Privacy Policy
Last updated: 29 June 2026
This Privacy Policy explains how TED Learning Sdn Bhd ("TED Learning", "we", "us", or "our") collects, uses, discloses, stores, and protects personal data when you use our web application at https://webapp.ted.com.my/, including the Staff portal (/u), Trainers portal (/t), public pages (/public), class pages, forms, APIs, notifications, attendance, evaluations, claims, grants, certificates, document viewing, and related services (the "Service").
This policy is intended to support our compliance with applicable Malaysian personal data protection requirements, including the Personal Data Protection Act 2010, where applicable.
1. Who This Policy Applies To
This Policy applies to personal data we process about:
- Staff and internal users who use the Staff portal to manage classes, courses, orders, inquiries, claims, tasks, trainers, grants, certificates, evaluations, reports, documents, and related workflows.
- Trainers who use the Trainers portal to view or manage assigned classes, schedules, attendance, evaluations, reminders, and related trainer records.
- Clients, HR representatives, vendors, and business contacts who communicate with us, submit inquiries, participate in order or vendor workflows, or interact with public pages.
- Course participants who register for, attend, evaluate, or receive communications about training programs.
- Public users who access public links, QR attendance pages, questionnaires, evaluations, vendor order pages, document views, or other public-facing pages.
2. Personal Data We Collect
The personal data we collect depends on your role and how you use the Service.
2.1 Account, Profile, and Contact Data
We may collect:
- Name, contact name, display name, designation, company, department, and role.
- Email address, phone number, mobile number, and other business contact details.
- Account identifiers, contact IDs, UUIDs, password hashes, session identifiers, and login-related records.
- Profile photo or related profile image files where uploaded or displayed in the Service.
2.2 Training, Class, and Participant Data
We may collect:
- Course, class, trainer, schedule, venue, attendance, QR attendance, passcode, and registration records.
- Participant name, designation, company, email address, phone number, NRIC or identification number, and other information required for class administration.
- Evaluation responses, questionnaire answers, comments, ratings, signatures, certificates, and certificate delivery records.
- HRD Corp grant-related details and supporting records where required for training grant processing or documentation.
2.3 Staff, Trainer, Claim, Order, and Finance-Related Data
We may collect:
- Claim records, reimbursement details, receipts, attachments, payment status, and related approval records.
- Bank account details where required for staff or trainer reimbursement or claim processing.
- Vendor, order, invoice, receipt, attachment, comment, acceptance, completion, and document workflow records.
2.4 Sensitive or Higher-Risk Data
Where necessary for legitimate business, legal, HRD Corp, reimbursement, or training administration purposes, we may process sensitive or higher-risk data such as:
- NRIC, identification, or passport information.
- Bank account details for claims or reimbursements.
- Gender, race, ethnicity, or similar information where required for grant, registration, reporting, or documentation purposes.
- Signatures, attendance records, evaluation records, and uploaded supporting documents.
We only collect this information where it is necessary for the relevant purpose or where you provide it to us through the Service.
2.5 Technical, Security, and Usage Data
We may collect:
- IP address, browser type, device or operating system information, page access, request metadata, and error logs.
- Login status, session cookies, authentication tokens, and security validation records.
- Records of create, read, update, delete, export, approval, submission, download, email, notification, and other user actions.
- System logs used for troubleshooting, security, audit, support, and operational monitoring.
2.6 Location Data
We may process training venue addresses and class location details. We do not intentionally collect GPS or precise mobile location data through the Service unless a specific feature clearly requires it and you provide it.
3. How We Collect Personal Data
We collect personal data when:
- You create or use an account, log in, set up a password, or update your profile.
- You submit forms, inquiries, registrations, claims, comments, evaluations, questionnaire responses, or attachments.
- Staff or trainers create or manage records relating to courses, classes, participants, vendors, grants, certificates, orders, or claims.
- You scan or access a QR code, public class page, evaluation link, document link, vendor order link, or notification link.
- We send, receive, or process email, SMS, in-app notifications, calendar files, certificates, documents, reports, or reminders.
- Our systems automatically generate logs, cookies, session records, and security records.
We may also receive personal data from your employer, HR representative, client organization, trainer, vendor, or other authorized representative where they provide information for training, administration, grant, order, or communication purposes.
4. Why We Use Personal Data
We use personal data to:
- Provide, operate, secure, maintain, and improve the Service.
- Authenticate users and manage account access for staff, trainers, and authorized users.
- Manage courses, classes, schedules, trainers, participants, attendance, certificates, evaluations, summaries, and reports.
- Process inquiries, registrations, vendor orders, comments, claims, receipts, reimbursements, grants, and supporting documents.
- Send operational communications, including class information, reminders, certificates, calendar invites, SMS notifications, email notifications, and in-app alerts.
- Generate documents, reports, PDFs, spreadsheets, summaries, certificates, and downloadable files.
- Troubleshoot errors, investigate issues, monitor performance, prevent misuse, and maintain audit logs.
- Meet legal, regulatory, HRD Corp, accounting, tax, audit, contractual, and internal governance requirements.
- Respond to requests, complaints, disputes, lawful instructions, or enforcement requirements.
We do not sell personal data.
5. Artificial Intelligence and Automated Processing
The Service may use AI-assisted tools, including Google Gemini or similar services, to help summarize evaluation comments, training feedback, or class-related text.
Where practical, we avoid sending direct personal identifiers to AI tools for summary generation. AI-generated summaries are used to support administrative review and reporting, not to make fully automated decisions that produce legal or similarly significant effects on individuals.
6. Cookies and Similar Technologies
The Service uses cookies and similar browser storage for:
- Login sessions and authentication.
- Remembering basic user information needed by the application, such as account or display details.
- Maintaining form state, public page access, or short-term preferences.
- Security, request validation, and application functionality.
Some public-user cookies or temporary form-related values may be kept only for a short period, while login-related cookies may remain for the period needed to support the user session or application workflow.
You may disable cookies in your browser, but doing so may prevent login, form pre-fill, public workflows, or other Service features from working correctly.
7. When We Share Personal Data
We may share personal data only where necessary and appropriate, including with:
- Service providers and processors that support hosting, databases, backups, email, SMS, document generation, file storage, QR code functions, reporting, or technical operations.
- SMS and communication providers, such as 360.my / SMS Guru Sdn Bhd, where needed to send operational SMS notifications.
- AI or text-processing service providers, such as Google Gemini, where used for evaluation or comment summarization and subject to the safeguards described above.
- Clients, employers, HR representatives, trainers, vendors, or participants where disclosure is necessary for training delivery, attendance, evaluation, order, grant, certificate, or administrative purposes.
- Regulators, authorities, auditors, legal advisers, or enforcement bodies where required by law, regulation, contract, audit, dispute resolution, or lawful request.
- Successors or transaction parties in connection with a merger, restructuring, acquisition, financing, sale of assets, or similar business transaction, subject to appropriate safeguards.
We do not rent or sell personal data to third parties.
8. Data Storage and Transfers
Our primary systems, web application, database, and operational records are intended to be hosted and managed in Malaysia or through service providers supporting our Malaysian operations.
Some service providers may process data using infrastructure outside Malaysia or may access data from another country. Where cross-border processing is necessary, we take reasonable steps to ensure appropriate safeguards are applied and that the transfer is consistent with applicable legal requirements.
9. Data Retention
We retain personal data for as long as reasonably necessary for the purposes described in this Policy, including to provide the Service, maintain records, comply with legal or regulatory obligations, support HRD Corp or training documentation, resolve disputes, enforce agreements, maintain audit logs, and protect our systems.
Different records may have different retention periods. For example:
- Account, training, class, certificate, grant, claim, order, receipt, and attendance records may be retained for business, audit, legal, and compliance purposes.
- Technical logs may be retained for security, troubleshooting, audit, and operational needs.
- Temporary files, generated documents, cached files, and public workflow records may be deleted or replaced according to operational schedules.
Where deletion is requested, we may delete, anonymize, restrict, or disable records where appropriate. Some records may be retained where required for legal, audit, accounting, contractual, security, or legitimate business purposes.
10. Security
We use administrative, technical, and operational safeguards designed to protect personal data, including:
- HTTPS for web application access.
- Session handling, token validation, and server-side request checks.
- Password hashing for account passwords.
- Role-based or portal-based access controls.
- Database access controls and protected server configuration.
- System logs and audit records for selected user and application actions.
- Backup and operational controls for continuity and recovery.
No internet-based system can be guaranteed to be completely secure. You are responsible for keeping your login details confidential and for notifying us promptly if you believe your account or data has been accessed without authorization.
11. Your Rights and Choices
Subject to applicable law and verification of your identity, you may request to:
- Access personal data that we hold about you.
- Correct or update inaccurate, incomplete, or outdated personal data.
- Withdraw consent where processing is based on consent.
- Object to or restrict certain processing where applicable.
- Request deletion, deactivation, or anonymization of personal data, subject to legal, audit, contractual, security, and operational retention requirements.
- Ask questions or make a complaint about how we handle personal data.
To make a request, contact us using the details in the Contact Us section below. We may need to verify your identity and may ask for additional information to process your request.
12. Data Provided by Employers, Clients, or Representatives
If your employer, client organization, HR representative, trainer, or another authorized person provides your personal data to us, that person or organization is responsible for ensuring they have the authority to provide it and, where required, that you have been informed of the disclosure.
If you provide personal data about another person through the Service, you confirm that you are authorized to do so and that the information is accurate to the best of your knowledge.
13. Children's Privacy
The Service is intended for business, professional training, staff, trainer, vendor, client, and course administration use. It is not intended for children under 18. We do not knowingly collect personal data from children under 18 unless it is provided by an authorized parent, guardian, employer, institution, or representative for a lawful and necessary purpose.
14. Links to Other Websites or Documents
The Service may contain links to external websites, documents, attachments, email addresses, maps, forms, or third-party resources. We are not responsible for the privacy practices, content, security, or availability of third-party websites or services.
15. Changes to This Policy
We may update this Privacy Policy from time to time. The updated version will be posted on this page with a revised "Last updated" date. Continued use of the Service after an update means you acknowledge the updated Policy.
16. Contact Us
If you have questions, requests, or complaints about this Privacy Policy or our handling of personal data, please contact:
TED Learning Sdn Bhd
12-07, Binjai 8 Premium SOHO
No. 2, Lorong Binjai
50450 Kuala Lumpur, Malaysia
Email: privacy@ted.com.my
Phone: +60 3 2742 1829
Website: https://www.ted.com.my/