1. Introduction
Welcome to Boostmychild! This Privacy Policy outlines how Boostmychild Pvt. Ltd. ("we," "us," or "our") collects, uses, processes, and protects personal data in accordance with the Malaysian Personal Data Protection Act 2010 ("PDPA").
Boostmychild is an early-education website designed to support educational assessments and early development support for children and their parents. Please note that children will NOT be directly using this website or any associated mobile applications. This platform is intended for use by parents/legal guardians and authorized school staff only.
By accessing or using the Boostmychild Smart Parent App, you signify your agreement to the terms of this Privacy Policy. If you do not agree with the terms herein, please do not use our website.
2. The Malaysian Personal Data Protection Act (PDPA) 2010
We are committed to upholding the seven Personal Data Protection Principles as mandated by the PDPA:
- General Principle: Personal data shall not be processed without the consent of the data subject.
- Notice and Choice Principle: You must be informed of the data being collected and its purpose, and have the choice to consent or withdraw consent.
- Disclosure Principle: Personal data shall not be disclosed for any purpose other than that for which it was collected, or to a third party not authorized by the data subject.
- Security Principle: Appropriate security measures must be taken to protect personal data from loss, misuse, modification, unauthorized or accidental access or disclosure, alteration, or destruction.
- Retention Principle: Personal data shall not be kept longer than is necessary for the fulfillment of the purpose for which it was processed.
- Data Integrity Principle: Reasonable steps must be taken to ensure that personal data is accurate, complete, not misleading, and kept up-to-date.
- Access Principle: You have the right to access your personal data and to correct it if it is inaccurate, incomplete, misleading, or not up-to-date.
3. What Personal Data Do We Collect?
We collect personal data that is necessary for the purposes outlined in this policy. The types of personal data we collect from parents/legal guardians and authorized school staff include:
From Parents/Legal Guardians:
- Full Name
- Email Address
- Contact Number
- Relationship to the Child
- Child's Name (for identification within the assessment context)
- Child's Date of Birth (for age-appropriate assessments)
- Child's Gender (for demographic reporting, not for individual assessment)
- School Name (where the child is enrolled)
- Assessment information on individual child performance.
From Authorized School Staff:
- Full Name
- Email Address
- Contact Number
- Job Title/Designation
- School Name
- Login Credentials (username and password)
- Photos of children in classroom settings, for communication to Parents/Guardians
- Videos of children in classroom settings, for communication to Parents/Guardians.
- Assessment information on individual child performance.
- Communications/messages to and from school personnel to childrens' Parents/Guardians.
We do not directly collect sensitive personal data as defined by the PDPA (e.g., race, political opinions, religious beliefs, health data) from users of this website.
4. How Do We Collect Your Personal Data?
We collect personal data through various methods:
- Directly from you: When you register an account, fill out forms, subscribe to services, or communicate with us via email or support channels.
- From your school: Authorized school staff may provide us with your child's basic identifying information (name, DOB, gender) to link assessment data to your child within the system, with your prior consent obtained by the school.
- Automatically: Through cookies and similar tracking technologies when you browse our website (please see Section 10 on Cookies).
5. Purposes for Which We Process Your Personal Data (Notice and Choice Principle)
We collect and process your personal data for the following specific purposes. We will not process your personal data for any other purpose without obtaining your explicit consent.
- To create and manage user accounts for parents/legal guardians and school staff.
- To facilitate access to the early-education assessment tools and results.
- To link assessment data to specific children (identified by name, DOB, gender).
- To communicate with you regarding your account, assessments, and updates to our services.
- To provide technical support and address inquiries.
- To send important notices or marketing communications that you have explicitly opted-in to receive.
- To improve our website's functionality and user experience.
- To comply with legal and regulatory requirements.
6. Consent (General Principle)
By registering an account on Boostmychild or providing us with your personal data, you provide your explicit consent for us to process your personal data for the purposes outlined in this Privacy Policy.
Specific to Children's Data: For any personal data related to your child (e.g., name, DOB, gender) provided by you or your child's school, your explicit consent as a parent/legal guardian is mandatory. If the school is providing this information, they are required to have obtained your consent beforehand and provide assurance of such consent.
You have the right to withdraw your consent at any time by contacting us at support@boostmychild.com. Withdrawal of consent may affect your ability to use certain features of the website.
7. Disclosure of Personal Data (Disclosure Principle)
We are committed to the Disclosure Principle. We will NOT disclose your personal data to any third party for purposes other than those for which it was collected, or to third parties not authorized by you, except in the following limited circumstances:
- To Authorized School Staff: If you are a parent, your child's assessment data will be accessible to authorized school staff associated with your child's school, solely for educational purposes.
- To Third-Party Service Providers: We may engage trusted third-party service providers (e.g., cloud hosting, payment processors, analytics providers) to assist us in operating our website and providing our services. These providers are contractually bound to protect your data in accordance with PDPA and are only permitted to use your data for the specific services they provide to us.
- Legal Compliance: If required by law, court order, or governmental regulation, we may disclose your personal data.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, your personal data may be transferred to the acquiring entity, subject to them adhering to this Privacy Policy or a substantially similar policy.
We will never sell, rent, or trade your personal data to third parties for marketing purposes.
8. Security of Personal Data (Security Principle)
We take the security of your personal data very seriously. We implement appropriate administrative, physical, and technical security measures to protect your personal data from loss, misuse, modification, unauthorized or accidental access or disclosure, alteration, or destruction. These measures include:
- Encryption: Data transmitted to and from our website is encrypted using SSL/TLS technology.
- Access Controls: Strict access controls are in place to limit access to personal data only to authorized personnel who have a legitimate need to know.
- Secure Servers: Our website and data are hosted on secure servers with robust security infrastructure.
- Regular Security Audits: We conduct regular security assessments and updates to identify and address potential vulnerabilities.
- Staff Training: Our staff are regularly trained on data protection best practices and our internal privacy policies.
However, no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee its absolute security.
9. Retention of Personal Data (Retention Principle)
We will retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements.
The retention periods for different types of data are determined based on:
- The duration of your active account with us.
- The educational assessment cycle requirements.
- Any statutory or regulatory obligations to retain data (e.g., tax records).
- The need to resolve disputes or enforce our agreements.
When personal data is no longer necessary for the purposes for which it was collected, or when you request deletion, we will securely delete or anonymize it in a manner that prevents its reconstruction.
10. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to enhance your experience on the Boostmychild.com website and Parent Smart App.
What are Cookies? Cookies are small text files placed on your device by websites that you visit. They are widely used to make websites work, or work more efficiently, as well as to provide information to the owners of the site.
How We Use Cookies:
- Essential Cookies: Necessary for the website to function correctly (e.g., maintaining your login session).
- Performance/Analytics Cookies: Help us understand how users interact with our website, which pages are most popular, and identify areas for improvement. This data is typically aggregated and anonymized.
- Functionality Cookies: Remember your preferences and choices to provide a more personalized experience.
Your Choices: Most web browsers allow you to control cookies through their settings. You can usually set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of the Boostmychild School Assessment Module, Reporting Modules, or Smart Parent Mobile App may become inaccessible or not function properly.
11. Your Rights as a Data Subject (Access Principle & Data Integrity Principle)
Under the PDPA, you have the following rights concerning your personal data:
- Right to Access: You have the right to request access to the personal data we hold about you. We will provide you with a copy of your personal data within a reasonable timeframe, subject to administrative fees if applicable as permitted by PDPA.
- Right to Correction: You have the right to request correction of any inaccurate, incomplete, misleading, or outdated personal data we hold about you.
- Right to Withdraw Consent: As mentioned in Section 6, you have the right to withdraw your consent to the processing of your personal data at any time.
- Right to Prevent Processing for Direct Marketing: You have the right to request that we cease processing your personal data for the purposes of direct marketing.
- Right to Prevent Processing Likely to Cause Distress: You have the right to request that we cease processing your personal data if such processing is likely to cause substantial damage or distress to you or another person.
To exercise any of these rights, please contact us at support@boostmychild.com. We may require you to provide proof of identity to ensure your request is legitimate and to protect the privacy of others.
12. Transfer of Personal Data Outside Malaysia
We generally process and store personal data within India. In the event that we need to transfer your personal data outside Malaysia (e.g., if our cloud hosting provider's servers are located internationally), we will only do so if:
- The recipient country has laws that provide an equivalent level of data protection as the PDPA.
- We have obtained your explicit consent for such transfer – include the country here so that acceptance for handling outside Malaysia is provided as part of the overall policy acknowledgement/acceptance.
- We have implemented appropriate contractual clauses or other safeguards to ensure the adequate protection of your personal data in accordance with the PDPA.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, regulatory, or operational reasons. Any changes will be posted on this page with an updated "Last Updated" date. We will notify you of any significant changes by e-mail or through a prominent notice on our website. Your continued use of the website after any changes constitutes your acceptance of the revised Privacy Policy.
14. Contact Us
If you have any questions about this Privacy Policy, our data practices, or if you wish to exercise your rights, please contact our Data Protection Officer at:
Thank you for trusting Boostmychild with your data. We are committed to protecting your privacy and upholding the principles of the Malaysian PDPA.