Privacy Policy

Last Updated: 24 October 2025
Version 1.0

Data Sovereignty Guaranteed

At Xeep, we believe your physiological intelligence data belongs to you. Our privacy policy ensures Malaysian-hosted, end-to-end encrypted protection of your most personal health information.

End-to-End Encryption

All your physiological data is encrypted from device to storage, ensuring only you can access your information.

Malaysian-Hosted

Your data stays within Malaysia's borders, protected by local data protection laws and regulations.

Transparent Data Use

We're transparent about how your anonymized data helps improve wellness for all Malaysians.

1. Introduction

Welcome to Xeep. This Privacy Policy explains how XEEP PLT (Company Registration No. 202504002688) ("Xeep," "we," "us," or "our") collects, uses, shares, and protects your personal information when you use our wellness intelligence platform, including our website (xeep.io), mobile applications (iOS and Android), and Xeep Device (smart wellness wearable).

Your privacy is important to us. We are committed to protecting your personal data and complying with the Personal Data Protection Act 2010 (PDPA) of Malaysia and other applicable data protection laws.

By using Xeep's services, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with this Privacy Policy, please do not use our services.

2. Information We Collect

We collect several types of information to provide you with our services and improve your wellness experience.

2.1 Personal Information You Provide

When you create an account or use our services, you provide us with:

Account Information

  • • Full name
  • • Email address
  • • Phone number
  • • Date of birth (for age verification and personalized insights)
  • • Malaysian Identity Card (IC) number (optional, for identity verification)
  • • Password (encrypted and not accessible by Xeep staff)
  • • Profile photograph (optional)
  • • Gender
  • • Height and weight

Payment Information

  • • Credit card details (processed securely by HitPay, our payment processor)
  • • Billing address
  • • Subscription transaction history (including initial hardware delivery and recurring platform access fees)

Communication Data

  • • Support inquiries and correspondence
  • • Feedback and survey responses
  • • Messages to our customer service team

2.2 Health and Wellness Data Automatically Collected

When you use your Xeep Device and our platform, we automatically collect:

Nine Primary Health Data Streams

1. Heart Rate: Continuous measurements (288 readings per day, 5-minute intervals)

2. Blood Oxygen Saturation (SpO2): Periodic measurements (144 readings per day, 10-minute intervals)

3. Blood Pressure: Algorithmic estimates based on sensor data (60-85% confidence level) - NOT medical-grade measurements

4. Sleep Data: Duration, stages (light, deep, REM), efficiency, and quality metrics

5. Physical Activity: Steps, distance, calories burned, active minutes, exercise sessions

6. Stress Levels: Real-time stress indicators based on heart rate variability

7. Heart Rate Variability (HRV): Measurements indicating autonomic nervous system balance

8. XQ (Flow State) Scores: Our proprietary wellness intelligence metric calculated from your health data

9. Wellness Checks: Multi-metric manual assessments you perform

Additional Data

  • • Device usage patterns and interaction data
  • • App navigation and feature usage
  • • Notification settings and preferences
  • • Dashboard customization preferences
  • • Cycle tracking data (for applicable users)
  • • Meal and nutrition logs (if you use this feature)
  • • Symptom tracking and health notes

2.3 Technical and Device Information

We automatically collect technical information about your device and how you use our services:

  • • Device identifiers (Xeep Device serial number, mobile device ID)
  • • IP address (last octet masked for privacy)
  • • Device model, operating system, and version
  • • Browser type and version
  • • Mobile network information
  • • Approximate location (state/region level only, derived from IP address)
  • • Time zone settings
  • • Language preferences
  • • App version and build number
  • • Crash reports and error logs

2.4 Cookies and Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience. Please see our Cookie Policy for detailed information about:

  • • Essential cookies for authentication and security
  • • Analytics cookies for platform improvement
  • • Preference cookies for customization
  • • How to manage your cookie preferences

3. How We Use Your Information

We use your personal information for the following purposes, all lawfully processed under the Personal Data Protection Act 2010 (PDPA):

3.1 To Provide Our Core Services

XQ Score Calculation

We process your health data through our proprietary algorithm to generate your personalized XQ (Flow State Intelligence) score, which predicts your optimal times for focused work, creativity, and wellness activities.

AI-Powered Wellness Insights

We use artificial intelligence and machine learning to analyze your health patterns and provide personalized recommendations for improving your wellness, sleep, stress management, and productivity.

Real-Time Health Monitoring

We process continuous data from your Xeep Device to display your current health metrics, trends, and alerts in your dashboard.

Historical Analysis

We store and analyze your historical health data to identify long-term patterns, improvements, and areas needing attention.

3.2 To Improve Our Platform and Algorithm

Algorithm Training and Enhancement

We use aggregated and anonymized health data from all users to continuously improve the accuracy and reliability of our XQ algorithm, making it more effective for Malaysian users specifically.

Platform Optimization

We analyze how users interact with our platform (which features are used most, where users encounter difficulties) to improve the user experience and add requested features.

Bug Detection and Fixing

We use error logs and crash reports to identify and resolve technical issues, ensuring platform stability and reliability.

Additional Uses

  • • To train and improve our artificial intelligence models and algorithms. This involves using your data as part of a larger, collective dataset to enhance the insights provided to all users.
  • • Incorporate User-Generated Content, such as meal suggestions, into our central database to enhance the service for all users.

3.3 For Research and Data Flywheel

Malaysian Health Research

With your consent (opt-out available), we create anonymized datasets from your health data to advance wellness research in Malaysia. This helps us understand Malaysian health patterns, develop better wellness insights, and contribute to public health knowledge.

Commercial Data Licensing: We license anonymized datasets to academic institutions, healthcare providers, pharmaceutical companies, and government health agencies. Your identifiable personal information is NEVER shared with third parties. All data is irreversibly anonymized using industry-leading privacy techniques (k-anonymity ≥20, differential privacy, HIPAA Safe Harbor compliance).

Your Data Helps Others

Your contribution to our data flywheel enables us to keep subscription prices affordable (RM39 Lite, RM59 Pro) while building the largest Malaysian wellness intelligence dataset to improve health outcomes for all Malaysians.

Data Contribution is Mandatory (No Opt-Out)

Contributing your anonymized health data to research and our data flywheel is a mandatory, non-negotiable condition of using Xeep services. There is no opt-out mechanism available.

Why This Is Required: Your data contribution is what makes Xeep affordable. Our business model relies on the data flywheel:

  • • You receive premium hardware (RM78-138 value) included with your subscription
  • • You pay only RM39-59/month (70% below competitors)
  • • Your anonymized data helps us generate B2B revenue that subsidizes consumer pricing
  • • This keeps Xeep accessible to all Malaysians

Your Privacy is Protected

While data contribution is mandatory, your privacy remains paramount:

  • • All data is irreversibly anonymized using multi-layer protection (k-anonymity ≥20, differential privacy ε≤0.5, HIPAA Safe Harbor)
  • • Cannot be traced back to you individually
  • • Your identifiable personal data is never sold or shared
  • • You retain the right to access, correct, and delete your identifiable data

Alternative Options

If you are uncomfortable with mandatory data contribution for research:

  • • Consider standalone fitness trackers (Apple Watch, Garmin) at RM1,500-3,000 upfront
  • • These devices don't require data sharing but lack AI insights and cost significantly more
  • • You fully own your data but pay premium pricing

This mandatory data license is explicitly stated in our Terms of Service Section 5.4 and is a condition of creating a Xeep account.

3.4 For Communication and Customer Support

  • • Respond to your inquiries and provide technical support
  • • Send you service-related notifications (account activity, subscription status, device pairing)
  • • Deliver important updates about our services, Privacy Policy, or Terms of Service
  • • Request feedback about your experience with Xeep
  • • Send marketing communications (only with your consent; you can opt out anytime)

3.5 For Security and Fraud Prevention

  • • Detect and prevent unauthorized account access
  • • Protect against fraudulent transactions and abuse of our services
  • • Investigate and respond to security incidents
  • • Comply with legal obligations and law enforcement requests

3.6 For Legal Compliance and Business Operations

  • • Comply with applicable Malaysian laws and regulations
  • • Enforce our Terms of Service and other legal rights
  • • Process payments and manage subscriptions
  • • Maintain business records and financial reporting
  • • Facilitate potential business transactions (mergers, acquisitions) with continued privacy protections

4. Data Sharing and Disclosure

We take your privacy seriously and only share your information in limited circumstances:

4.1 What We NEVER Share

We will NEVER:

  • • Sell your identifiable personal information to third parties
  • • Share your name, email, IC number, or contact details for marketing purposes
  • • Provide your personal health data to insurers for underwriting decisions
  • • Share your data with employers for hiring or performance evaluations
  • • Use your health data to discriminate against you in any way
  • • Share your identifiable data with researchers or commercial partners

4.2 Service Providers We Work With

We share limited data with trusted third-party service providers who help us operate our platform:

Firebase (Google Cloud Platform)

  • Purpose: Cloud database storage, user authentication, security
  • Data Shared: All user data (stored with AES-256 encryption)
  • Location: Google Cloud servers (may be outside Malaysia)
  • Privacy Policy: https://firebase.google.com/support/privacy
  • Data Processing Agreement: Google Cloud Terms of Service

HitPay Payment Gateway

  • Purpose: Process subscription payments securely
  • Data Shared: Email, subscription plan, payment amount (credit card details processed directly by HitPay, NOT stored by Xeep)
  • Location: Singapore
  • Privacy Policy: https://www.hitpayapp.com/privacy
  • Compliance: PCI-DSS Level 1 certified

ReCaptcha (Google)

  • Purpose: Bot protection and fraud prevention for AI analysis endpoints
  • Data Shared: Browser information, interaction patterns
  • Privacy Policy: https://policies.google.com/privacy

Third-Party Service Provider Obligations

All our service providers are contractually obligated to:

  • • Use your data only for the specified purposes
  • • Implement appropriate security measures
  • • Not share your data with others without authorization
  • • Comply with PDPA and international data protection standards

4.3 Anonymized Data Sharing (Research and Commercial)

What Gets Shared

We create anonymized datasets that CANNOT identify you and share them with:

  • • Academic institutions (Malaysian universities) for health research
  • • Healthcare providers for wellness program development
  • • Government health agencies (Malaysian Ministry of Health) for public health insights
  • • Pharmaceutical companies for clinical trial recruitment insights (not medical diagnosis)

How We Protect Your Privacy

  1. 1. Remove ALL Identifiers: Name, email, IC number, phone, address, device serial number, Firebase UID
  2. 2. Generalize Quasi-Identifiers: Date of birth → Age range (5-year buckets: 25-30, 31-35, etc.), Postcode → State/Region only (Selangor, KL, Penang, etc.), Exact timestamps → Time buckets (Morning, Afternoon, Evening)
  3. 3. K-Anonymity (k≥20): Each record is indistinguishable from at least 19 other users
  4. 4. Differential Privacy (ε≤0.5): Add calibrated statistical noise to aggregates
  5. 5. Annual External Audit: Independent privacy experts test our anonymization quality

Re-identification Risk: Our target is <0.05% (less than 1 in 2,000 chance of re-identifying any individual).

4.4 Legal Requirements

We may disclose your information if required by Malaysian law or in response to:

  • • Valid court orders or subpoenas
  • • Law enforcement requests with proper legal basis
  • • National security or public safety investigations
  • • Regulatory inquiries from PDPA Commissioner or other authorities

User Notification: We will notify you within 7 days of any legal disclosure request unless legally prohibited from doing so. We publish the number of legal requests received annually in our Transparency Report.

4.5 Business Transfers

If Xeep is involved in a merger, acquisition, asset sale, or bankruptcy, your personal information may be transferred to the acquiring entity. We will:

  • • Notify you via email and prominent notice on our website 30 days before transfer
  • • Ensure the acquiring entity commits to the same privacy protections
  • • Provide you the option to delete your account before the transfer

5. Data Retention

We retain your information for different periods depending on the type of data and legal requirements:

5.1 Active Accounts

While your account is active:

  • • Personal information (Tier 1): Retained indefinitely
  • • Health data (Tier 2): Retained indefinitely for historical analysis and XQ calculation
  • • Technical logs: Retained for 1 year

5.2 Deleted Accounts

When you delete your account:

Days 1-30 (Cooling-Off Period):

  • • Your account is suspended (cannot log in)
  • • Data is NOT deleted yet
  • • You can cancel the deletion request by contacting support@xeep.io

Day 31-60 (Permanent Deletion):

  • • Personal identifiers (name, email, IC, phone, address) deleted from production database
  • • All identifiable health data removed from our systems
  • • Data purged from backups within 60 days

What Remains After Deletion:

  • • Transaction records: Kept for 7 years (Malaysian Companies Act requirement for financial records)
  • • Anonymized datasets: Cannot be deleted as they no longer contain any information that identifies you (anonymization is irreversible)
  • • Aggregate insights: Statistical information like "Average Malaysian XQ = 68" (company intellectual property)

Confirmation: You will receive an email confirmation when your account deletion is complete (approximately 60 days after request).

5.3 Special Retention Rules

  • Audit Logs: Retained for 1 year for security auditing and fraud prevention
  • Legal Disputes: If you are involved in a legal dispute with Xeep, relevant records retained until dispute resolution plus 7 years
  • Consent Records: Your consent history retained for 7 years to demonstrate PDPA compliance

6. Your Rights Under Malaysia PDPA

Under the Personal Data Protection Act 2010, you have the following rights:

6.1 Right to Access (Data Subject Access Request)

You can request:

  • • A copy of all personal information we hold about you
  • • Complete health data history (all 9 data streams)
  • • Information about how we use your data
  • • Categories of third parties receiving anonymized datasets
  • • Access logs (who viewed your data, when)
  • • Your consent history

How to Request:

Response Time: 14 days (PDPA requires 21 days; we commit to faster service)

Format: CSV, JSON, or PDF report

Cost: First request per year is FREE. Subsequent requests may incur RM20 fee (to prevent abuse).

6.2 Right to Correction

You can request correction of:

  • • Inaccurate personal details (name, email, phone, date of birth)
  • • Profile information (height, weight, gender)
  • • Manual entries (meal logs, symptom notes)

Cannot be Corrected:

  • • Sensor-collected data (heart rate, SpO2, sleep) - reflects actual measurements
  • • Historical XQ scores - calculated from sensor data
  • • Anonymized datasets - already irreversibly de-identified

How to Request:

  • • Simple changes: Update directly in Settings → Account
  • • Complex changes: Email support@xeep.io with supporting evidence

Response Time: 7 days

6.3 Right to Deletion ("Right to Be Forgotten")

How to Delete Your Account:

  • • In-app: Settings → Account → "Delete My Account"
  • • Email: dpo@xeep.io with subject "Account Deletion Request"

Verification Required:

  • • Password confirmation
  • • Email confirmation link
  • • Type "DELETE" to confirm (prevents accidental deletion)

Timeline: 30-day cooling-off period, then permanent deletion within 60 days total.

What Happens:

  • • ALL identifiable data deleted (name, email, IC, health data, photos)
  • • Transaction records retained 7 years (legal requirement)
  • • Anonymized datasets CANNOT be deleted (no longer identifiable)

6.4 Right to Data Portability

Export Your Data:

  • • Button: Settings → Privacy → "Export My Data"
  • • Formats: CSV (Excel-compatible), JSON (developer-friendly), PDF (human-readable)
  • • Delivery: Secure download link within 48 hours
  • • Contents: All health metrics, XQ scores, AI insights, account information

Transfer to Another Platform:

  • • You can download and upload to another wellness platform manually
  • • We do NOT provide direct API integration with competitor platforms

6.5 Right to Withdraw Consent

You can opt out of:

  • • Marketing emails - Settings → Notifications or unsubscribe link
  • • AI-powered personalized insights - Settings → Features (note: this may reduce platform functionality)
  • • Specific third-party analytics cookies - Settings → Privacy → Cookie Preferences

You CANNOT opt out of:

  • • Anonymized data creation and use for research - This is mandatory for all Xeep users
  • • Essential services (XQ calculation, data sync, account security)
  • • Legal compliance (transaction records, audit logs required by law)
  • • Already-created anonymized datasets (anonymization is irreversible)

6.6 Right to Complain

If you're not satisfied with how we handle your data:

Step 1: Contact our Data Protection Officer

Step 2: Escalate to Data Governance Committee

  • • If DPO resolution unsatisfactory
  • • Review: Within 30 days

Step 3: File Complaint with PDPA Commissioner

7. Data Security

We implement industry-standard security measures to protect your personal information:

7.1 Technical Security

Encryption

  • • In Transit: TLS 1.3 encryption for all data transmission
  • • At Rest: AES-256 encryption for all data stored in Firebase
  • • Passwords: Bcrypt hashing (NOT stored in plain text)

Access Controls

  • • Role-based access (RBAC) - employees only access data needed for their job
  • • Multi-factor authentication (MFA) required for admin access to production systems
  • • 100% of production database access logged and audited

Network Security

  • • Firebase App Check (ReCaptcha v3) protects against bot attacks
  • • Rate limiting on API endpoints prevents abuse
  • • IP whitelisting for production database access

Monitoring

  • • 24/7 automated security monitoring
  • • Real-time alerts for suspicious activity
  • • Quarterly security audits

7.2 Organizational Security

Employee Training

  • • Quarterly data privacy and security training for all staff
  • • PDPA compliance certification required

Access Policies

  • • Least privilege principle (minimum access necessary)
  • • Access requests must be justified and logged
  • • Customer Support can only view data with support ticket reference

Vendor Management

  • • All third-party service providers undergo security review
  • • Data Processing Agreements required
  • • Annual vendor security assessments

7.3 Physical Security

Data Centers

Firebase (Google Cloud Platform) data centers with:

  • • 24/7 security personnel
  • • Biometric access controls
  • • Video surveillance
  • • Environmental controls (fire suppression, climate control)

Device Security

  • • Xeep Device firmware encrypted and signed
  • • Secure pairing process with mobile app
  • • Remote device wipe capability (if lost/stolen)

7.4 Incident Response

If a Data Breach Occurs:

  • • Detection and containment within 2 hours
  • • User notification within 72 hours (PDPA best practice)
  • • PDPA Commissioner notification (if user rights/freedoms affected)
  • • Full incident investigation and remediation
  • • Post-incident security improvements

Cyber Insurance: We maintain RM5 million cyber liability insurance coverage.

Responsible Disclosure: If you discover a security vulnerability, please report it to security@xeep.io. We do NOT take legal action against security researchers who report vulnerabilities responsibly.

8. International Data Transfers

8.1 Data Storage Location

Your data may be stored and processed outside Malaysia:

Firebase (Google Cloud Platform)

  • • Data centers in Singapore, Japan, United States, or other regions
  • • Google provides adequate data protection safeguards
  • • Complies with international data protection standards

HitPay (Singapore)

  • • Payment processing in Singapore
  • • Adequate data protection (Singapore PDPA)

8.2 Safeguards for International Transfers

When we transfer data internationally, we ensure:

  • • Adequacy: Destination country has adequate data protection laws
  • • Contractual Protection: Standard Contractual Clauses (SCCs) with service providers
  • • Encryption: All data encrypted in transit and at rest
  • • User Consent: You consent to international transfers by using our services

8.3 Future Expansion

If we expand to serve users in other countries (Singapore, EU, US), we will:

  • • Update this Privacy Policy with specific provisions for those regions
  • • Comply with GDPR (EU), CCPA (California), and other local laws
  • • Provide 30 days notice of material changes

9. Cookies and Tracking

We use cookies and similar technologies. Key highlights:

Essential Cookies (Always Active)

  • • Authentication tokens (keep you logged in)
  • • Security tokens (prevent fraud)
  • • Session management

Analytics Cookies (With Your Consent)

  • • Google Analytics (planned, not yet active)
  • • Custom analytics for platform improvement
  • • Performance monitoring

Preference Cookies

  • • Theme preference (light/dark mode)
  • • Language preference
  • • Dashboard layout

How to Manage

  • • Cookie banner on first visit (Accept All / Essential Only / Customize)
  • • Settings → Privacy → Cookie Preferences
  • • Browser cookie settings

Full Details: See our separate Cookie Policy at https://xeep.io/cookies

10. Children's Privacy

Xeep is intended for users aged 18 years and above only.

We do NOT knowingly collect personal information from children under 18.

If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at dpo@xeep.io. We will delete such information within 30 days.

Age Verification: We require date of birth during registration and will reject accounts for users under 18.

11. Third-Party Links and Services

Our platform may contain links to third-party websites, apps, or services not operated by Xeep:

  • • Research publications citing Xeep data
  • • Health resources and educational content
  • • Payment processor (HitPay) during checkout

We are NOT responsible for:

  • • Privacy practices of third-party websites
  • • Content or services provided by third parties
  • • Data collected by third parties when you leave our platform

Recommendation: Review the privacy policies of any third-party services you access through Xeep.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect:

  • • Changes in our data practices
  • • New features or services
  • • Legal or regulatory requirements
  • • User feedback and industry best practices

12.1 How We Notify You

Material Changes:
  • • Email notification to all users 30 days before changes take effect
  • • Prominent banner on website and mobile app
  • • Require acknowledgment of new Privacy Policy on next login
Non-Material Changes:
  • • Update "Last Updated" date at top of this policy
  • • Notify in monthly newsletter
  • • No action required from users

12.2 Version History

We maintain a complete version history of this Privacy Policy:

Your Rights: If you do not agree with updated Privacy Policy, you may delete your account within 30 days of notification.

13. Contact Us & Data Protection Officer

13.1 Company Information

XEEP PLT

Company Registration No. 202504002688

Registered Address: B-01-09 Savanna Lifestyle Retail, Jalan BBL2, Dengkil, Selangor, Malaysia

13.2 Contact Information

General Inquiries

Data Protection Officer (DPO)

  • • Email: dpo@xeep.io
  • • Subject Line: "Privacy Inquiry - [Your Issue]"
  • • Response Time: 7-14 days

Privacy Complaints

  • • Email: dpo@xeep.io with subject "Privacy Complaint"
  • • Response Time: 48 hours acknowledgment, 7-14 days resolution

Data Requests

Security Issues

13.3 Regulatory Authority

Personal Data Protection Commissioner, Malaysia

Personal Data Protection Department

Level 6, Menara MCMC, Jalan Impact, Cyber 6

63000 Cyberjaya, Selangor, Malaysia

• Email: pdp@pdp.gov.my

• Phone: +603-8911 7000

• Website: https://www.pdp.gov.my

15. Transparency Commitment

We are committed to radical transparency about data usage:

Annual Transparency Report

  • • Published every February at https://xeep.io/transparency-report
  • • Number of users and anonymized datasets created
  • • Third-party data recipients (categories)
  • • Data licensing revenue (aggregate)
  • • Law enforcement requests received
  • • Privacy complaints and resolution
  • • Security incidents (if any)

User Data Dashboard

  • • Settings → Privacy → Data Transparency
  • • See your contribution to research (number of datasets)
  • • View anonymized data usage impact
  • • Export your complete data history anytime

Data Governance

  • • Quarterly Data Governance Committee meetings
  • • Annual external privacy audit (published summary)
  • • User representative on Data Governance Committee (elected annually)

16. Additional Resources

Detailed Information

Data Governance

Support

Last Updated: 24 October 2025 | Effective Date: 24 October 2025 | Version: 1.0

This Privacy Policy is governed by the laws of Malaysia.