Last updated: 9 September 2026
This notice explains what personal data Localhost Sdn Bhd collects, why we hold it, and who we pass it to. It is issued under the Personal Data Protection Act 2010 ("PDPA").
One point first: some of the data you give us must be sent to a registry, and part of it can be published. Section 3 covers that — read it before you enter a contact.
Where a field is required, we cannot register the domain without it, because the registry will not accept the order.
We use account and contact data to register and manage domains on your instruction, to authenticate you, and to send renewal notices. We use order data to bill you and to meet accounting and tax obligations. We use technical data to keep the service secure and to fix faults. We do not sell personal data, and we send marketing email only where you have opted in.
To register a domain we must send the registrant and contact details to the registry — MYNIC for .my, the relevant operator for others. The registry keeps them for the life of the registration and applies its own policy.
Registries publish some of this data through WHOIS or RDAP. What is published varies by namespace and changes as registry policy changes. We do not control it and cannot withdraw a name from a registry's public record. Give an address you are content to have associated with a domain publicly.
Registries operate outside Malaysia, so registering a domain transfers your data outside Malaysia. Placing the order is your consent to that. Withdrawing consent means we can no longer keep the domain registered for you.
Each receives only the data it needs for that purpose.
Contact data stays for as long as the domain is registered through us, because the registry requires it. Billing records stay seven years to satisfy tax law. Account and log data stay while your account is open and for a limited period afterwards. Data already held by a registry is subject to the registry's retention period, not ours.
Access requires two-factor authentication. Traffic is encrypted in transit, passwords are stored hashed, and access to production data is restricted to the staff who need it. Where a breach affects your data and is likely to cause you significant harm, we notify you and the relevant authority. Keeping your own credentials secure is your responsibility.
Under the PDPA you may ask us for a copy of the data we hold about you, ask us to correct it, or ask us to stop using it for marketing. Most of it you can view and correct directly in your account. For anything else, write to the address below — we respond within 21 days and may charge the prescribed fee for a data access request.
Two limits: data a registry requires for an active domain cannot be erased while that domain is registered, and records kept for tax purposes stay until that period ends.
We set only the cookies the service needs — your session, your security token, and your interface preferences. We do not use advertising cookies. Blocking them prevents you from signing in.
Requests about your data go to
razi@localhost.myWe may update this notice and will give notice before a material change takes effect.