LFAI Academy
Operated by LFAI Academy Sdn Bhd
Effective date: 17 June 2026
Last updated: 17 June 2026
1. Introduction
This Privacy Policy explains how LFAI Academy Sdn Bhd (“LFAI Academy”, “we”, “us”, or “our”) collects, uses, manages, discloses, and protects your personal data when you use our website, learning platform, programmes, community channels, and related services (the “Services”).
We are headquartered in Malaysia, and our handling of personal data is governed primarily by the Personal Data Protection Act 2010 (Malaysia), as amended (“PDPA”). Because we serve learners and organisations across the Asia-Pacific region and beyond, this Policy also reflects the EU and UK General Data Protection Regulation (GDPR) and the Australian Privacy Act 1988 where they apply to you. Region-specific rights are set out in Section 14.
Note for review: Under the PDPA’s Notice and Choice Principle, your privacy notice should be made available in both Bahasa Malaysia and English. This document is the English version; a Bahasa Malaysia translation should be prepared before launch.
2. Personal Data We Collect
Depending on how you use the Services, we may collect:
- Identity and contact data — your name, email address, phone or mobile number, mailing or billing address, and password.
- Professional data — your company name and job title.
- Eligibility data — where needed to confirm you meet a programme’s requirements, your date of birth.
- Enrolment and transaction data — the programmes and courses you enrol in, your purchase and billing history, and payment information. Card payments are handled by our payment provider; we do not store full card numbers.
- Learning data — your course progress, assessment results, certificates and credentials earned, and feedback, reviews, or evaluations you submit.
- Communications data — enquiries and support requests you send us through forms, email, chat, or other channels, and your contributions in our community channels.
- Organisation data — where an employer enrols you, the contact and enrolment details they provide.
- Technical and usage data — your IP address; browser, device, and operating system type, version, and settings; details of your visits to our website, including traffic, location, and log data; and how you interact with the Services.
- Marketing preferences — your subscription status and communication choices.
- Any other information you voluntarily provide while using the Services.
We do not seek to collect sensitive personal data (such as health, religious, or biometric data) in the ordinary course of providing the Services, and will only do so with your explicit consent or where permitted by law.
3. How We Collect Personal Data
We collect personal data: (a) directly from you, when you register, enrol, communicate with us, or participate in the Services; (b) automatically, through cookies and similar technologies as you use our website and platform; and (c) from third parties, such as an employer enrolling you in a programme, or our service providers and partners.
Where we offer the option to register or sign in using a third-party account (for example, Google), and you choose to use it, we may receive certain profile information from that provider, such as your name and email address, in accordance with that provider’s settings and privacy policy. If you prefer not to share this information, please register without using a third-party login.
4. Consent
When you register for an account, enrol in a programme, or submit your details through our forms, you consent to our collecting and processing your personal data for the purposes described in this Policy, alongside the other legal bases set out in Section 6.
If you provide us with personal data about another person — for example, when an organisation enrols its employees — you confirm that you are authorised to do so and that the individual has been informed of, and where required has consented to, the processing described in this Policy.
You may withdraw your consent at any time by contacting us at support@lfaiacademy.com. Withdrawal does not affect the lawfulness of any processing carried out before withdrawal, and may mean we can no longer provide certain Services to you.
5. How We Use Personal Data
We use personal data to:
- provide, operate, and deliver the Services, including granting access to programmes and content;
- process enrolments, payments, invoicing, and accounting;
- issue, verify, and display certificates and credentials;
- communicate with you about your account, enrolments, and operational matters, and provide customer support;
- send you marketing communications where you have consented or where otherwise permitted, which you can opt out of at any time;
- understand your interests and improve the Services, content, and learning experience, including through research, reporting, and testing;
- maintain the security and integrity of the Services and resolve technical issues; and
- comply with our legal, regulatory, and accreditation obligations, and establish, exercise, or defend legal rights.
6. Legal Bases for Processing
Where the GDPR applies, we rely on the following legal bases: performance of our contract with you (to deliver programmes you enrol in); your consent (for marketing and optional cookies); our legitimate interests (to operate, secure, and improve the Services, balanced against your rights); and compliance with legal obligations. Where we rely on consent, you may withdraw it at any time.
7. Marketing and Your Choices
We may send you information about our programmes and, where relevant, those of our partners. You can opt out of marketing communications at any time using the unsubscribe link in any message, through our contact form, or by emailing support@lfaiacademy.com. Opting out of marketing does not affect operational messages necessary to deliver the Services.
8. Cookies and Analytics
We use cookies and similar technologies to operate the website, remember your preferences, and understand how the Services are used, so we can serve you better. You can manage cookies through your browser settings, and, where required, through our cookie consent tool. Disabling some cookies may affect how the Services function.
Note for review: If you deploy a cookie banner and analytics (for example, on your WordPress site), consider a short standalone Cookie Policy listing the specific cookies used. We can draft one separately.
9. How We Share Personal Data
We do not sell your personal data. We share it only as needed to operate the Services, and access within our organisation is limited to staff and authorised agents on a need-to-know basis. We may disclose personal data to:
- Service providers who process data on our behalf under appropriate safeguards, including providers of payment processing, hosting and our learning platform, data storage, email and newsletter delivery, customer relationship management, credential issuance, event hosting, messaging and community channels, analytics, error logging, and workflow automation;
- Instructors, to the extent necessary to deliver a programme you are enrolled in;
- Your employer or sponsoring organisation, where they have enrolled you, in relation to your participation and completion;
- Accreditation and certification bodies, where a programme carries external recognition;
- Our employees, contractors, and related entities; and
- Courts, regulatory authorities, law enforcement, and professional advisers, where required by law or to establish, exercise, or defend our legal rights.
Our key service providers currently include Stripe (payments), our website and platform hosting, Kit (email and newsletter), HubSpot (customer relationship management), Accredible (credentials), Luma (events), Telegram and WhatsApp (community channels), and Zapier (automation). This list may change as our Services evolve.
10. International Transfers
Some of our service providers are located outside Malaysia, so your personal data may be transferred to and processed in other countries. Under the PDPA’s revised cross-border framework, we transfer personal data outside Malaysia where the destination provides protection substantially similar to or adequate under the PDPA, or under another lawful basis or permitted exception. Where the GDPR applies, we rely on appropriate safeguards such as the European Commission’s standard contractual clauses or an adequacy decision. We take reasonable steps to ensure your data remains protected wherever it is processed.
11. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes set out in this Policy — including providing the Services, maintaining your credentials and learning records, and meeting our legal, accounting, and accreditation obligations — after which we securely delete or anonymise it. We will not keep personal data for longer than required by applicable law.
12. Data Security
We implement reasonable technical and organisational measures to protect personal data against loss, misuse, and unauthorised access, disclosure, copying, use, or modification, and we limit access to a need-to-know basis. No method of electronic transmission or storage is completely secure, so we cannot guarantee absolute security, and you are responsible for keeping your account credentials confidential.
13. Data Breach Notification
In line with the PDPA, if a personal data breach occurs, we will notify the Personal Data Protection Commissioner as soon as practicable, and within the timeframes required by the applicable guidelines. Where a breach is likely to cause significant harm, we will also notify affected individuals without undue delay. Equivalent obligations under the GDPR and other applicable laws will be met where they apply.
14. Your Rights
Subject to the law that applies to you, you have rights in relation to your personal data, which may include the right to: access the personal data we hold about you; correct inaccurate, incomplete, or out-of-date data; withdraw consent where we rely on it; object to or restrict certain processing; request that we stop processing your data for direct marketing; request data portability (to receive or transmit your data to another provider); and, in some jurisdictions, request erasure of your data.
- Malaysia (PDPA): rights of access and correction, withdrawal of consent, the right to prevent processing likely to cause damage or distress, the right to prevent direct marketing, and data portability.
- EEA / UK (GDPR): the rights above plus erasure, restriction, objection, and the right to lodge a complaint with your local supervisory authority.
- Australia (Privacy Act): rights of access and correction, and the right to complain to the Office of the Australian Information Commissioner.
To exercise any of these rights, contact us at support@lfaiacademy.com. We may need to verify your identity before responding, and we will respond within the period required by applicable law.
15. Complaints
If you believe we have handled your personal data in breach of applicable data protection law, please contact us first at support@lfaiacademy.com with full details of your concern. We will promptly investigate and respond to you in writing, setting out the outcome and the steps we will take. You may also complain to the relevant authority — in Malaysia, the Personal Data Protection Commissioner; in the EEA or UK, your local supervisory authority; and in Australia, the Office of the Australian Information Commissioner.
16. Children
The Services are intended for working professionals and are not directed at children under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can remove it.
17. Third-Party Links
The Services may link to external websites and tools that we do not operate or control. This Policy does not apply to those third parties, and we accept no responsibility for their privacy practices. We encourage you to review their privacy policies.
18. Changes to This Policy
We may amend this Policy from time to time at our discretion and subject to applicable law. The “Last updated” date shows when the latest version took effect, and we will notify you of material changes through the Services or by email. Where changes are significant, we will seek your consent again where required by law.
19. Contact Us
For any questions about this Policy or how we handle your personal data, or to exercise your rights, please contact:
LFAI Academy Sdn Bhd
Email: support@lfaiacademy.com
Website: https://www.lfaiacademy.com
Note for review: The PDPA requires a designated contact point for data protection matters, and organisations engaged in large-scale processing must appoint a Data Protection Officer (DPO) resident in Malaysia and publish a DPO contact. Consider whether LFAI Academy meets that threshold and, if so, set up and publish a dedicated address (for example, dpo@lfaiacademy.com).
This document is a template prepared to support the LFAI Academy website and does not constitute legal advice. Given the recent PDPA amendments and the multiple jurisdictions you serve, we recommend that a qualified Malaysian legal practitioner review and finalise this Policy, and that a Bahasa Malaysia version be prepared, before publication.

