1. About This Policy and Notice
1.1 This Privacy & Personal Data Protection Policy ("Policy") explains how Strongbox Tech Sdn. Bhd. (Company No. 201401036253 (1112392-X)), as the operator of EpicDewan ("EpicDewan", "we", "us" or "our"), collects, records, holds, stores, uses, discloses, transfers, secures, retains and otherwise processes Personal Data in connection with the EpicDewan platform, websites, applications, account services, payment facilities, modules and related services (collectively, the "Platform" or "Services").
1.2 This Policy is also intended to serve as EpicDewan's Personal Data Protection Notice for purposes of the Personal Data Protection Act 2010 [Act 709] ("PDPA"), as amended from time to time, together with applicable regulations, standards, circulars, guidelines and codes of practice.
1.3 This Policy applies to individuals whose Personal Data may be processed through EpicDewan, including Members, applicants, administrators, office bearers, representatives of Organizations, event participants, purchasers, guests, website visitors, support contacts and other Users.
1.4 This Policy should be read together with the EpicDewan Platform Terms of Service and, where applicable, an Organization's own privacy notice or membership terms.
1.5 The PDPA principally regulates processing of Personal Data in commercial transactions in Malaysia. EpicDewan may nevertheless apply the protections in this Policy more broadly to Personal Data processed through the Platform where appropriate.
2. Key Definitions
2.1 “Data Controller” means a person who, alone or jointly or in common with others, processes Personal Data or has control over or authorises the processing of Personal Data, as provided under applicable law.
2.2 “Data Processor” means a person, other than an employee of the Data Controller, who processes Personal Data solely on behalf of the Data Controller and does not process the Personal Data for the person's own purposes.
2.3 “Data Subject” means the individual to whom Personal Data relates.
2.4 “Member” means an individual who is, was, may become, or applies to become a member, participant, affiliate or other recognised individual associated with an Organization.
2.5 “Organization” means an association, society, chamber, professional body, club, non-profit organisation, company or other entity using EpicDewan.
2.6 “Organization Data” means data, records, documents and information submitted, generated or maintained specifically for an Organization's activities through EpicDewan.
2.7 “Personal Data” has the meaning given under the PDPA and includes information that relates directly or indirectly to an identified or identifiable individual.
2.8 “Sensitive Personal Data” has the meaning given under the PDPA and applicable amendments and may include, where applicable, information concerning health or physical or mental condition, political opinions, religious or similar beliefs, commission or alleged commission of an offence, biometric data, and other information treated as sensitive under applicable law.
3. EpicDewan's Data Protection Roles
3.1 EpicDewan's role depends on the specific processing activity. The fact that an Organization originally supplied information does not by itself determine the legal role of every subsequent processing activity.
3.2 EpicDewan as Data Controller. EpicDewan may act as a Data Controller where we determine the purposes or means of processing, including for:
- creation and administration of EpicDewan or shared ecosystem Accounts;
- authentication and single sign-on functionality;
- Platform security, logging and fraud prevention;
- administration of EpicDewan's own Services and Fees;
- payment reconciliation and Platform transaction records;
- customer and technical support;
- service analytics, system performance and product improvement;
- consent and communication-preference records;
- legal, regulatory, tax, accounting, audit and compliance requirements; and
- EpicDewan's own communications and marketing where permitted.
3.3 EpicDewan as Data Processor. EpicDewan may act as a Data Processor where an Organization determines the purposes of processing and uses EpicDewan primarily to process Personal Data on its instructions, for example to maintain its membership database, administer renewal records, generate invoices, communicate with Members or administer Organization events.
3.4 Organizations as Data Controllers. An Organization may independently act as a Data Controller for Personal Data relating to its Members, applicants, office bearers, representatives, event participants and other individuals. Each Organization remains responsible for its own collection, notices, decisions, membership administration and other processing activities within its control.
3.5 Where a separate data processing agreement is entered into between EpicDewan and an Organization, that agreement may provide additional detail concerning the respective responsibilities of the parties.
4. Our Multi-Organization Data Principle
4.1 EpicDewan is a multi-organisation platform. An individual may be associated with more than one Organization and may also maintain an independent relationship with EpicDewan.
4.2 An Organization may manage the records that relate to its own relationship with a Member, but membership in that Organization does not give the Organization exclusive ownership or control over the Member's identity, general Personal Data, EpicDewan Account, relationship with EpicDewan or relationship with another Organization.
4.3 EpicDewan is designed to maintain logical separation between Organization-specific records. We do not make Organization A's confidential membership or administrative records available to Organization B merely because the same individual is connected to both Organizations.
4.4 Where an individual ceases to be associated with one Organization, that does not automatically require closure of the individual's EpicDewan Account or deletion of information required for another Organization, another Service, a continuing transaction, legal compliance or another permitted purpose.
5. Personal Data We May Process
Depending on the Services used and the relationship involved, we may process the following categories of Personal Data.
5.1 Account and Identity Information
This may include name, username, profile information, date of birth where required, photograph, identification information where reasonably required, authentication information, Account status and other identifiers.
5.2 Contact Information
This may include email address, telephone number, mailing or correspondence address, business contact information and other contact details.
5.3 Organization and Membership Information
This may include Organization affiliation, membership number, membership category, application status, membership status, joining date, renewal date, qualifications or professional information where relevant, committee or office-bearing information, benefits, attendance, participation and other Organization-specific records.
5.4 Organization Verification and Administrator Information
Where a person represents an Organization, we may process the person's name, designation, contact information, authority, Organization registration details and documents reasonably required to verify the Organization or representative.
5.5 Payment, Billing and Transaction Information
This may include invoice and receipt records, amounts, payment method type, transaction identifiers, payment status, refunds, reversals, chargebacks, settlement information and related financial records. Full payment-card or bank credentials may be collected directly by the relevant Payment Provider rather than by EpicDewan.
5.6 Event, Purchase and Activity Information
This may include event registration, ticket purchase, attendance, order information, guest information supplied for a transaction, activity history and related records.
5.7 Communications and Support Information
This may include enquiries, support requests, correspondence, messages sent through supported Platform functions, communication preferences and records relating to service delivery.
5.8 Technical, Device and Usage Information
This may include IP address, browser type, device type, operating system, login time, session information, security logs, audit logs, error information, pages or functions used, referral information and similar technical or usage data.
5.9 Consent and Preference Records
This may include records showing acceptance of terms, acknowledgement of privacy notices, marketing choices, consent given or withdrawn, communication preferences and the date or method by which a preference was recorded.
5.10 Sensitive Personal Data
EpicDewan does not require every User to provide Sensitive Personal Data. However, an Organization or particular Service may lawfully require certain sensitive information for a specific purpose. Where EpicDewan processes Sensitive Personal Data, it will be handled in accordance with applicable PDPA requirements, including express consent where required and appropriate security safeguards.
5.11 Cookies and Similar Technologies
Our websites and Platform may collect information through cookies and similar technologies as further described in the applicable Cookie Policy and consent controls.
6. Sources of Personal Data
6.1 We may obtain Personal Data:
- directly from you when you create or use an Account;
- from an Organization that has an existing or prospective relationship with you;
- from an Administrator authorised by an Organization;
- through a shared account, identity or single sign-on service used by the EpicDewan ecosystem, including Polydomy where enabled;
- when you make a payment, place an order or register for an event;
- from a Payment Provider or financial institution in connection with transaction status or reconciliation;
- from integrated third-party services that you or an Organization has authorised;
- through cookies, logs and use of the Platform;
- through customer support or other communications; and
- from public, regulatory or verification sources where reasonably necessary and permitted by law.
6.2 Where an Organization supplies Personal Data about an individual, the Organization is responsible for ensuring it has the authority to do so and for providing any notice or obtaining any consent required for its own processing activities.
7. Purposes for Which We Process Personal Data
7.1 We may process Personal Data for purposes including:
- registering, authenticating and administering Accounts;
- enabling single sign-on or shared identity functionality;
- verifying Users, Organizations and authorised representatives;
- enabling Organizations to administer memberships and applications;
- maintaining membership, renewal and Organization-specific records;
- generating invoices, receipts, statements and other records;
- processing, recording, reconciling, refunding and investigating Transactions;
- facilitating event registration, ticketing, orders and attendance;
- sending operational, membership, security and transaction communications;
- enabling Organization communications to authorised recipients;
- providing customer service and technical support;
- preventing fraud, misuse, unauthorised access and security incidents;
- maintaining audit trails and system integrity;
- complying with applicable laws, lawful requests, regulatory obligations, tax, accounting and reporting requirements;
- establishing, exercising or defending legal rights;
- monitoring Platform performance, troubleshooting and correcting errors;
- improving existing Services and developing new features;
- carrying out aggregated, statistical or appropriately de-identified analysis;
- operating integrations requested by Users or Organizations;
- managing consent and communication preferences; and
- sending EpicDewan marketing or promotional communications where permitted and, where required, consented to.
7.2 We will not intentionally use Personal Data for a materially incompatible purpose without taking any additional steps required under applicable law, which may include providing further notice or obtaining consent.
8. Consent and Other Permitted Processing
8.1 Where the PDPA requires consent, EpicDewan will seek consent in a form that can be recorded and maintained as required by applicable law.
8.2 The PDPA also permits certain processing without consent in specified circumstances. Depending on the facts, this may include processing necessary to perform a contract with the Data Subject, take steps requested before entering into a contract, comply with a legal obligation, protect vital interests, administer justice, exercise functions conferred by written law or another circumstance permitted under the PDPA.
8.3 This Policy does not create a right for EpicDewan to process Personal Data beyond what is permitted by applicable law.
8.4 Consent to use EpicDewan is not treated as blanket consent for unrelated marketing. Where marketing consent is required, EpicDewan may provide a separate choice such as an optional checkbox, preference setting or unsubscribe mechanism.
9. Mandatory and Optional Information
9.1 Certain Personal Data is mandatory because it is reasonably necessary to provide a requested Service, verify an Account, administer membership, process a payment, maintain security or comply with law.
9.2 Other information may be optional and will be identified as such where reasonably practicable.
9.3 If required information is not provided, the consequences may include inability to:
- create or verify an Account;
- join, renew or manage a membership through the Platform;
- process or reconcile a payment;
- register for an event or complete an order;
- verify an Organization or Administrator;
- provide a requested feature or support request; or
- comply with applicable legal or security requirements.
9.4 Refusing optional marketing consent will not prevent a User from using core Services that do not depend on that consent.
10. Data Supplied by Organizations
10.1 An Organization may upload or provide information concerning existing or prospective Members for legitimate membership, administrative, event or service purposes.
10.2 The fact that an Organization provides information about an individual does not:
- transfer ownership of the individual's Personal Data to the Organization or EpicDewan;
- give the Organization exclusive rights over the individual's identity or EpicDewan Account;
- authorise disclosure of another Organization's confidential records;
- automatically constitute consent to EpicDewan's own unrelated direct marketing; or
- prevent the individual from exercising applicable statutory rights.
10.3 EpicDewan may invite or permit the individual to verify, activate or use an independent Account so the individual can manage his or her own Platform relationships.
11. Disclosure of Personal Data
11.1 We may disclose Personal Data to the following classes of persons where reasonably necessary and permitted by law:
Organizations. An Organization may receive information relating to its own Members, applicants, representatives, participants, transactions and activities where the Organization is authorised to receive that information.
Service Providers and Data Processors. We may use providers of hosting, cloud infrastructure, storage, content delivery, cybersecurity, system monitoring, communications, email, SMS, authentication, identity verification, analytics, customer support, software integration, backup and other operational services.
Payment Providers and Financial Institutions. Information reasonably required to initiate, verify, authenticate, settle, refund or reconcile Transactions may be shared with relevant payment gateways, processors, banks, acquiring institutions, card networks, e-wallet providers and other payment participants.
Professional Advisers and Auditors. Information may be disclosed to lawyers, accountants, auditors, insurers and other professional advisers where reasonably necessary.
Authorities. Information may be disclosed where required or permitted by Malaysian law, court order, regulator, law enforcement authority, tax authority or another lawful process.
Corporate Transactions. Information may be disclosed or transferred in connection with a merger, acquisition, restructuring, financing, sale or transfer of all or part of the business, subject to applicable legal safeguards.
Authorised Recipients. We may disclose information where you or the relevant Organization has instructed or authorised us to do so.
11.2 EpicDewan will not disclose Organization A's confidential Organization-specific records to Organization B merely because an individual is connected to both Organizations.
12. Service Providers and Subprocessors
12.1 EpicDewan may appoint and replace service providers as our technology and operations evolve.
12.2 We are not required to obtain separate permission from every Organization or User each time we appoint or replace an ordinary infrastructure or operational provider, unless applicable law or a specific written agreement requires otherwise.
12.3 We will take reasonable steps to require providers handling Personal Data on our behalf to maintain appropriate confidentiality, security and data protection measures and to process data consistently with their contracted role.
12.4 EpicDewan may make information concerning categories of service providers or material subprocessors available where appropriate.
13. Payment Data
13.1 EpicDewan may facilitate payments using third-party Payment Providers. Payment methods and providers may change from time to time.
13.2 A Payment Provider may independently collect payment credentials and may itself act as a separate Data Controller for certain processing undertaken under financial, anti-fraud, regulatory or network requirements.
13.3 EpicDewan may receive transaction references, payment status, amount, payment-channel information and other data required for reconciliation and support without receiving the complete payment credentials used by the payer.
13.4 Users should review any privacy information displayed by the relevant Payment Provider at the point of payment.
14. Operational Communications and Direct Marketing
14.1 EpicDewan may send communications necessary or reasonably related to requested Services, including Account verification, password resets, security alerts, invoices, receipts, payment status, membership-related system notices, event confirmations, technical notices and material service or legal notices.
14.2 Operational communications are separate from EpicDewan's own promotional marketing.
14.3 Where consent is required for direct marketing, EpicDewan will provide an appropriate mechanism for the User to choose whether to receive such communications.
14.4 A User may withdraw marketing consent or request that EpicDewan stop direct marketing through the available unsubscribe mechanism, preference setting or by contacting us.
14.5 Withdrawal from EpicDewan marketing does not prevent necessary operational or transactional communications.
14.6 An Organization may independently send communications to its Members using EpicDewan. The Organization is responsible for ensuring that those communications are lawful and appropriately authorised. A User's preference concerning EpicDewan marketing does not automatically determine the User's separate communication preferences with every Organization.
15. Shared Account and Single Sign-On Services
15.1 EpicDewan may use a shared account or single sign-on system, including Polydomy where enabled, to allow a User to access EpicDewan and potentially other services within the same technology ecosystem using a common identity or authentication mechanism.
15.2 Where shared authentication is used, basic Account and security information may be processed across the relevant account infrastructure to authenticate the User, maintain Account security and provide access to the services selected by the User.
15.3 Organization-specific confidential records are not made available to another platform merely because the same authentication account is used, unless such sharing is necessary for a feature requested by the User, authorised by the relevant party or otherwise permitted by law.
16. Cookies and Similar Technologies
16.1 EpicDewan may use cookies and similar technologies to:
- maintain authenticated sessions;
- remember preferences;
- protect security;
- prevent fraud;
- understand Platform usage;
- detect errors and measure performance; and
- where permitted, support analytics or marketing.
16.2 Where applicable law requires consent for a particular non-essential cookie or tracking technology, EpicDewan will provide an appropriate choice mechanism.
16.3 Further details may be provided in a separate EpicDewan Cookie Policy.
17. Cross-Border Transfers
17.1 Some providers, systems, infrastructure or support functions used by EpicDewan may be located outside Malaysia or may process Personal Data from outside Malaysia.
17.2 Where Personal Data is transferred outside Malaysia, EpicDewan will take reasonable steps to comply with section 129 of the PDPA and applicable regulatory guidance on cross-border transfers.
17.3 Depending on the circumstances, this may include assessing whether the destination has laws substantially similar to the PDPA or an adequate level of protection, applying contractual or organisational safeguards, relying on consent or another condition permitted under the PDPA, and maintaining appropriate records of the transfer.
17.4 The countries involved may change as service providers and infrastructure evolve. Where additional disclosure is required by law, EpicDewan will provide it through this Policy, a supplementary notice or another appropriate channel.
18. Security and Data Protection by Design
18.1 EpicDewan takes reasonable technical and organisational measures to protect Personal Data against loss, misuse, modification, unauthorised or accidental access or disclosure, alteration or destruction.
18.2 Measures may include, where appropriate:
- access controls and role-based permissions;
- authentication controls;
- encryption in transit and/or at rest where appropriate;
- system, security and audit logging;
- network and infrastructure safeguards;
- backup and recovery controls;
- vulnerability and patch management;
- restrictions on personnel access;
- confidentiality obligations;
- vendor and processor controls; and
- security incident response procedures.
18.3 EpicDewan will seek to apply data protection principles in the design and development of Platform functionality proportionate to the nature and risk of the processing.
18.4 No internet-connected system can guarantee absolute security. Users and Organizations also have responsibilities to protect their own devices, credentials, Administrator permissions and connected accounts.
19. Personal Data Breaches
19.1 EpicDewan maintains procedures for assessing and responding to suspected Personal Data breaches.
19.2 Where EpicDewan acts as Data Controller and a breach is subject to mandatory notification requirements, EpicDewan will notify the Personal Data Protection Commissioner and affected Data Subjects within the applicable statutory or regulatory timeframe and in the manner required by law.
19.3 Where EpicDewan acts as Data Processor for an Organization, EpicDewan will take reasonable steps to inform the relevant Data Controller of a confirmed or reasonably suspected breach affecting Personal Data processed on its behalf, consistent with applicable legal and contractual requirements.
19.4 Organizations must promptly notify EpicDewan if they become aware of a security incident or suspected Personal Data breach involving the Platform so that the relevant parties can investigate and take appropriate action.
20. Retention of Personal Data
20.1 EpicDewan retains Personal Data only for as long as reasonably necessary for the purpose for which it was processed, or for a longer period where required or permitted by law.
20.2 Retention periods may depend on:
- whether an Account or Organization relationship remains active;
- membership and administrative requirements;
- payment, accounting, tax and reconciliation requirements;
- legal and regulatory obligations;
- security, fraud-prevention and audit requirements;
- unresolved disputes, investigations or legal claims;
- applicable limitation periods; and
- backup and disaster-recovery cycles.
20.3 When Personal Data is no longer reasonably required, EpicDewan may securely delete, destroy, anonymise or otherwise dispose of it in accordance with applicable requirements.
20.4 Data contained in routine backups may remain for a limited period until the relevant backup is overwritten or securely retired, during which time access will remain restricted.
21. Accuracy and Data Integrity
21.1 EpicDewan takes reasonable steps to keep Personal Data accurate, complete, not misleading and up to date where necessary for the purpose for which it is processed.
21.2 Users should keep their Account information current and notify EpicDewan or the relevant Organization where correction is required.
21.3 Organizations remain responsible for the accuracy of Organization-specific information under their control.
22. Your Rights as a Data Subject
22.1 Subject to the PDPA, applicable regulations and statutory exceptions, a Data Subject may have rights including:
- the right to be informed whether Personal Data is being processed;
- the right to request access to Personal Data;
- the right to request correction of inaccurate, incomplete, misleading or outdated Personal Data;
- the right to withdraw consent where processing is based on consent;
- the right to prevent processing in circumstances recognised by the PDPA where processing is likely to cause damage or distress;
- the right to require the cessation of processing for direct marketing purposes;
- the right to request data portability in accordance with section 43A of the PDPA, subject to technical feasibility, format compatibility and applicable prescribed requirements; and
- any other rights available under applicable Malaysian Personal Data law from time to time.
22.2 These rights are not absolute. A request may be subject to identity verification, statutory exceptions, technical limitations, retention requirements, the rights of other persons or other limitations permitted by law.
23. Access, Correction, Withdrawal and Other Requests
23.1 A User may be able to update certain information directly through the Platform.
23.2 A request concerning access, correction, withdrawal of consent, direct marketing, portability or another Personal Data matter may be submitted to EpicDewan using the contact information in Clause 30 below.
23.3 EpicDewan may require sufficient information to verify the identity and authority of the requester before acting on a request.
23.4 Where the relevant Personal Data is controlled by an Organization rather than EpicDewan, EpicDewan may direct the Data Subject to the relevant Organization or reasonably assist the Organization in handling the request.
23.5 Withdrawal of consent does not affect processing already lawfully undertaken before withdrawal and may not prevent processing that remains permitted or required without consent under applicable law.
23.6 Where withdrawal or deletion makes it impossible to provide a particular Service, EpicDewan will explain the relevant consequence where reasonably practicable.
24. Account Closure and Organization Termination
24.1 Closing an EpicDewan Account does not necessarily result in immediate deletion of every related record.
24.2 EpicDewan may continue to retain information required for transactions, tax, accounting, fraud prevention, security, audit, dispute resolution, legal claims, regulatory compliance or another lawful purpose.
24.3 Termination by one Organization does not give that Organization authority to require deletion of:
- Personal Data required for the individual's independent EpicDewan Account;
- records relating to another Organization;
- information required for an ongoing Transaction or Service;
- legal, accounting, audit or security records; or
- data that may otherwise lawfully be retained.
24.4 Organization-specific records will be handled according to the relevant Organization's instructions, applicable service terms, statutory retention requirements and EpicDewan's legal obligations.
25. Aggregated, Anonymised and De-Identified Information
25.1 EpicDewan may create and use aggregated, anonymised or appropriately de-identified information for Platform analytics, statistics, benchmarking, system performance, security, service improvement, product development and similar purposes.
25.2 EpicDewan will not treat information as anonymised merely because obvious identifiers have been removed where the information can still reasonably be linked to an identifiable individual.
25.3 This Clause does not permit EpicDewan to disclose an Organization's identifiable confidential records to another Organization without appropriate authority.
26. Automated Decision-Making, Profiling and Advanced Functionality
26.1 EpicDewan may introduce analytics, automation, recommendations, fraud detection, risk indicators or other advanced functionality from time to time.
26.2 Where such functionality involves automated decision-making or profiling using Personal Data, EpicDewan will seek to implement it consistently with the PDPA and applicable guidance issued by the Personal Data Protection Commissioner, including appropriate transparency, risk assessment, human governance and safeguards where required.
26.3 EpicDewan will provide additional notice where a new feature materially changes the purposes or manner in which Personal Data is processed and additional notice is required by law.
27. Children and Persons Without Full Legal Capacity
27.1 EpicDewan is primarily intended for Organizations and their Members. Some Organizations may lawfully have members or participants who are minors or persons who require a parent, guardian or authorised representative.
27.2 Where an Organization submits Personal Data concerning such a person, the Organization is responsible for ensuring that any consent, authority or notice required by applicable law has been properly addressed.
27.3 EpicDewan may implement additional verification or consent measures for Services intended for minors where appropriate.
28. We Do Not Sell Personal Data as a Standalone Commodity
28.1 EpicDewan does not sell Personal Data as a standalone commercial commodity.
28.2 We do not provide an Organization's identifiable membership database to an unrelated third party for that third party's independent marketing merely because the information is stored on EpicDewan.
28.3 This does not restrict disclosures necessary to provide the Services, process Transactions, comply with law, operate authorised integrations or undertake another processing activity described in this Policy.
29. Changes to This Policy
29.1 EpicDewan may update this Policy to reflect changes in law, regulatory guidance, Platform functionality, processing activities, security practices, service providers or business operations.
29.2 The latest revision date will be displayed at the beginning of the Policy.
29.3 Where a change materially affects how Personal Data is processed, EpicDewan will provide additional notice where reasonably appropriate or legally required.
30. Contact, Data Requests and Complaints
30.1 EpicDewan is operated by:
STRONGBOX TECH SDN. BHD.
Company No. 201401036253 (1112392-X)
Platform: EpicDewan
Website: epicdewan.com
Privacy / general contact: hello@techstrongbox.com
30.2 Personal Data access, correction, withdrawal, direct-marketing, portability and privacy-related enquiries may be sent to the contact above or through the support/contact facility made available on EpicDewan.
30.3 EpicDewan will appoint and register a Data Protection Officer where required under the PDPA and applicable Commissioner requirements. Where a DPO has been appointed, the relevant contact information may be made available through the Platform or this Policy.
30.4 A Data Subject may also lodge a complaint with the Personal Data Protection Commissioner of Malaysia in accordance with applicable law.
31. Language
31.1 This Policy is provided in English and Bahasa Malaysia to support the Notice and Choice requirements under the PDPA.
31.2 Both versions are intended to carry the same meaning. Any inconsistency will be interpreted and resolved in accordance with applicable Malaysian law.