Legal
Privacy Policy
What we collect, why we collect it, who else sees it, how long we keep it, and what you can make us do about it.
- Who is responsible for your data
- What we collect
- Why we collect it, and on what basis
- Cookies
- Who we share it with
- Where your data goes
- How long we keep it
- How we protect it
- If something goes wrong
- Your rights
- Marketing and unsubscribing
- Children
- Changes to this policy
- Contact and complaints
1. Who is responsible for your data
Ben Lim Training Technologies Sdn. Bhd. (company no. [COMPANY NO. — TO BE FILLED], registered address [REGISTERED ADDRESS — TO BE FILLED]) is the data user under the Personal Data Protection Act 2010 for personal data collected through this site.
Our data protection contact is [DPO NAME / EMAIL — TO BE FILLED]. Until that is published you can reach us through the contact form.
2. What we collect
We collect only what the site needs to work. There is no advertising network, no tracking pixel and no analytics script on this site — we do not build a profile of you, and we do not buy or sell data about you.
If you create an account
| Data | Where it comes from |
|---|---|
| Name and email address | You, at sign-up |
| Password | You — stored only as a salted scrypt hash, never as text. We cannot read it and cannot tell it to you |
| Whether your email is verified, your account status and role | Generated by us |
| Record of your consent: which version of the terms you accepted, whether you opted into marketing, the date and your IP address | Recorded at sign-up, because the law requires us to be able to prove consent |
| Sessions: a hashed login token, the IP address and browser user-agent used, and when it expires | Generated when you log in, so you can stay logged in and spot unfamiliar sign-ins |
| Sign-in history, failed attempts, password resets and lockouts | Generated — this is what stops someone brute-forcing your account |
If you buy a course
| Data | Note |
|---|---|
| Order records: what you bought, the amount, the currency, the status, and the Stripe session and payment identifiers | Kept for accounting and tax |
| Your Stripe customer identifier | A reference, so refunds and receipts can be matched to you |
| Course entitlements: what you have access to, when it was granted, and why | |
| Your card or bank details | Never reach this website. Payment happens on Stripe's own hosted checkout page. We receive confirmation that you paid, the amount, and (for cards) the last four digits and card brand on Stripe's dashboard — not the number |
While you use a course
How far through each lesson you have watched, and whether you completed it, so the player can resume where you stopped. Each time a video or download is unlocked for you, that decision is recorded with your account id, the time, the IP address and the browser — this is how we detect account sharing and content scraping.
If you request the free guide or subscribe
Your name, email address, which form you used, and when. Lead records are held separately from accounts, because the consent and the retention are different.
If you send us a message
Your name, email address, the content of your message, your IP address and the time. We store the message before we try to email ourselves about it, so an email outage can never lose what you wrote.
Automatically, for everyone
Our web server and our hosting and content providers keep short-lived technical logs containing IP addresses, request times and user-agents. These exist for security and debugging.
3. Why we collect it, and on what basis
| Purpose | Basis under the PDPA |
|---|---|
| Creating and running your account, giving you the courses you bought | Necessary to perform our contract with you |
| Taking payment, issuing receipts, handling refunds and chargebacks | Contract, and our legal obligations |
| Sending service email — verification, password reset, security notices, purchase confirmations | Contract. These are not marketing and you cannot unsubscribe from them while you hold an account |
| Keeping accounts secure: rate limiting, lockouts, audit logging, detecting shared logins and content theft | Our legitimate interest in protecting customers and our material |
| Keeping financial and tax records | Legal obligation |
| Marketing email about courses and events | Your consent, given by ticking the box. Withdraw it any time |
| Answering your enquiry | Your request |
4. Cookies
This site sets one cookie, and only after you log in. It holds a random,
signed session token — not your name, not your email, not your password. It is
httpOnly (scripts on the page cannot read it), SameSite=Lax, and
sent only over HTTPS in production.
It is strictly necessary: without it you cannot stay logged in. Because we set no analytics, advertising or profiling cookies, there is no consent banner to click through. Logging out, or clearing cookies in your browser, removes it.
If we ever add analytics, this section and the consent mechanism will change first.
5. Who we share it with
We do not sell your personal data, and we do not share it for anyone else's marketing. We share it only with the service providers that make the site work, each limited to what it needs:
| Provider | What it handles |
|---|---|
| Stripe | Payments. Receives your email and payment details directly from you; returns confirmation to us |
| Cloudflare (R2) | Stores course video and files. The bucket is private; each playback link is signed individually and expires |
| Resend | Delivers our email. Receives your email address and the message content |
| Calendly | Only if you book a call. What you enter there is held by Calendly under its own policy |
| Our hosting provider | Runs the server and holds the database |
We may also disclose data where the law requires it — a court order, a tax audit, a regulator's demand — or to establish or defend a legal claim, or to prevent fraud or serious harm. If our business is sold or restructured, records may transfer to the buyer, who would be bound by this policy.
6. Where your data goes
Our database is held on our own server. Several of the providers above operate outside Malaysia, so some of your data is processed abroad. Where that happens we rely on the provider's contractual data protection commitments and on their being subject to comparable data protection law. By using the site you understand that this transfer takes place.
7. How long we keep it
| Record | Kept for |
|---|---|
| Account and profile | While your account is open, then anonymised — see below |
| Orders, payments and tax records | 7 years, as Malaysian tax law requires, even after you close your account |
| Consent records | As long as we rely on the consent, plus 6 years |
| Login sessions | Up to 30 days, then expired and pruned automatically |
| Verification and password-reset tokens | 24 hours and 60 minutes respectively; single-use and stored hashed |
| Security and access logs | Up to 24 months |
| Contact messages | 24 months after the matter is closed |
| Marketing list entries | Until you unsubscribe, plus a suppression record so we do not email you again by mistake |
What "deleting your account" actually means. We cannot simply erase everything, because the law requires us to keep financial records. So we anonymise: your name and email are blanked, your password and sessions are destroyed, your entitlements end, and the order rows survive under an identifier that is no longer linked to a person. The practical effect is that you are no longer identifiable to us.
8. How we protect it
- Passwords are stored as salted scrypt hashes, never in readable form, and are checked against known-breached password lists at sign-up.
- Sessions live on the server. The cookie holds a random token; the database stores only its hash. A stolen database does not yield working logins.
- Verification and reset tokens are single-use, expiring, and stored hashed.
- Five failed logins lock an account for 15 minutes; further rate limits apply per account and per network.
- Changing your password ends every other session and emails you a notice.
- Course video is never public. Every playback link is signed for one viewer and expires within minutes.
- Payment card data never touches our server at all.
- Traffic is encrypted with HTTPS; the database is backed up and the backups are restricted.
No system is perfectly secure, and we do not claim otherwise. Use a unique password here, and tell us at once if you think your account has been accessed by someone else.
9. If something goes wrong
If a breach of personal data occurs that is likely to cause you significant harm, we will notify the Personal Data Protection Commissioner and affected users as required by the PDPA, telling you what happened, what data was involved, and what you should do.
10. Your rights
Under the PDPA you may:
- Ask what we hold about you and get a copy. Logged-in account holders can download everything held about them from the account page, immediately and free. The export deliberately contains no password material.
- Correct anything wrong — ask us and we will fix it.
- Withdraw consent to marketing, at any time.
- Ask us to stop processing that causes you distress, or to limit it.
- Ask for your data in a portable form, or transmitted to another provider where that is technically feasible.
- Ask us to delete your account, subject to the records we must keep (clause 7).
Ask through the contact form. We may need to confirm your identity first — we are not going to hand your data to someone claiming to be you. We respond within 21 days. Access requests may attract a small prescribed fee where the law allows one; in practice we do not charge for a first request.
Please note: account deletion is currently handled by us manually on request rather than by a button in your account. It is done within 30 days of a verified request.
11. Marketing and unsubscribing
We only send marketing email to people who asked for it — by ticking the box at sign-up or by requesting a free guide. Every marketing email carries an unsubscribe link, and unsubscribing takes effect immediately.
Unsubscribing does not stop service email about an account you still hold: verification, password resets, security alerts and receipts are part of running the account and are not marketing.
12. Children
This site is for adults. We do not knowingly collect data from anyone under 18. If you believe a child has given us personal data, contact us and we will delete it.
13. Changes to this policy
We will update this page when what we do changes. The version and effective date at the top always identify the current text. If a change materially affects how we use data we already hold about you, we will email account holders before it takes effect.
14. Contact and complaints
Ben Lim Training Technologies Sdn. Bhd.
Company no. [COMPANY NO. — TO BE FILLED]
[REGISTERED ADDRESS — TO BE FILLED]
Data protection contact: [DPO NAME / EMAIL — TO BE FILLED]
Or use the contact form.
If you are not satisfied with how we have handled your data, please raise it with us first — we would rather fix it. You also have the right to complain to the Department of Personal Data Protection (Jabatan Perlindungan Data Peribadi), Malaysia.