Legal

Privacy Policy

This Privacy Policy sets out the manner in which Digital Qasas Sdn Bhd collects, uses, processes, discloses, retains, and protects Personal Data, and the rights available to you, in accordance with the Personal Data Protection Act 2010 of Malaysia (the “PDPA”) and applicable subsidiary legislation.

Last updated · 6 June 2026

1. Introduction and scope

Digital Qasas Sdn Bhd (the “Company”, “we”, “us”, or “our”) is committed to protecting and respecting the privacy of individuals whose Personal Data we process. This Privacy Policy (this “Policy”) governs the collection, recording, holding, storage, use, disclosure, and other processing of Personal Data in connection with your access to and use of our website, learning platform, courses, and related services (collectively, the “Services”).

By accessing or using the Services, registering for an account, or otherwise providing Personal Data to us, you acknowledge that you have read and understood this Policy and consent to the processing of your Personal Data in the manner described herein. Where you do not agree with any part of this Policy, you should refrain from using the Services.

2. Definitions

For the purposes of this Policy: “Personal Data” means any information relating to an identified or identifiable natural person that is processed in connection with the Services; “Processing” means any operation performed upon Personal Data, including collection, recording, organisation, storage, retrieval, use, disclosure, or erasure; and “Data Subject” means the individual to whom the Personal Data relates. Capitalised terms not defined herein bear the meanings ascribed to them under the PDPA.

3. Categories of Personal Data we process

In the course of providing the Services, we may collect and process the following categories of Personal Data:

  • Identity and contact data — including your name and electronic mail address, provided upon invitation, registration, or authentication.
  • Account and credential data — information necessary to establish and secure your account. We do not retain your password in plain text; authentication credentials are stored in an encrypted or irreversibly hashed form.
  • Learning and engagement data — records of the courses in which you enrol, the lessons you access, your progress, and your completion status, processed to deliver the Services and to maintain your learning records.
  • Transaction data — where you purchase a course, confirmation of the transaction, the amount paid, the currency, and a payment reference. Payment is effected through an independent third-party payment service provider; we do not collect, process, or store your full payment card number, bank account credentials, or equivalent sensitive financial instruments.
  • Technical and usage data — limited technical information such as access logs and aggregated, privacy-preserving usage metrics, processed for security, diagnostic, and service- improvement purposes.

4. Lawful basis and consent

We process Personal Data on one or more of the following bases: (a) your consent; (b) the performance of a contract to which you are a party, or in order to take steps at your request prior to entering into such a contract; (c) compliance with a legal obligation to which we are subject; and (d) our legitimate interests in operating, securing, and improving the Services, provided such interests are not overridden by your rights and freedoms. Where processing is founded on consent, you may withdraw that consent at any time in the manner described in Section 9, without affecting the lawfulness of processing carried out prior to such withdrawal.

5. Purposes of processing

We process Personal Data for the following purposes:

  • to establish, administer, and maintain your account and your access to the Services;
  • to deliver course content and to record and report your learning progress;
  • to facilitate and confirm transactions and to issue receipts and related communications;
  • to send operational and transactional communications, including invitations, security notifications, and password-related messages;
  • to maintain the security, integrity, and availability of the Services and to detect, prevent, and address fraud or misuse;
  • to comply with applicable legal, regulatory, accounting, and reporting obligations; and
  • to evaluate and improve the quality, functionality, and content of the Services.

6. Disclosure of Personal Data

We do not sell, rent, or trade Personal Data. We may, however, disclose Personal Data to the following categories of recipients, in each case to the extent reasonably necessary for the purposes set out in this Policy and subject to appropriate contractual and security safeguards:

  • Service providers and data processors engaged to perform functions on our behalf, including cloud infrastructure, hosting and database providers; identity and authentication providers; a payment service provider; a learning-delivery infrastructure provider; and content-delivery, security, and analytics providers. Such parties are authorised to process Personal Data only on our instructions and in accordance with this Policy.
  • Professional advisers, such as auditors, accountants, and legal advisers, where required;
  • Regulatory, governmental, or law-enforcement authorities, where disclosure is required or permitted by law, court order, or other legal process; and
  • Successors in interest, in connection with any merger, acquisition, reorganisation, or transfer of all or part of our business, subject to the recipient agreeing to honour this Policy.

7. Cross-border transfers

Certain of our service providers may process or store Personal Data at locations outside Malaysia. Where Personal Data is transferred to a place outside Malaysia, we will take reasonable steps to ensure that the recipient is bound by obligations to protect the Personal Data to a standard comparable to that required under the PDPA.

8. Cookies and similar technologies

We employ strictly necessary cookies to authenticate users and to maintain session continuity. Where analytics are used, we endeavour to adopt privacy-preserving, cookieless measurement wherever reasonably practicable. You may configure your browser to refuse non-essential cookies, although doing so may impair certain functionality of the Services.

9. Your rights as a Data Subject

Subject to the conditions and exceptions prescribed under the PDPA, you are entitled to: (a) request access to the Personal Data we hold about you; (b) request the correction of Personal Data that is inaccurate, incomplete, misleading, or not up to date; (c) withdraw your consent to the processing of your Personal Data; (d) request that we limit the processing of your Personal Data; and (e) request the deletion of your Personal Data where it is no longer required for the purposes for which it was collected. To exercise any of these rights, please submit a written request to hello@digitalqasas.com. We may require verification of your identity before giving effect to any such request and may decline a request to the extent permitted or required by law.

10. Data security

We implement appropriate technical and organisational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Notwithstanding these measures, no method of transmission over the internet or method of electronic storage is wholly secure, and we cannot guarantee absolute security.

11. Data retention

We retain Personal Data only for so long as is necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, regulatory, or reporting requirements, after which it will be securely deleted or anonymised.

12. Children

The Services are intended for individuals who are of the age of majority and possess the legal capacity to enter into a binding contract. We do not knowingly collect Personal Data from children without appropriate consent. Where we become aware that such data has been collected inadvertently, we will take reasonable steps to delete it.

13. Third-party websites

The Services may contain links to third-party websites or resources that are not operated or controlled by us. This Policy does not apply to such third parties, and we are not responsible for their privacy practices. We encourage you to review the privacy notices of any third-party services you access.

14. Amendments

We may revise this Policy from time to time to reflect changes in our practices or in applicable law. Any revisions will take effect upon publication, and the “last updated” date above will be amended accordingly. Your continued use of the Services following any such revision constitutes acceptance of the amended Policy.

15. Contact

Any enquiries, requests, or complaints concerning this Policy or our processing of Personal Data may be addressed to Digital Qasas Sdn Bhd at hello@digitalqasas.com.

16. Governing law

This Policy shall be governed by and construed in accordance with the laws of Malaysia, and any matter arising in connection with it shall be subject to the exclusive jurisdiction of the courts of Malaysia.