Preparing research content…
Privacy
This draft explains how the AST / SilverStream research-platform prototype currently handles personal data. It is written for the UKM-related research context shown by the site, but the site is not itself an official UKM publication or UKM privacy notice. The operator must confirm the missing legal details before launch.
The data controller/operator name, registered address, privacy contact and data-protection contact are not configured in this prototype. They must be inserted and approved by the UKM/AST owner before this notice is published.
For a question about this draft, use the site's Contact route only after the owner has configured a verified channel. Do not send personal, confidential or controlled information until that channel and the production workflow have been confirmed.
The public expression-of-interest form at /people asks for a name, a research interest or opportunity description, an optional telephone number, an optional selected opportunity, and an affirmative consent checkbox. It does not ask for an email address. A successful submission is stored in the site's PostgreSQL-backed EOI inbox for review by an authenticated editor. The record also contains technical submission, consent and workflow timestamps/identifiers needed to prevent duplicate submissions and manage review.
The collaboration form currently validates its fields in the browser only. Its current implementation does not transmit or store the challenge, organisation, email or consent values. If a future release sends that form to a server, mail service or CRM, this notice and the form copy must be updated before that release.
The newsletter form currently validates an email and interests in the browser only and displays that no subscription is created. It does not currently store or transmit those values. A real subscription service would require a new notice, consent flow, unsubscribe route and processor review.
The Contact page constructs mailto, telephone, WhatsApp, Telegram, map and other external links from owner-configured channel values. Following one of those links can disclose information directly to the selected provider. The site does not receive a copy of that external communication through the link itself.
The private editor uses an encrypted, HTTP-only, SameSite=Strict session cookie named ast_editor, a server-side session record, CSRF state, audit records and bounded rate-limit records. These support authentication, security and editorial administration; they are not used for advertising or visitor profiling.
The browser may keep a sessionStorage flag named silverstream:intro-seen so the introductory loader is shown once per browser session. It is not a user account or analytics identifier.
EOI information is used to receive, secure, triage and respond to a research-interest or study-opportunity enquiry connected with the site's UKM/AST research context. The public form's stated ground is the person's consent to storage for authorised editor review. Supplying the required fields and consent is voluntary, but the EOI cannot be submitted without them.
Security and administration records are used to sign in editors, prevent request abuse, protect the database and maintain an editorial audit trail. The precise statutory, contractual or legitimate-interest basis must be confirmed by the operator for its actual role and deployment.
The site does not currently use the collaboration or newsletter browser forms for a live service. No direct-marketing subscription should be inferred from either form.
EOI records are visible to the authorised editor account(s) that operate the private inbox. They may be disclosed to a database, hosting, security or infrastructure provider only where that provider is actually configured and contractually authorised for the stated purpose. The current repository does not establish the production provider, data location or processor list, so those details must be completed before publication.
Information may be disclosed where required by law or to protect the site, users, UKM/AST systems or another person's rights. The owner must document its approved disclosure list and any required notice or consent.
The repository does not identify the production hosting, database or storage region. Do not assume that submitted information stays in Malaysia. Before launch, the operator must determine whether any personal data is transferred outside Malaysia and document the applicable condition, due diligence, contractual safeguard and transfer-impact assessment required under section 129 of Malaysia's Personal Data Protection Act 2010 (Act 709) and the Personal Data Protection Guidelines on Cross-Border Personal Data Transfer (Guidelines No. 3/2025).
If Google Fonts or another external provider is retained, its network request and location must be included in that deployment assessment. The final notice should identify relevant provider classes and locations in clear language.
The current code has no automatic deletion schedule for EOI records. The operator must set and publish a purpose-based retention period, review cadence and deletion/anonymisation process before launch. Editor sessions are designed to expire after eight hours, while the database session and audit/rate-limit records require an owner-approved retention rule.
The browser intro flag lasts only for the browser session. Values entered into the collaboration and newsletter forms remain in the browser's live component state and are discarded when that page state is gone, subject to ordinary browser behavior.
Subject to the Personal Data Protection Act 2010 (Act 709) and other applicable requirements, you may ask whether your personal data is being processed, request access or correction, withdraw consent where consent is the ground, and ask questions or make a complaint about the handling of your data. The operator must publish the verified address and process for these requests before launch.
A withdrawal request does not undo processing that was already lawful, and a request may be subject to identity verification, legal exceptions and the operator's documented procedure. Do not use an unverified social-media or third-party channel for a rights request.
The application validates EOI inputs, limits request size and rate, verifies the request origin, uses parameterised database operations, restricts the public query to published records, and separates the authenticated editor session from the public site. These are technical controls observed in the prototype, not a guarantee that a deployed service is secure.
Do not submit identity-card numbers, health information, religious or political views, passwords, payment details, trade secrets, export-controlled information or another person's information. The site is not designed to collect sensitive personal data through the public EOI form.
The site is an academic and research information service. It is not directed at children and the operator has not configured a child-specific collection process. If a programme is intended for minors, the responsible UKM/AST owner must add an approved safeguarding and consent process.
The owner may update this notice when the site, research routes, providers or law changes. The date shown at the top should be updated with each approved revision. A new collection purpose or provider requires notice and choice before the changed processing begins.
Draf ini menerangkan cara prototaip platform penyelidikan AST / SilverStream mengendalikan data peribadi pada masa ini. Ia disediakan dalam konteks penyelidikan berkaitan UKM yang dipaparkan di laman ini, tetapi laman ini bukan penerbitan rasmi UKM atau notis privasi UKM. Pemilik hendaklah mengesahkan butiran undang-undang yang belum lengkap sebelum pelancaran.
Nama pengawal data/operator, alamat berdaftar, hubungan privasi dan hubungan perlindungan data belum ditetapkan dalam prototaip ini. Pemilik UKM/AST hendaklah memasukkan dan meluluskan butiran tersebut sebelum notis ini diterbitkan.
Untuk pertanyaan tentang draf ini, gunakan laluan Contact hanya selepas pemilik menyediakan saluran yang disahkan. Jangan hantar maklumat peribadi, sulit atau terkawal sehingga saluran dan aliran kerja produksi disahkan.
Borang expression of interest di /people meminta nama, huraian minat penyelidikan atau peluang, nombor telefon pilihan, peluang yang dipilih jika ada, serta kotak persetujuan. Alamat e-mel tidak diminta. Selepas berjaya dihantar, maklumat disimpan dalam peti masuk EOI berasaskan PostgreSQL untuk semakan editor yang disahkan. Rekod turut mempunyai cap masa/pengecam teknikal bagi persetujuan dan aliran kerja untuk mengelakkan penghantaran pendua dan mengurus semakan.
Borang kerjasama pada masa ini hanya mengesahkan medan dalam pelayar. Kod semasa tidak menghantar atau menyimpan nilai cabaran, organisasi, e-mel atau persetujuan. Jika versi akan datang menghantar borang kepada pelayan, perkhidmatan e-mel atau CRM, notis dan teks borang hendaklah dikemas kini sebelum versi itu diterbitkan.
Borang newsletter pada masa ini hanya mengesahkan e-mel dan minat dalam pelayar serta memaklumkan bahawa langganan tidak dibuat. Nilai tersebut tidak disimpan atau dihantar pada masa ini. Perkhidmatan langganan sebenar memerlukan notis, aliran persetujuan, cara berhenti langgan dan semakan pemproses baharu.
Halaman Contact membina pautan e-mel, telefon, WhatsApp, Telegram, peta dan pautan luaran lain daripada nilai saluran yang dikonfigurasi pemilik. Mengikuti pautan itu boleh mendedahkan maklumat terus kepada penyedia berkenaan. Laman ini tidak menerima salinan komunikasi luaran tersebut melalui pautan itu.
Editor persendirian menggunakan kuki sesi disulitkan, HTTP-only dan SameSite=Strict bernama ast_editor, rekod sesi pada pelayan, keadaan CSRF, rekod audit dan rekod had kadar. Ini menyokong log masuk, keselamatan dan pentadbiran editorial; ia tidak digunakan untuk iklan atau pemprofilan pelawat.
Pelayar mungkin menyimpan tanda sessionStorage bernama silverstream:intro-seen supaya pemuat pengenalan hanya muncul sekali bagi setiap sesi pelayar. Ia bukan akaun pengguna atau pengecam analitik.
Maklumat EOI digunakan untuk menerima, melindungi, menapis dan memberi respons kepada pertanyaan minat penyelidikan atau peluang pengajian yang berkaitan dengan konteks penyelidikan UKM/AST di laman ini. Asas yang dinyatakan oleh borang awam ialah persetujuan untuk menyimpan maklumat bagi semakan editor yang diberi kuasa. Medan wajib dan persetujuan diperlukan untuk menghantar EOI, namun penyediaannya adalah secara sukarela.
Rekod keselamatan dan pentadbiran digunakan untuk log masuk editor, mencegah penyalahgunaan permintaan, melindungi pangkalan data dan mengekalkan jejak audit editorial. Operator hendaklah mengesahkan asas undang-undang, berkanun, kontrak atau kepentingan sah yang tepat mengikut peranan dan penggunaan sebenar.
Borang kerjasama dan newsletter pada masa ini bukan perkhidmatan langsung. Jangan anggap mana-mana borang itu sebagai langganan pemasaran langsung.
Rekod EOI boleh dilihat oleh akaun editor yang diberi kuasa dan mengendalikan peti masuk persendirian. Rekod boleh didedahkan kepada penyedia pangkalan data, hos, keselamatan atau infrastruktur hanya jika penyedia itu benar-benar dikonfigurasi dan dibenarkan melalui kontrak bagi tujuan yang dinyatakan. Repositori ini tidak menetapkan penyedia produksi, lokasi data atau senarai pemproses; butiran tersebut mesti dilengkapkan sebelum penerbitan.
Maklumat boleh didedahkan apabila diwajibkan oleh undang-undang atau untuk melindungi laman, pengguna, sistem UKM/AST atau hak orang lain. Pemilik hendaklah mendokumenkan senarai pendedahan yang diluluskan serta notis atau persetujuan yang diperlukan.
Repositori ini tidak mengenal pasti hos produksi, pangkalan data atau rantau storan. Jangan menganggap maklumat yang dihantar kekal di Malaysia. Sebelum pelancaran, operator hendaklah menentukan sama ada data peribadi dipindahkan ke luar Malaysia dan mendokumenkan syarat, usaha wajar, perlindungan kontrak dan penilaian impak pemindahan yang berkenaan di bawah seksyen 129 Akta Perlindungan Data Peribadi 2010 (Akta 709) serta Garis Panduan Pemindahan Data Peribadi Merentas Sempadan (Garis Panduan No. 3/2025).
Jika Google Fonts atau penyedia luaran lain dikekalkan, permintaan rangkaian dan lokasinya hendaklah dimasukkan dalam penilaian penggunaan tersebut. Notis akhir hendaklah menyatakan kelas dan lokasi penyedia yang berkaitan dengan bahasa yang jelas.
Kod semasa tidak mempunyai jadual pemadaman automatik untuk rekod EOI. Operator hendaklah menetapkan dan menerbitkan tempoh penyimpanan berdasarkan tujuan, kekerapan semakan serta proses pemadaman atau penganoniman sebelum pelancaran. Sesi editor direka untuk tamat selepas lapan jam, manakala sesi pangkalan data dan rekod audit/had kadar memerlukan kaedah penyimpanan yang diluluskan pemilik.
Tanda pengenalan dalam pelayar hanya bertahan sepanjang sesi pelayar. Nilai dalam borang kerjasama dan newsletter berada dalam keadaan komponen pelayar dan akan hilang apabila keadaan halaman itu berakhir, tertakluk kepada kelakuan biasa pelayar.
Tertakluk kepada Akta Perlindungan Data Peribadi 2010 (Akta 709) dan keperluan lain yang berkenaan, anda boleh bertanya sama ada data peribadi anda sedang diproses, meminta akses atau pembetulan, menarik balik persetujuan apabila persetujuan menjadi asas, serta bertanya atau membuat aduan tentang pengendalian data. Operator hendaklah menerbitkan alamat dan proses permintaan yang disahkan sebelum pelancaran.
Penarikan balik tidak membatalkan pemprosesan yang telah dilakukan secara sah, dan permintaan mungkin tertakluk kepada pengesahan identiti, pengecualian undang-undang dan prosedur operator yang didokumenkan. Jangan gunakan saluran media sosial atau pihak ketiga yang tidak disahkan untuk permintaan hak.
Aplikasi mengesahkan input EOI, mengehadkan saiz dan kadar permintaan, mengesahkan asal permintaan, menggunakan operasi pangkalan data berparameter, mengehadkan pertanyaan awam kepada rekod yang diterbitkan, serta memisahkan sesi editor yang disahkan daripada laman awam. Ini ialah kawalan teknikal yang dilihat dalam prototaip dan bukan jaminan keselamatan perkhidmatan yang telah digunakan.
Jangan hantar nombor kad pengenalan, maklumat kesihatan, pandangan agama atau politik, kata laluan, butiran bayaran, rahsia dagangan, maklumat kawalan eksport atau maklumat orang lain. Laman ini tidak direka untuk mengumpul data peribadi sensitif melalui borang EOI awam.
Laman ini ialah perkhidmatan maklumat akademik dan penyelidikan. Ia tidak ditujukan kepada kanak-kanak dan operator belum menyediakan proses pengumpulan khusus kanak-kanak. Jika sesuatu program ditujukan kepada bawah umur, pemilik UKM/AST hendaklah menambah proses keselamatan dan persetujuan yang diluluskan.
Pemilik boleh mengemas kini notis ini apabila laman, laluan penyelidikan, penyedia atau undang-undang berubah. Tarikh di atas hendaklah dikemas kini bagi setiap semakan yang diluluskan. Tujuan atau penyedia baharu memerlukan notis dan pilihan sebelum pemprosesan berubah bermula.