Legal
Privacy Policy
How AnnexHub collects, uses and protects personal data, whether you run events on AnnexHub, register or check in to one, or just visit this site.
Effective
1. Who we are and what this policy covers
AnnexHub is run by Annex Creative Solutions (M) Sdn. Bhd. (company no. 202301005655 (1499574-X)), a company registered in Malaysia. In this policy “AnnexHub”, “we” and “us” mean that company.
This policy explains how we handle personal data when you use AnnexHub as an event organiser, when you register for or check in to an event that runs on AnnexHub, and when you visit annexhub.ai. It is written to meet the Personal Data Protection Act 2010 of Malaysia (PDPA). If the GDPR or UK GDPR applies to you, the rights in section 9 cover those laws too.
We play two different roles, and it matters which one applies to you:
- Organisers and visitors. For your account, billing and your use of this site, we decide how your data is used. We are the data controller (the “data user” in PDPA terms).
- Attendees. When an organiser collects your details through a registration page, ticket or check-in on AnnexHub, the organiser decides what is collected and why. The organiser is the controller and we process the data on their instructions. Contact the organiser first with any request about your data; we help them respond.
2. What we collect
Organiser accounts. First and last name, email address, organisation, an optional phone number, your time zone, plan and billing status, and your password, which we store only as a one-way hash. If you sign in with Google we receive your Google account identifier, name, email and profile picture as Google supplies them. We never see your Google password.
Billing. Our payment processor handles payment. We keep the customer reference it gives us, your plan, invoice status and amounts. Card numbers never reach our servers.
Attendee records (as processor). Whatever the organiser’s registration form asks for. Typically a name, email, phone number and organisation, plus any custom fields the organiser adds such as dietary needs or T-shirt size. We also hold each attendee’s ticket, payment status for paid tickets, and check-in scans: the time, the scan point and which staff account scanned.
Paid tickets. Attendees pay on our payment processor’s hosted checkout page. We receive the transaction reference, amount and status. Card details stay with the payment processor.
Technical data. IP address, browser and device type, timestamps and error reports. We use these for security (rate limiting, bot protection), to keep the service running and to fix bugs.
Support and sales. What you send us by email, through the quote form, or on WhatsApp. If you message us on WhatsApp, Meta’s own terms apply to that conversation.
3. Why we use it
- To run AnnexHub for you: creating your account, hosting your events, sending tickets, running check-in, showing you your attendee data. Basis: performing our contract with you.
- To bill you and keep the financial records the law requires. Basis: contract and legal obligation.
- To keep the service secure: telling humans from bots on sign-up, rate limiting, spotting fraud and abuse. Basis: our legitimate interest in protecting the service and its users.
- To send service email: email verification, ticket delivery, password resets, receipts and notices about changes to these terms. You cannot opt out of these while you hold an account.
- To tell account holders about product changes, occasionally. Every such email has an unsubscribe link, and you can also opt out by emailing us.
- To comply with the law, for example tax record-keeping or a lawful request from an authority.
We do not sell personal data, and we do not use it for advertising.
4. Who we share it with
These types of provider process data for us. Each is bound by a contract that limits what it may do with the data.
| Type of provider | What it does for AnnexHub | Where data is processed |
|---|---|---|
| Database and file storage | Holds everything stored in AnnexHub | Singapore |
| Web hosting and API compute | Serves annexhub.ai and runs the AnnexHub API | API in Singapore; static pages served from a worldwide edge network |
| Payment processing | Card payments for subscriptions, event passes and paid tickets | United States, with regional entities |
| Transactional email delivery | Verification, tickets, receipts, password resets | United States |
| Sign in with Google | Only if you choose it | United States |
| Bot protection and DNS | Tells humans from bots on the sign-up form; DNS for our domains | Worldwide edge network |
| Error monitoring | Crash and error reports, configured not to collect personal data | United States |
| Internal team alerts | Tells our own team when a new account is created (name, email, organisation) | United States |
We do not publish provider names on this page. A customer who needs the current list for a vendor assessment can request it from support@annexcs.com; we share it under confidentiality.
Beyond those providers, we share personal data only with professional advisers under confidentiality, with authorities where the law requires it, or with a buyer if the business is sold, in which case we tell you first.
Within AnnexHub, organisers see the attendee data for their own events, and event staff who are given a scanner link see the attendee list for that one event.
5. Where data is stored and international transfers
Your data lives in Singapore. Some providers in the table above process data in the United States or on a worldwide network. Where data leaves Malaysia we rely on contracts that require the provider to protect it to a standard at least equal to this policy, together with the provider’s own security certifications. Where the GDPR applies, transfers are covered by the European Commission’s standard contractual clauses.
6. How long we keep it
- Organiser accounts: for as long as the account is open. After a verified deletion request we delete or anonymise the account within 30 days, except billing and tax records, which Malaysian law requires us to keep for seven years, and anything needed to deal with a legal claim.
- Attendee data: for as long as the organiser keeps the event. Organisers can delete individual attendees or an entire event at any time. When an organiser closes their account, their events and attendee data go with it on the schedule above.
- Check-in logs stay with the event. They are the audit trail for who was let in and when.
- Backups expire on a rolling schedule within 30 days.
- Technical logs are kept for up to 90 days.
7. How we protect it
Traffic is encrypted in transit with TLS, and our hosting providers encrypt data at rest. Passwords are hashed. Access is role-based (organiser, staff, administrator), scanner links are scoped to a single event, and every change to a check-in is logged. Databases are backed up daily. If a data breach affects you, we notify the Personal Data Protection Commissioner and the people affected as the PDPA requires.
8. Cookies and browser storage
We do not use advertising cookies or third-party analytics trackers on annexhub.ai.
What we do store in your browser:
- Sign-in tokens, so you stay signed in between visits. Clearing your browser storage signs you out.
- Your language and display preferences.
- On the staff scanner, a queue of check-in scans made while offline, so the door keeps working without signal. It syncs when the connection returns.
Third parties may set their own cookies where you meet them: the bot-protection check on the sign-up page, the payment processor on its checkout and billing pages, and Google if you use Sign in with Google.
9. Your rights
Under the PDPA you can ask us to give you access to your personal data, correct it, limit how we process it, stop using it for direct marketing, and provide a copy in a portable format. You can also withdraw consent you have given, without affecting anything done before you withdrew it. If the GDPR or UK GDPR applies to you, you also have the rights to erasure, restriction and objection, and to complain to your local supervisory authority.
To make a request, email support@annexcs.com from the address on your account. We may ask you to confirm your identity. We respond within 21 days, as the PDPA requires.
If you are an attendee, your organiser is the controller of your data, so please contact them first. If you cannot reach them, contact us and we will help.
Organisers can export their attendee data to CSV from the event dashboard at any time.
You can complain to the Personal Data Protection Department of Malaysia at pdp.gov.my.
10. Children
AnnexHub accounts are for people aged 18 or over acting for a business or organisation. Organisers who run events for minors are responsible for obtaining any parental consent their event requires.
11. Changes to this policy
We post changes on this page with a new effective date. If a change is material, we email account holders at least 14 days before it takes effect.
12. Contact
Annex Creative Solutions (M) Sdn. Bhd.
Company no. 202301005655 (1499574-X)
1-13-08, Prima U1, Jalan Kerjaya, Seksyen U1, 40150 Shah Alam, Selangor, Malaysia
Email: support@annexcs.com
See also our Terms of Service.
