Privacy Policy
Last updated: 23 September 2026.
Identity and Role of the Data Controller
codezenly operates this commercial website focused on Course Programming and acts as the data controller under the Personal Data Protection Act 2010 of Malaysia. We determine the purposes and means of processing personal data collected through the site, including course enrolment, blog interactions, and contact forms.
Scope of the Notice and the People It Covers
This notice applies to all visitors, prospective students, enrolled learners, and blog readers located in Malaysia or accessing our services from within the country. It covers personal data processed when you browse courses, submit enquiries, or engage with our content, but does not extend to third-party websites linked from our platform.
Categories of Personal Data and Sources
We collect identification details such as name and email address via forms, usage data including IP addresses and browsing behaviour from cookies, and educational information like course preferences when you register. Data is obtained directly from you through interactions, from analytics tools, and occasionally from publicly available professional profiles when relevant to course recommendations.
Purpose-by-Purpose Explanation of Processing and Legal Basis
Personal data is processed to deliver Course Programming services under contract necessity, to respond to enquiries with your consent, to improve site functionality based on legitimate interests, to send marketing updates where consent is obtained, and to comply with Malaysian legal obligations such as record-keeping under PDPA. Each purpose is documented with its corresponding lawful basis to ensure transparency.
Whether Providing Data Is Required and Consequences
Supplying certain data such as contact details is necessary to enrol in courses or receive responses; failure to provide it may prevent access to services or result in incomplete processing of your requests. Optional data like preferences enhances personalisation but does not affect core functionality if withheld.
Cookies and Similar Technologies
We use cookies for session management, analytics, and personalisation. Details on types, durations, and management options are provided in our separate Cookie Policy, which you can access via the site-wide cookie banner or footer links. You may adjust browser settings to limit cookies, though this could affect site performance.
Processors, Service-Provider Categories, Recipients, and Disclosures Required by Law
Categories of processors include hosting providers, email delivery services, payment gateways for course fees, and analytics platforms. We may disclose data to regulatory authorities when legally compelled under Malaysian law or to protect our rights in cases of suspected fraud.
International Transfers and Safeguards
Some processors may be located outside Malaysia. Transfers occur only with appropriate safeguards such as contractual clauses ensuring equivalent protection levels consistent with PDPA requirements, and we assess recipient jurisdictions for adequacy before any transfer.
Specific Retention Periods or Criteria
Enrolment data is retained for seven years after course completion to meet accounting and legal obligations. Marketing consent records are kept until withdrawal. Usage logs are deleted after twenty-four months unless required for dispute resolution. Criteria include statutory limitation periods and ongoing service improvement needs.
Security and Data-Minimisation Practices
We implement technical measures including encryption for data in transit, access controls, and regular audits. Data collection is limited to what is necessary for stated purposes, with periodic reviews to delete unnecessary information and reduce exposure risks.
All Applicable Data-Subject Rights and Exercising Them
Under PDPA you may request access, correction, or deletion of your personal data, and object to processing. Submit requests via the Contacts page form or by writing to [email protected]. We respond within the timelines prescribed by Malaysian regulations and may require identity verification.
Right to Withdraw Consent and Object to Direct Marketing or Profiling
You can withdraw consent at any time by using unsubscribe links in emails or contacting us at [email protected]. Objections to direct marketing or automated profiling for course suggestions are honoured promptly without affecting other services.
Right to Complain to the Competent Supervisory Authority
If unsatisfied with our response, you may lodge a complaint with the Personal Data Protection Commissioner of Malaysia at the Department of Personal Data Protection. Contact details are available on the official government website.
Children or Age Restrictions
Our Course Programming content targets individuals aged eighteen and above. We do not knowingly collect data from minors; if such data is identified it will be deleted promptly upon notification to [email protected].
Automated Decision-Making and Profiling
Limited profiling may occur to recommend courses based on past enrolments and interests, but no solely automated decisions with legal effects are made. You can request human review of any recommendation by contacting us.
Policy Changes and Effective Date
We review this policy periodically and update it to reflect legal or operational changes. The current version is effective from 23 September 2026. Continued use of the site after updates constitutes acceptance of the revised terms. For questions contact [email protected] or use the form on our Contacts page.
