PRIVACY POLICY
1. Introduction
This Privacy Policy explains how Persatuan Jururawat Infusi Malaysia, also known as Infusion Nurses Society Malaysia (INSM), collects, processes, uses, stores, protects, and discloses personal data obtained through this Website and through INSM’s online forms, membership services, event registration, training activities, publication sales, enquiry channels, and payment processes.
INSM respects the privacy of members, participants, customers, healthcare professionals, website users, speakers, trainers, facilitators, partners, sponsors, and other persons who interact with INSM. This Privacy Policy is prepared with reference to the Personal Data Protection Act 2010 of Malaysia and applicable personal data protection requirements.
2. Consent and Acceptance
By accessing the Website, submitting personal data, registering an account, applying for membership, registering for an event, purchasing any item, communicating with INSM, or making payment, you acknowledge that you have read and understood this Privacy Policy and consent to the collection, processing, use, storage, and disclosure of your personal data in accordance with this Privacy Policy.
Where you provide personal data relating to another person, you confirm that you have obtained that person’s consent or have lawful authority to provide the personal data to INSM.
3. Personal Data We May Collect
Depending on your interaction with INSM, we may collect the following categories of personal data:
· Identity data: name, title, gender, nationality, identification or professional registration details where required for membership, certification, attendance, verification, or official records.
· Contact data: email address, mobile number, postal address, workplace address, billing details, and communication preferences.
· Professional data: occupation, employer, department/unit, professional role, clinical area, membership category, professional interest, training needs, attendance records, competence assessment records, and continuing professional development information where applicable.
· Account data: username, password or authentication data, account preferences, membership status, and account history.
· Transaction data: order details, event registration details, payment amount, payment status, invoice or receipt details, payment reference, refund record, and purchase history.
· Communication data: enquiries, feedback, complaints, survey responses, email correspondence, WhatsApp or other messaging records, and support requests.
· Technical data: IP address, browser type, device information, website usage data, cookies, page interactions, log data, and security-related technical records.
· Media data: photographs, videos, testimonials, recordings, or images captured during INSM events only where applicable and subject to the event’s stated notice or consent arrangement.
4. How We Collect Personal Data
We may collect personal data from the following sources:
· directly from you when you complete forms, register for membership, register for events, make payment, purchase publications, contact INSM, subscribe to updates, respond to surveys, or participate in activities;
· from your authorised representative, employer, institution, sponsor, or organisation where they register or communicate on your behalf;
· from payment gateways, banks, card issuers, e-wallet providers, or other transaction processors involved in completing or verifying payment;
· from event platforms, webinar platforms, learning platforms, website hosting systems, email systems, analytics tools, or IT service providers used by INSM;
· from publicly available professional sources, directories, or official records where relevant to INSM’s legitimate professional or administrative purposes.
5. Purposes for Processing Personal Data
· to create, process, verify, approve, maintain, and renew membership records;
· to process registration for webinars, seminars, conferences, workshops, training programmes, certification-related activities, and other INSM events;
· to process payments, invoices, receipts, refunds, duplicate payment checks, and transaction records;
· to deliver publications, guidelines, digital resources, event materials, certificates, attendance records, or related services;
· to communicate with you regarding membership, events, purchases, payment status, refunds, enquiries, complaints, updates, reminders, or administrative matters;
· to verify eligibility, attendance, assessment completion, certificate entitlement, or professional participation where applicable;
· to manage INSM’s website, member services, event operations, training records, secretariat administration, council reporting, accounting, audit, and governance requirements;
· to improve INSM’s services, education programmes, website functionality, user experience, and professional activities;
· to send newsletters, event announcements, professional updates, marketing communications, or promotional materials where permitted by law and subject to your communication preferences;
· to comply with legal, regulatory, tax, audit, governance, law enforcement, dispute resolution, and record-keeping obligations;
· to protect the security, integrity, and lawful operation of the Website, payment process, INSM systems, INSM materials, and INSM events.
6. Payment Information
Online payments on the Website are processed through senangPay-DOKU or another third-party payment processor appointed by INSM. INSM may receive transaction details such as payment reference, payment amount, payment status, payer name, payer contact details, and confirmation records necessary to verify and manage the transaction.
INSM does not store your full credit card or debit card details on its own Website system. Card, banking, FPX, e-wallet, and other payment credentials are processed by the relevant Payment Gateway, bank, card issuer, or payment provider according to their own security standards, privacy notices, and terms of service.
7. Disclosure of Personal Data
INSM may disclose personal data only where necessary and appropriate, including to:
· INSM council members, authorised committee members, secretariat personnel, volunteers, trainers, facilitators, examiners, event organisers, and administrative personnel who require the information for authorised INSM purposes;
· payment gateways, banks, card issuers, e-wallet providers, accounting providers, auditors, and financial service providers involved in payment, refund, invoicing, accounting, or compliance matters;
· website developers, hosting providers, IT support providers, email service providers, event platforms, webinar platforms, cloud service providers, analytics providers, and other service providers engaged by INSM;
· courier or delivery providers where physical publications or materials are delivered;
· professional bodies, partner organisations, sponsors, venues, institutions, or agencies involved in an event, training programme, certification-related activity, or professional collaboration, but only where relevant and necessary;
· government authorities, regulators, law enforcement agencies, courts, professional bodies, or other parties where required or permitted by law;
· any other party with your consent or where disclosure is necessary to protect INSM’s legal rights, safety, security, reputation, property, or legitimate interests.
8. Cross-Border Processing and Cloud Services
INSM may use digital platforms, cloud hosting, email systems, payment gateways, webinar systems, analytics tools, or other service providers that process or store data inside or outside Malaysia. Where personal data is transferred or accessed outside Malaysia, INSM will take reasonable steps to ensure that the personal data is protected in accordance with applicable requirements and contractual safeguards where appropriate.
9. Cookies and Website Analytics
The Website may use cookies, tracking technologies, analytics tools, and server logs to support website functionality, user experience, security, traffic analysis, account access, cart functions, payment flow, and service improvement. You may adjust your browser settings to refuse or delete cookies, but some Website features may not function properly if cookies are disabled.
10. Marketing and Professional Updates
INSM may use your contact details to send professional updates, event notices, membership notices, training announcements, newsletters, or related communications. You may request to stop receiving marketing or promotional communications by contacting INSM or using any unsubscribe method provided, where available. INSM may still send administrative, transactional, payment, membership, event, or service-related communications where necessary.
11. Retention of Personal Data
INSM will retain personal data for as long as necessary to fulfil the purposes stated in this Privacy Policy, including membership administration, event records, certification and attendance verification, accounting, audit, tax, legal, governance, dispute resolution, fraud prevention, and regulatory requirements.
When personal data is no longer required, INSM will take reasonable steps to delete, anonymise, archive, or securely dispose of the data, subject to applicable legal, administrative, and operational requirements.
12. Security of Personal Data
INSM takes reasonable administrative, technical, and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration, disclosure, or destruction. These measures may include access controls, password protection, secure payment processing, limited internal access, service provider controls, and reasonable website security practices.
However, no website, email system, online payment process, or internet transmission can be guaranteed to be completely secure. Users are responsible for protecting their own account credentials, devices, email accounts, and internet connection.
13. Access, Correction, Withdrawal, and Enquiries
You may request access to your personal data, correction of inaccurate personal data, withdrawal of consent where applicable, limitation of processing where permitted by law, or cessation of direct marketing communications by contacting INSM.
INSM may require verification of your identity before processing a request. INSM may refuse or limit a request where permitted by law, where the request is incomplete, where the request affects another person’s rights, or where retention is necessary for legal, governance, accounting, certification, dispute resolution, or legitimate administrative purposes.
14. Accuracy of Personal Data
You are responsible for ensuring that the personal data you provide to INSM is accurate, complete, and up to date. If your details change, you should update your account or contact INSM. Failure to provide accurate information may affect INSM’s ability to process membership, event registration, payment, certificate issuance, publication delivery, or enquiries.
15. Third-Party Websites and Payment Gateway Policies
The Website may contain links to third-party websites, payment gateways, event platforms, sponsors, partners, journals, resources, or external services. INSM is not responsible for the privacy practices, security, or content of third-party websites or services. You should review the relevant third party’s privacy notice and terms before using their services.
16. Children and Minors
The Website and INSM’s professional activities are primarily intended for healthcare professionals, members, adult learners, institutional representatives, and professional participants. INSM does not knowingly collect personal data from children for general website use. Where any minor participates in an approved activity, personal data should be provided only with appropriate parental, guardian, institutional, or lawful consent where required.
17. Updates to This Privacy Policy
INSM may update this Privacy Policy from time to time. The latest version will be published on the Website with the effective date. Continued use of the Website or INSM services after publication of the updated Privacy Policy means that you acknowledge the updated Privacy Policy.
18. Contact for Privacy Matters
For privacy enquiries, access requests, correction requests, withdrawal requests, complaints, or questions about this Privacy Policy, please contact:
Persatuan Jururawat Infusi Malaysia / Infusion Nurses Society Malaysia (INSM)
Suite 2-18, No. 16-C, Jalan Suarasa 8/4, Bandar Tun Hussein Onn, 43200 Cheras, Selangor, Malaysia
Email: insofmalaysia@gmail.com
Website: https://insmalaysia.org
Please state clearly in your email subject whether your message is a “Privacy Request”, “Correction Request”, “Withdrawal Request”, or “Privacy Complaint”.
Who we are
Our website address is: https://www.insmalaysia.org/.
Comments
When visitors leave comments on the site we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection.
An anonymized string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment.
Media
If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.
Cookies
If you leave a comment on our site you may opt-in to saving your name, email address and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year.
If you visit our login page, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.
When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select “Remember Me”, your login will persist for two weeks. If you log out of your account, the login cookies will be removed.
If you edit or publish an article, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.
Embedded content from other websites
Articles on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.
These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website.
Who we share your data with
If you request a password reset, your IP address will be included in the reset email.
How long we retain your data
If you leave a comment, the comment and its metadata are retained indefinitely. This is so we can recognize and approve any follow-up comments automatically instead of holding them in a moderation queue.
For users that register on our website (if any), we also store the personal information they provide in their user profile. All users can see, edit, or delete their personal information at any time (except they cannot change their username). Website administrators can also see and edit that information.
What rights you have over your data
If you have an account on this site, or have left comments, you can request to receive an exported file of the personal data we hold about you, including any data you have provided to us. You can also request that we erase any personal data we hold about you. This does not include any data we are obliged to keep for administrative, legal, or security purposes.
Where your data is sent
Visitor comments may be checked through an automated spam detection service.