Privacy Policy

Effective January 2026

Placeholder text. This document is a starting point only and has not been reviewed by counsel. Replace with terms drafted or approved by your legal advisor before relying on it in production.

Respublica Ventures Sdn Bhd ("MyStakeIQ", "we", "us") respects your privacy and is committed to handling personal data in accordance with the Malaysian Personal Data Protection Act 2010 (PDPA) and applicable data protection laws.

1. What we collect

  • Account data: email address, hashed password, MFA configuration, phone number (if enrolled for SMS 2FA), tenant/company name, role.
  • Uploaded ROD data: records of depositors that you upload, including holder names, addresses, NRIC/passport identifiers, broker codes and shareholdings.
  • Usage telemetry: request method, response status, IP address, and user-agent. Logged for security and debugging.
  • Billing data: processed by Curlec / Razorpay. We store only the subscription identifier and lifecycle status — no card numbers.

2. How we use it

  • To operate the service: parse ROD files, generate dashboards, deliver signals.
  • To authenticate you (email + password + MFA) and prevent abuse.
  • To bill your subscription and process cancellation.
  • To respond to support requests you initiate.

3. How long we keep it

ROD data is retained for as long as the tenant remains active. Audit log entries are retained for at least 12 months. On account deletion, ROD data and personal data are removed within 30 days; backups are purged within 90 days.

4. Where it's stored

Application data is stored in tenant-isolated tables in our managed database, hosted in infrastructure within the ASEAN region. ROD files are stored on our application server's encrypted disk under a tenant-scoped path.

5. Sharing

We do not sell personal data. We share data only with sub-processors required to operate the service: Resend (email delivery), SMS360 (SMS OTP), Curlec / Razorpay (subscription billing), and our hosting provider. Each is bound by their own data-protection commitments.

6. Security

  • Passwords hashed with argon2id.
  • MFA secrets encrypted at rest with AES-256-GCM.
  • Sessions are HttpOnly + SameSite=Lax cookies; __Host- prefix in production.
  • Per-tenant row-level isolation; every database query is scoped by tenant id.
  • All authentication and upload actions written to an audit log.

7. Your rights

Under PDPA you may request access, correction or deletion of your personal data, and you may withdraw consent. Send requests to info@respublica.my. We respond within 21 calendar days.

8. Changes

If we make material changes to this policy we will notify you by email and update the effective date above.

9. Contact

Data protection enquiries: info@respublica.my.