Memuatkan...
Memuatkan...
Effective date / Tarikh kuat kuasa: 7 Aug 2025
DuitMap ("duitmap.my", "we", "us", "our") operates online calculators and tools that help Malaysians plan savings and retirement. We are a data user (data controller) under Malaysia's Personal Data Protection Act 2010 ("PDPA").
DuitMap ("duitmap.my", "kami") mengendalikan kalkulator atas talian untuk membantu rakyat Malaysia merancang simpanan dan persaraan. Kami ialah Pengguna Data di bawah Akta Perlindungan Data Peribadi 2010 ("PDPA").
| Category (EN) | Contoh (BM) | Purpose / Tujuan |
|---|---|---|
| Account details | Nama, e-mel, telefon | Signup & login |
| Financial inputs | Pendapatan, perbelanjaan, baki EPF, umur bersara | Run calculators |
| Technical data | Alamat IP, jenis peranti, kuki, ID pelayar | Security, analytics |
| Communications | Soalan, maklum balas, laporan ketidaktepatan, e-mel susulan pilihan | Support, content review, marketing with consent |
We do not collect sensitive data (religion, health, biometrics).
Kami tidak mengumpul data sensitif (agama, kesihatan, biometrik).
Penggunaan data selaras dengan Prinsip Am, Notis & Pilihan, dan Integriti Data PDPA.
We process data with your consent (Section 6 PDPA) and to perform the service you request. Consent is obtained via tick-box at signup and can be withdrawn through "Delete my data". Notice is provided in BM & EN as required by the Notice & Choice Principle (Section 7).
Primary servers are in a Tier-III data-centre in Cyberjaya, Malaysia. Some non-personal or aggregated metrics may pass through third-party services (e-mail, analytics, support) that are also located in Malaysia.
We may share limited data with:
| Type | Provider example | Safeguard |
|---|---|---|
| Cloud e-mail (transactional) | Local MSC-status provider | DPA, TLS |
| Analytics | Matomo On-Prem (MY) | Pseudonymised IDs |
| Payment gateway (if premium features) | FPX-certified bank | PCI-DSS |
No data is transferred outside Malaysia unless later required; if so we will comply with Section 129 PDPA and the 2025 Cross-Border Guidelines (adequacy, contractual clauses or explicit consent).
Security controls follow the Personal Data Protection Standard 2015.
| Data type | Retained | Rationale |
|---|---|---|
| Account & saved calculations | 24 months of inactivity → auto-deletion | Industry norm; PDPA Retention Principle |
| Raw inputs (not saved) | Deleted after 30 days | Reduce footprint |
| Server logs | 12 months | Security |
| Inaccuracy reports & optional follow-up e-mail | Up to 24 months after closure or latest review | Editorial review and audit trail |
Users can click "Delete my data" in settings or e-mail admin@duitmap.my to erase all personal data within 10 working days.
Under PDPA you may access, correct, delete or withdraw consent to processing of your personal data. Contact us (Section 11). Fees permitted by law may apply for repeated or manifestly unfounded requests.
Essential cookies keep you logged-in; analytics cookies are optional and disabled until you opt-in. Financial inputs typed while logged-out stay only in your browser's localStorage unless you choose "Save to Cloud".
Our tools are designed for Malaysians aged 18 and above. If you are under 18, please obtain parental consent before creating an account. We will delete any account created by a minor without verifiable consent.
Data Protection Lead
DuitMap
E-mail: admin@duitmap.my
(Office hours: Mon-Fri 09:00–17:00 MYT)
We may update this policy; the latest version is always at https://duitmap.my/privacy. Significant changes will be announced via in-app banner or e-mail.
This notice is provided for informational purposes and is not legal advice. For tailored compliance, consult your legal counsel.