KUALA LUMPUR20–23 NOVEMBER 2026M WORLD HOTELAPPLICATIONS CLOSE 9 NOVEMBER
Legal · In force from 13 September 2026

Privacy Notice

What we collect about you, why, who else sees it, how long we keep it, and what you can tell us to do about it. Written for Malaysia’s Personal Data Protection Act 2010.

Who is responsible for your information

First Experts Sdn Bhd is the data user under Malaysia’s Personal Data Protection Act 2010 — the legal term for the company answerable for what happens to your personal information.

Purple Door (M) Sdn Bhd produces the event and handles your information on First Experts’ instructions.

MIT Hacking Medicine provides the programme, the method and the mentors. Where it receives information from us — the newsletter, if you ask for it — it does so under its own privacy statement, not this one.

What we collect

If you apply for the hackathon. Your name, email addresses, mobile and WhatsApp numbers, the country you are travelling from and your city, age group, gender, ethnicity, whether you study or work, your organisation, your job title or degree programme, your professional field, LinkedIn and any CV, photograph, website or social links you give us, the languages you work in, your shirt size, whether you need a letter for a Malaysian visa, the themes that interest you, what you wrote about why you want a place, any MIT connection, whether you have been to one of these before, how you heard about us, and the name, number and relationship of somebody to ring in an emergency.

If you buy a ticket. Your name, work email, phone number, job title and organisation, the names of the people attending on your booking, and any dietary or access notes. Payment is taken by Billplz. We never see or hold your card details.

If you offer to speak, mentor or sponsor. Your name, email, phone, organisation and role, a short biography, the links you give us, and what you wrote to us.

If you write to us. Whatever is in your message, and the address or number you sent it from.

If you only visit the website. The ordinary records a web server keeps — the page you asked for, when, and the address you asked from. We set no cookies and no tracking of any kind: no Google Analytics, no advertising pixel, no session recording, nothing that follows you to another site. The one thing that leaves our servers is our typeface, which is loaded from Google Fonts, and Google receives your IP address in order to send it.

If you buy a ticket or apply. Those pages keep what you have typed in your own browser so a half-finished form survives a closed tab. It never leaves your device until you submit, and clearing your browser data removes it. Signing in sets one cookie, which is what keeps you signed in and nothing else.

Checked on the live site on 13 September 2026.

The questions you do not have to answer

Some of what we ask is what the Act calls sensitive personal data — information about your physical or mental health, your religious or political beliefs, or offences. We may only use it if you have explicitly agreed, and you are free not to answer.

  • What the kitchen should know, and anything else about food. This can reveal a health condition or a religious practice. It is asked so you get fed properly.
  • Anything that would make the room work better for you. Asked so the venue works for you, not to judge an application.
  • Ethnicity. Asked so we can see whether the room reflects the country. Malaysian law does not class ethnicity as sensitive personal data; European law does, and we treat it that way for anybody in the EEA or the UK. Answering is optional.

Your emergency contact is somebody else’s information. Please ask them before you give us their number. By entering it you are telling us they agreed.

Why we use it

Malaysian law works mainly on your agreement. You give it when you send the form, and you can take it back at any time. We use your information to:

  • decide who gets a place, and put balanced teams together;
  • run the four days — badges, catering, access, teams, certificates;
  • take payment for tickets and keep proper accounts;
  • tell you what is happening by email, and on WhatsApp only if you said yes;
  • report attendance and outcomes to partners and to MIT Hacking Medicine, as numbers rather than as people;
  • answer you when you write to us;
  • meet our legal, tax and audit obligations.

We do not use your information to make an automated decision about you. A person reads every application.

Who else sees it

  • Sponsors — only the people who ticked “May sponsors contact you about opportunities?” on the form. Nobody else’s details reach a sponsor, and we never hand over the whole list. A sponsor is given your name, role, organisation and the contact details you gave us — never your application, your CV, or anything you wrote about yourself.
  • MIT Hacking Medicine, in the United States — for the programme and the mentor network, and for the newsletter if you asked for it.
  • Suppliers working on our instructions: Supabase (the database), Vercel (the website), Billplz (payments, Malaysia), Meta Platforms (WhatsApp messages), Google (documents).
  • The venue, for access and catering, and only what it needs.
  • Anybody the law requires us to tell.

We do not sell your personal information and we do not rent lists.

Where it is kept, and when it leaves Malaysia

The database is hosted by Supabase in Singapore. The website is served by Vercel from servers in several countries. WhatsApp messages pass through Meta. The MIT Hacking Medicine newsletter is run from the United States.

So your information does leave Malaysia. The Act sets conditions on that.

How long we keep it

How long we hold on to things:

  • applications and attendee records: 24 months after the event, so the next edition can invite people back;
  • accounting and payment records: 7 years, as Malaysian tax law requires;
  • WhatsApp conversations: 12 months;
  • anything you ask us to delete: within 30 days, except what the law obliges us to keep.

What you can tell us to do

Under the Act you may:

  • ask for a copy of what we hold about you;
  • have anything wrong corrected;
  • take back your agreement, at any time;
  • tell us to stop sending you things;
  • ask us to limit how we use your information;
  • complain to Malaysia’s Personal Data Protection Commissioner (Jabatan Perlindungan Data Peribadi).

Write to info@mymithackmed.com. We will answer an access request within 21 days, which is the period the Act allows. We do not charge for this.

Taking back your agreement does not undo what we already did with your information while it stood, and it may mean we cannot keep you in the event.

Keeping it safe

Access to the hub requires a sign-in, and every table in the database is restricted to the people whose job needs it. Card details never reach us. Documents live on a company drive with named members.

If you are in Europe or the United Kingdom

Your rights under the GDPR are broadly those above, and also include portability and the right to object. Where MIT Hacking Medicine is the party responsible — the newsletter, and its own events — MIT’s statement applies and names its representatives in Paris and London. Write to us first and we will point you to the right place.

This notice in Bahasa Malaysia

The Act requires this notice in both the national language and English. The Bahasa Malaysia version will be written once the English wording is settled — translating a legal text that is still changing wastes the reviewer’s time — and the two will be published together.

Changes

We may change this notice. If we change anything that matters, we will say so on this page and, where it affects you directly, write to you.

Written 12 September 2026. Checked by a lawyer and in force from 13 September 2026.

Questions about this notice?

Write to us and a person answers.

Contact us →