Privacy Policy
Last updated: March 2026
1. Overview
This privacy policy explains how Minilab Sdn Bhd collects, uses, and protects personal data in compliance with the Personal Data Protection Act 2010 (PDPA 2010) of Malaysia.
2. Data We Collect
We collect the following types of data:
- Name, phone number, and unit number (for residents via WhatsApp registration)
- Name, phone number, email, and role (for building staff via Telegram)
- Facial biometric data (for attendance verification, with explicit consent)
- Visitor information (name, vehicle number, purpose of visit)
- Building operational data (cases, invoices, attendance records)
3. How We Use Data
Your data is used for the following purposes:
- To provide building management services
- To process and route resident complaints
- To verify staff attendance
- To manage visitor access
- To generate reports for building committees
- To improve our AI models (anonymised data only)
4. Data Storage
All data is stored on Supabase PostgreSQL in the Singapore region (ap-southeast-1). Data is encrypted at rest using AES-256 and in transit using TLS 1.3. Row-level security ensures building data isolation.
5. Data Retention
- Active account data: retained for the duration of the subscription
- Visitor logs: retained for 12 months
- Attendance records: retained for 24 months
- Facial biometric data: deleted within 7 days of staff deregistration
- Deleted accounts: all data permanently removed within 30 days
6. Your Rights Under PDPA 2010
You have the right to:
- Access your personal data
- Correct inaccurate data
- Withdraw consent for data processing
- Request deletion of your data
- Be informed about how your data is used
7. Third-Party Sharing
We do not sell personal data. We share data only with the following parties:
- Supabase (infrastructure provider)
- WhatsApp/Meta (message delivery)
- Telegram (message delivery)
- Payment processors (for billing)
All third parties are bound by data processing agreements.
8. Cookies
Our web application uses minimal cookies for session management only. We do not use third-party tracking cookies or analytics services.
9. Data Breach Notification
In the event of a data breach, we will notify affected users and the Malaysian Personal Data Protection Commissioner within 72 hours.
10. Children's Privacy
Our service is not directed at individuals under 18. We do not knowingly collect data from minors.
11. Contact
For privacy matters: privacy@minilab.my
Data Protection Officer: Minilab Sdn Bhd, Kuala Lumpur, Malaysia.