Back to home

Privacy Policy

How we collect, use, disclose and protect your personal data — and the rights you have over it under the Malaysian Personal Data Protection Act 2010.

Last updated 21 July 2026

On this page
  1. 01About this policy
  2. 02Personal data we collect
  3. 03Where we obtain your data
  4. 04Sensitive personal data
  5. 05Why we process your data
  6. 06Who we disclose it to
  7. 07How long we keep it
  8. 08Transfers outside Malaysia
  9. 09Your rights
  10. 10Security
  11. 11Contact and complaints
  12. 12Changes to this policy
  13. 13Notis (Bahasa Malaysia)

1. About this policy

Aura Pixel Creative Studio Sdn. Bhd. (Registration No. 202601009966 (1672064-D)) (“AuraPixel”, “we”, “us”, “our”) is committed to protecting your personal data in accordance with the Personal Data Protection Act 2010 (the “PDPA”). For the purposes of the PDPA we are the data controller of the personal data described below.

This policy applies to:

  • our website at aurapixel.live, including the enquiry form;
  • our event registration platform at aurapixel.live/rsvp; and
  • our email and WhatsApp communications with you.

Where we run an event registration on behalf of a client, that client is a joint or independent controller of the attendee data for their own purposes. We will tell you who the event organiser is at the point of registration.

2. Personal data we collect

2.1 If you submit an enquiry on our website

Your name, company name, work email address, phone or WhatsApp number, the service you are interested in, and your indicated monthly budget range. All of these fields are mandatory — if you do not provide them we cannot respond to your enquiry.

2.2 If you register for an event

Mandatory: your full name, email address, phone or WhatsApp number, and whether you will be attending.

Optional:your company or organisation, job title, industry, your role in relation to the event, whether you are bringing a guest and that guest’s name, your meal preference or dietary requirements, and any message you choose to send us.

Generated by us: a registration reference, your seat or table allocation, a signed QR pass token, check-in timestamps, and records of the communications we have sent you.

2.3 If you are a guest brought by another attendee

We may hold your name because the attendee who invited you provided it. We ask attendees to obtain your agreement before doing so. You may ask us to remove your name at any time using the contact details in section 11.

2.4 Technical data

Our hosting provider records standard server log data, including IP address, browser type and the time of your request, for security and reliability purposes.

At the date of this policy our website does not use analytics, advertising or tracking cookies. If we introduce them we will update this policy and provide a cookie notice before doing so.

3. Where we obtain your data

Directly from you through our forms; from the organiser or host of an event you have been invited to; from an attendee who has registered you as their guest; or from a registration form on a client’s own website that feeds into our platform.

4. Sensitive personal data

If you tell us about dietary requirements, that information may reveal your religious beliefs or your state of health. Under the PDPA this is sensitive personal data and we process it only with your explicit consent, which we request separately at the point of registration.

We use it for one purpose only: to inform the event caterer of meal requirements. We share it with the caterer and the event organiser only so far as necessary, and we delete it in accordance with section 7.

Please note

Do not include medical details, diagnoses or medication information in any free-text field. We do not need it and we ask you not to provide it.

5. Why we process your data

We process your personal data for the following purposes, on the following bases under the PDPA:

Responding to your enquiry and preparing a proposal

Basis

Your consent; steps taken at your request before a contract

Providing our services under a signed engagement

Basis

Performance of a contract

Processing your event registration, issuing your pass, allocating seating and managing check-in

Basis

Your consent; performance of a contract with the event organiser

Sending you event communications — confirmations, passes, reminders and changes

Basis

Your consent

Providing attendance and event reports to the event organiser

Basis

Our legitimate interest in delivering our contracted service

Marketing our services to you by email or WhatsApp

Basis

Your consent — withdrawable at any time

Security, fraud prevention and maintaining our systems

Basis

Our legitimate interest; compliance with the Security Principle

Complying with legal, tax and regulatory obligations

Basis

Legal obligation

6. Who we disclose your data to

We do not sell your personal data. We disclose it to:

  • The event organiser or our client, where you registered for an event we administer on their behalf — including your name, contact details, attendance status and, where applicable, meal requirements.
  • Event suppliers such as caterers and venue security, limited to what they need.
  • Our service providers (see section 8), who process data on our instructions only.
  • Professional advisers — lawyers, accountants and insurers — where necessary.
  • Regulators, law enforcement or courts, where required by law.
  • A buyer or successor, in the event of a sale, merger or restructuring of our business.

7. How long we keep your data

Website enquiries that do not become clients

Retention period

24 months from last contact

Client records and engagement documents

Retention period

7 years after the end of the engagement, to meet tax and limitation requirements

Event registration and attendance records

Retention period

12 months after the event date

Dietary and meal-requirement data

Retention period

Deleted within 30 days after the event

Marketing consent records

Retention period

Until you withdraw consent, plus 24 months to evidence the withdrawal

Server and security logs

Retention period

As retained by our hosting provider, typically 30 days

At the end of these periods we delete the data or permanently anonymise it so that you can no longer be identified from it.

8. Transfers outside Malaysia

We use reputable service providers located outside Malaysia. Your personal data will therefore be transferred to and processed in other countries. Our principal processors are:

Cloud hosting & database providers

Purpose

Hosting our website and event platform, and storing registration data

Location

United States / global

Email delivery provider

Purpose

Sending confirmations, passes and event notifications

Location

United States

Messaging provider (WhatsApp)

Purpose

Sending WhatsApp confirmations and passes

Location

Singapore / United States

Before transferring, we satisfy ourselves that the data will receive a level of protection substantially similar to that required by the PDPA, and we put contractual data protection terms in place with each provider. By submitting your data to us you consent to these transfers. If you would prefer your data not to be transferred abroad, please contact us — but note that we may then be unable to provide the service.

9. Your rights

Under the PDPA you have the right to:

  • Access the personal data we hold about you. We will respond within 21 days. A prescribed fee may apply.
  • Correct data that is inaccurate, incomplete, misleading or out of date.
  • Withdraw your consent at any time. This does not affect processing already carried out.
  • Limit or object to processing that is causing, or is likely to cause, you damage or distress.
  • Stop direct marketing — an absolute right. You do not have to give a reason, and every marketing email includes an unsubscribe link.
  • Data portability — request that we transfer your data to another data controller in a structured, commonly used format, where technically feasible.

To exercise any of these rights, contact us using section 11. We may ask you to verify your identity first.

10. Security

We take practical steps to protect your personal data, including encryption in transit, access controls and authentication on administrative systems, time-limited session expiry, cryptographically signed event passes, and restricting access to those who need it.

No system is completely secure. If a breach occurs that is likely to cause you significant harm, we will notify the Personal Data Protection Commissioner and you, as required by law.

11. Contact and complaints

Questions, requests or complaints about this policy or your personal data:

Aura Pixel Creative Studio Sdn. Bhd.
Attn: Arveenthakumar, Founder & Creative Director
11-07, The Boulevard Office, Lingkaran Syed Putra,
Mid Valley City, 59200 Kuala Lumpur, Malaysia
Email: privacy@aurapixel.live
Tel: +6010-284 1290

If you are not satisfied with our response, you may complain to the Personal Data Protection Commissioner (Jabatan Perlindungan Data Peribadi), Ministry of Digital, Malaysia — pdp.gov.my.

12. Changes to this policy

We may update this policy from time to time. The current version is always at aurapixel.live/privacy with the “last updated” date shown above. Where changes are significant we will notify you directly.

13. Notis Perlindungan Data Peribadi

Section 7(3) of the PDPA requires this notice to be issued in both Bahasa Malaysia and English. The Bahasa Malaysia version follows.

Bahasa Malaysia

NOTIS PERLINDUNGAN DATA PERIBADI

Aura Pixel Creative Studio Sdn. Bhd. (“AuraPixel”) memproses data peribadi anda menurut Akta Perlindungan Data Peribadi 2010.

  1. Data yang dikumpul:nama, alamat e-mel, nombor telefon/WhatsApp, nama syarikat, jawatan, industri, nama tetamu (“+1”), pilihan makanan, dan sebarang maklumat yang anda isi dalam ruangan mesej.
  2. Sumber data: secara langsung daripada anda melalui borang kami, atau daripada penganjur acara yang menjemput anda.
  3. Tujuan: memproses pendaftaran anda, mengeluarkan pas QR dan nombor tempat duduk, berhubung dengan anda mengenai acara tersebut, menguruskan pendaftaran masuk, dan menyediakan laporan kehadiran kepada penganjur acara.
  4. Penzahiran: kepada penganjur acara dan pembekal acara seperti pihak katering, serta kepada penyedia perkhidmatan pihak ketiga kami — perkhidmatan hosting awan, penghantaran e-mel dan pemesejan.
  5. Pemindahan ke luar Malaysia: penyedia perkhidmatan di atas terletak di luar Malaysia. Dengan menghantar borang kami, anda bersetuju data anda dipindahkan dan diproses di luar negara.
  6. Data yang diwajibkan: ruangan bertanda (*) adalah wajib. Sekiranya anda tidak memberikannya, kami tidak dapat memproses pendaftaran anda.
  7. Data peribadi sensitif: maklumat pilihan makanan mungkin mendedahkan kepercayaan agama atau kesihatan anda. Anda memberikan persetujuan nyata untuk kami memprosesnya bagi tujuan katering sahaja. Sila jangan kemukakan maklumat perubatan.
  8. Hak anda: anda berhak mengakses dan membetulkan data anda, menarik balik persetujuan, mengehadkan pemprosesan, dan memohon mudah alih data. Hubungi privacy@aurapixel.live.
  9. Notis ini dikeluarkan dalam Bahasa Malaysia dan Bahasa Inggeris. Sekiranya terdapat percanggahan, versi Bahasa Inggeris akan digunapakai.

Questions about this page? privacy@aurapixel.live