Privacy Policy & Personal Data Protection Notice

Effective and last updated: 29 September 2026 · Version 2026-09-29

Versi Bahasa Malaysia: Notis Perlindungan Data Peribadi

This policy explains what personal data GuestNet collects, why, who we share it with, how long we keep it and the rights you have. It is our written notice under section 7 of Malaysia's Personal Data Protection Act 2010 (the "PDPA", as amended).

1. Who we are

GuestNet (the website guestnet.my and the web app app.guestnet.my, together the "Service") is operated by BBJCreative LLP, a limited liability partnership registered in Malaysia (LLP No. [LLP registration number]), [registered business address], Malaysia ("we", "us", "our"). For the PDPA, we are the data user for the personal data described in this policy.

Privacy contact: sales@bbjcreative.com (please put "Privacy" in the subject line).

2. The short version

3. Data we collect

CategoryWhatSourceRequired?
Account dataEmail address; business (organisation) name; account password, which we store only as an Argon2 hash and never in readable form; the date and version of the Terms and this policy you accepted.You, at sign-up and in SettingsYes. Without it we cannot create or secure your account.
Card contentCard names, WiFi network names (SSIDs), security type, design choices (template, font, colours, header and footer text) and any logo or background image you upload.You, in the appYes, to create cards. Uploads are optional.
Exported filesThe PNG or PDF files generated when you export a card. They contain the QR code, which encodes your WiFi password (see section 4).Generated by the Service at your requestOnly if you export
Payment data (once paid plans launch)Plan purchased, amount, currency, date, payment status and the payment provider's transaction reference. Card, bank and e-wallet details are entered on the payment provider's page and are not received or stored by us.You and our payment providersOnly if you buy a paid plan
Technical and security dataIP address, browser and device type, date and time, pages and API endpoints requested, and response codes, recorded in server and network logs. Sign-in attempts are rate-limited by IP address.Automatically, when you use the ServiceYes. Needed to deliver and protect the Service.
CommunicationsWhat you send us by email and our replies.YouOptional

We do not intentionally collect sensitive personal data (as defined in the PDPA). Please do not include it in card text, file names or uploads.

4. Your WiFi password and exported files

A WiFi QR code only works if it contains the network password, so we want to be precise about how that password is handled:

  1. Preview. The QR preview is drawn in your browser. Typing the password does not send it to us.
  2. Export. When you export, the password is sent once over HTTPS so our server can draw the print file. It is not written to our database or application logs, and it is not included in the request-body logging of our servers.
  3. The file. The exported PNG or PDF contains the QR code, and anyone who can see or scan the QR can join the network. The file is stored on our servers at a long, random, unguessable address so you can download it again. It is marked so it is not stored by browser or network caches and not indexed by search engines.
  4. Retention. We keep only the latest export for each card and each format. A new export replaces the previous file. Deleting a card deletes its exports, and deleting your account deletes all of them.

Treat exported files and their links like the password itself. Don't post them publicly online unless you intend anyone to join. We strongly recommend using a separate guest network for your card, not your main business network.

5. Why we use your data (purposes)

We process personal data only for these purposes:

We rely on your consent, given when you create an account and use the Service, and on the other grounds the PDPA allows, including where processing is necessary to perform our contract with you, to comply with a legal obligation, or to protect your vital interests. We will not use your data for a purpose not directly related to these without asking you first. We will only send marketing email if you opt in, and every such email will let you opt out.

6. Who we share it with

We do not sell or rent personal data. We disclose it only to the following classes of third parties, and only as needed for the purposes above:

Our service providers act on our instructions and must protect the data. They may not use it for their own purposes, except payment providers acting as independent controllers of payment data.

7. Transfers outside Malaysia

Some providers, including Cloudflare's global network and our hosting and payment providers, may process or store data outside Malaysia. Where personal data is transferred abroad, we do so as permitted by section 129 of the PDPA. We use reputable providers with appropriate safeguards and contractual protections, so that your data receives protection comparable to the PDPA. By using the Service you consent to these transfers.

8. Cookies and local storage

We use only strictly necessary technologies, so no cookie banner is required:

We do not use advertising, cross-site tracking or third-party analytics cookies.

9. How long we keep data

We may keep data longer where needed to comply with law or to establish, exercise or defend legal claims.

10. Security

We take practical steps to protect personal data from loss, misuse, modification, unauthorised or accidental access or disclosure, alteration and destruction, as the PDPA's Security Principle requires. These include:

No online service can be completely secure. You are responsible for choosing a strong account password and keeping it confidential. If we become aware of a personal data breach that is likely to cause significant harm, we will notify the Personal Data Protection Commissioner and affected users as the PDPA requires.

11. Your rights and choices

Under the PDPA you may:

Email sales@bbjcreative.com with the subject "Privacy request". We will verify your identity, usually by asking you to write from your account email, and respond within 21 days as the PDPA requires. We do not charge for reasonable requests; we may charge a fee as permitted by the PDPA regulations for repeated or excessive requests, or refuse them where the law allows. If you withdraw consent, or don't provide required data, we may be unable to provide the Service.

If you are unhappy with our response, you may complain to the Department of Personal Data Protection (Jabatan Perlindungan Data Peribadi), Malaysia.

12. Your guests' data

GuestNet does not collect any data from people who scan your card. Scanning happens on the guest's phone and connects it to your network; it does not contact us. GuestNet does not provide internet access, captive portals or guest tracking. If you collect guest data on your own network, for example through your router or a separate WiFi portal, you are the data user for it and responsible for complying with the PDPA.

13. Children

The Service is for businesses and is not intended for anyone under 18. We do not knowingly collect personal data from children. If you believe a child has given us data, contact us and we will delete it.

14. Changes to this policy

We may update this policy, for example when paid plans launch or if we add providers. We will post the new version here with a new "last updated" date. If a change materially affects how we use your personal data, we will tell you by email or in the app before it takes effect and, where required, ask for your consent.

15. Contact us

BBJCreative LLP (operator of GuestNet)
[registered business address], Malaysia
Email: sales@bbjcreative.com

If there is any inconsistency between the English and Bahasa Malaysia versions of this notice, the English version prevails, to the extent permitted by law.


Notis Perlindungan Data Peribadi (Bahasa Malaysia)

Berkuat kuasa: 29 September 2026 · Versi 2026-09-29

Notis ini diberikan menurut seksyen 7 Akta Perlindungan Data Peribadi 2010 ("APDP"). GuestNet (laman guestnet.my dan aplikasi app.guestnet.my) dikendalikan oleh BBJCreative LLP, perkongsian liabiliti terhad yang didaftarkan di Malaysia (No. LLP [nombor pendaftaran LLP]), [alamat perniagaan berdaftar], Malaysia ("kami").

Data yang kami kumpul

  • Data akaun: alamat e-mel, nama perniagaan, kata laluan akaun (disimpan hanya sebagai cincangan Argon2), dan tarikh serta versi Terma dan notis ini yang anda terima.
  • Kandungan kad: nama kad, nama rangkaian WiFi (SSID), jenis keselamatan, pilihan reka bentuk, serta logo atau imej latar yang anda muat naik.
  • Fail eksport: fail PNG/PDF yang dijana apabila anda mengeksport kad. Fail ini mengandungi kod QR yang mengekod kata laluan WiFi anda.
  • Data pembayaran (apabila pelan berbayar dilancarkan): pelan, jumlah, tarikh, status dan rujukan transaksi. Butiran kad atau bank dimasukkan di laman penyedia pembayaran dan tidak diterima atau disimpan oleh kami.
  • Data teknikal: alamat IP, jenis pelayar dan peranti, masa, dan permintaan yang dibuat, dalam log pelayan dan rangkaian.

Kata laluan WiFi anda

Kata laluan WiFi anda tidak disimpan dalam pangkalan data kami. Pratonton QR dijana dalam pelayar anda. Kata laluan dihantar sekali melalui sambungan HTTPS yang disulitkan semasa anda mengeksport, untuk menjana fail cetakan. Fail eksport mengandungi kod QR, jadi kami simpan hanya eksport terkini bagi setiap kad dan format, dan memadamkannya apabila anda memadam kad atau akaun. Layan fail eksport seperti kata laluan itu sendiri.

Tujuan pemprosesan

Kami memproses data peribadi untuk:

  • mewujudkan, mengendalikan dan melindungi akaun anda;
  • menyediakan Perkhidmatan (menyimpan reka bentuk, menjana pratonton dan eksport);
  • memproses pembayaran dan menyimpan rekod transaksi;
  • menjawab pertanyaan dan menghantar notis perkhidmatan;
  • mengesan dan mencegah penyalahgunaan, penipuan dan insiden keselamatan;
  • menambah baik kebolehpercayaan Perkhidmatan;
  • mematuhi undang-undang dan mempertahankan tuntutan undang-undang.

Kami tidak menjual data anda dan tidak menghantar e-mel pemasaran tanpa persetujuan anda.

Pihak ketiga yang menerima data

Data hanya didedahkan kepada pihak berikut, setakat yang perlu:

  • penyedia pengehosan pelayan (kini Hostinger);
  • Cloudflare (rangkaian, DNS dan keselamatan);
  • penyedia pembayaran Billplz dan/atau Stripe (apabila dilancarkan);
  • penyedia e-mel;
  • penasihat profesional;
  • pihak berkuasa, apabila dikehendaki oleh undang-undang;
  • pengganti perniagaan, sekiranya berlaku penggabungan atau pengambilalihan.

Sesetengah penyedia mungkin memproses data di luar Malaysia; pemindahan sedemikian dibuat menurut seksyen 129 APDP.

Kuki

Kami hanya menggunakan kuki yang benar-benar perlu:

  • kuki log masuk refresh_token (sehingga 30 hari);
  • kuki keselamatan Cloudflare;
  • cache luar talian aplikasi pada peranti anda.

Tiada kuki pengiklanan atau analitik pihak ketiga.

Tempoh penyimpanan

  • Data akaun, kad dan muat naik disimpan selagi akaun wujud, dan dipadam serta-merta apabila anda memadam akaun di Tetapan.
  • Rekod transaksi disimpan selama yang dikehendaki oleh undang-undang cukai dan perakaunan (lazimnya 7 tahun).
  • Log pelayan diputar dan dipadam secara automatik.
  • Sandaran (jika ada) dipadam dalam kitaran biasa, dalam tempoh 35 hari.

Wajib atau sukarela

Data akaun dan kandungan kad adalah wajib untuk menggunakan Perkhidmatan; jika tidak diberikan, kami tidak dapat menyediakan Perkhidmatan. Muat naik logo atau imej, data pembayaran dan komunikasi adalah sukarela.

Hak anda

Anda berhak untuk:

  • mengakses dan mendapatkan salinan data peribadi anda;
  • membetulkan data yang tidak tepat;
  • menarik balik persetujuan;
  • menghalang pemprosesan yang mungkin menyebabkan kerosakan atau distres, dan pemasaran langsung;
  • meminta pemindahan data (portabiliti), jika diperuntukkan oleh undang-undang;
  • memadam akaun anda pada bila-bila masa di Tetapan.

Hantar permintaan ke sales@bbjcreative.com dengan subjek "Permintaan Privasi". Kami akan menjawab dalam tempoh 21 hari. Anda juga boleh membuat aduan kepada Jabatan Perlindungan Data Peribadi Malaysia.

Hubungi kami

BBJCreative LLP, [alamat perniagaan berdaftar], Malaysia. E-mel: sales@bbjcreative.com.

Sekiranya terdapat percanggahan antara versi Bahasa Inggeris dan Bahasa Malaysia, versi Bahasa Inggeris akan diguna pakai setakat yang dibenarkan oleh undang-undang.