Privacy at a glance
1. Who we are
CXTRUST MARK is operated by CX Powercert Services, Malaysia. For privacy, access, correction, deletion, objection, marketing opt-out or data-protection enquiries, contact info@cxtrustmark.com.
2. Our privacy framework
CXTRUST applies a global privacy framework designed around applicable Malaysian data-protection requirements and internationally recognised privacy principles. In Malaysia, this includes the Personal Data Protection Act 2010 (Act 709), as amended, and applicable guidance issued by the Personal Data Protection Commissioner.
Where the EU GDPR, UK GDPR or another jurisdiction's privacy law applies to a particular individual or processing activity, CXTRUST intends to apply the rights, safeguards and lawful-processing requirements that apply in that context. This notice is not a claim that every privacy law in every country applies to every CXTRUST transaction.
3. What information we may collect
- Account and contact data: name, role, organisation, business email, phone, country and login/access records.
- Organisation data: organisation name, industry, declared assessment scope, programme/team information and public recognition details.
- Assessment and evidence data: submitted claims, reports, dashboards, screenshots, survey outputs, complaints/process evidence, governance records and applicant notes.
- Transaction data: order, payment status, invoice and billing metadata. Payment-card details are handled by the payment provider rather than being intentionally stored by CXTRUST.
- Technical data: security logs, IP/device/browser information, cookies and diagnostic events where used.
- Communications: support messages, operational emails, consent/opt-out choices and other service correspondence.
4. Why we process information
We may process information to create and secure My CXTRUST access; receive and validate applications; assess evidence; generate qualification results; administer the Improvement Window; activate recognition after qualification and payment; issue certificates and digital marks; maintain public verification records; support renewal and revalidation; prevent fraud/abuse; provide support; meet accounting/legal obligations; and improve the reliability and security of the service.
5. Lawful basis, service processing and consent
Depending on the jurisdiction and activity, processing may be necessary to provide the CXTRUST service or perform a contract, comply with legal obligations, protect legitimate operational/security interests, or be based on consent where consent is the appropriate legal basis.
Optional marketing is separate. Where consent is required for marketing or non-essential cookies, it should be requested separately and can be withdrawn without affecting an organisation's assessment or recognition status.
6. Assessment evidence and confidentiality
Applicant evidence is used to validate CX claims within the declared scope. CXTRUST expects applicants to submit only material they are authorised to provide. Evidence may be reviewed automatically and, where required, by authorised personnel or service providers supporting the assessment process.
Public verification should contain recognition information intended for public assurance; it is not intended to expose private evidence, internal reports, detailed personal data or confidential applicant files.
7. AI-assisted validation and automated processing
CXTRUST may use AI-assisted tools to classify, extract, compare or validate submitted information against the published CXTRUST methodology and evidence requirements. Automated tools are support mechanisms: they do not have authority to change the published standard, alter recognition thresholds, bypass mandatory gates or sell a recognition outcome.
Where applicable law gives an individual rights concerning significant solely automated decisions, CXTRUST will provide the safeguards required in that context, which may include information about the processing and a route to request review or human intervention.
9. International and cross-border transfers
Because CXTRUST is designed for international use and may rely on global infrastructure, information may be processed or stored outside the user's country. Where cross-border transfer requirements apply, CXTRUST will use an applicable transfer mechanism or other recognised safeguard and will consider the sensitivity, destination, service provider and security measures involved.
10. Retention, archival and deletion
Information is retained for as long as reasonably necessary for the purpose for which it was collected, including assessment integrity, recognition validity, renewal history, dispute/appeal handling, security, accounting and legal obligations. Retention periods may differ by record type and jurisdiction.
When information is no longer required, CXTRUST may delete, anonymise or securely archive it where continued retention is justified. A request to delete data may be limited where retention is required by law or necessary to preserve legitimate audit, fraud-prevention or recognition-integrity records.
11. Your data-protection rights
Depending on the law that applies, you may have rights to request access, correction, deletion, restriction, portability, objection to certain processing, withdrawal of consent, information about automated processing, or review of certain automated decisions. Direct marketing opt-out requests will be respected.
To exercise a right, email info@cxtrustmark.com. We may need to verify identity and may ask for information needed to locate the relevant record. You may also have the right to complain to the relevant data-protection regulator.
13. Security and personal-data breaches
CXTRUST uses administrative, technical and organisational safeguards appropriate to the service, which may include controlled access, OTP authentication, secure transport, logging, role restrictions, backups and service-provider controls. No internet service can promise absolute security.
Suspected personal-data breaches are assessed and managed under the applicable incident-response process. Where law requires notification to a regulator or affected individuals, CXTRUST will follow the applicable notification requirements.
14. Children and minors
CXTRUST is a business-to-business organisation assessment and recognition service. It is not designed for children and we do not intentionally request children's personal data as part of the normal applicant journey.
15. Changes to this notice and how to contact us
We may update this notice as the service, technology, providers or applicable privacy requirements evolve. The effective date and version shown above identify the current published notice.