Data Privacy
GDPR & Data Privacy Rights
Altream Sdn Bhd (NeurometriX)
Last Updated: March 2026
1. Our Commitment to Data Privacy
Altream Sdn Bhd, operating as NeurometriX, is committed to protecting the privacy and personal data of all individuals who interact with our platform. We comply with the following data protection frameworks:
- Personal Data Protection Act 2010 (PDPA) — Malaysia's primary data protection law, as amended in 2024 to include mandatory breach notification, data portability, and the appointment of a Data Protection Officer.
- General Data Protection Regulation (GDPR) — The European Union's comprehensive data protection regulation governing the processing of personal data of individuals in the EU/EEA.
- UK GDPR— The United Kingdom's retained version of the GDPR, supplemented by the Data Protection Act 2018.
- California Consumer Privacy Act (CCPA) — California's consumer privacy law granting residents rights over their personal information.
2. Your Data Privacy Rights
Depending on your jurisdiction, you have the following rights regarding your personal data. We honour these rights regardless of your location.
Right of Access
Request a copy of all personal data we hold about you, including assessment results and behavioural metrics.
How to exercise: Submit a request via the form below or email dpo@neurometrix.io.
Right to Correction
Request correction of inaccurate or incomplete personal data we hold about you.
How to exercise: Submit a request via the form below or contact your account administrator.
Right to Erasure
Request deletion of your personal data ("right to be forgotten"), subject to legal retention obligations.
How to exercise: Submit a deletion request via the form below.
Right to Data Portability
Receive your personal data in a structured, commonly used, machine-readable format (JSON or CSV).
How to exercise: Submit a portability request via the form below.
Right to Object
Object to processing of your personal data for specific purposes, including profiling and automated decision-making.
How to exercise: Submit an objection via the form below or email dpo@neurometrix.io.
Right to Restrict Processing
Request that we limit how we process your personal data while a dispute or request is being resolved.
How to exercise: Submit a restriction request via the form below.
Right to Withdraw Consent
Withdraw your consent to data processing at any time, without affecting the lawfulness of prior processing.
How to exercise: Submit a withdrawal request via the form below or update your account settings.
3. Data Breach Notification
In the event of a personal data breach, we will take the following actions in accordance with applicable laws:
Notification to the PDP Commissioner — Within 72 hours of becoming aware of a breach, as required by the PDPA 2024 amendments and GDPR Article 33.
Notification to affected individuals — Within 7 days if the breach is likely to result in significant harm to the affected individuals.
Security incidents: Report suspected breaches to security@neurometrix.io.
4. Data Protection Officer (DPO)
In compliance with the PDPA 2024 amendments, Altream Sdn Bhd has appointed a Data Protection Officer responsible for overseeing our data protection strategy and ensuring compliance with applicable data protection laws.
Data Protection Officer
dpo@neurometrix.io5. Submit a Privacy Request
Use the form below to exercise any of your data privacy rights. We will verify your identity before processing your request.
6. Regulatory Authorities
If you are not satisfied with our response to your privacy request, you have the right to lodge a complaint with the relevant supervisory authority:
Malaysia — Jabatan Pelindungan Data Peribadi (JPDP)
The Personal Data Protection Department, responsible for enforcing the PDPA 2010.
pdp.gov.myEuropean Union — Local Data Protection Authority
EU residents may lodge a complaint with their local supervisory authority. Each EU member state has its own Data Protection Authority (DPA).
United Kingdom — Information Commissioner's Office (ICO)
The UK's independent authority set up to uphold information rights in the public interest.
ico.org.uk