Apo388 Privacy Policy – Malaysian User Data Protection

Apo388 is committed to protecting the privacy and personal data of all members. This document clearly explains how we collect, use, store, and protect your information.

Updated: January 2026 256-bit SSL Sensitive Data Bahasa Melayu
Privacy Policy
Version 3.1 · 2026

Apo388 Privacy Commitment

Six core principles that shape our approach to data protection

Advanced Multi-Layer Data Encryption

All data transmitted between your device and apo388 servers is protected by 256-bit SSL encryption. This means your personal and financial information cannot be intercepted or read by unauthorised parties during transmission.

Strict Access Control

Only apo388 staff who have been granted specific authorisation may access members' personal data, and only for legitimate operational purposes. All access is automatically logged and monitored to detect any unauthorised use.

No Sale of Data to Third Parties

Apo388 does not sell, rent, or share members' personal data with third parties for marketing purposes without your consent. Your data belongs to you — we only use it to enable you to enjoy the platform's services safely.

Secure Data Storage

Members' personal data is stored on servers protected by industry-grade firewalls, intrusion detection systems, and regular backups. Our data centres comply with the ISO 27001 international security standard to ensure the integrity of your data.

Your Privacy Control Options

Apo388 gives you control over your personal data. Through your account settings, you can manage communication preferences, request access to stored data, or submit a data deletion request in accordance with your rights under data protection law.

Local Law Compliance

Apo388's Privacy Policy complies with Malaysia's Personal Data Protection Act 2010 (PDPA) and international data protection standards. We conduct periodic compliance reviews to ensure our practices consistently meet the latest legal requirements.

Note: By using the apo388 platform, you agree to this Privacy Policy. Please read this document carefully to understand how your personal data is managed. This Policy applies to all users of the apo388.onl website.

01 Introduction and Scope of the Privacy Policy

This Privacy Policy ("Policy") is published by apo388 ("we", "Platform") to describe our commitment to protecting the personal data of all users and members of the apo388.onl platform. We understand that privacy matters greatly to you, and we take this responsibility seriously.

This Policy describes the types of personal data we collect, the purposes for collecting it, how we use it, who we share it with where necessary, and the security measures we take to protect your data. It also outlines your rights as a user with regard to your personal data.

This Policy applies to all services provided through the apo388.onl website, the apo388 mobile app, and all other digital platforms operated under the apo388 brand. By continuing to use our platform following any amendments to this Policy, you are deemed to have accepted the updated terms.

02 Types of Personal Data We Collect

Apo388 collects your personal data through various means, including during account registration, platform usage, and interactions with our support team. Below is a summary of the data we may collect:

Data Category Example Information Collection Method
Identity Information Full name, identification card number, date of birth, gender Registration form, KYC process
Contact Information Email address, phone number, residential address Registration form, profile updates
Financial Information Bank account number, bank name, digital wallet details Deposit and withdrawal process
Usage Data Game records, betting history, access times Automatic activity during usage
Technical Data IP address, device type, web browser, approximate location Automated logging systems, cookies
Communications Live chat records, support emails, feedback Interactions with the support team

2.1 Data You Provide Directly

This includes all information you actively provide during account registration, profile updates, identity verification (KYC), deposit or withdrawal requests, and when interacting with our customer support team via live chat or email.

2.2 Data Collected Automatically

When you use the apo388 platform, our systems automatically record technical information including your IP address, web browser type and version, device operating system, pages visited, time and duration of visits, and actions taken within the platform. This data helps us improve platform performance and detect any suspicious activity.

03 How We Use Your Personal Data

Apo388 uses your personal data only for legitimate purposes directly related to the provision of platform services. We do not use your data for any other purpose without obtaining your consent first. The following are the primary purposes for which your personal data is used:

  • Account Management: Creating, verifying, and managing your account on the apo388 platform, including secure login processes and two-factor authentication
  • Transaction Processing: Processing deposits, withdrawals, and all financial transactions securely and efficiently
  • Identity Verification (KYC): Ensuring compliance with anti-money laundering (AML) legal requirements and verifying that you meet the minimum age requirement
  • Customer Support: Providing technical assistance and resolving your enquiries or complaints more effectively
  • Platform Security: Detecting and preventing fraud, account abuse, cyber intrusions, and activities that violate the terms of use
  • Service Improvement: Analysing aggregated usage patterns to enhance the user experience, improve platform performance, and develop new features
  • Service Communications: Sending important notifications related to your account, security updates, policy changes, and transaction information
  • Legal Compliance: Fulfilling applicable legal obligations, regulatory requirements, and court orders
Our commitment: apo388 will not use your personal data to make automated decisions that have a material negative impact on you without appropriate human review.

04 Data Sharing with Third Parties

Apo388 does not sell your personal data to any third party. However, there are certain situations where we need to share your information with specific parties to enable the platform to function properly:

4.1 Trusted Service Providers

We share necessary data with third-party service providers who help us operate the platform, including payment gateway providers, identity verification service providers, cloud infrastructure providers, and customer support service providers. All third parties are bound by strict confidentiality agreements and are prohibited from using your data for any purpose other than those specified by apo388.

4.2 Legal Compliance and Regulatory Authorities

Apo388 may be required to disclose your personal data to government authorities, regulatory bodies, or law enforcement agencies when mandated to do so by Malaysian law or a valid court order. In such situations, we will disclose only the minimum information necessary.

4.3 Game Providers

To enable you to access games from leading providers on our platform, certain game session information is shared with the respective game providers. This is technical information required to ensure games function correctly, and not sensitive personal data.

Protection: Every third party that receives data from apo388 is bound by a data protection agreement requiring them to safeguard your information to the same standards we uphold.

05 Data Security Measures

Apo388 invests seriously in security infrastructure to ensure your personal data is always protected against unauthorised access, loss, destruction, or accidental disclosure. The following are the security layers we employ:

  • 256-bit SSL Encryption: All communications between your device and our servers are secured with the latest TLS 1.3 protocol
  • Two-Factor Authentication (2FA): An additional security layer for account login using SMS codes or an authenticator app
  • 24/7 Monitoring: An automated monitoring system operating around the clock to detect suspicious or abnormal activity
  • Hashed Password Storage: Your password is stored in hashed form using the bcrypt algorithm — we ourselves cannot read your password
  • Data Segregation: Sensitive data such as financial information is stored separately with an additional layer of encryption
  • Regular Backups: Data is automatically backed up daily to a secure, geographically separate location to ensure service continuity
  • Penetration Testing: Independent security assessments are conducted periodically by third-party cybersecurity experts
Security Certificate: apo388 servers are PCI-DSS certified for payment card data processing and comply with ISO 27001 standards for information security management.

While we take all reasonable steps to protect your data, no security system can guarantee 100% protection. We therefore encourage you to take precautions such as using a strong password, not sharing your login credentials, and enabling two-factor authentication on your account.

06 Cookies and Tracking Technologies

Apo388 uses cookies and similar tracking technologies to enhance the user experience, analyse platform performance, and ensure account security. Cookies are small text files stored on your device when you visit our website.

6.1 Types of Cookies We Use

  • Essential Cookies: Required for core platform functions such as login session verification and account security. These cookies cannot be disabled without affecting platform functionality
  • Performance Cookies: Collecting anonymous statistical data on how users interact with the platform to help us improve the user experience
  • Preference Cookies: Saving your settings and preferences such as language, time zone, and preferred display layout
  • Security Cookies: Helping detect suspicious login attempts and protecting your account from unauthorized access

6.2 Cookie Management

You can manage and delete cookies through your web browser settings. Please note, however, that disabling certain cookies may affect the functionality of the apo388 platform and your overall user experience. For guidance on managing cookies in your browser, refer to your browser's help section.

07 Your Privacy Rights as a User

As an apo388 member, you have certain rights regarding your personal data under Malaysia's Personal Data Protection Act 2010 (PDPA). We respect and facilitate the exercise of these rights:

Right of Access

You have the right to request and obtain a copy of all personal data we hold about you at any time.

Right to Rectification

If your data is inaccurate or incomplete, you have the right to request a correction or update to that information.

Right to Erasure

You may request the deletion of your personal data, subject to legal and operational requirements that necessitate record retention.

Right to Object

You have the right to object to the processing of your data for direct marketing purposes or in certain other circumstances.

Right to Data Portability

You may request your personal data in a machine-readable format for transfer to another platform if required.

Right to Restriction

In certain circumstances, you may request that we restrict the processing of your personal data while a dispute is being resolved.

How to Submit a Request: To exercise any of the above rights, contact the apo388 support team via live chat or email at [email protected]. We will process your request within 14 business days.

08 Child Data Protection

Apo388 is a platform exclusively for adults aged 18 and above. We do not knowingly collect personal data from anyone under 18. If you are a parent or guardian and believe your child has provided us with personal data without your consent, please contact us immediately so we can take appropriate action to delete that information.

Apo388's age verification system is designed to screen underage users during the registration process. However, should any case slip through this verification, we take responsibility to respond promptly upon being notified.

09 Cross-Border Data Transfers

In operating the apo388 platform, some of your personal data may be processed or stored on servers located outside Malaysia. These cross-border data transfers occur in the context of using cloud infrastructure services and international game providers.

In all cases of cross-border data transfers, apo388 ensures that:

  • The recipient country or region provides a level of data protection equivalent to or higher than that of Malaysia
  • Legally binding data protection agreements are established with data recipients
  • Appropriate transfer mechanisms are applied in accordance with relevant legal requirements
  • Data is only transferred for legitimate purposes necessary for the provision of platform services

10 Data Retention Period

Apo388 retains your personal data for as long as necessary to fulfil the purpose of collection or as required by law. In general, our data retention policy is as follows:

  • Active Account Data: Retained for the duration that your account remains active and in use
  • Financial Transaction Records: Retained for a minimum of 7 years from the transaction date to comply with legal and audit requirements
  • KYC Documents: Retained for a minimum of 5 years after account closure to comply with anti-money laundering regulations
  • Communication Logs: Customer support interaction records are retained for 3 years for reference and dispute resolution
  • Technical Data & Logs: System logs are retained for 12 months for security and technical troubleshooting purposes

Once the designated retention period expires, your personal data will be securely deleted or anonymised using methods that ensure the data cannot be recovered or identified.

11 Contact Us Regarding Privacy

If you have any questions, concerns, or complaints regarding this Privacy Policy or how we handle your personal data, the apo388 Data Protection Officer (DPO) team is ready to assist you. We take every privacy concern seriously and are committed to responding within a reasonable timeframe.

For formal complaints regarding personal data protection that we are unable to resolve, you also have the right to contact the Department of Personal Data Protection Malaysia (JPDP) or the relevant regulatory authority in your jurisdiction.

Response Time: We are committed to responding to all privacy-related enquiries within 3 business days and resolving data rights requests within 14 business days.

Your Data Is Safe with apo388

Create an account today and enjoy a secure gaming experience. Your privacy is our priority.

Bahasa Melayu