Privacy policy

Last updated: 26 June 2026

DIGITAL X (“DIGITAL X”, “we”, “us” or “our”), a business operated by DIGITAL X LABS of 14, Lorong Sri Damak 13, Taman Sri Andalas, 41200 Klang, Selangor, Malaysia, operates the website digitalxlabs.io (the “Site”) and provides digital services and print-on-demand merchandise to customers worldwide. We respect your privacy and are committed to protecting the personal data you entrust to us.

This Privacy Policy is issued in accordance with the Malaysian Personal Data Protection Act 2010 (“PDPA”) and its 2024 amendments, and is also designed to meet the standards of the EU and UK General Data Protection Regulation (GDPR) and the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA) for our international customers. Under the PDPA, DIGITAL X is the “data user” (and, under the GDPR, the “data controller”) responsible for your personal data.

1. Scope and consent

This Policy applies to personal data we process about customers, website visitors, subscribers, service clients and other individuals who interact with us. By providing your personal data, placing an order, creating an account or using our Site, you consent to the collection, use and disclosure of your personal data as described here. Where we rely on consent, you may withdraw it at any time (see section 12).

2. The PDPA principles we follow

We comply with the seven Personal Data Protection Principles under the PDPA:

  1. General Principle — we process personal data only with consent or as otherwise permitted by law.
  2. Notice and Choice Principle — this Policy serves as your written notice of what we collect and why.
  3. Disclosure Principle — we do not disclose personal data for purposes other than those notified to you, without consent.
  4. Security Principle — we take practical steps to protect personal data.
  5. Retention Principle — we keep personal data only as long as necessary.
  6. Data Integrity Principle — we take reasonable steps to keep data accurate and up to date.
  7. Access Principle — you may request access to and correction of your personal data.

3. Personal data we collect

Category Examples
Identity & contact data Name, billing and delivery address, email address, telephone/WhatsApp number.
Order & transaction data Products and services ordered, order history, design/model variants selected, and correspondence about your orders.
Payment data Processed by our payment providers (e.g. Shopify Payments, PayPal, Stripe). We do not store complete card numbers; we receive transaction confirmation and limited billing details.
Account & subscription data Login credentials, subscription status, preferences and settings.
Service-delivery data Information you provide so we can perform services (e.g. project briefs, brand assets, domain/hosting credentials, analytics access) and content you submit to our tools.
Technical & usage data IP address, device and browser type, operating system, pages viewed, referring URLs and interactions, collected via cookies and similar technologies.
Marketing data Your marketing and communication preferences and consent records.

4. How we collect your personal data

We collect data: (a) directly from you when you order, register, subscribe, contact us or engage our services; (b) automatically through cookies and analytics when you use the Site; and (c) from third parties such as our e-commerce platform, payment processors and fulfilment partners. Providing certain data is necessary to perform a contract with you; if you do not provide it, we may be unable to process your order or deliver services.

5. Purposes and legal bases for processing

Purpose Basis (PDPA / GDPR)
Processing and fulfilling orders, including sending data to print providers and carriers Performance of a contract
Providing, delivering and supporting digital services and subscriptions Performance of a contract
Taking payment and preventing fraud Contract; legitimate interests; legal obligation
Customer support and responding to enquiries Contract; legitimate interests
Direct marketing (where permitted or consented) Consent; legitimate interests
Operating, securing, analysing and improving the Site and services Legitimate interests; consent for non-essential cookies
Meeting legal, tax and accounting obligations Legal obligation

6. Cookies and similar technologies

We use: strictly necessary cookies (cart, checkout, security); functional cookies (preferences); analytics cookies (to understand usage); and, where applicable, advertising cookies. Non-essential cookies are used only with your consent where the law requires it. You can manage cookies through our cookie banner or your browser settings; disabling some cookies may affect Site functionality.

7. Disclosure of your personal data

Consistent with the PDPA Disclosure Principle, we disclose personal data only as necessary to: print-on-demand and fulfilment partners (e.g. Printify and its print providers) to produce and ship merchandise; our e-commerce and hosting platform (Shopify); payment processors; shipping carriers; service providers (analytics, email/marketing, support, IT) acting on our instructions; and regulators, authorities, advisers or acquirers where required by law, to enforce our terms, protect rights, or in connection with a business transfer. We require these parties to protect your data and use it only for the agreed purposes.

8. Direct marketing and your right to opt out

We may send you marketing communications where you have consented or as otherwise permitted by law. In line with section 43 of the PDPA, you may at any time require us to stop processing your personal data for direct marketing by emailing support@digitalxlabs.io or using the unsubscribe link in our emails. We will comply without charge.

9. Cross-border data transfers

As a global business, we and our partners (including Printify, Shopify and payment processors) may store or process personal data outside Malaysia, including in the United States, the European Union and elsewhere. Where we transfer personal data across borders, we take steps to ensure an adequate level of protection, relying on safeguards such as contractual protections (e.g. Standard Contractual Clauses), the recipient’s adequate protections, or your consent, as permitted under the PDPA and the GDPR.

10. Data security

In accordance with the Security Principle, we maintain appropriate technical and organisational measures — including encryption in transit (TLS), access controls, and the use of reputable, security-vetted processors — to protect personal data against unauthorised or accidental access, processing, loss or destruction. No internet transmission is completely secure, and while we work hard to protect your data, we cannot guarantee absolute security.

11. Data retention and accuracy

We retain personal data only for as long as necessary to fulfil the purposes set out above and to satisfy legal, tax, accounting and dispute-resolution requirements. Order and transaction records are generally retained for up to seven (7) years in line with Malaysian tax and record-keeping requirements. Marketing data is retained until you opt out. We take reasonable steps to keep your data accurate, complete and up to date; please notify us of any changes.

12. Your rights

Under the PDPA you have the right to: access your personal data and request a copy; correct inaccurate, incomplete or out-of-date data; withdraw consent to processing; limit processing for direct marketing; and be informed of disclosures. Under the GDPR (for EU/UK individuals) you additionally have rights to erasure, restriction, objection and data portability, and may complain to a supervisory authority. Under the CCPA/CPRA (for California residents) you may request to know, delete and correct your personal information and opt out of any “sale” or “sharing”; we do not discriminate against you for exercising these rights.

To exercise any right, email support@digitalxlabs.io. We will verify your identity and respond within the time required by law (generally 21 days under the PDPA and one month under the GDPR). We may charge a prescribed fee for a PDPA data-access request where permitted.

13. Data breach notification

In line with the PDPA 2024 amendments, if a personal data breach occurs that is likely to cause significant harm, we will notify the Personal Data Protection Commissioner, and affected individuals where required, within the timeframe prescribed by law (currently as soon as practicable, and to the Commissioner within 72 hours where applicable).

14. Sensitive personal data and children

We do not seek to collect “sensitive personal data” (such as data on health, religious beliefs or political opinions) except where you voluntarily provide it (for example in connection with charitable contributions), in which case we process it only with your explicit consent and for the stated purpose. Our Site and services are not directed at children under 16, and we do not knowingly collect their data; if you believe a child has provided us data, contact us and we will delete it.

15. Third-party links

Our Site may link to third-party websites and services that we do not control. We are not responsible for their privacy practices; please review their policies before providing data.

16. Changes and how to contact us / complaints

We may update this Policy from time to time; the “Last updated” date shows the latest version, and material changes will be notified on the Site or by email where appropriate. For any privacy question, to exercise your rights, or to make a complaint, contact our privacy team at support@digitalxlabs.io or +60 11-1414 1401. See also our Terms of Service. If you are not satisfied with our response, you may lodge a complaint with the Personal Data Protection Department (Jabatan Perlindungan Data Peribadi) of Malaysia or, if applicable, your local data-protection authority.