AAU Club Manager

Version 1.0 · Effective 15 Sep 2026 · Published 15 Sep 2026

Privacy Notice

Version 1.0 - Draft for legal review. This notice is issued under section 7 of the Personal Data Protection Act 2010 (Malaysia) ("PDPA"). Section 7(3) requires the notice to be given in both the national language and English; the Bahasa Malaysia version follows the English text below and must be reviewed by counsel before publication.

1. Who this notice is from

This notice is issued by the operator of the AAU Club Manager platform ("we", "us", "the Platform"). Our registered legal name, company registration number and address are shown at the foot of this page once entered in the platform's privacy settings.

The Platform is used by sports clubs, academies, societies and other membership organisations ("Organisations") to manage their members, participants and parents. For the personal data an Organisation collects about you through the Platform, the Organisation is the data controller and we act as its data processor. For the data we collect to run the Platform itself (your login account, subscription billing, support, the affiliate programme), we are the data controller.

If your question is about how your club uses your information, contact the club first; its contact details are on its club page and in the club's own privacy notice where it has published one.

2. What personal data we process

Category Examples Collected from
Account & identity name, email address, phone number, password (hashed), profile photo, language you
Participant / member profile name, preferred name, date of birth, gender, nationality, IC / passport number and images, address, school, T-shirt size, skill level, display ID you, your parent/guardian, or your club
Guardian & emergency contact parent/guardian name, phone and email; emergency contact name, relationship and phone you or your club
Health information (sensitive personal data) medical conditions, allergies, blood type - collected only where a club needs it to keep participants safe you or your parent/guardian
Enrolment & activity club and category enrolment, branch, attendance, check-in method and time, excuse letters / medical certificates, assessments, certificates, tournament entries and results your club, coaches, you
Location (attendance) your device's GPS position at the moment you check in, the distance from the venue, IP address and browser details of that request your device, only when you use geolocation check-in
Billing invoices, receipts, payment method, amount, payment reference, bank-transfer proof images, billing name/email/phone your club, you, payment gateways
Coach verification coaching certifications, IC/passport number and images, verification status coaches
Communications notifications, emails we send you, help-assistant conversations, contact-form messages you
Technical login history, session identifiers, device push tokens, audit-log entries about actions on your account, IP address your device
Affiliate programme (if you join it) IC number and images, selfie for identity verification, bank details for payouts, referral statistics you

We do not store card numbers or online-banking credentials. Card and FPX payments are entered directly with the payment provider (Stripe, Billplz, ToyyibPay or HerePay).

3. Why we process it and on what basis

Purpose Basis under the PDPA
Creating and securing your account; signing you in performance of the contract with you; our legitimate operation of the service
Enrolling participants, recording attendance, running sessions, assessments, tournaments and certificates performance of the club membership contract; the club's legitimate activities
Health information your explicit consent (section 40) - it is optional unless your club makes it a condition of participation for safety reasons, in which case the club will tell you
Identity verification (IC/passport) the club's legitimate need to verify who its members are, and to prevent duplicate or fraudulent registrations
Geolocation check-in your consent each time you allow your browser to share location; the alternative check-in methods do not require it
Invoicing, receipts, payment collection and reminders performance of contract; legal obligations to keep accounting records
Essential service emails and notifications (verification, invoices, session changes, certificates) performance of contract - these cannot be switched off while you have an account
Marketing emails from the Platform your consent, which you can withdraw at any time
Showing a participant's name and photo on a club's public website or public tournament results consent of the participant, or of the parent/guardian for a participant under 18
Help assistant (AI) your consent to let it look up your own account data; questions are processed by Google's Gemini API
Security, fraud prevention, audit logging our legal obligation to protect personal data (section 9) and our legitimate interests
Complying with the law and responding to lawful requests legal obligation

4. Children

Most participants on the Platform are under 18. Where a data subject is under 18, the PDPA Regulations require consent to be given by a parent or guardian. Parents and guardians manage their children's profiles, choose whether a child may appear on public pages, and can exercise all rights on the child's behalf from their Privacy Centre. A child's name and photo are not shown on any public page unless a guardian has recorded that choice.

5. Who we share personal data with

We do not sell personal data.

6. Transfers outside Malaysia

Our hosting, media storage, email delivery, push notifications and AI assistant providers operate from outside Malaysia (principally the United States). We transfer personal data to them on the basis that the transfer is necessary to perform our contract with you and your Organisation, and under written contracts that require them to protect the data. Where the PDPA requires it, we carry out a transfer impact assessment before adding a provider. Details are in the sub-processor table.

7. How long we keep it

We keep personal data only as long as needed for the purposes above and then delete or anonymise it. Key periods:

Data Retention
Account and participant profile while the account is active; anonymised on a verified deletion request, or after a documented period of inactivity
Attendance, assessments, certificates for the membership period plus the period the club needs for its records
Geolocation coordinates from check-in 90 days, then deleted automatically
Invoices, receipts, payment records 7 years (Income Tax Act 1967 s.82; Companies Act 2016 s.245), after which the billing name and contact details are redacted
Identity document images until verification is complete and for the period the club's policy requires; the ID number and verification status are kept
Login history and audit log 12 months
Help-assistant conversations 180 days
Used password-reset / verification tokens 30 days

The full schedule is in our Data Retention Policy.

8. How we protect it

Data is encrypted in transit (TLS), stored with an established cloud provider, and protected by role-based access controls, tenant isolation between Organisations, rate-limited logins, audit logging of sensitive actions and encryption of payment-gateway credentials. Identity documents and payment proofs are only delivered to authorised users through short-lived links. We test these controls with automated tests. No system is perfectly secure; if we become aware of a breach that is likely to cause you significant harm we will notify the Commissioner and you as the law requires.

9. Your rights

Under the PDPA you may:

You can exercise these from Privacy & Data in your account (Privacy Centre), which lets you download your data instantly, change your marketing and public-display choices, sign out other devices, and submit access, correction, deletion or other requests. We respond to access and correction requests within 21 days. We may need to verify your identity, or your relationship to a child, before acting. Requests about a club's records are routed to that club, which decides them as controller with our assistance.

Deleting an account anonymises it: identifying details are removed while invoices and receipts are kept for the legal retention period.

10. Cookies

We use strictly necessary cookies (session, security, language). Optional analytics cookies are only set if you accept them on the cookie banner. See our Cookie Notice.

11. Contact and complaints

Privacy enquiries and requests: use the Privacy Centre or email the privacy contact shown at the foot of this page. If we have appointed a Data Protection Officer, their contact details are shown there too.

If you are not satisfied with our response you may complain to the Personal Data Protection Commissioner, Jabatan Perlindungan Data Peribadi (JPDP), Malaysia.

12. Changes to this notice

We version this notice. When we make a material change you will be asked to acknowledge the new version the next time you sign in, and previous versions remain available on this page.


Notis Privasi (Bahasa Malaysia)

Versi 1.0 - Draf untuk semakan undang-undang. Notis ini dikeluarkan di bawah seksyen 7 Akta Perlindungan Data Peribadi 2010 ("APDP").

1. Siapa kami

Notis ini dikeluarkan oleh pengendali platform AAU Club Manager ("kami", "Platform"). Platform ini digunakan oleh kelab sukan, akademi, persatuan dan organisasi keahlian lain ("Organisasi") untuk mengurus ahli, peserta dan ibu bapa. Bagi data peribadi yang dikumpul oleh Organisasi anda melalui Platform, Organisasi tersebut adalah pengawal data dan kami bertindak sebagai pemproses data. Bagi data yang kami kumpul untuk mengendalikan Platform (akaun log masuk, bil langganan, sokongan, program affiliate), kami adalah pengawal data.

2. Data peribadi yang kami proses

Akaun dan identiti (nama, e-mel, telefon, kata laluan yang dicincang, foto profil); profil peserta/ahli (nama, tarikh lahir, jantina, kewarganegaraan, nombor dan imej IC/pasport, alamat, sekolah); maklumat penjaga dan hubungan kecemasan; maklumat kesihatan (data peribadi sensitif) seperti keadaan perubatan, alahan dan jenis darah - hanya jika kelab memerlukannya untuk keselamatan peserta; pendaftaran, kehadiran, surat cuti/sijil sakit, penilaian, sijil dan keputusan pertandingan; lokasi peranti semasa daftar masuk kehadiran (jika anda memilih kaedah ini); bil dan pembayaran (invois, resit, kaedah bayaran, bukti pindahan bank); pengesahan jurulatih; komunikasi; data teknikal (sejarah log masuk, sesi, token peranti, log audit, alamat IP); dan, jika anda menyertai program affiliate, IC, swafoto dan butiran bank.

Kami tidak menyimpan nombor kad atau kelayakan perbankan dalam talian.

3. Tujuan dan asas pemprosesan

Mencipta dan melindungi akaun anda; pendaftaran, kehadiran, sesi, penilaian, pertandingan dan sijil; pengesahan identiti; invois dan kutipan bayaran; e-mel perkhidmatan yang penting; keselamatan dan log audit; mematuhi undang-undang. Maklumat kesihatan diproses dengan persetujuan nyata anda (seksyen 40). Lokasi diproses dengan persetujuan anda setiap kali anda membenarkan pelayar berkongsi lokasi. E-mel pemasaran, paparan nama dan foto peserta di laman web awam kelab, dan pembantu bantuan AI hanya dengan persetujuan anda, yang boleh ditarik balik pada bila-bila masa.

4. Kanak-kanak

Bagi subjek data di bawah 18 tahun, persetujuan diberikan oleh ibu bapa atau penjaga. Nama dan foto kanak-kanak tidak dipaparkan di mana-mana halaman awam melainkan penjaga telah merekodkan pilihan tersebut di Pusat Privasi.

5. Pendedahan

Kepada Organisasi anda (pentadbir dan, atas dasar keperluan, jurulatih dan kakitangan); pembekal perkhidmatan (sub-pemproses) yang disenaraikan dalam jadual di hujung notis ini; penyedia pembayaran apabila anda membayar melalui mereka; dan pihak berkuasa jika dikehendaki oleh undang-undang. Kami tidak menjual data peribadi.

6. Pemindahan ke luar Malaysia

Pengehosan, storan media, penghantaran e-mel, pemberitahuan tolak dan pembantu AI kami beroperasi dari luar Malaysia (terutamanya Amerika Syarikat). Pemindahan dibuat kerana perlu bagi melaksanakan kontrak dengan anda dan Organisasi anda, dan di bawah kontrak bertulis yang mewajibkan pembekal melindungi data.

7. Tempoh penyimpanan

Data disimpan hanya selagi diperlukan. Antaranya: koordinat lokasi daftar masuk - 90 hari; invois, resit dan rekod pembayaran - 7 tahun (Akta Cukai Pendapatan 1967 s.82; Akta Syarikat 2016 s.245), selepas itu nama dan butiran hubungan pengebilan disunting; sejarah log masuk dan log audit - 12 bulan; perbualan pembantu bantuan - 180 hari. Jadual penuh ada dalam Dasar Penyimpanan Data kami.

8. Keselamatan

Penyulitan semasa penghantaran, kawalan akses berasaskan peranan, pengasingan data antara Organisasi, had kadar log masuk, log audit, penyulitan kelayakan gerbang pembayaran, dan penghantaran dokumen identiti serta bukti pembayaran hanya melalui pautan bertempoh kepada pengguna yang dibenarkan.

9. Hak anda

Anda boleh mengakses (s.30), membetulkan (s.34), menarik balik persetujuan (s.38), menghalang pemprosesan yang menyebabkan kerosakan atau kesusahan (s.42), menghentikan pemasaran langsung (s.43) dan mendapatkan salinan data dalam format boleh dibaca mesin (s.43A). Gunakan Privasi & Data dalam akaun anda. Kami membalas permintaan akses dan pembetulan dalam tempoh 21 hari. Pemadaman akaun dilakukan secara penamaan semula (anonimisasi); invois dan resit dikekalkan untuk tempoh penyimpanan undang-undang.

10. Kuki

Kuki yang perlu sahaja digunakan secara lalai; kuki analitik pilihan hanya ditetapkan jika anda menerimanya.

11. Hubungi dan aduan

Gunakan Pusat Privasi atau e-mel hubungan privasi di bahagian bawah halaman ini. Aduan boleh dibuat kepada Pesuruhjaya Perlindungan Data Peribadi, Jabatan Perlindungan Data Peribadi (JPDP).

12. Perubahan

Notis ini diversikan. Anda akan diminta mengakui versi baharu apabila terdapat perubahan penting.

Third-party service providers

Providers that process personal data on our behalf or receive it to deliver a service you use. Kept current from our sub-processor register.

ProviderPurposeData involvedLocation
BillplzFPX / online banking payments (Malaysia)Payer name, email, phone, amountMalaysia
Cloudinary (media storage/CDN)Stores uploaded images and files: profile photos, ID documents, payment proofs, certificates, club mediaUploaded files incl. identity documents of children and coachesUnited States / global CDN
Google Analytics (optional, per SEO settings)Web analytics when a GA ID is configuredCookie IDs, pages viewed, device dataUnited States / global
Google Firebase Cloud MessagingPush notifications to the Android/iOS appDevice push token, notification title/body (may include child name / invoice reference)United States / global
Google Fonts / jsDelivr / cdnjs / Tailwind CDNStatic assets for the web UIVisitor IP address and user agent (implicit in any CDN request)Global CDN
Google Gemini API (help assistant)Answers in-app help questions; can look up the asking user's own children and invoicesQuestion text; child names, display IDs; invoice numbers/amounts (DOB removed)United States / global
Google Identity (OAuth sign-in)"Sign in with Google"Google account email, name, profile picture (at sign-in only)United States / global
HerePayPayment channel (Malaysia)Payer name, email, phone, amountMalaysia (confirm)
ipapi.co (IP geolocation)Detect visitor country on the public marketing site to pick a default languageVisitor IP addressUnited States
Railway (app hosting + PostgreSQL)Runs the application and hosts the primary database and backupsAll platform data (every category in the data inventory)United States (region to confirm in Railway project settings)
Resend (transactional email)Delivers verification, billing, attendance, certificate and notification emailsRecipient name, email address, email content (may include invoice amounts, child names)United States
StripeCard / FPX payment processing for club fees and platform subscriptionsPayer name, email, amount; card data is entered on Stripe and never stored hereUnited States / Singapore
ToyyibPayFPX payments (Malaysia)Payer name, email, phone, amountMalaysia