Privacy Document

Privacy Policy & Personal Data Protection Notice

Effective Date: 26 September 2026 | AnySport SRM Technologies / AnySheetDesign

PDPA Compliance: This Privacy Policy explains how AnySport SRM Technologies / AnySheetDesign collects, processes, stores, and protects personal data in compliance with the Personal Data Protection Act 2010 (PDPA) of Malaysia and international data privacy best practices.

1. Personal Data We Collect

When you register for Academy programs, manage staff profiles, or use our digital portals, we collect the following categories of personal information:

  • Student & Parent Information: Full legal name, date of birth, age, gender, contact phone number, emergency contact details, relationship to student, and residential address.
  • Billing & Identification Details: Billing email address, corporate identity (company name, Business Registration Number / BRN, Tax Identification Number / TIN), and uploaded payment proof images.
  • Sports & Academic Performance: Class enrollment choices, attendance timestamps, evaluation skill scores, progress notes, and gamification badge achievements.
  • Security & Authentication: FIDO2 WebAuthn credential identifiers, user role claims, and security audit log metadata. (Biometric credentials like fingerprints or face geometry remain strictly on your local device).

2. Purpose of Data Processing

We process your personal information strictly for legitimate operational purposes, including:

  • Organizing class schedules, capacity limits, and on-court coach assignments.
  • Compiling student billing ledgers, tuition invoices, receipts, and payment reconciliations.
  • Delivering automated class schedule reminders, payment dunning alerts, and achievement updates via WhatsApp and email.
  • Fulfilling statutory tax compliance and mandatory e-invoice reporting with tax authorities.
  • Ensuring physical safety, emergency medical contacts, and participant accountability on court.

3. Third-Party Subprocessors

AnySport contracts trusted technology subprocessors to operate cloud infrastructure under strict confidentiality and security commitments. Our primary subprocessors include:

Subprocessor Purpose Location
Supabase Inc. Cloud Database, Authentication & RLS Storage Singapore / US
Cloudflare, Inc. Global Edge CDN, DNS & Static Hosting Global / Edge
Meta / WhatsApp Cloud API Automated Payment Reminders & Class Notifications Global
Inland Revenue Board of Malaysia (LHDN) Statutory MyInvois E-Invoice & Receipt Reporting Malaysia
Google Gemini AI Automated Bank Transfer Proof Receipt Verification Global / Cloud

4. Security Safeguards & Encryption

We implement industry-grade technical and organizational safeguards:

  • Encryption in Transit: All HTTP traffic is protected using Transport Layer Security (TLS 1.3 / HTTPS).
  • Row-Level Security (RLS): Multi-tenant isolation is enforced at the database kernel level to prevent cross-academy data leaks.
  • Encrypted Backups: Automated off-site database backups are secured with OpenSSL AES-256-CBC encryption.

5. Retention & User Rights

Under the Malaysian PDPA 2010, you have rights regarding your personal information:

  • Right of Access & Correction: You may review and update personal details via the Customer Hub or request corrections from your Academy administrator.
  • Right to Withdraw Consent: You may withdraw consent for promotional messages at any time.
  • Data Retention: We retain active student and transaction records for the duration of enrollment plus statutory accounting and tax retention periods required by law (typically 7 years).

6. Privacy Inquiries & Data Officer

For inquiries, access requests, or privacy concerns, please contact our Data Protection Coordinator at [email protected].

AnySport SRM Technologies / AnySheetDesign