Back to SPLIX

Privacy Policy

Introduction & Scope

This Privacy Policy explains how SPLIX (“we,” “us,” “SPLIX”) collects, uses, discloses, and protects personal data through the SPLIX platform (the “Portal”), in accordance with the Personal Data Protection Act 2010 (“PDPA”) of Malaysia. SPLIX is operated by [Legal entity name], the data user responsible for the personal data described in this Policy.

This Policy applies to Players who book Venues through the Portal and to Merchants who list and manage Venues on the Portal.

Collection of Personal Data

We may collect and process personal data provided by users when they register an account, make a booking, submit enquiries, or interact with our portal. The types of personal data collected may include, but are not limited to:

  • Personal Identification Information — Such as full name, identification details (where applicable), date of birth, gender, and other information required for account verification or booking purposes.
  • Contact Information — Such as email address, phone number, residential address, or other communication details provided by users.
  • Account Information — Such as username, login credentials, account preferences, and profile information created during registration.
  • Booking Information — Such as booking details, selected venue, facility type, booking date and time, number of participants, booking status, cancellation records, and booking history.
  • Payment Information — Such as payment transaction details, payment method, payment status, invoices, and transaction records. We do not store complete payment card details; card data is handled directly by our payment gateway provider.
  • Device and Technical Information — Such as IP address, browser type, operating system, device information, access logs, and usage data collected when users access or interact with the portal.
  • Communication Records — Such as enquiries, feedback, support requests, and any correspondence submitted through the portal.
  • Merchant & Business Information (for Merchants only) — Such as business registration details, venue ownership or authorisation documents, bank account details for payouts, and identification documents collected during merchant onboarding and verification.

Purpose

We collect, use, and process personal data for purposes including, but not limited to, the following:

  • To create, verify, and manage user accounts.
  • To process, confirm, modify, and manage venue bookings.
  • To process payments, issue receipts, and maintain transaction records.
  • To communicate with users regarding bookings, payments, cancellations, updates, or important service announcements.
  • To respond to enquiries, feedback, complaints, and customer support requests.
  • To verify user identity where necessary and prevent fraudulent, unauthorised, or unlawful activities.
  • To maintain the security, integrity, and proper operation of the portal.
  • To analyse portal usage, improve system performance, and enhance user experience.
  • To generate operational, statistical, and management reports for internal business purposes.
  • To comply with applicable laws, regulations, court orders, or requests from authorised government or regulatory authorities.
  • To enforce our Terms and Conditions and protect the rights, property, and safety of users, the portal, and other parties where permitted by law.

Disclosure

We may disclose or share your personal data only where necessary and in accordance with applicable laws. Your personal data may be disclosed to the following parties:

  • Venue Operators (Merchants) — to facilitate and manage your Bookings at the relevant Venue.
  • Payment Service Providers — to process payments for Online-Collect Bookings.
  • Authorised Service Providers — such as cloud hosting, IT, SMS, and customer support providers who process data on our behalf.
  • Government Authorities and Regulatory Bodies — where required by law or a valid legal request.
  • Professional Advisers — such as auditors, lawyers, and accountants, where necessary.
  • Other Parties — in connection with a business transaction such as a merger, acquisition, financing, or sale of assets, where your data may be transferred as part of that transaction.

We require third parties who receive personal data on our behalf to protect such information, maintain its confidentiality, and use it only for the purposes for which it was disclosed and in accordance with applicable data protection laws.

Cross-Border Transfer of Personal Data

Some of our authorised service providers, including our payment gateway and cloud hosting providers, may store or process personal data outside Malaysia. Where this occurs, we will take reasonable steps to ensure such data receives a standard of protection comparable to that required under the PDPA, in accordance with Section 129 of the PDPA.

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to meet legal, accounting, or reporting requirements. As a general rule, we retain booking and payment records for 7 years from the date of the relevant transaction, in line with standard record-keeping obligations under Malaysian law. Once personal data is no longer required, we will take reasonable steps to securely delete or anonymise it.

Security

We implement reasonable administrative, technical, and organisational security measures to protect personal data against unauthorised access, disclosure, alteration, misuse, loss, or destruction.

These measures may include, where appropriate:

  • Secure user authentication and access controls.
  • Encryption of data during transmission where applicable.
  • System monitoring, audit logs, and activity tracking.
  • Regular system maintenance, security updates, and vulnerability management.
  • Restricted access to personal data on a need-to-know basis for authorised personnel only.
  • Secure storage and handling of personal data in accordance with applicable laws and industry practices.
  • Payment card details are handled directly by our PCI-DSS compliant payment gateway provider through a tokenised process; SPLIX does not store full card numbers on its own systems.

While we take reasonable steps to safeguard personal data, no method of electronic transmission or storage is completely secure. Accordingly, we cannot guarantee absolute security, but we are committed to taking appropriate measures to minimise security risks and respond promptly to any identified security incidents.

Data Breach Notification

In the event of a personal data breach that is likely to result in significant harm to affected individuals, SPLIX will notify the Personal Data Protection Commissioner, and affected individuals where required, in accordance with the notification requirements under the Personal Data Protection (Amendment) Act 2024.

Your Rights

Subject to the applicable provisions of the Personal Data Protection Act 2010 (PDPA) and other applicable laws, you have the following rights regarding your personal data:

  • To request access to the personal data we hold about you.
  • To request correction or updating of inaccurate, incomplete, or outdated personal data.
  • To withdraw your consent for the processing of your personal data where such processing is based on your consent, subject to legal or contractual limitations.
  • To request clarification on how your personal data is collected, used, disclosed, and protected.
  • To lodge a complaint if you believe your personal data has been handled in a manner that is inconsistent with applicable data protection laws.

Requests relating to your personal data may be submitted through the contact details provided in this Privacy Policy. We may require reasonable verification of your identity before processing any request and may refuse or limit a request where permitted under applicable law.

Children’s Privacy

The Portal is intended for use by individuals aged 18 and above, consistent with our Terms & Conditions. We do not knowingly collect personal data from individuals under 18. If we become aware that we have inadvertently collected personal data from a minor, we will take reasonable steps to delete it.

Cookies

Our portal may use cookies and similar technologies to enhance functionality, improve performance, and provide a better user experience. Cookies are small text files stored on your device when you visit our portal.

Cookies may be used for purposes including:

  • Remembering your login session and user preferences.
  • Improving the functionality and performance of the portal.
  • Analysing website traffic, usage patterns, and user interactions to enhance our services.
  • Supporting security features and detecting fraudulent or unauthorised activities.
  • Maintaining the reliability and efficiency of the portal.

You may manage or disable cookies through your browser settings. However, disabling certain cookies may affect the availability or functionality of some features of the portal.

Consent

By registering for an account, accessing, or using the portal, you acknowledge that you have read and understood this Privacy Policy and consent to the collection, use, processing, storage, and disclosure of your personal data in accordance with this Privacy Policy and the Personal Data Protection Act 2010 (PDPA) of Malaysia.

Where your consent is required by law, you may withdraw your consent at any time by contacting us through the details provided in this Privacy Policy. Please note that withdrawing your consent may affect our ability to provide certain services, including account management, venue bookings, payment processing, or other portal functionalities.

Data Protection & Contact

If you have any questions, enquiries, or requests regarding this Privacy Policy or the handling of your personal data, please contact our data protection team using the details below:

Email: [email protected]

Where applicable, requests relating to access, correction, or other matters concerning your personal data may also be submitted through the above contact channels. We will respond to your request within a reasonable timeframe and in accordance with the Personal Data Protection Act 2010 (PDPA) and other applicable laws.

v0.6.2