Privacy policy
Last updated July 28, 2026
Trigger Next Sdn Bhd [201101011123 (939253-K)]
25-1 Jalan Tasik Selatan 3,Bandar Tasik Selatan,57000 Kuala Lumpur,MalaysiaThis policy explains how we handle personal data around AlarmNX: what we collect through this website, what the AlarmNX mobile app and the cloud relay behind it process, and what never reaches us at all because it stays inside your own AlarmNX installation. It is written to meet our obligations under the Personal Data Protection Act 2010 of Malaysia (the PDPA). We keep it in plain language so you can see exactly what we collect and why.
Who we are
This website is operated by Trigger Next Sdn Bhd, company registration number 201101011123 (939253-K), the data controller for personal data collected here. Our registered address is 25-1 Jalan Tasik Selatan 3, Bandar Tasik Selatan, 57000 Kuala Lumpur, Malaysia, and our phone number is +603 9056 4888. AlarmNX is our on-premise alarm management and notification product. We also operate the cloud relay that carries AlarmNX mobile push notifications, and the web portal that comes with it.
The three places this policy covers
Personal data appears in three different places around AlarmNX, and they work differently:
- This website, where you can send us a demo or contact request.
- The AlarmNX mobile app, together with the cloud relay and web portal that carry its notifications. We operate that service.
- Your own AlarmNX installation, which runs on your network under your control. We do not receive the data inside it.
The sections below take each in turn.
What we collect on this website
On this website, we only collect personal data that you choose to send us through the two forms.
When you request a demo, we collect your name, work email address, company, role, phone number if you provide it, and any message you write about what you would like to see.
When you use the contact form, we collect your name, work email address, the subject of your message, and the message itself.
For both forms, our server also records the network address (IP address) of the device you submit from, your browser user agent string, and the date and time of the submission. We record this to confirm the request is genuine and to keep a basic record of when it was received.
Why we collect it
We use the personal data you submit for one purpose: to respond to your demo or contact request and to follow up with you about it. We do not use it for unrelated marketing, and we do not sell it.
Where form submissions are stored
Submissions are stored in a server-side database on infrastructure that we manage in Malaysia, and a copy of each submission is delivered to our own team by email so we can respond quickly. Access is limited to staff who need it to respond to your request. Nightly backup copies protect submissions against a fault, and each backup is replaced in rotation after roughly two weeks.
How long we keep it
We keep your submission until the purpose it was collected for has been met, for example once your demo has taken place or your inquiry has been closed and any follow-up is complete. We review stored submissions at least once a year and remove records that are no longer needed.
Sharing your form data
We do not sell or rent your personal data, and we do not share it for marketing. The details you submit stay with Trigger Next Sdn Bhd and are used only by our own team to answer your request. One technical exception applies to the forms themselves, described in the next section.
Spam prevention on forms
The demo and contact forms are protected by reCAPTCHA, a service operated by Google. When you submit a form, reCAPTCHA sends your IP address and information about how you interacted with the page to Google, which returns a score telling us how likely the submission is to be automated. We use that score only to decide whether a submission is genuine, and we store it alongside your submission so we can tell a real enquiry from a machine one.
Google’s use of that information is governed by the Google Privacy Policy and Terms of Service, both linked underneath every form on this site.
Unlike analytics, this runs whether or not you accept the cookie banner, because it is what keeps the forms usable at all. If you would rather not use it, call us on +603 9056 4888 instead.
Analytics and cookies
This site can use Google Analytics 4 to understand how visitors use the pages. Analytics only loads after you give explicit consent through the banner shown on your first visit. If you decline, no analytics scripts run and no analytics data is collected. Analytics is also configured to anonymize visitor IP addresses.
The analytics we use is configured so that the personal data from the forms is never included in any analytics payload. Analytics measures page usage, not the contents of your messages.
You can withdraw consent at any time. Clear this site’s stored choice in your browser (site data or local storage for this site) and decline the banner the next time it appears, and analytics will stay off.
The AlarmNX mobile app and the cloud relay
Mobile push has to leave a plant’s network to reach a phone, so it travels through a cloud relay that we operate. The same relay carries the web portal that admins of a connected site use. This part of the policy applies when your organization has connected its AlarmNX to that relay and you use the mobile app or the web portal.
Your app account
You register in the app with your phone number, a display name, and a password, and we confirm the number with a code sent to it by text message through a message delivery provider. Your password is stored only in a protected form, never as the password itself. The service also keeps the notification preferences you set (sites muted, quiet hours, minimum severity) so they follow you across your devices. We do not collect your email address, your contacts, your location, or any advertising identifier. If you turn on biometric unlock, that check happens on your device, and your biometric data never reaches us. Signing in to the web portal uses only the cookies needed for your session; the portal carries no advertising or analytics trackers. The app may also collect basic crash diagnostics so we can fix failures.
Your devices and push notifications
For each phone you sign in on, the relay keeps the device type, the app version, the delivery address for push notifications (the push token), and when the app was last active. Push notifications are delivered through Google’s and Apple’s notification services, and what those carry is the alarm name, its description, and its severity, never your name or number. The relay keeps a log of what was sent to your devices and whether it arrived.
Alarm data a connected site sends to the relay
When an organization connects its AlarmNX to the relay, alarm traffic travels outward from that installation to us: alarm names and descriptions, severity, the measured value that triggered the alarm, the display name of whoever acknowledged it, comments made on incidents (with the author’s name and phone number), and the list of phone numbers that installation’s escalation chains are set to notify. That recipient list is how the app links up: the first alarm sent to your number connects your account to that site. The list can also include numbers that have never installed the app. Connected installations also send selected live process values that power the portal’s health view; these are equipment measurements, not personal data, and are kept for two days.
For all of this, the organization that runs the AlarmNX installation decides what its alarms contain and whose numbers its escalation chains notify. We store and carry that data on its behalf, to deliver the service.
Who can see service data
Admins of a connected site can see, for their own site only, who is registered to it, their devices and when they were last active, their notification delivery history, and an audit trail of admin actions. Our own operations staff can access service data when provisioning or supporting a site, and every such access is recorded. Where an authorized partner supports your site, that partner’s staff can see the same site records. We do not sell service data, and we do not use it for advertising.
How long the relay keeps data
By default, incidents together with their comments and recipient lists are kept for 90 days, the push delivery log for 30 days, and the log of raw messages received from connected installations for 14 days. An organization can ask us to shorten these windows for its site. Records of admin actions are kept longer because they are the audit trail. Your account details stay for as long as you keep the account.
Deleting your app account
You can delete your account from inside the app. Deleting it removes your devices and push history and disconnects you from every site. Comments you wrote remain part of each incident’s record, with your name and number removed from them. We retain a minimal record of the closed account. You can also raise any request about your data through the contacts at the end of this policy.
Where the relay processes data
The relay runs on infrastructure that we operate. Push notifications travel through Google’s and Apple’s networks, and verification codes through our message delivery provider, so those deliveries can be processed outside Malaysia.
Your AlarmNX installation stays yours
AlarmNX itself runs on your hardware, inside your network. The user accounts, phone numbers, alarm history, and logs inside it belong to your installation, and we do not receive them. The product sends us no usage data and no crash reports, and its licensing works entirely offline; nothing in it reports back to us. If your admin points the product at an update source, the update check discloses only the system type and installed version, never personal data. Notification channels you enable (your mail server, your messaging and SMS providers) deliver through accounts your organization holds with those providers, under your arrangements with them. The mobile relay described above stays disconnected until an admin connects it, and even then your AlarmNX only ever calls out; nothing reaches into your network from us.
Customer and licensing records
When your organization evaluates or licenses AlarmNX, we keep ordinary business records: who we spoke with, the company, and the license we issued, meaning the customer name, tier, and validity dates. We use them to run the customer relationship and to support your installation.
Your rights
Under the PDPA you have the right to ask us to give you access to the personal data we hold about you, to correct it if it is inaccurate, and to erase it when it is no longer needed. You can also ask us to stop using it for a purpose you did not agree to. These rights cover both this website’s forms and the mobile service we operate. Where your data reached us from a connected AlarmNX installation, we may need to route your request through the organization that runs it, since that organization decides what its alarm system collects.
How to contact us about your data
To make an access, correction, or erasure request, call us on +603 9056 4888 or use the contact form on this site and describe your request. For the mobile app, account deletion is built into the app itself. We are in the process of nominating a dedicated data protection contact and will publish an email address here once it is in place. We will respond to your request within a reasonable time.
Changes to this policy
We may update this policy as our practices or the law change. When we do, we will revise the date shown at the top of this page. Please check back from time to time for the current version.