Privacy
Last updated 28 September 2026
This page covers two different things: this website, and the EventGen platform that organisers run their events on. Genact AI Studio Sdn. Bhd. ("we") operates both.
This website
The site uses Google Analytics to count visits and see which pages are read. It sets Google Analytics cookies, and Google receives your IP address, browser details and the pages you view on its behalf. We use these figures only to improve the site, and set no advertising cookies. If you send the contact form, we receive the name, email, organisation, phone number, event type and message you typed, and we use them to reply to you and nothing else. We keep enquiries for as long as the conversation is live and delete them when it is not.
The platform
When you register for an event run on EventGen, the organiser of that event decides what is collected and why — they are the data controller, and we process it on their behalf. Typically that is your name, email, and whatever their registration form asks for, plus what you do at the event: check-ins, sessions attended, points earned and, where you consented, leads shared with an exhibitor.
A visitor passport is one account across the events you attend on EventGen. It lets a later registration fill itself in and keeps your history in one place. Organisers see only their own events' data about you.
Consent
Consent is recorded per purpose and per event with a timestamp — sharing your details with an exhibitor is a separate decision from attending, and either can be withdrawn. An exhibitor receives your contact details only when you allowed that specific scan.
How long data is kept
Attendee data for an event is kept for three months after it ends. An organiser may extend that in blocks. When retention runs out, three reminders and fourteen days of grace pass, then the personal data is archived to encrypted storage and removed from the live system. What remains is the event, its totals and its financial records, which we keep for the period Malaysian law requires.
Where it lives
Data is hosted on Amazon Web Services in the Malaysia (ap-southeast-5) region. Email is delivered by a third-party provider, and card and FPX payments are handled by Stripe — we never see or store card numbers.
Your rights
Under the Personal Data Protection Act 2010 you may:
- ask what personal data we hold about you, and get a copy;
- correct anything inaccurate;
- withdraw a consent you gave;
- ask for your data to be erased, where we are not required to keep it.
You can do the first three from your own account in the visitor app. For anything else, email[email protected] and we will answer within 21 days. If the request concerns data an organiser controls, we will route it to them and tell you we have.
Security
Traffic is encrypted in transit, data is encrypted at rest, and access to production is limited to named people through audited sessions. We test the platform's security before each significant change and fix what we find. No system is perfect; if something happens that affects you, we will say so rather than wait to be asked.
Changes
If this policy changes materially we will update the date above and, where the change affects how your data is used, tell you directly.