01
Who we are
Bottega is a webinar funnel platform operated by GOATEDX (“GOATEDX”, “we”, “us”). We provide it by invitation to the speakers, coaches and businesses we work with (our “clients”). It includes the console at bottega.goatedx.com, the landing pages (“landers”) our clients publish with it, and the emails it sends.
This policy explains what personal data Bottega handles, why, who it is shared with and the choices you have. We handle personal data in line with Malaysia's Personal Data Protection Act 2010 (PDPA) and, where they apply to you, data protection laws such as the EU and UK General Data Protection Regulation (GDPR).
Questions or requests about your data can go to bottega@goatedx.com at any time.
02
Our two roles
How we handle data depends on whose data it is:
- Console users and site visitors. For people who use the Bottega console (GOATEDX staff and our clients' team members) and visitors to bottega.goatedx.com, GOATEDX decides how data is used. We act as the data user under the PDPA (the “controller” under the GDPR).
- Webinar registrants and lander visitors. When someone visits or registers on a client's lander, the client decides why that data is collected and how it is used. The client is the data user or controller. GOATEDX processes the data on the client's behalf as a data processor, following the client's instructions and this policy.
Registered for a webinar?
03
Information we collect
Console accounts
- Name, email address and, if you add one, a profile photo.
- Your password, which is stored only as a secure hash by our authentication provider. We never see it.
- The workspaces you belong to, your role (for example admin or viewer) and who invited you.
- Sign-in and security records, such as sign-in times, one-time links and codes sent, and a change log of what was edited in each workspace and by whom.
- Messages you send us for support.
Registrants and visitors on client landers
Collected on behalf of the client who runs the lander:
- Registration details: name, email address, WhatsApp or phone number, the session chosen, answers to any extra form questions, and a record that you ticked the consent box (with the time).
- Campaign and ad information: UTM parameters, ad click identifiers (such as
fbclid,gclidorttclid), and Meta campaign, ad set, ad and placement identifiers carried in the link you clicked. - Device information: browser, operating system and device type (from the user agent), screen width and similar technical signals used to tell people from bots.
- Approximate location: country, region and city, derived from your IP address by our hosting provider's network. We do not use precise GPS location.
- IP address: used briefly for security, rate limiting, bot filtering and (where the client has enabled it) Meta's Conversions API. We do not store raw IP addresses: we keep only a salted, one-way hash.
- Behavioural events: pages viewed, scroll depth, time spent on sections, button clicks, form interactions and form errors, engagement time, and which version of a page you saw in a split test.
- Webinar attendance: from Zoom, when the client connects it: whether you joined, join and leave times, and how long you stayed.
- Email activity: whether confirmation, reminder and other emails were delivered, bounced or marked as spam, opens and link clicks where measured, and unsubscribes.
Visitors to bottega.goatedx.com
The public Bottega site does not run advertising pixels or third-party analytics. Standard server logs (such as request time, page and a truncated or temporary IP record) are kept by our hosting provider for security and reliability. If you sign in, we use the cookies described below to keep you signed in.
04
How we use it
| Purpose | What it involves | Legal basis (where the GDPR applies) |
|---|---|---|
| Run the service | Accounts, sign-in, workspaces, landers, registration forms and the session a registrant chose. | Contract; for registrants, the client's basis |
| Webinar communication | Confirmation, reminder and follow-up emails and messages sent for the client, with unsubscribe handling. | Client's basis (consent or contract) |
| Attendance and reporting | Showing clients who registered, attended and engaged, and which pages and campaigns performed. | Legitimate interests of the client |
| Ad measurement | Sending conversion events to Meta, only when the client connects Meta. | Client's basis, usually consent |
| Security and abuse prevention | Bot filtering, rate limiting, fraud checks, audit logs and investigating incidents. | Legitimate interests; legal obligation |
| Support and service emails | Sign-in links and codes, invitations, password resets and security notices. | Contract; legitimate interests |
| Improving Bottega | Understanding how features are used so we can fix and improve them. | Legitimate interests |
| Legal compliance | Keeping records we must keep and responding to lawful requests. | Legal obligation |
We do not sell personal data, and we do not use registrant data for our own marketing or combine one client's registrants with another's.
06
Meta Conversions API
If a client connects their Meta (Facebook and Instagram) ad account, Bottega sends events such as page views and registrations from our server to Meta's Conversions API, alongside the browser pixel, so the client can measure and optimise their ads.
- Before sending, Bottega hashes identifiers with SHA-256: email, phone number, first and last name, city, country and a pseudonymous visitor ID.
- As Meta requires, the IP address and browser user agent are sent in their original form for matching. We send them to Meta but do not store the raw IP ourselves.
- The
_fbpand_fbcvalues and a shared event ID are included so Meta can remove duplicates between the pixel and the server event.
Meta processes this data under its own Business Tools terms and data policy. Clients who enable this are responsible for telling registrants and, where the law requires it, getting their consent.
08
International transfers
Bottega's database is hosted in Singapore, and some providers above process data in the United States and elsewhere. When personal data leaves Malaysia or your country, we rely on the transfer conditions allowed by the PDPA and, where the GDPR applies, on safeguards such as the providers' data processing agreements and standard contractual clauses. We only use providers with appropriate security and confidentiality commitments.
09
How long we keep data
- Console accounts: while your account is active. When access ends we delete or anonymise account data within a reasonable period, keeping only what we need for security, audit or legal reasons.
- Registrant and lander data: for as long as the client keeps it in their workspace, or as the client instructs. Clients can ask us to delete registrant data at any time. When a client relationship ends, we delete the client's workspace data within 90 days unless the client asks for an export first or the law requires us to keep it.
- Unsubscribe and bounce records: kept for as long as needed so we never email someone who opted out.
- Backups: removed on our providers' regular backup cycles.
10
Security
We protect personal data with safeguards suited to its sensitivity, including:
- Encryption in transit (HTTPS) and encryption at rest by our infrastructure providers.
- Database row-level security that keeps each client's workspace separate from every other client's.
- Role-based access: for example, viewers cannot see registrants' phone numbers.
- Salted hashing of IP addresses and SHA-256 hashing of identifiers sent to Meta.
- Integration tokens kept in an encrypted secrets vault, not in plain database columns.
- A change log of who edited what, one-time sign-in links and codes, and limited staff access.
No system is perfectly secure. If a data breach is likely to cause significant harm, we will notify affected clients, people and authorities as the law requires.
11
Your rights and choices
Depending on where you live, you can ask to:
- Access the personal data we hold about you and get a copy.
- Correct data that is inaccurate, incomplete or out of date.
- Withdraw consent you gave, for example to marketing emails. Every marketing email has an unsubscribe link.
- Limit how your data is processed, including stopping direct marketing.
- Where the GDPR or similar laws apply: delete your data, receive it in a portable format, object to processing based on legitimate interests, and restrict processing.
Email bottega@goatedx.com to make a request. We may need to confirm your identity first. We aim to respond within 21 days, as the PDPA requires for access and correction requests. If you registered through a client's lander, we will work with that client, who makes the final decision about their data.
You can also complain to a data protection authority, such as Malaysia's Personal Data Protection Commissioner or the authority in your country. We would appreciate the chance to help first.
12
Children
Bottega is a business tool and is not directed at children. Clients must not use landers to knowingly collect data from anyone under 18. If you believe a child's data has been collected, contact us and we will help remove it.
13
Short notice for registrants
If you registered for a webinar on a page powered by Bottega, here is the short version:
- Who is responsible: the webinar host named on the page. GOATEDX runs Bottega and processes your details for them.
- What is collected: your name, email, WhatsApp or phone number, your consent, how you found the page (such as the ad you clicked), your device, approximate location and how you used the page. Your IP address is only stored as a one-way hash.
- Why: to register you, send your webinar link and reminders, record attendance, measure which ads and pages work and keep the page secure.
- Who receives it: the host and their team, GOATEDX, and service providers such as Supabase, Vercel, Resend, Zoom and, if the host uses it, Meta (with your identifiers hashed).
- Your choices: unsubscribe from any email, and ask the host or bottega@goatedx.com to access, correct or delete your data.
Suggested consent line for landers
I agree that [Host name] may use my details to send my webinar access, reminders and related updates by email and WhatsApp, and to measure its ads. Bottega by GOATEDX processes this data for [Host name]. Privacy notice: bottega.goatedx.com/privacy#registrants
14
Changes and contact
We may update this policy as Bottega and the law change. We will change the “last updated” date above and, for significant changes, tell console users by email or in the app.
Contact GOATEDX about privacy at bottega@goatedx.com.