About This Notice
Purpose
This notice describes how Klicktify Sdn Bhd (Company Registration No. 202601000123 (1456789-X)) ("Klicktify", "we", "us", or "our") collects, uses, discloses, and protects personal data in compliance with Malaysia's Personal Data Protection Act 2010 (Act 709) ("PDPA"), including the 2024 amendments that introduced the Personal Data Protection Officer (PDPO) role and breach-notification obligations. This notice is issued pursuant to Section 7 of the PDPA (Notification of Purpose and Identity).
This notice applies to all personal data processed by Klicktify in connection with its loyalty platform services in Malaysia. It complements our full Privacy Policy at /legal/privacy.
Legal Disclaimer
This notice has been prepared to the best of our knowledge and ability as a lay compliance statement. It does not constitute legal advice. The interpretation and application of the PDPA is subject to legal complexity and evolving regulatory guidance. We strongly recommend that you seek independent legal advice from a qualified Malaysian lawyer before treating this notice as definitive guidance on your own PDPA obligations. Klicktify accepts no liability for decisions made solely on the basis of this notice.
The 7 PDPA Principles and Klicktify's Compliance
Principle 1 — Notice and Choice (Section 6 of the PDPA)
The PDPA requires that data users (controllers) inform data subjects of the purpose for which personal data is collected before or at the time of collection.
How Klicktify complies: At the point of account creation or loyalty programme registration, we provide a clear notice of what data is collected, why it is collected, who it may be shared with, and how long it will be retained. This Privacy Policy and this notice fulfil this obligation. Members and Merchants are also informed of their right to withdraw consent and how to do so.
Principle 2 — Disclosure (Section 6 of the PDPA)
Personal data shall not be disclosed for any purpose other than the original purpose of collection without the data subject's consent.
How Klicktify complies: We disclose personal data only: (a) as necessary to provide the service (e.g., sharing Member data with the specific Merchant whose programme they joined); (b) to our authorised service providers acting as sub-processors (e.g., Stripe for payments, Neon for hosting, email delivery providers); or (c) as required by law. We do not sell personal data. Our sub-processors are bound by contractual data protection obligations equivalent to the PDPA. See our Privacy Policy (/legal/privacy) for full details.
Principle 3 — Purpose (Section 6 of the PDPA)
Personal data shall be collected only for a specific purpose, and personal data collected shall not be further processed in a way that is incompatible with that purpose.
How Klicktify complies: We collect personal data only for the purposes described in Section 3 of our Privacy Policy: service provision, account management, billing, security, and (with consent) marketing. We do not repurpose Member or Merchant data for secondary purposes incompatible with the original purpose of collection. Any new purpose would require fresh consent or a legitimate interest assessment.
Principle 4 — Security (Section 9 of the PDPA)
Data users must apply security measures to protect personal data against unauthorised access, loss, or destruction.
How Klicktify complies: See our Security Overview (/legal/security) for the full technical description. In summary: we encrypt data in transit (TLS) and at rest (AES-256); we use bcrypt for password hashing; we apply database access controls and row-level tenant isolation; we maintain audit logs; and we have a documented breach response procedure. Our security measures are reviewed and updated regularly.
Principle 5 — Retention (Section 9 of the PDPA)
Personal data shall not be retained longer than necessary for the purpose for which it was collected.
How Klicktify complies: We maintain a data retention schedule that defines retention periods for each data category. Personal data is deleted or anonymised when it is no longer required for its original purpose, subject to any legal or accounting retention obligations. For billing records, we retain data for 7 years in compliance with Malaysian tax law. See Section 8 of our Privacy Policy for the full retention schedule.
Principle 6 — Data Integrity (Section 9 of the PDPA)
Data users must take reasonable steps to ensure that personal data is accurate, complete, and not misleading.
How Klicktify complies: Members and Merchants can update most of their own profile data directly through the platform. We take reasonable steps to ensure data accuracy at the point of collection (e.g., format validation on email addresses and phone numbers). Merchants are responsible for ensuring that data they submit about their Members is accurate and not misleading. We comply with data correction requests within the time prescribed by the PDPA.
Principle 7 — Access (Section 7 of the PDPA)
Data subjects have the right to request access to their personal data and to correct any inaccurate or incomplete data.
How Klicktify complies: Data subjects can access and self-correct most of their personal data through their account settings. For requests that cannot be self-served, data subjects may contact privacy@klicktify.com. We will respond to access and correction requests within the period prescribed by the PDPA. A reasonable fee may be charged for access requests. See Section 10 of our Privacy Policy for full details on your rights.
Categories of Data Subjects and Personal Data
Merchant Account Holders
Data collected: name, business name, email address, phone number, business address, payment and billing information (via Stripe). Purpose: account creation, authentication, billing, and platform service delivery.
Member Account Holders
Data collected: name, email address, phone number, birthday (optional), points balance, tier status, check-in records, and reward redemption history. Purpose: loyalty programme participation, points calculation, reward redemption, and (with consent) marketing.
Visitors to klicktify.com
Data collected: IP address, browser type, device identifiers, pages visited. Purpose: platform operation, security, and (with consent) analytics.
Purposes of Processing
Primary Purposes
- Creating and maintaining Merchant and Member accounts.
- Authenticating users at sign-in and protecting against unauthorised access.
- Facilitating QR-based loyalty check-ins and points calculations.
- Managing tier progression and reward redemptions.
- Processing subscription billing via Stripe.
- Sending transactional notifications (points earned, rewards redeemed, tier upgraded).
- Providing Merchant dashboards and analytics.
- Ensuring platform security and preventing fraud.
Secondary Purposes (With Consent)
- Marketing communications about Klicktify features and promotions.
- Promotional communications from Merchants about their own programmes (sent on the Merchant's behalf).
- Platform improvement research (aggregated and de-identified data only).
Data Retention
Retention Schedule
Personal data is retained only for as long as necessary. Billing records are retained for 7 years to comply with Malaysian tax and accounting obligations. Member data is retained for the duration of the membership plus 2 years, after which it is deleted or anonymised unless a longer period is required by law. See Section 8 of our Privacy Policy for the full schedule.
Personal Data Protection Officer (PDPO)
Appointment and Role
In accordance with the 2024 amendments to the PDPA, Klicktify has appointed a Personal Data Protection Officer (PDPO) responsible for overseeing compliance with the PDPA, advising on data protection obligations, and serving as the point of contact for data subjects and the Personal Data Protection Commissioner (PDPC).
Contact the PDPO
For any matter relating to your personal data, your PDPA rights, or our data protection practices, please contact our PDPO at: dpo@klicktify.com.
Personal Data Breach Notification
Our Obligation
Pursuant to the 2024 PDPA amendments, Klicktify is required to notify the Personal Data Protection Commissioner (PDPC) and affected data subjects of any personal data breach that is likely to result in a risk to the rights and freedoms of individuals, without undue delay and in any event within 72 hours of becoming aware of the breach.
What We Will Do
- Assess the breach promptly upon discovery.
- Notify the PDPC within 72 hours if the breach meets the threshold.
- Notify affected data subjects directly where the breach is likely to result in high risk to their rights and freedoms.
- Document all breaches and remedial actions taken.
- Review and update our security measures following any breach.
Your Rights
Summary of Your Rights Under the PDPA
- Right to access: request a copy of your personal data.
- Right to correct: request correction of inaccurate or incomplete data.
- Right to withdraw consent: withdraw consent for processing based on consent at any time.
- Right to limit processing: request that we limit processing of your data in certain circumstances.
- Right to complain: make a complaint to the PDPC/JPDP if you believe we have contravened the PDPA.
How to Exercise Your Rights
Most data subject rights can be exercised directly through your account settings. For other requests, contact privacy@klicktify.com or our PDPO at dpo@klicktify.com. We will respond within the period prescribed by the PDPA. You may also contact the JPDP directly:
- Website: jpdp.gov.my
- Address: Jabatan Perlindungan Data Peribadi, Aras 6, Blok Pentadbiran, Presint 1, 62000 Putrajaya, Malaysia
Changes to This Notice
Updates
We may update this notice from time to time to reflect changes in our practices, the PDPA, or regulatory guidance. The updated notice will be posted at /legal/pdpa with a revised "Last Updated" date. Material changes will be communicated to affected data subjects.