This Privacy Policy describes how personal data is collected, used, shared and protected in connection with VeyraDesk.
1. Who we are
VeyraDesk is provided by Erazem Sdn Bhd (“Erazem”, “we”, “us”, “our”), a company incorporated in Malaysia. This Privacy Policy explains how we handle personal data when you visit the VeyraDesk website, create or use a VeyraDesk workspace, or contact us.
We handle personal data in accordance with the Personal Data Protection Act 2010 of Malaysia (“PDPA”), as amended, including by the Personal Data Protection (Amendment) Act 2024, and its subsidiary legislation and guidelines.
2. Our role: controller and processor
Website, sales and account data. For information about visitors, prospects and the people who register and manage VeyraDesk accounts, Erazem decides how and why the data is processed and acts as the data controller.
Customer Content. Our customers use VeyraDesk to store information about their own customers, sites, devices, end users and support tickets (“Customer Content”). For Customer Content, our customer is the data controller and Erazem processes that data on the customer’s behalf and on its instructions, as a data processor. If you are an end user of one of our customers, please contact that organisation first about your personal data; we will assist them as required.
3. Information we collect
Account information
When you create a workspace or are added as a user: your name, email address, password (stored only as a one-way hash), role, organisation name, workspace identifier (“slug”), country and contact number.
Customer and support information
Information you or your team enter to provide support, such as customer names and codes, site names, ticket subjects, descriptions, replies, internal notes, priorities and assignments.
Device information
When the VeyraDesk Agent is installed on a computer: a device name, a technical device identifier, the Agent version, basic operating-system details, online/offline status and last-seen time, and the identifiers needed to establish remote sessions.
Remote session information
Records of remote sessions, such as who requested the session, the device, related ticket, the access mode used, and when the session was authorised, started, ended, cancelled or revoked. VeyraDesk does not record the screen contents of remote sessions.
Usage and log information
Audit records of activity in a workspace (for example sign-ins, failed sign-in attempts, session events, ticket changes and administrative actions), and technical information our servers receive, such as IP address, browser type and request timestamps.
Communications
Information you give us when you email or call us, or when you use the contact form, such as your name, company, email, phone number and message.
Payment and billing information
If you subscribe to a paid plan, we collect billing details such as the billing contact, company details and plan. Card or bank payment details are processed by our payment service provider and are not stored by VeyraDesk.
4. Cookies and similar technologies
The VeyraDesk website does not currently use analytics or advertising cookies. The VeyraDesk application stores sign-in tokens in your browser’s local storage so that you stay signed in. See our Cookie Policy for details.
5. How we use information
We use personal data to:
- provide, operate, secure and maintain VeyraDesk and your workspace;
- authenticate users, enforce roles and permissions, and authorise remote sessions;
- keep audit records and detect, investigate and prevent security incidents, fraud and misuse;
- respond to enquiries and provide customer support;
- manage subscriptions, billing and plan limits;
- send service-related messages, such as security or account notices;
- send marketing communications where permitted, with an option to opt out at any time;
- improve and develop VeyraDesk; and
- comply with legal obligations and enforce our terms.
We do not sell personal data.
6. How we share information
We share personal data only as needed to run VeyraDesk, including with:
- Service providers who help us host, operate, secure and support the service (for example cloud hosting, email and payment providers), under contracts that require them to protect the data;
- Integrations you enable, such as systems connected through the VeyraDesk API or webhooks by your workspace administrators;
- Professional advisers, such as lawyers, auditors and insurers, where necessary;
- Authorities, where required by law or to protect rights, safety and security; and
- A successor business in connection with a merger, acquisition or sale of assets, subject to this Policy.
7. International transfers
VeyraDesk may be hosted, or use service providers, outside Malaysia. Where personal data is transferred outside Malaysia, we take steps required under the PDPA to ensure it continues to be protected to a comparable standard, for example through contractual safeguards.
8. Data retention
We keep personal data only for as long as needed for the purposes described in this Policy. Account and Customer Content is kept while your workspace is active. After a workspace is closed, we delete or anonymise the data within a reasonable period, unless we need to keep some of it to meet legal, accounting or security obligations or to resolve disputes. Audit records may be retained for longer for security and compliance purposes.
9. Data security
We use technical and organisational measures designed to protect personal data, including access controls and role-based permissions, workspace separation, password hashing, encryption of sensitive values at rest, and audit logging. More detail is on our Security page.
No method of transmission or storage is completely secure. If a personal data breach occurs, we will notify affected customers, and where required the Personal Data Protection Commissioner and affected individuals, in accordance with the PDPA.
10. Your rights
Subject to the PDPA, you may have the right to:
- request access to the personal data we hold about you;
- request correction of personal data that is inaccurate, incomplete, misleading or out of date;
- withdraw your consent to our processing of your personal data;
- ask us to stop processing that is likely to cause substantial damage or distress;
- ask us to stop processing your personal data for direct marketing; and
- request that your personal data be transmitted to another data controller (data portability), where applicable.
Withdrawing consent or limiting processing may mean we cannot continue to provide some or all of the service to you.
11. Making a data request
To make a request, email sales@erazemsdnbhd.com with the subject “Personal data request”. We may need to verify your identity before acting on it. We will respond within the time required by the PDPA. A fee may apply to some access requests where permitted by law.
If your request concerns Customer Content held by one of our customers, we will refer it to, or assist, that customer as the data controller.
12. Account termination
Workspace owners can ask us to close their workspace at any time. Before closure, you are responsible for exporting any data you want to keep. After closure, data is handled as described in “Data retention” above.
13. Children’s privacy
VeyraDesk is a business service and is not intended for children. We do not knowingly collect personal data directly from anyone under 18. If you believe a child has provided us with personal data, contact us and we will take appropriate steps.
14. Changes to this Policy
We may update this Policy from time to time. We will post the updated version on this page with a new effective date and, where the changes are significant, notify account owners by email or in the service.
15. Contact us
For questions about this Policy or your personal data, contact:
Erazem Sdn Bhd
Email: sales@erazemsdnbhd.com
Phone: +60 19-307 3152