Privacy Policy
Altream Sdn Bhd (operating as NeurometriX)
Last Updated: March 2026 | Effective: January 2025
1. About Us
Altream Sdn Bhd ("Altream", "we", "us", "our") operates NeurometriX, a neuroscience-based talent assessment platform accessible at neurometrix.io. Altream Sdn Bhd (formerly known as Streamz Holding Sdn Bhd) is a company incorporated in Malaysia, registered with the Companies Commission of Malaysia (SSM Registration No: 202501005010 (1606424-P)).
For the purposes of the Malaysian Personal Data Protection Act 2010 (as amended in 2024) ("PDPA"), the EU General Data Protection Regulation ("GDPR"), and the California Consumer Privacy Act ("CCPA"), Altream Sdn Bhd is the data controller responsible for your personal data processed through the NeurometriX platform.
This Privacy Policy describes how we collect, use, store, share, and protect your personal data when you interact with our platform, website, and related services (collectively, the "Services"). By using our Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with the practices described herein, please do not access or use our Services.
2. What Data We Collect
2.1 Employers & Hiring Managers
- Account Information: Full name, work email address, company name, job title, phone number, and profile avatar.
- Billing Data: Payment details are collected and processed securely by our payment processor, Stripe. We do not store full credit card numbers on our servers. We retain only the last four digits, card brand, and expiration date for reference purposes.
- Usage Data: IP address, browser type and version, operating system, pages visited, features used, access timestamps, referral URLs, and session duration.
2.2 Candidates
- Identity Information: Full name and email address as provided by the employer or entered during assessment onboarding.
- Assessment Behavioral Data: Interaction data captured during neuroscience-based cognitive games, including response times (millisecond precision), click patterns, accuracy metrics, error rates, task-switching behaviour, and decision sequences.
- Derived Trait Scores: Cognitive and behavioural trait scores computed by our proprietary scoring engine, including but not limited to working memory, cognitive flexibility, emotional regulation, attention control, risk tolerance, and processing speed.
- Device Information: Device type, screen resolution, browser fingerprint (hashed), operating system, and language settings. This information helps us ensure assessment integrity and optimise the experience.
Biometric Data Notice
Under the PDPA 2024 amendments, behavioural biometric data (including patterns derived from keystroke dynamics, mouse movements, and game interaction sequences) is classified as sensitive personal data. We process this data solely for the purpose of generating cognitive trait scores and do so only with your explicit consent obtained prior to assessment commencement. This data is never used for identification or surveillance purposes.
Webcam Proctoring
NeurometriX offers optional webcam-based proctoring to help employers verify assessment integrity. When enabled by the employer, you will be clearly notified and asked for explicit consent before your camera is activated. Webcam proctoring performs real-time presence detection only — video is NOT recorded, stored, or transmitted. The webcam feed is analysed locally in your browser to detect the presence of a single test-taker and flag potential anomalies (e.g., absence from frame, multiple faces). Only binary flag data (present/absent/anomaly timestamps) is sent to our servers.
3. How We Use Your Data
We process your personal data for the following purposes:
- Provide and Operate Services: To deliver our assessment platform, create and manage accounts, administer cognitive games, and generate assessment reports.
- Compute Trait Scores: To analyse behavioural data collected during assessments and compute cognitive and behavioural trait scores using our proprietary algorithms and AI models.
- Match Candidates to Roles: To compare derived trait profiles against job benchmarks configured by employers and produce fit scores and ranking insights.
- Send Invitations and Notifications: To send assessment invitations to candidates on behalf of employers, deliver results notifications, and communicate important account or service updates.
- Improve the Platform: To analyse aggregate usage patterns, refine our scoring algorithms, improve game design, conduct research, and develop new features that enhance the user experience.
- Comply with Legal Obligations: To meet our obligations under applicable laws, regulations, and legal processes including tax reporting, audit requirements, and responses to lawful government requests.
- Prevent Fraud and Ensure Security: To detect, investigate, and prevent fraudulent activity, cheating during assessments, unauthorised access, and other security threats to protect the integrity of our platform and our users.
4. Legal Basis for Processing
We rely on the following legal bases under the PDPA 2010 (as amended 2024) and the GDPR to process your personal data:
- Consent: You provide explicit consent before commencing an assessment, enabling webcam proctoring, or opting into marketing communications. Under the PDPA 2024 amendments, consent is mandatory for processing sensitive personal data including behavioural biometric data. You may withdraw your consent at any time by contacting us.
- Performance of a Contract: Processing is necessary to fulfil our contractual obligations to employers (subscription agreements) and to candidates (providing the assessment experience and delivering results).
- Legitimate Interest: We process certain data where we have a legitimate business interest that is not overridden by your rights, including platform security, fraud prevention, service improvement, and aggregate analytics. We conduct balancing tests to ensure our interests do not disproportionately impact your privacy.
- Legal Obligation: Processing is necessary to comply with our legal obligations under Malaysian law (including tax and corporate regulations), EU law, and other applicable jurisdictions.
5. Data Sharing
We share personal data only with trusted third parties who assist us in operating our platform, and only to the extent necessary. All third-party processors are bound by data processing agreements (DPAs) that require them to protect your data.
Service Providers
- Anthropic:We use Anthropic's AI models to generate natural-language assessment reports and candidate insights. Anonymised trait scores and job context are sent for report generation. No raw behavioural data or candidate names are shared with Anthropic.
- Resend: We use Resend for transactional email delivery, including assessment invitations, result notifications, and account communications. Recipient email addresses and message content are processed by Resend.
- Stripe: We use Stripe for payment processing. Billing details are collected directly by Stripe and are subject to Stripe's Privacy Policy.
- Amazon Web Services (AWS): Our infrastructure is hosted on AWS. All data is stored and processed within AWS data centres with enterprise-grade physical and network security.
What We Do NOT Do
- We do NOT sell your personal data to any third party, ever.
- We do NOT share data between tenants. Each employer's candidate data is strictly isolated. Employer A cannot access data belonging to Employer B.
- We do NOT use your data for advertising or share it with ad networks, data brokers, or social media platforms.
6. International Data Transfers
NeurometriX operates infrastructure across multiple AWS regions to serve our global user base:
- US-East (us-east-1): North American customers.
- EU-West (eu-west-1): European Economic Area customers.
- APAC (ap-southeast-1): Asia-Pacific customers, including Malaysia and Southeast Asia.
Data originating from Malaysian users is stored in the APAC region (ap-southeast-1, Singapore) by default, ensuring proximity and compliance with PDPA requirements regarding cross-border data transfers.
Where personal data is transferred outside the originating region (for example, when utilising global service providers), we ensure appropriate safeguards are in place, including EU Standard Contractual Clauses (SCCs) and executed Data Processing Agreements (DPAs) with all sub-processors. For transfers from Malaysia, we comply with Section 129 of the PDPA 2010 regarding cross-border data transfers and ensure the receiving jurisdiction provides an adequate level of data protection.
7. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes described in this policy or as required by law. Our specific retention periods are:
- Assessment Data330 days from assessment completion
- Employer Account DataDuration of subscription + 90 days
- Billing Records7 years (Malaysian tax law requirement)
- Audit Logs2 years
Upon expiration of the applicable retention period, personal data is securely deleted or anonymised. Anonymised data that can no longer be linked to an individual may be retained indefinitely for research, statistical analysis, and platform improvement purposes.
You may request early deletion of your data at any time by contacting us at privacy@neurometrix.io, subject to any legal obligations that require us to retain certain records.
8. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data. We honour these rights under the PDPA 2010 (as amended 2024), GDPR, and CCPA:
- Right of Access: You may request a copy of the personal data we hold about you and information about how it is processed.
- Right to Correction: You may request that we correct inaccurate or incomplete personal data.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.
- Right to Erasure (NEW under PDPA 2024): You may request the deletion of your personal data where it is no longer necessary for the purpose for which it was collected, or where you have withdrawn consent. This right is now recognised under the PDPA 2024 amendments in addition to the GDPR.
- Right to Data Portability (NEW under PDPA 2024): You may request to receive your personal data in a structured, commonly used, machine-readable format (such as JSON or CSV) and have it transmitted to another data controller where technically feasible.
- Right to Object: You may object to the processing of your personal data where processing is based on legitimate interests. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests.
- Right to Restrict Processing: You may request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or have objected to processing pending verification.
How to exercise your rights: Send your request to privacy@neurometrix.io with sufficient detail to identify yourself and specify which right(s) you wish to exercise. We will respond to all verifiable requests within 21 calendar days in accordance with PDPA timelines. For GDPR requests, we will respond within 30 days. If we require additional time, we will notify you of the extension and the reasons for the delay.
10. Security
We implement comprehensive technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction:
- Encryption at Rest: All personal data is encrypted using AES-256 encryption at rest across all storage systems, including databases, backups, and file storage.
- Encryption in Transit: All data transmitted between your browser and our servers is protected using TLS 1.3 encryption. We enforce HTTPS across all endpoints with HSTS headers.
- SOC 2-Aligned Controls: Our security programme is aligned with SOC 2 Type II standards covering security, availability, and confidentiality. We conduct regular penetration testing and vulnerability assessments.
- Access Controls: Role-based access control (RBAC), multi-factor authentication for administrative access, and the principle of least privilege across all internal systems.
Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the Personal Data Protection Commissioner (PDP Commissioner) within 72 hours of becoming aware of the breach, in compliance with the PDPA 2024 mandatory breach notification requirement and GDPR Article 33. Affected individuals will be notified within 7 days of the breach determination where the breach is likely to result in high risk to their rights and freedoms.
11. Children's Privacy
Our Services are designed for professional hiring and talent assessment purposes and are not intended for individuals under the age of 18. We do not knowingly collect, solicit, or process personal data from minors.
If you are a parent or guardian and believe that your child has provided personal data to NeurometriX, please contact us immediately at privacy@neurometrix.io. We will promptly investigate and delete any such data from our systems.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
- Update the "Last Updated" date at the top of this page.
- Notify registered users via email and/or a prominent notice within the platform at least 14 days before the changes take effect.
- Where required by law, obtain your renewed consent before applying the updated terms to your data.
Your continued use of the Services after the updated Privacy Policy becomes effective constitutes your acceptance of the changes. If you do not agree with the updated terms, you should discontinue use of the Services and contact us to exercise your rights regarding your personal data.
13. Contact Us & Data Protection Officer
If you have any questions, concerns, or requests regarding this Privacy Policy or our data protection practices, please contact us using the details below:
Data Protection Officer (DPO)
Appointed in compliance with the PDPA Amendment 2024 requirement for organisations processing sensitive personal data.
Email: dpo@neurometrix.io
Privacy Team
Email: privacy@neurometrix.io
Legal Department
Email: legal@neurometrix.io
Regulatory Authority
If you are unsatisfied with our response to your privacy concern, you have the right to lodge a complaint with the relevant supervisory authority. In Malaysia, this is the Jabatan Pelindungan Data Peribadi (JPDP) — the Department of Personal Data Protection:
Website: pdp.gov.my
For users in the EU/EEA, you may also lodge a complaint with your local Data Protection Authority. For users in California, you may contact the California Attorney General's office.