Privacy Policy
NEWVIA SDN. BHD. Last Updated: 19 August 2026
This Privacy Policy explains how NEWVIA SDN. BHD. (SSM Business Registration No. 202601032040 (1694135-H)), with its registered address at 7-2, Plaza Danau 2, Jalan 2/109f, Taman Danau Desa, 58100 Kuala Lumpur, W.P. Kuala Lumpur, Malaysia ("NewVia", "we", "us", "our"), collects, uses, discloses, and protects personal data when you use our websites at newvia.ai and app.newvia.ai and our related software and services (the "Services").
We are committed to processing personal data in compliance with the Malaysian Personal Data Protection Act 2010 ("PDPA") and, where applicable to individuals in the European Economic Area or United Kingdom, the EU/UK General Data Protection Regulation ("GDPR"). This notice also serves as our personal data protection notice under Section 7 of the PDPA. For the purposes of the PDPA, NewVia is the data user; for the purposes of the GDPR, NewVia is the data controller in respect of the data described below (and acts as a processor for data our business customers submit about their own clients).
1. Data We Collect
1.1 Account Information
- Name, business/company name, and job title
- Email address and phone number
- Account credentials (passwords are stored only in salted, hashed form)
- Business profile details, service menus, and settings you configure
- Communications with us (e.g., support requests to support@newvia.ai)
1.2 Technical Telemetry
- IP address, browser type and version, operating system, and device identifiers
- Log data: pages viewed, features used, session timestamps, referring URLs, and error/diagnostic reports
- Cookies and similar technologies, as described in our Cookie & Tracking Policy
1.3 Transaction Metadata
- Subscription plan, billing history, invoices, and receipts
- Payment transaction references, payment status, currency and amount
- Limited, non-sensitive card metadata provided to us by our payment gateways: card brand, last four digits, and expiry month/year (for display and dunning purposes only)
- Tokenized payment references generated by our payment gateways
1.4 Customer-Submitted Data
Where you, as a business user, submit data about your own clients or staff into the platform (e.g., booking records), you are responsible for having a lawful basis to do so; we process that data on your behalf and on your instructions.
2. Payment Card Security Boundary (PCI-DSS)
NewVia never stores, processes, or transmits full payment card numbers (PANs), CVV/CVC security codes, or card PINs on NewVia servers.
When you enter payment details, those details are captured in secure fields served by, and transmitted directly to, our third-party payment gateways — which may include Stripe, Airwallex, HitPay, and Razorpay — each of which is certified as a PCI-DSS Level 1 service provider, the highest level of certification available under the Payment Card Industry Data Security Standard. NewVia receives back only tokenized references and limited transaction metadata (as described in Section 1.3) necessary to administer your subscription, issue receipts, and prevent fraud. Your card data is governed by the privacy policy of the applicable payment gateway.
3. Purposes of Processing
We process personal data for the following purposes:
- Account administration — creating and managing accounts, authenticating users, providing customer support, and communicating service notices;
- Billing — processing subscriptions, renewals, invoicing, receipts, dunning for failed payments, and maintaining financial records required by law;
- Platform security — detecting, investigating, and preventing fraud, abuse, unauthorized access, and violations of our Terms of Service, including sharing necessary data with payment gateways for risk and anti-fraud screening;
- Feature delivery — operating, maintaining, and improving the Services, delivering the features of your plan, and providing integrations you enable;
- Legal compliance — complying with applicable laws, tax and accounting obligations, lawful requests from authorities, and enforcing our legal rights.
We do not sell personal data, and we do not use personal data for third-party advertising.
4. Legal Grounds for Processing
4.1 Under the Malaysian PDPA 2010
We process personal data in accordance with the PDPA's General, Notice and Choice, Disclosure, Security, Retention, Data Integrity, and Access Principles. Our processing is carried out: (a) with your consent, given when you register for and use the Services; (b) where necessary for the performance of a contract to which you are a party (the Terms of Service); and/or (c) where necessary for compliance with our legal obligations. This Privacy Policy constitutes the written notice required under Section 7 of the PDPA, and is issued in the English language; a Bahasa Malaysia version is available upon request to support@newvia.ai.
4.2 Under the GDPR (where applicable)
Where the GDPR applies, we rely on the following legal bases:
- Contract performance (Art. 6(1)(b)) — account administration, feature delivery, and billing;
- Legal obligation (Art. 6(1)(c)) — tax, accounting, and regulatory record-keeping;
- Legitimate interests (Art. 6(1)(f)) — platform security, fraud prevention, service improvement, and defending legal claims, balanced against your rights and freedoms;
- Consent (Art. 6(1)(a)) — non-essential cookies and optional marketing communications, which you may withdraw at any time.
5. Disclosure of Personal Data
We disclose personal data only to:
- Payment gateways (e.g., Stripe, Airwallex, HitPay, Razorpay) for payment processing, risk screening, and fraud prevention;
- Service providers / sub-processors that host infrastructure, deliver email and messaging, provide analytics, or support customer service — bound by confidentiality and data processing obligations;
- Integration partners you actively enable (e.g., calendar or accounting integrations);
- Professional advisers, regulators, courts, and law enforcement where required by law or to protect our legal rights; and
- A successor entity in the event of a merger, acquisition, or sale of assets, subject to this Policy.
6. International Transfers
Our service providers and payment gateways may store or process data outside Malaysia. Where personal data is transferred internationally, we take steps to ensure an adequate level of protection consistent with the PDPA and, where the GDPR applies, implement appropriate safeguards such as the European Commission's Standard Contractual Clauses.
7. Data Retention
We retain personal data only as long as necessary for the purposes described above: account data for the life of the account and a reasonable period thereafter; transaction and invoicing records for at least seven (7) years as required by Malaysian tax and companies legislation; and technical logs for shorter operational periods. When data is no longer required, it is deleted or irreversibly anonymized.
8. Security
We implement administrative, technical, and physical safeguards appropriate to the risk, including encryption in transit (TLS), encryption at rest for sensitive data, access controls and least-privilege permissions, logging and monitoring, and vendor due diligence. No system is perfectly secure; you are responsible for keeping your account credentials confidential.
9. Your Rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about you;
- Correct inaccurate or incomplete personal data;
- Delete your personal data (subject to legal retention obligations);
- Withdraw consent to processing based on consent, including marketing;
- Limit or object to certain processing, and — where the GDPR applies — request data portability and lodge a complaint with your supervisory authority.
To exercise any of these rights, contact us at support@newvia.ai or write to us at:
NEWVIA SDN. BHD. 7-2, Plaza Danau 2, Jalan 2/109f, Taman Danau Desa, 58100 Kuala Lumpur, W.P. Kuala Lumpur, Malaysia
We may need to verify your identity before fulfilling a request, and we will respond within the timeframes required by applicable law (generally 21 days under the PDPA and one month under the GDPR). A reasonable fee may apply to access requests where permitted by the PDPA.
10. Children
The Services are intended for business use by adults. We do not knowingly collect personal data from individuals under eighteen (18) years of age. If you believe a minor has provided us personal data, contact support@newvia.ai and we will delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified via the Services or by email before they take effect. The "Last Updated" date at the top indicates the current version.
12. Contact
NEWVIA SDN. BHD. (202601032040 (1694135-H)) 7-2, Plaza Danau 2, Jalan 2/109f, Taman Danau Desa, 58100 Kuala Lumpur, W.P. Kuala Lumpur, Malaysia Email: support@newvia.ai