Skip to content

Privacy

Last updated 28 September 2026

This page covers two different things: this website, and the EventGen platform that organisers run their events on. Genact AI Studio Sdn. Bhd. ("we") operates both.

This website

The site uses Google Analytics to count visits and see which pages are read. It sets Google Analytics cookies, and Google receives your IP address, browser details and the pages you view on its behalf. We use these figures only to improve the site, and set no advertising cookies. If you send the contact form, we receive the name, email, organisation, phone number, event type and message you typed, and we use them to reply to you and nothing else. We keep enquiries for as long as the conversation is live and delete them when it is not.

The platform

When you register for an event run on EventGen, the organiser of that event decides what is collected and why — they are the data controller, and we process it on their behalf. Typically that is your name, email, and whatever their registration form asks for, plus what you do at the event: check-ins, sessions attended, points earned and, where you consented, leads shared with an exhibitor.

A visitor passport is one account across the events you attend on EventGen. It lets a later registration fill itself in and keeps your history in one place. Organisers see only their own events' data about you.

Consent

Consent is recorded per purpose and per event with a timestamp — sharing your details with an exhibitor is a separate decision from attending, and either can be withdrawn. An exhibitor receives your contact details only when you allowed that specific scan.

How long data is kept

Attendee data for an event is kept for three months after it ends. An organiser may extend that in blocks. When retention runs out, three reminders and fourteen days of grace pass, then the personal data is archived to encrypted storage and removed from the live system. What remains is the event, its totals and its financial records, which we keep for the period Malaysian law requires.

Where it lives

Data is hosted on Amazon Web Services in the Malaysia (ap-southeast-5) region. Email is delivered by a third-party provider, and card and FPX payments are handled by Stripe — we never see or store card numbers.

Your rights

Under the Personal Data Protection Act 2010 you may:

  • ask what personal data we hold about you, and get a copy;
  • correct anything inaccurate;
  • withdraw a consent you gave;
  • ask for your data to be erased, where we are not required to keep it.

You can do the first three from your own account in the visitor app. For anything else, email[email protected] and we will answer within 21 days. If the request concerns data an organiser controls, we will route it to them and tell you we have.

Security

Traffic is encrypted in transit, data is encrypted at rest, and access to production is limited to named people through audited sessions. We test the platform's security before each significant change and fix what we find. No system is perfect; if something happens that affects you, we will say so rather than wait to be asked.

Changes

If this policy changes materially we will update the date above and, where the change affects how your data is used, tell you directly.