OFFICIAL DATA PROTECTION POLICY

Privacy Policy Apatu

Your privacy is more than a legal obligation to us — it is a core value we uphold. Find out exactly how apatu collects, uses, and protects your personal information.

Effective: 1 January 2026
256-bit
SSL Encryption
0
Member Data Sales
24/7
Security Monitoring
PDPA
Malaysian Act Compliance

Quick Summary: Apatu collects only necessary data, uses it for purposes you have consented to, does not sell it to third parties, and protects it with industry-grade encryption. This document explains all the details transparently.

1. Introduction and Scope of This Policy

This Privacy Policy ("Policy") describes how apatu ("we", "Platform") collects, stores, uses, and protects your personal information when you use the apatu.onl website and all related services.

This Policy applies to all registered members, website visitors, and any individual who interacts with our Platform. By registering or continuing to use apatu's services, you confirm that you have read, understood, and agree to the terms set out in this Privacy Policy.

Apatu fully complies with Malaysia's Personal Data Protection Act 2010 (PDPA) and all related legislation. We take this responsibility seriously because your trust is the foundation of our relationship. Your personal data has never been and will never be sold, rented, or traded to any third party for commercial purposes.

Apatu is an online betting platform that complies with Malaysia's PDPA 2010. Any privacy-related enquiries can be directed to our team via email [email protected].

2. Types of Personal Data We Collect

We only collect data that is strictly necessary to deliver apatu services safely and efficiently. Below are the categories of data we collect and their purposes:

2.1 Data You Provide Directly

  • Full name as per identity card or passport
  • Identity card number (MyKad) or passport number
  • Date of birth for age verification (must be 18 years or above)
  • Email address for account communications and notifications
  • Mobile number for two-factor authentication and support
  • Current residential address for KYC compliance purposes
  • Bank account or digital wallet details for processing financial transactions
  • KYC supporting documents such as identity card photos, utility bills, and bank statements

2.2 Data Collected Automatically

  • IP address and network information to identify location and prevent fraud
  • Device type, operating system, and web browser version
  • Login session data including time, date, and session duration
  • Betting history, deposit and withdrawal transactions
  • Cookie and session token data for an improved user experience
  • Activity and interaction logs within the Platform for security purposes
Data Category Primary Purpose Legal Basis
Identification Data Account registration & KYC Legal obligation
Financial Data Transaction processing Contract execution
Technical Data Security & Anti-Fraud Legitimate interest
Usage Data Service improvement Legitimate interest
Communication Data Customer support Contract execution

3. How We Use Your Data

The personal data we collect is used solely for the stated, legitimate purposes. We do not use your data for any other purpose without obtaining additional consent from you.

3.1 Service Operations

  • Create and manage your member account securely
  • Process deposits, withdrawals, and all financial transactions
  • Verify your identity through the KYC process required by law
  • Provide responsive and effective customer support
  • Send important notifications related to your account, transactions, and security

3.2 Security and Compliance

  • Detect and prevent fraud, money laundering, and unauthorised access
  • Comply with reporting obligations to the relevant authorities
  • Verify age compliance (18 years and above)
  • Enforce Platform terms of use and prevent misuse

3.3 Platform Improvements

  • Analyse usage patterns to improve Platform design and functionality
  • Personalise your gaming experience based on your preferences
  • Send relevant promotional offers (with your consent)
  • Run A/B tests to improve the user experience

Marketing Communications: We only send promotional emails and offer notifications if you have given explicit consent during registration or in your account settings. You may withdraw this consent at any time through the notification settings section in your account.

4. Information Sharing and Disclosure

Apatu does not sell, rent, or trade your personal data to any third party for commercial purposes. This is an absolute policy we have never compromised on. However, there are specific situations where we need to share your information with approved parties:

4.1 Third-Party Service Providers

We work with carefully selected service providers who are bound by strict confidentiality agreements. These parties are only permitted to use your data for the designated purposes:

  • Payment Processor: FPX, Touch 'n Go, GrabPay, Boost, and banking partners to process financial transactions
  • KYC Provider: Licensed identity verification service to comply with legal requirements
  • Cloud Infrastructure: Hosting and security provider that stores data in certified data centres
  • Analytics: Anonymous analytics tools to understand platform usage patterns

4.2 Legal Requirements

Apatu may be required to disclose your information to authorities in the following circumstances:

  • When ordered by a court or competent authority in Malaysia
  • To comply with reporting obligations under the Anti-Money Laundering, Anti-Terrorism Financing and Proceeds of Unlawful Activities Act 2001
  • In criminal investigations or fraud cases involving your account
  • To protect the rights, property, or safety of apatu, other members, or the general public

Important: Apatu has never and will never share your personal data with third-party advertisers, social media platforms, or any other commercial entity without your explicit consent.

5. Data Security Measures

Apatu continually invests in the latest security infrastructure to ensure your data remains protected at all times. The following are the layers of protection we employ:

5.1 Encryption and Technical Safeguards

  • All data transmitted between your browser and our servers is protected by 256-bit SSL/TLS encryption
  • Passwords are stored using the bcrypt hashing algorithm, which cannot be decrypted
  • Two-factor authentication (2FA) is available and encouraged for all accounts
  • Database stored in an isolated environment with strict access controls
  • Intrusion detection system (IDS) monitors unusual activity in real time

5.2 Internal Access Controls

  • Access to member data is restricted to staff who genuinely require it
  • All internal access is logged and audited regularly
  • apatu staff are bound by legally enforceable confidentiality agreements
  • Data security training is conducted regularly for all relevant staff

5.3 Incident Response

In the event of a data security breach affecting your personal information, apatu is committed to notifying you within 72 hours of becoming aware of the incident, in line with industry best practices and applicable compliance requirements. Notification will be sent to the email address registered to your account.

6. Cookies and Tracking Technologies

Apatu uses cookies and similar technologies to enhance your experience on our Platform. Cookies are small text files stored on your device when you visit our website.

6.1 Types of Cookies We Use

  • Essential Cookies: Required for core Platform functions such as login authentication and session security. These cookies cannot be disabled.
  • Preference Cookies: Save your settings such as preferred language and display options for a better experience.
  • Analytics Cookies: Help us understand how you use the Platform so we can improve it. This data is anonymised.
  • Security Cookies: Detect suspicious activity and help prevent unauthorised access to your account.

6.2 Managing Cookies

You can manage and delete cookies through your web browser settings at any time. Please note that disabling essential cookies may affect certain Platform features. For more information on managing cookies, refer to your web browser's documentation.

Apatu does not use third-party cookies for advertising purposes or to track your activity on other websites. We only use cookies to enhance your experience on our own Platform.

7. Your Rights Under PDPA

As a data subject under Malaysia's Personal Data Protection Act 2010 (PDPA), you hold important rights that we fully respect. Here are your rights and how to exercise them:

01
Right of Access

You have the right to obtain a copy of all personal data we hold about you. Requests will be processed within 21 business days.

02
Right to Rectification

If your data is inaccurate or outdated, you have the right to request immediate correction. Updates can be made directly through your account profile settings.

03
Right to Erasure

You may request deletion of your personal data, subject to the legal retention obligations binding apatu as a licensed financial operator.

04
Right to Withdraw Consent

For processing based on your consent (such as marketing emails), you may withdraw that consent at any time without any adverse consequences.

05
Right to Restrict Processing

In certain circumstances, you may request that we restrict how we process your data while a dispute or request is being investigated.

06
Right to Lodge a Complaint

If you are unsatisfied with how apatu handles your data, you have the right to lodge a complaint with the Department of Personal Data Protection Malaysia.

To exercise any of the above rights, please contact our privacy team via email [email protected] by stating the right you wish to exercise and sufficient identifying information for us to verify your identity. We will acknowledge your request within 3 business days and resolve it within the timeframe prescribed by law.

8. Data Retention Period

Apatu retains your personal data only for as long as necessary for the purpose it was collected, or as required by applicable Malaysian law. The following is a guide to our retention periods:

  • Active account data: Retained for the lifetime of your account and 7 years after account closure for financial compliance purposes
  • Financial transaction records: Retained for a minimum of 7 years in compliance with the Companies Act and anti-money laundering regulations
  • Security logs: Retained for 12 months for fraud detection and security investigation purposes
  • KYC Records: Retained for the lifetime of the account and 5 years after closure, subject to regulatory requirements
  • Cookies and session data: Automatically expires between 24 hours and 12 months depending on cookie type
  • Marketing Data: Deleted within 30 days after you withdraw consent

Upon expiry of the applicable retention period, your data will be securely deleted or permanently anonymised so that it can no longer be linked to your identity.

9. Changes to This Privacy Policy

Apatu reserves the right to update or amend this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or service improvements. All changes will be published on this page with an updated effective date.

For significant changes that affect how we use your personal data, apatu will provide at least 14 days' advance notice before the changes take effect via:

  • In-Platform notifications when you log in
  • Email to your registered address
  • Clear notice displayed on the website homepage

Continued use of the Platform after the effective date of any changes constitutes your acceptance of the updated Privacy Policy. If you disagree with the changes made, you have the right to close your account and request data deletion in accordance with the procedures outlined in Section 7.

Current version: This Privacy Policy takes effect on 1 January 2026 and supersedes all previous versions.

10. Contact Our Privacy Team

We welcome any inquiries, concerns, or requests relating to this Privacy Policy or how we handle your personal data. The apatu privacy team is ready to assist you in Malay, English, and Mandarin.

  • Privacy Email: [email protected] (mark subject as: "Data Privacy Request")
  • Live Chat: Available 24/7 on the apatu Platform
  • Response Time: Within 3 business days for general enquiries; 21 business days for formal data rights requests

If you feel that apatu has not handled your privacy complaint satisfactorily, you have the right to contact the Department of Personal Data Protection Malaysia (JPDP) under the Ministry of Communications and Digital for further assistance.

Why Apatu Is It Safe for You?

Six pillars of data security that make apatu the most trusted betting platform in Malaysia.

Military-Grade Encryption

All data transmitted between your device and apatu's servers is protected by 256-bit SSL encryption — the same standard used by Malaysia's leading banking institutions.

Integrated & Trusted KYC

Our integrated identity verification process ensures that only verified members aged 18 and above can access the Platform, safeguarding our community as a whole.

No Data Sales

Your personal data is not our product. apatu has never and will never sell, rent, or share your information with advertisers or third-party marketing companies.

Continuous 24/7 Monitoring

Our threat detection system operates around the clock, tracking suspicious activity in real time and responding immediately before any harm occurs.

Malaysia PDPA Compliance

Apatu fully complies with Malaysia's Personal Data Protection Act 2010 (PDPA). We undergo regular compliance audits to ensure the highest standards are consistently maintained.

Full Control in Your Hands

Through your apatu account settings, you can manage privacy preferences, update personal information, control notifications, and submit data requests at any time.

JOIN THE apatu COMMUNITY TODAY

Your Data Is Safe. Your Game Is Risk-Free.

With industry-grade privacy protection and our transparent commitment, you can focus entirely on the best gaming experience. Register now and enjoy peace of mind with apatu.

Bahasa Melayu