Datanah policies

Privacy Policy

How Datanah handles the information needed to run a property research service.

Effective 10 August 2026

1. Information we handle

When you create or use an account, we handle your name and email address, along with saved research and alert preferences. If you contact us, we store the name, email address, message and support topic you submit. Request information is processed transiently to prevent abuse; we do not store a raw IP address with your support message.

We also keep authentication and security logs. These may include a hashed IP address and browser or device information used to protect accounts and investigate misuse. Our first-party analytics do not use analytics cookies. They record page paths, referrer origins, campaign parameters, device class, sanitised search terms and selected product actions. For general traffic counts, a daily-rotating hash prevents anonymous visits from being linked across days. Some events performed while you are signed in, such as signing in or saving research, are linked to your account's internal user ID.

2. Why we use it

We use this information to create and secure accounts, provide saved research and alerts, operate and improve Datanah, respond to support requests, and meet applicable legal obligations. We do not sell personal information.

3. Service providers and payments

We use Resend to send service emails, including contact-form notifications, and infrastructure providers for hosting and database operations. If payments are introduced, Curlec is planned to process payments. Datanah will receive transaction references, payment status and related account information needed to provide paid access, but will not store full card or bank-account details.

These providers may process information in countries where they or their infrastructure operate. We require service providers to protect information and handle it only for the contracted service, subject to their legal obligations.

4. Retention and protection

Raw analytics events, including account-linked events, are deleted after 18 months; aggregate analytics rollups may be retained without a fixed expiry. Other information is retained for as long as reasonably needed for account operations, security, support, legal obligations and dispute handling.

Our login session cookie is HttpOnly and SameSite=Lax, is marked Secure in production, and expires after 30 days. One-time login codes expire after 10 minutes. We use reasonable technical and organisational measures designed to protect information, but no online service can guarantee absolute security.

5. Your choices and rights

Subject to applicable Malaysian data-protection law, you may ask to access or correct your personal information, withdraw consent where processing depends on consent, opt out of direct marketing, or raise a privacy concern. You may also ask us to delete information, although we may need to retain some records for security, legal or operational reasons. To make a request, use our contact page.

6. Updates

We may update this policy as Datanah changes or legal requirements develop. We will post the revised policy here with an updated effective date.