Version 1.0 - Draft for legal review. This notice is issued under section 7 of the Personal Data Protection Act 2010 (Malaysia) ("PDPA"). Section 7(3) requires the notice to be given in both the national language and English; the Bahasa Malaysia version follows the English text below and must be reviewed by counsel before publication.
This notice is issued by the operator of the AAU Club Manager platform ("we", "us", "the Platform"). Our registered legal name, company registration number and address are shown at the foot of this page once entered in the platform's privacy settings.
The Platform is used by sports clubs, academies, societies and other membership organisations ("Organisations") to manage their members, participants and parents. For the personal data an Organisation collects about you through the Platform, the Organisation is the data controller and we act as its data processor. For the data we collect to run the Platform itself (your login account, subscription billing, support, the affiliate programme), we are the data controller.
If your question is about how your club uses your information, contact the club first; its contact details are on its club page and in the club's own privacy notice where it has published one.
| Category | Examples | Collected from |
|---|---|---|
| Account & identity | name, email address, phone number, password (hashed), profile photo, language | you |
| Participant / member profile | name, preferred name, date of birth, gender, nationality, IC / passport number and images, address, school, T-shirt size, skill level, display ID | you, your parent/guardian, or your club |
| Guardian & emergency contact | parent/guardian name, phone and email; emergency contact name, relationship and phone | you or your club |
| Health information (sensitive personal data) | medical conditions, allergies, blood type - collected only where a club needs it to keep participants safe | you or your parent/guardian |
| Enrolment & activity | club and category enrolment, branch, attendance, check-in method and time, excuse letters / medical certificates, assessments, certificates, tournament entries and results | your club, coaches, you |
| Location (attendance) | your device's GPS position at the moment you check in, the distance from the venue, IP address and browser details of that request | your device, only when you use geolocation check-in |
| Billing | invoices, receipts, payment method, amount, payment reference, bank-transfer proof images, billing name/email/phone | your club, you, payment gateways |
| Coach verification | coaching certifications, IC/passport number and images, verification status | coaches |
| Communications | notifications, emails we send you, help-assistant conversations, contact-form messages | you |
| Technical | login history, session identifiers, device push tokens, audit-log entries about actions on your account, IP address | your device |
| Affiliate programme (if you join it) | IC number and images, selfie for identity verification, bank details for payouts, referral statistics | you |
We do not store card numbers or online-banking credentials. Card and FPX payments are entered directly with the payment provider (Stripe, Billplz, ToyyibPay or HerePay).
| Purpose | Basis under the PDPA |
|---|---|
| Creating and securing your account; signing you in | performance of the contract with you; our legitimate operation of the service |
| Enrolling participants, recording attendance, running sessions, assessments, tournaments and certificates | performance of the club membership contract; the club's legitimate activities |
| Health information | your explicit consent (section 40) - it is optional unless your club makes it a condition of participation for safety reasons, in which case the club will tell you |
| Identity verification (IC/passport) | the club's legitimate need to verify who its members are, and to prevent duplicate or fraudulent registrations |
| Geolocation check-in | your consent each time you allow your browser to share location; the alternative check-in methods do not require it |
| Invoicing, receipts, payment collection and reminders | performance of contract; legal obligations to keep accounting records |
| Essential service emails and notifications (verification, invoices, session changes, certificates) | performance of contract - these cannot be switched off while you have an account |
| Marketing emails from the Platform | your consent, which you can withdraw at any time |
| Showing a participant's name and photo on a club's public website or public tournament results | consent of the participant, or of the parent/guardian for a participant under 18 |
| Help assistant (AI) | your consent to let it look up your own account data; questions are processed by Google's Gemini API |
| Security, fraud prevention, audit logging | our legal obligation to protect personal data (section 9) and our legitimate interests |
| Complying with the law and responding to lawful requests | legal obligation |
Most participants on the Platform are under 18. Where a data subject is under 18, the PDPA Regulations require consent to be given by a parent or guardian. Parents and guardians manage their children's profiles, choose whether a child may appear on public pages, and can exercise all rights on the child's behalf from their Privacy Centre. A child's name and photo are not shown on any public page unless a guardian has recorded that choice.
We do not sell personal data.
Our hosting, media storage, email delivery, push notifications and AI assistant providers operate from outside Malaysia (principally the United States). We transfer personal data to them on the basis that the transfer is necessary to perform our contract with you and your Organisation, and under written contracts that require them to protect the data. Where the PDPA requires it, we carry out a transfer impact assessment before adding a provider. Details are in the sub-processor table.
We keep personal data only as long as needed for the purposes above and then delete or anonymise it. Key periods:
| Data | Retention |
|---|---|
| Account and participant profile | while the account is active; anonymised on a verified deletion request, or after a documented period of inactivity |
| Attendance, assessments, certificates | for the membership period plus the period the club needs for its records |
| Geolocation coordinates from check-in | 90 days, then deleted automatically |
| Invoices, receipts, payment records | 7 years (Income Tax Act 1967 s.82; Companies Act 2016 s.245), after which the billing name and contact details are redacted |
| Identity document images | until verification is complete and for the period the club's policy requires; the ID number and verification status are kept |
| Login history and audit log | 12 months |
| Help-assistant conversations | 180 days |
| Used password-reset / verification tokens | 30 days |
The full schedule is in our Data Retention Policy.
Data is encrypted in transit (TLS), stored with an established cloud provider, and protected by role-based access controls, tenant isolation between Organisations, rate-limited logins, audit logging of sensitive actions and encryption of payment-gateway credentials. Identity documents and payment proofs are only delivered to authorised users through short-lived links. We test these controls with automated tests. No system is perfectly secure; if we become aware of a breach that is likely to cause you significant harm we will notify the Commissioner and you as the law requires.
Under the PDPA you may:
You can exercise these from Privacy & Data in your account (Privacy Centre), which lets you download your data instantly, change your marketing and public-display choices, sign out other devices, and submit access, correction, deletion or other requests. We respond to access and correction requests within 21 days. We may need to verify your identity, or your relationship to a child, before acting. Requests about a club's records are routed to that club, which decides them as controller with our assistance.
Deleting an account anonymises it: identifying details are removed while invoices and receipts are kept for the legal retention period.
We use strictly necessary cookies (session, security, language). Optional analytics cookies are only set if you accept them on the cookie banner. See our Cookie Notice.
Privacy enquiries and requests: use the Privacy Centre or email the privacy contact shown at the foot of this page. If we have appointed a Data Protection Officer, their contact details are shown there too.
If you are not satisfied with our response you may complain to the Personal Data Protection Commissioner, Jabatan Perlindungan Data Peribadi (JPDP), Malaysia.
We version this notice. When we make a material change you will be asked to acknowledge the new version the next time you sign in, and previous versions remain available on this page.
Versi 1.0 - Draf untuk semakan undang-undang. Notis ini dikeluarkan di bawah seksyen 7 Akta Perlindungan Data Peribadi 2010 ("APDP").
Notis ini dikeluarkan oleh pengendali platform AAU Club Manager ("kami", "Platform"). Platform ini digunakan oleh kelab sukan, akademi, persatuan dan organisasi keahlian lain ("Organisasi") untuk mengurus ahli, peserta dan ibu bapa. Bagi data peribadi yang dikumpul oleh Organisasi anda melalui Platform, Organisasi tersebut adalah pengawal data dan kami bertindak sebagai pemproses data. Bagi data yang kami kumpul untuk mengendalikan Platform (akaun log masuk, bil langganan, sokongan, program affiliate), kami adalah pengawal data.
Akaun dan identiti (nama, e-mel, telefon, kata laluan yang dicincang, foto profil); profil peserta/ahli (nama, tarikh lahir, jantina, kewarganegaraan, nombor dan imej IC/pasport, alamat, sekolah); maklumat penjaga dan hubungan kecemasan; maklumat kesihatan (data peribadi sensitif) seperti keadaan perubatan, alahan dan jenis darah - hanya jika kelab memerlukannya untuk keselamatan peserta; pendaftaran, kehadiran, surat cuti/sijil sakit, penilaian, sijil dan keputusan pertandingan; lokasi peranti semasa daftar masuk kehadiran (jika anda memilih kaedah ini); bil dan pembayaran (invois, resit, kaedah bayaran, bukti pindahan bank); pengesahan jurulatih; komunikasi; data teknikal (sejarah log masuk, sesi, token peranti, log audit, alamat IP); dan, jika anda menyertai program affiliate, IC, swafoto dan butiran bank.
Kami tidak menyimpan nombor kad atau kelayakan perbankan dalam talian.
Mencipta dan melindungi akaun anda; pendaftaran, kehadiran, sesi, penilaian, pertandingan dan sijil; pengesahan identiti; invois dan kutipan bayaran; e-mel perkhidmatan yang penting; keselamatan dan log audit; mematuhi undang-undang. Maklumat kesihatan diproses dengan persetujuan nyata anda (seksyen 40). Lokasi diproses dengan persetujuan anda setiap kali anda membenarkan pelayar berkongsi lokasi. E-mel pemasaran, paparan nama dan foto peserta di laman web awam kelab, dan pembantu bantuan AI hanya dengan persetujuan anda, yang boleh ditarik balik pada bila-bila masa.
Bagi subjek data di bawah 18 tahun, persetujuan diberikan oleh ibu bapa atau penjaga. Nama dan foto kanak-kanak tidak dipaparkan di mana-mana halaman awam melainkan penjaga telah merekodkan pilihan tersebut di Pusat Privasi.
Kepada Organisasi anda (pentadbir dan, atas dasar keperluan, jurulatih dan kakitangan); pembekal perkhidmatan (sub-pemproses) yang disenaraikan dalam jadual di hujung notis ini; penyedia pembayaran apabila anda membayar melalui mereka; dan pihak berkuasa jika dikehendaki oleh undang-undang. Kami tidak menjual data peribadi.
Pengehosan, storan media, penghantaran e-mel, pemberitahuan tolak dan pembantu AI kami beroperasi dari luar Malaysia (terutamanya Amerika Syarikat). Pemindahan dibuat kerana perlu bagi melaksanakan kontrak dengan anda dan Organisasi anda, dan di bawah kontrak bertulis yang mewajibkan pembekal melindungi data.
Data disimpan hanya selagi diperlukan. Antaranya: koordinat lokasi daftar masuk - 90 hari; invois, resit dan rekod pembayaran - 7 tahun (Akta Cukai Pendapatan 1967 s.82; Akta Syarikat 2016 s.245), selepas itu nama dan butiran hubungan pengebilan disunting; sejarah log masuk dan log audit - 12 bulan; perbualan pembantu bantuan - 180 hari. Jadual penuh ada dalam Dasar Penyimpanan Data kami.
Penyulitan semasa penghantaran, kawalan akses berasaskan peranan, pengasingan data antara Organisasi, had kadar log masuk, log audit, penyulitan kelayakan gerbang pembayaran, dan penghantaran dokumen identiti serta bukti pembayaran hanya melalui pautan bertempoh kepada pengguna yang dibenarkan.
Anda boleh mengakses (s.30), membetulkan (s.34), menarik balik persetujuan (s.38), menghalang pemprosesan yang menyebabkan kerosakan atau kesusahan (s.42), menghentikan pemasaran langsung (s.43) dan mendapatkan salinan data dalam format boleh dibaca mesin (s.43A). Gunakan Privasi & Data dalam akaun anda. Kami membalas permintaan akses dan pembetulan dalam tempoh 21 hari. Pemadaman akaun dilakukan secara penamaan semula (anonimisasi); invois dan resit dikekalkan untuk tempoh penyimpanan undang-undang.
Kuki yang perlu sahaja digunakan secara lalai; kuki analitik pilihan hanya ditetapkan jika anda menerimanya.
Gunakan Pusat Privasi atau e-mel hubungan privasi di bahagian bawah halaman ini. Aduan boleh dibuat kepada Pesuruhjaya Perlindungan Data Peribadi, Jabatan Perlindungan Data Peribadi (JPDP).
Notis ini diversikan. Anda akan diminta mengakui versi baharu apabila terdapat perubahan penting.
Providers that process personal data on our behalf or receive it to deliver a service you use. Kept current from our sub-processor register.
| Provider | Purpose | Data involved | Location |
|---|---|---|---|
| Billplz | FPX / online banking payments (Malaysia) | Payer name, email, phone, amount | Malaysia |
| Cloudinary (media storage/CDN) | Stores uploaded images and files: profile photos, ID documents, payment proofs, certificates, club media | Uploaded files incl. identity documents of children and coaches | United States / global CDN |
| Google Analytics (optional, per SEO settings) | Web analytics when a GA ID is configured | Cookie IDs, pages viewed, device data | United States / global |
| Google Firebase Cloud Messaging | Push notifications to the Android/iOS app | Device push token, notification title/body (may include child name / invoice reference) | United States / global |
| Google Fonts / jsDelivr / cdnjs / Tailwind CDN | Static assets for the web UI | Visitor IP address and user agent (implicit in any CDN request) | Global CDN |
| Google Gemini API (help assistant) | Answers in-app help questions; can look up the asking user's own children and invoices | Question text; child names, display IDs; invoice numbers/amounts (DOB removed) | United States / global |
| Google Identity (OAuth sign-in) | "Sign in with Google" | Google account email, name, profile picture (at sign-in only) | United States / global |
| HerePay | Payment channel (Malaysia) | Payer name, email, phone, amount | Malaysia (confirm) |
| ipapi.co (IP geolocation) | Detect visitor country on the public marketing site to pick a default language | Visitor IP address | United States |
| Railway (app hosting + PostgreSQL) | Runs the application and hosts the primary database and backups | All platform data (every category in the data inventory) | United States (region to confirm in Railway project settings) |
| Resend (transactional email) | Delivers verification, billing, attendance, certificate and notification emails | Recipient name, email address, email content (may include invoice amounts, child names) | United States |
| Stripe | Card / FPX payment processing for club fees and platform subscriptions | Payer name, email, amount; card data is entered on Stripe and never stored here | United States / Singapore |
| ToyyibPay | FPX payments (Malaysia) | Payer name, email, phone, amount | Malaysia |