Effective Date: 4 September 2026 Version: 1.0 (unified)
This is a single Privacy Policy covering two products operated by the same company:
SOURems — our web-based event management system for businesses and organisers. Product-specific terms are in Annex A.
SOUR — our mobile app for event networking, name card scanning, and ticketing. Product-specific terms are in Annex B.
Part 1 applies to both products. Read Part 1, then the Annex for the product you use. Where an Annex says something more specific than Part 1, the Annex applies to that product.
SOURems and SOUR are operated by 413 Labs Sdn Bhd (Company No. 202601003992), trading as FOT Labs ("we", "us", "our"), a private limited company incorporated in Malaysia. We are the data user responsible for the personal data described in this policy.
By using either product you consent to the practices described here. If you do not agree, please do not use our services.
"Organiser" or "Host" means a business, company, or individual who uses our products to create, manage, or run events.
"Attendee" means an individual who registers for, purchases a ticket to, or attends an event powered by our products.
"User" means anyone who uses either product in any capacity.
"Personal Data" means information that can identify an individual, directly or indirectly.
"Platform" means the SOURems website and web application, the SOUR mobile app, and all related services.
Across both products we may automatically collect:
Device information — browser or device model, operating system, app version, language, time zone
IP address and approximate location derived from it
Usage data — pages or screens viewed, features used, time spent, interactions
Diagnostic data — crash reports and performance logs
Cookies and similar technologies (web) or device identifiers and push tokens (app) — see the relevant Annex
Purpose | What this involves |
|---|---|
Service delivery | Providing and maintaining the Platform, managing accounts, running events, processing registrations, issuing tickets, enabling check-in |
Payments | Processing ticket payments, calculating and deducting platform fees, paying out to Organisers, handling refunds and chargebacks |
Communication | Sending transactional messages — confirmations, tickets, reminders, account and security notices |
Marketing | Sending news and product updates only where you have consented; see Section 9 |
Analytics and reporting | Providing Organisers with insights on event performance and engagement |
AI features | Generating reports and insights from aggregated, de-identified data — see Annex A, Section A4 |
Safety and security | Detecting and preventing fraud, abuse, and unauthorised access; verifying Organiser identity before payouts |
Platform improvement | Analysing aggregated usage to fix problems and improve features |
Legal compliance | Meeting obligations under tax, accounting, anti-money-laundering, and other applicable law |
We do not sell your Personal Data.
We do not use your Personal Data, scanned contacts, or event data to train any artificial intelligence or machine learning model, whether ours or a third party's.
With Organisers. When you register for an event, the Organiser receives your registration details. Organisers are responsible for their own use of that data and their own compliance with applicable law. Contact the Organiser directly with questions about how they use it.
With other Users (SOUR only). Only what you choose to share — see Annex B.
With service providers. We engage third parties to operate the Platform, contractually bound to protect your data and use it only as we instruct:
Provider type | Purpose |
|---|---|
Payment processing | Fiuu (Razer Merchant Services Sdn Bhd) — collecting payments and making payouts. Card details go directly to Fiuu and are never stored on our servers |
Cloud hosting | Storing and processing data securely |
Email and messaging | Delivering transactional and consented marketing messages |
AI service providers | Delivering AI features as described in Annex A, Section A4 |
Analytics and crash reporting | Understanding usage and diagnosing faults |
Authentication | Apple and Google, where you sign in with them |
For legal reasons. Where required by law, a court order, or a valid request from a regulator or law enforcement, or where necessary to establish or defend legal claims.
In a business transfer. If we are involved in a merger, acquisition, or sale of assets, your data may transfer. We will notify you before it becomes subject to a different privacy policy.
Location. Data is stored in secure hosting facilities in Malaysia and Singapore.
Transfers. Some service providers process data outside Malaysia. Where we transfer Personal Data across borders, we apply safeguards consistent with the Personal Data Protection Act 2010 and, where applicable, the General Data Protection Regulation.
Security. We apply encryption in transit and at rest, access controls limiting data to authorised personnel, secure development practices, regular backups, and periodic security review. No system is completely secure and we cannot guarantee absolute security.
We keep Personal Data only as long as needed for the purposes above, unless law requires longer. Product-specific retention periods are in each Annex. The following apply to both products:
Data | Retention |
|---|---|
Transaction, payout, and billing records | Seven (7) years, as required by Malaysian tax and accounting law, regardless of account status |
Identity verification records | As required by anti-money-laundering and regulatory obligations |
Diagnostic and usage logs | Up to 12 months |
Data after account deletion | Deleted or anonymised within 30 days, except records we must keep by law and backups overwritten on our normal cycle |
Under the Personal Data Protection Act 2010 and other applicable law you may:
Access — request a copy of the Personal Data we hold about you
Correct — ask us to fix inaccurate or incomplete data
Withdraw consent — withdraw consent to processing, including marketing, at any time
Limit processing — ask us to restrict processing in certain circumstances
Port — request your data in a structured, commonly used format, where technically feasible
Delete — request deletion of your account and associated data (SOUR users can do this in-app; see Annex B)
To exercise any right, email benjamin@fotlabs.xyz. We will respond within a reasonable period and as required by law.
If your question concerns data an Organiser collected through their own registration form, please contact that Organiser directly.
Transactional messages — confirmations, tickets, reminders, account and security notices — are part of the service and cannot be switched off while your account is active.
Marketing messages are sent only with your consent. You can withdraw it at any time via the unsubscribe link in any marketing email or by contacting us.
Our products are not intended for children under 13, and we do not knowingly collect their Personal Data. Users aged 13 to 17 may use SOUR only with the consent and supervision of a parent or guardian. Users must be 18 or over to create ticketed events, sell tickets, or receive payouts on either product. If you believe a child under 13 has given us data, contact us and we will delete it.
If a Personal Data breach occurs, we will investigate, contain, and remediate it promptly. Where required by applicable law and where the breach is likely to result in a risk to your rights and freedoms:
We will notify the relevant supervisory authority, including where applicable the Personal Data Protection Commissioner of Malaysia, within 72 hours of becoming aware of it, unless a longer period is permitted by law.
We will notify affected individuals without undue delay where the breach is likely to result in a high risk to them, describing the nature of the breach, likely consequences, and measures taken.
We will maintain a record of all Personal Data breaches.
Organisers acting as data users for Attendee data under their control are responsible for their own notification obligations. We will cooperate with them in good faith.
The Platform may link to third-party websites or services we do not operate. We are not responsible for their privacy practices. Review their policies before providing data.
We may update this policy. Changes will be posted here with a revised effective date. Where changes are material, we will notify you in-app, on the Platform, or by email before they take effect. Continued use after the effective date constitutes acceptance.
413 Labs Sdn Bhd (trading as FOT Labs) Company No. 202601003992 Email: benjamin@fotlabs.xyz
Applies to the SOURems web-based event management system. Read together with Part 1.
When you register for a SOURems account and use our services, we collect:
Full name and designation
Company or organisation name
Email address
Phone number
Billing and payment information
Payout details, where you sell tickets through the Platform: account holder name, bank name, bank account number or DuitNow ID, country, the organisation or individual name the account is held under, and a mobile number. These are collected solely to pay out ticket proceeds to you and to verify that the account belongs to you
Business address
Event-related data such as event details, schedules, operational records, and layouts
When you register for an event through SOURems, we collect:
Full name
Email address
Company or organisation name
Contact number
Payment details for ticket purchases — processed directly by our PCI-compliant payment processor and not stored on our servers. We retain only transaction metadata (transaction ID, amount, timestamp, ticket reference) for record-keeping, reconciliation, and refunds
Organisers may collect additional information through customisable registration forms. Those fields are configured at the Organiser's discretion; review the form carefully and contact the Organiser with questions about them.
SOURems uses cookies and similar technologies to remember preferences, authenticate users, analyse usage, and deliver relevant communications. You can control cookies in your browser settings; disabling some may affect Platform functionality.
SOURems uses AI to generate event reports, insights, and recommendations.
What we do:
Process aggregated event and performance data to generate insights for Organisers. Personally identifiable information is removed or pseudonymised before AI processing wherever technically feasible.
Engage third-party AI service providers as sub-processors for certain features.
What we do not do:
Use your Personal Data or Organiser data to train any AI or machine learning model, ours or anyone else's.
Sell, license, or share AI-derived insights about you or your events with third parties for advertising or marketing.
Use AI to make automated decisions with legal or similarly significant effects on any individual. AI outputs are advisory and reviewed by human users.
SOURems includes a directory of third-party vendors. If you contact a vendor through the Marketplace, the details you provide go to that vendor, who is responsible for their own handling of your data.
Data | Retention |
|---|---|
Attendee and event data | Three (3) months after the event concludes |
Organiser account data | Duration of the account, plus three (3) months after termination |
Transaction, payout, and billing records | Seven (7) years — see Part 1, Section 7 |
Applies to the SOUR app for iOS and Android. Read together with Part 1. This Annex is the privacy disclosure for the app for the purposes of the Apple App Store and Google Play.
Account — name, email address, phone number, and either a hashed password or an authentication token from Sign in with Apple or Google Sign-In.
Profile and your Contact Card — job title, company, profile photo, social or website links, and any other details you add.
Host information (if you create ticketed events):
Business or trading name and SSM registration number, where applicable
NRIC or passport number, used to verify your identity before you can sell tickets
Bank account details or DuitNow ID for payouts, and the account holder name returned by the bank when we verify it
Identity verification documents (such as an NRIC photo), where further verification is required
The refund policy and contact method you list on your event page. This contact method is visible to anyone viewing your event, so attendees can reach you about refunds
Event information — events you create (titles, descriptions, dates, venues, images, ticket types), events you register for or attend, and your answers to any Host registration questions.
When you use Card Scan, we collect the photograph of the physical name card and the details extracted from it — typically the cardholder's name, job title, company, phone, email, and business address.
This is another person's Personal Data. See Section B5.
Card or bank details for ticket purchases are collected and processed directly by Fiuu. We never receive or store full card numbers, CVVs, or online banking credentials. We keep only transaction metadata (reference, amount, method type, timestamp, ticket) for records, refunds, and disputes.
Permission | Why we ask |
|---|---|
Camera | Scanning name cards and QR codes at check-in |
Photo library | Uploading a profile or event image, or scanning a card from an existing photo |
Notifications | Event reminders, confirmations, and card-trade alerts |
Location (optional) | Showing events near you, only if you enable it |
We also collect a device or installation identifier and, if you enable notifications, a push token. We do not collect precise GPS location unless you grant permission for a feature that needs it.
Scanning someone's card. You are collecting that person's Personal Data. You are responsible for having their permission — normally satisfied by them handing you their card — and for using it only for genuine networking, not marketing lists, resale, or unsolicited messages. We process it on your behalf.
Trading your card. When you share your Contact Card with another User, they receive a copy that belongs to their account. We cannot recall a card once shared. Deleting your account does not remove copies other Users already hold; ask them directly.
If your details are in the app and you are not a User. Email benjamin@fotlabs.xyz and we will take reasonable steps to locate and delete the record, and where appropriate notify the User holding it. You do not need an account to make this request.
Only what you choose: your Contact Card when you trade it, and your name on a Host's attendee list.
We use analytics to understand usage and diagnose faults. We do not use third-party advertising trackers and do not track you across other companies' apps or websites for advertising. If we ever introduce tracking that requires it, we will ask via Apple's App Tracking Transparency prompt first.
Settings → Account → Delete Account, or email benjamin@fotlabs.xyz.
Your profile, saved contacts, event history, and Contact Card are deleted or anonymised within 30 days. Deletion is permanent. Transaction and payout records we must legally keep survive, as do any Contact Card copies already held by other Users. If you are a Host with an upcoming event or a pending payout, contact us first so we can settle those.
Data | Retention |
|---|---|
Account, profile, and Contact Card | While your account is active |
Your saved contacts (scanned cards) | While your account is active — not deleted on a schedule |
Cards you have shared | Held in the recipient's account, under their control |
Event and registration history | While your account is active |
Transaction, payout, and billing records | Seven (7) years — see Part 1, Section 7 |
This Privacy Policy was last updated on 4 September 2026.
© 413 Labs Sdn Bhd, trading as FOT Labs. All rights reserved.