Malaysian Sovereign Digital Framework • Enterprise Governance
Cloudist Enterprise Legal Architecture & Sovereign
Framework
Authoritative statutory governance, cloud hosting terms, data privacy adherence, and
asset protection covenants for Cloudist (a premier tech-flagship
brand operated by D'Corp Tech, Malaysia). All services and compute
infrastructure are governed under the sovereign jurisdiction of Malaysia.
Corporate EntityD'Corp Tech (Malaysia)
Registration No(003837724-U)
BrandCloudist
Governing LawsLaws of Malaysia
Framework Versionv2026.2
100%
PDPA 2010 Compliant
99.9%
SLA Network Guarantee
30-DAY
Risk-FREE Money-Back
AIAC
Arbitration Venue (KL)
Filtering clauses matching: (0 found)
Clause 1.1PDPA 2010Data Controller
1.1 Introduction, Data Controller Identity
& Our Commitment to Privacy
D'Corp Tech, a duly registered sole proprietorship under the laws of
Malaysia and the corporate parent of the Cloudist brand and
full portfolio of enterprise cloud, hosting, and digital engineering services,
is irrevocably committed to the protection, integrity, and lawful governance of
all personal data entrusted to us by our customers, website visitors, business
partners, and registered users. This Privacy Policy constitutes a comprehensive,
legally binding declaration of our data governance practices, our technical and
organizational security posture, and the rights available to you as a data
subject under applicable Malaysian and international law.
This Policy operates in strict compliance with the Personal
Data Protection Act 2010 (PDPA, Act 709) of Malaysia, the
Communications and Multimedia Act 1998 (CMA), the
Computer Crimes Act 1997, and all directives issued by the
Malaysian Personal Data Protection Commissioner. Where Cloudist processes data
belonging to individuals in international jurisdictions, we additionally adhere
to applicable international standards including the APEC Privacy Framework and
ISO/IEC 27001:2022 data protection principles.
This Privacy Policy governs the collection, use, storage,
disclosure, transfer, and destruction of personal data across all Cloudist
digital touchpoints — including our primary corporate website (cloudist.my), the
Cloudist Client Management Dashboard (mywebsitedashboard.com), RESTful and
WebSocket API endpoints, mobile-responsive service portals, WhatsApp support
channels, email marketing systems, payment processing integrations, and all
enterprise service agreements.
As the registered Data Controller under the PDPA
2010, D'Corp Tech accepts full legal accountability for the manner in which
personal data is collected, processed, stored, and protected across our
operations. Our Designated Data Protection Officer (DPO) is directly appointed
by and accountable to the Founder of D'Corp Tech and operates with executive
authority to enforce internal data governance policies, investigate data
handling breaches, and liaise with regulatory authorities.
By accessing cloudist.my, registering an account, subscribing to any
Cloudist service, or otherwise providing personal data through any Cloudist
digital interface, you affirmatively confirm that you have read, clearly
understood, and irrevocably consented to the terms of this Privacy Policy in
full. If you do not agree with any provision of this Policy, you must
immediately discontinue access to and use of all Cloudist digital services.
Data Protection Officer
Contact: All data subject requests, consent withdrawals, access
applications, correction demands, erasure requests, and data breach reports must
be submitted in writing to dpo@cloudist.my. Our DPO will acknowledge
receipt within forty-eight (48) hours and respond within twenty-one (21)
calendar days.
Clause 1.2Data CategoriesMinimization
1.2 Categories of Personal Data Collected
& the Data Minimization Principle
D'Corp Tech applies the principle of data
minimization — collecting only information that is strictly
necessary, adequate, and relevant to achieve the specified, legitimate
processing purpose for which it was gathered. The categories of personal data we
collect include:
Identity & Contact Data: Full legal name,
business trading name, Malaysian NRIC or passport number (where required for
enterprise verification), registered address, correspondence email, mobile
number, and WhatsApp contact.
Account Credentials & Authentication Data:
Usernames, password hashes (stored using bcrypt or Argon2id — plaintext
passwords are never stored), two-factor authentication TOTP seed tokens,
OAuth 2.0 session tokens, and API authentication keys.
Financial & Billing Data: Payment card
type and last four digits (tokenized by PCI-DSS Level 1 compliant processors
— full card numbers are never stored by D'Corp Tech), FPX bank account
references, invoicing history, payment confirmations, and Malaysian SST
registration numbers where applicable.
Technical & Usage Data: IPv4 and IPv6
source addresses, browser user-agent strings, device operating system,
screen resolution, referring URL, dashboard pages visited, session duration,
API endpoint call logs, server access logs, and CDN edge telemetry.
Service Configuration Data: Hosting plan
specifications, provisioned resource allocations (vCPU, RAM, storage),
registered domain names, DNS zone configurations, SSL certificate metadata,
installed CMS applications, database schema identifiers, backup schedules,
and firewall rule profiles.
Support & Communications Data: Full
records of support tickets, email correspondence, WhatsApp support message
logs, post-resolution CSAT survey responses, formal complaint submissions,
and escalation audit trails.
Sensitive Corporate Data: SSM registration
certificates, director identification, proof of business address, and
statutory compliance records submitted for enterprise account verification —
treated with heightened security protocols and accessed only by authorized
personnel on a strict need-to-know basis.
Data is collected through: (i) direct voluntary submission via
registration forms and checkout flows; (ii) automated technical collection
through server logs and API telemetry; (iii) third-party payment processors
transmitting transaction metadata; (iv) domain registrar and SSL CA confirmation
notices; and (v) legally mandated disclosures from regulatory authorities.
Clause 1.3Lawful BasisPDPA 2010
1.3 Lawful Basis for Processing under the
PDPA 2010
D'Corp Tech processes personal data only where a valid, specific,
and documented legal basis exists under the Personal Data Protection Act 2010
(PDPA) of Malaysia. We operate under the following lawful processing bases:
Contractual Necessity: The majority of D'Corp
Tech's data processing operations are necessary for the performance of a
service contract — including account provisioning, billing, technical
service delivery, SLA monitoring, and support communications. Without such
processing, D'Corp Tech cannot fulfil its contractual obligations.
Legitimate Interests: We process certain
technical and operational data under the legitimate interests basis —
balanced against and not overriding data subject rights — for purposes
including network security, fraud prevention, abuse mitigation, service
performance optimisation, and internal compliance audits.
Explicit Consent: For marketing
communications, personalization cookies, optional analytics features, and
promotional targeting, D'Corp Tech relies exclusively on explicit, freely
given, specific, informed, and revocable consent. Consent may be withdrawn
at any time without affecting the lawfulness of prior processing.
Legal Obligation: D'Corp Tech is legally
required to process and retain certain data, including financial records
under the Income Tax Act 1967, anti-money laundering records under AMLA
2001, and account access logs pursuant to valid judicial orders or CMA 1998
directives.
Vital Interests: In rare emergency
circumstances where processing is strictly necessary to protect the physical
safety or life of an individual, we may process limited personal data
without consent to the minimum extent absolutely required.
D'Corp Tech does not engage in fully automated decision-making that
produces legal effects or significantly impacts data subjects — including
automated credit assessments or algorithmic pricing discrimination — without
providing the individual with adequate information, an explanation of the logic,
and an opportunity to contest the decision.
Clause 1.4Processing Purposes
1.4 Specific Purposes of Personal Data
Processing
Personal data collected by D'Corp Tech is processed exclusively for
the following specific, explicit, and legitimate purposes:
Service Delivery & Provisioning: To
provision, configure, activate, maintain, monitor, diagnose, and
troubleshoot all subscribed hosting, VPS, cloud, domain, SSL, email, and
managed engineering services.
Account Management & Authentication: To
create and maintain secure accounts; enforce multi-factor authentication;
generate and rotate API keys; manage session tokens; audit access logs; and
prevent credential stuffing, session hijacking, and unauthorized account
takeover.
Billing, Invoicing & Financial Operations:
To generate and dispatch invoices; process payments; manage subscription
renewals and cancellations; execute refund disbursements; apply promotional
credits; maintain financial audit trails; and comply with Malaysian SST
reporting obligations.
Technical Support & Incident Resolution:
To receive, log, triage, assign, escalate, and resolve support tickets;
diagnose infrastructure anomalies; conduct post-incident forensic analysis;
and publish formal Post-Incident Review (PIR) reports.
Security, Fraud Prevention & Abuse
Mitigation: To monitor network traffic for DDoS attacks,
brute-force authentication attempts, malware propagation, and unauthorized
API exploitation; investigate confirmed security incidents; and prevent
fraudulent account registrations and illegitimate chargebacks.
Legal Compliance & Regulatory Obligations:
To fulfil mandatory obligations under Malaysian tax law, AMLA 2001, MCMC
regulatory requirements, and valid judicial court orders or statutory
notices.
Service Improvement & Quality Assurance:
To analyse aggregate, pseudonymized usage patterns; identify infrastructure
performance bottlenecks; benchmark against SLA commitments; and inform
engineering roadmap decisions — exclusively using data that cannot identify
any specific individual.
Marketing Communications (Consent-Only): To
send product announcements, promotional offers, webinars, case studies, and
maintenance advisories — exclusively to customers who have provided
explicit, revocable opt-in consent.
Corporate Administration & Legal Defense:
To maintain corporate records; conduct internal risk assessments; engage
legal counsel; and enforce contractual rights through arbitration,
mediation, or litigation.
Data Sale Prohibition:
D'Corp Tech categorically does not sell, rent, auction, license, or otherwise
commercially transfer personal data to any third-party organization for their
own independent marketing, profiling, or commercial purposes — under any
circumstances, without exception.
Clause 1.5Third-Party
ProcessorsData
Sharing
1.5 Data Sharing, Disclosure & Approved
Third-Party Sub-Processors
D'Corp Tech maintains rigorous data governance over all third-party
relationships. We engage a curated set of approved sub-processors who process
personal data strictly on our behalf under binding contractual Data Processing
Agreements (DPAs) imposing equivalent or greater protection obligations than the
PDPA 2010. All sub-processors are subjected to a formal privacy and security
assessment before engagement and are prohibited from using customer personal
data for any purpose beyond their contracted function.
Data Center & Colocation Partners:
Physical and virtual server infrastructure is hosted within Tier III+
certified data centers in Malaysia and Singapore, operated under formal DPAs
with D'Corp Tech.
PCI-DSS Compliant Payment Processors: All
credit/debit card transactions are processed by Stripe (PCI-DSS Service
Provider Level 1) or equivalent accredited processors. For FPX transactions,
MCMC-licensed and Bank Negara Malaysia-regulated providers are used.
Cloudist never receives or stores full card numbers.
Transactional Email Infrastructure: Automated
emails (invoices, security alerts, service notifications) are dispatched via
enterprise-grade email delivery infrastructure operating under contractual
DPAs.
Domain Registrar & Certificate Authority
Partners: Domain registrations are facilitated through
ICANN-accredited and MYNIC-accredited registrar channels. SSL/TLS
certificates are issued through Let's Encrypt, DigiCert, Sectigo, and
GlobalSign.
Performance Monitoring Tools: Aggregated,
anonymized metrics are processed through approved infrastructure monitoring
platforms with individual user identifiers pseudonymized or stripped.
Legal Counsel & Compliance Advisors: In
formal legal proceedings, D'Corp Tech's authorized legal counsel may access
relevant personal data under binding professional confidentiality
obligations.
D'Corp Tech will not share personal data with social media
advertising platforms, programmatic advertising networks, data brokers, or
commercial marketing aggregators. Any mandatory legal disclosure to Malaysian
authorities — PDRM, MCMC, or other statutory bodies — shall occur only upon
receipt and verification of a certified judicial court order or formal statutory
notice issued under the Criminal Procedure Code or CMA 1998, and only to the
minimum extent legally required.
Cloudist and its web portals employ cookies, local browser storage
(localStorage), session storage, pixel tags, and web beacons to deliver
essential platform functions, maintain secure authentication sessions,
personalise user experiences, and measure service performance. This Cookie
Policy operates in full accordance with the PDPA 2010, the Malaysian Personal
Data Protection Regulations 2013, and globally recognized consent management
best practices.
We categorize our cookies and tracking technologies into four
distinct tiers:
Strictly Necessary Cookies: Session management
tokens, CSRF protection cookies, load balancer affinity cookies, TLS session
resumption identifiers, and payment session tokens. Technically essential to
platform security and operation — cannot be disabled without critically
impairing functionality. No consent is required under applicable law.
Performance & Analytics Cookies:
Aggregated, anonymized metrics including page load times, API response
latency, and infrastructure error rates. Assist engineering teams in
continuously improving platform reliability. Activated only upon explicit
informed consent.
Functional Cookies: User interface preference
cookies storing language selection, timezone, currency format, dark/light
mode, dashboard layout, and notification preferences. Enhance usability
without tracking users across external websites.
Marketing & Campaign Attribution Cookies:
First-party campaign tracking tags measuring the conversion effectiveness of
Cloudist's own digital marketing. Do not track users across unrelated
third-party websites, do not participate in programmatic RTB advertising,
and do not share identifiable data with social media platforms.
You may adjust or withdraw cookie consent at any time through: the
Cloudist Cookie Preference Centre in the platform footer; standard browser
cookie controls; or by submitting a written request to dpo@cloudist.my.
Consent Record
Retention: D'Corp Tech maintains complete, auditable, timestamped
records of all cookie consent interactions — including the consent notice
version presented, choices made, and consenting device identity — for a minimum
of seven (7) years in compliance with PDPA accountability obligations.
Clause 1.7Retention Schedule
1.7 Data Retention Schedule, Archive
Policies & Secure Destruction Protocols
D'Corp Tech retains personal data only for the minimum duration
necessary to fulfil the specific, documented purpose for which it was collected,
or as required by mandatory Malaysian law. Our operative retention schedule is
as follows:
Data Category
Retention Period
Legal Basis
Active Account & Profile Data
Active term + 6 years post-closure
Limitation Act 1953 (contractual)
Financial Records & Invoices
7 years from financial year-end
Income Tax Act 1967
Payment Transaction Logs
7 years from transaction date
AMLA 2001 compliance
Support Ticket Records
3 years from ticket closure
Legitimate interests / contractual
Server & Access Logs
12 months (rolling)
Network security / CMA 1998
Marketing Consent Records
Indefinitely until consent withdrawal
PDPA consent accountability
Security Incident Records
7 years post-resolution
Legal defense / regulatory
Backup Archives Containing PD
Overwritten within 90 days of retention limit
PDPA data minimization
Upon expiry of the applicable retention period, personal data is
securely and irreversibly destroyed using NIST SP 800-88 Rev. 1
data sanitization standards — including cryptographic erasure for cloud storage
and degaussing or physical destruction for magnetic media. Data subjects may
request early deletion under Clause 1.8, subject to overriding statutory
retention obligations.
Clause 1.8Your RightsPDPA S.30-38
1.8 Your Rights as a Data Subject under the
PDPA 2010
Under the Personal Data Protection Act 2010 (Act 709) of
Malaysia, all individuals whose personal data is processed by
D'Corp Tech hold the following enforceable statutory rights, which D'Corp Tech
is unconditionally committed to upholding with full transparency and within the
statutory timeframes:
Right of Access (PDPA Section 30): You may
request confirmation of whether D'Corp Tech holds your personal data and
receive a complete copy in a readable format. Responded to within twenty-one
(21) calendar days of a verified access request submitted to
dpo@cloudist.my.
Right of Correction (PDPA Section 34): You may
request correction of inaccurate, incomplete, misleading, or outdated
personal data. Verified corrections are processed within twenty-one (21)
calendar days of receipt with supporting documentation.
Right to Withdraw Consent (PDPA Section 38):
Where D'Corp Tech processes your personal data on the basis of consent, you
have the absolute right to withdraw that consent at any time, with immediate
effect for future processing. Withdrawal does not retroactively affect the
lawfulness of prior processing.
Right to Prevent Marketing Processing: You
retain an absolute statutory right to instruct D'Corp Tech to cease all
direct marketing processing involving your personal data, actioned within
five (5) business days of receipt.
Right to Data Portability: Where technically
feasible, D'Corp Tech will provide your personal data in a structured,
machine-readable format (JSON, CSV, or XML) within twenty-one (21) calendar
days.
Right to Erasure: You may request deletion of
your personal data where it is no longer necessary for the collection
purpose, consent has been withdrawn, or processing is unlawful — subject to
overriding statutory retention requirements under Malaysian law.
Right to Complain to the Regulator: If you
believe D'Corp Tech has failed to comply with the PDPA 2010, you may submit
a complaint to the Personal Data Protection Commissioner of
Malaysia via pdp.gov.my.
Exercise Your Rights:
Submit all requests in writing to dpo@cloudist.my with your full name, account
email, the specific right you are exercising, and proof of identity.
Acknowledgement within 48 hours guaranteed. No fees are charged for reasonable,
non-repetitive requests.
Clause 1.9Minors & Age
Policy
1.9 Children's Privacy Protection, Age
Verification & Parental Rights
Cloudist's enterprise cloud computing and web hosting services are
strictly intended for adults aged eighteen (18) years or above, or legal
entities represented by authorized adults. D'Corp Tech does not knowingly
solicit, collect, store, or process personal data from individuals below
eighteen (18) years of age without verified, documented parental or legal
guardian consent obtained in accordance with the PDPA 2010 and applicable child
protection legislation.
Where D'Corp Tech becomes aware — through internal audit, user
report, or parental notification — that personal data has been inadvertently
collected from a minor, the following immediate actions shall be taken: (i)
immediate suspension of the relevant account pending identity and age
verification; (ii) notification of the parent or guardian where their contact
details are ascertainable; (iii) complete and irreversible deletion of all
associated personal data within seven (7) business days of confirmed discovery;
and (iv) a formal root-cause investigation and systemic remediation within
thirty (30) days.
Parents or legal guardians who believe a minor has submitted
personal data to Cloudist must immediately contact dpo@cloudist.my with official identification
documentation for both the parent/guardian and the minor. All verified parental
erasure and access requests are prioritized and actioned within twenty-one (21)
calendar days.
Clause 1.10Marketing
ConsentOpt-Out
Rights
1.10 Marketing Communications, Newsletter
Subscriptions & Opt-Out Rights
With your explicit, freely given, and informed opt-in consent,
D'Corp Tech may send electronic marketing communications including Cloudist
product announcements, promotional pricing, enterprise service tier upgrade
offers, technical webinar invitations, industry reports, platform feature
updates, and scheduled maintenance advisories to your registered email address
and/or WhatsApp number.
You retain an absolute, unconditional, and immediately effective
right to withdraw your marketing consent at any time through: (i) the one-click
unsubscribe link in every marketing email footer; (ii) replying "STOP" via
WhatsApp to our official support number; (iii) updating Communication
Preferences in your authenticated Cloudist dashboard; or (iv) submitting a
written request to dpo@cloudist.my — all processed within five (5) business
days.
Following opt-out, you will continue to receive essential
transactional communications — including invoices, payment
confirmations, security alerts, and service interruption notices — as these
constitute core contractual service delivery and are not subject to marketing
opt-out controls. D'Corp Tech does not engage third-party marketers or data
brokers to target Cloudist customers with personalized advertising using their
personal data.
Clause 1.11Security
ArchitectureBreach Protocol
1.11 Data Security Architecture, Technical
Controls & Breach Response Protocol
D'Corp Tech operates a comprehensive, defense-in-depth information
security architecture protecting personal data against unauthorized access,
unlawful disclosure, accidental loss, destruction, and all other forms of
compromise. Our security posture is continuously reviewed against ISO/IEC
27001:2022 and the NIST Cybersecurity Framework 2.0.
Encryption at Rest & in Transit: All
databases, file storage volumes, and backup archives containing personal
data are encrypted using AES-256. All data in transit between client
browsers and Cloudist servers is protected using TLS 1.3.
Zero-Knowledge Password Security: Customer
passwords are stored exclusively as cryptographic hashes using the Argon2id
algorithm with per-user unique salts. Plaintext or reversibly encrypted
passwords are never stored.
Multi-Factor Authentication (MFA): TOTP-based
MFA is enforced for all privileged administrative accounts and strongly
recommended for all customer accounts via the dashboard security settings.
Web Application Firewall (WAF) & DDoS
Mitigation: All public-facing endpoints are protected by a
continuously updated enterprise WAF with OWASP Top 10 ruleset coverage, with
multi-layer DDoS scrubbing against volumetric, protocol, and
application-layer attacks.
Role-Based Access Controls (RBAC) & Least
Privilege: Access to personal data is strictly controlled via
RBAC, limiting data access to authorized personnel on a verified
need-to-know basis. All privileged access is logged and audited.
Penetration Testing & Vulnerability
Management: Independent third-party penetration tests are
conducted at minimum twice annually. Critical and high-severity
vulnerabilities are patched within seventy-two (72) hours of validated
discovery.
Personnel Security & Training: All D'Corp
Tech personnel and contractors with access to personal data undergo
background verification, mandatory annual data protection training, and are
bound by contractual confidentiality obligations.
In the event of a confirmed data breach, D'Corp Tech activates its
Cyber Incident Response Plan (CIRP): (i) DPO and technical
response team notified within two (2) hours of discovery; (ii) MCMC Personal
Data Protection Commissioner notified within seventy-two (72) hours where
legally required; (iii) affected data subjects notified individually without
undue delay; and (iv) independent forensic digital investigation commissioned.
Zero-Ransom Policy:
D'Corp Tech maintains an absolute no-ransom payment policy. All ransomware
attacks and cyber extortion attempts are immediately reported to PDRM's CCID and
CyberSecurity Malaysia.
Clause 1.12Cross-Border Transfers
1.12 International Data Transfers &
Cross-Border Processing Safeguards
D'Corp Tech primarily processes and stores personal data within
Malaysia. Where approved sub-processors operate systems outside Malaysia —
including Singapore, the EU, or the US — D'Corp Tech ensures that legally
adequate data transfer safeguards are in place as required by Section 129 of the
PDPA 2010. Transfer mechanisms include Standard Contractual Clauses (SCCs) in
all international sub-processor DPAs; formal adequacy assessments of destination
jurisdictions; and contractual obligations requiring immediate notification of
any governmental access request or security incident affecting Cloudist customer
data.
For enterprise customers with mandatory data residency requirements
— including Malaysian government-linked entities and regulated industries —
Cloudist offers dedicated Malaysia-only Data Residency
configurations guaranteeing that all customer data, metadata, and
backup archives remain exclusively within Malaysia-based data center
infrastructure, available as an enterprise add-on under a formal Data Residency
Agreement.
Clause 1.13Policy Updates
1.13 Privacy Policy Amendments, Version
Control & Effective Date Notification
D'Corp Tech reserves the unrestricted right to amend this Privacy
Policy at any time in response to changes in Malaysian data protection
legislation, technological advances in our data processing architecture,
evolution of business operations or sub-processor relationships, judicial or
arbitral decisions affecting data protection obligations, or industry best
practice developments.
Material amendments — changes substantially altering data subject
rights, significantly expanding data categories collected, introducing new
processing purposes, or materially changing data sharing arrangements — shall be
communicated through: (i) a prominent fourteen (14) day advance notice on the
Cloudist homepage and authenticated portal; (ii) a direct email to all
registered account holders at least fourteen (14) days in advance; and (iii) an
updated "Effective Date" and version identifier prominently displayed at the top
of this Privacy Policy page.
The most current version of this Privacy Policy shall at all times
supersede all prior versions. Continued use of any Cloudist service following
the effective date of any amendment constitutes your binding, irrevocable
acceptance of the revised Policy terms. The current operative version is
Privacy Policy Version 2026.3 — Ultra-God Framework Edition,
effective 1 September 2026.
Clause 2.1DefinitionsScope
2.1 Definitions, Interpretation & Scope
of Agreement
This Universal Terms of Service Agreement ("Agreement") constitutes
a legally binding contract between D'Corp Tech (a sole
proprietorship duly registered under Malaysian law, trading as and operating the
Cloudist brand) ("Company," "we," "us," "our") and the
individual, company, or legal entity subscribing to or using any Cloudist
product or service ("Customer," "Client," "you," "your"). This Agreement governs
all commercial interactions, service subscriptions, API access, and platform use
between the parties.
"Services" means all web hosting plans,
virtual private server (VPS) solutions, enterprise cloud computing
infrastructure, domain name registration, SSL/TLS certificate provisioning,
managed engineering retainers, AI-powered development services, eCommerce
platform builds, mobile application development, digital marketing, and all
other products offered by Cloudist.
"Service Order" means a purchase order, online
checkout confirmation, subscription enrollment, or signed service proposal
specifying the particular Services subscribed, pricing tier, billing cycle,
and any special conditions.
"Cloudist Platform" means all software, APIs,
web interfaces, dashboards, AI models, network infrastructure, brand assets,
and technical documentation owned and operated by D'Corp Tech in connection
with the delivery of Services.
"Customer Content" means all data, files,
databases, source code, digital media, website content, applications, and
materials uploaded to or stored on Cloudist-provisioned infrastructure by or
on behalf of the Customer.
"AUP" means the Acceptable Use Policy in
Clause 2.2, defining permitted and prohibited conduct on the Cloudist
Platform.
"SLA" means the Service Level Agreement
commitments in Section 3 (Hosting Agreement), including the 99.9% Monthly
Core Network Uptime guarantee and associated service credit entitlements.
"Effective Date" means the date on which the
Customer completes account registration, submits a Service Order, or
commences use of any Cloudist Service — whichever is earliest.
This Agreement, together with the Privacy Policy (Section 1),
Hosting Agreement (Section 3), Customer Service Policy (Section 4), Refund
Policy (Section 5), and any applicable Service Order, constitutes the entire,
exclusive agreement between the parties with respect to the subject matter
hereof, superseding all prior representations, negotiations, understandings, and
agreements. In conflict between documents, precedence is: (i) signed
supplementary agreement; (ii) Service Order; (iii) Hosting Agreement; (iv) these
Terms of Service; (v) Privacy Policy.
Clause 2.2Acceptable Use
PolicyProhibited Conduct
2.2 Acceptable Use Policy (AUP) &
Prohibited Conduct
All Customers, users, and authorized administrators of Cloudist
Services are irrevocably bound by this Acceptable Use Policy. The AUP defines
the boundaries of lawful, ethical, and technically responsible conduct on the
Cloudist Platform. Violation of any provision constitutes a material breach of
this Agreement and may result in immediate service suspension or account
termination under Clause 2.8, without prior notice, without refund entitlement,
and without liability to D'Corp Tech.
The following conduct categories are strictly and absolutely
prohibited on the Cloudist Platform:
Illegal Content Hosting: Hosting,
distributing, linking to, or facilitating access to any content violating
Malaysian law — including the CMA 1998, Penal Code, Film Censorship Act 2002
— including child sexual abuse material (CSAM), terrorist propaganda,
seditious content, and content violating national security directives.
Network Attacks & Cyber Crimes:
Initiating, facilitating, hosting, or participating in DDoS attacks, DoS
attacks, network scanning or port sweeping, brute-force authentication
attacks, packet injection, traffic spoofing, man-in-the-middle interception,
or any other network attack against Cloudist infrastructure or any external
target.
Malware & Exploit Distribution: Hosting,
uploading, distributing, or executing malware, ransomware, trojans,
rootkits, keyloggers, exploit kits, phishing pages, drive-by download
scripts, or any code designed to compromise, damage, or gain unauthorized
access to any computing system.
Spam & Unsolicited Commercial Email (UCE):
Operating spam campaigns, bulk email sends without recipient consent, email
harvesting operations, or any messaging activity violating the CMA 1998 or
applicable anti-spam regulations.
Cryptocurrency Mining & Unauthorized
Computing: Deploying cryptocurrency mining software, blockchain
validation nodes, or distributed computing clients consuming resources
beyond subscribed allocations without explicit prior written authorization.
Copyright & IP Infringement: Hosting,
distributing, or facilitating unauthorized access to copyrighted content,
software, media, or databases in violation of the Copyright Act 1987 of
Malaysia.
Identity Fraud & Impersonation: Creating
accounts using false, fabricated, or stolen identities; impersonating D'Corp
Tech, Cloudist, or any other entity; or misrepresenting corporate authority
or legal standing in dealings with D'Corp Tech.
Resource Abuse: Deliberately consuming compute
resources in excess of provisioned allocations in a manner adversely
affecting service quality experienced by neighboring tenants on shared
infrastructure.
Mandatory Regulatory
Reporting: D'Corp Tech is legally obligated to report confirmed
instances of CSAM, terrorist content, and certain other illegal activities to
the MCMC, PDRM, and relevant authorities without prior customer notification.
To access Cloudist Services, Customers must complete the account
registration process by providing accurate, complete, and current identity
information — including full legal name or corporate entity name, valid primary
email address, active mobile telephone number, and a secure password. Corporate
accounts must additionally provide the authorized representative's name, title,
and documentary evidence of authority to bind the organization. D'Corp Tech
reserves the right to verify any information submitted during registration and
to suspend accounts where information is found to be false, misleading, or
unverifiable.
Customers are solely and exclusively responsible for: (i)
maintaining strict confidentiality of all account credentials — including
usernames, passwords, API keys, and 2FA recovery codes; (ii) ensuring access to
their Cloudist dashboard and server infrastructure is restricted to authorized
personnel only; (iii) immediately notifying D'Corp Tech via security@cloudist.my
upon discovery of unauthorized access, credential compromise, or account breach;
and (iv) reviewing account access logs at appropriate intervals.
D'Corp Tech strongly recommends and may mandate, for certain service
tiers, the activation of TOTP multi-factor authentication (MFA) on all customer
accounts. D'Corp Tech shall bear no liability for unauthorized access, data
loss, or financial damage resulting from a Customer's failure to maintain
adequate credential security, disclosure of credentials to unauthorized parties,
or failure to activate available MFA controls. All actions performed through an
authenticated account session are legally attributed to the registered account
holder.
Clause 2.4Liability CapDisclaimer
2.4 Limitation of Liability & Exclusion
of Consequential Damages
To the maximum extent permitted by applicable Malaysian law —
including the Contracts Act 1950 — D'Corp Tech, its Founder, directors,
employees, contractors, agents, and approved sub-processors collectively
disclaim all liability for: (i) any indirect, incidental, special,
consequential, punitive, or exemplary damages arising from or in connection with
the use or inability to use any Cloudist Service; (ii) loss of anticipated
business revenue, profits, market share, or commercial opportunity; (iii) loss,
corruption, or unauthorized disclosure of Customer Content; (iv) business
interruption, reputational harm, or brand value diminution; (v) service
disruptions caused by events within the SLA exclusion provisions of Clause 3.2;
or (vi) acts or omissions of approved third-party sub-processors.
The aggregate maximum cumulative liability of D'Corp Tech to any
Customer for all claims — whether in contract, tort, breach of statutory duty,
or any other legal theory — arising from or in connection with this Agreement,
any Service Order, or any Cloudist Service shall be strictly capped and limited
to the lesser of: (a) the total fees actually paid by the Customer for the
specific affected Service during the one (1) calendar month immediately
preceding the event giving rise to the claim; or (b)
Ringgit Malaysia One Hundred (RM100.00).
These limitation of liability provisions reflect a reasonable
allocation of risk between the parties — a risk allocation reflected in the
competitive pricing at which Cloudist Services are offered. Nothing herein
excludes D'Corp Tech's liability for: (i) death or personal injury caused by
D'Corp Tech's gross negligence; (ii) fraudulent misrepresentation; or (iii) any
liability that cannot lawfully be excluded under the Consumer Protection Act
1999.
Warranty Disclaimer:
Cloudist Services are provided on an "AS IS" and "AS AVAILABLE" basis without
warranty of any kind — express, implied, or statutory — including any implied
warranty of merchantability, fitness for a particular purpose, non-infringement,
data accuracy, uninterrupted availability, or freedom from harmful code.
This Agreement and all contractual relations, obligations, disputes,
and claims arising from or in connection with it — including questions of
validity, formation, interpretation, performance, breach, or termination — shall
be exclusively governed by and construed in accordance with the Laws of
Malaysia, including without limitation the Contracts Act 1950, the
Civil Law Act 1956, and all applicable Malaysian statutory and regulatory
instruments, without regard to conflict-of-law rules that would apply the law of
another jurisdiction.
Any dispute, controversy, or claim arising out of or relating to
this Agreement shall be finally and exclusively resolved through binding
arbitration administered by the Asian International
Arbitration Centre (AIAC) in Kuala Lumpur, Malaysia, in accordance
with the AIAC Arbitration Rules then in effect. The seat and legal place of
arbitration shall be Kuala Lumpur, Malaysia. The language of
all proceedings and awards shall be English. The tribunal shall
consist of a sole arbitrator for disputes not exceeding RM250,000.00, or a
three-person panel for larger disputes. The arbitral award shall be final,
binding, and enforceable in any competent court worldwide.
The parties hereby expressly and irrevocably waive: (i) any right to
initiate, join, or participate in class action or collective dispute
proceedings; (ii) any right to trial by jury; and (iii) any right to litigate
disputes outside the AIAC arbitration framework, except for applications for
urgent interlocutory or conservatory relief. D'Corp Tech reserves the right to
seek emergency injunctive relief in any competent Malaysian court to prevent
irreparable harm to its intellectual property, platform security, or business
operations.
Clause 2.6Billing &
PaymentAuto-Renewal
2.6 Billing Cycles, Payment Methods,
Auto-Renewal & Late Payment Consequences
All Cloudist Services are billed in advance on a monthly, quarterly,
semi-annual, or annual billing cycle as elected at Service Order submission.
Electronic invoices are generated and dispatched to the registered account email
on the first day of each billing period. Payment is contractually due within
seven (7) calendar days of invoice issuance, unless a longer
payment term is expressly agreed in a signed Service Order or enterprise
framework agreement.
FPX Online Banking (Preferred for Malaysian
Entities): Direct real-time bank transfer via Malaysia's
Financial Process Exchange (FPX) — accepted from all major Malaysian banks
including Maybank, CIMB, Public Bank, RHB, Hong Leong, and AmBank.
International Credit & Debit Cards: Visa,
Mastercard, and American Express processed through Stripe's PCI-DSS Service
Provider Level 1 certified infrastructure. Card data is tokenized at point
of capture; D'Corp Tech never stores full card numbers.
Local Payment Gateways: ToyyibPay, Billplz,
iPay88, Razer Merchant Services, and other MCMC-registered and BNM-regulated
Malaysian payment service providers.
Telegraphic Transfer (TT): Domestic or
international wire transfers to D'Corp Tech's designated corporate bank
account, subject to three (3) to five (5) business days clearing. TT
reference must be provided to support@cloudist.my upon initiation.
Cryptocurrency (Enterprise Only): Select
cryptocurrency payment pairs may be accepted for enterprise contracts
exceeding RM10,000.00 per annum, subject to D'Corp Tech's prior written
approval and at the prevailing exchange rate at time of processing.
Auto-Renewal: Unless the Customer provides clear
written cancellation notice — via authenticated dashboard request or to
support@cloudist.my — at least seventy-two (72) hours before the renewal date,
all active subscriptions automatically renew at the then-current published
pricing. Renewal invoice notifications are dispatched seven (7) days before the
renewal date.
Late Payment Escalation:
Day 1-7 post-due: Payment reminder. Day 8-14: Grace suspension (services
provisioned but throttled). Day 15+: Services suspended and data archived. Day
45+: Account terminated and data scheduled for deletion. RM30.00 administrative
late fee per overdue invoice applicable from Day 8 onwards.
Cloudist Platform IP: All software source code,
proprietary algorithms, AI models, user interface design systems, visual
graphics, logos, brand marks, trade dress, domain names, product names,
technical documentation, API specifications, and all other intellectual property
comprising the Cloudist Platform are and shall remain the exclusive,
unencumbered property of D'Corp Tech and its Founder, comprehensively protected
under the Copyright Act 1987 (Act 332) and Trademarks
Act 2019 (Act 815) of Malaysia, and international conventions
including the Berne Convention and TRIPS Agreement.
A Cloudist service subscription grants the Customer a strictly
limited, non-exclusive, non-transferable, non-sublicensable, revocable license
to access and use the Cloudist Platform dashboard and APIs solely for the
purpose of managing and consuming their subscribed Services. No Customer
acquires ownership rights, sublicense rights, reverse engineering rights, or any
other intellectual property rights in or to the Cloudist Platform through a
service subscription.
Customer Content Ownership: The Customer retains
full, exclusive, and unencumbered ownership of all Customer Content. D'Corp Tech
is granted a strictly limited, non-exclusive, royalty-free, non-transferable
operational license to host, store, cache, transmit, backup, and process
Customer Content solely for the purpose of delivering contracted Services, and
for no other purpose.
Customer IP Warranty: The Customer unconditionally
represents and warrants that Customer Content does not infringe any copyright,
trademark, patent, trade secret, moral right, privacy right, or other
intellectual property right of any third party; the Customer holds all necessary
rights and permissions; and Customer Content does not violate applicable law.
The Customer accepts exclusive liability for all third-party intellectual
property infringement claims arising from Customer Content.
Clause 2.8Suspension &
Termination
2.8 Account Suspension, Service Restriction
& Termination Rights
D'Corp Tech reserves the unilateral, executive right to immediately
suspend, restrict, throttle, or terminate any Cloudist Service or Customer
account — with or without advance notice, and without refund obligation for
unexpired pre-paid service — upon discovery or reasonable determination of any
of the following triggering circumstances:
AUP Violation (Clause 2.2): Any confirmed or
credibly suspected violation of the Acceptable Use Policy — including
malware distribution, DDoS origination, spam operations, or illegal content
hosting. AUP violations trigger immediate suspension with no prior warning
required.
Non-Payment or Payment Default: Outstanding
invoices not settled within fourteen (14) calendar days of the due date
following the escalation schedule in Clause 2.6.
Identity Fraud or Fraudulent Registration:
Discovery that account registration information is false, fabricated, or
based on stolen identity; use of stolen payment instruments; or fraudulent
misrepresentation in dealings with D'Corp Tech.
Legal Mandates & Regulatory Directives:
Receipt and verification of a valid judicial court order, MCMC directive,
Bank Negara Malaysia instruction, or other binding legal mandate requiring
suspension, content removal, or account data disclosure.
Active Security Threat: Where Cloudist's
security monitoring determines that a Customer's infrastructure is actively
compromised, conducting unauthorized scanning, propagating malware, or
posing a credible threat to Cloudist's multi-tenant infrastructure or
neighboring customers.
Regulatory Non-Compliance: Discovery that
Customer operations violate applicable Malaysian or international law in a
manner creating legal, reputational, or regulatory risk for D'Corp Tech.
For voluntary Customer-initiated account termination, a written
request must be submitted via the authenticated Cloudist dashboard or to
support@cloudist.my with minimum fourteen (14) calendar days' advance
notice. Customer Content remains accessible and downloadable for
thirty (30) calendar days post-termination, after which all Customer Content is
permanently and irreversibly deleted from all Cloudist systems and backup
archives.
No-Liability Suspension:
D'Corp Tech bears zero liability for any loss, damage, business interruption,
revenue loss, reputational harm, or data inaccessibility resulting from any
lawful service suspension or termination executed under this Clause.
Customers operating as digital agencies, managed service providers
(MSPs), IT consultancies, web development studios, or other technology
intermediaries who wish to provision, manage, or commercially resell Cloudist
Services to their end clients must operate under a formally executed
Cloudist Reseller Partnership Agreement ("CRPA") — a distinct
legal instrument separate from and supplementary to these Universal Terms of
Service specifying reseller pricing tiers, white-label branding permissions,
sub-account management rights, and supplementary obligations.
Authorized Cloudist Resellers under a valid CRPA may present
Cloudist infrastructure under their own brand ("white-label"), subject to the
following non-negotiable mandatory conditions:
Resellers remain exclusively, primarily, and severally liable
to D'Corp Tech for 100% of all service fees, renewal charges, and applicable
taxes — irrespective of whether end clients have paid the reseller.
Resellers must contractually bind their end clients to usage
terms no less restrictive than this AUP regarding illegal content, network
abuse, spam, malware, and data protection compliance.
Resellers may not sublicense, transfer, assign, sub-resell, or
redistribute Cloudist's core infrastructure, intellectual property, or
Platform APIs to third parties beyond their contracted end clients without
the express prior written consent of D'Corp Tech's Founder.
Resellers may not represent themselves as D'Corp Tech,
Cloudist, or any affiliated entity in public communications, regulatory
filings, contracts with end clients, or any other context.
Resellers must immediately notify D'Corp Tech of any end client
AUP violations, security incidents affecting shared infrastructure, or legal
process directed at reseller-managed accounts.
Unauthorized commercial resale or redistribution of Cloudist
Services by any Customer without a valid, currently effective CRPA constitutes a
material breach and grounds for immediate account termination without refund.
D'Corp Tech reserves the right to pursue full recovery of commercial damages
from unauthorized resale activities.
Clause 2.10API PolicyRate Limiting
2.10 API Access, Rate Limiting, Programmatic
Interfaces & Prohibited Automation
D'Corp Tech provides RESTful HTTP and WebSocket API access to the
Cloudist Platform for eligible enterprise customers under designated API
licensing tiers. API access is granted upon issuance of an authenticated API key
pair and is governed in all respects by this Agreement. API access is a
privilege, not a right, and may be modified, restricted, or revoked at any time
in the exercise of platform governance authority.
API Key Security Responsibility: The Customer
is solely responsible for secure generation, storage, rotation, and
revocation of all API keys and OAuth credentials. Keys must be stored in
encrypted secrets management systems and never exposed in publicly
accessible source code, client-side code, or unencrypted configuration
files. D'Corp Tech bears zero liability for unauthorized API access
resulting from Customer-side key compromise.
Rate Limiting & Quota Enforcement: API
request rates are metered against the quota defined by the Customer's
subscribed API tier. Requests exceeding the quota receive HTTP 429 "Too Many
Requests" responses and are throttled. Sustained quota violations may
trigger automatic temporary IP-level rate limiting or API key suspension.
Prohibited Programmatic Activities: Strictly
prohibited activities include automated mass account creation or
enumeration; credential stuffing or password spraying; bulk scraping of
Cloudist's website, documentation, or knowledge base; resource exhaustion
attacks against API endpoints; unauthorized reconnaissance of Cloudist's API
infrastructure; and bypassing rate limiting through distributed request
rotation across multiple IP addresses or accounts.
Third-Party Integration Disclosure: Customers
integrating third-party applications with the Cloudist API in a manner
routing personal data through the third-party must: (i) disclose the data
flow to D'Corp Tech's DPO upon request; (ii) ensure PDPA 2010 compliance;
and (iii) accept full responsibility for the third-party's data protection
practices.
AI & Machine Learning
Prohibition: Cloudist's proprietary AI inference APIs, language
model outputs, and AI-generated recommendations are licensed exclusively for
Customer production use. Using Cloudist's AI outputs for training, fine-tuning,
distilling, benchmarking, or reverse-engineering any external AI or machine
learning model without a separately executed Data Science Partnership Agreement
is strictly and absolutely prohibited.
For individual consumers who subscribe to Cloudist Services in their
personal capacity — not as a business entity, corporate representative, or
professional — certain non-derogable, mandatory statutory rights exist under the
Consumer Protection Act 1999 (Act 599) of Malaysia. D'Corp Tech
unequivocally recognizes and respects these rights. Nothing in these Terms of
Service is intended to limit, exclude, abrogate, or derogate from any consumer
right that is mandatorily protected and cannot lawfully be excluded under
applicable Malaysian consumer protection legislation.
All Cloudist Services are rendered with reasonable care,
professional skill, and due diligence by qualified personnel, in accordance
with Section 53 of the Consumer Protection Act 1999 (implied warranty of
services).
All service descriptions, feature specifications, performance
benchmarks, and pricing published on cloudist.my are accurate, truthful, and
not misleading or deceptive in breach of Sections 13-17 of the Consumer
Protection Act 1999.
All promotional offers, limited-time discounts, and bundled
pricing arrangements are clearly disclosed with applicable terms,
conditions, and expiry dates prominently communicated before purchase.
Consumer data is protected in accordance with the Privacy
Policy and PDPA 2010, with consumer rights under Part VII of the Consumer
Protection Act 1999 fully preserved.
Individual consumer subscribers who believe D'Corp Tech has failed
to comply with the Consumer Protection Act 1999 may refer their complaint to the
Tribunal for Consumer Claims Malaysia (TTPM) under Part XII of
the Consumer Protection Act 1999 for claims not exceeding RM50,000.00, in
addition to any rights available through AIAC arbitration.
D'Corp Tech is a sole proprietorship under Malaysian law, and all
ultimate, final, and unappealable executive authority over the Cloudist Platform
— including all decisions relating to infrastructure security architecture,
resource tier allocations, service pricing and feature sets, AUP enforcement
actions, account sanctions and terminations, platform feature deprecations,
strategic service partnerships, data center selection, and all other platform
governance matters — vests exclusively and irrevocably in the Founder
and Owner of D'Corp Tech.
The Founder's executive prerogative is legally supreme and
operationally absolute. No Customer, reseller, investor, or other third party —
except regulatory bodies acting within the lawful boundaries of their statutory
authority — may limit, challenge, supersede, or otherwise interfere with the
Founder's unilateral decision-making authority over the Cloudist Platform and
D'Corp Tech's business operations. The exercise of Founder authority shall at
all times be conducted in good faith and in compliance with applicable Malaysian
law.
D'Corp Tech reserves the unilateral right to amend these Terms of
Service at any time for any reason, including in response to legal changes,
technological advancement, business model evolution, or regulatory guidance.
Amended Terms shall be published on cloudist.my with at least fourteen (14)
days' notice to active subscribers for material amendments. Continued use of any
Cloudist Service following the effective date of any amendment constitutes full,
irrevocable, and binding acceptance of the revised Terms.
Current Effective
Version: This Universal Terms of Service Agreement is Version
2026.3 — Ultra-God Framework Edition, effective 1 September 2026. This version
supersedes all prior versions in their entirety.
Clause 3.199.9% Uptime
SLAService
Credit Matrix
3.1 Service Level Agreement (SLA), 99.9%
Network Uptime Guarantee & Service Credits
D'Corp Tech provides an enterprise-grade Service Level
Agreement (SLA) guaranteeing a minimum of 99.9% Monthly
Core Network Uptime for all provisioned cloud hosting, VPS, and
shared hosting services. This commitment reflects Cloudist's investment in
carrier-grade network infrastructure, redundant power systems, multi-homed BGP
routing, and enterprise storage architectures across Tier III+ certified data
center operations.
"Monthly Core Network Uptime" is defined as the percentage of total
minutes in a calendar month during which the Customer's provisioned server
instance(s) are reachable via the public network — as measured from Cloudist's
core network monitoring infrastructure — excluding downtime attributable to SLA
Exclusion events in Clause 3.2. Uptime is calculated as: ((Total Monthly
Minutes − Verified Downtime Minutes) / Total Monthly Minutes) ×
100.
Where Monthly Core Network Uptime falls below 99.9% in a given
billing cycle, eligible Customers may submit a Service Credit claim per the
following verified schedule:
Monthly Network Uptime
Equivalent Outage Window
Service Credit Entitlement
99.90% – 100%
≤ 43 minutes/month
SLA Met — No
Credit Due
99.00% – 99.89%
43 min – 7.3 hours
5% of Monthly Service
Fee
98.00% – 98.99%
7.3 – 14.4 hours
10% of Monthly Service
Fee
95.00% – 97.99%
14.4 – 36.5 hours
25% of Monthly Service
Fee
< 95.00%
> 36.5 hours/month
50% of Monthly Service Fee
(Maximum)
Service Credits are the Customer's sole and
exclusive financial remedy for SLA breach. Credits are applied as billing
credits against future invoices and cannot be redeemed for cash. Claims must be
submitted to support@cloudist.my within fifteen (15) calendar days of the
affected billing month's end.
Clause 3.2SLA ExclusionsForce Majeure
3.2 SLA Exclusions, Force Majeure Events
& Shared Responsibility Model
The 99.9% Monthly Core Network Uptime SLA and associated Service
Credit entitlements apply exclusively to service interruptions within D'Corp
Tech's direct operational control attributable to Cloudist's own infrastructure
failures. The following events are expressly excluded from SLA calculations and
do not generate Service Credit entitlements:
Scheduled Maintenance Events: Planned
maintenance windows announced at least twenty-four (24) hours in advance via
the Cloudist status page and email notification — covering kernel patching,
hypervisor firmware upgrades, network equipment maintenance, storage
controller replacements, and fiber cable work.
Customer-Initiated Actions: Interruptions from
the Customer's own actions — including accidental file deletion, database
corruption from application updates, CMS plugin conflicts, misconfigured
firewall rules, incorrect DNS modifications, failed deployments, or errors
in Customer-executed server commands.
Upstream Telecommunications & Internet
Infrastructure: Outages attributable to MyIX disruptions,
subsea cable failures, Transit ISP BGP routing anomalies, or Tier 1 internet
backbone disruptions entirely outside Cloudist's network boundary and BGP
peering relationships.
DDoS Attacks Exceeding Scrubbing Thresholds:
DDoS attacks exceeding the contracted scrubbing capacity where null-routing
of the targeted IP is applied as a protective measure to preserve
multi-tenant network integrity.
Force Majeure Events: Acts of God, natural
disasters (earthquakes, floods, tsunamis), acts of war, civil insurrection,
national emergency declarations, government-mandated infrastructure
shutdowns, pandemic-related facility closures, or any other event beyond
D'Corp Tech's reasonable control.
Third-Party Service Failures: Failures of
upstream providers including DNS registrar outages, SSL CA failures, payment
gateway disruptions, or CDN provider failures not within D'Corp Tech's
operational control.
Security Isolation Actions: Temporary network
isolation or null-routing of Customer instances implemented in response to
confirmed active security threats, malware propagation, or abuse originating
from the Customer's infrastructure.
Shared Responsibility
Model: D'Corp Tech is responsible for the security and availability
of the underlying hosting infrastructure ("security of the cloud"). The Customer
is responsible for security of their applications, data, OS configurations,
access credentials, and network settings ("security in the cloud").
Cloudist deploys a multi-tier, enterprise-grade Distributed Denial
of Service mitigation architecture protecting all hosted infrastructure against
volumetric network attacks, protocol exploitation, and application-layer attack
vectors across OSI Layers 3, 4, and 7.
Network-Layer (L3) Volume Mitigation: Upstream
volumetric DDoS traffic filtered at the carrier edge using BGP Flowspec and
RTBH (Remotely Triggered Black Hole) techniques, protecting against UDP
floods, ICMP floods, and IP fragment attacks at terabit scale.
Transport-Layer (L4) Protocol Defense: SYN
flood protection via SYN cookies and SYN proxy; TCP state table exhaustion
prevention; UDP reflection and amplification mitigation (NTP, DNS, SSDP,
CLDAP amplification vectors).
Application-Layer (L7) WAF Filtering: Web
Application Firewall rules protecting against HTTP/S floods, Slowloris
attacks, HTTP header manipulation, SSL renegotiation attacks, and exploit
payloads — aligned with OWASP Top 10.
BGP Null-Routing (Blackholing): Where inbound
DDoS attack volume exceeds contracted scrubbing thresholds or poses a
credible threat to hypervisor stability and multi-tenant integrity,
Cloudist's automated systems may null-route the targeted IP at the BGP
level. The Customer is notified and the null-route removed once the attack
subsides.
Hypervisor-Level Security Isolation: Each VPS
and cloud instance is isolated at the hypervisor level through dedicated
VLAN segmentation, strict firewall enforcement, and network namespace
isolation — architecturally preventing cross-tenant data access or traffic
bleeding.
Instances exhibiting confirmed active compromise — outbound malware
C2 communications, active port scanning, SMTP spam relay, or botnet
participation — will be immediately placed into full network isolation, with
simultaneous notification to the Customer. Isolation remains in effect until the
Customer provides a remediation plan and written AUP compliance commitment.
Responsible Disclosure:
Customers discovering security vulnerabilities in Cloudist's platform
infrastructure must immediately report to security@cloudist.my under responsible
disclosure principles. D'Corp Tech operates a formal vulnerability disclosure
program.
Clause 3.4Backup
ObligationsData
Sovereignty
3.4 Customer Data Backup Obligations,
Disaster Recovery & Data Sovereignty
While D'Corp Tech performs routine infrastructure-level snapshot and
backup operations as part of platform operational procedures, the Customer bears
full, exclusive, and unconditional legal and operational
responsibility for maintaining independent, comprehensive, and
regularly tested backup copies of all Customer Content — including all website
files, databases, email data, application source code, configuration files, and
any other data stored on Cloudist-provisioned infrastructure.
Cloudist's infrastructure-level snapshots are performed for
platform disaster recovery purposes only and are not guaranteed
to be Customer-Content-complete, immediately accessible to Customers, or
available for individual file restoration. Cloudist's backup operations must not
be relied upon as the Customer's primary or sole backup strategy. Specific
backup service tiers with defined Customer Content restoration capabilities may
be available as optional add-on services.
Automated Daily Database Dumps: Scheduled
exports of all MySQL, MariaDB, PostgreSQL, or MongoDB databases to an
off-platform storage destination — separate cloud storage bucket, NAS, or
geographically remote server.
Weekly Full-Filesystem Backups: Complete
filesystem archives of all web files, application directories, and
configuration files retained for a minimum of four (4) weeks.
Version Control Integration: All application
source code maintained in a Git repository hosted off-platform (GitHub,
GitLab, Bitbucket, or self-hosted Gitea).
3-2-1 Backup Rule: At minimum three (3) copies
of data on at least two (2) different storage media types, with at minimum
one (1) copy stored off-site in a geographically separate location.
Backup Restoration Testing: Periodic testing
of restoration procedures — at minimum quarterly — to verify backup
completeness, data integrity, and recoverability within the Customer's
target RTO.
Liability Disclaimer — Data
Loss: D'Corp Tech disclaims all liability for loss, corruption, or
unavailability of Customer Content arising from hardware failure without
available snapshot, Customer-executed deletion, CMS update failures, database
application errors, or any event not attributable to D'Corp Tech's gross
negligence. The Customer's independent backup strategy is their primary data
protection mechanism.
Clause 3.5Resource QuotasFair Use Policy
3.5 Resource Quotas, Fair Use Policy &
Compute Allocation Enforcement
Each Cloudist hosting plan is provisioned with defined compute
resource allocations — including vCPU core count, RAM (GB), NVMe SSD storage
(GB), monthly network data transfer quota (GB), and concurrent process limits —
as specified in the Service Order or published pricing tier. These quotas define
the Customer's contractual resource entitlement and must not be exceeded without
upgrading to a higher-tier plan.
CPU Utilization Throttling: For shared hosting
plans, sustained average CPU utilization exceeding the plan's defined
process threshold for fifteen (15) or more continuous minutes triggers
automated process-level throttling via cgroups resource controls, preventing
single-tenant monopolization from degrading neighboring tenants. VPS and
dedicated server plans are not CPU-throttled within provisioned vCPU
allocations.
Storage Quota Monitoring & Enforcement:
Automated email alerts are triggered at 80%, 90%, and 95% disk usage. At
100% saturation, write operations are suspended — new file uploads, database
insertions, and log writes fail until capacity is freed or the plan is
upgraded. Email dispatch may also be suspended where mail queue storage is
implicated.
Bandwidth Overage Billing: For plans with
defined monthly transfer quotas, excess bandwidth is billed at RM0.50 per
additional GB (subject to change with thirty (30) days' notice). Plans
marketed as "Unmetered Bandwidth" are subject to a 10Gbps port-speed fair
use policy — unmetered by volume but constrained to the provisioned port
speed.
Concurrent Connection & Process Limits:
PHP-FPM worker pool sizes, concurrent database connections, and cron job
execution frequency are capped per plan tier. Exceeding soft limits triggers
queuing; exceeding hard limits results in connection rejection.
Prohibited Resource Activities: Irrespective
of available headroom, prohibited on all standard plans without prior
written authorization: cryptocurrency mining, blockchain validation,
GPU-accelerated neural network training, distributed computing workloads,
BitTorrent seeding, and IRC server operation.
Clause 3.6Domain
ManagementDNS
Services
3.6 Domain Registration, DNS Zone Management
& Transfer Authorization Protocols
Where Cloudist provides domain name registration — bundled in a
hosting package or as a standalone service — registrations are facilitated
through ICANN-accredited international registrar partners for gTLDs (.com, .net,
.org, .io, .tech, .ai, .app) and through MYNIC-accredited Malaysian registrar
channels for ccTLDs (.com.my, .my, .org.my, .net.my, .edu.my, .gov.my).
Domain Ownership & Registrant of Record:
The Customer retains full, exclusive legal ownership and administrative
control of all registered domain names. D'Corp Tech acts exclusively as a
technical management and billing intermediary. Cloudist will never register
domains in D'Corp Tech's name or hold them as collateral without express
written Customer authorization.
Annual Renewal & Grace Periods: D'Corp
Tech dispatches renewal reminders sixty (60), thirty (30), seven (7) days,
and on the expiry day. Expired domains enter a thirty (30) day Redemption
Grace Period (RGP) at standard renewal fee plus an RGP recovery charge.
After RGP, domains enter a five (5) day Pending Delete phase before public
release.
Domain Transfer Authorization (EPP Code): To
initiate an outbound domain transfer, the Customer requests the EPP
Authorization Code via the Cloudist dashboard. Transfers may be initiated
after sixty (60) days from initial registration or last transfer (per ICANN
IRTP). Transfer unlock requests are processed within two (2) business days.
Domain Locking: All domains are registered
with Registrar Lock enabled by default as a security measure against
unauthorized transfers. Customers may unlock via the dashboard when
initiating a legitimate transfer.
DNS Record Management & Propagation: DNS
record modifications (A, AAAA, CNAME, MX, TXT, SRV, CAA) take effect within
sixty (60) seconds at Cloudist's authoritative nameservers. Global
propagation across all public resolvers may take up to forty-eight (48)
hours depending on TTL values. D'Corp Tech accepts no liability for
interruptions during DNS propagation periods initiated by Customer-directed
changes.
All Cloudist hosting plans include complimentary, fully automated
SSL/TLS certificate provisioning via the Let's Encrypt Certificate
Authority (CA) — a globally trusted, non-profit CA operated by the
Internet Security Research Group (ISRG). Let's Encrypt certificates provide
Domain Validation (DV) level assurance, are recognized by all major browsers and
operating systems, and are automatically renewed on a ninety (90) day rotation
cycle through the ACME protocol.
Automated Certificate Lifecycle Management:
Certificates are renewed automatically fifteen (15) days before expiry via
ACME HTTP-01 or DNS-01 challenge validation. Customers must ensure: (i) DNS
records correctly point to the Cloudist server; (ii) port 80 (HTTP) is
accessible to ACME challenge servers; and (iii) custom WAF rules, .htaccess,
or CDN proxy settings do not block ACME challenge verification requests.
Premium CA Certificates (EV, OV, Wildcard):
For enterprise requirements — Extended Validation (EV) certificates
displaying company name in browsers, Organization Validation (OV)
certificates verifying corporate identity, or Wildcard certificates
(*.domain.com) protecting all subdomains — Cloudist offers managed
procurement and installation from DigiCert, Sectigo, GlobalSign, and Entrust
as professional add-ons.
HTTPS Redirect Enforcement: Cloudist enables
automated HTTP-to-HTTPS redirection at the reverse proxy level for all
hosted domains with valid SSL certificates. HSTS (HTTP Strict Transport
Security) response headers may additionally be configured through the
Cloudist dashboard.
Customer-Managed Certificate Installation:
Enterprise customers managing their own certificates may install via the
dashboard or SFTP. Customers who install self-managed certificates accept
sole responsibility for monitoring expiry and performing timely renewal.
D'Corp Tech bears no liability for service degradation from Customer-managed
certificate expiry.
TLS Version Enforcement: Cloudist enforces TLS
1.2 minimum on all hosted domains and recommends TLS 1.3. Legacy SSL 3.0,
TLS 1.0, and TLS 1.1 are disabled by default due to known vulnerabilities.
Time-limited technical exemption requests may be submitted for legacy system
compatibility.
Clause 3.8Website MigrationOnboarding
3.8 Website Migration, Platform Onboarding
& Transfer Liability Framework
Cloudist provides complimentary website migration assistance as part
of the onboarding experience for new customers transitioning from third-party
hosting providers. Our migration service is designed to minimize downtime,
preserve data integrity, and ensure a seamless transition to Cloudist
infrastructure.
Complimentary migration scope includes:
Static Website & CMS Files: All HTML, CSS,
JavaScript, PHP, image, media, and other website files; complete WordPress,
Joomla, Drupal, PrestaShop, Magento, or other CMS installations including
themes, plugins, and content.
Database Content: MySQL, MariaDB, or
PostgreSQL database exports including all tables, stored procedures, views,
and data — up to the Customer's subscribed plan storage quota.
Email Configurations: DNS MX records, email
account configurations, and mailbox data transfers up to 5GB total mailbox
storage.
DNS Zone Files: Complete DNS zone transfer
including all record types (A, AAAA, CNAME, MX, TXT, SRV) from the source
DNS provider to Cloudist's authoritative DNS infrastructure.
Migration Timeline: Standard migrations are
completed within two (2) to five (5) business days from receipt of valid source
server access credentials (cPanel login, SFTP, or complete backup archive),
written migration authorization, and confirmation of no legal encumbrances.
Complex migrations — multi-server configurations, databases over 10GB, custom
middleware stacks, or high-traffic eCommerce platforms — require an extended
timeline mutually agreed before commencement.
Data Integrity
Guarantee: Cloudist performs pre-migration MD5/SHA-256 checksum
verification of all transferred archives and conducts post-migration functional
testing to verify website accessibility, database connectivity, and email
receipt before requesting migration completion confirmation from the Customer.
D'Corp Tech executes scheduled infrastructure maintenance activities
— including Linux kernel security patches, hypervisor platform upgrades, network
switch firmware updates, storage controller replacements, and data center
facility maintenance — under a structured Change Management
Protocol designed to minimize service impact and maintain SLA
framework integrity.
Standard Maintenance Windows: Scheduled
between 2:00 AM to 6:00 AM Malaysian Standard Time (MST,
UTC+8) on Tuesdays and Saturdays — empirically the
lowest-traffic periods. Announced via the Cloudist status page
(status.cloudist.my) and email at least twenty-four (24)
hours in advance.
Extended Maintenance Windows: Major
infrastructure upgrades — complete data center electrical maintenance, SAN
storage migrations, or BGP routing topology changes — may require four (4)
to eight (8) hour windows announced at least seventy-two (72)
hours in advance with detailed impact assessments.
Emergency Security Patching (Zero-Day
Response): Critical vulnerabilities (CVEs rated CVSS 9.0+ or
actively exploited in the wild) require immediate out-of-window patching
with minimal or no advance notice. A formal security advisory and
post-patching incident report is published within twenty-four (24) hours of
emergency patch deployment.
Hypervisor Live Migration (Zero-Downtime):
Where technically feasible, VPS instances are live-migrated between physical
hosts using QEMU KVM live migration, typically completing in under sixty
(60) seconds with no perceptible service interruption.
Cold Migration (Scheduled Restart): Where live
migration is not feasible, a scheduled cold migration requiring a controlled
instance restart of approximately three (3) to five (5) minutes is performed
with minimum forty-eight (48) hours advance notice within the standard
maintenance window.
SLA Maintenance
Exclusion: All downtime during properly announced maintenance
windows is explicitly excluded from the 99.9% Monthly Core Network Uptime SLA
calculation per Clause 3.2. Emergency patching downtime may also be excluded
where the patch was necessitated by an active, critical security threat.
Clause 4.1Multi-Channel
Support
4.1 Multi-Channel Enterprise Support
Architecture & Communication Standards
Cloudist operates a dedicated, multi-tiered customer support
infrastructure serving the full spectrum of enterprise clientele — from
individual website owners and SMEs to large-scale corporations managing
mission-critical cloud deployments. All support interactions are conducted with
the highest standard of technical professionalism, clear communication, and
solution-oriented urgency appropriate to each incident's severity
classification.
Client Dashboard Portal
Authenticated ticketing with complete
SLA tracking, audit history, and escalation controls.
All support requests via official channels are assigned a unique
ticket reference number and tracked through Cloudist's internal incident
management system from submission through resolution and post-closure
satisfaction assessment. Requests via unofficial channels — personal social
media, forum posts, or unsolicited calls — cannot be guaranteed a response and
do not activate SLA response obligations.
Clause 4.2Incident Severity
Matrix
4.2 Incident Classification Framework &
Response Time Service Level Targets
Cloudist employs a four-tier incident severity classification
framework ensuring technical support resources are allocated proportionally to
business impact, with highest-urgency incidents receiving immediate, continuous
engineering attention.
Severity
Incident Description
Initial Response
Resolution Target
Sev 1 —
Critical
Core production service down; website inaccessible; database
offline; network unroutable; active security breach in progress.
Non-critical bug; control panel slowdown; minor feature
malfunction; isolated intermittency not affecting primary
functionality.
≤ 4 biz hours
≤ 24 biz hours
Sev 4 —
General
General inquiries; billing questions; DNS configuration advice;
domain management; account settings; general technical
consultation.
≤ 12–24 biz hours
Standard business flow
* Business hours: Mon–Fri, 9:00 AM–6:00 PM
MST. Severity 1 & 2 incidents trigger 24/7 on-call escalation irrespective
of business hours. Response targets are best-effort commitments and do not
independently constitute additional SLA warranties beyond Section 3.
Clause 4.3Support Scope
4.3 Demarcation of Support Scope &
Technical Responsibility Boundaries
Cloudist's standard support encompasses all matters within D'Corp
Tech's direct operational control — specifically the underlying hosting
infrastructure, network connectivity, operating system kernel stability, DNS
operations, hypervisor health, physical data center infrastructure, and base
container runtime environments.
Standard support covers:
Server hardware, data center, network infrastructure,
hypervisor platform, and virtualization layer issues.
Base OS (Linux kernel) stability, system daemon failures, and
core system library issues.
Cloudist DNS authoritative server operations and DNS record
changes through the dashboard.
SSL/TLS certificate provisioning, renewal failures, and HTTPS
configuration through the Cloudist platform.
Billing system inquiries, invoice disputes, payment processing
questions, and subscription management.
Domain registration, transfer, lock/unlock, and renewal through
the Cloudist domain management interface.
Outside standard scope (requires a MESA retainer
per Clause 4.7):
Debugging Customer-developed PHP, Node.js, Python, Ruby, Go, or
other application source code.
MySQL/MariaDB/PostgreSQL query optimization or database schema
design.
WordPress plugin conflicts, theme customizations, or
third-party CMS configuration troubleshooting.
Customer-managed WAF, CDN, or load balancer configuration.
CI/CD pipeline development, Docker orchestration, or DevOps
automation workflows.
Application security architecture advisory or application-level
penetration testing.
Clause 4.4Personnel
ProtectionZero
Tolerance
4.4 Anti-Harassment Policy & Support
Personnel Protection
D'Corp Tech enforces an absolute, unwavering zero-tolerance policy
against any form of abusive, threatening, harassing, vulgar, discriminatory, or
demeaning conduct directed at Cloudist's engineering team, support
representatives, account managers, or any other personnel — whether in written
tickets, email, WhatsApp, or any other channel.
Prohibited conduct includes: profane, vulgar, or sexually explicit
language; threats of physical harm expressed in an intimidatory manner; racial,
ethnic, religious, or gender-based discriminatory language; deliberate
misrepresentation of facts or wilful deception of support personnel; and
sustained, repetitive submission of bad-faith tickets intended to consume
support resources without legitimate technical basis.
Upon confirmed violation, Cloudist reserves the right to: (i)
immediately terminate the active support interaction and close the associated
ticket; (ii) suspend the Customer's interactive support privileges for a defined
period; and (iii) initiate account termination proceedings under Clause 2.8
without refund entitlement. Credible threats of physical harm will be reported
in full cooperation with PDRM and legal authorities.
Tier 1 — Customer Support Engineers: Handle
all inbound support, initial triage, Severity 3 and 4 incidents, general
account inquiries, billing questions, DNS assistance, and standard CMS
troubleshooting. Target resolution: same business day.
Tier 3 — Systems Architecture Specialists:
Engaged for all Severity 1 incidents; hypervisor failures; BGP routing
anomalies; SAN storage array failures; DDoS attacks exceeding standard
mitigation; and any incident with multi-tenant impact potential. Continuous
engagement until resolved.
Tier 4 — Founder & Executive Engineering
Review: Reserved for strategic enterprise clients under MESA
retainers, data center infrastructure failures, incidents with regulatory
implications, and situations requiring executive-level commercial decisions.
Tier 4 engagement is at the sole discretion of D'Corp Tech's Founder.
Clause 4.6Service Excellence
4.6 Service Quality Standards, Post-Incident
Reviews & Continuous Improvement
Cloudist's commitment to enterprise-grade customer experience
extends beyond issue resolution to encompass systematic quality assurance,
transparent incident reporting, and proactive service improvement:
Post-Incident Reviews (PIR) for Severity 1 &
2: Following resolution of every Critical and Major incident,
Cloudist publishes a formal PIR within seventy-two (72) hours — detailing
verified root cause, event timeline, immediate remediation actions, and
systemic preventive measures implemented.
Customer Satisfaction (CSAT) Surveys: Every
resolved ticket generates an automated satisfaction survey. Aggregate CSAT
scores are reviewed monthly, with deteriorating scores triggering mandatory
service quality reviews.
Formal Complaints Process: Customers
dissatisfied with support resolution may submit a formal complaint to
legal@cloudist.my. Formal complaints are acknowledged within forty-eight
(48) hours; investigated by a senior manager independent of the original
interaction; and resolved with a formal decision within fourteen (14)
business days.
Service Reliability Reporting: Cloudist
publishes monthly uptime and incident statistics on the public status page
(status.cloudist.my) for full transparency regarding historical SLA
performance.
Service Guarantee
Commitment: Our enterprise clients deserve nothing less than
industry-leading performance, transparency, and accountability. Cloudist's
Founder is personally committed to upholding this standard across every customer
interaction.
Clause 4.7Managed ServicesMESA Retainer
4.7 Managed Engineering Service Agreements
(MESA) & DevOps Retainer Programs
For enterprise customers requiring dedicated server administration,
DevOps pipeline engineering, application security hardening, and managed
technical operations beyond standard support scope (Clause 4.3), Cloudist offers
formal Managed Engineering Service Agreements (MESA) —
individually tailored, dedicated retainer engagements with defined scope,
deliverables, and committed engineering hours.
Dedicated Named Account Infrastructure
Engineer: A senior Cloudist engineer assigned as the Customer's
primary technical point of contact, with deep familiarity with the
Customer's infrastructure and application stack. Includes scheduled
bi-weekly technical review calls.
Proactive Server Health Monitoring &
Remediation: 24/7 monitoring with automated alerting; proactive
performance tuning of web server, database, and caching layers; memory leak
identification; and accelerated OS-level security patch application.
DevOps Pipeline Management: CI/CD pipeline
design and maintenance (GitLab CI, GitHub Actions, Jenkins); Docker and
container orchestration management; automated deployment engineering; and
infrastructure-as-code (IaC) with Terraform or Ansible.
Security Hardening & Vulnerability
Management: Monthly infrastructure security assessments aligned
to CIS Benchmarks; WAF rule tuning; IDS deployment and tuning; and
remediation of identified vulnerabilities within agreed SLAs.
Monthly Infrastructure Assessment Reports:
Comprehensive reports covering performance benchmarks vs. baseline; security
posture ratings; cost optimization recommendations; renewal and technology
refresh planning; and forward-looking capacity analysis.
MESA engagements are governed by a separately executed Managed
Engineering Service Agreement and Scope of Work document specifying committed
monthly engineering hours, response guarantees, and commercially agreed pricing.
Contact support@cloudist.my or WhatsApp +601126174237 for custom MESA pricing and
availability.
Clause 5.130-Day Full
Money-BackRisk-FREE Guarantee
5.1 Cloudist 30-Day Full Risk-FREE
Money-Back Guarantee
Cloudist extends to every new subscriber — across all pricing plans,
service tiers, and product categories — an unwavering, ironclad 30-Day
Full Risk-FREE Money-Back Guarantee. This guarantee reflects our
absolute confidence in the enterprise-grade quality, technical performance, and
measurable business value that every Cloudist customer will experience from day
one of their service engagement. We believe so profoundly in our product that we
are prepared to offer a complete, unconditional refund if you are not fully
satisfied within the first thirty (30) calendar days of your initial
subscription — no justification required, no questions asked, and no
administrative hurdles imposed. This is not a promotional commitment — it is a
legally binding contractual obligation that D'Corp Tech honours without
exception, and it forms the cornerstone of our brand promise to every enterprise
customer we serve.
To initiate your refund under this guarantee, simply contact our
dedicated refund team via our official WhatsApp — or submit a
formal refund request through your authenticated Cloudist dashboard within the
thirty (30) day window. Include your account email and invoice reference number
to facilitate rapid processing. Our team will acknowledge within four (4)
business hours and initiate the disbursement process promptly, consistent with
the verification timeline in Clause 5.3.
The 30-Day Money-Back Guarantee applies to the net service fee paid
for the initial subscription term. Domain name registration fees, SSL
certificate premium upgrade fees, and applicable government taxes (SST) are
excluded from the refund scope, as these costs are immediately incurred by
D'Corp Tech from third-party registrars and certificate authorities on the
Customer's behalf and are non-recoverable. For customers subscribing under
promotional pricing or receiving bundled complimentary add-ons, the refund
amount reflects the actual net fee paid at checkout.
Fast-Track WhatsApp Refund Request
Message us with your Invoice ID to
immediately activate your 30-day refund. No forms, no wait times.
5.2 Service Satisfaction Covenant,
Revision Maximum Cap & Cancellation Eligibility
For all service categories involving human-delivered engineering
output — including website design and development, mobile application
development, custom software builds, eCommerce platform development, branding
projects, and managed content creation — Cloudist provides a structured
satisfaction assurance framework allowing the Customer to direct up to
three (3) comprehensive revision cycles before the deliverable
is deemed accepted. Each revision cycle may encompass multiple individual
feedback items communicated in a single, consolidated revision brief — allowing
the Customer to efficiently direct amendments to design, content, functionality,
and user experience within one structured session.
Should the Customer determine, after receiving the initial
deliverable and prior to exhausting the three (3) revision allowance, that the
service is fundamentally unable to meet their documented project requirements —
and this is communicated in writing within the thirty (30) day guarantee window
— the Customer is fully entitled to cancel and submit a refund application under
Clause 5.1 without forfeiture of the Money-Back Guarantee. Cloudist will treat
such cancellations with highest priority and process the refund consistent with
Clause 5.3.
Once the Customer has consumed more than three (3) iterative
revision cycles — each constituting a defined round of feedback and
corresponding engineering amendments — the project deliverable shall be
conclusively and irrevocably deemed accepted, constituting bespoke
custom-engineered intellectual property tailored to the Customer's
specifications. At this point, the service is regarded as satisfactorily
completed under the Contracts Act 1950, the Money-Back Guarantee no longer
applies, and the delivered IP ownership vests in the Customer upon full payment
settlement.
Clause 5.330–90 Days
ProcessingVerification Window
Upon receipt of a valid refund application submitted within the
applicable guarantee window, D'Corp Tech's financial compliance and operations
team initiates a comprehensive refund verification process designed to protect
all parties — including honest customers — against fraudulent refund abuse,
multi-accounting schemes, coordinated chargeback fraud, and identity-based
payment fraud. This verification encompasses: cross-referencing the refund
applicant's identity against D'Corp Tech's KYC records; reviewing service
utilization logs, API access patterns, and resource consumption data to verify
good-faith usage; confirming the absence of pending chargeback disputes through
our payment processor; and auditing for multi-account or related-entity patterns
suggesting systematic refund abuse.
Customers must allow a processing window of a minimum of
thirty (30) business days to a maximum of ninety (90) business days
from the formal refund application date for completion of verification and
initiation of disbursement. While straightforward cases are prioritized at the
lower end of this range, complex cases — including those requiring third-party
reconciliation or fraud investigation — may require the full ninety (90) day
window. D'Corp Tech will provide status updates upon request and proactively
notify the Customer if additional documentation or identity verification is
required.
Upon successful verification, the refund will be disbursed to the
original payment instrument — the same card, bank account, or payment method
used for the original purchase — within the applicable bank clearing timeframe
following our disbursement instruction: typically three (3) to seven (7)
business days for FPX transfers, and five (5) to ten (10) business days for
international credit card refunds, subject to the Customer's issuing bank's
processing schedule. D'Corp Tech does not issue refunds via alternative payment
methods, cryptocurrency, or cash without express prior written agreement.
Clause 5.4Chargeback
DefenseRM500
Penalty
5.4 Protection Against Unauthorized
Chargebacks & Fraudulent Payment Disputes
Because Cloudist provides an exceptionally accessible 30-Day Full
Money-Back Guarantee — reachable instantly via whatsapp or email — any Customer
who initiates a payment chargeback, payment dispute, or bank reversal request
through their financial institution without first exhausting Cloudist's direct
refund resolution mechanism is engaged in conduct constituting a
material breach of this Agreement under the Contracts Act 1950.
Unauthorized chargebacks bypass the agreed contractual dispute resolution
process, impose unjust financial penalties on D'Corp Tech from payment
processors, and represent a fundamental violation of the Customer's good-faith
contractual obligations.
Accounts associated with unauthorized or fraudulent chargebacks are
subject to the following consequences without exception: (i) immediate,
permanent account termination and denial of future service access; (ii)
immediate blacklisting across D'Corp Tech's internal fraud database and
notification to relevant industry fraud prevention networks; (iii) assessment of
a fixed administrative chargeback recovery fee of RM500.00 per
unauthorized chargeback transaction, representing reasonable
compensation for payment processor penalties, administrative costs, and legal
coordination expenses; and (iv) submission of a formal dispute response to the
payment processor with all available evidence — service delivery confirmation,
server access logs, and API utilization records — to contest and seek reversal.
Where the aggregate value of unauthorized chargebacks and associated
recovery fees exceeds RM1,000.00, D'Corp Tech reserves the unconditional right
to initiate formal debt recovery proceedings through the Malaysian Magistrate's
Court or Sessions Court, pursuing full recovery of all outstanding amounts plus
solicitor-client legal fees, court filing fees, and all enforcement costs.
D'Corp Tech's legal counsel is authorized to register unsatisfied judgments and
employ all available Malaysian enforcement mechanisms against individual and
corporate account holders.
Statutory Defense & Governance FAQ
Enterprise Sovereignty & IP
Governance
Authoritative legal declarations regarding intellectual property ownership, founder
prerogatives, and statutory immunity under Malaysian law.
Legal Counsel Notice
All assets, marks, trade dress, codebases, and systems are vigorously protected
under the Copyright Act 1987 and Trademarks Act 2019.
All software source code, proprietary algorithms, neural network
configurations, UI/UX architecture, visual graphics, vector logos,
brand marks, and technical documentation associated with
Cloudist and D'Corp Tech
constitute the exclusive intellectual property of D'Corp Tech and
its Founder.
These assets are vigorously protected under the Copyright
Act 1987 (Act 332) and the Trademarks Act 2019
(Act 815) of Malaysia, as well as international
conventions including the Berne Convention and TRIPS Agreement. Any
unauthorized reproduction, reverse engineering, decompilation,
scraping, or branding imitation will be prosecuted to the fullest
extent of civil and criminal law.
The Founder and Owner of D'Corp Tech maintains full, absolute, and
unappealable discretion regarding all platform governance,
operational routing, infrastructure resource reallocation, account
sanctions, and compliance determinations.
No external entity, reseller, or subscriber may limit, supersede, or
challenge the Founder's executive authority in safeguarding
corporate integrity, sovereign data compliance, and network
stability.
Every customer agrees to unconditionally indemnify, defend, and hold
completely harmless D'Corp Tech, its Founder, officers, engineers,
and corporate affiliates against any third-party claims,
liabilities, damages, fines, or losses (including full
solicitor-client legal fees) arising from:
Any content, application, data, or media stored or
processed through the customer's Cloudist account.
Any breach of Malaysian laws (including CMA 1998,
PDPA 2010, or Penal Code) committed using Cloudist compute
infrastructure.
Any intellectual property infringement action
initiated by third parties against customer-hosted applications.
All international, regional, and domestic clients irrevocably submit
to the exclusive governing authority of the Laws of
Malaysia.
Disputes are subject to mandatory, confidential, and binding
arbitration at the Asian International Arbitration Centre
(AIAC) in Kuala Lumpur. Parties expressly waive any
right to initiate class action proceedings, jury trials, or
litigation in non-Malaysian jurisdictions.
D'Corp Tech cooperates with authorized Malaysian statutory and law
enforcement agencies (including PDRM, MCMC, and CyberSecurity
Malaysia) solely upon receipt of a certified judicial court order,
warrant, or formal statutory notice issued under the Criminal
Procedure Code or CMA 1998.
We uphold strict constitutional privacy safeguards and resist
extra-judicial or unauthorized third-party telemetry access requests
to protect customer data sovereignty.
D'Corp Tech and Cloudist respect the intellectual
property rights of all parties. Verified copyright owners who
believe their work is being infringed upon through content hosted on
Cloudist infrastructure may submit a formal takedown request in
writing to legal@cloudist.my.
A valid copyright infringement notice must include: (i)
the copyright owner's full legal name and contact details; (ii) a
specific description of the copyrighted work alleged to be
infringed; (iii) the precise URL(s) of the allegedly infringing
content; (iv) a good-faith statement that the complainant holds
rights to the identified content; and (v) a declaration that the
notice is accurate and submitted in good faith.
D'Corp Tech will review all valid notices within five
(5) business days and, where infringement is confirmed, issue a
takedown order to the hosting customer. Customers who repeatedly
infringe third-party copyrights will have their accounts permanently
terminated. Counter-notices by the hosting customer may be submitted
within fourteen (14) days of takedown notification.
Cloudist operates a comprehensive Business Continuity
and Disaster Recovery (BCP/DR) framework designed to ensure service
resilience in the face of catastrophic data center failures, natural
disasters, or large-scale cyber incidents. Key BCP/DR elements
include:
Geographic Redundancy: Production
data is replicated asynchronously to a secondary disaster
recovery site located in a separate seismic zone, ensuring
geographic diversity for critical customer data.
Recovery Time Objective (RTO):
Cloudist targets an RTO of four (4) hours for full platform
restoration following a declared disaster event.
Recovery Point Objective (RPO):
Database transaction logs are replicated with a target RPO of
one (1) hour, minimizing potential data loss to the most recent
synchronization checkpoint.
Annual DR Testing: Cloudist
conducts full disaster recovery failover tests at minimum once
annually, with results reviewed by the Founder and technical
leadership.
While Cloudist implements industry-grade BCP/DR
controls, customers with mission-critical applications are strongly
advised to implement independent application-level redundancy,
geographic load balancing, and off-site backup solutions.
The "Cloudist" brand name, visual
identity (including the Cloudist logo, brand color system,
typography, and trade dress), website architecture, marketing copy,
and all associated digital assets constitute the exclusive, legally
registered intellectual property of D'Corp Tech. The Cloudist brand
represents a high-prestige enterprise technology identity comparable
to global leaders such as Hostinger, GoDaddy, and Exabytes.
Artificial Intelligence & Brand
Policy: No third party, individual, or automated AI
system may use the Cloudist brand name, logo, marketing materials,
or trade dress to train, fine-tune, or generate derivative AI
models, synthetic media, or competing brand identities without the
explicit written consent of D'Corp Tech's Founder. This prohibition
extends to LLM scraping, dataset collection, brand impersonation,
and unauthorized AI-generated content.
Violations of Cloudist's brand exclusivity rights shall
be vigorously prosecuted through civil and criminal proceedings
under the Trademarks Act 2019 (Act 815), Copyright Act 1987 (Act
332), and the Computer Crimes Act 1997 (Act 563) of Malaysia, in
addition to international trademark enforcement mechanisms through
WIPO and applicable treaties.