Introduction
VKraft treats personal information with care and processes it only for clear, legitimate business purposes.
This privacy statement describes how VKraft collects, uses and shares personal information about individuals who deal with us — including people at our clients, prospects, technology and delivery partners, suppliers, and visitors to vkraftsoftware.com. It applies to the VKraft group entities and the offices through which we operate in Malaysia, India, Singapore, the United Kingdom and the United States, except where a local entity publishes its own notice without referring to this statement.
VKraft works as a business-to-business provider. Where we deliver integration, API management, iPaaS, automation, Gen AI, migrations or a product such as finX, Health360, DwaniAI, MetricMonitor or Easy-Invois into a client's environment, that client is responsible for how personal information is collected and used inside those systems. That processing is covered by the client's own privacy policy, unless we say otherwise. Our contract with the client may allow us to request details about authorised users for account and delivery management. In that case, this statement, or a product-specific notice, applies.
We may publish additional privacy information in a supplementary notice where a particular service, product or engagement needs it.
Information we collect and use
The information we collect depends on how you deal with us: reading the site, sending a form, joining an event, applying for a role, or working with us on a delivery. We collect what we need to respond, to run the site, and to deliver the work we have been asked to do.
This website
vkraftsoftware.com is how we describe our services, products and offices, and how you can contact us. Information collected on the site is used to make the pages available, keep them secure, and understand how the site is used. You do not need an account to browse. There is no public login for visitors.
We collect information about visits to the site, such as:
- the pages you view and the time of the request
- the referring URL, if your browser sends one
- approximate location derived from IP address
- links you follow on our pages
Your browser or device also sends technical details, such as IP address and browser type, operating system, device type and version, language settings, and any error or crash information generated by the hosting environment. We use those details to deliver pages correctly on your device, meet security and network requirements, diagnose faults, investigate misuse and keep the site available.
We do not run third-party advertising or analytics pixels on this site, and we do not use this information to build advertising audiences.
Pages may link to other organisations — for example a partner, a map, or a social profile. Their content and privacy practices are their own. This statement does not cover those sites.
Enquiry and demo forms
Forms on this site collect the details you type in. Depending on the form, that can include:
- Name, work email, organisation, phone number and role
- Service, industry or product of interest, including finX, Health360, DwaniAI, MetricMonitor and Easy-Invois
- How you heard about us, partnership type, or Open Finance / PayNet role
- A free-text message, and whether you agree to this policy
Those fields appear on the contact form, product and industry lead forms, the partnerships form, and the Open Finance connect form. We use them to reply, book a call, send a proposal or demo, and keep a record of the request. Forms include a Cloudflare Turnstile check so we can tell a person from automated spam.
Products and client platforms
finX, Health360, DwaniAI, MetricMonitor and Easy-Invois are built for client organisations. Personal data that end users or customers put into those systems — consent records in an Open Finance programme, clinic workflow data, conversation transcripts, operational metrics, or invoice records — is processed under the client's instructions and under that client's own notices. VKraft does not use that production data to market this website.
If you ask for a product demo or an Open Finance conversation from these pages, that request is treated as enquiry data under this statement, not as data inside the product itself.
Sensitive personal data
Some client systems we build or operate hold sensitive categories of personal data — health and clinical information in a Health360 deployment, or financial account information in an Open Finance programme. Where that happens we act on the client's instructions as their service provider, and the client is responsible for obtaining any explicit consent the law requires. We do not collect sensitive personal data through this website, and you should not include it in a form message or an enquiry email.
Marketing and events
We may use business contact details to tell you about a relevant service, product or event. We do this where you have asked us to, or on the basis of our legitimate interest in business-to-business marketing to people in a relevant professional role. Where the law requires your prior consent, we ask for it first. We do not buy advertising audiences or run retargeting pixels on this site. You can stop marketing messages at any time by using the unsubscribe link in an email, or by writing to contact@vkraftsoftware.com.
Client engagements
When we quote, contract or deliver work — API management, application and partner integration, IBM hybrid iPaaS, open source, Gen AI, AI agents, low-code, data and analytics, hyper automation, or migrations — we collect the business contact and project information needed to staff the work, reach named stakeholders, and meet the contract. That can include names, roles, work emails, meeting notes and technical context you choose to share.
Support and security
If you raise a support or security issue we keep the ticket content, related logs and contact details for as long as we need them to resolve the issue and to protect the site and our clients. Turnstile tokens are used only to validate the submission, not as a marketing identifier.
Offices and visits
If you visit or call an office we may record your name, organisation, contact details and the reason for the visit so we can host you and keep the premises secure. Our locations are listed on the contact page: Kuala Lumpur (headquarters) and Kuantan in Malaysia; Singapore; Hyderabad and Nashik in India; Watford in the United Kingdom; and Jacksonville in the United States.
Careers
Applications sent through the careers page or to contact@vkraftsoftware.com are used to assess suitability, arrange interviews and keep a record of the process. We do not ask applicants to create an account on this website.
Children
This website, our services and our products are intended for business users. They are not directed at children. We do not knowingly collect personal information from children. If you believe we have, please write to contact@vkraftsoftware.com and we will delete it.
Cookies and similar technologies
This public website uses only what is needed to operate it: hosting and security logs, and Cloudflare Turnstile on pages that carry a form. Turnstile may place a short-lived token or cookie in your browser to confirm the submission came from a person; it is not used to profile you or to track you across sites.
We do not set optional advertising or analytics cookies on these pages, which is why you will not see a cookie-preference bar. Signed-in VKraft staff use session cookies on internal tools that are not part of this public website.
Automated decisions
We do not make decisions about you by automated means alone that produce legal effects or a similarly significant effect. Where we use AI tools internally — for example to summarise an enquiry or draft a reply — a person reviews the output before we act on it or send it to you.
Sharing
We do not sell personal information. We share it only where we need to run the site, answer you, deliver contracted work, or meet a legal duty. That can include:
- Hosting and infrastructure providers that serve vkraftsoftware.com
- Form processors such as Formspark, which receive submissions from selected lead and Open Finance forms
- Cloudflare, which provides the Turnstile check on those forms
- Email and, where used, CRM tools that store business contacts so we can reply and manage the relationship
- Professional advisors such as lawyers, auditors and insurers, on a need-to-know basis
- VKraft colleagues in the offices listed above, so the right delivery or sales person can respond
Each supplier is bound by a written contract that limits them to processing the information on our instructions and requires them to keep it secure.
We may also disclose information if required by law, a court or a regulator, or to protect VKraft, our clients or other users — for example to investigate fraud or abuse of the site.
International transfers
Because we work from more than one country, authorised staff in Malaysia, India, Singapore, the United Kingdom or the United States may access enquiry or project contacts in order to handle them. Some of our suppliers also store or process data outside the country you are in.
Where personal data covered by the GDPR or UK GDPR leaves the European Economic Area or the United Kingdom, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision, together with additional technical and organisational safeguards where a transfer risk assessment calls for them. For transfers from Malaysia and Singapore we rely on the contractual protections required under the Malaysian PDPA and the Singapore PDPA. You can ask us for a copy of the relevant safeguards using the contact details below.
We limit access to people who need it, and we protect the information in transit and at rest.
Who is responsible
For personal information collected through this website and its forms, the controller is:
VKraft Software Services Sdn Bhd
L3-I-2, Hive 5, Taman Teknologi MRANTI
Lebuhraya Puchong Sg Besi, 57000 Kuala Lumpur, Malaysia
We have appointed a Data Protection Officer, who is responsible for how we handle personal information and for answering your questions about it.
Data Protection Officer
Write to us and mark your message for the Data Protection Officer
contact@vkraftsoftware.com
Privacy and security questions
Any request under this policy, or a security issue you have found
contact@vkraftsoftware.com
For personal data inside a client-hosted product or a system we operate on a client's instructions, the client is typically the controller. Their own policy, and the contract with VKraft, govern that processing. If you are an end user of a client system and you contact us, we will point you to that client unless we collected the data ourselves on this website.
Security and retention
We apply access control, encryption in transit, role-based restrictions on who can reach enquiry and project data, and operational practices reviewed against recognised information security standards. No method of transmission or storage is perfect; we work to reduce the risk of unauthorised access, loss or misuse.
We keep personal information only as long as we need it. What counts as long enough depends on the record:
- Enquiry and demo records — until the enquiry is closed and any follow-up has run its course, unless it becomes a client engagement
- Client engagement records — for the term of the contract, then for the period our accounting, tax and legal duties require
- Career applications — for the recruitment process and a limited period afterwards, so we can consider you for a similar role, unless you ask us to delete them sooner
- Support and security tickets — until the issue is resolved and no longer needed as a reference for related problems
- Technical and security logs — for as long as they remain useful for security and operations, or longer where we are investigating an incident
At the end of those periods we delete the information or anonymise it so it can no longer identify you.
Data breaches
We keep procedures for detecting, investigating and responding to personal data breaches. If a breach happens and the law requires it, we notify the relevant regulator — including the Personal Data Protection Commissioner in Malaysia within the statutory deadline — and we tell affected individuals directly where the breach is likely to cause them significant harm.
Where we hold data as a service provider for a client, we notify that client without undue delay so they can meet their own reporting duties, on the timelines set in our contract with them.
If you think you have found a security problem affecting this website or our services, please write to contact@vkraftsoftware.com.
Your rights
Depending on where you are, you may have rights under the Malaysian Personal Data Protection Act, the Singapore PDPA, India's Digital Personal Data Protection Act, the GDPR or UK GDPR, or a United States state privacy law. Those rights can include:
- Access to the personal information we hold about you
- Correction of inaccurate or incomplete details
- Deletion, where we no longer need the information or you withdraw consent
- Restriction of, or objection to, certain processing, including direct marketing
- A copy of your data in a portable format, where that right applies
- Withdrawal of consent, without affecting earlier lawful use
- Nomination of another person to exercise your rights, where Indian law provides it
Write to contact@vkraftsoftware.com. We will acknowledge your request and respond within the period the applicable law allows — 21 days under the Malaysian PDPA, 30 days under the Singapore PDPA, and one month under the GDPR and UK GDPR. If a request is complex we may extend that period and will tell you why. We do not charge a fee unless the law permits one. We may need to verify who you are before we act.
If we hold the data only as a service provider for a client, we will pass your request to that client where we cannot act on it ourselves.
You can also complain to the privacy regulator where you live or work:
| Where you are | Regulator |
|---|---|
| Malaysia | Department of Personal Data Protection (JPDP) |
| Singapore | Personal Data Protection Commission (PDPC) |
| India | Data Protection Board of India |
| United Kingdom | Information Commissioner's Office (ICO) |
| European Economic Area | Your national supervisory authority |
Legal basis
Where a privacy law requires a legal basis, we rely on one or more of the following:
- Steps prior to a contract, and performance of a contract — answering an enquiry, sending a proposal, delivering agreed work
- Legitimate interests — running and securing this website, understanding which practice area you asked about, and business-to-business follow-up that you would reasonably expect. You can object to processing on this basis at any time
- Consent — where a form asks you to agree to this policy, or where we send marketing that needs consent
- Legal obligation — tax, accounting, and responding to lawful requests
Updates
We will change this statement when our practices or the law require it. The "Last updated" date at the top of the page will move when we publish a revision, and we will tell you directly if a change materially affects how we use information you have already given us. Continued use of the website after an update means the revised statement applies to later collection.
