UNM Robotics Society
Privacy Policy & Personal Data Protection Notice
How we collect, use, disclose and protect personal data on unmrobotics.com.
1. Introduction
The Personal Data Protection Act 2010 (“the Act” or “PDPA”), as amended by the Personal Data Protection (Amendment) Act 2024, regulates the processing of personal data in commercial transactions in Malaysia. The Act requires us to inform you about the personal data we collect from you and how we process it.
This Privacy Policy and Personal Data Protection Notice (“this Notice”) explains how the UNM Robotics Society (“the Society”, “we”, “us”, “our”) collects, uses, discloses and protects personal data through the website at unmrobotics.com and its associated services.
The terms personal data, sensitive personal data, processing, data controller, data processor, commercial transactions and relevant person have the meanings prescribed in the Act.
In this Notice, “you” and “your” refer to any person who visits the website, registers for an account, posts on the forum, applies to attend an event, browses merchandise, or otherwise interacts with the Society through this website — whether or not you are a student of the University of Nottingham Malaysia.
For the purposes of the Act, the Society acts as the data controller in respect of personal data collected through unmrobotics.com.
1.1 Relationship with the University of Nottingham Malaysia
The UNM Robotics Society is a registered student society of The University of Nottingham Malaysia (“the University”). This Notice governs personal data collected by the Society through unmrobotics.com. It operates in addition to, and does not replace, the University’s own Data Protection Notice, which continues to govern your relationship with the University as a student, applicant, employee or visitor.
The University’s Data Protection Notice is available at www.nottingham.edu.my.
Where this Notice and the University’s Notice both apply to the same processing activity, the more protective provision applies.
1.2 Data of relevant persons
Where you provide us with personal data belonging to a third party — for example a parent, guardian or visitor you are bringing to an event — you warrant that you are authorised to provide that data and to give consent on that person’s behalf, and you undertake to bring this Notice to their attention. Provision of this Notice to you is deemed notice given to, and consent obtained from, that third party.
2. Personal data we collect
2.1 Account registration
We operate two registration paths. Both require you to set a password, which is stored in hashed form by our authentication provider and is never visible to us in plain text.
If you register as a University of Nottingham Malaysia student, we collect:
- Full name
- University email address (your OWA / @nottingham.edu.my address)
- Student ID number
- Year of study
- Course of study
If you register as an external member (non-UNM), we collect:
- Full name
- Email address
- School, college or institution name
- Region (e.g. state and country)
- Year or level of study
2.2 Profile information
Once registered, you may optionally provide or generate:
- A nickname or display name
- A short biography
- A profile picture (avatar) and profile banner image
- Tags assigned to you by the Society, which the Society can show or hide
- A committee role or designation, where assigned to you
2.3 Account security
If you choose to enable two-factor authentication, we process the data necessary to operate time-based one-time password (TOTP) verification, including your enrolled authenticator factor. We do not store the codes themselves.
2.4 Forum activity
When you use the forum, we collect and store:
- Threads and replies you post, including their text content, category and any images you attach
- Likes you give to threads or replies
- The date and time of your posts and the account they are associated with
- A view count for each thread
A record of which threads you have opened is stored locally in your own browser (in localStorage) so we do not count the same visitor twice. This information stays on your device and is not transmitted to us.
2.5 Event applications
You must be signed in to apply for an event. When you apply, we collect:
- Your name and the registration details already held on your profile (student ID, OWA, year and course; or email, school, region and year for external members)
- Dietary restrictions and medical conditions — requested only for events where food is provided, and only on an optional basis
- The number of visitors you intend to bring, where an event permits visitors
- Any supporting documents or files an event requires you to upload
- Proof of payment, where an event carries a fee — typically a bank transfer receipt or screenshot
- Your application status, submission timestamp, the committee member who reviewed it, and where applicable the reason for rejection or your position on a waitlist
You are asked to tick a consent box before your application details are recorded.
2.6 Sensitive personal data
Dietary restrictions and medical or health information constitute sensitive personal data under section 40 of the Act. We collect this only where an event involves food or where an accommodation may be needed, only with your explicit consent, and only for the purpose of accommodating you safely at that event. You are never obliged to provide it, and you may attend without doing so — though we may then be unable to accommodate specific requirements.
Proof-of-payment documents may incidentally contain financial information such as bank account names or partial account numbers. We ask that you redact anything not needed to verify the payment.
2.7 Merchandise
The Products section of the website may list Society merchandise. Items you add to your cart are stored only in your own browser and are not transmitted to us. There is currently no online checkout, so we do not collect payment or delivery details through this website. If checkout is enabled in future, this Notice will be updated before it goes live.
2.8 Technical and log data
Our website is served as a static site through GitHub Pages, and our application data is held with Supabase. Those providers automatically record technical information in the ordinary course of delivering the service, which may include your IP address, browser type and version, device and operating system, referring page, and the date and time of your request. This information is generated at infrastructure level and we access it only for security, abuse-prevention and troubleshooting purposes.
2.9 Cookies and browser storage
The Society does not operate any advertising, analytics or third-party tracking on unmrobotics.com. We do not use Google Analytics, advertising pixels, or similar technologies.
We use only browser storage that is strictly necessary for the site to function:
| Purpose | Mechanism | What it holds |
|---|---|---|
| Keeping you signed in | Authentication session token (Supabase) | Session and refresh tokens |
| Shopping cart | localStorage (rs-cart) | Items you have added to your cart |
| Thread view counting | localStorage (rs-viewed-threads) | IDs of forum threads you have opened |
| Returning you to the application form after sign-in | sessionStorage | The event you were applying to; cleared on use |
You can clear this data at any time through your browser settings, though doing so will sign you out and empty your cart.
2.10 Photographs and recordings at events
We may take photographs, video or audio recordings at Society events for publicity, reporting and archival purposes, and may publish these on this website, on our social media channels, and in Society or University materials. Where you do not wish to appear, please tell an organiser at the event or contact us using the details in section 9.
2.11 Accuracy
You confirm that the personal data you provide is accurate, complete, current and not misleading. If it is incomplete or inaccurate, we may be unable to provide you with the services you have requested — for example, we may be unable to verify your student status or accommodate a dietary requirement.
3. Publicly visible information
This is a community platform, and some of what you provide is visible to others by design. Please read this section carefully before posting.
The following are visible to other signed-in users, and in some cases to anyone on the internet:
- Your display name or nickname, avatar and banner image
- Your biography and any tags the Society has made visible
- Your committee role or designation, if you hold one
- All forum threads and replies you post, together with your name and the time of posting
- Any images you attach to a forum post
- Photographs from events in which you appear
The following are never publicly visible:
- Your password
- Your student ID number
- Your email address
- Your course, year of study, school or region
- Your dietary or medical information
- Your proof-of-payment documents and event application attachments
Event application data — including sensitive information — is accessible only to Society committee members holding administrative or moderator permissions, and only for the purpose of running the event concerned.
Please note that content you post publicly may be seen, copied, quoted or archived by others, including by search engines and web archiving services, and we cannot recall it once it has left our systems.
4. Purposes of processing
We process your personal data for the following purposes:
Membership and account administration
- To create, authenticate and administer your account
- To verify that you are a student of the University of Nottingham Malaysia where membership, pricing or eligibility depends on it
- To secure your account, including two-factor authentication and detecting unauthorised access
Community and forum services
- To operate the forum, display your posts and replies, and attribute them to you
- To moderate content, enforce our community standards, and investigate reports of abuse or misconduct
- To personalise your experience, including your public profile
Events
- To process event applications, manage capacity and waitlists, and confirm attendance
- To accommodate dietary requirements, allergies and medical conditions where food is served or accessibility support is needed
- To verify payment for paid events and maintain financial records
- To contact you with information, changes or cancellations relating to an event you have applied for
- To manage visitors you bring to an event
Communications
- To respond to your enquiries, requests and complaints
- To send you Society announcements, event notifications and updates, where you have consented to receive them — you may withdraw this consent at any time
Governance, safety and compliance
- To report on Society activities to the University, including membership numbers and event attendance, as required for society registration, funding, room bookings and insurance
- To maintain the Society’s internal records and accounts
- To investigate incidents, complaints and safeguarding concerns
- To comply with legal, regulatory and University requirements, and to establish, exercise or defend legal claims
We do not sell your personal data, and we do not use it for automated decision-making that produces legal or similarly significant effects on you. Where an event has a capacity limit, applications are placed on a waitlist in submission order and admitted automatically as places free up; a committee member can override this at any time.
5. Disclosure of personal data
We may disclose your personal data to the following categories of recipient, within and outside Malaysia:
Within the Society
- Committee members and appointed moderators, on a need-to-know basis and limited to the function they perform (for example, an events officer reviewing applications for the event they run)
To the University
- The University of Nottingham Malaysia, including the Students’ Association, Student Services, and relevant faculty, departments or staff — for society registration and reporting, funding and financial reconciliation, venue and facilities bookings, insurance, safeguarding, and where required by University policy or in the event of an emergency, accident or disciplinary matter
Service providers (data processors)
| Provider | Function | Where processed |
|---|---|---|
| Supabase | Database, authentication, and file storage for the site | Outside Malaysia — see section 6 |
| GitHub (Microsoft) | Website hosting via GitHub Pages | Outside Malaysia — see section 6 |
| jsDelivr | Public CDN serving the JavaScript library used by the site | Global CDN |
Our service providers are engaged to process personal data on our instructions and are subject to their own security and confidentiality obligations. Under the amended Act, data processors also carry direct obligations in respect of the security of the personal data they handle.
Other recipients
- The Society’s or University’s finance function, in respect of paid events
- Professional advisers, auditors and insurers, where necessary
- Law enforcement, regulators, courts or other authorities where required by law or legal process, or where necessary to protect the life, safety, security or property of any person or of the Society or the University
- The general public, in respect of information you have chosen to make public and photographs or recordings taken at events (see sections 2.10 and 3)
If you follow links from our website to external platforms — including Instagram, GitHub, LinkedIn, Discord or YouTube — those platforms operate under their own privacy policies, over which we have no control. We encourage you to review them.
6. Transfers outside Malaysia
Our infrastructure providers store and process data on servers located outside Malaysia. By using this website and providing your personal data, you consent to the transfer of your personal data outside Malaysia for the purposes described in this Notice.
Where we transfer personal data outside Malaysia, we do so in accordance with the cross-border transfer requirements of the Act, which permit transfers to jurisdictions with substantially similar data protection law or which ensure an equivalent level of protection, and otherwise on the basis of your consent or the other grounds permitted under the Act.
7. Retention
We retain personal data only for as long as necessary for the purposes set out in this Notice, or for as long as required by law, University policy, or the Society’s own governance obligations.
Please note: we do not currently operate an automated deletion schedule. Records remain in our systems until a committee member removes them or until you ask us to delete them. The periods below are the Society’s review targets — the points at which we aim to review a category of data and delete what is no longer needed — not automatic expiry dates. We are working towards automating them.
| Data | How long we keep it |
|---|---|
| Account and profile data | For as long as your account exists. Deleted on request — see section 9. |
| Forum threads and replies | Retained indefinitely as part of the community archive. You can delete your own posts at any time. |
| Event application records | Kept for the Society’s event and financial records. Reviewed 12 months after the event, and deleted unless still needed for audit purposes. Deleted immediately if the event itself is deleted. |
| Dietary and medical information | Held as part of the application record. Reviewed and deleted within 12 months of the event it relates to; deleted sooner on request. |
| Proof-of-payment documents and application attachments | Retained in line with the Society’s financial record-keeping, typically 1 year, then reviewed. Replacing your proof of payment deletes the previous file. |
| Photographs and recordings from events | Retained indefinitely for archival and publicity purposes unless you object. |
What happens when an account is deleted. Deleting your account removes your profile, avatar and banner images, likes and tags. Your forum posts remain as part of the archive. Your event application records also remain, but are unlinked from your account — the Society keeps them for its event attendance and financial records. If you want your application records erased as well, say so in your request and we will delete them unless we are required to keep them.
8. Security
We take practical steps to protect personal data from loss, misuse, unauthorised access, alteration or disclosure, including:
- Encrypted connections (HTTPS/TLS) across the whole website
- Passwords stored using industry-standard hashing; the Society never has access to your password in plain text
- Optional two-factor authentication for user accounts
- Row-level access controls in our database, restricting each account to the records it is entitled to see
- Private storage for sensitive uploads such as proof-of-payment documents and application attachments, which are accessible only through short-lived, expiring links issued to the uploader and to authorised committee members
- Role-based permissions limiting administrative and moderation functions to designated committee members
- Server-side limits on the type and size of files that can be uploaded
No system can be guaranteed completely secure, and you are responsible for keeping your own password confidential and for the activity that occurs under your account.
Data breaches. Under the amended Act, where we have reason to believe a personal data breach has occurred, we will notify the Personal Data Protection Commissioner as soon as practicable and in any event within 72 hours of becoming aware of it. Where the breach causes or is likely to cause significant harm to you, we will notify you without unnecessary delay and in any event within 7 days. We maintain an internal record of personal data breaches.
9. Your rights
Under the Act, you have the right to:
- Access the personal data we hold about you, and be told whether we hold any
- Correct personal data that is inaccurate, incomplete, misleading or out of date
- Withdraw your consent to our processing, in whole or in part, subject to any contractual conditions and legal restrictions
- Object to direct marketing, including Society announcements and event notifications
- Limit the processing of your personal data where processing is likely to cause you unwarranted damage or distress
- Data portability — to request that your personal data be transmitted to another data controller, where technically feasible and where the conditions under the Act are met
Some of these you can exercise yourself from your account: you can edit your profile details, change your avatar and banner, delete your own forum threads and replies, and replace a proof-of-payment file you have uploaded.
Account deletion is not currently self-service. To delete your account, or to make any other request under this section, please contact us:
UNM Robotics Society — Data Protection ContactEmail: unmcrobots@gmail.com
Postal: UNM Robotics Society, c/o Students’ Association,
The University of Nottingham Malaysia, Jalan Broga,
43500 Semenyih, Selangor, Malaysia
Please submit requests in writing so that we can verify your identity. We will respond within the period required by the Act. If we refuse a request for access or correction, we will tell you why.
You may also contact the University’s Data Protection Officer in respect of personal data held by the University:
Data Protection OfficerThe University of Nottingham Malaysia
Jalan Broga, 43500 Semenyih, Selangor, Malaysia
Email: DPO@nottingham.edu.my
If you are not satisfied with our response, you may lodge a complaint with the Personal Data Protection Commissioner (Jabatan Perlindungan Data Peribadi, Malaysia).
10. Keeping your data up to date
Please notify us, or update your profile directly, if your personal data changes — particularly your email address, course or year of study, or any dietary or medical information relevant to an upcoming event.
11. Minors
Some of our events and community activities are open to school and pre-university students, who may be under 18 years of age.
Where you are under 18, the Act requires that consent to the processing of your personal data be given by your parent, guardian or person with parental responsibility. By registering an account or applying to an event, you confirm that you have obtained that consent where required.
If you believe we hold personal data relating to a person under 18 without appropriate consent, contact us at the address in section 9 and we will delete it.
12. Changes to this Notice
We may review and update this Notice from time to time to reflect changes in our practices, our services, or the law. The current version will always be available at unmrobotics.com. Where changes are material, we will take reasonable steps to notify registered members. Your continued use of the website following any change constitutes acceptance of the revised Notice.