Effective Date: December 2021. Last updated: 2nd August 2021.
WE ARE DEDICATED TOWARDS PROTECTING AND RESPECTING YOUR PRIVACY
Our aim is to:
1. About us
In compliance with the Personal Data Protection Act 2010 (“PDPA”) and all other relevant regulations and guidelines pertaining to data protection, this notice is issued to all our valued customers and/or prospective customers. This notice will inform you of your rights with regards to your personal data that has been and/or will be collected and processed by MyMy Payments Malaysia Sdn Bhd (“MyMy”).
2. Why do I need to read this policy?
We will collect your personal data when you use:
THIS POLICY CONTAINS IMPORTANT INFORMATION
When we say ‘personal data’, we mean information which can be used to personally identify you (for example, a combination of your name and address). Personal data also includes any sensitive personal data or expression of opinion about the data subject. Personal data does not include any information that is processed for the purpose of a credit reporting business carried on by a credit reporting agency under the Credit Reporting Agencies Act 2010. Personal information simply means any information or data that can be used to distinguish, identify or contact you.
If you have concerns about how we use your personal data, you can contact our Data Protection Officer at email@example.com.
Your Personal Data
3. What personal data do you collect about me?
We collect different types of personal data from you and others. The information below explains what personal data we collect and use.
Information you give us
How we collect information you provide when you:
Information from your device
Whenever you use our website or the MyMy app, we collect the following information:
When you access our website or content or use our application or MyMy’s services, we or companies we work with may place small data files called cookies or pixel tags on your computer or other device. A cookie is a small file of letters and numbers that we store on your browser or the hard drive of your computer if you agree. Cookies contain information that is transferred to your computer’s hard drive.
We use the following cookies:
Our website uses Google Analytics, a web traffic analysis service provided by Google Inc. (“Google”). Please refer to https://policies.google.com/technologies/partner-sites to find out more about how Google uses data when you use our website and how to control the information sent to Google.
You block cookies by activating the setting on your browser that allows you to refuse the setting of all or some cookies. However, if you use your browser settings to block all cookies (including essential cookies) you may not be able to access all or parts of our site.
Furthermore, you can prevent Google’s collection and processing of data by using the Google Ads Settings page or downloading and installing their browser plug-in (https://tools.google.com/dlpage/gaoptout).
Information about your location
If you have location services in the MyMy app switched on, we track your location using GPS technology.
Information from others
We collect personal data from third parties, such as credit-reference agencies, financial or credit institutions, official registers and databases, as well as fraud-prevention agencies and partners who help us to provide our services.
This includes your credit record, information about late payments, information to help us check your identity, information about your spouse and family (if applicable in the context of an application for credit that you make) and information relating to your transactions.
When you ask us to, we will also collect personal data from accounts you hold with third party banks (and some accounts with third party providers that aren't banks) so that you can see everything in one place in your MyMy app. You can create a linked account by activating Open Banking in the app.
Information from social media
Occasionally, we will use publicly available information about you from selected social media websites or apps to carry out enhanced due diligence checks. Publicly available information from social media websites or apps may also be provided to us when we conduct general searches on you (for example, to comply with our anti-money laundering or sanctions screening obligations).
If you are a MyMy Business customer, we may collect information about you if you make it publicly available on social media websites or apps. We only do this as part of our MyMy Business KYC checks. For example, if you have not yet set up a website for your business, we may need to look at information available on social media websites or apps to make sure your business is legitimate.
Information from publicly available sources
We collect information and contact details from publicly available sources, such as media stories, online registers or directories, and websites for enhanced due diligence checks, security searches, and KYC purposes for MyMy Business customers.
We will collect the following information:
If you give us personal data about other people (such as your spouse or family), or you ask us to share their personal data with third parties, you confirm that you have brought this policy to their attention beforehand.
In order to help protect you from fraud and misuse of your personal information, we may collect information about your use and interaction with our website or MyMy’s services. For example, we may evaluate your computer, mobile phone or other access device to identify any malicious software or activity that may affect the availability of MyMy’s services.
WHY WE COLLECT PERSONAL INFORMATION AND HOW WE USE IT
We use your personal data so we can provide the best service, tell you about products and services you may be interested in, and meet our legal obligations.
Whenever you apply for a product or service, we will use your personal data to check your identity (as part of our KYC process) and decide whether or not to approve your application.
If you are already a MyMy customer, we use your personal data to meet our obligations relating to any transactions you make (for example, making payments into and out of your MyMy account, withdrawing cash or making payments with your MyMy Card). If you ask us to exchange the currency of the e-money you hold in your MyMy account, we'll use your personal data to help us do that.
Our primary purpose in collecting personal information is to provide you with a secure, efficient, and customized experience. We may use collect, use, process and examine your personal information when reasonable, relevant and necessary to:
We also intend to use your personal data in direct marketing and we require your consent (which includes an indication of no objection) for that purpose. In this connection, please note that:
MARKETING AND PROVIDING NEW PRODUCTS AND SERVICES THAT MIGHT INTEREST YOU
We use your personal data to do the following:
process applications for products and services available through us, and make decisions about whether to approve applications.
Remember, you can ask us to stop sending you marketing information by adjusting your marketing choices.
HERE'S AN EXAMPLE OF HOW WE USE YOUR PERSONAL DATA FOR MARKETING
If you are a MyMy customer, we may contact you about optional extras or promotional offers. We may use personal data we gather about you through your use of our services to tailor these offers to you.
TO KEEP OUR SERVICES UP AND RUNNING
We use your personal data to manage our website and the MyMy app, (including troubleshooting, data analysis, testing, research, statistical and survey purposes), and to make sure that content from our website is presented in the most effective way for you and your device.
We also use your personal data to allow you to take part in interactive features of our services, to tell you about changes to our services, and to help keep our website and the MyMy app safe and secure.
HERE'S AN EXAMPLE OF HOW WE USE YOUR PERSONAL DATA TO RUN OUR SERVICES
If any changes we make to our services affect you, we'll normally contact you using the email address you gave us when you signed up, or through the MyMy app, to tell you about the changes.
Our legal basis is one or more of the following:
HELPING WITH SOCIAL INTERACTIONS
We use your personal data to help social interactions through our services or to add extra functions in order to provide a better experience.
HERE'S AN EXAMPLE OF HOW WE USE YOUR PERSONAL DATA FOR SOCIAL INTERACTIONS
We'll let you know if any MyMy customers are in the same area as you (if you and they have location services switched on).
If you give us permission, we'll use the contacts list on your phone, so you can easily make payments to your contacts using the MyMy app or upload photos to your savings vaults in the MyMy app.
Our legal basis is one or more of the following:
PROVIDING LOCATION-BASED SERVICES
We use your personal data to provide relevant advertising to you (for example, information on nearby merchants), to protect against fraud, and to let you know when any of your MyMy customers are in the same area as you (if they have location services switched on).
HERE'S AN EXAMPLE OF HOW WE USE YOUR LOCATION INFORMATION
If you go abroad, the MyMy app may automatically tell you the exchange rate in that country.
If you are under the age of 18, please do not share or send any personal data about yourself to us without prior consent from your parent(s) and/or legal guardian.
We must have a legal basis (a valid legal reason) for using your personal data. Our legal basis will be one of the following.
We need certain personal data to provide our services and cannot provide them without this personal data.
In some cases, we have a legal responsibility to collect and store your personal data (for example, under anti-money laundering laws we must hold certain information about our customers).
We sometimes collect and use your personal data, or share it with other organisations, because we have a legitimate reason to use it and this is reasonable when balanced against your right to privacy.
Where you've agreed to us collecting your personal data, for example when you have ticked a box to indicate you are happy for us to use your personal data in a certain way.
Where we process your sensitive personal data (sometimes known as special category personal data) to adhere to government regulations or guidance, such as our obligation to support you if you are or become a vulnerable customer.
MEETING OUR LEGAL OBLIGATIONS, ENFORCING OUR RIGHTS AND OTHER LEGAL USES
We may need to share personal data about you:
Our legal basis is one or more of the following:
Depending on the MyMy products or services you use, we may make automated decisions about you.
This means that we may use technology that can evaluate your personal circumstances and other factors to predict risks or outcomes. We do this for the efficient running of our services and to ensure decisions are fair, consistent and based on the right information.
Where we make an automated decision about you, you have the right to ask that it is manually reviewed by a person.
For example, we may make automated decisions about you that relate to:
HOW WE SHARE PERSONAL INFORMATION WITH OTHER PARTIES
We may share your personal information with:
MyMy will not sell or rent any of your personal information to third-parties for their marketing purposes and only share your personal information with third-parties as described in this policy. If there is an actionable breach of your personal information, we will notify you as soon as practicable .
If you establish a MyMy account indirectly on a third-party website or via a third-party application, any information that you enter on that website or application (and not directly on a MyMy website) will be shared with the owner of the third-party website or application and your information may be subject to their privacy policies.
We will notify you of material changes to this policy by updating the ‘Last Updated’ date at the top of this page. It is recommended that you visit this page frequently to check for changes.
MYMY GROUP COMPANIES
We share your personal data within the MyMy group of companies in order to provide you with the best service.
OTHER MYMY CUSTOMERS
We will ask you to let us sync your mobile phone contacts. This will help you to identify which of your trusted mobile phone contacts are MyMy customers. Your ‘trusted contacts’ will also be able to see if you are a MyMy customer through our ‘Payment with Friends’ functionality.
‘Payment with Friends’ gives you access to MyMy features like requesting money from your friends, splitting bills, group vaults and paying other MyMy customers near you.
We use technological safeguards to ensure a ‘trusted contact’ is somebody you already know and who knows you (for example, you have each other saved in each other’s mobile phone contacts lists or have already received or given money through a peer-to-peer payment with them).
Both you and your trusted contact must have synced your mobile phone contacts lists with MyMy to be viewable to each other in the MyMy app.
We only show your basic contact details in the MyMy app to your trusted contacts who are also MyMy customers (for example, your name (as saved in your friend’s contacts list), mobile phone number, MyMy username, your MyMy profile photo (if you have one)).
You can, of course, choose not to sync your contacts list with MyMy. This means that you will not be able to identify which of your mobile phone contacts are MyMy customers.
You can also turn off ‘Payments with Friends’ through the privacy settings in the MyMy app.
PEOPLE OR COMPANIES THAT YOU TRANSFER MONEY TO
Where you make a payment from your MyMy account, we will provide the recipient with your details (for example, your full legal name and IBAN).
The information below explains which suppliers we normally share your personal data with and why.
Suppliers who provide us with IT, payment and delivery services
To help us provide our services to you.
Our banking and financial-services partners and payments networks.
To help us provide our services to you. This includes banking and lending partners, banking intermediaries and international payment-service providers.
Card manufacturing, personalisation and delivery companies
To create and deliver your personalised MyMy Card.
Analytics providers and search information providers
To help us improve our website or app.
Customer-service providers, survey providers and developers
To help us to provide our services to you.
Communications services providers
To help us send you emails, push notifications and text messages.
Debt collection agencies
To manage and recover debts that you owe or may become owing if you have a MyMy credit product.
THIRD PARTY PAYERS
We may share your name with third parties that pay money into your MyMy account. This is necessary to onboard you, confirm your transactions have been made to the destinations.
PARTNERS WHO HELP TO PROVIDE OUR SERVICES
We may share your personal data with our partners in order to provide you with certain services you have asked us for (for example, when we offer overseas medical insurance as part of our Premium or Metal plans).
HERE'S AN EXAMPLE OF WHEN WE MIGHT SHARE YOUR PERSONAL DATA WITH OUR PARTNERS
If you have asked for insurance services, we will share your relevant personal data with the provider of our insurance services. The service provider will require your personal data to provide you with insurance.
We will only share your personal data in this way if you have asked for the relevant service or it is provided as part of one of our plans.
From time to time we may work with other partners to offer you co-branded services or promotional offers, and we will share some of your personal data with those partners. We will always make sure you understand how we and our partners process your personal data for these purposes.
If you apply for a credit product, we'll share your personal data with credit-reference agencies to check whether you are likely to make repayments when due.
OTHER FINANCIAL INSTITUTIONS
We may share your personal data with other financial institutions if requested.
HERE'S AN EXAMPLE OF WHEN WE MIGHT SHARE YOUR PERSONAL DATA WITH OTHER FINANCIAL INSTITUTIONS
If you have activated ‘Open Banking’ through an account you hold with another financial institution and given them permission, we will share data from your MyMy account with that financial institution.
We may also share your personal data with other financial institutions where you do not ask us to. For example:
FOR LEGAL REASONS
We also share your personal data with fraud-prevention agencies to check your identity, protect against fraud, keep to anti-money laundering laws and confirm that you are eligible to use our products and services.
HERE'S AN EXAMPLE OF WHEN WE MIGHT SHARE YOUR PERSONAL DATA FOR LEGAL REASONS
If you give us false or inaccurate personal data and we identify fraud, we will let fraud-prevention agencies know. Law-enforcement agencies may check and use this personal data.
If fraud is detected, you could be refused certain services, finance or employment. You can contact us through the MyMy app to ask us for details of the fraud-prevention agencies we may share your personal data with.
We may also need to share your personal data with other third party organisations:
HERE'S AN EXAMPLE OF WHEN WE MIGHT SHARE YOUR PERSONAL DATA FOR ADVERTISING PURPOSES
We may share your personal data (your name, email address and app events) with our advertising partners in the ways described below, but the personal data is hashed before we send it, and the social-media platform we share it with is only allowed to use that hashed personal data in the ways described below.
When we use social media for marketing purposes, your personal data may be shared with the social-media platforms so that they can check if you also hold an account with them. If you do, we may ask the advertising partner or social-media provider to:
An example of how we may use social media for marketing purposes is through Facebook’s ‘Custom Audience’ tool, the terms of which are available here.
Our legal basis is:
You can contact us at any time, either through the MyMy app or by emailing firstname.lastname@example.org, if you do not want us to share your personal data for advertising purposes. You can also use the privacy settings in the MyMy app to opt out from having your personal data shared in this way.
Remember you can also manage your marketing preferences directly with any social media provider that you have an account with.
WHERE YOU ASK US TO SHARE YOUR PERSONAL DATA
Where you direct us to share your personal data with a third party, we may do so. For example, you may authorise third parties to act on your behalf (such as a lawyer, accountant or family member or guardian under a power of attorney).
If you sign up to our services, and where allowed by law, we will assume you want us to contact you by post, email and SMS text message with information about MyMy products, services, offers and promotions. We may use the personal data we have collected about you in order to tailor our offers to you.
You can adjust your preferences, or tell us you don't want to hear from us, at any time. Just use the privacy settings in the MyMy app or click on the unsubscribe links on any marketing message we send you.
We won't pass your details on to any organisations outside the MyMy group of companies for their marketing purposes without your permission.
We acknowledge that you have the right in deciding the information you wish to provide to us. The provision of the information listed above is voluntary in nature. However, please note that if you do not provide the information above or limit the way such information is to be processed, it may result in us not being able to:
The accuracy and completeness of your personal data depends on the information you provide. We assume that the information you have provided is accurate, up to date and complete unless you inform us otherwise
Where you provide any third party information to us, it is our assumption that such information is accurate, up to date and complete and that you have obtained the necessary consent to disclose the same.
Where you have consented or allowed us to disclose personal data to third party and/or other User when using our Services, you understand that We no longer have any control or authority as to how the said third party and/or other User will use or process the personal data. Therefore, you agree that We will not be responsible for the subsequent use of your personal data by the third party or other User. If you wish to stop them from further using your personal data, please contact them directly.
The information below explains what rights you have and what those rights mean.
You have the right to be told about how we use your personal data
If you ask, we will provide a copy of the personal data we hold about you. We can’t give you any personal data about other people, personal data which is linked to an ongoing criminal or fraud investigation, or personal data which is linked to settlement negotiations with you. We also won't provide you with any communication we've had with our legal advisers.
You can ask us to correct your personal data if you think it's wrong
You can have incomplete or inaccurate personal data corrected. Before we update your file, we may need to check the accuracy of the new personal data you have provided.
You can ask us to delete your personal data
You can ask us to delete your personal data if:
Just to let you know, we may not be able to agree to your request. As a regulated financial services provider, we must keep certain customer personal data even where you ask us to delete it (we've explained this in more detail below). If you've closed your MyMy account, we may not be able to delete your entire file because these regulatory responsibilities take priority. We will always let you know if we can't delete your information.
You can object to us processing your personal data for marketing purposes
You can tell us to stop using your personal data for marketing.
You can object to us processing other personal data (if we are using it for legitimate interests)
If our legal basis for using your personal data is 'legitimate interests' and you disagree with us using it, you can object.
However, if there is an overriding reason why we need to use your personal data, we will not accept your request.
If you object to us using personal data which we need in order to provide our services, we may need to close your account as we won’t be able to provide the services.
You can ask us to restrict how we use your personal data
You can ask us to suspend using your personal data if:
You can ask us to transfer personal data to you
If we can, and are allowed to do so under regulatory requirements, we will provide your personal data in a structured, commonly used, machine-readable format.
You can withdraw your permission
If you have given us any consent we need to use your personal data, you may exercise your opt-out right by notifying us if you wish to object to the use of your personal data for direct marketing purposes. Please send requests for such objections, access to data, correction of data, information regarding policies and practices and kinds of data held, questions or complaints to:
MyMy Payments Malaysia Sdn. Bhd.
D-23A-3, Menara Suezcap 1,
KL Gateway, No. 2 Jalan Kerinchi,
Gerbang Kerinchi Lestari, 59200
Kuala Lumpur, Malaysia.
Phone: +60 3 2391 9696
(Note, it will have been lawful for us to use the personal data up to the point you withdraw your permission).
You can ask us to carry out a human review of an automated decision we make about you
If we make an automated decision about you that significantly affects you, you can ask us to carry out a manual review of this decision.
Your ability to exercise these rights will depend on a number of factors. Sometimes, we will not be able to agree to your request (for example, if we have a legitimate reason for not doing so or the right does not apply to the particular information we hold about you).
To exercise any of your rights set out in the previous section, you can contact us through the MyMy app or send us an email at email@example.com.
For security reasons, we can't deal with your request if we are not sure of your identity, so we may ask you for proof of your ID.
MyMy will usually not charge you a fee when you exercise your rights. However, we are allowed by law to charge a reasonable fee or refuse to act on your request if it is manifestly unfounded or excessive.
If you are unhappy with how we have handled your personal data you can get in touch with the Personal Data Commissioner:
THE MALAYSIAN ADMINISTRATIVE MODERNISATION AND MANAGEMENT PLANNING UNIT
Level 6, Setia Perdana 2
Setia Perdana Complex
Federal Government Administrative Centre
+ 603 8000 8000
+ 603 8888 3721
As we provide an international service, we may need to transfer your personal data outside Malaysia in order for us to provide our services.
For example, if you ask to make an international payment, we will send funds to banks outside of Malaysia. We might also send your personal data outside of Malaysia to keep to global legal and regulatory requirements, and to provide ongoing support services.
We may share your personal data with credit-reference agencies and fraud-prevention agencies that are based outside of Malaysia.
Further, we may also be required to transfer your personal data outside of Malaysia for the purposes and to such third parties stated in this Statement. The transfer of your personal data outside of Malaysia would also be required if you are traveling, residing or based outside of the said territory.
If you would like more information, please contact us through the MyMy app or by sending an email to firstname.lastname@example.org.
We recognise the importance of protecting and managing your personal data. Any personal data we process will be treated with the utmost care and security. This section sets out some of the security measures we have in place.
In our offices we have organized departments so that those persons who are authorized to view, monitor, analyze, and manage personal information are isolated from other employees.
All information you provide to us is stored on our secure servers. Where we have given you (or where you have chosen) a password, which enables you to access certain parts of our site, you are responsible for keeping this password confidential. We ask you not to share a password with anyone. Please be sure to sign off when you finish using our Services on a shared computer.
14. How long will you keep my personal data for?
We will generally keep your personal data for six years after our business relationship ends or such period as may be required by applicable local laws. However, if there is a need to retain the data longer for circumstances out of MyMy’s hand, such as to assist an ongoing investigation and so on.
We are required to keep your personal data for this long by anti-money laundering and e-money laws. We may keep your personal data for longer because of a potential or ongoing court claim or another legal reason.
GOVERNING LAW AND JURISDICTION
This agreement is drafted in the English language and Bahasa Melayu. If this agreement is translated into any other language, the English language version shall prevail.
HOW YOU CAN CONTACT US ABOUT PRIVACY QUESTIONS