What we collect about you, why, who else sees it, how long we keep it, and what you can tell us to do about it. Written for Malaysia’s Personal Data Protection Act 2010.
First Experts Sdn Bhd is the data user under Malaysia’s Personal Data Protection Act 2010 — the legal term for the company answerable for what happens to your personal information.
Purple Door (M) Sdn Bhd produces the event and handles your information on First Experts’ instructions.
MIT Hacking Medicine provides the programme, the method and the mentors. Where it receives information from us — the newsletter, if you ask for it — it does so under its own privacy statement, not this one.
If you apply for the hackathon. Your name, email addresses, mobile and WhatsApp numbers, the country you are travelling from and your city, age group, gender, ethnicity, whether you study or work, your organisation, your job title or degree programme, your professional field, LinkedIn and any CV, photograph, website or social links you give us, the languages you work in, your shirt size, whether you need a letter for a Malaysian visa, the themes that interest you, what you wrote about why you want a place, any MIT connection, whether you have been to one of these before, how you heard about us, and the name, number and relationship of somebody to ring in an emergency.
If you buy a ticket. Your name, work email, phone number, job title and organisation, the names of the people attending on your booking, and any dietary or access notes. Payment is taken by Billplz. We never see or hold your card details.
If you offer to speak, mentor or sponsor. Your name, email, phone, organisation and role, a short biography, the links you give us, and what you wrote to us.
If you write to us. Whatever is in your message, and the address or number you sent it from.
If you only visit the website. The ordinary records a web server keeps — the page you asked for, when, and the address you asked from. We set no cookies and no tracking of any kind: no Google Analytics, no advertising pixel, no session recording, nothing that follows you to another site. The one thing that leaves our servers is our typeface, which is loaded from Google Fonts, and Google receives your IP address in order to send it.
If you buy a ticket or apply. Those pages keep what you have typed in your own browser so a half-finished form survives a closed tab. It never leaves your device until you submit, and clearing your browser data removes it. Signing in sets one cookie, which is what keeps you signed in and nothing else.
Checked on the live site on 13 September 2026.
Some of what we ask is what the Act calls sensitive personal data — information about your physical or mental health, your religious or political beliefs, or offences. We may only use it if you have explicitly agreed, and you are free not to answer.
Your emergency contact is somebody else’s information. Please ask them before you give us their number. By entering it you are telling us they agreed.
Malaysian law works mainly on your agreement. You give it when you send the form, and you can take it back at any time. We use your information to:
We do not use your information to make an automated decision about you. A person reads every application.
We do not sell your personal information and we do not rent lists.
The database is hosted by Supabase in Singapore. The website is served by Vercel from servers in several countries. WhatsApp messages pass through Meta. The MIT Hacking Medicine newsletter is run from the United States.
So your information does leave Malaysia. The Act sets conditions on that.
How long we hold on to things:
Under the Act you may:
Write to info@mymithackmed.com. We will answer an access request within 21 days, which is the period the Act allows. We do not charge for this.
Taking back your agreement does not undo what we already did with your information while it stood, and it may mean we cannot keep you in the event.
Access to the hub requires a sign-in, and every table in the database is restricted to the people whose job needs it. Card details never reach us. Documents live on a company drive with named members.
Your rights under the GDPR are broadly those above, and also include portability and the right to object. Where MIT Hacking Medicine is the party responsible — the newsletter, and its own events — MIT’s statement applies and names its representatives in Paris and London. Write to us first and we will point you to the right place.
The Act requires this notice in both the national language and English. The Bahasa Malaysia version will be written once the English wording is settled — translating a legal text that is still changing wastes the reviewer’s time — and the two will be published together.
We may change this notice. If we change anything that matters, we will say so on this page and, where it affects you directly, write to you.
Written 12 September 2026. Checked by a lawyer and in force from 13 September 2026.