Privacy Policy
How we collect, use and safeguard your personal data.
Last updated: 19 May 2026
1. Who we are
IMPACT365 ("IMPACT365", "we", "us") operates this ESG Community & Event Operating System. We are the data controller for the personal data processed through this platform. Contact: hello@impact365.my.
2. Data we collect
- Account data — name, email, phone, password (stored hashed), role and profile details.
- Membership & payment data — plan, invoices and payment status. Card/banking details are handled by our payment provider (Billplz); we do not store card numbers.
- Activity data — event registrations, attendance check-ins, ESG project submissions, sponsorships and referrals.
- Technical data — IP address, browser/user-agent and sign-in logs, used for security and audit.
3. How we use it
To provide and operate the platform, process membership and event registrations, enable QR attendance, run the referral programme, moderate submissions, prevent fraud, comply with legal obligations and communicate service notices.
4. Legal basis (Malaysia PDPA 2010)
We process personal data in accordance with the Malaysian Personal Data Protection Act 2010 on the basis of your consent, the performance of our services to you, and our legitimate interests in operating a secure, governed community platform.
5. Sharing
We share data only with: our payment provider (Billplz) to process payments; event organizers for attendees who register to their events; and authorities where legally required. We do not sell your data.
6. Security & retention
We apply role-based access control, hashed passwords, CSRF protection, prepared database statements and audit logging. Data is retained while your account is active and as required for legal, accounting and audit purposes.
7. Your rights
You may access, correct or request deletion of your personal data, and withdraw consent, by contacting hello@impact365.my. You can edit most details directly from your profile.
8. Cookies
We use a single essential session cookie to keep you signed in. No third-party advertising or tracking cookies are used.
9. Changes
We may update this policy; material changes will be notified on this page with a revised date above.