๐ฌ๐ง Privacy Notice โ RevoTraders
Last updated: 19 July 2026 ยท Effective: 19 July 2026 ยท Contact: admin@example.com
This notice satisfies the PDPA 2010 (Amd. 2024) Notice & Choice Principle and is provided in both English and Bahasa Malaysia as required by the JPDP Personal Data Protection Standard 2015.
1. Who we are
RevoTraders ("we", "us", "our") operates an online platform for managing membership subscriptions to a trading-education community delivered via Telegram. Under the Personal Data Protection Act 2010, as amended by Act A1727 (2024) (PDPA), RevoTraders is the Data Controller for personal data collected through this platform.
2. What personal data we collect
| Category | Examples | Why |
|---|---|---|
| Account & contact | name, email, phone, Telegram username/chat ID | identification, delivery, support |
| Payment & transaction | transaction reference, amount, currency, status, masked card details from gateway | subscription, fraud, accounting |
| Membership & access | products you have access to, expiry, renewal history | grant/revoke Telegram access, send reminders |
| Usage & communications | Telegram messages to our bot, support emails, broadcast engagement | service delivery, support, abuse prevention |
| Technical | IP, browser type, last login, session metadata, server logs (no PII) | security, abuse investigation, debug |
We do not collect sensitive personal data as defined by the PDPA 2024 โ no health, biometric, religious/belief, political-opinion, or offence data.
3. How we use it
- Process your subscription and payment for our products.
- Grant you access to the relevant Telegram groups and channels.
- Send renewal reminders, payment confirmations, and service announcements.
- Customer support and respond to your enquiries.
- Prevent fraud, abuse, and unauthorised access.
- Meet our legal, accounting, and tax obligations.
- Improve the platform (using only aggregated/anonymised data where possible).
We will not use your personal data for direct marketing of third-party products without your separate, explicit consent.
4. Disclosure to third parties (sub-processors)
We do not sell your personal data. We share it only with the sub-processors listed in our Sub-Processor Register โ payment gateways, cloud host, Telegram (for delivery), and the email/SMS service if you opt in. Each sub-processor is bound by a data-processing agreement that limits use to our documented instructions.
Cross-border transfer: some sub-processors (Telegram Bot API, Google Fonts, CHIP Collect Asia) may process your data outside Malaysia. We only use sub-processors whose jurisdiction provides protection comparable to the PDPA, per the 2024 cross-border transfer guidelines.
5. Your rights
You have the right to:
- Access a copy of the personal data we hold about you.
- Correct any data that is inaccurate, incomplete, or out of date.
- Delete your personal data (subject to legal retention).
- Port your data to another controller (new right under PDPA 2024).
- Withdraw consent at any time.
- Complain to the JPDP if you believe we have mishandled your data.
To exercise any of these rights, email admin@example.com. We respond within 30 days at no cost.
6. How long we keep your data
See our Retention & Deletion Policy. In short:
- Account data: life of account + up to 90 days after closure.
- Transaction records: 7 years (Income Tax Act 1967 / Companies Act 2016).
- Server logs: rolling 90 days.
- Backups: rolling 30 days, then rotated.
7. How we protect your data
See our Information Security Policy. Highlights:
- TLS 1.2+ on every public endpoint; HSTS preload.
- Encryption at rest for sensitive columns (payment data) and stored secrets.
- Passwords hashed with bcrypt (cost factor 12).
- Multi-factor authentication available for admin accounts.
- Restricted server access (MFA, least privilege) on production.
- Rate-limited login and webhooks; signed/verified payment webhooks.
- Centralised application logging; no PII or secrets in logs.
8. Breach notification
In the event of a personal-data breach that is likely to cause you significant harm, we will notify the Personal Data Protection Commissioner within 72 hours and notify you within 7 days of the Commissioner's notice. Our internal procedure is in our Breach Response Runbook.
9. Cookies
We use only session cookies required to keep you signed in and to protect against CSRF. We do not use analytics, advertising, or third-party tracking cookies.
10. Changes to this notice
We will update this notice if our practices change. The "Last updated" date will be revised, and for material changes (e.g. a new category of data collected) we will notify active members by email or in-product notice.
11. Contact
- Email: admin@example.com
- Address: [registered business address โ to be inserted by operator]
- DPO / Data Protection contact: [name + contact once appointed]
๐ฒ๐พ Notis Privasi โ RevoTraders
Kemaskini terakhir: 19 Julai 2026 ยท Berkuat kuasa: 19 Julai 2026 ยท Hubungi: admin@example.com
Notis ini memenuhi Prinsip Notis & Pilihan PDPA 2010 (Pindaan 2024) dan disediakan dalam Bahasa Melayu dan Bahasa Inggeris seperti yang diperlukan oleh Standard Perlindungan Data Peribadi JPDP 2015.
1. Siapa kami
RevoTraders ("kami") mengendalikan platform dalam talian untuk menguruskan langganan keahlian kepada komuniti pendidikan dagangan yang dihantar melalui Telegram. Di bawah Akta Perlindungan Data Peribadi 2010, pindaan oleh Akta A1727 (2024) (PDPA), RevoTraders ialah Pengawal Data untuk data peribadi yang dikumpulkan melalui platform ini.
2. Data peribadi yang kami kumpulkan
| Kategori | Contoh | Tujuan |
|---|---|---|
| Akaun & hubungan | nama, e-mel, telefon, nama pengguna/ID sembang Telegram | pengenalan, penghantaran, sokongan |
| Pembayaran & transaksi | rujukan transaksi, amaun, mata wang, status, butiran kad separa dari gerbang | langganan, anti-penipuan, perakaunan |
| Keahlian & akses | produk yang diakses, tarikh tamat, sejarah pembaharuan | beri/tarik balik akses Telegram, hantar peringatan |
| Penggunaan & komunikasi | mesej Telegram ke bot kami, e-mel sokongan, penglibatan penyiaran | penyampaian, sokongan, anti-penyalahgunaan |
| Teknikal | IP, jenis pelayar, log masuk terakhir, metadata sesi, log pelayan (tiada PII) | keselamatan, siasatan, nyahpepijat |
Kami tidak mengumpul data peribadi sensitif seperti ditakrifkan oleh PDPA 2024.
3. Bagaimana kami menggunakannya
- Memproses langganan dan pembayaran anda.
- Memberi akses kepada kumpulan/ saluran Telegram.
- Menghantar peringatan pembaharuan, pengesahan pembayaran, dan pengumuman perkhidmatan.
- Sokongan pelanggan dan menjawab pertanyaan.
- Mencegah penipuan, penyalahgunaan, dan akses tanpa kebenaran.
- Memenuhi obligasi undang-undang, perakaunan, dan cukai.
- Meningkatkan platform (data agregat/tanpa nama di mana boleh).
4. Pendedahan kepada pihak ketiga
Kami tidak menjual data peribadi. Kami berkongsi hanya dengan sub-pemproses yang disenaraikan dalam Daftar Sub-Pemproses kami. Setiap sub-pemproses terikat dengan perjanjian pemprosesan data yang mengehadkan penggunaan kepada arahan kami.
5. Hak anda
Anda berhak untuk:
- Mengakses salinan data peribadi anda.
- Membetulkan data yang tidak tepat atau lapuk.
- Memadamkan data peribadi (tertakluk kepada pengekalan undang-undang).
- Memindahkan data ke pengawal lain (hak baharu PDPA 2024).
- Menarik balik persetujuan.
- Mengadu kepada JPDP.
Untuk menggunakan hak ini, e-mel admin@example.com. Kami menjawab dalam 30 hari tanpa kos.
6. Berapa lama kami menyimpan data anda
Lihat Dasar Pengekalan & Pemadaman kami. Ringkasnya:
- Data akaun: hayat akaun + sehingga 90 hari selepas penutupan.
- Rekod transaksi: 7 tahun (kehendak cukai di Malaysia).
- Log pelayan: tatal 90 hari.
- Sandaran: tatal 30 hari.
7. Bagaimana kami melindungi data anda
Lihat Dasar Keselamatan Maklumat kami. Sorotan: TLS 1.2+, penyulitan semasa rehat, bcrypt 12, MFA untuk pentadbir, akses terhad, log masuk dan webhook kadar terhad, log tanpa PII.
8. Pemberitahuan pelanggaran
Sekiranya berlaku pelanggaran yang berkemungkinan menyebabkan kemudaratan ketara, kami akan memberitahu Pesuruhjaya dalam 72 jam dan memberitahu anda dalam 7 hari selepas notis Pesuruhjaya. Prosedur: Runbook Tindak Balas Pelanggaran.
9. Kuki
Kami hanya menggunakan kuki sesi (log masuk + CSRF). Tiada analitik, pengiklanan, atau kuki penjejakan pihak ketiga.
10. Perubahan pada notis ini
Kami akan mengemas kini notis ini jika amalan kami berubah. Tarikh "Kemaskini terakhir" akan disemak semula. Untuk perubahan material, kami akan memberitahu ahli aktif melalui e-mel atau notis dalam produk.
11. Hubungi
- E-mel: admin@example.com
- Alamat: [alamat perniagaan berdaftar โ untuk diisi oleh pengendali]
- Pegawai Perlindungan Data (DPO): [nama + hubungan sebaik sahaja dilantik]
Disclaimer: this notice is engineering evidence, not legal advice. It should be reviewed by a qualified Malaysian lawyer before relying on it in a dispute, audit, or regulator interaction. Penalty figures, notification timelines, and DPO thresholds are current as of 1 June 2025 (PDPA Amendment in full force) and 26 August 2024 (Cyber Security Act 2024) โ re-verify before each engagement. Source: malaysia-security-compliance-kit v1.4.0.