Legal

Privacy Policy

Pursuant to the Personal Data Protection Act 2010, as amended 2024

Effective Date: 28/04/2026 | Last Updated: 28/04/2026 | Version: 1.0

1. Identity and Contact Details of the Data Controller

Arvia Tech Enterprise (Company Registration No. 202603071201 (JR0188604-K)) ("Arvia", "we", "us", or "our") is a financial technology and software platform company incorporated and registered in Malaysia, with its registered office at Jalan PUJ 2/6, Taman Puncak Jalil, 43300 Seri Kembangan, Selangor, Malaysia.

Arvia operates a business-to-business (B2B) network acting as the transaction spine of Malaysia's B2B economy. Our platform serves as a networked Accounts Receivable (AR) and Accounts Payable (AP) pipeline, automating reconciliation and generating verified financial identities and credit profiles for Malaysian SMEs.

1.1 Privacy Compliance Contact

If you have any questions about this Policy or wish to exercise your data rights, please contact our privacy team at:

  • Name: Arvia Privacy team
  • Designation: Privacy Compliance Administrator
  • Email: [email protected]
  • Response time: Within twenty-one (21) working days of receipt of a verifiable written request

2. Scope and Application of This Policy

This Privacy Policy applies to all personal and business data collected, used, disclosed, stored, and processed by Arvia in connection with the following activities:

  • Arvia's web platform, mobile application, and API services.
  • All AR/AP file uploads, invoice matching, and reconciliation activities.
  • All payments, auto-debits, and fund transfers facilitated through our integrated payment gateways.
  • The generation of behavioural credit profiles and data sharing under our credit marketplace.
  • All communications and automated profiling carried out by Arvia's platform systems.

This policy applies to businesses transacting on the network, including Suppliers (Sellers), Buyers, and their authorised representatives.

3. Categories of Personal Data Collected

3.1 Data Collected from Network Participants (Buyers and Suppliers)

Upon registration or onboarding on the Arvia platform, the following categories of data are collected:

  • Full legal name and NRIC or passport number of the authorised account holder/director.
  • Business name and Company Registration Number (SSM).
  • Business registered address, principal operating address, email, and telephone number.
  • Bank account details (bank name, account number, account holder name) for direct fund transfers and mandate execution.
  • Transaction and Invoice Data: Accounts Receivable and Accounts Payable files, including invoice amounts, counterparty details, and payment terms.
  • Payment Behaviour Data: Timestamps of payment clearing, settlement frequency, mandate status, and live cash flow analytics.

3.2 Data Collected Automatically

When you visit our platform, Arvia automatically collects technical and usage data: browser type, device type, operating system, IP address, approximate geographic location, and session cookies required for platform functionality and fraud prevention.

4. Purposes of Processing

Arvia processes data to transition dormant spreadsheets into live financial intelligence. Purposes include:

  • Platform Operations & Reconciliation: To automate invoice matching, verify identities, manage accounts, and serve as the single source of truth for B2B transactions.
  • Payment Execution: To instruct our integrated payment gateway partners (such as Airwallex or Curlec) to execute scheduled debits or direct fund transfers.
  • Credit Profile Generation: To systematically accumulate payment behaviour into a verifiable credit profile that replaces collateral-based lending with behaviour-based creditworthiness.
  • Fraud Prevention & Security: To detect, investigate, and prevent fraudulent transactions and abuse of the Arvia network.
  • Legal Compliance: To fulfil obligations under the PDPA 2010, AMLA 2001, and tax legislation.

5. Lawful Basis for Processing

Arvia processes data on the following lawful bases:

  • Consent: For the collection of bank account details, execution of payment mandates, and the explicit sharing of credit profiles with third-party financiers.
  • Contractual necessity: For processing required to fulfil SaaS subscriptions, reconciliation services, and payment settlements on the network.
  • Legal obligation: For compliance with Malaysian statutory obligations, including AMLA and tax record-keeping.
  • Legitimate interests: For network security, fraud prevention, and system improvements.

6. Disclosure of Personal Data

Arvia operates as an integrated ecosystem and discloses data only to the minimum extent necessary:

  • Payment Gateways: Licensed processors (e.g., Airwallex, Curlec) receive bank account details and payment instructions solely to execute fund transfers securely.
  • Financial Institutions & Financiers: Through our credit and data API licensing model, we share anonymised or consent-based behavioural credit profiles with banks, insurers, and trade financiers to facilitate loan origination and invoice factoring on our financing marketplace.
  • Network Counterparties: Invoice status and reconciliation updates are visible to verified buyers and suppliers involved in a specific transaction.
  • Regulatory & Legal Authorities: Bank Negara Malaysia (BNM), the Personal Data Protection Commissioner, or law enforcement, as required by law.

7. Security Measures

Arvia ensures transaction data remains immutable and protected:

  • Data in transit is encrypted using TLS 1.2 or higher. Sensitive data at rest is encrypted using AES-256 or equivalent standards.
  • Arvia does not store full bank account credentials on its own servers; details are transmitted directly to our partners' PCI-DSS compliant infrastructure.
  • Strict role-based access controls and independent security audits are routinely enforced.

8. Retention of Personal Data

Arvia retains data to preserve accumulated credit behavioural histories and meet legal requirements:

  • Identity and transaction data: Seven (7) years from the last transaction, per tax and AMLA requirements.
  • Payment behaviour data: Retained as long as the business remains active on the network to maintain its credit profile.
  • Closed accounts: Deleted or anonymised ninety (90) days from closure, barring legal retention mandates.

9. Your Rights as a Data Subject

Under the PDPA (as amended 2024), you have the right to access, correct, limit processing, request data portability, and withdraw consent. Requests can be made to [email protected]. Please note that withdrawing consent for payment processing or data sharing may restrict access to network financing or automated reconciliation capabilities.