Privacy Policy
How SmartID collects, uses, and protects your personal data.
Last updated: August 2026
1. Introduction
This Privacy Policy explains how Pointgate Systems Sdn Bhd (“Pointgate”, “we”, “us”), the developer of the SmartID platform (SmartID TIME, SmartID CAFE, SmartID EDUTIME, SmartID EDUCAFE and SmartID PAY), collects, uses, stores, and protects personal data. It is written to comply with the Malaysian Personal Data Protection Act 2010 (PDPA). SmartID is used by schools, institutions, and organisations to record attendance and, where enabled, to operate cashless payments using contactless palm-vein recognition.
2. Information We Collect
2.1 Biometric data
When a person is enrolled, a contactless infrared scan of the palm is converted into a mathematical template. This template is a set of numbers — it is not a photograph or image of the hand and cannot be reversed into one. It is used only to recognise the same palm at a later scan.
2.2 Identity and attendance data
Full name, system or enrolment ID, grade or class (for pupils), user type, and attendance records (the date and time of each check-in and the resulting status).
2.3 Payment data
Where SmartID CAFE, EDUCAFE or PAY is enabled: wallet balance and transaction records for cashless purchases.
2.4 Device and technical data
Terminal identifiers (device name, hardware address) used to register and secure each installed device, and basic operational logs needed to keep the service running and secure.
3. How We Use Your Information
- To recognise enrolled individuals and record their attendance or access.
- To operate cashless payments where the institution has enabled them.
- To provide reporting, administration, and support to the institution.
- To secure the service and prevent misuse, such as refusing a revoked enrolment.
Biometric enrolment is carried out with the consent of the individual (or, for a minor, the consent of a parent or guardian obtained by the institution). An individual may decline biometric enrolment; the institution is responsible for offering an alternative method.
4. Biometric Data
We treat palm-vein data with particular care:
- Palms are stored only as encrypted mathematical templates, never as images. Raw scan images are not retained.
- Matching happens on the institution’s own terminal or server, so attendance continues to work even when the local network is down.
- Biometric templates are not sent to any third-party biometric cloud, and the platform does not transmit biometric data to any external vendor.
- Biometric data is used solely for identification and authentication within the SmartID services.
5. How We Store and Protect Your Data
- Data in transit is encrypted using industry-standard transport security (HTTPS/TLS).
- Access to personal data is restricted by role and enforced at the database level.
- Terminals authenticate to the service with per-device credentials that can be revoked individually.
- Palm data is stored as encrypted templates only, on servers operated for Pointgate and, for offline matching, on the institution’s own attendance terminals.
6. Data Retention
6.1 Personal data is retained for as long as the individual remains enrolled with the institution and as specified in our agreement with that institution.
6.2 When an enrolment is revoked, the associated palm template is removed from active use.
6.3 We will delete personal data, including biometric templates, within 30 days of account termination, subject to legal retention requirements.
7. Sharing and Disclosure
We do not sell personal data. We share it only:
- with the institution that enrolled the individual, which uses the data for its own attendance and administration;
- with service providers that host or support the platform under confidentiality obligations; and
- where required by law or to protect the rights and safety of users.
8. Children’s Data
SmartID is deployed and operated by institutions, including schools. Where the data of a minor is processed, it is done on behalf of and under the instruction of the institution, which is responsible for obtaining the necessary parental or guardian consent. The SmartID terminal application is intended to be installed and administered by institution staff, not downloaded or operated by children directly.
9. Your Rights
Under the PDPA you may, subject to the Act, request to:
- access the personal data we hold about you;
- correct inaccurate or incomplete data;
- withdraw consent to biometric processing, which may mean the institution provides an alternative attendance method; and
- enquire how your data is being processed.
Requests relating to attendance records are usually best directed to your institution, which controls its own records. You may also contact us using the details below.
10. Cookies
Our web portal uses only the cookies necessary to keep you signed in and to operate the service securely. We do not use cookies to track you across other websites for advertising.
11. Changes to This Policy
We may update this Privacy Policy from time to time. The “last updated” date at the top shows when it was last revised. We will communicate material changes through the platform or to the institution.
12. Contact Us
If you have questions about this Privacy Policy or how your data is handled, please contact us:
Pointgate Systems Sdn Bhd
By using SmartID services, you acknowledge that you have read and understood this Privacy Policy.