1. Introduction and scope
[Legal entity name] (“we”, “us”, “our”, or the “Data Fiduciary/Controller”) respects your privacy and is committed to protecting the personal data of everyone who visits this website, registers for, or attends the APAC Data Center Leadership Summit 2026 (the “Summit”), a webinar hosted from India.
This Privacy Policy explains what personal data we collect, why we collect it, how we use, share, store, and protect it, and the rights you have over it. It applies to visitors and registrants located in our target markets: India, Singapore, Malaysia, Indonesia, Thailand, Vietnam, and South Korea. It does not apply to residents of China, Australia, or New Zealand, who are outside the scope of this event’s intended audience.
Because the Summit is hosted in India and attended by people across seven jurisdictions, this Policy is written to meet the general standards common to India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”), Singapore’s Personal Data Protection Act (“PDPA”), Malaysia’s Personal Data Protection Act 2010 as amended by the Personal Data Protection (Amendment) Act 2024, Indonesia’s Law No. 27 of 2022 on Personal Data Protection (“UU PDP”), Thailand’s Personal Data Protection Act B.E. 2562 (“Thai PDPA”), Vietnam’s Law on Personal Data Protection, Law No. 91/2025/QH15, and its implementing Decree No. 356/2025/ND-CP, and South Korea’s Personal Information Protection Act (“PIPA”). Where a specific jurisdiction imposes an additional or different requirement, that is set out in the country-specific annexures at the end of this Policy (Annexures A–G).
Our separate Cookie Policy explains, in more detail, how we use cookies and similar technologies, and forms part of this Privacy Policy by reference.
If you are located in India, our DPDPA Notice sets out the same information in the specific form required by India’s Digital Personal Data Protection Act, 2023.
2. Who we are
- Data Fiduciary / Controller
- [Legal entity name]
- Registered address
- [Registered office address]
- Contact email for privacy queries
- [Privacy contact email]
- Event host / organiser
- [Event organiser entity]
- Country from which the Summit is hosted
- India
3. Personal data we collect
We collect the following categories of personal data, all of which are provided directly by you when you use the registration form on this website:
| Category | Specific data points | Why we ask for it |
|---|---|---|
| Identity data | Full name | To identify you and personalise your registration and event access |
| Professional data | Company name, job designation/title | To confirm eligibility for this invitation-only event and tailor content |
| Contact data | Email address, phone number (with country dialling code) | To send registration confirmation, joining instructions, and (if opted in) reminders via email and Whatsapp |
| Location data (declared) | Country selected from the registration form | To understand attendee geography and apply the correct country-specific notice |
| Location data (inferred) | Approximate location estimated from your IP address | To tailor the country-specific notice you see automatically — see Cookie Policy |
| Consent records | Whether you checked the privacy, recording, and reminder checkboxes, and when | To keep an auditable record that consent was validly obtained |
| Technical and analytics data | IP address, browser type, device type, general usage data via cookies | To operate, secure, and improve the website — see Cookie Policy |
| Marketing attribution data | Advertising campaign/source/medium, referring website, page address, click identifier | To understand marketing effectiveness and report registrations back to ad platforms |
| Device and session technical data | Time zone, language, device type, screen resolution, session identifier | To understand our attendee base and improve this website |
| On-site engagement data | Which sections you view and how far you scroll (with cookie consent) | To understand which parts of this page are useful — see Cookie Policy |
We do not currently collect any special category / sensitive personal data (e.g. health data, financial account numbers, biometric data, government identity numbers) through this registration form.
4. How we collect your personal data
- Directly from you, when you complete the inline registration form or the pop-up registration drawer on this website.
- Automatically, through standard web technologies (server logs and content-delivery services used to render this page).
- If you attend the live session, through the video/webinar platform used to host the Summit — see Section 6.
The Summit is delivered using [Webinar platform]. That platform may separately collect connection and participation data under its own privacy notice.
5. How we use your personal data (purposes)
Consistent with the DPDP Act’s requirement that notices be itemised and purpose-specific, we use your personal data only for the following clearly stated purposes, and for no other purpose without seeking fresh consent:
- To process your registration and confirm your place at the Summit.
- To send you essential service communications: registration confirmation, joining instructions, and material changes to the event.
- To send you optional reminders about your registration, only if you separately opted in.
- To operate the live session and, since it will be recorded, produce and distribute an on-demand recording, only with your separate recording consent.
- To maintain a record of consent for legal and audit purposes.
- To comply with applicable law and establish, exercise, or defend legal claims.
- To maintain the security and proper functioning of this website.
- Where you have given cookie consent, to understand website traffic and measure our promotion of the Summit — see Cookie Policy.
- To evaluate and improve the performance of our advertising campaigns, using aggregated, non-identifying statistics only (for example, how many registrants came from each campaign, or what proportion used mobile versus desktop) — shared with our marketing partner. This does not include your name, email, phone number, or other identifying information. See Section 8.
- To send you registration confirmations, joining instructions, and event reminders via WhatsApp, using the phone number you provide at registration. These messages are delivered through WATI, our WhatsApp Business messaging provider. You may opt out at any time by replying STOP or writing to us at [Privacy contact email].
6. Session recording notice
The Summit will be recorded. If you attend the live session, your registration details and any participation you choose to provide (camera video, microphone audio, chat messages, or Q&A submissions) may be captured as part of that recording.
The recording may be used to deliver the live session, produce an on-demand version for post-event distribution, and create excerpts or transcripts for those purposes.
We only proceed on this basis where you have given your affirmative, separate consent via the “recording consent” checkbox on the registration form.
7. Cookies and similar technologies
We use cookies and similar technologies on this website, including IP-based location detection and analytics/advertising tools:
- flagcdn.com — used to display country flag icons in the phone number field.
- IP-based location detection — used to estimate your approximate country.
- Google Analytics — used to understand how visitors use this website.
- Google Ads and Meta Pixel — used to measure and improve our promotion of the Summit.
Analytics and advertising cookies are only set where you have given consent through the cookie banner on this website. Full detail, including a country-by-country breakdown of consent requirements, is set out in our separate Cookie Policy, which forms part of this Privacy Policy by reference.
8. Who we share your personal data with
We do not sell your personal data. We share it only with the following categories of recipients, on a need-to-know basis:
| Recipient | Purpose |
|---|---|
| TA-Uncharted | Our appointed event management and marketing partner for this Summit. Operates the registration process, sends registration-related outreach, and processes — and may retain — your registration data on our behalf. |
| [Advertising & social media agency] | Our advertising and social media promotion partner. Receives only aggregated, non-identifying campaign-performance statistics — not your name, email, phone number, or other identifying information. |
| [Email / CRM provider] | To send registration confirmations and, if opted in, reminders |
| [Webinar platform] | To host and record the live session |
| [Website hosting provider] | To host this website |
| Google Analytics | Website analytics — only where you have given cookie consent |
| Google Ads, Meta | Measuring and improving our promotion of the Summit — only where you have given cookie consent |
| Advertising platform(s) you clicked through from | Where you arrived via a paid advertisement, we may report a registration back using the click identifier, so the platform can measure that campaign’s performance |
| NTT DATA / NTT Group affiliates | Internal event administration and follow-up |
| Professional advisers, auditors, and regulators | Where required by law or to establish, exercise, or defend legal claims |
| WATI and its underlying WhatsApp Business Platform infrastructure | Our WhatsApp Business messaging provider. Used to send registration confirmations, joining instructions, and event reminders to the phone number you provide. |
9. International data transfers
The Summit is hosted from India, and your registration data will be processed in India by or on behalf of [Legal entity name]. If you are registering from Singapore, Malaysia, Indonesia, Thailand, Vietnam, or South Korea, this means your personal data is being transferred out of your home country to India.
- We only transfer the minimum personal data necessary for the purposes described in Section 5.
- Where our vendors process data outside India, we require contractual protections consistent with applicable law.
- For South Korea specifically, PIPA requires a dedicated, itemised disclosure and separate consent before transfer — see Annexure G.
- For Vietnam specifically, we may need to prepare and submit a Data Protection Impact Assessment and Transfer Impact Assessment before transferring Vietnamese registrants’ data abroad — see Annexure F.
10. How long we keep your personal data
We keep your registration and consent records for [retention period] after the Summit date, or until you withdraw your consent, whichever is earlier, unless a longer period is required to comply with applicable law or to resolve a dispute.
The on-demand recording of the session remains available to registrants for [recording availability period] after the Summit.
11. How we protect your personal data
We apply reasonable technical and organisational security safeguards appropriate to the nature of the data collected, including access controls, encryption of data in transit (HTTPS), and limiting access to personnel who need it. No method of transmission or storage is completely secure.
12. Your rights
| Right | What it means |
|---|---|
| Access | Ask for a summary of what personal data we hold about you and how it is being processed. |
| Correction | Ask us to correct or update inaccurate or outdated personal data. |
| Erasure / deletion | Ask us to delete your personal data, subject to legal retention requirements. |
| Withdraw consent | Withdraw any consent you previously gave, at any time and as easily as you gave it. |
| Grievance / complaint | Raise a complaint with us, and escalate to the relevant data protection authority if unresolved. |
| Nomination (India only) | Nominate another individual to exercise your rights in the event of death or incapacity. |
13. How to exercise your rights or withdraw consent
You can exercise any of the rights above, or withdraw consent, by writing to us at [Privacy contact email]. We will respond within the timeframe required by the law applicable to you.
14. Grievance Officer (India)
If you are located in India, you may raise a complaint about how we handle your personal data with our Grievance Officer:
- Name
- [Grievance Officer name]
- [Grievance Officer email]
- Address
- [Grievance Officer address]
- Response timeline
- Complaints will be acknowledged and resolved within 90 days, as required by the DPDP Rules, 2025.
15. Data Protection Officer / Privacy Officer
Our appointed Data Protection Officer for this event can be contacted at [DPO name and contact details].
16. Children’s data
The Summit is a business, executive-level event and is not directed at, or intended for, individuals under the age of 18.
17. Data breach notification
If a personal data breach occurs that is likely to affect you, we will notify the relevant data protection authority and affected individuals within the timeframe required by applicable law.
18. Changes to this Policy
We may update this Policy from time to time. The “Effective date” at the top shows when it was last revised.
19. Contact us
Questions about this Policy can be sent to [Privacy contact email].
Annexure A — India: Digital Personal Data Protection Act, 2023
- We act as the Data Fiduciary for the personal data described in Section 3.
- This notice is intended to be read as a standalone, itemised notice per Rule 3 of the DPDP Rules, 2025.
- You may withdraw consent at any time, with withdrawal being at least as easy as giving it.
- Our Grievance Officer’s details are set out in Section 14.
- We will report eligible personal data breaches to the Data Protection Board of India without undue delay.
Annexure B — Singapore: Personal Data Protection Act
- We notify you of the purposes for collection, use, and disclosure on or before collection.
- Eligible data breaches are notified to the PDPC within 3 calendar days of completing our assessment.
- Optional event reminder emails are treated as service/transactional messages, exempt from the Do Not Call Registry.
Annexure C — Malaysia: Personal Data Protection Act 2010
- We process your data as a data controller under the PDPA 2010 as amended by the 2024 Amendment Act.
- A Malaysia DPO has been mandatory, and registered with the Commissioner, since 1 June 2025.
- Cross-border transfers rely on a Transfer Impact Assessment under the 2024 Amendment Act’s framework.
Annexure D — Indonesia: Law No. 27 of 2022 (UU PDP)
- We act as a data controller under Indonesia’s UU PDP, in force since October 2024.
- Eligible data breaches are notified within 72 hours of discovery.
- Consent is voluntary and specific; a pre-ticked box is not valid consent.
Annexure E — Thailand: Personal Data Protection Act B.E. 2562
- Consent for each purpose is sought separately — Thailand is the strictest jurisdiction covered on this point.
- Non-essential cookies are blocked until you actively opt in.
- Data breaches likely to result in a risk to your rights are notified to the PDPC without undue delay.
Annexure F — Vietnam: Law on Personal Data Protection, Law No. 91/2025/QH15
- We process your personal data under Vietnam’s Law No. 91/2025/QH15 and its implementing Decree No. 356/2025/ND-CP, both effective 1 January 2026.
- Consent must be separate for each processing purpose — silence or non-response does not constitute consent.
- Consent to process your data is sought separately from consent to any cross-border transfer of it.
Annexure G — South Korea: Personal Information Protection Act (PIPA)
Before any personal data of a South Korea-based registrant is transferred outside South Korea, the following must be disclosed and separate consent obtained:
| Required disclosure item | Detail |
|---|---|
| Recipient | [Legal entity name] in India, and any sub-processors listed in Section 8 |
| Purpose of transfer | To process your Summit registration and, if applicable, deliver the recorded session |
| Data items transferred | Full name, company, designation, email, phone number, country, consent records |
| Retention period after transfer | As set out in Section 10 of this Policy |
| How to refuse | You may decline to register, or contact us to withdraw consent before the transfer occurs |