Legal
Privacy.
What we collect, why, how long we keep it, and how to make us forget.
Last updated · 2026-10-05
Who this covers
This policy covers DIVITEB MEDIA (Selangor, Malaysia), the company operating diviteb.com ("Diviteb", "we", "us"), and you, whether you're a visitor to the site, a prospect who's contacted us, a customer under an active engagement, a job applicant, or a vendor/partner. Where we act as a Processor on behalf of a customer Controller, the customer's privacy notice and our DPA govern the data — this policy covers what we do as a Controller in our own right.
What we collect
We collect information in four buckets: what you give us, what your browser sends with every request, what we measure on the site, and what we share with Meta to measure our ads (see Advertising measurement for exactly when).
- What you give us — name, work email, phone (optional), company, role, budget range, and message when you submit the contact form. Email and list when you subscribe to our newsletter or changelog. With a contact form submission we also keep the Meta ad click ID you arrived with, Meta's browser ID where ad cookies are on, details of the device you used (browser, operating system, device model, screen size, language and time zone, from your browser and its user agent), and your approximate city, region and postal code from your IP address.
- What your browser sends — IP address, user agent, and the page requested, plus the approximate city, region, and postal code that Cloudflare derives from your IP address. Cloudflare and our server use these to deliver the site, stop abuse, and filter automated traffic. Our page-view records never store your raw IP address; events queued for Meta keep it only until shortly after Meta accepts them (see How long we keep it).
- What we measure — one record per page view from a real browser: the page, the referring site's domain, campaign tags (utm_*) and ad click type, country, and device type. Where ad cookies are off (see below), these records carry no identifier, so visits can't be linked to each other or to you.
- Ad cookies — a random visitor ID, the campaign that first brought you here, and Meta's browser and click IDs (see Cookies and Advertising measurement below).
Cookies and browser storage
Essential storage is always on. Ad cookies follow where you are and what you choose: in the EU, EEA, UK, and Switzerland (or when we can't tell where you are) they are written only after you choose Accept all. Everywhere else they are also written before you choose, until you pick Essentials only. Essentials only, in the banner or in Cookie settings (footer), deletes them at once and stops them coming back.
- diviteb.cookie-consent.v1 (local storage) and dv_consent (cookie) — remember your cookie choice, so our pages and our server can respect it. Kept until you change it (the cookie, 1 year). Essential.
- dv_region (cookie) — whether you're browsing from the EU, EEA, UK, or Switzerland, from your IP address, so the rule above applies. 30 days. Essential.
- theme (local storage) — remembers light or dark mode. Kept until you clear it. Essential.
- dv_session (session storage) — the campaign source of this visit, sent with a form if you submit one. Cleared when you close the tab. Essential.
- dv_vid (cookie) — a random ID that links your visits to diviteb.com. 1 year. Ad cookie.
- dv_ft (cookie) — the campaign that first brought you here, so we know which ads lead to real conversations. 90 days. Ad cookie.
- _fbp (cookie) — Meta's browser ID. We set it on diviteb.com with Meta's Parameter Builder; the Meta Pixel uses the same one. 90 days. Ad cookie.
- _fbc (cookie) — the click ID when you arrive from a Facebook or Instagram ad, set the same way. 90 days. Ad cookie.
Advertising measurement (Meta)
We advertise on Facebook and Instagram. Meta tells us which ads lead to visits and inquiries in two ways: the Meta Pixel in your browser, which loads only after you choose Accept all, and events our server sends through Meta's Conversions API. What our server sends depends on where you are and what you choose:
- Outside the EU, EEA, UK, and Switzerland — our server sends the events below with the hashed identifiers listed, whatever you choose in the banner. We do this on our legitimate interest in measuring our advertising and preventing fraud. You can object at any time (see Opting out).
- In the EU, EEA, UK, and Switzerland (or when we can't tell where you are) — with Accept all, the same. Otherwise we send only contact form submissions, newsletter sign-ups, contact clicks, and page content views, carrying just the event, the page, your IP address and user agent, and the ad click ID you arrived with: no hashed identifiers, no location, no browser ID. Page views aren't sent at all.
- Events — page views, page content views, contact clicks (email, phone, booking), contact form submissions, and newsletter sign-ups. Later, when we mark your inquiry as qualified or you become a customer, our server sends one event for each of those steps, so we can see which ads bring real customers rather than form fills.
- Data sent — event name and time, page URL, a random event ID (so Meta counts each event once), your IP address and user agent, _fbp and _fbc, our visitor ID (hashed), and the approximate city, region, postal code, and country from your IP address (hashed). For a contact form submission, also your email, phone, and name; for a newsletter sign-up, your email. Each is hashed with SHA-256 before it leaves our server. A contact form submission also carries the budget range you picked. The qualified and customer events carry the same hashed contact details, our visitor ID (hashed), and the Meta click and browser IDs stored with your inquiry.
- Meta's role — Meta receives this data under its Business Tools Terms and is an independent controller for its own use of it, including ad delivery and its own products. See Meta's Privacy Policy at facebook.com/privacy/policy.
- Opting out — Essentials only, in the cookie banner or in Cookie settings (footer), turns off the Meta Pixel and deletes our ad cookies and Meta's cookies on diviteb.com. To object to the server events tied to your email address (contact form, newsletter sign-up), email [email protected] and we'll stop sending them. You can also manage ad preferences in your Facebook or Instagram settings.
- We don't use Meta's automatic event setup, and we don't send the content of your message to Meta.
Emails we send
We send email through Cloudflare Email Sending. When you contact us, we reply right away with a confirmation; when you subscribe, we ask you to confirm.
- Opens and clicks — our confirmation, subscription, and newsletter emails contain a small image and links served from diviteb.com. When they load, we record that the email was opened or a link was clicked, with the time. We use this to check our email reaches people and which content is useful. Blocking images in your mail app stops open tracking.
- Mail scanners — security scanners often open emails and links automatically. We flag those events so they don't count as you.
- Delivery status — Cloudflare tells us whether each email was delivered, deferred, or bounced. Addresses that hard-bounce or mark us as spam go on a suppression list so we stop sending to them.
- Unsubscribing — every marketing email has a one-click unsubscribe link.
What we don't do
We don't sell personal data or share it with data brokers. We don't fingerprint browsers. We don't build profiles of you across other websites. We don't send your data to any advertising platform other than Meta, and only as described under Advertising measurement. If we add another tracker, we'll name it here and in the cookie banner before it loads.
Why we collect each thing
We handle personal data in line with Malaysia's Personal Data Protection Act 2010 (PDPA) and, for visitors and customers in the EU/EEA or UK, the GDPR and UK GDPR. Where the GDPR applies, we rely on these legal bases:
- Consent — the Meta Pixel; ad cookies and Conversions API events with hashed identifiers for visitors in the EU, EEA, UK, and Switzerland; and marketing emails (newsletter, changelog). You can withdraw at any time; it doesn't affect processing that happened before.
- Legitimate interests — running diviteb.com securely, filtering automated traffic, counting page views without identifiers, replying to your inquiry, checking our emails are delivered and read, and measuring our advertising: the Conversions API events and ad cookies described above for visitors outside the EU, EEA, UK, and Switzerland, and the stripped conversion events (no identifiers) inside them. You can object to this at any time.
- Performance of a contract — delivering an engagement once you've signed an SOW, and the steps you ask us to take before that.
- Legal obligation — keeping records that tax, accounting, and regulatory authorities require.
How long we keep it
We delete data on a schedule. An automated job applies these limits several times a day.
- Contact form submissions — kept, with the browser and device details and approximate location stored with them, until you ask us to delete them (email [email protected]). Submissions we mark as spam are deleted after 30 days.
- Page-view and click records, and visitor IDs — 13 months.
- Data queued for Meta — IP address, user agent, and hashed identifiers are removed 24 hours after Meta accepts the event; the remaining record (event name, time, and the names of the fields that were sent, never their values) is deleted after 90 days. An event Meta never accepts stops retrying after 7 days and is deleted, with everything in it, after 30 days.
- Email records (status, opens, clicks) — kept with the related inquiry; otherwise 13 months. Email bodies are removed from our queue 24 hours after sending.
- Newsletter subscriptions — until you unsubscribe. Unconfirmed sign-ups are deleted after 30 days. We keep a record of unsubscribes and suppressed addresses so we never email you again by mistake.
- Counts of blocked automated requests — 30 days, as daily totals with no personal data.
- Objections to ad measurement — the email address, kept for as long as we advertise, so we keep honoring your request.
- Security logs — only as long as needed to investigate abuse.
Who processes it
We keep your data on our own server and use a small number of providers to run the site:
- Cloudflare — DNS, content delivery, security filtering, and sending and receiving our email.
- Our server host — the virtual private server that runs diviteb.com and its database.
- Meta Platforms — advertising measurement, as described under Advertising measurement.
Your rights
Depending on where you live, you have one or more of the following rights under data-protection law: access, correction, deletion, restriction, portability, objection, and withdrawal of consent. We honor these regardless of jurisdiction where it's reasonable.
- To exercise any right, email [email protected] with the subject 'Privacy request' and the right you want to exercise.
- We respond within 30 days. Where the request is complex we may extend by another 60 days and tell you why.
- We don't charge a fee for routine requests. Repeated, manifestly unfounded, or excessive requests may incur a reasonable administrative fee.
- If you're unhappy with our response, you can complain to your local supervisory authority.
International transfers
Diviteb is based in Malaysia. Some providers (Cloudflare and Meta) operate in the US and elsewhere, so your data may be processed outside your country, with the safeguards the PDPA requires. Where personal data is transferred outside the EEA/UK/Switzerland, we rely on the EU Standard Contractual Clauses (2021) plus the UK International Data Transfer Addendum, supplemented by additional safeguards where the transfer impact assessment requires them.
Advertising services
When we manage advertising for a customer, we work inside the customer's own ad accounts (for example their Meta business portfolio, Google Ads, TikTok, or LinkedIn accounts) through partner access the customer grants and can revoke. In that role we act as the customer's Processor, under their instructions and our DPA.
- Data involved — campaign performance, aggregated audience insights, lead-form submissions, and conversion events sent by the customer's website or app.
- Customer lists — uploaded only by or for the customer, hashed before matching, and used under each platform's custom audience terms.
- Tracking — conversion tags and APIs we install fire only in line with the customer's consent mechanism and the platforms' business tool terms.
- Ownership — the ad accounts, pixels or datasets, audiences, and data stay with the customer; when an engagement ends, our access is removed.
Engagement data
When we work with you under contract, we process customer Personal Data only as instructed in that contract and the accompanying DPA. Your data lives in your systems wherever practical; we don't replicate it into ours unless the engagement requires it. Sub-processor list and security measures are in our DPA.
Children's data
diviteb.com isn't directed at children, and we don't knowingly collect data from children under 16. If you believe we have, contact [email protected] and we'll delete it.
Marketing & consent
We send marketing emails only to people who've subscribed to a list (newsletter, changelog) or are in active conversation with us about an engagement. Every email has an unsubscribe link in the footer. Unsubscribing applies to that list; you can still receive transactional or service emails relating to an engagement.
Changes to this policy
When we update this policy in a material way, we update the Last updated date at the top, post a note in our changelog, and email anyone on our marketing lists. The current version always lives at this URL.
Contact
Email [email protected] for any privacy question, request, or concern. For DPA negotiation or vendor security questionnaires, route to [email protected].
Legal questions
Reach out before you sign.
We'll redline your master agreement, sign your NDA, and clear procurement before kickoff.