Privacy Notice

Version: 2026-06-30 · Last updated: 2026-06-30

1. Who we are

Conveo is a beta event-management service operated by Peter Ho ("we", "us"). Contact: support@digistories.cc. This notice describes how we collect, use, disclose, store, transfer, and protect personal data, in line with Malaysia's Personal Data Protection Act 2010 (PDPA, as amended 2024) and equivalent frameworks (EU GDPR).

2. What data we collect

We process the following categories of personal data:

  • Account: your email address (required to sign in via magic link), and a timestamped record that you accepted this notice.
  • Event data you upload or enter: attendee names, emails, phone numbers, gender, age band, household/family grouping, dietary or sleep preferences (e.g., snorer/light sleeper), accessibility needs, roommate requests, volunteer skills, travel details, and any custom registration-form answers.
  • Technical: IP address and user agent at the moment of consent (audit log only); standard server logs.
  • Analytics: privacy-friendly, cookieless product analytics (aggregate page views and page-performance metrics only) — no cookies, no cross-site tracking, and no personal data.

3. Purposes of processing

We process personal data solely to provide the service you have asked for:

  • Authenticate you and keep your session.
  • Store, display, and let you manage the event data you upload.
  • Run the matching algorithms you trigger (room allocation, small groups, volunteer teams, car-pool matching).
  • Send transactional emails relating to your use of the service.
  • Maintain an audit trail of consent and material actions.

4. Sensitive personal data

Some event data may constitute "sensitive personal data" under PDPA — for example data revealing religious belief (e.g., a church camp roster) or health-adjacent information (snoring, dietary/medical needs). By uploading such data you confirm that you have the explicit consent of each data subject to share it with us for the purposes above. Do not upload sensitive personal data without that consent.

5. Third parties and cross-border transfer

We use the following classes of processors. Your data is transferred to and stored in the regions indicated. Specific subprocessor names are available on written request (see §11). By accepting this notice you consent to these transfers.

Processor (class)Role · RegionPurpose
Managed Postgres providerDatabase · SingaporeStores all event data you enter.
Cloud hosting providerApplication hosting · Asia (Singapore edge)Runs this web app and serves pages to your browser.
Transactional email providerEmail delivery · United StatesSends the magic-link sign-in email.
AI inference providerAI column-mapping (optional) · ChinaWhen you click "Suggest with AI", spreadsheet column headers (not row data) are sent to suggest a mapping. Disabled by default — admin opt-in.

6. Disclosure

We do not sell personal data and do not share it with any party other than the processors listed above. We may disclose data when compelled by law or to protect the safety of users.

7. Your rights

Under PDPA you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate or incomplete data.
  • Withdraw your consent at any time (note: withdrawing consent will end your access to the service).
  • Delete your account and all associated event data yourself, at any time, from your dashboard — or ask us to.
  • Receive a copy of your data in a portable format.
  • Lodge a complaint with the Personal Data Protection Commissioner of Malaysia.

8. Retention

Event data is kept as long as the event exists in your dashboard. You can delete an event at any time, which removes all its associated data immediately. Deleting your account (from the dashboard) immediately removes your account, the organisations you own and all their event data, except records we are required to retain by law (e.g., the consent log, which is keyed to your email, not your account).

9. Security

Data is transmitted over TLS and stored encrypted at rest by our infrastructure providers. Access is gated by magic-link authentication. We do not log or persist passwords. No system is perfectly secure; please contact us immediately if you suspect unauthorised access to your account.

10. Data breaches

If we become aware of a personal data breach that is likely to result in significant harm, we will notify the Personal Data Protection Commissioner within 72 hours and notify affected users without undue delay, as required by the PDPA 2024 amendments.

11. Contact

For access, correction, deletion, or any privacy question, email support@digistories.cc.