Privacy Policy

Last updated: March 2026

1. Overview

This privacy policy explains how Minilab Sdn Bhd collects, uses, and protects personal data in compliance with the Personal Data Protection Act 2010 (PDPA 2010) of Malaysia.

2. Data We Collect

We collect the following types of data:

  • Name, phone number, and unit number (for residents via WhatsApp registration)
  • Name, phone number, email, and role (for building staff via Telegram)
  • Facial biometric data (for attendance verification, with explicit consent)
  • Visitor information (name, vehicle number, purpose of visit)
  • Building operational data (cases, invoices, attendance records)

3. How We Use Data

Your data is used for the following purposes:

  • To provide building management services
  • To process and route resident complaints
  • To verify staff attendance
  • To manage visitor access
  • To generate reports for building committees
  • To improve our AI models (anonymised data only)

4. Data Storage

All data is stored on Supabase PostgreSQL in the Singapore region (ap-southeast-1). Data is encrypted at rest using AES-256 and in transit using TLS 1.3. Row-level security ensures building data isolation.

5. Data Retention

  • Active account data: retained for the duration of the subscription
  • Visitor logs: retained for 12 months
  • Attendance records: retained for 24 months
  • Facial biometric data: deleted within 7 days of staff deregistration
  • Deleted accounts: all data permanently removed within 30 days

6. Your Rights Under PDPA 2010

You have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Withdraw consent for data processing
  • Request deletion of your data
  • Be informed about how your data is used

7. Third-Party Sharing

We do not sell personal data. We share data only with the following parties:

  • Supabase (infrastructure provider)
  • WhatsApp/Meta (message delivery)
  • Telegram (message delivery)
  • Payment processors (for billing)

All third parties are bound by data processing agreements.

8. Cookies

Our web application uses minimal cookies for session management only. We do not use third-party tracking cookies or analytics services.

9. Data Breach Notification

In the event of a data breach, we will notify affected users and the Malaysian Personal Data Protection Commissioner within 72 hours.

10. Children's Privacy

Our service is not directed at individuals under 18. We do not knowingly collect data from minors.

11. Contact

For privacy matters: privacy@minilab.my

Data Protection Officer: Minilab Sdn Bhd, Kuala Lumpur, Malaysia.