Legal
BRQ+ Privacy Notice
Version Privacy 1.0 · Last updated 2026-09-29
BRQ+ Privacy Notice
Version 1.0 — WORKING DRAFT, not yet final. Subject to legal review.
This notice explains how BRQ Plus Sdn Bhd collects, uses, shares and protects personal data. It covers everyone who uses the BRQ+ website and member portal: applicants, Personal and Corporate members, Company Users, program participants, event attendees, and external signers of BRQ+ NDAs. It is written to Malaysia's Personal Data Protection Act 2010 (PDPA), as amended, and also takes Singapore's PDPA 2012 into account where programs run there.
1. Who we are
BRQ Plus Sdn Bhd (Company Reg. 202601006582 (1668680-A)), trading as BRQ+, is the data user (controller) responsible for your personal data.
- Address: [To confirm: registered address, Kuala Lumpur]
- Privacy contact / Data Protection Officer: [To confirm: name] at [To confirm: privacy@brqplus.ai]
- Website: brqplus.ai
Where BRQ+ runs a program with a partner, such as The Give Network with AMP Singapore, that partner may also hold your data under its own privacy notice. We tell you who they are when you sign up.
2. What we collect
We collect only what we need to run membership, programs and engagements. Most of it comes from you directly.
| Where it comes from | What we collect |
|---|---|
| Personal membership application | Name, email, phone, LinkedIn, country, city, role, organisation, sector, expertise, years of experience, languages, program interests, bio; for The Collective: domain, markets, mandate, availability |
| Corporate membership application | Company details (legal name, registration number, address, sector, size, markets); the contact's name, job title, work email, phone, LinkedIn; billing contact |
| Program forms (e.g. The Give Network, Founders @ BRQ+) | Interests, expertise, hours available, geographic preference, career stage, company and venture details, event RSVPs, dietary notes |
| Your member profile and portal use | Profile updates, photo, mission and engagement records, messages in portal chat, documents you upload |
| Agreements and NDAs you sign | Typed name, job title, drawn signature, date and time, IP address, device and browser, a fingerprint of the signed text, the signed PDF |
| Website and security logs | IP address, device, browser, pages visited, sign-in events, how you reached a form (e.g. via an event QR code) |
| Other people | Your Company Admin (when inviting you), members or partners who refer you, and public professional profiles such as LinkedIn |
We do not ask for sensitive personal data, such as health, religious beliefs or political opinions. Please don't include it in free-text fields.
3. Why we use it
We use your personal data to:
- assess your application and verify your identity or your company's details;
- create and manage your member profile, company profile and portal access;
- match you with engagements, missions, programs, partners and opportunities that fit your expertise and preferences;
- run programs and events, including The Collective, Founders @ BRQ+ and The Give Network, and their RSVPs and follow-ups;
- prepare, sign and store membership agreements and NDAs, and keep records that show they were validly signed;
- communicate with you about your membership, engagements, programs and service updates;
- measure how programs perform, for example sign-ups by event or channel, using aggregated figures where we can;
- keep the platform secure, prevent fraud and misuse, and enforce our agreements;
- meet our legal, tax, audit and regulatory obligations;
- send you news about BRQ+ events and programs, only if you opted in (see section 5).
4. Who we share it with
We share personal data only as needed for the purposes above. We do not sell it.
- Other members: active members can see directory profiles (name, role, company, expertise, markets). Your contact details stay hidden unless you choose to show them. [To confirm]
- Engagement and mission parties: clients, partners, sponsors and co-members on an engagement you join or apply for see your profile and the documents for that engagement.
- Program partners: for example AMP Singapore and The Give Network partners (GIV, Ventura, WSF), for programs you sign up to.
- Service providers acting for us: hosting and database, authentication, file storage, email delivery and analytics. [To confirm: list providers]
- Professional advisers: lawyers, auditors and insurers, under confidentiality.
- Authorities: regulators, courts or law enforcement, where the law requires it.
- A buyer or successor: if BRQ+ reorganises or is acquired, under equivalent protections.
Transfers outside Malaysia. Some partners and service providers are in other countries, such as Singapore, Indonesia or where our cloud providers host data. When we transfer data abroad, we do so as the PDPA allows, including with your consent or where it is needed to carry out an engagement you asked for, and we require the recipient to protect it to a comparable standard. [To confirm: hosting region]
5. What you must provide, and your choices
- Required fields are marked with an asterisk on each form. Without them we cannot assess your application, create your account or arrange engagements.
- Optional fields, such as phone, LinkedIn, bio and photo, help us match you better. Leaving them blank will not stop your application.
- Consent: by submitting a form and ticking the consent box, you agree to us using your data as this notice describes. You can withdraw consent at any time (section 7). We may then be unable to continue your membership or engagement.
- Marketing: we send newsletters and event invitations only if you opt in. Every message has an unsubscribe link, and you can also change this in your profile.
6. How long we keep it, and how we protect it
We keep personal data only as long as the purpose needs it, or the law requires. These are our default periods. [To confirm]
| Data | How long we keep it |
|---|---|
| Unsuccessful applications and program interest forms | 12 months from submission |
| Member and company profiles | While membership is active, then 2 years |
| Signed agreements, NDAs and signing records | 7 years after the agreement or engagement ends |
| Engagement and mission records, invoices | 7 years, for tax and audit |
| Security and access logs | 12 months |
After that we delete or anonymise the data.
Security. We use encryption in transit, access controls based on role, private storage for signed documents with time-limited download links, and audit logs of admin actions. No system is perfectly secure. If a breach is likely to harm you, we will tell you and the Personal Data Protection Commissioner as the law requires, and tell you what to do.
7. Your rights
You can ask us to:
- access the personal data we hold about you and get a copy;
- correct data that is inaccurate, incomplete or out of date (you can also edit most of it in your profile);
- withdraw consent or limit how we use your data;
- stop direct marketing;
- move your data to another provider in a common format, where the law gives you this right. [To confirm]
Email [To confirm: privacy@brqplus.ai] with your request. We may need to verify your identity first. We will reply within 21 days, as the PDPA requires for access and correction requests. The law allows us to charge a small fee for some access requests; we will tell you before charging. If we cannot meet a request, we will explain why.
If you are not satisfied, you may complain to Malaysia's Personal Data Protection Commissioner (Jabatan Perlindungan Data Peribadi).
8. Cookies, changes and language
- Cookies: we use essential cookies to keep you signed in and the site secure, and basic analytics to see how pages are used. [To confirm: analytics tool]
- Changes: we may update this notice. We will post the new version here with its date, and tell members by email or in the portal about material changes.
- Language: this notice is available in English and Bahasa Malaysia, as the PDPA requires. If they differ, [To confirm] prevails.
- Minors: BRQ+ is for adults. We do not knowingly collect data from anyone under 18.