1. Introduction
MyKakaks® is committed to protecting the privacy of every customer, cleaner, applicant and business partner. This Privacy Policy explains how personal data is collected, used, disclosed, stored and protected in accordance with the Personal Data Protection Act 2010 (Malaysia).
2. Definitions
"Personal Data" means any information capable of identifying an individual. "Processing" includes collection, recording, storage, use, disclosure and deletion.
3. Scope
This Policy applies to all MyKakaks websites, mobile applications, customer support channels and related services.
4. Personal Data We Collect
We may collect identity details, contact information, addresses, booking information, payment references, device identifiers, IP addresses, GPS location (where permission is granted), communications, photographs, reviews, employment information and technical logs.
5. How We Collect Data
Information is collected directly from users, automatically through our applications, from payment partners and from authorised third parties.
6. Lawful Purposes
Personal data is processed to create accounts, verify identity, match cleaners, manage bookings, process payments, prevent fraud, improve our technology platform, provide customer support, comply with legal obligations and conduct internal analytics.
7. Legal Basis
Where required, processing is based on consent, contractual necessity, legal obligations and legitimate business interests permitted under Malaysian law.
8. Matching & Location Services
Location data may be used to improve service availability, optimise cleaner matching and provide estimated arrival times.
9. Payments
Payments are processed through authorised payment providers. MyKakaks does not intentionally retain complete payment card information.
10. Cookies & Analytics
Cookies, SDKs and analytics technologies may be used to improve functionality, performance and user experience.
11. Artificial Intelligence
MyKakaks may use AI-assisted technologies to improve customer support, booking recommendations, fraud detection and operational efficiency. Human oversight remains in place for significant business decisions.
12. Marketing
Marketing communications are provided only where permitted by law. Users may opt out at any time.
13. Sharing & Disclosure
Personal data may be shared only with authorised vendors, cloud providers, payment processors, auditors, insurers, regulators and law enforcement where legally required.
14. International Transfers
Where information is processed outside Malaysia, reasonable contractual safeguards will be implemented.
15. Data Security
We employ encryption where appropriate, secure cloud infrastructure, access controls, monitoring, employee confidentiality obligations and periodic security reviews.
16. Data Retention
Personal data is retained only as long as reasonably necessary for legal, operational, accounting and dispute resolution purposes.
17. Your Rights
Subject to the PDPA, users may request access, correction, withdrawal of consent and deletion where legally permissible.
18. Account Deletion
Users may request account deletion by contacting our support team. Certain information may be retained where required by law.
19. Children's Privacy
Services are intended for adults unless otherwise permitted by law.
20. Third-Party Services
Third-party websites and services maintain their own privacy policies.
21. Business Transfers
Personal data may transfer during mergers, acquisitions or investments subject to legal protections.
22. Data Breach Response
Where appropriate, MyKakaks will investigate suspected security incidents, mitigate risks and comply with applicable legal notification requirements.
23. Changes
We may update this Privacy Policy periodically. Continued use constitutes acceptance of the revised version where permitted by law.
24. Contact Details
Privacy Officer
AJS Maju Services Sdn. Bhd.
Brand: MyKakaks®
Phone: +60 12-686 5313
Email: [email protected]
Registered Office: Office 2, Ground floor, Cyberview 9B, Persiaran Apec, Cyber 8, 63000, Cyberjaya, Selangor.
Appendix A — Categories of Personal Data
- Identity
- Contact
- Addresses
- Bookings
- Payment references
- GPS location
- Device information
- Support conversations
- Reviews
- Employment records
Appendix B — Technical & Organisational Security Measures
- Encryption
- Role-based access control
- Multi-factor authentication
- Audit logs
- Vendor due diligence
- Employee confidentiality
- Incident response
- Business continuity
- Regular vulnerability assessments
- Security awareness training