Effective date: 7 May 2026

1. Introduction

Bellfield Star Sdn Bhd ("Bellfield Star", "we", "us" or "our") is a technology company incorporated in Malaysia. We provide low-code application development, workflow automation, AI-driven knowledge management and data analytics services to enterprise customers across the ASEAN region.

This Privacy Policy explains what personal information we collect from you, how we use and share it, and the rights and choices you have regarding it. It applies to our website at bellfieldstar.com, to any web or mobile applications we publish under the "Bellfield Star" or "Moji5" brand, and to any related services we operate. It does not cover applications that our customers build on our platform and publish independently — those are governed by the privacy policy of the customer that publishes them.

We are committed to processing personal information in line with the Personal Data Protection Act 2010 (Malaysia), the EU General Data Protection Regulation (GDPR) and other applicable data-protection laws, and with the Google Play User Data policy where our software is distributed via Google Play.

2. Scope of this policy

This policy applies to information we collect from and about:

  • Visitors to our website and marketing pages;
  • Individuals who fill in a form on our site (for example, "Book a Demo" or "Contact Us");
  • Users of applications published by Bellfield Star on public app stores;
  • Representatives of prospective, current and former customers, partners and suppliers;
  • Recipients of our marketing communications.

Where we act as a data processor on behalf of a customer — for example, when a customer uses our platform to store information about their own end users — the customer is the data controller and their privacy policy governs how that data is handled. This policy covers our activities as a data controller.

3. Information we collect

We collect only what is necessary to operate our services, respond to enquiries, comply with our legal obligations and improve our products.

3.1 Information you provide directly

  • Contact details — name, business email, phone number, company, job title, country.
  • Enquiry content — the free-text messages, meeting requests or specifications you send us.
  • Account details — where you register for an account or portal, your username, role and preferences.
  • Customer service records — the correspondence, tickets and call notes generated when you contact our support team.

3.2 Information collected automatically

  • Technical data — IP address, browser type and version, operating system, device model, screen resolution, referrer URL and language.
  • Usage data — pages viewed, actions taken, timestamps, session duration and error events.
  • Cookies and similar technologies — see Cookies & tracking below.

3.3 Information from third parties

We may receive information about you from third parties such as our resellers, integration partners, publicly available business directories, and identity or fraud-prevention services — but only where that third party is permitted to share it with us.

3.4 Information we do not collect

We do not knowingly collect government identification numbers, biometric data, health data, precise geolocation, or information about your political, religious or philosophical beliefs unless you provide it voluntarily for a specific purpose and we have a lawful basis to process it.

4. How we use information

We use the information we collect for the following purposes:

  • To respond to enquiries and demo requests;
  • To provide, maintain and improve our services;
  • To communicate with you about your account, security updates and service changes;
  • To send you marketing information about products and services relevant to your role, where you have consented or where permitted by applicable law;
  • To measure how our website and applications are used, and to improve their design and content;
  • To detect, investigate and prevent fraud, security incidents and abuse;
  • To comply with our legal, tax and regulatory obligations;
  • To defend our legal rights, or those of third parties.

Where the GDPR or UK GDPR applies to our processing, our legal bases are:

  • Contract — to enter into or perform a contract with you or the organisation you represent;
  • Legitimate interest — to operate and improve our services, to secure our systems, and to communicate with existing business contacts (balanced against your rights and freedoms);
  • Consent — for marketing communications where consent is required, and for non-essential cookies;
  • Legal obligation — where processing is necessary to meet a legal requirement.

Where we rely on consent, you may withdraw it at any time by contacting us at the address in section 19.

6. How we share information

We share personal information only in the following circumstances:

  • Service providers — cloud hosting, email delivery, analytics, customer support and payment processing vendors that act on our instructions under a contract that requires them to safeguard your data;
  • Professional advisers — auditors, lawyers, insurers and other advisers who need the information to advise us;
  • Regulators and law enforcement — where we are required or permitted to disclose information to a public authority under applicable law;
  • Business transfers — in connection with a merger, acquisition, financing or sale of assets, in which case we will require the recipient to honour this policy;
  • With your consent — where you have asked or permitted us to share information with a specific third party.

We do not sell personal information, and we do not allow third parties to sell personal information we collect through our services.

7. Third-party SDKs & integrations

Our website and applications may include software development kits (SDKs), plug-ins or content from third parties (for example, analytics providers, embedded video, or authentication providers). These third parties may collect information about your device and use of our service in accordance with their own privacy policies. We select SDK providers that publish clear data-handling practices and, where possible, offer regional data residency and user controls. We monitor these providers and will remove or replace any that fail to meet our compliance requirements.

8. Cookies & tracking

We use cookies and similar technologies to:

  • Keep you signed in and remember your preferences (strictly necessary);
  • Understand how visitors use our site so we can improve it (analytics);
  • Measure the effectiveness of our marketing campaigns (marketing, only with your consent where required).

You can control cookies through your browser settings. Blocking strictly necessary cookies may cause parts of the site (for example, secure areas) to stop working correctly.

9. Data retention

We retain personal information for as long as necessary to fulfil the purposes described in this policy, unless a longer retention period is required or permitted by law. Typical retention periods are:

  • Enquiry and demo request data — 24 months from the last contact;
  • Customer account data — for the duration of the account, plus up to 7 years afterwards to meet accounting and tax obligations;
  • Marketing lists — until you unsubscribe, or 24 months of inactivity;
  • Website logs — up to 90 days, aggregated after that.

When your data is no longer needed, we either delete it securely or anonymise it so it can no longer be linked to you.

10. Security

We take appropriate technical and organisational measures to protect personal information against unauthorised access, disclosure, alteration and loss. These include:

  • Encryption of data in transit using TLS;
  • Encryption of sensitive data at rest;
  • Role-based access controls and periodic access reviews;
  • Secure software-development practices and vulnerability testing;
  • Incident-response procedures and regular staff training.

No system is completely secure, and we cannot guarantee absolute security. If we become aware of a breach that affects your personal data, we will notify you and the relevant authorities where required by law.

11. International transfers

Our primary operations are in Malaysia and we may transfer personal information to countries with different data-protection laws — for example, when using cloud providers hosted in Singapore, the European Union or the United States. Where transfers are made from the EEA, the UK or Switzerland, we rely on European Commission adequacy decisions or Standard Contractual Clauses (or their equivalent), supplemented by additional safeguards where necessary.

12. Your rights

Depending on the law that applies to you, you may have the right to:

  • Access the personal information we hold about you;
  • Correct information that is inaccurate or incomplete;
  • Delete your personal information (see section 13);
  • Restrict or object to certain processing;
  • Withdraw consent where processing is based on consent;
  • Portability — receive a copy of your data in a common machine-readable format;
  • Lodge a complaint with your local data-protection authority.

To exercise any of these rights, contact us at the address in section 19. We will respond within the time limits required by applicable law (typically 30 days). We may need to verify your identity before acting on the request.

13. Account & data deletion

If you have an account with us, you can request deletion of your account and associated personal data at any time using either of the following:

  • In-app — go to Settings → Account → Delete account in any Bellfield Star application you use;
  • By web — email privacy@bellfieldstar.com with the subject line "Delete my account", from the address associated with your account.

On receipt of a verified deletion request we will delete all associated personal data, except for information we are legally required to retain (for example, records of transactions kept for tax or anti-money-laundering purposes). Freezing or deactivating an account is not treated as deletion. We will confirm the deletion to you when it is complete.

14. Sensitive information

Where an application collects sensitive information (for example, personal identifiers, contacts, location or content of user communications), we will make a clear in-app disclosure before requesting your permission, explaining what is being collected and how it will be used or shared. We will not treat continuing use, back-button presses, or auto-dismissed prompts as consent. Sensitive data is used only for the purposes disclosed and is never sold to third parties.

15. Financial information

Payment card details, bank account numbers, and government-issued identification numbers are never displayed publicly, published in any user-visible profile, or shared with third parties except a regulated payment processor operating under contract with us. We limit access to this information to a small number of authorised staff on a need-to-know basis.

16. Children's privacy

Our services are directed to businesses and their staff. They are not directed to children under the age of 16, and we do not knowingly collect personal information from children. If you believe we have inadvertently collected data from a child, please contact us and we will delete it promptly.

Our website may contain links to third-party sites (for example, our LinkedIn and YouTube pages, or partner websites). We are not responsible for the privacy practices of those sites. We encourage you to read their privacy policies before providing information.

18. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our services, our legal obligations or industry practice. We will post the updated policy on this page and change the "Last updated" date at the top. For material changes we will provide reasonable prior notice (for example, by email or an in-product notice). Continued use of our services after the effective date of a change constitutes acceptance of the updated policy.

19. Contact us

If you have questions or complaints about this Privacy Policy or how we handle your personal information, please contact us at:

Bellfield Star Sdn Bhd
Kuala Lumpur, Malaysia
Email — Privacy: privacy@bellfieldstar.com
Email — General: sales@bellfieldstar.com

If you are located in the EEA, the UK or Switzerland and are not satisfied with our response, you have the right to lodge a complaint with your local data-protection authority. If you are located in Malaysia, complaints may be directed to the Personal Data Protection Department (JPDP) under the Ministry of Digital.