Trust & Security
This Trust & Security statement describes the measures implemented by Synorex Sdn. Bhd. (“Synorex”, “we”, “us”, or “our”) to protect customer data, system integrity, and service reliability. This document complements our Terms of Service and Privacy Policy.
1. Where Data Is Hosted
Customer data is hosted on secured infrastructure selected by Synorex based on the applicable product and customer location. For customers based in Malaysia, data is hosted on servers located in Malaysia, including infrastructure owned and managed by Synorex. For international customers or cross-border deployments, data may be hosted on reputable third-party cloud providers such as Amazon Web Services (AWS) or equivalent platforms.
Data hosting location may vary depending on service requirements, regulatory considerations, redundancy, and performance needs.
2. Encryption (In-Transit / At Rest)
Data transmitted between users and Synorex systems is protected using industry-standard encryption protocols where applicable. Sensitive data stored within the system may be encrypted at rest based on technical feasibility and security requirements.
3. Backups & Disaster Recovery
Regular data backups are performed by Synorex to support system recovery and business continuity. Backup schedules, retention periods, and restoration procedures are designed to reduce the risk of data loss but do not guarantee zero data loss in all circumstances.
Backup and restoration processes are managed by Synorex. Restoration resulting from system faults, infrastructure failures, or technical issues attributable to Synorex will be performed at no additional cost. Restoration requests arising from user error, accidental deletion, misconfiguration, or customer-initiated actions may be subject to additional fees and service charges.
4. Access Control & Staff Permissions
Access to customer data and systems is restricted to authorized personnel only. Internal access is granted based on role, job function, and operational necessity, and is subject to internal policies and monitoring.
5. Network & Server Security
Synorex employs technical safeguards such as firewalls, access restrictions, monitoring, and security configurations to protect systems against unauthorized access, misuse, or attacks.
6. Vulnerability Management & Updates
Systems are maintained through periodic updates, patches, and improvements. Vulnerability assessments and remediation activities are conducted based on risk, priority, and available resources.
7. Third-Party Vendors Used
Synorex may engage trusted third-party vendors for infrastructure, hosting, analytics, payment processing, or support services. Such vendors are selected based on reliability and are required to comply with reasonable data protection and security obligations.
8. Incident Reporting & Breach Response
In the event of a confirmed security incident or data breach affecting customer data, Synorex will take reasonable steps to investigate, mitigate impact, and notify affected customers where required by applicable law.
9. Customer Data Isolation
Customer data is logically isolated within the system to prevent unauthorized access between different customers or tenants. Isolation mechanisms depend on system architecture and service configuration.
10. Compliance Statement
Synorex is committed to handling data responsibly and in accordance with applicable data protection laws, including the Personal Data Protection Act (PDPA) where relevant. References to other regulations such as GDPR are provided for general transparency and do not constitute a certification or guarantee of full regulatory compliance unless expressly stated.
11. Contact Information
For trust, security, or data protection inquiries, please contact: hi@synorex.group
Version History
Download the current approved file or retrieve an older archived version for reference.