Legal
Privacy Policy
Last updated: 20 June 2025
1. Introduction
Tensorloom ("we", "us", "our") is committed to handling personal data responsibly. This Privacy Policy describes what personal data we collect from visitors to our website and from people who enrol in our courses, how we use it, and the rights available to you under Malaysian law and, where applicable, international data protection principles.
This policy applies to the website at tensorl.blog and to all Tensorloom online courses. If you have questions about this policy, contact us at [email protected].
2. Data we collect and how we collect it
We collect the following categories of personal data:
- Contact enquiry data: Name, email address, and optionally phone number, submitted through the contact form on our website.
- Enrolment data: Name, email address, and payment records submitted when enrolling in a course.
- Course participation data: Exercise submissions, project files, and feedback you share during a course.
- Technical data: IP address, browser type, and pages visited, collected automatically through standard web server logs and analytics tools.
- Cookie data: Preferences stored in your browser's local storage. See Section 6 and our Cookie Policy for detail.
We collect personal data when you submit a contact form, when you enrol in a course, and automatically when you browse our website.
3. Legal basis for processing
We process personal data on the following bases under Malaysia's Personal Data Protection Act 2010 (PDPA):
- Contract performance: Processing necessary to deliver the course you have enrolled in.
- Legitimate interest: Responding to enquiries, maintaining website security, and improving our services.
- Consent: Sending optional email updates about future courses or events, which you may withdraw at any time.
4. How we use personal data
- To respond to enquiries submitted through the contact form.
- To process course enrolments and deliver course materials.
- To send administrative communications related to an enrolled course (session times, recordings, feedback).
- To improve the website and course content based on aggregate usage patterns.
- To meet our legal and accounting obligations as a registered business in Malaysia.
We do not use personal data to send unsolicited marketing unless you have specifically consented. We do not sell personal data to third parties or share it for third-party marketing purposes.
5. Data retention
We retain personal data for as long as it is needed for the purpose collected:
- Contact enquiry data: up to 12 months from last contact, unless an enrolment follows.
- Enrolment and payment records: 7 years, as required for accounting and tax records under Malaysian law.
- Course participation data (exercise submissions, project files): retained for the duration of the course plus 6 months.
- Technical and analytics data: retained in aggregate, anonymised form for up to 24 months.
6. Cookies
We use cookies and browser local storage to store your cookie consent preference. Analytics cookies may be set if you have accepted them. See our Cookie Policy for the full list of cookies used, their purpose, and how to manage your preferences.
7. Data sharing and third-party services
We share personal data only where necessary:
- Payment processors: Payment card data is handled by our payment provider and is not stored on our servers.
- Email service provider: Used to send course communications. Your email address is provided to the service for this purpose.
- Analytics: We may use analytics tools that collect anonymised usage data. We do not share identifiable personal data with analytics providers.
- Legal requirements: We may disclose personal data to authorities if required to do so by Malaysian law.
We do not transfer personal data outside Malaysia except where your email or payment processor operates international infrastructure, in which case appropriate contractual safeguards are in place.
8. Data protection measures
- Our website is served over HTTPS. Data in transit is encrypted.
- Access to personal data is restricted to staff who need it for their role.
- Payment card data is not stored by Tensorloom.
- In the event of a data breach that is likely to affect you, we will notify you within a reasonable timeframe.
9. Your rights under the PDPA (Malaysia)
Under Malaysia's Personal Data Protection Act 2010, you have the right to:
- Access personal data we hold about you.
- Correct inaccurate or incomplete personal data.
- Withdraw consent for processing where consent is the legal basis (this does not affect lawfulness of processing before withdrawal).
- Request that we stop processing your personal data for direct marketing purposes.
- Lodge a complaint with the Personal Data Protection Department of Malaysia if you believe your rights have not been respected.
To exercise any of these rights, email [email protected] with your name and the specific request. We will respond within 21 days.
10. Third-party links
Our website may link to external sites (for example, documentation for tools used in course materials). We are not responsible for the privacy practices of those sites. Please review the privacy policy of any external site you visit.
11. Age restriction
Our courses are intended for adults aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe we hold data about a person under 18, please contact us at [email protected] so we can address it promptly.
12. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of the page. If the changes are material, we will notify enrolled learners by email. Continued use of the website after a policy update constitutes acceptance of the revised terms.
13. Contact
For any privacy-related question or to exercise your rights:
- Email: [email protected]
- Post: Tensorloom, 18 Persiaran APEC, 63000 Cyberjaya, Selangor, Malaysia