1. Introduction and Scope
This comprehensive website Privacy Policy (“Privacy Policy”) governs the data processing practices of Sparvia Systems Sdn Bhd (“Sparvia Systems”, “we”, “us”, or “our”) with respect to the website located at https://www.sparvia.com.my and any associated subdomains, digital forms, and digital touchpoints owned or operated by Sparvia Systems.
As an organization that is ISO 27001 Certified and SOC 2 Type II Audited, we enforce stringent informational integrity, availability, and confidentiality rules across our environment. We respect your digital privacy rights and are fully committed to protecting your personal data transparently. This document serves to formally inform website visitors, enterprise prospects, stakeholders, and subscribers exactly how their Personally Identifiable Information (PII) is captured, managed, processed, stored, and protected in full alignment with the Malaysian Personal Data Protection Act 2010 (PDPA), the Singapore Personal Data Protection Act (PDPA), the Thailand Personal Data Protection Act (PDPA), and other regional statutory requirements across our Southeast Asian operating footprint.
2. Information We Collect
In the course of operating our digital presence, Sparvia Systems processes two distinct categories of data:
A. Voluntarily Provided Personal Data
This comprises any personal data or business context that you proactively submit to us through interactive fields on our website. This includes, but is not limited to:
- Consultation & Inbound Request Data: When you utilize our "Book a free consultation" tools or contact our engineering team directly, we collect your full legal name, business email address, direct corporate phone number, company name, job title, geographic location, and the specific technological scope (such as Microsoft Copilot adoption, Sovereign Managed SBCs, UCaaS, or ProAV requirements) of your inquiry.
- Marketing and Subscriber Communications Data: When you voluntarily register for our monthly industry publication, "Teams Talk SEA", we capture your business email address, company affiliation, and explicit communication preferences.
- Media and Asset Download Data: In keeping with our corporate philosophy of eliminating friction, we minimize form-fill blocks for basic spec sheets, whitepapers, and case studies. However, should an enterprise-grade architectural document require authorization, any identity details provided at that junction fall under this category.
B. Automatically Collected Technical Data
To ensure maximum uptime, system performance, and threat detection, our servers automatically collect telemetry data when you browse our site:
- Device and Connectivity Telemetry: Your Internet Protocol (IP) address, operating system version, browser engine type, hardware model, language settings, and unique device identifiers.
- Interaction and Behavioral Analytics: Detailed clickstream logs, timestamps of site entry and exit, specific pages visited (e.g., Banking compliance solutions, Manufacturing multi-country case studies), links clicked, resources downloaded, and total duration spent per section.
3. Cookies and Advanced Tracking Mechanisms
Our website utilizes essential, functional, and analytical cookies, web beacons, and tracking pixels to optimize your browsing journey.
- Essential and Technical Cookies: Mandatory for web security, load balancing, and form data retention while you browse. Disabling these via browser preferences may cause structural elements of the website to malfunction.
- Analytical and Personalization Cookies: These tools allow us to aggregate anonymous user journeys. They help us understand whether our visitors are primarily researching voice integration, compliance recording, or managed services. This insight ensures our content aligns with actual business demands across Southeast Asia.
- Cookie Management: Visitors retain absolute control over cookie permissions. You may configure your local web browser to reject, block, or delete cookies at any time, though this may restrict certain interactive elements of the website.
4. Legal Basis and Purpose of Data Processing
Sparvia Systems will only process your personal data when we have a valid legal foundation to do so. We process data under the following administrative justifications:
- Fulfillment of Pre-Contractual or Contractual Obligations: Processing your Identity and Consultation Data is mandatory to execute your requests for direct engineer bookings, architectural consults, or tailored commercial proposals.
- Legitimate Business Interests: Processing technical and behavioural data is necessary to secure our website infrastructure, prevent malicious cyber threats, perform quality control, and continuously improve our platform's UX.
- Explicit Statutory Consent: Delivering our monthly Teams Talk SEA newsletter is based entirely on your opt-in consent. You maintain the right to withdraw this consent instantaneously at any point without penalty.
- Regulatory Compliance: Processing data to comply with explicit regional laws, legal processes, or independent information security audits mandated by our SOC 2 Type II or ISO 27001 structures.
5. Third-Party Disclosures and Shared Data Ecosystems
Sparvia Systems strictly enforces a policy that forbids the selling, leasing, trading, or unauthorized renting of your personal data to external brokers. Your data is only shared with third parties under clear contractual terms, strictly limited to the following entities:
- Authorized Sub-Processors and IT Providers: Secure cloud infrastructure providers, CRM platforms, customer support communication software, and email distribution engines that actively enable Sparvia Systems to deliver client-side operations.
- Ecosystem Technology Partners: For instances where you seek specific multi-vendor integrations, we may share high-level project parameters with confirmed enterprise partners listed within our network (including Microsoft, AudioCodes, Ribbon, HP, Poly, Yealink, or Logitech) only after gaining your clear engineering authorization.
- Judicial and Regulatory Mandates: We may disclose personal data to law enforcement bodies, regulatory agencies, or government auditors if forced by a valid legal subpoena, or when necessary to protect the fundamental safety, rights, or verified security properties of Sparvia Systems, our 150+ corporate clients, or the public.
6. International and Cross-Border Data Flows
Sparvia Systems maintains an entrenched operational network spanning five distinct nations: Malaysia, Singapore, Indonesia, Thailand, and the Philippines. Consequently, personal data collected via our website may be transferred, stored, and processed outside your native country of residence.
Whenever your personal data is transferred across borders, we implement strict safeguards. These include end-to-end data encryption, localized data residency configurations where mandated by regional banking frameworks, and binding data transfer agreements. These structures guarantee that your information receives an equivalent level of protection to that required under the Malaysian PDPA and international frameworks.
7. Rigorous Security Governance (ISO 27001 & SOC 2 alignment)
In strict compliance with our active ISO 27001 Certification and SOC 2 Type II Audit verification, Sparvia Systems deploys a multilayered security architecture designed to prevent unauthorized access, loss, modification, or exposure of data:
- Cryptographic Protocols: All web traffic moving to and from https://www.sparvia.com.my is protected by advanced Transport Layer Security (TLS/SSL) encryption protocols.
- Access Control Matrices: Internal access to collected PII is governed by the Principle of Least Privilege (PoLP) and Role-Based Access Control (RBAC). Only named, authorized compliance and engineering personnel who require the data to fulfill your request are granted access.
- Regular Infrastructure Auditing: Our digital perimeters are subjected to routine vulnerability scanning, penetration testing, and continuous observability monitoring to stop threats before they happen.
8. Structured Data Retention
We retain your data only as long as necessary to achieve the clear purposes outlined in Section 4 of this policy. Identity data tied to marketing communications or the Teams Talk SEA newsletter is retained until you choose to unsubscribe. Data linked to enterprise consultations is retained for the duration of our commercial assessment period, or longer if required to satisfy statutory financial, tax, or legal archiving obligations. Once data outlives its operational or legal utility, it is permanently purged or anonymized using certified digital destruction protocols.
9. Your Statutory Data Rights
Under applicable regional data protection laws, you hold clear rights regarding your personal information. These include:
- Right of Access: The right to request formal confirmation of whether your data is being processed, and to receive a structured copy of your personal data.
- Right to Rectification: The right to demand that we correct or update any inaccurate, outdated, or incomplete data we hold about you.
- Right to Erasure ("Right to be Forgotten"): The right to request the total deletion of your personal data when it is no longer required for business operations or legal compliance.
- Right to Withdraw Consent: The right to revoke processing permissions at any time (e.g., opting out of marketing tracking).
- Right to Data Portability: The right to request a digital transfer of your data to another service provider in a structured, machine-readable format.
To exercise any of these rights, please submit a formal request to our Data Protection Officer using the contact credentials provided below.
10. External Framework Links
Our website contains references, links, and integrations to third-party digital portals (such as corporate LinkedIn profiles, case studies, or partner platforms). Sparvia Systems holds no jurisdiction over the privacy architectures, cookie rules, or content guidelines of external websites. We strongly advise checking the individual privacy documentation of any external site you visit.
11. Amendments to This Policy
We reserve the absolute right to modify, amend, or update this Comprehensive Privacy Policy at any time to account for changing technologies, legal updates, or changes in our operational procedures. The revised policy will be published immediately on this page with an updated "Last Updated" date. Continued interaction with our website after changes go live constitutes an explicit acknowledgment of the updated policy.
12. Regulatory Governance and Contact
For any compliance questions, concerns, complaints regarding data handling, or to execute your statutory data rights, please reach out to us:
Attn: Data Protection & Compliance OfficerSparvia Systems Sdn Bhd
Registered Headquarters: Level 27, Centrepoint South, The Boulevard, Mid Valley City, 59200 Lingkaran Syed Putra, Kuala Lumpur, Malaysia.
