Our commitment to protecting your personal data under Malaysia's Personal Data Protection Act 2010.
🛡️ This notice is issued by SLV Group Sdn. Bhd. (operator of PropertyHub.my) in compliance with Malaysia's Personal Data Protection Act 2010 (PDPA / Act 709). It sets out our obligations as a data processor and your rights as a data subject.
The data controller responsible for your personal data is:
PropertyHub.my processes personal data in accordance with all seven principles of the PDPA 2010:
We process personal data only with the data subject's consent, except where permitted by law. You provide consent when registering, making a booking, or submitting a dispute.
We notify you of the purposes for which your data is collected at the point of collection via this notice, our Privacy Policy, and registration forms. You have the right to choose whether to provide optional data.
We do not disclose your personal data to third parties except as described in our Privacy Policy and this notice. All data sharing is limited to purposes directly related to platform operation.
We implement appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, modification, or disclosure. This includes SSL encryption, password hashing, and access controls.
Personal data is retained only for as long as necessary for the stated purpose or as required by law. Financial records are retained for 7 years per Malaysian statutory requirements.
We take reasonable steps to ensure personal data is accurate, complete, and up to date. You may update your data through your account settings at any time.
You have the right to access and correct your personal data held by us. Requests may be submitted to privacy@propertyhub.my and will be processed within 21 days.
We collect the following categories of personal data:
📌 We do not collect sensitive personal data as defined under the PDPA (race, religion, health, political opinions, criminal record) unless voluntarily and explicitly provided in a dispute description.
Personal data is processed for the following specific purposes:
Under PDPA 2010, we rely on the following legal bases:
✅ Where we rely on consent as the legal basis, you may withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal.
When you make a booking, relevant booking details (name, unit number, date, service requested) are shared with the Partner providing the service. This is necessary to fulfil the contract.
Transaction data is shared with certified payment gateways: iPay88 Sdn. Bhd., Touch 'n Go Digital Sdn. Bhd., PayNet (FPX), and DuitNow. These providers are bound by Bank Negara Malaysia regulations and their own PCI DSS compliance obligations.
TribunalBot uses the Anthropic Claude API for dispute analysis. Dispute-related data submitted for AI review may be processed on Anthropic's servers. We implement data minimisation — only dispute content relevant to the case is transmitted, and personally identifiable information is minimised where possible.
Our platform is hosted on Hostinger servers. Data is primarily stored in servers located within or compliant with applicable data protection standards. We do not intentionally transfer personal data outside Malaysia except as described above.
We do not sell, rent, or trade personal data to any third party for their own commercial purposes.
Under PDPA 2010, you have the following rights:
Request a copy of the personal data we hold about you. We will provide this within 21 days.
Request correction of inaccurate, incomplete, or outdated personal data held about you.
Withdraw consent for processing where consent is the legal basis (e.g. marketing emails). Withdrawal does not affect prior lawful processing.
Request that we stop or limit processing of your data for specific purposes, where there is no overriding legitimate interest or legal obligation.
Request a copy of your data in a structured, commonly-used, machine-readable format (e.g. CSV or JSON).
Request deletion of your personal data, subject to our legal retention obligations (e.g. financial records required by law to be retained for 7 years).
⚠️ Some rights may be limited where processing is necessary for legal compliance, contractual obligations, or fraud prevention. We will always explain the basis for any limitation.
To exercise any of your rights under PDPA, follow these steps:
In the event of a personal data breach that poses a risk to your rights and freedoms, we will:
To report a suspected security issue or data breach, contact security@propertyhub.my immediately.
If you believe we have not handled your personal data in accordance with PDPA 2010, you may:
Our Data Protection Officer is available to assist with any PDPA-related questions.
privacy@propertyhub.my