Privacy, Security & Customer Asset Protection Policy

Effective Date: [01 August 2026]
Last Updated: [01 September 2026]
1. Our Commitment
Train Evolution respects the privacy of our customers, participants, users and business partners.
We believe that providing a training service or a digital asset management service does not give us unrestricted rights over a customer’s information or digital assets.
Our approach is therefore based on three principles:
Your personal information is used only for legitimate and relevant purposes.
Your digital assets remain your assets.
Access to a system does not mean permission to look at, copy, use or interfere with its contents.
This Policy explains how Train Evolution handles personal data and protects customer digital assets across:
- Train Evolution websites;
- Training Courses;
- Training & Laboratory (“TLab”);
- MY1DAM Portal;
- enquiries, bookings and registrations;
- customer support and onboarding; and
- related Train Evolution services.
Train Evolution intends to process personal data in accordance with Malaysia’s Personal Data Protection Act 2010 [Act 709], as amended, and other applicable data-protection requirements.
2. Personal Data and Customer Assets Are Different
For purposes of this Policy, we distinguish between Personal Data and Customer Assets.
Personal Data
Personal Data may include information such as:
- your name;
- email address;
- telephone number;
- company or organisation;
- job title;
- billing information;
- course registration;
- attendance records;
- account details;
- communications with us;
- transaction records;
- technical and security information relating to the use of our systems; and
- other information reasonably required to supply our services.
Customer Assets
Customer Assets include the business files and digital content managed, referenced or used through MY1DAM or supplied for an agreed TLab activity, including:
- images;
- photographs;
- videos;
- artwork;
- documents;
- presentations;
- design files;
- marketing materials;
- product files;
- brand materials;
- audio;
- working files; and
- associated business content.
A file may sometimes also contain Personal Data. Where it does, applicable data-protection obligations continue to apply.
3. Our Customer Asset Non-Interference Commitment
This is a central Train Evolution commitment.
Train Evolution does not treat access to a customer’s MY1DAM environment as permission to access the customer’s asset contents.
As part of normal service operation, Train Evolution personnel will not intentionally:
- open or preview Customer Assets merely to see their contents;
- browse through a customer’s asset library;
- download Customer Assets for Train Evolution’s own use;
- make separate copies for Train Evolution;
- move or rename Customer Assets without authority;
- modify or alter Customer Assets without authority;
- delete Customer Assets without authority;
- share Customer Assets with another customer;
- publish Customer Assets;
- use Customer Assets for Train Evolution’s advertising or marketing;
- sell Customer Assets;
- analyse Customer Asset content for unrelated commercial purposes;
- use Customer Assets to train artificial-intelligence models; or
- tamper with or interfere with Customer Assets.
We do not claim ownership of a customer’s Customer Assets simply because MY1DAM is used to manage them.
Our role is to provide a management layer, workflow and related services — not to take ownership of the customer’s files.

4. Limited Exceptions to the Non-Interference Commitment
There may be exceptional situations where access is necessary.
Train Evolution may access specifically relevant information only where:
- the customer expressly requests technical assistance and authorises the required access;
- access is necessary to investigate a security or service incident affecting that customer;
- access is necessary to perform a specific customer-authorised configuration, migration or support task; or
- Train Evolution is required to act under applicable law, court order or lawful regulatory requirement.
Where practical, such access will be:
- limited to the relevant issue;
- limited to authorised personnel;
- limited to the minimum information reasonably necessary; and
- ended when the authorised purpose has been completed.
A general support request is not intended to give Train Evolution unlimited permission to browse a customer’s content.
5. MY1DAM and the Customer’s Google Environment
MY1DAM is designed as a digital asset management layer operating with the customer’s authorised Google environment.
For customer MY1DAM deployments, the customer’s authorised Google storage remains the primary location of the customer’s digital files.
Train Evolution does not operate MY1DAM on the principle that a customer must surrender its asset library to Train Evolution.
Depending on the functions being used, MY1DAM may technically process information associated with an asset, for example:
- file identifiers;
- filenames;
- file locations or links;
- metadata;
- asset-record information;
- permissions;
- version information;
- workflow status;
- approval information;
- request information;
- catalogue records; and
- audit or system events.
This technical processing is necessary for DAM functionality and does not by itself mean that Train Evolution personnel are reading or viewing the contents of the file.
Train Evolution will not intentionally create and retain an independent Train Evolution content library containing copies of a customer’s MY1DAM assets unless the customer has specifically requested and authorised such a service.
6. Training & Laboratory — TLab
TLab is a training, simulation, testing and guided laboratory environment.
Because TLab is intended for learning, simulation and controlled testing, customers and trainees should wherever practical use:
- training files;
- sample files;
- sanitised materials;
- non-confidential content; or
- other materials approved for laboratory use.
Where a participant intentionally uploads files into a designated TLab workspace, those files may necessarily be stored in that laboratory environment for the duration required to perform the exercise.
Such storage does not give Train Evolution permission to reuse those files for unrelated purposes.
Train Evolution will not intentionally:
- create unrelated secondary copies;
- use TLab customer files for another customer’s exercise;
- publish them;
- commercialise them;
- use them for AI-model training; or
- retain them indefinitely merely because they entered the laboratory.
TLab files will be handled according to the relevant workshop, testing or laboratory retention and cleanup process.
Customers should not upload confidential production assets into TLab unless this is necessary for an agreed exercise and appropriate arrangements have been made.
7. Training Course Materials
Information supplied for a training course may include registration information, attendance information, assessments or work intentionally submitted to a trainer.
Where a participant intentionally submits an exercise, assignment or assessment for trainer review, Train Evolution may review that material for the purpose for which it was submitted.
This is different from Train Evolution obtaining unrestricted access to a customer’s MY1DAM asset repository.
Participants should avoid inserting unrelated confidential business information into course exercises unless specifically required.

8. Personal Data We May Collect
Depending on your relationship with Train Evolution, we may collect:
Identity and Contact Information
Such as name, email address, telephone number, company, department and job title.
Booking and Training Information
Such as course selected, session date, attendance, participation, training completion and certification information.
Account Information
Such as user identity, role, organisation, tenant or workspace association and information required to administer access.
Transaction Information
Such as order number, invoice information, payment status and transaction reference.
Payment processing may be carried out through third-party payment providers. Train Evolution generally requires transaction and payment-status information rather than unrestricted access to full payment-card information.
Technical and Security Information
This may include information reasonably generated through use of our website or systems, such as:
- IP address;
- browser or device information;
- login information;
- access records;
- system events;
- error information; and
- security or audit records.
Communications
We may retain enquiries, support requests, feedback and other correspondence necessary to serve the customer and maintain an appropriate business record.
9. Why We Process Personal Data
We may use Personal Data where reasonably necessary to:
- respond to enquiries;
- process registrations and bookings;
- supply training;
- administer TLab access;
- provision and administer MY1DAM;
- authenticate users;
- provide customer support;
- maintain account and transaction records;
- issue invoices, receipts or certificates;
- maintain security and prevent misuse;
- troubleshoot technical issues;
- improve service reliability;
- meet legal, accounting or regulatory obligations; and
- provide marketing communications where permitted and appropriate.
We will not intentionally use Personal Data for an unrelated purpose merely because we possess it.
10. Marketing
Train Evolution may send relevant information about its services where permitted by applicable law and the recipient’s preferences.
Recipients may request that direct marketing communications stop.
Unsubscribing from marketing does not prevent us from sending necessary transactional or service communications relating to an existing booking, account or service.

11. Disclosure to Other Parties
Train Evolution does not sell Personal Data as a business practice.
Personal Data may be disclosed where reasonably necessary to service providers supporting functions such as:
- website hosting;
- Google-based services;
- email;
- payment processing;
- accounting;
- customer communication;
- system support; or
- other infrastructure required to provide the service.
Such disclosure should be limited to information reasonably necessary for the relevant service.
Information may also be disclosed where Train Evolution is required to comply with applicable law or a lawful request from a competent authority.
12. Security
Train Evolution will take reasonable technical and organisational measures appropriate to the nature of the information being handled to protect Personal Data against risks including:
- unauthorised access;
- accidental loss;
- misuse;
- unauthorised alteration;
- inappropriate disclosure; and
- destruction.
Access should be limited according to legitimate operational need.
No internet-connected system can responsibly be described as absolutely immune from every possible security incident. Train Evolution therefore does not make an unrealistic guarantee that a breach can never occur.
Our commitment is instead to use reasonable safeguards, minimise unnecessary access, respond appropriately to security events and improve controls as our services develop.
13. Security Incidents and Data Breaches
Where Train Evolution becomes aware of a suspected security incident involving Personal Data, we will assess the incident and take reasonable steps to:
- contain the issue;
- investigate its nature and scope;
- protect affected systems or information;
- remediate the cause where reasonably possible;
- preserve appropriate incident records; and
- make notifications to the relevant authority or affected individuals where notification is required by applicable law.
14. Data Retention
Personal Data will not intentionally be retained indefinitely without a legitimate reason.
We may retain information for as long as reasonably required for:
- delivery of the relevant service;
- maintaining an account;
- training and certification records;
- customer support;
- accounting and taxation;
- contractual records;
- dispute handling;
- security and audit purposes; or
- other legal requirements.
When information is no longer reasonably required, it should be securely deleted, anonymised or otherwise disposed of in accordance with the applicable retention process.
Customer Asset retention follows the more specific MY1DAM and TLab provisions in this Policy.
15. Data Accuracy
We take reasonable steps to maintain Personal Data that is appropriate and relevant for the purpose for which it is being used.
Customers and users should notify Train Evolution if important account or contact information is incorrect or has changed.
16. Your Personal Data Rights
Subject to applicable Malaysian law and any permitted limitations, an individual may have rights including the right to:
- ask whether Personal Data is being processed;
- request access to Personal Data;
- request correction of inaccurate Personal Data;
- withdraw consent where applicable;
- object to or prevent certain processing;
- stop direct-marketing communications; and
- exercise other applicable data-subject rights.
Certain information may need to continue to be retained or processed despite a request where Train Evolution has a legal, contractual, security or other lawful obligation to do so.

17. Cookies and Website Technology
Train Evolution websites may use cookies or similar technologies required to:
- operate the website;
- maintain sessions or shopping-cart functions;
- provide security;
- remember preferences;
- understand website performance; or
- support other legitimate website functions.
Where consent is legally required for a particular type of cookie or tracking technology, appropriate consent controls should be provided.
Users may also manage cookies through their browser, although blocking essential cookies may affect site functionality.
18. International or Third-Party Infrastructure
Some technology providers used in delivering Train Evolution services may operate infrastructure in more than one country.
Where Personal Data is transferred or processed outside Malaysia, Train Evolution will take reasonable steps required under applicable law and will consider the safeguards offered by the relevant service provider.
19. Customer Responsibilities
Privacy and security are shared responsibilities.
Customers should:
- protect their login credentials;
- use appropriate password and authentication practices;
- assign access only to authorised personnel;
- promptly remove access for people who no longer require it;
- maintain appropriate permissions within their own Google environment;
- avoid placing confidential production information in TLab unnecessarily; and
- notify Train Evolution promptly of suspected unauthorised access affecting a Train Evolution service.
Train Evolution’s commitment not to interfere with Customer Assets does not replace the customer’s responsibility for controlling its own users and authorised access.
20. Ownership and Intellectual Property of Customer Assets
Unless otherwise expressly agreed, Customer Assets remain the property of the customer or the party that has lawful rights to those assets.
Use of MY1DAM, TLab or another Train Evolution service does not transfer ownership of the Customer Asset to Train Evolution.
Customers remain responsible for ensuring that they have the necessary rights to upload, manage, distribute or otherwise use material supplied through the relevant service.
21. No Use of Customer Assets for AI Training
Train Evolution will not intentionally use a customer’s private Customer Assets to train Train Evolution artificial-intelligence models or to create a general commercial AI training dataset.
If Train Evolution ever proposes a service that requires a materially different use of customer content, that use must not be silently introduced through this Policy. Appropriate disclosure and, where required, customer authorisation would be obtained separately.
22. Privacy Requests and Complaints
Questions or requests relating to Personal Data, privacy or Customer Asset handling may be sent to:
Train Evolution
Privacy Contact: [Insert Name/Role]
Email: [Insert Privacy Email]
Address: [Insert Business Address]
Telephone: [Insert Number, if applicable]
We may request reasonable verification before disclosing or changing Personal Data in order to avoid releasing information to an unauthorised person.
23. Changes to This Policy
Train Evolution may revise this Policy as its services, technology or legal obligations develop.
Where a change materially affects how we handle Personal Data or Customer Assets, we will take reasonable steps to communicate the change in an appropriate manner.
The current version and its effective date will be published on the Train Evolution website.
24. Our Simple Promise
The purpose of MY1DAM and TLab is to help customers manage, understand and control digital assets — not to take those assets away from them.
Where MY1DAM operates with a customer’s environment, the customer’s files remain under the customer’s control.
Where files are intentionally placed into TLab for training or testing, they are there for that defined purpose.
Train Evolution will not treat technical access as permission to browse, copy, alter, retain, exploit or interfere with customer assets.

Now Get Equipped. Get Organised For Success With DDAM Portal Packages. Add Digital Competencies to Your Go-to-Market Initiatives
We Are With You In Your DAM Journey Through Training & Technologies
Check out Train Evolution Courses







