VKraft Software Services

Loading

Legal

Privacy policy

How VKraft Software Services collects, uses, shares and protects personal information on vkraftsoftware.com and through our enquiry forms.

Last updated: September 2026

Introduction

VKraft treats personal information with care and processes it only for clear, legitimate business purposes.

This privacy statement describes how VKraft collects, uses and shares personal information about individuals who deal with us — including people at our clients, prospects, technology and delivery partners, suppliers, and visitors to vkraftsoftware.com. It applies to the VKraft group entities and the offices through which we operate in Malaysia, India, Singapore, the United Kingdom and the United States, except where a local entity publishes its own notice without referring to this statement.

VKraft works as a business-to-business provider. Where we deliver integration, API management, iPaaS, automation, Gen AI, migrations or a product such as finX, Health360, DwaniAI, MetricMonitor or Easy-Invois into a client's environment, that client is responsible for how personal information is collected and used inside those systems. That processing is covered by the client's own privacy policy, unless we say otherwise. Our contract with the client may allow us to request details about authorised users for account and delivery management. In that case, this statement, or a product-specific notice, applies.

We may publish additional privacy information in a supplementary notice where a particular service, product or engagement needs it.

Information we collect and use

The information we collect depends on how you deal with us: reading the site, sending a form, joining an event, applying for a role, or working with us on a delivery. We collect what we need to respond, to run the site, and to deliver the work we have been asked to do.

This website

vkraftsoftware.com is how we describe our services, products and offices, and how you can contact us. Information collected on the site is used to make the pages available, keep them secure, and understand how the site is used. You do not need an account to browse. There is no public login for visitors.

We collect information about visits to the site, such as:

  • the pages you view and the time of the request
  • the referring URL, if your browser sends one
  • approximate location derived from IP address
  • links you follow on our pages

Your browser or device also sends technical details, such as IP address and browser type, operating system, device type and version, language settings, and any error or crash information generated by the hosting environment. We use those details to deliver pages correctly on your device, meet security and network requirements, diagnose faults, investigate misuse and keep the site available.

We do not run third-party advertising or analytics pixels on this site, and we do not use this information to build advertising audiences.

Pages may link to other organisations — for example a partner, a map, or a social profile. Their content and privacy practices are their own. This statement does not cover those sites.

Enquiry and demo forms

Forms on this site collect the details you type in. Depending on the form, that can include:

  • Name, work email, organisation, phone number and role
  • Service, industry or product of interest, including finX, Health360, DwaniAI, MetricMonitor and Easy-Invois
  • How you heard about us, partnership type, or Open Finance / PayNet role
  • A free-text message, and whether you agree to this policy

Those fields appear on the contact form, product and industry lead forms, the partnerships form, and the Open Finance connect form. We use them to reply, book a call, send a proposal or demo, and keep a record of the request. Forms include a Cloudflare Turnstile check so we can tell a person from automated spam.

Products and client platforms

finX, Health360, DwaniAI, MetricMonitor and Easy-Invois are built for client organisations. Personal data that end users or customers put into those systems — consent records in an Open Finance programme, clinic workflow data, conversation transcripts, operational metrics, or invoice records — is processed under the client's instructions and under that client's own notices. VKraft does not use that production data to market this website.

If you ask for a product demo or an Open Finance conversation from these pages, that request is treated as enquiry data under this statement, not as data inside the product itself.

Sensitive personal data

Some client systems we build or operate hold sensitive categories of personal data — health and clinical information in a Health360 deployment, or financial account information in an Open Finance programme. Where that happens we act on the client's instructions as their service provider, and the client is responsible for obtaining any explicit consent the law requires. We do not collect sensitive personal data through this website, and you should not include it in a form message or an enquiry email.

Marketing and events

We may use business contact details to tell you about a relevant service, product or event. We do this where you have asked us to, or on the basis of our legitimate interest in business-to-business marketing to people in a relevant professional role. Where the law requires your prior consent, we ask for it first. We do not buy advertising audiences or run retargeting pixels on this site. You can stop marketing messages at any time by using the unsubscribe link in an email, or by writing to contact@vkraftsoftware.com.

Client engagements

When we quote, contract or deliver work — API management, application and partner integration, IBM hybrid iPaaS, open source, Gen AI, AI agents, low-code, data and analytics, hyper automation, or migrations — we collect the business contact and project information needed to staff the work, reach named stakeholders, and meet the contract. That can include names, roles, work emails, meeting notes and technical context you choose to share.

Support and security

If you raise a support or security issue we keep the ticket content, related logs and contact details for as long as we need them to resolve the issue and to protect the site and our clients. Turnstile tokens are used only to validate the submission, not as a marketing identifier.

Offices and visits

If you visit or call an office we may record your name, organisation, contact details and the reason for the visit so we can host you and keep the premises secure. Our locations are listed on the contact page: Kuala Lumpur (headquarters) and Kuantan in Malaysia; Singapore; Hyderabad and Nashik in India; Watford in the United Kingdom; and Jacksonville in the United States.

Careers

Applications sent through the careers page or to contact@vkraftsoftware.com are used to assess suitability, arrange interviews and keep a record of the process. We do not ask applicants to create an account on this website.

Children

This website, our services and our products are intended for business users. They are not directed at children. We do not knowingly collect personal information from children. If you believe we have, please write to contact@vkraftsoftware.com and we will delete it.

Cookies and similar technologies

This public website uses only what is needed to operate it: hosting and security logs, and Cloudflare Turnstile on pages that carry a form. Turnstile may place a short-lived token or cookie in your browser to confirm the submission came from a person; it is not used to profile you or to track you across sites.

We do not set optional advertising or analytics cookies on these pages, which is why you will not see a cookie-preference bar. Signed-in VKraft staff use session cookies on internal tools that are not part of this public website.

Automated decisions

We do not make decisions about you by automated means alone that produce legal effects or a similarly significant effect. Where we use AI tools internally — for example to summarise an enquiry or draft a reply — a person reviews the output before we act on it or send it to you.

Sharing

We do not sell personal information. We share it only where we need to run the site, answer you, deliver contracted work, or meet a legal duty. That can include:

  • Hosting and infrastructure providers that serve vkraftsoftware.com
  • Form processors such as Formspark, which receive submissions from selected lead and Open Finance forms
  • Cloudflare, which provides the Turnstile check on those forms
  • Email and, where used, CRM tools that store business contacts so we can reply and manage the relationship
  • Professional advisors such as lawyers, auditors and insurers, on a need-to-know basis
  • VKraft colleagues in the offices listed above, so the right delivery or sales person can respond

Each supplier is bound by a written contract that limits them to processing the information on our instructions and requires them to keep it secure.

We may also disclose information if required by law, a court or a regulator, or to protect VKraft, our clients or other users — for example to investigate fraud or abuse of the site.

International transfers

Because we work from more than one country, authorised staff in Malaysia, India, Singapore, the United Kingdom or the United States may access enquiry or project contacts in order to handle them. Some of our suppliers also store or process data outside the country you are in.

Where personal data covered by the GDPR or UK GDPR leaves the European Economic Area or the United Kingdom, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision, together with additional technical and organisational safeguards where a transfer risk assessment calls for them. For transfers from Malaysia and Singapore we rely on the contractual protections required under the Malaysian PDPA and the Singapore PDPA. You can ask us for a copy of the relevant safeguards using the contact details below.

We limit access to people who need it, and we protect the information in transit and at rest.

Who is responsible

For personal information collected through this website and its forms, the controller is:

VKraft Software Services Sdn Bhd

L3-I-2, Hive 5, Taman Teknologi MRANTI

Lebuhraya Puchong Sg Besi, 57000 Kuala Lumpur, Malaysia

We have appointed a Data Protection Officer, who is responsible for how we handle personal information and for answering your questions about it.

Data Protection Officer

Write to us and mark your message for the Data Protection Officer
contact@vkraftsoftware.com

Privacy and security questions

Any request under this policy, or a security issue you have found
contact@vkraftsoftware.com

For personal data inside a client-hosted product or a system we operate on a client's instructions, the client is typically the controller. Their own policy, and the contract with VKraft, govern that processing. If you are an end user of a client system and you contact us, we will point you to that client unless we collected the data ourselves on this website.

Security and retention

We apply access control, encryption in transit, role-based restrictions on who can reach enquiry and project data, and operational practices reviewed against recognised information security standards. No method of transmission or storage is perfect; we work to reduce the risk of unauthorised access, loss or misuse.

We keep personal information only as long as we need it. What counts as long enough depends on the record:

  • Enquiry and demo records — until the enquiry is closed and any follow-up has run its course, unless it becomes a client engagement
  • Client engagement records — for the term of the contract, then for the period our accounting, tax and legal duties require
  • Career applications — for the recruitment process and a limited period afterwards, so we can consider you for a similar role, unless you ask us to delete them sooner
  • Support and security tickets — until the issue is resolved and no longer needed as a reference for related problems
  • Technical and security logs — for as long as they remain useful for security and operations, or longer where we are investigating an incident

At the end of those periods we delete the information or anonymise it so it can no longer identify you.

Data breaches

We keep procedures for detecting, investigating and responding to personal data breaches. If a breach happens and the law requires it, we notify the relevant regulator — including the Personal Data Protection Commissioner in Malaysia within the statutory deadline — and we tell affected individuals directly where the breach is likely to cause them significant harm.

Where we hold data as a service provider for a client, we notify that client without undue delay so they can meet their own reporting duties, on the timelines set in our contract with them.

If you think you have found a security problem affecting this website or our services, please write to contact@vkraftsoftware.com.

Your rights

Depending on where you are, you may have rights under the Malaysian Personal Data Protection Act, the Singapore PDPA, India's Digital Personal Data Protection Act, the GDPR or UK GDPR, or a United States state privacy law. Those rights can include:

  • Access to the personal information we hold about you
  • Correction of inaccurate or incomplete details
  • Deletion, where we no longer need the information or you withdraw consent
  • Restriction of, or objection to, certain processing, including direct marketing
  • A copy of your data in a portable format, where that right applies
  • Withdrawal of consent, without affecting earlier lawful use
  • Nomination of another person to exercise your rights, where Indian law provides it

Write to contact@vkraftsoftware.com. We will acknowledge your request and respond within the period the applicable law allows — 21 days under the Malaysian PDPA, 30 days under the Singapore PDPA, and one month under the GDPR and UK GDPR. If a request is complex we may extend that period and will tell you why. We do not charge a fee unless the law permits one. We may need to verify who you are before we act.

If we hold the data only as a service provider for a client, we will pass your request to that client where we cannot act on it ourselves.

You can also complain to the privacy regulator where you live or work:

Where you areRegulator
MalaysiaDepartment of Personal Data Protection (JPDP)
SingaporePersonal Data Protection Commission (PDPC)
IndiaData Protection Board of India
United KingdomInformation Commissioner's Office (ICO)
European Economic AreaYour national supervisory authority

Where a privacy law requires a legal basis, we rely on one or more of the following:

  • Steps prior to a contract, and performance of a contract — answering an enquiry, sending a proposal, delivering agreed work
  • Legitimate interests — running and securing this website, understanding which practice area you asked about, and business-to-business follow-up that you would reasonably expect. You can object to processing on this basis at any time
  • Consent — where a form asks you to agree to this policy, or where we send marketing that needs consent
  • Legal obligation — tax, accounting, and responding to lawful requests

Updates

We will change this statement when our practices or the law require it. The "Last updated" date at the top of the page will move when we publish a revision, and we will tell you directly if a change materially affects how we use information you have already given us. Continued use of the website after an update means the revised statement applies to later collection.

Prefer to speak to someone?

Our team can answer questions about this policy or a specific engagement.

Contact us