How we handle your data.
Last updated March 23, 2026
1. Introduction
Welcome to gxwong.com (the "Site"), operated by GX Wong ("we", "us", or "our"). We respect your privacy and are committed to protecting your personal data in compliance with applicable laws, including but not limited to the Malaysia Personal Data Protection Act 2010 (PDPA), the General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA). This Privacy Policy explains how we collect, use, process, and disclose your information when you use our website and services.
2. Information We Collect
We may collect the following types of information when you interact with our Site:
- Personal Information: Information you voluntarily provide via forms (contact, audit requests, surveys), which may include your name, email address, website URL, company name, and any specific notes or files you submit.
- Automatically Collected Data: When you visit our Site, we automatically collect certain technical information, such as your IP address, browser type, device information, operating system, pages visited, and interaction data (e.g., clicks, scroll depth) through cookies and similar tracking technologies.
3. How We Use Your Information
We use the collected information for the following purposes:
- To provide, operate, and maintain our Site and services.
- To review your website and respond to audit or unlocking requests.
- To communicate with you, respond to your inquiries, and provide customer support.
- To analyze and understand how you interact with our Site to improve performance, user experience, and functionality.
- To detect, prevent, and address technical, security, or legal issues.
4. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA) or the UK, our legal basis for collecting and using your personal data depends on the context in which it was collected:
- Consent: Where you have given explicit consent (e.g., submitting a contact form or accepting non-essential cookies).
- Legitimate Interests: To operate our business, improve our Site, and provide necessary services unless overridden by your data protection interests.
- Performance of a Contract: When necessary to fulfill a service agreement with you.
5. Data Sharing and Disclosure
We do not sell, rent, or trade your personal information to third parties. We may share your information with trusted third-party service providers who assist us in operating our Site and conducting our business, such as:
- Hosting and infrastructure providers.
- Analytics and diagnostics tools (e.g., Google Analytics 4, Microsoft Clarity, Ahrefs Web Analytics).
- Email delivery and communication platforms.
These third parties are contractually obligated to protect your data and only use it for the purposes we specify. We may also disclose information if required by law or to protect our legal rights.
6. Data Retention and Security
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, to provide our services, and to comply with legal, accounting, or reporting obligations. We implement appropriate technical and organizational security measures (such as encryption and access controls) to protect your data against unauthorized access, loss, or misuse. However, no data transmission over the internet can be guaranteed as 100% secure.
7. International Data Transfers
Your information may be transferred to, stored, and processed in countries outside of your residence or where the data protection laws may differ (e.g., transfers from the EEA/UK to servers in the USA or Malaysia). When such transfers occur, we take steps to ensure appropriate safeguards are in place to maintain the protection of your data.
8. Your Privacy Rights
Depending on your location and applicable privacy laws (PDPA, GDPR, CCPA), you have the right to:
- Access/Request: Request a copy of the personal data we hold about you.
- Correction/Rectification: Request that we correct inaccurate or incomplete data.
- Deletion/Erasure ("Right to be Forgotten"): Request the deletion of your personal data under certain conditions.
- Restriction/Objection: Object to or request the restriction of our processing of your data.
- Data Portability: Request the transfer of your data to another organization.
- Withdraw Consent: Withdraw authorization for processing based on previously given consent at any time.
- Non-Discrimination (CCPA): Not receive discriminatory treatment for exercising your privacy rights. Note: We do not sell your personal information.
To exercise these rights, please contact us using the details below. We will verify your identity before processing your request.
9. Cookies and Tracking
This site uses cookies and similar technologies to ensure core functionality and provide insights into user behavior via tools such as Google Analytics 4, Microsoft Clarity, and Ahrefs Web Analytics. You can instruct your browser to refuse all non-essential cookies or to indicate when a cookie is being sent.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any significant changes by updating the "Last updated" date at the top of this page. Your continued use of the Site after changes are posted constitutes your acceptance of the revised policy.
11. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal
data, please contact our Data Protection Officer / Privacy Team at:
hello@gxwong.com