WINNGOO MALAYSIA – PRIVACY POLICY
This Privacy Policy explains how Winngoo (“the Company”, “we”, “us”, or “our”) collects, uses, discloses, processes, stores and protects personal data of users in Malaysia in accordance with the Personal Data Protection Act 2010 (PDPA) and applicable subsidiary legislation and guidelines issued by the Malaysian Personal Data Protection Commissioner.
By:
- Accessing the Winngoo website or mobile application
- Creating an account
- Submitting personal information
- Using any services, tools, features or platforms provided by Winngoo
You acknowledge that you have read, understood and agreed to the terms of this Privacy Policy. If you do not agree with this Privacy Policy, you must immediately discontinue use of the Platform.
1. DEFINITIONS
1.1 “Personal Data” means any information that identifies or is capable of identifying an individual, whether directly or indirectly, including but not limited to name, identification number, contact details, online identifiers, financial information or any combination thereof.
1.2 “Sensitive Personal Data” includes information relating to:
- Religious belief
- Health condition
- Physical or mental condition
- Political opinions
- Criminal record
- Biometric or genetic data
And shall be processed strictly in accordance with PDPA requirements.
1.3 “Data Subject” means the individual to whom the personal data relates.
1.4 “Processing” means any operation or set of operations performed on personal data including collection, recording, storage, organisation, adaptation, retrieval, disclosure, erasure or destruction.
1.5 “Platform” refers to Winngoo websites, mobile applications, portals, subdomains and related digital infrastructure.
1.6 “Third Party” means any individual or entity other than the Data Subject and Winngoo, including service providers, partners or affiliates.
2. SCOPE AND APPLICATION
2.1 This Privacy Policy applies to:
- Website users
- Mobile application users
- Registered account holders
- Merchants, vendors or partners
- Support inquiries and communications
- Contest or campaign participants
2.2 This Privacy Policy covers:
- Data collected online
- Data collected offline
- Data collected automatically (cookies, device data)
- Data provided voluntarily by the user
2.3 This Privacy Policy does not apply to:
- Third-party websites linked from the platform
- External services integrated but not controlled by Winngoo
- Data processed independently by third-party controllers
Users are encouraged to review privacy policies of external websites and services before providing personal information.
3. LEGAL BASIS FOR PROCESSING PERSONAL DATA
Personal data is processed under one or more of the following lawful bases:
3.1 Consent
Processing occurs when the Data Subject has explicitly consented.
3.2 Contractual Necessity
Processing is necessary for:
- Performance of a contract
- Providing services requested by the User
- Taking steps at the User’s request before entering a contract
3.3 Legal Obligation
Processing is required to comply with:
- Tax obligations
- Regulatory reporting
- Anti-money laundering and counter-terrorism requirements
- Lawful government directives
3.4 Legitimate Interest
Processing is necessary for legitimate interests of Winngoo such as:
- Fraud detection
- Service improvement
- Network and information security
- Business operations
While ensuring such interests do not override user rights.
3.5 Vital Interest
Processing required to protect life, safety or health of an individual.
4. TYPES OF PERSONAL DATA COLLECTED
Winngoo may collect the following categories of data:
4.1 Identity Data
- Full name
- Username
- Identification documents (where legally permissible)
- Profile photographs
4.2 Contact Data
- Email address
- Phone number
- Postal or billing address
- Emergency contact information (if applicable)
4.3 Account and Profile Data
- Login credentials
- Preferences and settings
- Account history and activity logs
4.4 Transaction Data
- Purchase or subscription history
- Order records
- Payment confirmations
- Billing information (handled through secure processors)
4.5 Technical and Device Data
- IP address
- Browser type
- Device identifiers
- Operating system
- Mobile network information
4.6 Usage Data
- Clickstream data
- Features used
- Time spent on pages
- Interaction with advertisements
4.7 Communications Data
- Messages sent through the platform
- Customer support queries
- Complaint submissions
- Feedback or survey responses
4.8 Location Data
- Approximate geographical location
- GPS-based location (only where permission granted)
4.9 Sensitive Personal Data
Only collected where strictly necessary and with explicit consent, subject to PDPA restrictions.
5. METHODS OF DATA COLLECTION
We collect data:
5.1 Directly from the User
- Account registration
- Profile updates
- Subscription or purchase
- Fraud verification checks
- Communications with us
5.2 Automatically
Through use of cookies, pixels, beacons and analytic tools.
5.3 From Third Parties
Including:
- Business partners and affiliates
- Publicly available sources
- Service providers
- Governmental authorities (where lawful)
6. PURPOSES OF COLLECTING AND PROCESSING PERSONAL DATA
6.1 Winngoo collects and processes personal data for the following purposes, which may be applied individually or cumulatively:
- To create, manage and administer user accounts
- To verify identity and prevent impersonation
- To provide access to the Platform and its services
- To process transactions, purchases, bookings or subscriptions
- To facilitate communication between Winngoo and the User
- To perform data analytics, trend analysis and service optimisation
- To personalise content, recommendations and advertisements
- To administer rewards, loyalty or referral programmes
- To provide technical support or customer assistance
- To comply with statutory, regulatory and legal obligations
- To prevent, detect and investigate fraud or prohibited activities
- To enforce contractual terms, rights and remedies
- To conduct marketing, promotional or advertising activities
- To maintain records and conduct internal audits
- To develop new features, services and business strategies
6.2 Where the User provides personal data of third parties (for example, referrals, beneficiaries or contacts), the User represents and warrants that consent has been obtained from such individuals.
7. MARKETING, ADVERTISING AND COMMUNICATION PREFERENCES
7.1 Winngoo may use personal data to:
- Send service announcements
- Notify about account activity
- Inform of updates or policy changes
- Deliver newsletters, offers or promotions
7.2 Marketing communications may be delivered through:
- SMS or messaging applications
- Push notifications
- In-app messages
- Telephone calls (where permitted)
7.3 Users may choose to:
- Opt in or opt out of direct marketing
- Restrict certain channels of communication
- Withdraw consent at any time
7.4 Even after opting out of marketing messages, Users may still receive:
- Transactional emails
- Security alerts
- Service notifications
- Legal or policy-related notices
As these are necessary for Platform operation.
8. DISCLOSURE OF PERSONAL DATA TO THIRD PARTIES
8.1 Winngoo does not sell or rent personal data.
8.2 Personal data may be disclosed to the following categories of third parties, strictly for legitimate purposes:
- Payment processors and financial institutions
- IT and cloud service providers
- Authentication and identity verification partners
- Analytics and advertising service providers
- Logistics, courier or delivery partners (if applicable)
- Professional advisers such as auditors, lawyers or consultants
- Business partners or affiliates participating in service provision
- Dispute resolution, mediation or arbitration bodies
- Governmental authorities, enforcement agencies and regulators
8.3 Disclosure will only occur where:
- Consent has been obtained; or
- Disclosure is required by law; or
- Disclosure is necessary for performance of a contract; or
- Disclosure is required to protect Winngoo’s legal interests.
8.4 Third parties to whom data is disclosed shall be required, where practicable, to adhere to confidentiality and data protection obligations consistent with Malaysian PDPA principles.
9. CROSS-BORDER TRANSFER OF PERSONAL DATA
9.1 Personal data may be transferred to servers or service providers located outside Malaysia.
9.2 In such circumstances, Winngoo shall take reasonable steps to ensure that the receiving jurisdiction offers protection at least equivalent to that provided under the PDPA.
9.3 Safeguards may include:
- Contractual data protection clauses
- Intra-group transfer agreements
- Technical encryption measures
- Anonymisation or pseudonymisation of data
9.4 Users acknowledge that data stored or processed overseas may be subject to foreign laws and lawful access requests.
10. DATA RETENTION AND STORAGE PERIODS
10.1 Personal data will be retained only for as long as necessary to fulfil the purposes for which it was collected, including:
- Providing services
- Complying with legal or regulatory requirements
- Resolving disputes
- Enforcing agreements
10.2 Retention periods may be extended where:
- Required by tax, accounting or audit obligations
- Required for fraud monitoring or enforcement actions
- Relevant litigation or disputes are ongoing
10.3 Upon expiry of retention periods, personal data shall be:
- Anonymised; or
- Securely deleted or destroyed
In accordance with Winngoo’s internal data retention policies.
11. DATA SECURITY AND PROTECTION MEASURES
11.1 Winngoo implements reasonable administrative, technical and physical safeguards to protect personal data against:
- Loss
- Theft
- Misuse
- Unauthorised access
- Alteration
- Destruction
11.2 Examples of security controls may include:
- Password protection
- Access control restrictions
- Encryption technologies
- Firewalls and intrusion detection systems
- Monitoring and logging mechanisms
11.3 However, Users acknowledge that:
- No system is entirely immune from cyber-attacks
- Data transmitted over the internet may not be 100% secure
Therefore, Winngoo does not warrant absolute security but undertakes to act diligently and promptly in the event of suspected breaches.
11.4 In the event of a data breach affecting Users’ rights, Winngoo will:
- Assess the incident
- Take remedial actions
- Notify relevant authorities where required by law
- Communicate with affected Users where appropriate
12. CHILDREN’S AND MINORS’ PERSONAL DATA
12.1 The Platform is not intended for persons below the age of majority as defined under Malaysian law, unless consent is provided by a parent or legal guardian.
12.2 Winngoo does not knowingly collect personal data from minors without appropriate consent.
12.3 Parents or guardians who believe a minor has provided data may contact Winngoo to:
- Request deletion
- Limit processing
- Withdraw consent
13. RIGHTS OF DATA SUBJECTS
13.1 Under the Malaysian Personal Data Protection Act 2010, Users have the following rights, subject to applicable exemptions:
- The right to be informed of processing activities
- The right to access personal data held by Winngoo
- The right to request correction of inaccurate or incomplete data
- The right to withdraw consent to processing
- The right to object to direct marketing activities
- The right to restrict certain types of processing where permitted by law
13.2 All requests must:
- Be submitted in writing
- Contain sufficient information to verify identity
- Specify the data or processing in question
13.3 Winngoo reserves the right to:
- Charge a reasonable fee where allowed by PDPA
- Refuse manifestly frivolous or abusive requests
- Request additional information for verification purposes
13.4 Winngoo will respond within a reasonable time frame as prescribed under Malaysian law.
14. ACCESS AND CORRECTION REQUESTS
14.1 Users may request:
- A copy of personal data held by Winngoo
- Confirmation whether data is being processed
- Information relating to the source of the data, where applicable
14.2 Users may request correction where the data is:
- Inaccurate
- Incomplete
- Misleading
- Outdated
14.3 Upon verification, Winngoo will make the necessary corrections and notify relevant third parties where practicable.
15. WITHDRAWAL OF CONSENT
15.1 Users may withdraw consent to processing of personal data at any time.
15.2 Withdrawal of consent may result in:
- Restriction of access to services
- Suspension or termination of accounts
- Inability to complete transactions
15.3 Winngoo shall not be responsible for any loss or limitation of service arising from withdrawal of consent.
16. AUTOMATED DECISION-MAKING AND PROFILING
16.1 Winngoo may use automated systems for purposes such as:
- Fraud detection
- Transaction monitoring
- Risk scoring
- Service personalisation
16.2 Where automated processing has a significant impact on the User, reasonable human review mechanisms may be made available, subject to applicable law.
17. COOKIES AND TRACKING TECHNOLOGIES
17.1 The Platform uses cookies, pixels, tags and similar technologies to:
- Authenticate users
- Remember preferences
- Improve platform performance
- Analyse traffic patterns
- Deliver personalised advertising
17.2 Users can manage cookie preferences through:
- Browser settings
- In-app controls (where available)
17.3 Disabling cookies may affect the functionality, availability or performance of the Platform.
18. THIRD-PARTY WEBSITES, PLUG-INS AND SERVICES
18.1 The Platform may contain:
- External website links
- Embedded content
- Third-party applications
- Payment gateways
- Social media plugins
18.2 Winngoo does not control such third-party platforms and is not responsible for:
- Their privacy practices
- Content accuracy
- Data security management
18.3 Users are encouraged to review the privacy policies of third-party platforms prior to interacting or providing personal data.
19. BUSINESS TRANSFERS, MERGERS AND CORPORATE RESTRUCTURING
19.1 In the event of:
- Merger
- Acquisition
- Joint venture
- Restructuring
- Asset sale
- Insolvency or liquidation
Personal data may be transferred as part of the transaction.
19.2 Any such transfer will continue to comply with applicable data protection laws.
20. COMPLAINTS AND GRIEVANCE HANDLING
20.1 Users may submit complaints regarding:
- Misuse of personal data
- Unauthorised disclosure
- Dissatisfaction with response to data requests
20.2 Complaints shall be:
- Acknowledged within a reasonable period
- Investigated impartially
- Addressed in accordance with internal procedures
20.3 Users retain the statutory right to lodge complaints with the Malaysian Personal Data Protection Commissioner where dissatisfied.
21. ANONYMISATION AND AGGREGATED DATA
21.1 Winngoo may convert personal data into anonymous or aggregated form.
21.2 Such anonymised data:
- Cannot identify users
- May be used for research, analytics or reporting
- May be shared with partners or the public
21.3 Once anonymised, PDPA rights no longer apply to such data.
22. STORAGE LOCATION AND DATA TRANSFER SECURITY
22.1 Data may be stored in:
- Malaysia
- Other jurisdictions where service providers operate
22.2 Winngoo will implement safeguards including:
- Contractual clauses
- Encryption
- Restricted access protocols
To protect transferred data.
23. RECORDS OF PROCESSING ACTIVITIES
23.1 Winngoo maintains records of:
- Categories of personal data processed
- Purposes of processing
- Data sharing activities
- Security measures applied
- Retention periods
23.2 These records may be reviewed by regulators upon lawful request.
24. OBLIGATIONS OF USERS
Users agree to:
- Provide accurate personal data
- Update information when changes occur
- Keep login credentials confidential
- Avoid misrepresentation or identity misuse
25. NON-PROVISION OF PERSONAL DATA
25.1 Failure to provide required personal data may result in:
- Inability to register an account
- Restriction of service features
- Transaction failure
- Rejection of applications
26. AMENDMENTS TO THIS PRIVACY POLICY
26.1 Winngoo reserves the right to amend this Privacy Policy at any time.
26.2 Updates may be due to:
- Legal changes
- Regulatory guidance
- Business developments
- Technological advancements
26.3 Continued use of the Platform constitutes acceptance of the revised Policy.
27. LANGUAGE
27.1 This Privacy Policy may be issued in multiple languages.
27.2 In the event of inconsistency, the English version shall prevail, unless otherwise required by Malaysian law.
28. CONTACT DETAILS
Users may contact Winngoo regarding privacy matters through:
- Email: [insert email]
- Phone No: [insert number]