MboxCloud
English ▼
English
Bahasa Melayu
中文
Go to Drive

PDPA Notice

Compliance with Personal Data Protection Act 2010 (Malaysia) & 2024 Amendments

1. The 7 PDPA Principles

Mbox Cloud strictly adheres to the seven Personal Data Protection Principles as set out in the PDPA 2010:

General Principle
We process your data only with your explicit consent.
Notice and Choice
We clearly inform you of what data we collect and why.
Disclosure Principle
We never share data with unauthorized third parties.
Security Principle
We use robust encryption to prevent data misuse.
Retention Principle
We do not keep your data longer than necessary.
Data Integrity
We ensure your data is accurate and up-to-date.
Access Principle
You have the right to view and correct your data.

2. Information We Collect

To provide our comprehensive cloud storage and affiliate services, we may collect the following categories of personal data:

  • ●
    Identity DataFull Name, Username, Date of Birth.
  • ●
    Contact DataEmail Address, Mobile Phone Number.
  • ●
    Financial DataBank Account Number, Payment Details (for commission payouts & subscriptions).
  • ●
    Technical DataIP Address, Browser User Agent, Time Zone, Login Data.
  • ●
    Usage DataCookies, Session Logs, Storage Usage Patterns.

3. Purpose of Collection

Your personal data is strictly used to facilitate the delivery of our services:

  • ➤
    Service FunctionalityTo enable file uploading, storage, retrieval, and sharing features.
  • ➤
    Transaction ProcessingTo process subscription payments and distribute affiliate cash rewards.
  • ➤
    Security & VerificationTo verify identity, prevent fraud, and secure your account access.
  • ➤
    Legal ComplianceTo comply with MCMC regulations, LHDN (Tax) requirements, and court orders.

4. Disclosure & Third Parties

We strictly do not sell or trade your personal data.

However, we may share minimal data with trusted third-party providers solely for operational purposes (e.g., Payment Gateways like ToyyibPay/Stripe, Analytics). We may also display ads from third-party networks (e.g., PropellerAds), which may collect non-personal data (Cookies/IPs) to serve relevant ads. We are not responsible for their independent privacy policies.

5. International Data Transfer & Storage

Your data may be stored outside of Malaysia.

To provide a robust, high-speed, and redundant cloud storage service, Mbox Cloud utilizes a distributed global infrastructure. By using our services, you acknowledge and consent that your personal data and stored files may be transferred to, stored, and processed on secure servers located outside of Malaysia. We utilize distributed global infrastructure to ensure your data is always accessible. While the physical servers may be managed by top-tier international storage providers, all data is strictly encrypted and Mbox Cloud retains full control over access rights. All international data transfers are conducted with partners who comply with stringent data protection standards equivalent to or higher than the Malaysia PDPA 2010.

6. Data Retention Period

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by law.

  • ●
    User FilesUpon account deletion, user files are retained for a 30-day buffer period to prevent accidental deletion, after which they are permanently securely erased.
  • ●
    Financial RecordsTransaction records and invoices are retained for 7 years to comply with LHDN (Inland Revenue Board of Malaysia) tax regulations.

7. Security & Data Breach Notification

We employ industry-standard security measures to safeguard your data. All stored files are protected using AES-256 industrial-grade encryption at rest. Your data is fragmented and stored across multiple secure nodes to prevent unauthorized access. In the unlikely event of a data breach that may cause significant harm, we will notify the Personal Data Protection Commissioner (PDPC) within 72 hours and inform affected users immediately, as required by the PDPA amendments.

8. Your Rights & Withdrawal of Consent

Under the PDPA, you have the right to access, correct, and limit the processing of your personal data. You may withdraw your consent for data processing at any time by contacting us, though this may result in the inability to continue providing our services to you.

9. Cookie Policy

Mbox Cloud uses cookies primarily to facilitate your secure cloud session, ensuring you remain logged in while navigating folders or uploading files. We also use analytics cookies to improve system performance. By continuing to use our service, you consent to our use of these essential cookies.

Data Protection Officer (DPO) Contact

For any inquiries, access requests, or complaints regarding your personal data, please contact:

privacy@mbox.cloud
MboxCloud

Malaysia's first SaaS cloud storage provider with a Permanent Cash Rewards program. Optimized for bit-perfect integrity, local data sovereignty, and PDPA compliance.

Follow Us:

Legal

  • Privacy Policy
  • Terms of Service
  • PDPA Notice
  • Cookie Policy
  • Report abuse

Support

  • Help Center
  • Contact Us
  • System Status

© 2026 Mbox Cloud Storage Enterprise. All rights reserved.