Effective: 1 June 2026 · Compliant with PDPA 2010 (Malaysia)
KASSIM (“we”, “our”, “the Platform”) is committed to protecting your personal data in accordance with the Personal Data Protection Act 2010 (PDPA 2010) of Malaysia. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use KASSIM.
Information you provide:
Automatically collected data:
We share your data with trusted third-party service providers as necessary to operate the Platform:
Supabase
Database & authentication (hosted in Singapore)
Stripe
Payment processing (PCI-DSS compliant)
Resend
Transactional email delivery
OAuth sign-in (optional)
Sentry
Error monitoring & performance
Vercel
Hosting & edge infrastructure
We do not sell your personal data to any third party.
As a data subject under the PDPA 2010, you have the right to:
To exercise these rights, contact us at syedshazni@todak.com with your request. We will respond within 21 days as required by PDPA 2010.
We use cookies and browser local storage to maintain your session, remember preferences (language, theme), track recently viewed items, and provide push notification functionality. You may disable cookies in your browser, but this may affect Platform functionality.
We implement industry-standard security measures including SSL/TLS encryption, row-level security (RLS) on our database, and secure escrow for financial transactions. However, no system is 100% secure. In the event of a data breach, we will notify affected users as required by law.
KASSIM is not intended for users under 18 years of age. We do not knowingly collect data from minors. If you believe a minor has registered, please contact us immediately.
For privacy-related inquiries, data access requests, or complaints: