1. Introduction
This Personal Data Protection Notice ("Notice") is issued by PsyMetric Sdn. Bhd. [Registration No. 202101030158 (1430458-M)] pursuant to section 7 of the Personal Data Protection Act 2010 (Act 709), as amended by the Personal Data Protection (Amendment) Act 2024, and the subsidiary regulations and guidelines issued under it (together, the "PDPA").
It explains what personal data we collect through the PsyMetric platform at www.psymetric.com.my, why we collect it, who we share it with, how long we keep it, and what rights you have. It applies to Individual Users, to representatives and staff of Corporate Users, and to visitors to the Website.
Our users are Indonesian Migrant Workers (PMI) in Malaysia who fall within the pendataan exercise established by Keputusan Direktur Jenderal Penempatan KP2MI/BP2MI No. 423 Tahun 2026 (KEP.423/01/HK.02.02/III/2026), ditetapkan 9 Maret 2026. We therefore also apply, where applicable to the relevant processing or activity, the requirements of Indonesian law, including Undang-Undang No. 18 Tahun 2017 as last amended by Undang-Undang No. 6 Tahun 2023, Peraturan Pemerintah No. 59 Tahun 2021, Peraturan Menteri KP2MI/BP2MI No. 27 Tahun 2025, and Undang-Undang No. 27 Tahun 2022 on Personal Data Protection.
This Notice is issued in English. A Bahasa Malaysia version is issued alongside this Notice and has equal effect. Where the two versions differ, the English version prevails to the extent permitted by law, save where the applicable law requires otherwise.
PsyMetric is the data controller (data user) in respect of the personal data described in this Notice.
Where applicable, PsyMetric has appointed a Data Protection Officer in accordance with section 12A of the PDPA and the applicable requirements and guidance issued by the Personal Data Protection Commissioner. The contact details of the Data Protection Officer are set out above.
Where a Corporate User registers and pays for an Employee, that Corporate User is a separate data controller in respect of personal data which it collects, holds or otherwise processes for its own purposes. The Corporate User is responsible for ensuring that it has an appropriate legal basis and has complied with its own obligations under applicable data protection laws before providing Employee data to PsyMetric.
PsyMetric separately determines the purposes and means by which it processes personal data on the Platform, including for the administration and delivery of Assessments, professional review, Certificate issuance and validation, security, support and compliance with applicable legal and regulatory requirements. PsyMetric and a Corporate User are not treated as joint data controllers merely because the Corporate User provides Employee data to PsyMetric or pays for an Assessment.
Identity data — full name, date of birth, gender, nationality, national identity number and/or passport number, and photograph where required for the Certificate.
Contact data — email address, mobile telephone number, and address in the country of employment and/or in Indonesia.
Employment and placement data — country and place of employment, employer, occupation, and the batch under which your Assessment was assigned.
Account data — username, hashed password, account type (Perorangan or Perusahaan), language preference and account status.
Transaction data — Assessments purchased and assigned, invoice records, payment status, SST applied, and refund history. We do not collect or store full card numbers or bank credentials.
Technical data — IP address, device and browser type, operating system, access times, pages viewed, and Audit Trail entries recording actions taken on the Platform.
Correspondence data — support requests, complaints and related correspondence.
Session and security data — login sessions, devices associated with your account, authentication events, security events and other information necessary to maintain the security and integrity of the Platform.
The core of the Service involves sensitive personal data as defined in section 4 of the PDPA, namely information as to your physical or mental health or condition. This includes:
your responses to questionnaire items and sub-tests;
scores, scale outputs and screening classifications derived from those responses;
the professional review, clinical opinion and any notes recorded by a Practitioner;
the outcome recorded on your Certificate and any comparison against a previous Assessment where such comparison is made.
Under section 40 of the PDPA, sensitive personal data may only be processed with your explicit consent, or where another statutory ground applies. We rely principally on your explicit consent for the processing of your sensitive personal data for the Assessment and its review by Practitioners.
We obtain and record your explicit consent before the Assessment begins. Where your registration or account creation involves the collection of ordinary personal data, we may also obtain the applicable consent or rely on another lawful basis for that processing, as described in Section 5.
Your explicit consent is documented and maintained in our records. You may withdraw your consent at any time by contacting our Data Protection Officer. Withdrawal of consent does not affect processing already carried out lawfully before withdrawal, but may mean that we cannot deliver the Service, complete an Assessment or validate a Certificate.
Where a Practitioner processes sensitive personal data for medical purposes within the scope of section 40 of the PDPA, that Practitioner may also rely on the applicable statutory ground for processing by a healthcare professional or a person owing an equivalent duty of confidentiality.
directly from you when you register or activate your account, update your profile, purchase an Assessment, complete a questionnaire, or contact us;
from a Corporate User that funds your Assessment and uploads your details as part of a batch, subject to the Corporate User’s responsibility to obtain any consent or other lawful basis required before providing the data to us;
from the Practitioner who reviews your Assessment;
automatically through cookies, server logs and the Audit Trail when you use the Website;
from our payment service provider in respect of the status of a transaction;
from other service providers or professional advisers where necessary to provide, secure or administer the Service; and
from competent authorities or other lawful sources where disclosure or collection is permitted or required by applicable law.
We do not use your sensitive personal data for advertising. We do not sell your personal data. We do not make decisions producing legal or similarly significant effects on you solely by automated means. Assessment results are subject to human review by Practitioners.
We disclose personal data only as described below, and only to the extent necessary:
Where a service provider processes personal data on our behalf, we require appropriate contractual, confidentiality and security obligations consistent with the PDPA and applicable requirements.
We do not disclose personal data to third parties for their independent advertising or direct marketing purposes without the applicable consent.
Because you are working abroad and your data may need to reach recipients in Indonesia or in your country of employment, your personal data may be transferred outside Malaysia.
We may transfer personal data outside Malaysia where the transfer is permitted under section 129 of the PDPA and applicable guidance issued by the Personal Data Protection Commissioner. Depending on the circumstances, this may include a transfer to a destination that provides an adequate level of protection, a transfer supported by an applicable statutory exception, or a transfer made with your consent where consent is an appropriate basis.
Before making a cross-border transfer, we consider the nature of the data, the purpose of the transfer, the destination and recipient, and the safeguards available for the data. Where required, we conduct an appropriate transfer assessment and implement contractual, technical or organisational safeguards.
Where consent is relied upon as the basis for a cross-border transfer, we will provide appropriate information about the transfer and its purpose so that the consent is informed and specific to the relevant processing.
In every case, we take reasonable steps to ensure that only the minimum personal data necessary is transferred and that appropriate security and confidentiality measures are applied.
In accordance with the Security Principle we apply measures proportionate to the sensitivity of health data, including:
encryption of data in transit and at rest;
role-based access control, so that BackOffice staff see only the data their role requires and item-level clinical data is restricted to Mental Health Practitioners, who authenticate with a second factor (one-time password) in addition to their password;
individual named accounts, enforced password rules and session controls — shared logins are prohibited;
a comprehensive Audit Trail recording administrative access and changes, which is reviewed periodically;
contractual confidentiality obligations on all staff, practitioners and processors;
regular backup, tested restoration procedures and secure disposal of media;
periodic review of security controls and of processor compliance;
procedures for identifying, assessing, containing and responding to suspected personal data breaches; and
measures designed to ensure that access to sensitive personal data is limited to authorised persons with a legitimate need to access it.
If we have reason to believe that a personal data breach has occurred which triggers a notification obligation under the PDPA or applicable breach-notification requirements, we will assess the breach and take the required steps to contain, investigate and remediate it.
Where notification to the Personal Data Protection Commissioner is required, we will notify the Commissioner within the applicable statutory timeframe. Where notification to affected individuals is required, we will notify them within the applicable statutory timeframe and in the manner prescribed by the applicable requirements.
Our notification will, where required, describe the nature of the breach, the likely consequences, the measures taken or proposed to address the breach and the steps that affected individuals may take to protect themselves.
We maintain appropriate records of personal data breaches and related remedial action in accordance with applicable requirements.
When a retention period ends, data is securely deleted or irreversibly anonymised.
Where data has been irreversibly anonymised so that an individual can no longer be identified and re-identification is not reasonably possible, the resulting anonymised information may be retained for statistical, analytical or Assessment-instrument validation purposes.
Subject to the exceptions in the PDPA, you have the following rights:
Send a written request to our Data Protection Officer at [email protected], or by post to our business address, stating the right you wish to exercise, your full name, the email address registered on your account, and enough information for us to identify your records.
We may ask for proof of identity before acting, in order to protect your data.
We will respond to a valid request within the applicable period prescribed by the PDPA. Where the law permits an extension because of the nature or complexity of the request, we will inform you of the extension and the reason for it.
A prescribed fee may apply to a data access request; where applicable, we will inform you of the fee before processing the request.
Access to sensitive personal data of a clinical nature may be provided with appropriate professional context, and in limited circumstances may be restricted where permitted by applicable law, including where release would be likely to cause serious harm to your physical or mental health, or would disclose information about another person. Where we restrict access we will explain why to the extent permitted by law and, where possible, offer an alternative such as a supervised explanation by a Practitioner.
The Platform uses strictly necessary, preference and analytics cookies.
Strictly necessary cookies support authentication, session management, Assessment progress, security and other essential Platform functions. Preference cookies may remember settings such as language, while analytics cookies help us understand aggregate usage and improve the Platform.
Full detail, including the cookies used, their purposes, durations and how to manage them, is set out in the PsyMetric Cookies Policy.
Where the cookie or similar technology involves the processing of personal data, such processing is subject to this Notice and the applicable requirements of the PDPA.
If your employer arranged your Assessment, the login details for your account may have been issued to your employer so that they can be passed to you. Change your password as soon as you first log in. Your employer is told only the information permitted under the Terms and Conditions, including the outcome of an employer-funded Assessment. Your answers and clinical notes are not disclosed to the Corporate User. If you believe someone else has used your account, contact us at [email protected].
Providing identity, contact and Assessment data is necessary in order for us to deliver the Service. If you do not provide it, or you withdraw consent, we will not be able to register your account, conduct an Assessment, or issue a Certificate. Providing marketing consent and optional profile information is voluntary and does not affect the Service.
The Service is intended for adults aged eighteen (18) and above. We do not knowingly collect personal data from children.
If we become aware that personal data relating to a person below the applicable age has been collected in circumstances where collection was not permitted, we will take reasonable steps to delete or otherwise appropriately handle that data in accordance with applicable law.
If you are concerned about how we handle your personal data, please contact our Data Protection Officer first at [email protected].
We will acknowledge your complaint within three (3) working days and will provide a substantive response within fourteen (14) working days, consistent with our general complaint handling process set out in Clause 16.1 of the Terms and Conditions.
Where additional time is reasonably required to investigate a complex complaint, we will inform you of the delay and provide an estimated timeframe for resolution.
You also have the right to complain to the Personal Data Protection Commissioner (Jabatan Perlindungan Data Peribadi, Malaysia).
Where the matter concerns your rights as a PMI or pendataan process, you may additionally raise the matter with the relevant Indonesian authority or Indonesian representative office, where applicable. Complaints about the professional conduct of a Practitioner may be raised with the Malaysian Medical Council.
We may update this Notice to reflect changes in the Platform, our practices, or the law.
The current version and its effective date are published on the Website.
Where a change materially affects how we process your personal data, we will provide you an appropriate notice before the change takes effect where reasonably practicable. Where the law requires fresh consent for the changed processing, we will obtain that consent before commencing the relevant processing.
Items shown in square brackets are placeholders to be confirmed by PsyMetric before publication. The appointment and registration of a Data Protection Officer is mandatory under section 12A of the PDPA and must be notified to the Commissioner.