIC / Passport Number (where required)
  • Nationality
  • Date of birth
  • Gender (where necessary)

Contact Information

  • Email address
  • Telephone number
  • Residential or business address
  • Country
  • Organisation
  • Job title

Professional Information

  • Employer
  • Industry
  • Professional experience
  • Academic qualifications
  • Professional memberships
  • CPD history
  • Certification records

Training Information

  • Course registrations
  • Learning progress
  • Assessment scores
  • Attendance records
  • Practical assessments
  • Examination results
  • Certificates issued

Accreditation Information

For Training Providers, Universities and Organisations:

  • Company registration information
  • Accreditation documents
  • Trainer qualifications
  • Business licences
  • Programme submissions
  • Audit reports
  • Accreditation status

Payment Information

Where applicable:

  • Billing address
  • Payment history
  • Invoice records
  • Transaction references

Note: Payment card information is processed by authorised payment service providers. ProCert Asia™ does not store complete credit or debit card details.


Technical Information

Automatically collected information may include:

  • IP address
  • Browser type
  • Operating system
  • Device information
  • Language settings
  • Login timestamps
  • Cookies
  • Session information
  • Website usage analytics

AI Learning Information

When using our AI Learning Assistant, we may collect:

  • Prompts submitted
  • Learning interactions
  • Feedback provided
  • Chat history (where enabled)
  • Learning recommendations

AI conversations should not include confidential or sensitive information unless specifically requested for an authorised purpose.


4. How We Collect Personal Data

We collect personal data directly when you:

  • Register an account;
  • Apply for certification;
  • Register for training;
  • Submit assessments;
  • Purchase services;
  • Apply for accreditation;
  • Contact our support team;
  • Subscribe to newsletters;
  • Participate in surveys;
  • Attend events;
  • Use our LMS;
  • Use our AI Learning Assistant.

We may also collect information from:

  • Employers;
  • Accredited Training Providers (ATPs);
  • Universities;
  • Government agencies (where legally permitted);
  • Public professional directories;
  • Business partners;
  • Identity verification providers.

5. Purpose of Processing Personal Data

We process personal data for legitimate business purposes, including:

Certification

  • Processing certification applications
  • Identity verification
  • Examination administration
  • Issuing certificates
  • Maintaining certification records
  • Renewal management

Accreditation

  • Evaluating accreditation applications
  • Conducting audits
  • Monitoring compliance
  • Maintaining accreditation registers

Learning Management

  • Delivering online learning
  • Tracking learner progress
  • Providing AI-assisted learning
  • Recording assessments
  • Issuing completion certificates

Customer Support

  • Responding to enquiries
  • Providing technical assistance
  • Handling complaints
  • Managing appeals

Administration

  • Account management
  • Payment processing
  • Billing
  • Record keeping
  • Compliance monitoring

Marketing

With your consent where required:

  • Newsletters
  • Industry updates
  • Events
  • New courses
  • Promotional campaigns

You may unsubscribe at any time.


Legal Compliance

We may process data to:

  • Comply with applicable laws;
  • Respond to lawful requests;
  • Protect our legal rights;
  • Prevent fraud;
  • Investigate misconduct.

6. Legal Basis for Processing

Depending on applicable law, we process personal data based on:

  • Your consent;
  • Contractual necessity;
  • Legal obligations;
  • Legitimate business interests;
  • Protection of vital interests;
  • Public interest where applicable.

7. Cookies and Similar Technologies

We use cookies to:

  • Authenticate users;
  • Improve website performance;
  • Remember preferences;
  • Analyse website traffic;
  • Enhance security;
  • Personalise learning experiences.

Users may disable cookies through browser settings; however, certain website functions may not operate properly.


8. Disclosure of Personal Data

We may disclose personal data only where necessary to:

  • Accredited Training Providers;
  • Employers (where authorised);
  • Certification verification services;
  • Payment processors;
  • Cloud hosting providers;
  • IT service providers;
  • Government authorities;
  • Regulatory agencies;
  • Professional advisers;
  • Auditors;
  • Law enforcement agencies where legally required.

We do not sell your personal data.


9. International Data Transfers

As ProCert Asia™ expands internationally, personal data may be processed or stored outside Malaysia.

Where personal data is transferred internationally, we will take reasonable steps to ensure an appropriate level of protection consistent with applicable data protection laws.


10. Certificate Verification

To maintain the integrity of professional certification, ProCert Asia™ may publish or verify limited certification information, including:

  • Certificate number;
  • Certification title;
  • Certification status;
  • Issue date;
  • Expiry date (where applicable).

No unnecessary personal information will be disclosed through verification services.


11. Data Security

We implement reasonable administrative, technical, and organisational measures to safeguard personal data, including:

  • Secure servers;
  • Encryption where appropriate;
  • Access controls;
  • Multi-factor authentication (where available);
  • Firewalls;
  • Malware protection;
  • Regular security monitoring;
  • Backup procedures;
  • Staff confidentiality obligations.

No system can guarantee absolute security; however, we continuously improve our security practices.


12. Data Retention

We retain personal data only for as long as necessary for the purposes outlined in this Policy or as required by law.

Indicative retention periods:

Record Type Retention Period
Website enquiries Up to 2 years
Learner accounts While active and up to 1 year after inactivity
Certification records Permanently or as required for verification and legal purposes
Accreditation records Up to 1 year after expiry or termination
Financial records Minimum 7 years
Examination records Up to 7 years
Audit reports Up to 10 years

After the applicable retention period, personal data will be securely deleted, anonymised, or archived where legally permissible.


13. Your Rights

Subject to applicable law, you may have the right to:

  • Request access to your personal data;
  • Request correction of inaccurate information;
  • Withdraw consent where processing is based on consent;
  • Request restriction of processing where applicable;
  • Object to certain processing activities;
  • Request deletion where legally permissible;
  • Request information regarding processing activities.

Requests may be subject to identity verification.


14. Withdrawal of Consent

You may withdraw consent at any time by contacting us.

Withdrawal of consent may affect our ability to continue providing certain services, including certification, accreditation, or LMS access.


15. Children’s Privacy

Our Services are intended primarily for individuals aged 18 years or older.

Where minors participate in educational programmes, consent from a parent, guardian, school, or authorised institution may be required.


16. AI Learning Services

The AI Learning Assistant is designed to enhance learning and productivity.

Users acknowledge that:

  • AI-generated responses are educational guidance only;
  • AI outputs may contain inaccuracies;
  • Users remain responsible for independent verification;
  • AI should not be relied upon as legal, medical, financial, or professional advice.

We may use AI interaction data to improve our educational services, subject to applicable privacy laws.


17. Third-Party Websites

Our website may contain links to third-party websites.

ProCert Asia™ is not responsible for the privacy practices or content of external websites.

Users should review the privacy policies of those third parties separately.


18. Marketing Communications

Where permitted by law, we may send information regarding:

  • New certification programmes;
  • Professional development opportunities;
  • Events;
  • Industry updates;
  • Learning resources.

You may opt out at any time by following the unsubscribe instructions or contacting us directly.


19. Changes to this Privacy Policy

We may revise this Privacy Policy from time to time.

Material changes will be published on our website with an updated effective date.

Continued use of our Services after changes become effective constitutes acceptance of the revised Policy.


20. Contact Us

For enquiries, requests, or complaints relating to this Privacy Policy or the processing of your personal data, please contact:

Data Protection Officer (DPO)
ProCert Asia™ Sdn. Bhd.
Website: https://www.procert.asia
Email: frontdesk@procert.asia


21. Governing Law

This Privacy Policy shall be governed by and construed in accordance with the laws of Malaysia, including the Personal Data Protection Act 2010 (Act 709), without prejudice to any mandatory rights available to individuals under other applicable data protection laws.


22. Reservation of Rights

Nothing in this Privacy Policy limits ProCert Asia™’s rights to process, retain, disclose, or protect information where required or permitted by applicable law, court order, or regulatory authority.