Privacy Policy
Your guest list is personal. Here's exactly what we collect, why, and how we keep it safe, in plain words first and the full detail after.
Last updated: 29 September 2026
In plain words
- We collect only what's needed to run your event: organiser account details, and the RSVP details guests choose to give.
- Guest details belong to the organiser's event. Only the organiser can see them. We never sell data or market to guests.
- Guest data is deleted automatically 12 months after the event, or sooner if the organiser deletes it.
- Our data is stored in Singapore with trusted providers, protected by encryption and strict access controls.
- For business events, the organisation decides what is collected (such as IC numbers or dietary needs) and asks for your consent. We process it only to run the event.
- You can access, correct, export or delete your data. Just email info@kontiv.com.
1.Who we are
ListNama is operated by Kontiv Solutions (Registration No. 202603017630 (003813924-K)), a sole proprietorship registered in Malaysia, based in Cyberjaya, Selangor, Malaysia (“we”, “us”).
This policy explains how we handle personal data under Malaysia's Personal Data Protection Act 2010 (as amended by the Personal Data Protection (Amendment) Act 2024) (“PDPA”), and, where they apply, other data protection laws such as the EU and UK General Data Protection Regulation (“GDPR”).
Our two roles
- For organisers (people who create events), we are the data controller (a “data user” under the PDPA). We decide how account data is used.
- For guests (people who RSVP), the organiser is the controller of their event's guest list. We act as a data processor, processing guest data only to run the organiser's event and under this policy.
2.What we collect
From organisers
- Account details from Google sign-in: your name, email address and profile photo.
- Event details you enter: event name, date, time, venue, sessions, uploaded cards or photos, and the form fields you choose. If you add a WhatsApp number for guest questions, it is shown on your RSVP page.
- Payment records: the tier purchased, amount, payment reference and, for DuitNow QR, the receipt screenshot you upload. We do not collect or store card numbers or bank login details.
When you contact us
- Support requests and feedback: what you write to us, any screenshot you attach, and details that help us fix the problem (the page, your device and your plan). Guests who report a problem can add a name and email if they want a reply.
From guests
- RSVP details: name, phone number, attendance, number of adults and children, and session.
- Optional details, only if the organiser switches them on: email address, vehicle plate number (for gate passes), dietary needs, department, and a message or wishes for the host.
- We do not ask for children's names or any sensitive personal data (such as health, religious beliefs or political opinions) as part of the standard RSVP form.
From everyone
- Technical data: IP address, browser and device type, and basic logs needed to keep the service secure and working.
3.ListNama Business accounts
When you request a Business account
We collect the company name, SSM number (optional), your name, work email, phone number and whether you are a training provider or an HR or company team. We also keep a scrambled (hashed) version of your network address to stop spam, never the address itself. We use these details to check and approve the request, to contact you about it, and to run the account. For this data, we are the data user (controller).
- Approved accounts: kept while the account is active, and deleted within 30 days of closing it, except where the law requires longer.
- Rejected requests: kept for up to 12 months, so we can handle re-applications and prevent abuse, then deleted.
- The company logo you upload is public, because it is shown on your event pages.
Guest data in business events
For guests of a business event, the organisation running the event is the data user (controller) and we are its data processor. Business question packs may ask guests for:
- name as per IC or passport, and IC or passport number;
- company, job title, department and staff ID;
- transport and T-shirt sizes;
- dietary needs and allergy details. These may reveal religious beliefs or health information, which the PDPA treats as sensitive personal data. They are only collected with your explicit consent, given through the PDPA consent question on the form.
The organisation uses these details to run its event, for example for attendance records, catering and proof of attendance for a client or HRD Corp claim. The organisation can view them in its dashboard, download them as an Excel file or print a sign-in sheet (with IC numbers masked by default). Copies it downloads or prints are its responsibility. The same retention applies as for all guests: guest data is deleted 12 months after the event, or earlier if the organisation deletes it. Guest details are never sent to our AI provider.
Guests: to access, correct or delete your details from a business event, contact the organisation that invited you. If you cannot reach them, email us and we will pass your request on and help.
4.How we use it
- To create and run event pages, collect RSVPs and show organisers their guest list and headcount.
- To let guests view, edit or cancel their own RSVP using their phone number.
- To send service emails, such as RSVP notifications to organisers and payment confirmations.
- To process and verify payments, and keep records required by Malaysian tax law.
- To prevent abuse and fraud, keep the service secure, and fix problems.
- To understand how the product is used (in aggregate) so we can improve it.
We never sell personal data. We never use guests' phone numbers or emails for our own marketing. Organisers receive marketing from us only if they opt in, and can opt out at any time.
5.Why we're allowed to use it
Under the PDPA, we process personal data with consent, or where it is necessary to:
- provide the service you signed up for or the RSVP you submitted (performance of a contract);
- comply with legal obligations, such as tax record-keeping;
- protect the security of the service and prevent fraud.
Where the GDPR applies, our legal bases are contract, legitimate interests (security, fraud prevention and improving the service), legal obligation, and consent (for optional marketing).
Providing a name and phone number is necessary to submit an RSVP, because the organiser needs them to manage attendance. Optional fields can be left blank.
7.Transfers outside Malaysia
Our main database is hosted in Singapore, and some providers above operate in other countries, including the United States and Japan. When personal data is transferred outside Malaysia, we do so in line with the PDPA's cross-border transfer requirements. We choose providers that maintain strong security standards and are bound by contractual obligations to protect the data.
8.How long we keep it
- Guest RSVP data: deleted automatically 12 months after the event date. Organisers can delete it earlier at any time.
- Organiser accounts: kept while your account is active. If you delete your account, we delete your data within 30 days, except where we must keep it by law.
- Payment records: kept for 7 years, as required by Malaysian tax law.
- Security logs (including sign-in attempts): kept for up to 90 days.
- Support requests and feedback: deleted automatically 2 years after the last update, together with any screenshots.
9.How we protect it
- All data is encrypted in transit (HTTPS) and at rest.
- Database-level access rules (row-level security) ensure each organiser can only access their own events and guests.
- Administrative access is limited, and access to personal data is logged.
- Our internal dashboards show counts and totals, not guests' personal details.
If a personal data breach occurs, we will notify the Personal Data Protection Commissioner within 72 hours of becoming aware of it, and notify affected individuals without undue delay where the breach is likely to cause significant harm, as required by the PDPA.
10.Your rights
You have the right to:
- Access the personal data we hold about you.
- Correct data that is inaccurate, incomplete or out of date.
- Withdraw consent and ask us to limit or stop processing.
- Data portability: receive your data in a common format, or have it sent to another service. Organisers can export their guest list as CSV at any time.
- Deletion of your data, subject to legal retention requirements.
- Opt out of marketing at any time.
To use these rights, email info@kontiv.com. We will respond within 21 days. Guests: you can edit or cancel your RSVP yourself using your phone number, or contact the organiser of the event. You can also contact us and we will help.
If you are not satisfied with our response, you may complain to the Personal Data Protection Commissioner of Malaysia (Jabatan Perlindungan Data Peribadi), or to your local data protection authority.
12.Children
Organiser accounts are for people aged 18 and over. RSVPs are normally submitted by an adult, such as a parent answering for their family. The standard RSVP form collects only a count of children attending, not their names or details.
If an organiser adds a field asking for a child's details (for example, for a school or kindergarten event), it must be filled in by the child's parent or guardian, who confirms their consent. These details are used only for that event and are deleted 6 months after the event date. Guests under 18 should not submit their own RSVP without a parent or guardian's permission.
13.AI features
ListNama offers optional AI assistance for organisers, powered by Anthropic (the Claude AI model), based in the United States. AI features run only when an organiser chooses to use them:
- Reading an invitation: when an organiser uploads an invitation card or pastes invitation text, it is sent to Anthropic to fill in the event details. The invitation may include names of the hosts, the venue address and other details printed on it.
- Drafting a reminder: when an organiser asks for a WhatsApp reminder draft, we send the event name, type, date, venue and RSVP deadline.
Guests' RSVP details are never sent to the AI provider. Anthropic processes this data only to return a result to us and does not use it to train its models. Anthropic deletes it automatically within 30 days, unless it is flagged for breaking Anthropic's usage rules (then it may be kept for up to 2 years) or the law requires longer. AI results are drafts: the organiser reviews and edits them, and nothing is sent to guests automatically.
If you would rather not use AI, simply don't use these features. You can create and run your event fully by hand.
14.Changes to this policy
We may update this policy as ListNama grows. We will change the “last updated” date above, and for significant changes we will notify organisers by email or in the dashboard.
This policy is available in English and Bahasa Melayu. If there is any inconsistency between the two versions, the English version prevails.
Contact us
Questions about this page or your data? We usually reply within 2 working days.
- Operated by
- Kontiv Solutions (202603017630 (003813924-K)), Cyberjaya, Selangor, Malaysia
- info@kontiv.com
- Phone