Applause Research Services Sdn. Bhd.

Privacy Policy and Personal Data Protection Notice

This notice explains how we collect, use, share, retain, transfer, and protect personal data across our market research and business activities.

Last updated: 31 July 2026
Project-specific information: A survey invitation, consent form, or project-specific notice may contain additional details relevant to a particular study. That information should be read together with this notice.

1. About This Notice

Applause Research Services Sdn. Bhd. (“Applause,” “we,” “our,” or “us”) respects the privacy of the individuals whose personal data we handle.

This notice describes our general data-handling practices for market research, respondent recruitment, research panels, project administration, quality control, website operations, and business communications.

We handle personal data in accordance with the Malaysian Personal Data Protection Act 2010, as amended, and other privacy and data-protection laws that apply to a particular activity. Where the European Union General Data Protection Regulation or another international law applies, we follow the relevant requirements.

2. Who We Are

Applause is a Malaysia-based market research company providing respondent recruitment, online sampling, fieldwork, project support, and related research services for consumer, business, healthcare professional, patient, and caregiver studies.

Applause Research Services Sdn. Bhd.
Level 35-02, East Wing, Q Sentral
2A Jalan Stesen Sentral 2, KL Sentral
50470 Kuala Lumpur, Malaysia

Privacy contact
Email: dataprivacy@arserviceco.com
Telephone: +60 3 2731 9315

3. Who This Notice Covers

This notice may apply to:

  • Research participants and people invited to participate in research;
  • Members of our research panel or recruitment database;
  • Healthcare professionals, patients, caregivers, and other specialist audiences;
  • Client, prospective-client, supplier, and business representatives;
  • Individuals included in an authorized client-provided contact list;
  • Website visitors and people who contact us; and
  • Other individuals whose information we process for legitimate research or business purposes.

4. Our Data-Protection Role

Our role depends on the activity:

  • We may decide why and how personal data is used, for example when managing our panel, business contacts, website enquiries, quality-control records, or incentive administration; or
  • We may process personal data for a client or research sponsor and follow that organization’s documented instructions.

The organization responsible for a specific project may be identified in the invitation, consent materials, or project-specific notice.

5. Information We May Collect

The information we collect depends on the purpose and the individual’s relationship with us. It may include:

  • Contact and identity information: name, email address, telephone number, country, general location, and participant or panel ID;
  • Profile and demographic information: age range, gender, region, household information, education, income range, interests, and consumer characteristics;
  • Professional information: employer, organization type, industry, job title, seniority, responsibilities, experience, specialty, practice setting, and relevant publicly available professional information;
  • Research information: screening answers, eligibility information, survey responses, opinions, interview or group-discussion contributions, recordings or transcripts where disclosed, participation history, and project status;
  • Sensitive personal data: health or other legally protected information where relevant to a study and handled with appropriate notice, consent, and safeguards;
  • Technical and quality information: IP address, browser, device, operating-system, access-time, approximate technical location, duplicate indicators, security signals, and response-quality information;
  • Payment information: limited details needed to arrange, verify, or reconcile an incentive or honorarium; and
  • Business and website information: correspondence, enquiries, meeting records, project documents, contracts, invoices, billing information, and website interactions.

We aim to collect only information reasonably relevant to the research, service, security, legal, or business purpose involved.

6. How We Obtain Personal Data

We may obtain personal data:

  • Directly from the individual;
  • Through our panel, recruitment database, screening forms, surveys, interviews, focus groups, or other research activities;
  • From a client, research sponsor, or authorized client-provided contact list;
  • From approved research, technology, quality-control, communication, incentive, or payment providers;
  • From referrals, company websites, professional directories, or other publicly available professional sources, where appropriate;
  • Through business correspondence, meetings, forms, or enquiries; and
  • Automatically through our website, systems, or survey links.

Where we receive information indirectly, we use it for the relevant purpose and provide information about the source where required by applicable law.

7. Why We Use Personal Data

We may use personal data to:

  • Register and manage panel or recruitment-database members;
  • Identify, invite, screen, schedule, and communicate with suitable research participants;
  • Conduct surveys, interviews, focus groups, research communities, or other research activities;
  • Manage project instructions, attendance, recontact, and study administration;
  • Administer incentives, honoraria, and payments;
  • Verify eligibility, identity, profile, employment, or professional background;
  • Prevent duplicate, fraudulent, abusive, ineligible, or poor-quality participation;
  • Review research quality and investigate project, payment, or security concerns;
  • Manage client projects, suppliers, contracts, invoices, and business relationships;
  • Respond to enquiries, complaints, privacy requests, audits, or legal claims;
  • Protect our systems, information, people, and business operations;
  • Improve our services and research processes; and
  • Meet contractual, legal, regulatory, accounting, tax, and reporting requirements.

Research responses are used for research and insight purposes. We do not use an individual’s research responses to market a client’s products or services to that individual unless separate permission has been obtained.

8. When Providing Information Is Required

Providing personal data is generally voluntary. However, certain information may be required to:

  • Determine eligibility for a research study;
  • Confirm identity, professional status, or study participation;
  • Arrange an incentive or payment;
  • Respond to an enquiry or privacy request;
  • Enter into or administer a client or supplier relationship; or
  • Meet legal, contractual, quality, security, or reporting requirements.

If required information is not provided, we may be unable to offer participation, process a payment, complete verification, respond fully to a request, or provide the relevant service.

9. Legal Grounds for Processing

The legal ground depends on the type of information, the activity, and the applicable law. We may rely on:

  • Consent, including explicit consent for sensitive information where required;
  • Contractual necessity, including steps requested before entering into a contract;
  • Legitimate and proportionate interests, where permitted, such as project administration, business relationship management, quality control, fraud prevention, information security, and protection of legal rights;
  • Legal obligations, including accounting, tax, regulatory, breach-notification, and reporting requirements; or
  • Another ground permitted by applicable law.

Where we rely on consent, it may be withdrawn by contacting us. Withdrawal does not affect processing already carried out lawfully and may not require deletion where another valid reason for retention applies.

10. Voluntary Research Participation

Participation in research is voluntary. Participants may normally decline an invitation, refuse to answer a question, or stop participating.

Before or at the start of a study, participants may receive information about the research purpose, expected duration, incentive, recording or observation, recontact, confidentiality, data sharing, and any special healthcare or safety-reporting requirements.

Some completed responses may no longer be removable after they have been anonymized, combined with other responses, delivered to a client, or used in completed analysis.

11. Healthcare and Sensitive Research

Some studies involve healthcare professionals, patients, caregivers, medical conditions, treatments, or other sensitive topics. For these studies, we limit collection to information relevant to the research and apply additional notice, consent, access, and confidentiality measures where appropriate.

If a participant reports an adverse event, product complaint, or safety concern during applicable healthcare research, relevant information may need to be passed to the research sponsor or its authorized safety team in accordance with the study notice and applicable requirements.

12. Client-Provided Lists and Business Contacts

A client may provide an authorized contact list for a particular research project. We use such information for the agreed purpose, restrict access, and do not use the list for unrelated marketing or unrelated studies.

We may also use professional contact details to communicate with existing or prospective clients, suppliers, or business partners about relevant research services or opportunities. Such details may come directly from the person, a referral, a company website, a professional directory, or another lawful business source.

Business contacts may opt out of future promotional communications by using an unsubscribe option where available, replying to the message, or contacting dataprivacy@arserviceco.com. We may retain limited suppression information so that the request is respected.

13. Sharing and Disclosure of Personal Data

To provide our research and business services, we may share limited personal data where necessary with:

  • Clients, research sponsors, and authorized project contacts;
  • Research, recruitment, fieldwork, translation, transcription, scheduling, or moderation partners;
  • Survey, hosting, communication, IT, security, fraud-prevention, incentive, and payment providers;
  • Professional advisers, auditors, insurers, banks, or parties involved in a legitimate business transaction; and
  • Courts, regulators, law-enforcement bodies, or other parties where disclosure is required or permitted by law.

Research findings are normally shared in aggregated, anonymized, or pseudonymized form. Direct contact details or other identifying information are disclosed only where needed for the stated purpose, the individual has been appropriately informed, and suitable safeguards apply.

Service providers may receive limited technical or operational information, such as log data, browser or device information, payment details, or project identifiers, only to the extent needed to provide their service.

Recipients are expected to use personal data only for the relevant purpose and to apply appropriate confidentiality, security, and data-protection measures.

We do not sell or rent personal data as a list for third-party direct marketing.

14. International Processing and Transfers

Applause is based in Malaysia and supports international research. Personal data may therefore be accessed, stored, or processed in Malaysia or another country used by a client, research partner, or service provider.

Where required, we use appropriate contractual, technical, and organizational measures for international transfers. These may include data-processing terms, contractual confidentiality requirements, access restrictions, data minimization, secure transfer methods, or approved transfer clauses.

For relevant transfers from the European Economic Area, an approved transfer mechanism such as the European Commission’s Standard Contractual Clauses may be used where appropriate.

15. Security, Fraud Prevention, and Quality Controls

We use reasonable administrative, technical, and organizational measures designed to protect personal data against unauthorized access, misuse, loss, alteration, or disclosure.

These measures may include access controls, password-protected accounts, approved business systems, secure transmission, software protection, backups, confidentiality obligations, staff guidance, and incident-response procedures.

We may use technical and behavioural indicators to support eligibility checks, duplicate prevention, fraud detection, survey security, and response-quality review. An automated indicator may lead to further review, exclusion from a study, withholding of an incentive while a matter is investigated, or restriction of future participation where justified.

No system or transmission method is completely secure, and absolute security cannot be guaranteed.

16. Retention and Deletion

We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, the research or business relationship, quality validation, payment administration, fraud prevention, legal claims, or applicable contractual, accounting, tax, and regulatory requirements.

Retention periods vary according to the type of information and project. When information is no longer needed, it may be deleted, anonymized, or securely destroyed. Information held in backups may be removed through the relevant backup-retention cycle.

Limited records may be retained after an opt-out or deletion request where needed to respect the request, prevent duplicate or fraudulent participation, resolve payments or quality disputes, comply with law, or protect legal rights.

17. Your Choices and Rights

Depending on applicable law and the circumstances, an individual may be able to:

  • Ask whether we hold personal data about them and request access to it;
  • Request correction of inaccurate or incomplete information;
  • Update consent or communication preferences;
  • Request deletion, restriction, or portability where applicable;
  • Object to certain processing or withdraw consent;
  • Opt out of future research invitations or business communications; and
  • Complain to an applicable privacy or data-protection authority.

These rights are not absolute. A request may be limited by identity-verification requirements, legal obligations, contractual responsibilities, completed anonymization, technical limitations, fraud-prevention needs, payment or quality disputes, or the rights of other persons.

Where Applause processes information only for a client or research sponsor, we may refer or forward the request to that organization and assist where appropriate.

Requests may be sent to dataprivacy@arserviceco.com.

18. Children and Young People

We do not knowingly involve children in research unless the project specifically requires their participation and suitable legal, consent, age-appropriate notice, privacy, and safety measures are in place.

If we learn that a child’s information was collected without required authorization, we will take appropriate steps, which may include deletion.

19. Cookies, Similar Technologies, and External Websites

A cookie is a small text file or similar identifier stored on or accessed from a browser or device. Our website and survey systems may use cookies or similar technologies for:

  • Essential and security purposes: operating the website or survey, maintaining sessions, protecting systems, and supporting basic functions;
  • Research quality and verification: preventing duplicate participation, supporting eligibility checks, detecting suspicious activity, and protecting survey integrity;
  • Preferences and functionality: remembering selected settings and improving the user experience; and
  • Measurement and performance: understanding website or survey usage and improving performance.

We do not use survey participants’ browsing information to provide third-party advertising. We will not describe or use advertising or targeting cookies unless such technologies are actually used.

Browser settings may be used to manage cookies. Where applicable law requires consent for non-essential cookies, appropriate information and consent choices will be provided.

External websites

Our website may contain links to external websites. We do not control their privacy, content, or security practices, and their own privacy notices apply.

20. Privacy and Security Incidents

We maintain procedures to assess, contain, investigate, document, and respond to suspected privacy or security incidents.

Where required, we may notify affected clients, individuals, regulators, or other authorities within the applicable legal period.

21. Contact, Requests, and Complaints

Questions, requests, concerns, or complaints may be sent to:

Privacy Contact
Applause Research Services Sdn. Bhd.
Level 35-02, East Wing, Q Sentral
2A Jalan Stesen Sentral 2, KL Sentral
50470 Kuala Lumpur, Malaysia

Email: dataprivacy@arserviceco.com
Telephone: +60 3 2731 9315

We will review the matter and respond within a reasonable period. An individual may also have the right to contact the relevant privacy or data-protection authority in their country.

22. Changes to This Notice

We may update this notice when our services, practices, technology, or legal obligations change. The latest version will be posted on this page with the revised date. Where required, we will provide additional notice of material changes.

Questions About Your Personal Data?

Please contact our Privacy Contact if you would like to ask a question, update your communication preferences, exercise an applicable privacy right, or raise a concern about how personal data has been handled.

Effective date: 31 July 2026
Document version: 1.0
Policy owner: Applause Research Services Sdn. Bhd.
Back to top ↑