Privacy Policy
Last Updated: October 12, 2025
OpenMindAgile (“we,” “our,” or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our educational services and administrative tools, including our Google Sheets integration for data management and social media messaging platforms.
Important: By using OpenMindAgile services, including messaging us on Facebook Messenger, Instagram, or WhatsApp, you consent to the data practices described in this policy.
1. About OpenMindAgile
OpenMindAgile conducts innovative education programs to develop and enhance children to their full potential. We use various tools and technologies, including Google Sheets integration and Meta’s messaging platforms (Facebook Messenger, Instagram Direct Messages, and WhatsApp Business) to manage our educational data, administrative processes, and customer communications efficiently.
2. Information We Collect
2.1 Educational Services Information
- Student Information: Names, ages, contact details, educational progress
- Parent/Guardian Information: Names, contact details, emergency contacts
- Program Data: Enrollment information, attendance records, assessment results
- Communication Records: Emails, messages, and feedback
2.2 Google Account Data
When authorized staff members connect their Google accounts to our administrative systems, we may access:
- Google Sheets: Read, write, and modify spreadsheet data for administrative purposes
- Profile Information: Basic profile info (name, email address) for authentication
- Usage: Finding duplicate records, data synchronization, report generation
2.3 Social Media Messaging Data (NEW)
When you contact us via Facebook Messenger, Instagram Direct Messages, or WhatsApp Business, we collect:
- Profile Information: Your name, username/handle, profile picture as displayed on the platform
- Platform User ID: Unique identifier assigned by Meta (Facebook/Instagram ID or WhatsApp number)
- Message Content: Text messages you send to us
- Media Files: Images, videos, documents, or other files you share with us
- Conversation Metadata: Message timestamps, read receipts, delivery status
- Interaction Data: Button clicks, quick reply selections, story mentions (Instagram)
- Reaction Data: Emoji reactions to our messages (if applicable)
Platform-Specific Data:
- Facebook Messenger: Your Facebook Page-scoped ID (PSID), name from your Facebook profile
- Instagram: Your Instagram username, Instagram-scoped ID, story mentions
- WhatsApp: Your phone number (in international format), WhatsApp profile name
2.4 Automatically Collected Information
- Log data (IP address, browser type, access times)
- Website usage statistics
- Error logs and system performance metrics
3. How We Use Your Information
We use the collected information for the following purposes:
3.1 Educational Services
- Deliver and improve our education programs
- Track student progress and development
- Communicate with parents and guardians
- Generate reports and assessments
- Manage enrollment and attendance
3.2 Administrative Purposes
- Process and manage educational data efficiently
- Identify and remove duplicate records in our systems
- Synchronize data across our administrative tools
- Generate internal reports and analytics
- Maintain accurate student records
3.3 Social Media Messaging Communication (NEW)
We use messaging data from Messenger, Instagram, and WhatsApp to:
- Customer Support: Respond to inquiries about our programs, services, and enrollment
- Program Information: Provide details about courses, schedules, pricing, and availability
- Appointment Scheduling: Coordinate consultations, enrollment meetings, and program sessions
- Service Updates: Send important program updates, schedule changes, and announcements (with your consent)
- Lead Generation: Capture interest in our programs and follow up with prospective students/parents
- Automated Responses: Provide instant replies to common questions using chatbot technology
- Conversation History: Maintain context across multiple conversations for better service
- Quality Improvement: Analyze common questions to improve our programs and communication
- Feedback Collection: Gather feedback about your experience with our services
Messaging Window: For Instagram and WhatsApp, we can only send messages within 24 hours of your last message to us, unless you’ve explicitly opted in to receive updates or we’re using approved message templates.
3.4 Communication
- Send program updates and announcements
- Respond to inquiries and support requests
- Share student progress reports with parents
3.5 Legal Compliance
- Meet educational and legal obligations
- Protect the safety and wellbeing of children
- Comply with data protection regulations
4. Data Storage and Security
4.1 Security Measures
We implement industry-standard security measures to protect your data:
- Encrypted data transmission (SSL/TLS) for all platforms
- Secure credential storage with encryption
- Access controls limited to authorized staff only
- Regular security audits and updates
- Automated backup systems
- Meta Platform Security: Access tokens stored in encrypted environment variables
- Webhook Verification: All incoming messages verified using cryptographic signatures
- Two-Factor Authentication: Required for admin access to messaging systems
4.2 Data Location
Data is stored on secure cloud servers located in trusted data centers with appropriate security certifications. Messaging data from Meta platforms may be processed on Meta’s international servers as per their infrastructure requirements.
4.3 Data Retention
- Active student records: Retained during enrollment and for 2 years after program completion
- Administrative data: Retained as required by educational regulations
- Messaging conversations (Messenger/Instagram/WhatsApp): Active conversations retained for 90 days, archived conversations for 1 year for quality assurance and service improvement
- Deleted account data: Purged within 30 days of deletion request
- Backup data: Retained for 30 days, then permanently deleted
Parents/guardians can request deletion of data by contacting openmindagile@gmail.com or messaging “DELETE MY DATA” on any platform (subject to legal retention requirements).
5. How We Share Your Information
We do NOT sell personal information. We may share information only in these limited circumstances:
5.1 Educational Partners
We may share student information with:
- Qualified teachers and program instructors
- Educational consultants involved in program delivery
- Partner schools or institutions (with consent)
5.2 Service Providers
We may share data with trusted third-party service providers who assist in:
- Hosting and IT infrastructure
- Payment processing
- Communication tools
- Administrative software
- Meta Platforms Inc.: When you message us on Messenger, Instagram, or WhatsApp, your data is transmitted through and processed by Meta’s infrastructure. Meta’s use of this data is governed by their Privacy Policy: https://www.facebook.com/privacy/policy
- Messaging Platform Providers: We may use third-party tools for chatbot functionality, analytics, and customer relationship management (CRM) integration
These providers are contractually obligated to protect your data and use it only for specified purposes.
5.3 Legal Requirements
We may disclose information when required by law, such as:
- Responding to legal process or government requests
- Protecting child safety and welfare
- Complying with educational regulations
- Investigating fraud or security issues
5.4 Parental Consent
We obtain parental consent before sharing children’s information for purposes beyond normal educational operations.
6. Google API Services User Data Policy
OpenMindAgile’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Limited Use Disclosure: OpenMindAgile’s use and transfer of information received from Google APIs to any other app will adhere to Google API Services User Data Policy, including the Limited Use requirements.
What We Access:
- Google Sheets data for administrative purposes only (finding duplicates, data synchronization, report generation)
- Basic profile information for staff authentication
- No access to personal Gmail, Drive files, or other Google services unless explicitly needed
7. Meta Messaging Platforms User Data Policy (NEW)
OpenMindAgile’s use of Facebook Messenger, Instagram, and WhatsApp Business APIs complies with Meta’s Platform Policies and Terms of Service.
7.1 Platform Compliance
- Facebook Platform Policy: https://developers.facebook.com/policy
- Messenger Platform Policy: https://developers.facebook.com/docs/messenger-platform/policy
- WhatsApp Business Policy: https://www.whatsapp.com/legal/business-policy
7.2 What We Access via Meta APIs
- Messenger: Page-scoped user ID, name, profile picture, messages, message reactions, postbacks
- Instagram: Instagram-scoped user ID, username, messages, story mentions, comments (on our posts only)
- WhatsApp: Phone number, profile name, messages, message status (delivered/read)
7.3 Limited Use Requirements
We use Meta messaging data ONLY for:
- Providing customer support and responding to inquiries
- Delivering educational program information
- Scheduling and managing appointments
- Sending service updates with user consent
- Improving our messaging services and customer experience
We DO NOT:
- Sell messaging data to third parties
- Use messaging data for advertising purposes outside Meta’s platforms
- Transfer messaging data to any other app without explicit consent
- Use data for purposes unrelated to the services you requested
- Send unsolicited promotional messages (spam)
- Share your messages with unauthorized parties
7.4 Message Opt-In and Consent
How we obtain consent:
- Messenger/Instagram: By sending us a message first, you consent to us responding
- WhatsApp: By messaging our business number, you consent to receive responses
- Marketing Messages: We will explicitly ask for opt-in before sending promotional content
- Service Updates: You can opt-in to receive program updates and notifications
How to opt-out:
- Send “STOP” or “UNSUBSCRIBE” via message
- Block or unfollow our account
- Email us at openmindagile@gmail.com
- WhatsApp: Use the “Block” or “Report” feature
7.5 Automated Messaging (Chatbots)
We may use automated chatbot responses for:
- Initial greeting and welcome messages
- Common frequently asked questions (FAQs)
- Business hours notifications
- Quick replies and menu options
Human Escalation: You can always request to speak with a human team member by messaging “TALK TO HUMAN” or similar requests.
7.6 International Data Transfers (Meta Platforms)
When you use Messenger, Instagram, or WhatsApp to contact us, your messages are transmitted through Meta’s global infrastructure, which may include servers located outside Malaysia. Meta implements appropriate safeguards in compliance with international data protection standards.
8. Your Rights and Choices
8.1 Access and Control
Parents and guardians have the right to:
- Access: Request a copy of their child’s educational records and messaging conversation history
- Correction: Update or correct inaccurate information
- Deletion: Request deletion of data (subject to legal requirements)
- Portability: Receive educational records and conversation transcripts in a structured format
- Object: Object to certain processing activities
8.2 Revoking Google Access
Authorized staff can revoke OpenMindAgile’s access to their Google account at any time by:
- Visiting Google Account Permissions
- Finding OpenMindAgile in the list of connected apps
- Clicking “Remove Access”
8.3 Managing Messaging Permissions (NEW)
Facebook Messenger & Instagram:
- Open your conversation with OpenMindAgile
- Click/tap on our business name at the top
- Select “Block,” “Restrict,” or adjust notification settings
- Or visit Facebook App Settings to manage permissions
WhatsApp Business:
- Open WhatsApp and go to our chat
- Tap on our business name at the top
- Select “Block” or “Report” to stop all communications
- Or simply message us “STOP” to opt-out of non-essential messages
Request Message Data Deletion:
- Send “DELETE MY DATA” via any messaging platform
- Email openmindagile@gmail.com with “Messaging Data Deletion Request”
- We will confirm deletion within 14 days
8.4 Communication Preferences
You can opt out of non-essential communications by contacting us at openmindagile@gmail.com
9. Children’s Privacy
As an educational organization serving children, we take children’s privacy extremely seriously:
- We comply with all applicable children’s privacy laws and regulations
- We obtain parental consent for collection of children’s information
- We limit data collection to what is necessary for educational purposes
- We implement strict access controls to protect children’s data
- We provide parents with access to their children’s information
- We never sell or market children’s information to third parties
- Messaging Platforms: We do not allow children under 13 (or under 18 for WhatsApp) to message us directly. All communications should be initiated by parents/guardians.
Parents have the right to review, correct, or delete their child’s personal information at any time.
10. International Data Transfers
Your information may be transferred to and maintained on servers located outside of Malaysia, including:
- Google Cloud Services: For administrative data management
- Meta’s Global Infrastructure: For Messenger, Instagram, and WhatsApp communications
- Other Service Providers: As necessary for service delivery
We ensure appropriate safeguards are in place to protect your data in accordance with this Privacy Policy and applicable data protection laws.
11. Third-Party Links
Our website, messaging responses, or communications may contain links to third-party websites or services. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies.
12. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. We will notify you of material changes by:
- Posting the updated policy on this page with a new “Last Updated” date
- Sending email notification for significant changes
- Messaging notification: For changes affecting messaging services, we may notify you via Messenger, Instagram, or WhatsApp
Your continued use of our services after changes become effective constitutes acceptance of the revised policy.
13. Data Protection Rights
13.1 Malaysian Personal Data Protection Act (PDPA)
Under Malaysia’s PDPA, you have rights including:
- Right to access your personal data
- Right to correct inaccurate data
- Right to withdraw consent
- Right to limit processing
- Right to data portability
- Right to opt-out: Stop receiving marketing messages at any time
- Right to deletion: Request deletion of messaging conversation history
13.2 European Users (GDPR)
If you are in the European Economic Area (EEA), you have additional rights under GDPR, including the right to erasure (“right to be forgotten”) and rights related to automated decision-making and profiling.
14. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
OpenMindAgile
Email: openmindagile@gmail.com
Website: https://openmindagile.com
Address: No 40 Jalan Badminton 13/29, Seksyen 13, 40100 Shah Alam, Selangor DE, Malaysia
For Privacy Requests:
- Email: Subject line “Privacy Request” – Response within 14 days
- Messaging Platforms: Send “PRIVACY REQUEST” via Messenger, Instagram, or WhatsApp
- Phone: [Your phone number if you want to add]
Data Protection Officer Contact:
Email: privacy@openmindagile.com (or use main email above)
Malaysian Personal Data Protection Department:
Website: https://www.pdp.gov.my
Phone: 03-8911 7000
For complaints or inquiries about data protection in Malaysia
15. Consent
By enrolling in OpenMindAgile programs, using our services, or contacting us via Messenger, Instagram, or WhatsApp, parents/guardians consent to the collection, use, and disclosure of information as described in this Privacy Policy.
Specific Messaging Consent: By initiating a conversation with us on any Meta messaging platform (Facebook Messenger, Instagram, WhatsApp), you explicitly consent to:
- Us collecting and processing your messages and profile information
- Receiving responses from our team or automated chatbot
- Your data being processed through Meta’s infrastructure
- Receiving service-related notifications within the 24-hour messaging window
Parents may withdraw consent at any time by contacting us, subject to legal and contractual restrictions.
This policy complies with Malaysia’s Personal Data Protection Act 2010, Google API Services User Data Policy, Meta Platform Policies, and applicable international data protection regulations.
Version 2.0 | Last Updated: October 12, 2025