Privacy
Privacy Notice
This notice explains, in plain language, how BLOOMDATA SDN. BHD. handles information submitted through the website, the Data & AI Community, website analytics and security controls.
Information we handle
Depending on how you use the site, Bloomdata may handle:
- information you submit as a learner or contributor, such as your name, email, mobile/WhatsApp number, State or Federal Territory, study or work context, interests, goals and availability;
- operational records such as registration reference IDs, status history and email-delivery logs;
- security information needed to protect forms and the administrator dashboard;
- optional website analytics described below.
Please do not submit NRIC/passport numbers, passwords, financial information or confidential employer/client material unless Bloomdata specifically requests it through an appropriate channel.
Why we use it
- to administer the Bloomdata Data & AI Community and Foundation Programme;
- to consider suitable cohorts and contribution opportunities;
- to send acknowledgements and programme-related communication;
- to secure registration forms and administrative access;
- where you allow analytics, to understand how public pages, sections and calls to action are used and improve the website.
Bloomdata does not sell registration or website analytics data to advertisers.
Optional analytics & approximate geography
Website analytics is optional. If you select Allow analytics, Bloomdata's first-party analytics may record the page path/title, referring host, campaign parameters, device class, viewport size, an ephemeral browser-tab session identifier, section views and link/button interactions.
For page views, Bloomdata may derive approximate country and region/state from the visitor's public IP address. The raw IP address is not written to the Web Analytics Google Sheet. Where the hosting environment does not provide geography, the server may perform a transient lookup with the configured GeoIP service. VPNs, mobile carriers and corporate gateways can make location inaccurate.
Cookies & browser storage
Strictly necessary
The private administrator area uses a secure session cookie for authentication. The public site stores a small preference cookie for up to one year so it can remember whether you allowed optional analytics. Cloudflare Turnstile, when enabled, is treated as a necessary security control for protected forms and may use browser/device signals required to distinguish automated traffic from legitimate users.
Optional analytics
When analytics is allowed, an ephemeral session identifier is kept in browser session storage for the current tab. Bloomdata does not use this analytics implementation for advertising profiles.
Service providers
Bloomdata currently relies on service providers to operate this programme and website. Depending on the feature used, information may be processed by:
- Google Apps Script and Google Sheets for the Community registry and governed operational records;
- Resend and its email-delivery infrastructure for transactional messages;
- Cloudflare Turnstile for anti-bot/security verification when enabled;
- the configured web-hosting/cPanel infrastructure;
- the configured GeoIP service for approximate location enrichment when analytics is allowed and a remote lookup is needed.
These providers operate under their own terms and privacy practices. Bloomdata aims to share only the information reasonably required for each function.
Your choices & corrections
You can choose Necessary only or Allow analytics at any time using Cookie settings. If you registered for the Community and need to correct or update your information, reply to your acknowledgement email or contact community@bloomdata.com.my with your reference ID.
For privacy, security, suspected misuse or related concerns, contact admin@bloomdata.com.my. You may also contact Bloomdata about access, correction or removal requests relating to information you submitted. Some operational or security records may need to be retained where reasonably necessary.
Retention & security
Bloomdata retains registration, communication, operational and security information for as long as reasonably needed for programme administration, audit/security, dispute handling or applicable obligations. Test records can be removed through the governed administrator workflow.
Security controls include restricted administrative access, hashed passwords, optional two-factor authentication, CSRF protection, rate limiting, server-side form verification and audit logging. No internet service can be guaranteed absolutely secure, so Bloomdata reviews and improves these controls over time.