Privacy

What this site collects, why, how long it is kept, and how to have it deleted. It collects very little, and this page says exactly what.

Who is responsible

Mohd Atasha is responsible for the personal data described here, and decides why and how it is processed. In the language of the Malaysian Personal Data Protection Act 2010 he is the data controller; the General Data Protection Regulation uses the same word.

No data protection officer has been appointed, and one is not required here. Malaysian law requires that appointment where processing involves more than twenty thousand people, more than ten thousand where the data is sensitive or financial, or where behaviour is monitored regularly and systematically. None of those apply to a contact form on a personal site. Questions are answered by him rather than by an office.

What is collected

Two things, and nothing else.

What you type into the contact form. Depending on which route you use, that is your name, your email address, and the details the page asks for, such as the event, the sector or your message. Every field exists because an answer depends on it. Nothing is collected because it is conventional to collect it.

A one-way fingerprint of your network address, when you send a message. This stops the form being flooded. It is a hash salted with a secret held on the server and cut short, so it cannot be turned back into an address by anyone, including him. It is kept for one hour and deleted nightly. It is not linked to your message.

There are no cookies, no analytics, no tracking pixels, no fingerprinting and no advertising. Nothing records which pages you read. If you never use the contact form, this site holds no personal data about you at all.

Why, and on what legal basis

Your message is used to read it and to reply to it. That is the whole purpose. It is not used for marketing, it is not profiled, no decision about you is automated, and it is never sold or shared for anyone else's purposes.

Under the GDPR the basis is legitimate interests, Article 6(1)(f): you wrote to ask something and answering you is the reason the data exists. Consent is not relied on, because treating a reply to your own enquiry as something you must separately consent to would be a formality rather than a protection. Under the Malaysian Act the processing is for the purpose you supplied the data for, and this page is the written notice section 7 requires.

The anti-flooding fingerprint rests on the same legitimate interest: keeping the form usable. It is the least identifying way to do that, which is why it is a salted hash rather than an address, and why the alternative most sites reach for, a third-party challenge script, is not used here.

How long it is kept

A message is deleted once it has been dealt with, or automatically one hundred and eighty days after it arrives, whichever comes first. The deletion runs nightly and is not a promise to remember: it is a scheduled job, and the same job is described on the colophon.

The anti-flooding fingerprint is kept for one hour and cleared nightly. Nothing else about a visit is stored.

Who else sees it

Your message is read by Mohd Atasha. It is not shared with anyone else, and it is not sent to any third party.

One thing does leave, and it is deliberately not your message. So that an enquiry is not missed, an email delivery service is told that an enquiry of a given kind arrived and when. It is not told your name, your email address, your organisation, or any word of what you wrote. Those stay in this site's own database.

The site runs on an edge hosting platform, which necessarily processes requests in order to serve pages, and the database and file storage are that platform's. Suppliers are described by what they do rather than by brand, because a supplier's name is not a privacy guarantee and naming one on this page would read as an endorsement. What matters is what reaches them, which is stated above exactly.

Both suppliers operate internationally, so data may be processed outside Malaysia. If your enquiry is sensitive enough that this matters, an encrypted route is available on request, and the contact page says how to ask for it.

Your rights, and how to use them

You can ask what is held about you, ask for it to be corrected, ask for it to be deleted, ask for a copy, or object to it being held at all. Under the Malaysian Act these are the access and correction rights and the right to withdraw consent; under the GDPR they are Articles 15 to 21.

There is a page for it: make a data protection request. It goes to the same person and is answered within five working days.

No email address is published anywhere on this site, which is deliberate: an address in the markup is harvested and then used without consent. The form is the route in, and it reaches him directly.

You do not need to prove your identity with documents, and none should be sent. Asking for a passport scan to release a name and an email address would collect far more sensitive data than the request concerns. Writing from the address you used before is enough.

If you are unhappy with the answer, you can complain to the Personal Data Protection Department in Malaysia, or to your own supervisory authority if you are in the EU or UK.

Two things this notice does not do

It is in English only. Section 7(3) of the Malaysian Act requires a notice in both Bahasa Malaysia and English. This page is English, as is the rest of the site. That is a known gap, stated here rather than left to be discovered.

It describes this site, not everything he does. Advisory work carried out for a client is governed by the agreement with that client. This notice covers mohdatasha.com and the messages sent through it.

Changes

This notice was published on 10 August 2026. If what the site does with personal data changes, this page changes in the same commit as the code, which is the practice the colophon sets out and invites you to check.