Skip to content

Event access

On Request

AIMY Smart Face

Register once, then walk in.

Face-recognition check-in for conferences, town halls and corporate events. Attendees enrol once at registration and walk through on every later entry — with the explicit consent, retention limits and fallback route that biometric data legally requires in Malaysia.

  • Enrol once; every entry after that is walk-through
  • A template is stored, and it expires on the schedule you set
  • Anyone who declines checks in the ordinary way, always

What deployments look like

Walk-through
entry after a single enrolment
no badge to find, no list to search
Explicit consent
recorded before any face is enrolled
required by law, not a configuration option
Deletion
is the default at the close of the event
retention is set by you, not by us
The problem

The queue at the door is the first thing anyone experiences.

Six hundred people arriving inside twenty minutes, three laptops, and a list being searched by surname. The badge printer jams. Somebody spells their own name differently from how they registered. The event has not started and it is already running late.

  • Manual check-in scales by adding staff and laptops, which is the wrong curve.
  • Badge scanning still requires the attendee to find and present the badge.
  • Nobody can say how many people are actually in the room at any moment.
  • Off-the-shelf face systems treat biometric data casually — which, since 2025, is a legal problem in Malaysia and not just a bad look.
Capabilities

What AIMY Smart Face actually does.

Enrol once, at registration

A photograph taken at the desk or supplied with the registration. That is the whole of the attendee's effort.

A template, not an album of faces

What the system holds for matching is a mathematical template rather than the photograph, and the photograph itself can be discarded once enrolment is complete.

Explicit consent, recorded

Biometric data is sensitive personal data under the amended PDPA, which means explicit consent — not a notice on a poster. Enrolment does not proceed without it, and the record is part of the audit trail.

A fallback that genuinely works

Anyone who declines, and anyone the system does not match, checks in by name or QR code. A consent regime where refusing is impractical is not consent.

Live headcount

Who is in the room, right now — for capacity, for safety, and for the sponsor who wants to know how many people saw their session.

Deletion on a schedule

Templates expire when you say, and the default is deletion at the close of the event. Keeping biometric data indefinitely is a decision, and it should have to be made deliberately.

How it works

From consent to deletion, and what happens in between.

  1. 01

    Agree the basis

    What is collected, why, how long it is kept, and what the alternative route is. This happens before any hardware is ordered.

  2. 02

    Consent and enrol

    At registration: explicit consent recorded, one photograph, template created, photograph discarded if that is your policy.

  3. 03

    Deploy on site

    Cameras at the entry points and an appliance in the venue. It runs with no outbound connection where the venue requires it.

  4. 04

    Walk in

    Attendees walk through. Matches are logged; non-matches are handed to the desk rather than left at the door.

  5. 05

    Delete

    At the retention point you set, templates and logs are destroyed, and you get the record showing it happened.

Technical profile

Deployment
On-site appliance · Customer VPC · Managed cloud
Enrolment
A photograph at the registration desk, or supplied in advance
Stored
Face template for matching; the source photograph can be discarded at enrolment
Fallback
Name or QR check-in, always available and never slower than the main desk
Reporting
Live headcount, entry times, exportable attendance record
Retention
Configurable, defaulting to deletion at the close of the event

Security & data handling

  • Biometric data is sensitive personal data under the amended PDPA — explicit consent is required, and it is recorded
  • A matching template is stored rather than the photograph, which can be discarded at enrolment
  • A non-biometric check-in route is always available to anyone who declines
  • Retention is configurable and defaults to deletion at the close of the event
  • Runs on-site with no outbound connection where the venue requires it
  • Full enrolment, consent and access log, exportable for audit
Questions

The ones procurement always asks.

Something not covered here? Ask directly — you will get a straight answer, including when the answer is that we are not the right fit.

Ask us
Is face recognition lawful in Malaysia?

Yes, with the right basis. The Personal Data Protection (Amendment) Act 2024 brought biometric data — including facial recognition data — within the definition of sensitive personal data, which requires explicit consent and stricter security. That is the design constraint this product starts from rather than one it works around.

What if an attendee refuses?

They check in the ordinary way, and it is not made slower or more awkward as a nudge. If declining is impractical, the consent was not real, and a regulator will see it the same way.

What is actually stored?

A mathematical template used for matching, plus the consent record and the entry log. The source photograph can be discarded the moment enrolment completes. Templates are not a general-purpose face database and are not shared between events unless you explicitly ask for that.

What happens after the event?

By default, templates and logs are deleted at the close of the event and you receive the record of the deletion. Keeping them longer is possible, but it is a deliberate decision with a stated purpose and retention period.

Is this part of AIMY Expert?

No. It is a separate application sharing the brand and the deployment options. It does not touch your document corpus.

Sectors where AIMY Smart Face is deployed

Next step

Tell us about the door, and about your lawyer.

Two conversations happen at once with this one: how many people arrive in how many minutes, and what your data protection officer needs to see before anyone is enrolled. We would rather have both early.