1. Introduction
Hernan Corporation Sdn Bhd ("Hernan", "we", "us", or "our") is committed to protecting the privacy and security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your data when you use our Supplier Invoice Portal ("Portal").
2. Information We Collect
When you submit an invoice through our Portal, we collect the following information:
- Business Information β Company name, Purchase Order (PO) number, invoice number, and invoice amount.
- Contact Details β Email address and contact phone number provided during submission.
- Uploaded Documents β PDF invoice files you upload to the Portal.
- Technical Data β Browser type, IP address, and submission timestamps for security and audit purposes.
3. How We Use Your Information
- To process, verify, and approve your submitted invoices.
- To communicate confirmation, status updates, and payment notifications to your registered email.
- To match your invoice against our Purchase Order records.
- To comply with Malaysian financial regulations and tax obligations under LHDN.
- To detect and prevent fraudulent or unauthorised submissions.
4. Data Sharing & Disclosure
We do not sell, rent, or trade your personal data. We may share your information with:
- Internal Finance Teams β Authorised Hernan personnel who process and approve invoices.
- Legal Authorities β When required by Malaysian law, court order, or regulatory bodies.
- Auditors β For statutory audit and compliance review purposes only.
5. Data Retention
Invoice records and associated personal data are retained for a minimum of 7 years in accordance with the Malaysian Companies Act 2016 and income tax regulations. After this period, data is securely deleted or anonymised.
6. Security
All data transmitted through the Portal is protected with 256-bit SSL/TLS encryption. Uploaded PDF files are stored in encrypted cloud storage with access restricted to authorised personnel only. We perform regular security audits to maintain data integrity.
7. Your Rights
Under the Personal Data Protection Act 2010 (PDPA) of Malaysia, you have the right to:
- Access personal data we hold about you.
- Correct inaccurate or incomplete personal data.
- Withdraw consent for processing (subject to legal obligations).
- Request deletion of your data where legally permissible.
To exercise these rights, contact our Data Protection Officer at dpo@hernan.com.my.
8. Contact
For any privacy-related enquiries, contact us at:
Hernan Corporation Sdn Bhd
No. 12, Jalan Industri 3, Kawasan Perindustrian Nilai, 71800 Nilai, Negeri Sembilan, Malaysia
π§ privacy@hernan.com.my Β· π +60 6-799 1234