DRAFT — this document has not yet been reviewed by a lawyer. Do not rely on it as final until it has been.
WooWoo World

Privacy Policy

Last updated: 3 August 2026 · Applies to woowoo.world and woowooworld.co

1. Who this policy covers

This Privacy Policy explains how [WooWoo World legal entity name to be inserted] ("WooWoo World", "we", "us") collects, uses, and protects personal data when you visit our website or make a booking, in accordance with Malaysia's Personal Data Protection Act 2010 (PDPA). Our registered office is at [Registered office address to be inserted].

If you are booking on behalf of colleagues, please make sure they are aware of this policy — you are responsible for having their consent to share their personal data with us for the purpose of the booking.

2. What we collect

DataWhen
Delegate full name, job title, and companyAt booking, for every delegate registered
Booking contact email addressAt booking
Sales rep code (if applicable)At booking, if a code is entered — used only for internal commission tracking
Payment card or bank detailsAt checkout — collected and processed directly by Stripe, our payment processor. We never see or store your full card details ourselves.
Basic technical data (IP address, browser type)Automatically, via our hosting provider, for security and performance purposes

3. Why we collect it

We do not sell your personal data, and we do not use it for advertising or marketing to third parties.

4. Who we share it with

We use a small number of trusted service providers to run our booking system. Each only receives the data it needs to do its job:

ProviderPurpose
StripePayment processing. Handles your payment details directly; we never store your card number.
NetlifyWebsite hosting and secure storage of your booking record (delegate names, company, booking reference).
ResendSending booking confirmation and invoice emails.
CloudflareWebsite delivery and security (DNS/CDN) for woowoo.world and woowooworld.co.

Some of these providers process data on servers located outside Malaysia. Where that happens, we rely on those providers' own compliance with recognised international data protection standards to ensure your data continues to be appropriately protected.

We do not share your data with any other third party except where required by law (for example, a lawful request from a Malaysian authority) or to support your organisation's HRD Corp claim, with your knowledge.

5. How long we keep it

We retain booking and payment records for as long as required for accounting and tax purposes under Malaysian law (typically 7 years from the relevant transaction). Delegate contact details used only for pre-event communication are deleted or anonymised once no longer needed for that purpose, unless a longer retention period is required for the reasons above.

6. Your rights under the PDPA

Under the Personal Data Protection Act 2010, you have the right to:

To exercise any of these rights, contact us using the details in Section 9.

7. Security

We use industry-standard technical measures — including encrypted connections (HTTPS) and access-controlled cloud storage — to protect the personal data we hold. Payment details are handled entirely by Stripe, a PCI-DSS compliant payment processor, and never touch our own servers.

8. Cookies

Our website does not currently use advertising or tracking cookies. Our hosting and security providers (Cloudflare, Netlify) may set minimal technical cookies necessary for the site to function securely — these do not identify you personally.

9. Contact us

For any question about this Privacy Policy, or to exercise your rights under the PDPA, contact: [privacy contact email to be inserted].

10. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices or the law. The version in force at the time of your booking is the one that applies to you. Material changes will be reflected in the "Last updated" date above.