Effective Date: 11 SEPTEMBER 2025
Last Updated: 11 SEPTEMBER 2025
1. Introduction
Refine Au Sdn Bhd ("we", "us", "our") is committed to ensuring the privacy and protection of personal data of individuals ("you", "your") using our platform for gold trading services. We adhere to the provisions of the Personal Data Protection Act 2010 (PDPA) of Malaysia which governs the collection, processing, and storage of personal data.
This Privacy Policy explains:
- What personal data we collect
- How we collect and process it
- The purposes for which we use it
- To whom it may be disclosed
- Your rights under the PDPA
2. Scope
This policy applies to all users of our platform, including website visitors, registered users, and customers using our mobile app, customer service, or partner portals.
3. What Personal Data We Collect
3.1 Identification Data
- Full legal name
- National Registration Identity Card (NRIC) number or passport number
- NRIC/Passport photos (front and back)
- Selfie or biometric image for facial verification
- Date of birth
- Gender
- Nationality
3.2 Contact Details
- Residential address (as per NRIC or proof of address)
- Email address
- Mobile phone number
- Emergency contact details (if required)
3.3 Financial Information
- Bank account details (for payments and withdrawals)
- Transaction records (amount, time, reference ID)
- Tax identification number (if applicable)
3.4 Technical and Usage Information
- Device identifiers (IP address, device model, operating system)
- Geolocation data (if you enable location services)
- Browser type, access time, and pages viewed
- Log files and metadata
4. How We Collect Your Personal Data
- When you register and create an account on our platform
- When you upload documents for identity verification
- When you conduct gold transactions
- Through cookies and other automated technologies
- From third-party KYC/AMLA service providers
- From publicly available sources or authorities (for verification)
5. Purposes for Processing Personal Data
We process your personal data for the following primary and secondary purposes:
5.1 Primary Purposes
- To establish your identity and verify authenticity of documents
- To process buy and sell gold transactions
- To comply with Anti-Money Laundering (AMLA), Counter Financing of Terrorism (CFT), and Know-Your-Customer (KYC) obligations
- To maintain legal and regulatory compliance
- To fulfill contractual obligations
5.2 Secondary Purposes
- To send account-related notices and updates
- To provide customer service and dispute resolution
- To personalize and improve user experience
- For business analytics and product development
- To inform you about changes in our policies or services
6. Legal Basis for Processing
We only process your personal data where there is a legal basis, such as:
- Your consent (explicitly provided for document uploads and identity verification)
- Performance of a contract (e.g., executing your transaction request)
- Legal obligation (compliance with AMLA laws)
- Legitimate interests (to protect against fraud and misuse of the platform)
7. Disclosure of Your Personal Data
We may disclose your data to the following categories of recipients:
7.1 Internal Parties
- Employees (only those who require access for their role)
- Compliance officers and auditors
7.2 External Parties
- Government agencies (e.g., Bank Negara Malaysia, Royal Malaysian Police)
- Third-party KYC and identity verification providers
- Payment gateway providers and financial institutions
- Legal, tax, and regulatory consultants
- IT service and cloud hosting providers
All third parties are bound by strict confidentiality and data processing agreements in line with PDPA requirements.
8. International Transfers
If personal data is transferred outside Malaysia, we ensure:
- The receiving country has adequate data protection laws; or
- Your explicit consent is obtained; or
- A binding contract ensures the recipient complies with PDPA standards
9. Data Retention Policy
We retain your personal data:
- For as long as your account remains active
- As required by AML regulations (typically 6–7 years)
- Until legally permissible for audit, litigation, or tax purposes
Data that is no longer needed is securely deleted or anonymized.
10. Data Security Measures
We adopt industry-standard safeguards to protect your data:
- End-to-end encryption during data transmission
- Secure data storage with restricted access
- Regular vulnerability testing and security audits
- Multi-factor authentication (MFA) for admin access
- Logging and monitoring of all data access activities
11. Your Rights Under the PDPA
You have the following rights, subject to PDPA conditions:
- Right to Access – Request a copy of your personal data
- Right to Correction – Request correction of inaccurate or incomplete data
- Right to Withdraw Consent – Withdraw your consent to data processing
- Right to Prevent Processing for Direct Marketing
- Right to Complain – Lodge a complaint with the Personal Data Protection Department (JPDP)
To exercise these rights, please contact our Data Protection Officer (details below).
12. Use of Cookies and Tracking
We use cookies to:
- Maintain user session and login status
- Analyze traffic and user behavior
- Store preferences
You can disable cookies via browser settings, but some features may be limited.
13. Children’s Data
Our platform is not intended for individuals under the age of 18. We do not knowingly collect data from minors without verifiable parental consent.
14. Updates to This Policy
We may revise this policy to reflect changes in legal or operational requirements. You will be notified via email or platform notification when significant updates occur.
15. Contact Us
If you have any questions about this Privacy Policy, or wish to exercise your rights, please contact:
Name : Mr Hoong
Company Name : Refine Au Sdn Bhd
Company Address : 1, Jalan Selukat 33/27 Shah Alam Technology Park, Seksyen 33, 40400 Shah Alam, Selangor
Email: info@refineau.com.my
Phone: +6011-19999 755
Tarikh Berkuat Kuasa: 11 SEPTEMBER 2025
Kemaskini Terakhir: 11 SEPTEMBER 2025
Refine Au Sdn Bhd ("kami", "kita", "milik kami") komited untuk melindungi data peribadi anda selaras dengan Akta Perlindungan Data Peribadi 2010 (PDPA). Dasar Privasi ini menerangkan bagaimana kami mengumpul, memproses, menggunakan, dan melindungi data peribadi anda apabila anda menggunakan platform kami untuk jual beli emas.
1. Pengenalan
Dasar ini merangkumi semua pengguna platform kami termasuk pengguna laman web, aplikasi mudah alih, dan perkhidmatan pelanggan.
2. Data Peribadi yang Kami Kumpul
2.1 Maklumat Pengenalan
- Nama penuh (seperti dalam NRIC atau pasport)
- Nombor Kad Pengenalan (NRIC) atau pasport
- Gambar Kad Pengenalan (depan dan belakang)
- Gambar swafoto untuk pengesahan identiti
- Tarikh lahir, jantina, dan kewarganegaraan
2.2 Maklumat Perhubungan
- Alamat kediaman
- Nombor telefon bimbit
- Alamat e-mel
2.3 Maklumat Kewangan
- Maklumat akaun bank
- Rekod transaksi
- Nombor cukai pendapatan (jika berkenaan)
2.4 Maklumat Teknikal & Penggunaan
- Alamat IP
- Jenis peranti dan pelayar
- Lokasi geografi (jika diaktifkan)
- Log akses dan aktiviti pengguna
3. Cara Kami Mengumpul Data Peribadi Anda
- Apabila anda mendaftar akaun
- Apabila anda melakukan transaksi emas
- Melalui penyedia perkhidmatan pihak ketiga (contoh: KYC, e-KYC)
- Melalui kuki dan teknologi penjejakan
- Melalui pangkalan data umum atau pihak berkuasa jika perlu
4. Tujuan Pemprosesan Data Peribadi
Tujuan Utama
- Pengesahan identiti (KYC/eKYC)
- Pemprosesan pembelian dan penjualan emas
- Pematuhan dengan undang-undang Anti-Pengubahan Wang Haram (AMLA)
- Pelaksanaan kontrak jual beli
Tujuan Sekunder
- Memberi khidmat pelanggan
- Memberi makluman akaun dan transaksi
- Meningkatkan pengalaman pengguna
- Menyediakan bahan pemasaran (dengan kebenaran)
5. Asas Perundangan
Kami memproses data peribadi anda berdasarkan:
- Persetujuan anda
- Pelaksanaan kontrak
- Pematuhan undang-undang
- Kepentingan sah (legitimate interest)
6. Pendedahan Maklumat Peribadi
Kami boleh berkongsi data anda dengan:
- Badan kerajaan (contoh: Bank Negara Malaysia, PDRM)
- Penyedia perkhidmatan KYC/eKYC
- Penyedia sistem pembayaran
- Juruaudit, penasihat undang-undang, pembekal teknologi
Setiap pihak ketiga terikat dengan perjanjian sulit dan pematuhan PDPA.
7. Pemindahan Data ke Luar Negara
Sekiranya data anda dipindahkan ke luar Malaysia, kami akan memastikan:
- Negara tersebut mempunyai undang-undang perlindungan data yang setara; atau
- Anda memberi persetujuan jelas; atau
- Perjanjian pemindahan data yang sah dilaksanakan
8. Tempoh Penyimpanan Data
Kami akan menyimpan data anda:
- Selagi akaun anda aktif
- Untuk tempoh minimum yang dikehendaki oleh undang-undang (contoh: 7 tahun bagi pematuhan AMLA)
- Selepas itu, data akan dipadam atau dinyahidentiti secara selamat
9. Keselamatan Data Peribadi
Kami mengambil langkah keselamatan termasuk:
- Penyulitan (encryption) semasa pemindahan data
- Akses terhad kepada staf yang dibenarkan sahaja
- Pematuhan kepada piawaian keselamatan IT dan audit berkala
10. Hak Anda di bawah PDPA
Anda berhak untuk:
- Mengakses data peribadi anda
- Membetulkan maklumat yang tidak tepat
- Menarik balik persetujuan (tertakluk kepada syarat tertentu)
- Membantah pemprosesan untuk pemasaran langsung
- Membuat aduan kepada Jabatan Perlindungan Data Peribadi (JPDP)
Untuk mengemukakan permintaan, sila hubungi Pegawai Perlindungan Data kami.
11. Kuki dan Penjejakan
Kami menggunakan kuki untuk:
- Mengurus sesi log masuk
- Menganalisis trafik laman web
- Menyesuaikan pengalaman pengguna
Anda boleh menyahaktifkan kuki melalui tetapan pelayar anda.
12. Perlindungan Kanak-Kanak
Platform kami tidak ditujukan kepada individu di bawah umur 18 tahun. Kami tidak mengumpul data kanak-kanak secara sengaja.
13. Perubahan kepada Dasar Ini
Kami boleh mengemaskini Dasar Privasi ini dari semasa ke semasa. Sebarang perubahan akan diumumkan melalui platform kami.
14. Hubungi Kami
Untuk pertanyaan atau permintaan berkenaan Dasar Privasi ini, sila hubungi:
Nama: Encik Hoong
E-mel: info@refineau.com.my
Telefon: +6011-19999 755
Alamat: 1, Jalan Selukat 33/27 Shah Alam Technology Park, Seksyen 33, 40400 Shah Alam, Selangor
15. Bahasa Dasar
Dasar ini disediakan dalam Bahasa Malaysia dan Bahasa Inggeris. Sekiranya terdapat percanggahan, versi Bahasa Inggeris akan diguna pakai.
16. Persetujuan
Dengan menggunakan platform kami, anda bersetuju terhadap pengumpulan dan pemprosesan data peribadi anda sebagaimana yang dinyatakan dalam Dasar Privasi ini.