The Cedar: Privacy Notice

Effective date: 18 August 2026

Last updated: 17 August 2026

This Privacy Notice describes how Industronics Advansystem Sdn. Bhd., Company Registration No. 202201048001 (1493698-D) ("we", "us", "our"), as the data controller, collects, uses, discloses and protects your personal data when you use The Cedar mobile application (the "App"), the resident app for the building managed with our smart building platform.

This notice is issued under the Personal Data Protection Act 2010 (Act 709) of Malaysia, as amended ("PDPA"). In accordance with section 7(3) of the PDPA, this notice is available in both English and Bahasa Malaysia (see Section 12, Language).

By creating an account or continuing to use the App, you confirm that you have read and understood this notice, and you consent to the processing of your personal data as described in it. Facial recognition is optional and needs its own separate consent, which you give on a dedicated screen and can withdraw at any time (see Section 4). This notice applies to personal data processed both before and after it was issued.

When you provide personal data about another person (for example a household member, family member or visitor), you confirm that you are authorised to act on their behalf, to consent to the processing of their personal data, and to receive this notice for them.

In brief, this notice explains that:

1. Who we are

The App is operated by Industronics Advansystem on behalf of The Cedar by Tribeca, the management of your building. Questions, requests and complaints about personal data should be directed to:

2. Personal data we collect

Data you provide when registering and managing your account:

Data you provide while using the App:

Data collected automatically:

Entry records at the building's access points. When you use your QR pass or your face at an access point, the record of that entry is created and held by the building's own access-control systems (the Nuveq access and lift controller, and the facial recognition terminals), which are operated for your Building Management (see Section 5). The App does not collect, receive or store those entry records, and does not show you a history of your movements in the building. Requests about entry records should be directed to Building Management.

Sources of your data: we collect personal data directly from you through the App, and from the building management that registers or verifies your residency.

Data collected with your device permission (each is optional and requested in context):

Unlocking your building pass with your device (no data collected). Before showing your QR pass, the App asks your phone to confirm it is you, using Face ID or Touch ID on iOS, or fingerprint, face or iris unlock on Android, falling back to your device PIN or passcode. This check is performed entirely by your phone's operating system, which tells the App only whether it succeeded. We never receive, see or store your fingerprint, your face scan or your passcode, and this is separate from, and unrelated to, the building's facial recognition described in Section 4. If your device has no biometric or passcode set up, the pass opens without this check.

Protecting your pass on screen (no data collected). While your QR pass is displayed, the App asks your phone to block screenshots and screen recording. On iOS the App is also told when a screenshot is attempted, so that it can show you a short on-screen explanation. That signal stays on your device: we are not notified, and no record of a screenshot attempt is created or sent to us.

We do not collect data for advertising. The App contains no advertising and no software that profiles or tracks you.

3. Why we process your data and our lawful basis

PurposeData usedBasis
Verify you are a resident and manage your accountIdentity, contact, unit detailsPerformance of residency services; consent
Building access (QR pass)Unit details, access credentialsBuilding security; performance of residency services
Building access by face (optional)Profile photo, face templateYour separate explicit consent, which you may withdraw at any time
Visitor, parcel and facility managementBookings, parcels, vehicle, pet recordsPerformance of residency services
Reports, maintenance and complaints handlingReports and attachmentsPerformance of residency services
Emergency response (SOS)Location, identity, contact detailsVital interest / emergency; consent to the location permission
Voice calls with securityCall audio (relayed in real time, not recorded by us)Performance of the call feature
Notices and service notificationsPhone notification code, contact detailsPerformance of residency services
Legal compliance and securityAny of the above as requiredLegal obligation; legitimate building-safety interest

We do not use your data for marketing and will not send you direct marketing without your separate opt-in consent. We do not sell your personal data.

Supplying your identity, contact and unit details is obligatory: without them we cannot register you as a resident or provide building access. Your profile photograph, and the facial recognition enrollment that depends on it, are voluntary. Declining leaves you with QR pass access and changes nothing else. Vehicle, pet, visitor and household-member details are also voluntary and needed only if you use those features.

4. Facial recognition (biometric data)

The building uses facial recognition terminals at its access points. Facial recognition is optional. Your QR access pass is the standard method and is issued to every resident with an active membership; entry by face is an alternative you may choose, and may stop using at any time:

5. Who we share data with

We do not disclose your personal data to any third party without your consent, except to the following categories of recipient, on a need-to-know basis:

Each service provider is contractually or by its published terms required to protect your personal data to a standard at least equal to that set out in this notice. We do not share your data with advertisers or data brokers.

6. International transfers

Some of your personal data is stored or processed on servers located outside Malaysia:

These transfers are made in accordance with section 129 of the PDPA and the Personal Data Protection Commissioner's Cross Border Personal Data Transfer Guidelines (GP 3/2025), on the basis that each recipient provides an adequate level of protection for your personal data at least equivalent to that afforded under the PDPA. We have carried out and documented a transfer assessment of these recipients, and each transfer is protected by the provider's data processing agreement incorporating contractual data protection clauses. Where a transfer relies on your consent, this notice provides you the recipients and purposes of that transfer before you give it.

7. How long we keep your data

We keep personal data only for as long as it is needed for the purposes above, in line with our retention and disposal schedule under the PDPA Retention Principle and the Personal Data Protection Standard 2015:

8. Your rights

Under the PDPA you have the right to:

To exercise any right, contact the Data Protection Officer listed in Section 1.

9. Security

Personal data is transmitted over encrypted connections (TLS/HTTPS) and stored on access-controlled cloud infrastructure. Access is limited to authorised building management and security personnel. Our service providers process data under data processing agreements that require security safeguards consistent with the PDPA Security Principle. If a data breach occurs that is likely to cause significant harm to you, we will notify the Personal Data Protection Commissioner within 72 hours and affected users within 7 days thereafter, in accordance with the PDPA and our obligations to Apple and Google.

10. Children

The App is intended for adult residents. Household member profiles for minors may only be created by a parent or guardian, who consents to that processing on the child's behalf. We do not knowingly allow minors to register their own accounts. A photograph is optional for a household member profile, as it is for your own. Where a parent or guardian chooses to provide one, it is enrolled into facial recognition on the same optional, consent-based footing set out in Section 4, and the parent or guardian gives that consent on the child's behalf and may withdraw it at any time by removing the photograph.

11. Changes to this notice

We may update this notice from time to time. Material changes will be notified in the App before they take effect, and the "Last updated" date above will change. Continued use after the effective date constitutes acceptance, except that new purposes for sensitive data always require fresh explicit consent.

12. Language

In accordance with section 7(3) of the PDPA, this notice is issued in both English and Bahasa Malaysia. In the event of any inconsistency between the English version and the Bahasa Malaysia version, the English version shall prevail.

13. Contact

Industronics Advansystem Sdn. Bhd.

No. 18, Jalan Industri PBP 9, Taman Perindustrian Pusat Bandar Puchong, 47100 Puchong, Selangor, Malaysia

Email: privacy@industronicsadvansystem.com