Privacy Notice
How Ledger & Signal handles your personal data, under the Personal Data Protection Act 2010 (Malaysia) as amended in 2024.
Who we are
Ledger & Signal is the data controller for the personal data described here. Questions, requests and complaints go to our Data Protection Officer at [email protected].
What we collect
We collect only what the service needs to function.
If you subscribe to the newsletter
- Your email address, so we can send you the newsletter
- The date, IP address and browser of your sign-up and of your confirmation click. The PDPA requires us to be able to demonstrate that you consented; the confirmation click is that evidence, and it is why we ask you to confirm before sending anything
- Which page you subscribed from, so we know which coverage people want more of
We use your address for the newsletter and nothing else. We do not sell it, rent it, or pass it to any advertiser. Every newsletter carries a one-click unsubscribe link that needs no account and no reply, and we keep a record that you unsubscribed so that a later import cannot add you back.
If you buy a ticket
- Your name and email address, so we can issue and deliver your ticket
- Your mobile number, if you choose to give it
- What you bought, when, and the amount
- The payment reference and any transfer receipt you submit, so we can match your payment to your order
We do not collect or store card numbers, CVV codes, or bank login credentials. Payment is made by DuitNow transfer directly to our bank, or through a licensed payment service provider. We never see your banking credentials.
If you create an account
- Your email address and display name
- A cryptographic hash of your password. We cannot read your password, and neither can anyone who obtains a copy of our database
- Session records, including the IP address and browser user-agent at sign-in, so you can review and revoke active sessions
If you just read the site
Nothing that identifies you. We do not use advertising trackers, and we do not sell or share reader data. Server logs record requests for security and debugging; IP addresses in those logs are truncated before storage, and email addresses are masked.
Why we use it
- To deliver what you bought. Issuing tickets, sending confirmations, admitting you at the door
- To keep accurate financial records. Malaysian tax and company law require us to retain transaction records
- To keep the platform secure. Detecting abuse, investigating incidents, and maintaining an audit trail of privileged actions
We do not use your data for automated decision-making or profiling, and we do not send marketing email unless you explicitly ask for it.
Who we disclose it to
We share personal data only with processors that make the service work:
- Our hosting and database provider, which stores the data on our behalf
- Our email provider, which receives your email address and the content of transactional messages in order to deliver them
- Our payment service provider, where one is used, which receives the information needed to process your payment
We may also disclose data where required by law, a court order, or a lawful request from a regulator. We do not sell personal data to anyone, ever.
Transfers outside Malaysia
Some of our processors operate outside Malaysia. Where that happens we rely on contractual safeguards with the processor and transfer only what the processor needs. If you want to know which processors are involved and where they are located, ask our DPO and we will tell you.
How long we keep it
- Financial and order records: seven years, as required for tax and accounting purposes
- Audit logs: seven years, so we can reconstruct who did what
- Sessions: until they expire or you revoke them
- Newsletter subscriptions: until you unsubscribe. After that we keep the address and the fact that you unsubscribed — deleting it entirely would let a later import silently add you back, which is the opposite of what you asked for. Ask us and we will erase it completely
- Account data: until you ask us to erase it, subject to the note below
Your rights
Under the PDPA you may:
- Ask for a copy of the personal data we hold about you
- Ask us to correct anything inaccurate
- Ask us to stop processing your data, or to erase it
- Withdraw consent where processing relies on it
- Ask us to transfer your data to another provider, where technically feasible
Write to [email protected]. We will respond within 21 days.
A note on erasure
When you ask us to erase your data, we anonymise your account rather than deleting the row outright. Your name, email and contact details are removed. What remains is the financial record of any transaction, stripped of anything identifying you.
We do this because accounting records must remain intact and internally consistent to satisfy tax law, and because our financial ledger is append-only by design — an entry, once written, is never edited or deleted. Erasure removes you from the record; it does not rewrite history.
Security
Traffic is encrypted in transit. Data is encrypted at rest. Passwords are hashed with Argon2id. Session tokens and API keys are stored only as hashes, so a database leak does not hand over working credentials. Access to production data is role-based, and every privileged action is written to an append-only audit log.
If something goes wrong
If a breach affecting your personal data occurs, we notify the Personal Data Protection Commissioner within 72 hours of becoming aware of it, as the PDPA requires. If the breach is likely to cause you significant harm we will also notify you directly, within 7 days.
Changes
If we change this notice we will update the date at the top. Where a change materially affects how we handle your data, we will tell affected users directly rather than relying on you to re-read this page.
Complaints
Raise it with our DPO first at [email protected]. If you are not satisfied with our response, you may complain to the Personal Data Protection Department (Jabatan Perlindungan Data Peribadi), Malaysia.