السَّلَامُ عَلَيْكُمْ · As-salāmu ʿalaykum Salam sejahtera Sat sri akaal नमस्ते آداب Hello, friend

Legal

Privacy notice

How I collect, use, and protect personal data on this site. PDPA 2010 (as amended in 2024) is the primary regime; GDPR applies as a cross-reference for visitors in the EEA and UK.

Last updated: 3 May 2026

1. Data controller

Name: Hamdan Akram. Email: mail@hamdanakram.com. Role: data controller for this personal website. For data processed by the companies I work for or own, that company is the controller; refer to its own notice.

2. What I collect

When you submit the Coffee with Hamdan Akram form: full name, email, mobile if provided, country and city, role, organisation, LinkedIn URL, how you found me, topic, what you hope to walk away with, format and duration preference, optional reading link, and your consent choices.

When you subscribe to the newsletter: email address and your opt-in record.

When you browse the site: IP address, browser, device, pages visited, referrer, and approximate location, only where you have given consent through the cookie banner.

3. Why I use it

Scheduling and conducting meetings (consent / legitimate interests). Sending the newsletter (consent). Operating and securing the website (legitimate interests). Measuring traffic to improve content (consent). Complying with legal obligations.

4. Who I share it with

Service providers acting as processors under written agreement: hosting and CDN provider, email provider, calendar provider, form and booking provider, newsletter platform, analytics provider, captcha provider. A current list is available on request from mail@hamdanakram.com. I do not sell personal data, and I do not share it with marketers.

5. Cross-border transfer

Some providers store data outside Malaysia, including the United States and the European Union. Transfers are made under contractual safeguards and, where relevant, the EU Standard Contractual Clauses 2021. Section 129 of the PDPA, as amended, has been considered in selecting providers.

6. Retention

Coffee with Hamdan Akram submissions: 12 months. Newsletter records: until you unsubscribe, plus 24 months for proof of consent. Web analytics: aggregated, 26 months. Cookie consent records: 12 months, then re-prompted.

7. Your rights

You may ask me to confirm and provide a copy of data I hold about you, correct inaccurate data, delete data subject to legal retention, restrict or object to processing, withdraw consent, or request portability where technically feasible. Send requests to mail@hamdanakram.com. I will reply within 21 days.

8. Complaints

If you believe your personal data has been mishandled, contact the Department of Personal Data Protection (JPDP), Malaysia, www.pdp.gov.my. If you are based in the EU or UK, you may contact your local supervisory authority.

9. Security

I follow ISO 27001 and NIST CSF aligned controls, including encryption in transit and at rest where supported by the provider, role-based access, multi-factor authentication, and quarterly access-log review. Suspected vulnerabilities should be reported under the disclosure programme at /.well-known/security.txt.

10. Children

This site is not directed at persons under 13. I do not knowingly collect data from children. If you believe a child has submitted data, contact me and I will delete it.

11. Changes

I will date material changes at the top of this notice and, for active newsletter subscribers, send a heads-up before the change takes effect.