CX CXTRUST MARK Privacy & Data Protection Centre
PRIVACY. SECURITY. ACCOUNTABILITY.

Your information deserves the same trust as the Mark.

This Centre explains how CXTRUST MARK handles personal and organisational information throughout registration, assessment, recognition, verification, support and renewal.

Effective 21 August 2026  •  Version 1.0

Privacy at a glance

We minimiseSubmit only what CXTRUST needs.
We separate marketingOptional marketing is not bundled into service access.
We protect evidenceApplicant evidence is treated as controlled assessment material.
We explain AIAI-assisted validation does not change the published standard or mandatory gates.

1. Who we are

CXTRUST MARK is operated by CX Powercert Services, Malaysia. For privacy, access, correction, deletion, objection, marketing opt-out or data-protection enquiries, contact info@cxtrustmark.com.

2. Our privacy framework

CXTRUST applies a global privacy framework designed around applicable Malaysian data-protection requirements and internationally recognised privacy principles. In Malaysia, this includes the Personal Data Protection Act 2010 (Act 709), as amended, and applicable guidance issued by the Personal Data Protection Commissioner.

Where the EU GDPR, UK GDPR or another jurisdiction's privacy law applies to a particular individual or processing activity, CXTRUST intends to apply the rights, safeguards and lawful-processing requirements that apply in that context. This notice is not a claim that every privacy law in every country applies to every CXTRUST transaction.

3. What information we may collect

  • Account and contact data: name, role, organisation, business email, phone, country and login/access records.
  • Organisation data: organisation name, industry, declared assessment scope, programme/team information and public recognition details.
  • Assessment and evidence data: submitted claims, reports, dashboards, screenshots, survey outputs, complaints/process evidence, governance records and applicant notes.
  • Transaction data: order, payment status, invoice and billing metadata. Payment-card details are handled by the payment provider rather than being intentionally stored by CXTRUST.
  • Technical data: security logs, IP/device/browser information, cookies and diagnostic events where used.
  • Communications: support messages, operational emails, consent/opt-out choices and other service correspondence.
Do not upload unnecessary personal data. Evidence should support the declared CX claim without including unrelated customer, employee or sensitive information.

4. Why we process information

We may process information to create and secure My CXTRUST access; receive and validate applications; assess evidence; generate qualification results; administer the Improvement Window; activate recognition after qualification and payment; issue certificates and digital marks; maintain public verification records; support renewal and revalidation; prevent fraud/abuse; provide support; meet accounting/legal obligations; and improve the reliability and security of the service.

6. Assessment evidence and confidentiality

Applicant evidence is used to validate CX claims within the declared scope. CXTRUST expects applicants to submit only material they are authorised to provide. Evidence may be reviewed automatically and, where required, by authorised personnel or service providers supporting the assessment process.

Public verification should contain recognition information intended for public assurance; it is not intended to expose private evidence, internal reports, detailed personal data or confidential applicant files.

7. AI-assisted validation and automated processing

CXTRUST may use AI-assisted tools to classify, extract, compare or validate submitted information against the published CXTRUST methodology and evidence requirements. Automated tools are support mechanisms: they do not have authority to change the published standard, alter recognition thresholds, bypass mandatory gates or sell a recognition outcome.

Where applicable law gives an individual rights concerning significant solely automated decisions, CXTRUST will provide the safeguards required in that context, which may include information about the processing and a route to request review or human intervention.

8. Service providers and information sharing

We may use carefully selected providers for website hosting, security, email delivery, payment processing, analytics, cloud infrastructure, support and AI-assisted processing. They should receive only the information reasonably required for their role and be subject to appropriate contractual or technical controls.

We do not treat applicant information as a product for sale to advertisers. We may disclose information where required by law, to protect legal rights/security, or as part of a legitimate corporate or service-provider transition subject to appropriate safeguards.

9. International and cross-border transfers

Because CXTRUST is designed for international use and may rely on global infrastructure, information may be processed or stored outside the user's country. Where cross-border transfer requirements apply, CXTRUST will use an applicable transfer mechanism or other recognised safeguard and will consider the sensitivity, destination, service provider and security measures involved.

10. Retention, archival and deletion

Information is retained for as long as reasonably necessary for the purpose for which it was collected, including assessment integrity, recognition validity, renewal history, dispute/appeal handling, security, accounting and legal obligations. Retention periods may differ by record type and jurisdiction.

When information is no longer required, CXTRUST may delete, anonymise or securely archive it where continued retention is justified. A request to delete data may be limited where retention is required by law or necessary to preserve legitimate audit, fraud-prevention or recognition-integrity records.

11. Your data-protection rights

Depending on the law that applies, you may have rights to request access, correction, deletion, restriction, portability, objection to certain processing, withdrawal of consent, information about automated processing, or review of certain automated decisions. Direct marketing opt-out requests will be respected.

To exercise a right, email info@cxtrustmark.com. We may need to verify identity and may ask for information needed to locate the relevant record. You may also have the right to complain to the relevant data-protection regulator.

12. Cookies, essential technology and analytics

Essential cookies or similar technologies may be used for security, session continuity, login, payment and core website functions. Non-essential analytics or marketing technologies, where used, should be controlled through the site's cookie/consent mechanism where applicable law requires it.

13. Security and personal-data breaches

CXTRUST uses administrative, technical and organisational safeguards appropriate to the service, which may include controlled access, OTP authentication, secure transport, logging, role restrictions, backups and service-provider controls. No internet service can promise absolute security.

Suspected personal-data breaches are assessed and managed under the applicable incident-response process. Where law requires notification to a regulator or affected individuals, CXTRUST will follow the applicable notification requirements.

14. Children and minors

CXTRUST is a business-to-business organisation assessment and recognition service. It is not designed for children and we do not intentionally request children's personal data as part of the normal applicant journey.

15. Changes to this notice and how to contact us

We may update this notice as the service, technology, providers or applicable privacy requirements evolve. The effective date and version shown above identify the current published notice.

CXTRUST MARK — Privacy & Data Protection Operated by CX Powercert Services, Malaysia info@cxtrustmark.com