Privacy Policy
Last Updated: 18 April 2025 · Effective: 18 April 2025
This policy explains how Bayan Neural collects, uses, and safeguards personal information provided by visitors to our website and participants in our courses. We are committed to handling your data with care and in accordance with Malaysia's Personal Data Protection Act 2010 (PDPA).
1. Data Controller
The data controller is Bayan Neural, based at Jalan Sultan Ismail, 50250 Kuala Lumpur, Malaysia. Questions about this policy or about your personal data can be directed to [email protected].
2. What We Collect and How
We collect personal data in two ways:
- Directly from you: when you submit the contact form on our website (name, email address, phone number, and message content) or when you enrol in a course (name, email, phone, and payment details handled by our payment processor).
- Automatically: analytics cookies collect anonymised data about page visits and usage patterns (see Section 5 and our Cookie Policy).
We do not collect sensitive personal data as defined under the PDPA (such as health information, political opinions, or financial records beyond what is needed to process payment).
3. Legal Basis for Processing
We process your personal data on the following grounds:
- Consent: for marketing communications and analytics cookies, where you have opted in.
- Contract performance: when processing your enrolment, responding to course enquiries, or sending course-related communications.
- Legitimate interests: for improving our courses and communications based on aggregated feedback and usage data, where this does not override your rights.
4. How We Use Your Data
- Responding to enquiries submitted through the contact form
- Processing course enrolments and sending enrolment confirmation
- Sending course materials, schedule updates, and relevant administrative communications
- Improving course content and website based on aggregated, anonymised usage data
- Processing refund requests in accordance with our Terms and Conditions
We do not sell your personal data. We do not share it with advertising networks.
5. Cookies
We use essential cookies (required for the site to function), and optional analytics cookies (to understand how the site is used). Optional cookies are only set with your consent. You can manage your cookie preferences at any time via our Cookie Policy page. We do not use marketing cookies.
6. Data Retention
- Contact form enquiries: retained for 12 months, then deleted.
- Enrolment records: retained for 5 years after course completion for administrative purposes.
- Analytics data: aggregated and anonymised, retained for up to 26 months.
7. Data Sharing with Third Parties
We share data only where necessary:
- Payment processor: payment card details are handled by our payment provider and are not stored by us.
- Analytics provider: anonymised usage data may be processed by an analytics service under a data processing agreement.
- Legal requirements: we may disclose data if required by law or court order.
All third-party providers are required to process data only on our instructions and in compliance with applicable data protection law.
8. Data Security
We use HTTPS encryption for data in transit. Access to personal data is restricted to staff who need it for their role. We conduct periodic reviews of our data handling practices. In the event of a data breach affecting your rights, we will notify you without undue delay as required under applicable law.
9. Your Rights Under the PDPA
Under Malaysia's Personal Data Protection Act 2010, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate or incomplete data
- Withdraw consent for processing based on consent (this does not affect processing already carried out)
- Request that we stop processing your data in certain circumstances
To exercise any of these rights, contact us at [email protected]. We will respond within 21 days.
10. Third-Party Links
Our website may include links to external sites. We are not responsible for the privacy practices of those sites and recommend reviewing their policies separately.
11. Children's Privacy
Our courses are intended for individuals aged 18 and above. We do not knowingly collect personal data from anyone under 18. If you believe a minor has submitted data to us, please contact us at [email protected] and we will delete it promptly.
12. Changes to This Policy
We may update this policy from time to time. The revised policy will be published on this page with an updated date. Continued use of our website after any changes constitutes acceptance of the updated policy.
13. Contact for Data Enquiries
For any questions about this privacy policy or your personal data, contact us at:
- Email: [email protected]
- Address: Jalan Sultan Ismail, 50250 Kuala Lumpur, Malaysia