Data Controller and Compliance Statement
Benamici Studio (Company, We, Us, Our) respects your privacy and is dedicated to protecting your personal data.
This Privacy Policy explains how we collect, use, disclose, store and safeguard your personal information in compliance with the Personal Data Protection Act 2010 (PDPA) of Malaysia.
Unless explicitly designated as a Data Processor on behalf of enterprise clients (section 07), Benamici Studio acts as the Data User and Data Controller for the information processed through our operations.
Registered entity
Benamici Studio
SSM registration
201603214684 (SA0390314-H)
MOF registration
357-0002432839
Registered premises
Level 1, TD1303, Jalan Sultan Zainal Abidin, 20000 Kuala Terengganu, Terengganu, Malaysia
Scope of Application
This policy applies to all personal data collected across the following touchpoints:
Digital platforms
benamici.com, quotation request forms, direct enquiry channels and the technical support ticketing system.
Proprietary SaaS (Skooldash)
Cloud school management web application, admin portals and the official mobile apps for iOS and Android.
Software products (Smartify Series)
Licence activation, telemetry validation and update management for Smart Review, Smart Reward, Smart Security, Smart Korban and future plugin releases.
Professional and enterprise services
Custom web and mobile apps, SaaS and ERP engineering, ArcGIS Enterprise integrations, managed cloud hosting and IT consultation.
Commercial transactions
Invoicing, transaction processing and client onboarding.
Exclusion. This policy does not apply to third party websites linked from our pages, nor to client operated application environments after final deployment and administrative handover.
Personal Data We Collect
A. Information provided directly by you
- Identity and contact details. Full name, business email address, direct phone number, designation, and company or institution name.
- Billing and transaction data. Tax registration details, invoicing address, bank account names and transaction references.
- Service credentials. Temporary administrative access keys, server credentials or staging API tokens provided for technical support or maintenance.
- Enquiries and deliverable content. Messages, scope briefs, attachments or screenshots submitted via contact forms, WhatsApp or support tickets.
B. Information collected automatically
- Technical logs. IP address, device type, browser identification, operating system and system performance logs.
- Usage and analytics. Web page views, navigation paths, click rates and interaction duration collected via privacy compliant analytics tools.
- Security telemetry. Automated tracking of failed login attempts, unauthorised API calls or security threats logged by our infrastructure security tools, such as the Smart Security engine.
C. Software and licence verification data
- For Smartify Series plugins and Skooldash enterprise licences we record the target site URL, licence activation key, domain IP and plugin version numbers, to ensure valid licensing and deliver automated updates.
Purpose of Data Processing
We collect and process personal data exclusively for legitimate business and operational purposes:
Service fulfilment
To provision SaaS accounts (Skooldash), deliver custom development deliverables, activate plugin licences and process orders.
Technical support and operations
To diagnose software bugs, perform server maintenance, manage cloud infrastructure and respond to enquiry tickets.
Billing and financial auditing
To process invoices, record payments, prevent fraudulent transactions and meet statutory tax audit requirements under Malaysian law.
Platform security
To defend against cyber threats, mitigate unauthorised plugin distribution and ensure multi tenant cloud data isolation.
Client communications
To send transactional updates, critical security advisories, system maintenance notices and invoicing statements.
Payment Security and Processing
Benamici Studio does not store or process sensitive credit card numbers or banking passwords directly on our servers.
- Online payment transactions are handled via trusted, PCI DSS compliant third party payment gateways, covering FPX, DuitNow, major card networks and direct debit partners.
- We only retain masked transaction references, payment dates, amounts and transaction status codes required for accounting and receipt issuance.
- All prices and payments are denominated in Malaysian Ringgit (MYR) unless a formal quotation states otherwise.
Cookies and Analytical Technologies
We use cookies and similar session tracking technologies to improve user experience on benamici.com:
Essential cookies
Necessary for core website functionality, security authentication and session persistence.
Analytics cookies
Used to monitor aggregated website traffic patterns and improve portal layout performance.
Users may configure browser settings to disable non essential cookies at any time.
Benamici as a Data Processor
For enterprise engagements, custom ERP and SaaS builds, and cloud environments such as Skooldash:
- Data ownership. Our clients (schools, corporate entities, institutions) remain the sole data owners and controllers of the student, employee or customer data hosted within their application database.
- Data processing role. Benamici Studio acts strictly as a data processor, maintaining server infrastructure, database performance and technical safeguards under the client's explicit authorisation.
- No unauthorised usage. We never rent, harvest, analyse, sell or utilise client hosted database records for our own commercial purposes.
Data Sharing and Third Party Disclosure
We do not sell, rent or trade your personal data to third parties. Data is shared strictly on a need to know basis with:
Vetted infrastructure partners
Enterprise cloud providers such as AWS, Hostinger VPS and ArcGIS infrastructure, payment gateways, and transactional email distribution services required to run our applications.
Regulatory and legal authorities
Law enforcement agencies, statutory bodies or tax authorities when mandated by legal warrants, court orders or applicable Malaysian legislation.
Professional services
External auditors, legal advisers or financial consultants under strict non-disclosure agreements.
Data Storage and Cross Border Transfer
Primary data storage environments and cloud databases operated by Benamici Studio are hosted in secure datacentre infrastructure located within Malaysia or established regional zones such as Singapore.
Where cross border data transfer is required for cloud backup redundancy or third party service integration, we ensure the service provider maintains data security protocols equivalent to or exceeding the standards prescribed under the Malaysian PDPA.
Data Retention Policy
Active accounts
Personal data associated with active user accounts, SaaS subscriptions or maintenance contracts is retained for the duration of the active service relationship.
Financial and accounting records
Billing invoices, quotation records and transaction logs are retained for seven (7) years in compliance with Malaysian statutory tax requirements.
Support and diagnostic logs
Temporary staging access credentials, server debugging logs and transient support attachments are permanently deleted once technical resolution is verified.
Security Safeguards
Benamici Studio implements robust physical, administrative and technical security measures to safeguard your personal data:
- Encryption. Standard SSL and TLS encryption for all web data transmissions, and database storage encryption where appropriate.
- Access control. Role based administrative access controls, multi factor authentication (MFA) and secure SSH key infrastructure.
- System hardening. Automated vulnerability scanning, application level firewall protections and regular software patching routines.
Your Data Protection Rights (PDPA)
Under the Malaysian Personal Data Protection Act 2010, you hold the following rights regarding your personal information:
Right of access
Request confirmation and a copy of the personal data we hold about you.
Right to correction
Request the correction of inaccurate, incomplete or outdated personal data.
Withdrawal of consent
Withdraw your consent for non essential processing, such as marketing communications, at any time.
Data erasure
Request the deletion of your personal account data, subject to statutory record retention obligations.
To exercise any of these rights, please submit a formal written request to our data enquiries team at support@benamici.com.
Children and Student Data (Skooldash Operations)
- Data processing within our Skooldash platform involves student information provided directly by participating schools or educational institutions.
- Educational institutions using Skooldash warrant that they have obtained the necessary parental or guardian consents to process student details for school administration purposes.
- We handle all educational records with heightened confidentiality and strict access isolation between institutional tenants.
Updates to This Policy
Benamici Studio reserves the right to revise or update this Privacy Policy periodically to reflect changes in legal requirements, corporate practices or system features. The last updated timestamp at the top of this document indicates the effective date of the latest revisions.
Contact Us and Data Protection Enquiries
If you have questions, feedback or formal data protection requests regarding this policy, please contact us at:
Data controller entity
Benamici Studio
201603214684 (SA0390314-H)
Registered address
Level 1, TD1303, Jalan Sultan Zainal Abidin, 20000 Kuala Terengganu, Terengganu, Malaysia
Official portal
https://benamici.com