Governance & ESG Commitment
At MyCRS, integrity is not just a value we talk about — it's the very problem we exist to solve. As a company built to protect construction quality and prevent testing fraud, we hold ourselves to the same standards of transparency and accountability that we help our clients and partners achieve.
Our Commitments
Environmental Responsibility
We are committed to minimizing environmental impact across our operations — from reducing paper usage through digital documentation, to responsible handling of IoT hardware and electronic components. Beyond our own operations, we actively contribute to national decarbonization efforts through ongoing construction carbon research in collaboration with Universiti Malaya, helping the industry reduce embodied carbon through more accurate, transparent material testing.
Social Responsibility
We believe responsible business starts with how we treat our people and communities. This means providing a safe working environment, ensuring fair and non-discriminatory treatment across all levels, complying strictly with Malaysian labour laws, and supporting community development through knowledge-sharing and industry awareness initiatives.
Ethics & Anti-Corruption
We maintain a zero-tolerance stance on bribery and corruption, and are guided by a formal Code of Conduct that governs how we operate with clients, partners, and government agencies. Integrity, transparency, and ethical behavior are non-negotiable principles across every level of our organization.
Health, Safety & Environment (HSE)
We maintain structured HSE practices across our operations and project deployments, ensuring the safety of our team, partners, and site personnel at every stage of our work.
Our Governing Policies
-
Environmental & Social Policy
-
Code of Conduct Policy
-
Anti-Bribery & Corruption Policy
Data Security & Data Governance Policy
1. Purpose
This Policy sets out how MyCRS Sdn Bhd (“MyCRS”, “we”, “our”) collects, processes, stores, secures, retains, and disposes of data generated through its AIoT concrete testing governance platform, including data belonging to clients, project partners, and end users. It applies to all data captured across our RFID tagging, blockchain-sealed record-keeping, robotic compression testing, and AI anomaly detection systems.
2. Scope
This Policy applies to:
-
All personal, operational, and project data processed by MyCRS systems, whether collected directly or on behalf of a client.
-
All employees, contractors, and third-party service providers who access, store, or process MyCRS data.
-
Data in transit (e.g. field data capture at batching plants and testing sites) and data at rest (e.g. cloud infrastructure, blockchain ledgers, local servers).
3. Data Governance Framework
MyCRS operates a layered data governance model aligned to the structure of our platform:
-
Collection layer (RFID): each specimen and batch record is tagged and bound to a source identity at the point of capture.
-
Integrity layer (Blockchain): custody and test records are sealed to an immutable ledger, preventing undetected alteration after capture.
-
Processing layer (AI/Robotics): automated compression testing and anomaly detection process data under defined access controls, with human review for flagged exceptions.
-
Governance layer (Policy & Oversight): documented roles, retention schedules, and access controls, reviewed on a periodic basis (see Section 9).
4. Data We Collect
Depending on the engagement, MyCRS may collect:
-
Project and specimen data: batch identifiers, RFID tag data, test results, timestamps, location of collection/testing.
-
Client and site personnel data: names, contact details, and roles of authorised personnel interacting with the platform, where required for chain-of-custody attribution.
-
System and access logs: authentication events, device identifiers, and audit trails of who accessed or modified a record.
MyCRS does not collect data beyond what is required to deliver chain-of-custody assurance, testing governance, and reporting to the client.
5. Data Security Controls
MyCRS applies the following technical and organisational controls:
-
Immutable record-sealing: test and custody records are cryptographically sealed to a blockchain ledger, making unauthorised alteration detectable.
-
Role-based access control (RBAC): access to raw project and specimen data is restricted by user role; administrative access is logged.
-
Encryption: data in transit is encrypted using industry-standard protocols (TLS);
-
Anomaly monitoring: our AI engine continuously screens incoming data for statistical patterns consistent with tampering or unauthorised substitution, generating alerts for review.
-
Least-privilege principle: employees and contractors are granted access strictly necessary for their function.
6. Data Retention & Disposal
Project and specimen data is retained for the duration of the engagement and for 16 years thereafter, in line with applicable construction record-keeping and contractual requirements, after which it is securely archived or deleted upon client request or contract expiry. Blockchain-sealed custody records are retained indefinitely as an immutable audit trail unless a client agreement specifies otherwise.
7. Client Data Protection & Third-Party Sharing
-
Client and project data is not sold, rented, or shared with third parties for marketing purposes.
-
Data may be shared with accredited testing laboratories or project partners strictly where required to deliver the engagement, under confidentiality obligations.
-
Any subcontractor or cloud service provider processing MyCRS data on our behalf is bound by data processing terms consistent with this Policy.
-
Clients may request a copy of, correction to, or deletion of their data, subject to legal and contractual retention obligations.
-
MyCRS may use anonymised and/or aggregated data derived from client engagements to train, validate, and improve its AI anomaly detection models, including across multiple client engagements, in order to enhance detection accuracy industry-wide. Personally identifiable or client-attributable data is not used for this purpose without separate consent.
8. Regulatory Compliance
MyCRS's data handling practices are designed to align with the Malaysian Personal Data Protection Act 2010 (PDPA), as our primary jurisdiction of operation. Where MyCRS processes data on behalf of clients or partners subject to other regimes, MyCRS will apply the additional controls required by that regime for the relevant engagement.
9. Breach Response
In the event of a suspected data breach, MyCRS will: (i) contain and assess the incident; (ii) notify affected clients without undue delay; (iii) notify the relevant regulatory authority where required by law; and (iv) document root cause and remediation steps.
10. Roles & Responsibilities
Policy Owner: COO, Kevyn Ho
Data Protection Contact: Operation@mycrs.com.my
Review Cycle: This Policy is reviewed at least annually, or upon material change to MyCRS's systems, client base, or applicable law.
11. Contact
Questions regarding this Policy, or requests relating to data held by MyCRS, may be directed to operation@mycrs.com.my
.
This document is a governance policy statement and does not constitute legal advice. MyCRS recommends independent legal review prior to external publication.