Privacy Policy
Last updated 27 July 2026
This policy explains what personal data Appcademy collects, why we collect it, and what you can do about it. We handle personal data in line with Malaysia's Personal Data Protection Act 2010 (PDPA).
Who we are
Appcademy, Malaysia. For any privacy question, contact [email protected].
What we collect
- When you contact us: your name, email, phone number (if you give one), company, budget range and the message you write.
- When you book a class or consultation: your name, email, phone number and any notes you add.
- When you buy something: your name, email and order details. We never see or store your card details — payments are processed by our payment gateway.
- When you create an account: your name, email and a securely hashed password. We cannot read your password.
- When you browse: page URL, referrer, approximate device type and a rotating, non-reversible visitor hash. We do not use advertising cookies to track you across other websites.
Why we use it
- To reply to your enquiry and deliver work you have asked for.
- To confirm bookings, grant course access and issue receipts.
- To understand which pages are useful, in aggregate.
- To meet legal, tax and accounting obligations.
We do not sell your personal data, and we do not share it for third-party marketing.
Who we share it with
Only service providers that make the site work, and only with what they need:
- Payment gateway — to take payment and confirm it.
- Email provider — to deliver transactional email such as confirmations and receipts.
- Hosting and CDN — to serve the site and protect it from abuse.
We may also disclose data where the law requires it.
How long we keep it
- Enquiries: up to 3 years from last contact, so we can pick up a conversation you resume.
- Orders, invoices and payment records: 7 years, as required for Malaysian tax and accounting.
- Account and course records: for as long as your account is open.
- Analytics: aggregated page-view data, pruned periodically.
Your rights under the PDPA
You may ask us to:
- Confirm what personal data we hold about you, and give you a copy.
- Correct anything inaccurate or out of date.
- Delete data we no longer have a legal reason to keep.
- Stop using your data for a particular purpose, including any marketing email.
Email [email protected] and we will respond within 21 days. We may need to verify your identity first.
Cookies
We use a session cookie to keep you signed in and a CSRF cookie to protect forms from cross-site abuse. Both are strictly necessary for the site to function. Our analytics are cookieless and do not identify you personally.
Security
The site is served over HTTPS, passwords are hashed, access to production data is restricted, and the database is backed up nightly. No system is perfectly secure, but if a breach ever affects your personal data we will tell you promptly and explain what happened.
Children
Our services are intended for adults. Where a course is taken by someone under 18, we expect a parent or guardian to make the booking and provide the contact details.
Changes
If we change this policy materially, we will update the date below and, where the change affects you directly, tell you by email.
Questions about this document? Get in touch — we'd rather explain it than have you guess.