Official Documents

Privacy Policy peti4d – Member Personal Data Protection

Your privacy is our priority. This document explains in detail how peti4d collects, uses, stores, and protects your personal information — as well as the rights you hold as a member of our platform.

Updated: January 2026 Bahasa Melayu (Malaysia) Malaysia PDPA Compliance
Our Commitment

Peti4d's Six Pillars of Privacy Protection

We don't just comply with the law — we go beyond the minimum standards to ensure your privacy is fully protected.

Full PDPA Compliance

Peti4d operates in full compliance with Malaysia's Personal Data Protection Act 2010 (PDPA). All processes involving the collection and use of members' personal data are subject to this legal framework without exception.

256-bit SSL encryption

All communication between your browser and peti4d's servers is protected by bank-grade 256-bit SSL encryption. Your personal and financial data cannot be intercepted or read by any third party while in transit.

Secure Data Storage

Member personal data is stored on servers protected by multiple layers of security, including role-based access controls, real-time audit logs, and regular backups at certified data centres.

No Data Sales

Peti4d has never and will never sell, rent, or trade members' personal data to advertisers or third-party data brokers. Your information belongs to you — it is not our business commodity.

Full Control in Your Hands

Peti4d members have full rights to access, correct, transfer, and request deletion of their personal data at any time. This process can be initiated directly through our 24/7 support team.

Data Minimisation Principle

We only collect data that is strictly necessary to deliver our services. There is no excessive or unjustified data collection — every piece of information we request has a clear and transparent rationale.

Section 01

Information We Collect

To provide a complete, secure, and responsible service, peti4d collects several categories of information from our members. This collection is carried out transparently and only when you actively interact with our platform.

A. Registration & Identity Information

During the account registration process, we collect basic information required to verify your identity and establish a valid account:

Full Name
As stated in your valid identification document
IC / Passport Number
For KYC identity verification
Email Address
Official communications and account recovery
Phone Number
SMS verification and important notifications
Date of Birth
Minimum age verification of 21 years
Residential Address
KYC and AML requirements compliance

B. Financial & Transaction Information

To process deposits and withdrawals securely, we retain your financial transaction records, including bank account details, e-wallet account numbers, deposit and withdrawal history, and current account balance. Sensitive financial data such as full card numbers is never stored on our servers — only securely formatted tokens.

C. Technical & Usage Data

Our system automatically logs technical information when you use the peti4d platform:

  • IP address and country-level geographic location
  • Device type, operating system, and browser version
  • Pages visited and session duration
  • Game activity logs for audit and security purposes
  • Session cookie data and user preferences
Collection Note: We do not collect sensitive personal information such as biometric data, medical records, or political views. All data collection is based on legitimate operational requirements of the platform.
Section 02

How We Use Your Data

Peti4d uses collected personal data solely for legitimate, transparent purposes directly related to the provision of our platform services. Below is a detailed description of each purpose of use:

Account Management & Identity Verification

Your registration data is used to create and manage your peti4d account, including the KYC (Know Your Customer) process required to ensure all members meet the eligibility and age requirements set out by law. This is a legal obligation that cannot be waived.

Financial Transaction Processing

Your financial information is required to process every deposit and withdrawal accurately and securely. This includes bank account verification, real-time anti-fraud checks, and records required for anti-money laundering (AML) regulatory compliance.

Platform Security & Fraud Prevention

Technical data such as IP addresses and usage patterns are analysed by our security systems to detect suspicious activity, unauthorised login attempts, multi-account usage, and potential fraud before it occurs.

Communication & Customer Support

Your contact information allows us to send important account notifications, security updates, customer support responses, and — with your consent — relevant promotional offers.

Service Improvement

Aggregated and anonymised usage data helps the peti4d team understand platform usage patterns, identify areas for improvement, and develop new features better suited to the needs of Malaysia members.

Important: Your data will not be used to make automated decisions that have a serious impact on your rights without human review. Every significant account action is reviewed by our team.
Section 03

Sharing Information with Third Parties

Peti4d does not sell, rent, or disclose members' personal data to external parties for marketing or commercial purposes. However, in the course of platform operations, there are limited situations where data sharing is necessary and permitted:

Trusted Service Providers

We only share the necessary data with trusted third-party service providers that support our platform operations, including payment processors (FPX, DuitNow, Touch 'n Go), cloud service providers, and customer support platforms. All such providers are bound by strict data confidentiality agreements and may only use your data for the specific purposes defined.

Legal Obligations

Peti4d will disclose personal data when required by law, court order, or a valid request from Malaysian government authorities. In such situations, we will endeavour to notify you in advance unless prohibited by law.

AML & Regulatory Body Compliance

In compliance with anti-money laundering (AML) and counter-terrorism financing (CFT) regulations, certain transaction information may be required to be reported to the relevant regulatory authorities.

Our Guarantee: All data sharing with third parties is governed by valid data processing agreements, equivalent data protection standards, and periodic audits to ensure ongoing compliance.

International Transfers

Some cloud services used by peti4d may store data on servers located outside Malaysia. In such cases, we ensure that all data transfers are protected by contractual safeguards equivalent to Malaysia's PDPA and applicable international standards.

Section 04

Data Security & Encryption

Peti4d continually invests in industry-grade security infrastructure to ensure members' personal and financial data is always protected against cyber threats, data breaches, and unauthorised access.

Technical Security Layers

  • 256-bit SSL/TLS encryption — all data in transit is fully protected
  • AES-256 encryption for data at rest — data stored in our database is encrypted
  • Web Application Firewall (WAF) — protection against SQL injection, XSS, and CSRF attacks
  • Intrusion Detection System (IDS/IPS) — real-time monitoring of suspicious traffic
  • Two-factor authentication (2FA) — an additional layer of protection for account Login
  • Role-based access control (RBAC) — staff can only access data necessary for their role

Operational Security Measures

Beyond technical measures, peti4d conducts regular security assessments, penetration testing carried out by independent security experts, security awareness training for all staff, and tested incident response procedures. The data centres we use hold ISO 27001 and SOC 2 security certifications.

What Happens in the Event of a Data Breach? In the event of a security incident affecting your personal data, peti4d will notify you within 72 hours of the incident being identified, detailing the scope of the event, the steps taken, and the actions you should follow.

Your Responsibilities in Maintaining Account Security

While peti4d takes all reasonable steps to protect your data, account security also depends on your own actions. We recommend using a strong and unique password, enabling 2FA, not sharing your login credentials, and notifying us immediately if you suspect any unauthorised access.

Section 05

Your Rights as a Member

Under Malaysia's PDPA and peti4d's privacy policy, you as a member have the following rights regarding your personal data. All requests can be submitted through our support team and will be processed within 14 working days.

Right to Access Data

You may request a copy of all personal data we hold on your account. We will provide it in a readable format within 14 days.

Right to Data Correction

If any of your information is inaccurate or out of date, you have the right to request an immediate correction. We will update our records once verification is complete.

Right to Data Deletion

You may request deletion of your personal data when it is no longer needed, subject to applicable legal obligations for retaining financial records.

Right to Object to Processing

You may object to the use of your data for direct marketing purposes at any time. Any objection will be processed immediately, no questions asked.

Right to Data Portability

You are entitled to receive your data in a structured, machine-readable format for transfer to another service provider of your choice.

Right to Restriction of Processing

In certain circumstances, you may request that we restrict the processing of your data while a dispute or review is being conducted by our team.

Section 06

Cookie Usage

The peti4d platform uses cookies and similar tracking technologies to enhance the user experience, ensure the platform functions properly, and understand overall usage patterns.

Types of Cookies Used

  • Essential Cookies: Required for core platform functions such as login session management, security, and language preferences. These cookies cannot be disabled.
  • Performance Cookies: Collects information about how you use the platform (pages visited, errors encountered) to help us improve performance. All data is aggregated and not personally identifiable.
  • Functional Cookies: Saves your preferences such as display settings, language, and game preferences so you don't have to reconfigure them each time.
  • Analytics Cookies: Helps us understand overall traffic and user behaviour through our internal analytics tools.
Cookie Controls: You can control or delete cookies through your browser settings at any time. However, disabling certain cookies may affect the functionality of some peti4d platform features.

Cookie Validity Period

Session cookies are automatically deleted when you close your browser. Persistent cookies are stored for the duration specified in each cookie, typically between 30 days and 12 months, depending on the cookie's purpose.

Section 07

Data Retention & Deletion

Peti4d retains members' personal data only for as long as necessary to fulfil the purposes stated in this policy or as required by applicable law. The following are our data retention guidelines:

  • Active Account Data: Retained for the duration of the active account and throughout the business relationship.
  • Financial Transaction Records: Retained for a minimum of 7 years after a transaction occurs, in line with Malaysia's tax and accounting legal requirements.
  • KYC & Verification Logs: Retained for 5 years after account termination in accordance with AML requirements.
  • Log & Audit Data: Retained for 2 years for security and investigation purposes.
  • Support Communication: Retained for 3 years to allow historical reference when required.

Data Deletion Process Upon Account Closure

When you close your peti4d account, your personal data will be handled as follows: marketing information and personal preferences not required by law will be deleted within 30 days; data subject to a legal retention period will be kept until that period expires before being permanently deleted from all our systems.

Exceptions: In cases where an account is closed following a fraud investigation or legal action, relevant records may be retained for a longer period in accordance with the requirements of the investigation or applicable court orders.
Section 08

Privacy Policy Amendments

Peti4d reserves the right to update or amend this Privacy Policy from time to time to reflect changes in our privacy practices, new legal requirements, or platform service improvements. All amendments are made to ensure your data protection remains relevant and adequate.

How We Notify You

When significant changes are made to this policy, we will notify you via in-platform notifications, email to your registered address, and a prominent notice on the peti4d homepage at least 14 days before the changes take effect. For minor changes such as grammatical corrections or clarifications, we will update the version date only.

Continuity of Use

Continued use of the peti4d platform after the effective date of any amendment is considered your acceptance of the updated policy. If you disagree with any changes, you have the right to close your account and request data deletion in accordance with the procedures outlined in Section 07.

Version Records: All previous versions of this Privacy Policy are retained by peti4d and available upon request. Contact our support team at [email protected] if you require an earlier version for reference.

Contact Our Data Protection Officer

For any inquiries, complaints, or requests relating to your privacy and personal data, please contact peti4d's Data Protection Officer via email [email protected] or via live chat on the platform. We are committed to responding to every inquiry within 3 business days.

FAQ

Privacy-Related FAQs

Absolutely not. peti4d has never and will never sell, rent, or disclose members' personal data to any third party for marketing or commercial purposes. Your data is only shared in very limited situations — such as legal requirements or with service providers supporting our platform operations — and is subject to strict confidentiality agreements.

You may submit a data access request through the peti4d customer support team, available 24 hours a day, 7 days a week. Contact us via live chat on the platform or by email at [email protected], specifying the type of data required. Requests will be processed within 14 working days and data will be delivered in a secure format.

Once an account is closed, marketing data and personal preferences not required by law will be deleted within 30 days. However, financial and transaction records must be retained for 7 years under Malaysian tax law, while KYC records are kept for 5 years in accordance with AML requirements. After these periods, all data will be permanently deleted.

No. peti4d does not store your full credit or debit card number on our servers. All card transactions are processed through a PCI DSS-certified payment gateway that returns only a secure token to our system. Your sensitive financial data always remains within an environment that meets the highest international payment security standards.

Yes, you can opt out of marketing communications at any time. Click the "unsubscribe" link in any marketing email you receive, or contact our support team to update your communication preferences. Requests will be processed within 5 business days. Please note that important account and security notifications cannot be disabled as they are part of our core service.
Trusted Platform

Join peti4d — A Platform That Respects Your Privacy

You now have a clear picture of our commitment to personal data protection. Register today and enjoy a safe, fair, and responsible gaming experience alongside more than 50,000 active peti4d Malaysia members.

256-bit SSL Protected Data Malaysia PDPA Compliance No Sale of Personal Data
Bahasa Melayu