Version 2026-08-21.1 · Last updated 21 AUG 2026
This bilingual notice is issued by Thither Global (M) Sdn Bhd, trading as UrusHQ, under the Personal Data Protection Act 2010 and describes personal data processed in commercial transactions relating to UrusHQ. “Processing” includes collecting, recording, holding, using, disclosing, correcting and deleting data.
We may process identity and contact information; employment and business information; company registration and tax identifiers; account credentials and permissions; billing and payment references; financial, payroll, leave, attendance, contact and supplier records entered into a workspace; communications; consent and audit records; device, browser, IP, usage, cookie, diagnostic and security information.
Data comes from you, your employer or workspace administrator, authorised users, enabled integrations, payment and identity providers, public or authorised registries, support interactions and use of the service. Required fields are identified when collected. If required data is not supplied, we may be unable to create an account, provide a feature, process payment or satisfy legal obligations.
We process data to provide, personalise, secure and support UrusHQ; administer users and permissions; process subscriptions and transactions; create requested records and reports; operate integrations; communicate service, security and billing information; prevent misuse; investigate incidents; maintain evidence; improve performance; and comply with law and enforce agreements.
Transactional processing required for the service is not optional. Marketing is optional and may be stopped using the message link or by contacting us. Withdrawing consent does not affect processing already lawfully performed or processing required on another lawful basis.
Data may be disclosed to authorised Customer users; hosting, database, communications, payment, monitoring, analytics, identity, integration and support providers; professional advisers; regulators, courts or authorities where required; and a successor in a protected corporate transaction. We do not sell personal data.
Some recipients and infrastructure are outside Malaysia, including current primary hosting in Singapore. We take reasonable steps to use appropriate contractual and security safeguards and to limit disclosure to the stated purposes.
Subject to the Act and applicable exceptions, you may request information about processing, access or correction; withdraw consent; object to direct marketing; or ask us to prevent processing likely to cause damage or distress. You may complain to Malaysia’s Personal Data Protection Commissioner.
We may require proof of identity, authority and sufficient detail, and may charge a lawful prescribed fee where applicable. For data controlled by a Customer, we may refer the request to that Customer and assist it.
We use role-based access, tenant separation, encryption in transit, credential controls, logging, monitoring, backups and restricted operational access appropriate to the service. No online system is risk-free; notify us promptly if you suspect unauthorised access.
Customers and users should keep data accurate and current. We retain it only as needed for the stated purposes, contracts, security, backups, disputes and statutory obligations, then delete, anonymise or securely isolate it.
Direct PDPA enquiries and requests to Thither Global (M) Sdn Bhd through the UrusHQ contact page or sales@urushq.my. State “PDPA request”, identify the relevant workspace and describe your request. This address receives privacy requests; it does not imply that a statutory Data Protection Officer appointment is required or has been made.