Updated: 1 January 2026

Privacy Policy pgtoto – Personal Data Protection for Malaysia Members

Pgtoto values the privacy of every member. This document transparently explains how we collect, use, store, and protect your personal information as a user of the pgtoto platform in Malaysia.

256-bit SSL
Full Encryption
No Data Sales
Your Data Is Secure
Malaysia PDPA
Full Compliance
Regular Audits
Reviewed Quarterly
Encrypted Data256-bit SSL at all times
Secure ServersMulti-layered data storage
Restricted AccessLicensed personnel only
Right to ErasureRequest data deletion at any time

Pgtoto's Six Core Privacy Principles

Our commitment to your privacy is more than a document — it is a daily practice upheld at every level of pgtoto's operations.

Minimum Data Collection

Pgtoto only collects information that is strictly necessary to provide our services. We do not gather excessive or irrelevant data. Every piece of information requested has a clear, lawful purpose.

Multi-Layered Security

All pgtoto member personal data is encrypted using the same 256-bit SSL technology employed by Malaysia's leading banking institutions such as Maybank and CIMB. Our servers are protected by multi-layered firewalls and a real-time intrusion detection system.

Your Data, Your Control

As a pgtoto member, you have full rights to access, correct, download, or request deletion of your personal data at any time. We believe your data belongs to you — we are simply its custodians.

No Sale of Data to Third Parties

Pgtoto has never and will never sell, rent, or share members' personal data with advertisers, marketing companies, or any third party without explicit consent. Your data is not a commodity we trade.

Malaysia PDPA Compliance

The pgtoto Privacy Policy is built entirely in accordance with Malaysia's Personal Data Protection Act 2010 (PDPA). We conduct quarterly compliance audits and continuously update our privacy practices in line with the latest legislative amendments.

Immediate Breach Notification

In the event of a security incident involving pgtoto member data, we are committed to notifying affected members within 72 hours of detecting the incident, in line with global industry best practices.

Important Note: By registering for and using the pgtoto platform, you consent to the collection and processing of your personal data as described in this Privacy Policy. If you do not agree with any part of this policy, please contact us or discontinue your use of the pgtoto platform.

1

Introduction & Scope of pgtoto's Privacy Policy

This Privacy Policy ("Policy") is published by pgtoto ("we", "pgtoto", "Platform") and applies to all users and members who access or use the pgtoto platform, including the website, mobile applications, and all related services in Malaysia.

This policy describes the types of personal information we collect from users, how we use it, who we share it with, and the measures we take to protect it. We are committed to safeguarding your privacy and ensuring your information is used only for legitimate and transparent purposes.

This pgtoto Privacy Policy is in full compliance with Malaysia's Personal Data Protection Act 2010 (PDPA) and international data protection best practices. We review this policy at least once every six months to ensure it remains relevant and up to date.

2

Types of Personal Data Collected by pgtoto

Pgtoto collects various types of personal information depending on how you interact with our platform. Below is a summary table of the data categories we collect:

Data Category Sample Information Requirements
Identity DataFull name, date of birth, MyKad numberMandatory
Contact DataMalaysian phone number, email addressMandatory
Financial DataPayment methods (TNG, GrabPay, DuitNow, FPX), RM transaction historyMandatory
Usage DataLogin, slot/casino/sports betting game history, session durationAutomatic
Technical DataIP address, device type, web browser, operating systemAutomatic
Location DataApproximate location based on IP address (state within Malaysia)Automatic
Communication DataCustomer support correspondence, feedbackWhen necessary

Note: pgtoto does not store your credit card numbers or full banking details. Financial transactions are processed through licensed payment providers that maintain their own rigorous security standards.

3

How pgtoto Collects Your Personal Data

Pgtoto collects personal information through several different channels:

  • Account Registration: Information you provide when registering a pgtoto account, such as your name, email, phone number, and date of birth.
  • Identity Verification (KYC): A copy of your MyKad or passport may be requested for age and identity verification purposes in accordance with compliance requirements.
  • Financial Transactions: Information recorded when you make a deposit via Touch 'n Go eWallet, GrabPay, DuitNow, FPX Maybank2u, CIMB Clicks, Boost, or ShopeePay, as well as during fund withdrawals.
  • Platform Usage: Data collected automatically while you play slots, Live Casino, bet on Malaysia Super League football or IPL cricket – including activity logs, game preferences, and usage patterns.
  • Communications: The content of your correspondence with the pgtoto customer support team via live chat, email, or Telegram.
  • Cookies & Tracking Technologies: Technical data collected via web browser cookies and tracking pixels as described in Section 7.
4

How pgtoto Uses Your Data

Pgtoto uses collected personal data solely for legitimate and transparent purposes, including:

  • Providing, managing, and improving pgtoto's platform services for you
  • Identity and age verification to fulfil KYC obligations and Malaysian legal compliance requirements
  • Processing deposit and withdrawal transactions in Malaysian Ringgit (MYR)
  • Detection and prevention of fraud, money laundering, and other illegal activities
  • Calculation and crediting of relevant pgtoto bonuses and promotions
  • Customer support and complaint resolution
  • Delivery of essential service communications such as transaction confirmations and security updates
  • Compliance with applicable legal, regulatory, and reporting obligations
  • Platform usage analysis for product improvement and user experience enhancement

Marketing: pgtoto may send you promotional communications regarding offers, bonuses, and new promotions. You may opt out of marketing communications at any time by clicking the "Unsubscribe" link in any email or by contacting pgtoto customer support.

5

Data Sharing with Third Parties

Pgtoto does not sell, rent, or share members' personal data to third parties for commercial purposes. However, in the context of legitimate business operations, data may be shared with the following parties:

  • Payment Service Providers: Licensed Malaysian payment providers such as Touch 'n Go operators, GrabPay, DuitNow, and banks operating FPX – solely for the purpose of processing MYR transactions.
  • Game Providers: Casino and slots game studios that supply games to pgtoto – limited to data necessary for the provision of gaming services.
  • Legal Authorities: When required by Malaysian law, court order, or a lawful government enforcement agency.
  • Audit & Compliance: An independent audit firm that conducts security and compliance reviews of the pgtoto platform – under a strict confidentiality agreement.

Our commitment: All third parties receiving data from pgtoto are bound by data confidentiality agreements that prohibit them from using such information for any purpose other than what is specified. pgtoto is responsible for ensuring that third parties adhere to equivalent data protection standards.

6

Pgtoto's Data Security Measures

Pgtoto invests seriously in cybersecurity infrastructure to protect members' personal data. The security measures we have implemented include:

  • End-to-End Data Encryption: All data transmitted between your browser and pgtoto's servers is encrypted using TLS 1.3 protocol with 256-bit SSL certificates.
  • Secure Data Storage: Data is stored on servers protected with server-level encryption (AES-256) at ISO 27001-certified data centres.
  • Access Controls: Only pgtoto staff who require access to perform their duties are permitted to do so, and all access is logged and audited.
  • Two-Factor Authentication: pgtoto's internal systems require two-factor authentication for all staff accessing sensitive member data.
  • Security Audit: Security audits by independent firms are conducted quarterly to identify and address vulnerabilities.
  • Incident Response Plan: pgtoto has established procedures in place to respond to data breaches promptly and efficiently.
7

Cookies, Tracking Technologies & Your Choices

Pgtoto uses cookies and similar tracking technologies to enhance your experience on our platform. The types of cookies we use:

  • Essential Cookies: Required for core platform functions such as login sessions and security. Cannot be disabled.
  • Performance Cookies: Collects analytics on how users interact with the platform for improvement purposes. Data is collected in aggregate and anonymised form.
  • Functional Cookies: Saves your preferences such as language, theme, and display settings to enhance your browsing experience.
  • Marketing Cookies: Used to display relevant promotions and offers. You may choose to disable this type of cookie.

You can manage or disable cookies through your web browser settings at any time. However, disabling essential cookies may affect certain functions of the pgtoto platform.

8

Data Retention & Deletion Period

Pgtoto retains members' personal data only for as long as necessary to fulfil the purposes stated in this policy, or as required under Malaysian law:

  • Active Account Data: Retained for the duration your account is active, plus 7 years after account closure (for legal compliance and dispute purposes).
  • Transaction Records: Retained for 7 years in accordance with Malaysian tax and financial regulatory requirements.
  • Communication Logs: Retained for 3 years from the date of last communication.
  • Cookie Data: Session cookies expire when you log out; persistent cookies expire within 12 months unless renewed.

Once the retention period expires, data will be permanently deleted or anonymised from all pgtoto systems. You may request early deletion in accordance with the rights set out in Section 9, subject to applicable legal requirements.

9

Your Personal Data Rights

As a pgtoto member in Malaysia, you have the following rights regarding your personal data, in accordance with the Personal Data Protection Act 2010 (PDPA):

Right of Access

Request a copy of the personal data we hold about you.

Right to Rectification

Correct data that is inaccurate or incomplete.

Right to Erasure

Requesting data deletion under certain circumstances.

Right to Object

Object to the processing of your data for direct marketing purposes.

Right to Portability

Receive your data in a machine-readable format.

Right to Restriction

Restricting data processing under certain circumstances.

To exercise any of the rights above, please contact pgtoto's Privacy Officer by email privacy@pgtoto.biz. We will process your request within 30 business days.

10

Child Data Protection

The pgtoto platform is a service intended solely for individuals aged 18 and above. pgtoto strictly does not knowingly collect or process the personal data of any individual under the age of 18.

Should we discover that personal data of a minor has been collected without our knowledge, we will take immediate action to delete that data and close the account in question. Parents or guardians who suspect their child has registered a pgtoto account are urged to contact us immediately at privacy@pgtoto.biz.

11

Pgtoto Privacy Policy Amendments

Pgtoto reserves the right to amend or update this Privacy Policy at any time. When material changes are made, we will:

  • Updating the "Last Updated" date at the top of this page
  • Sending notifications to members via their registered email
  • Posting a notice within the pgtoto platform no less than 14 days before the changes take effect

Continued use of the pgtoto platform after any changes take effect will be considered acceptance of the revised Privacy Policy. We encourage you to review this page periodically.

Current Version: pgtoto Privacy Policy version 3.2 – Effective 1 January 2026. Previous versions are available upon request by emailing our Privacy Officer.

12

Contact pgtoto's Privacy Officer

If you have any questions, concerns, or complaints regarding your data privacy at pgtoto, please reach out to us through the channels below. We are committed to responding to all privacy-related enquiries within 72 business hours.

pgtoto Privacy Officer
Email (Privacy Enquiries)privacy@pgtoto.biz
24/7 General Supportsupport@pgtoto.biz
Privacy Response TimeWithin 72 working hours
Office AddressKuala Lumpur, Malaysia

FAQ – pgtoto Privacy Policy

Answers to the most frequently asked privacy questions from pgtoto Malaysia members.

pgtoto will only disclose members' personal information to Malaysian government authorities when required by a valid court order, legal warrant, or legally binding regulatory compliance obligation. In each such case, pgtoto will disclose only the minimum information necessary and, where permitted by law, will notify the relevant member of the disclosure.

Yes, you have the right to request deletion of your personal data from pgtoto's systems. However, certain limitations apply — pgtoto may be required to retain specific data for periods prescribed by Malaysian law, such as financial transaction records which must be kept for 7 years. To submit a deletion request, please contact our Privacy Officer at privacy@pgtoto.biz. We will process your request within 30 days and inform you of the action taken, including details of any data that cannot be deleted and the reasons why.

pgtoto does not store credit card details or full banking data on our servers. All financial transactions are processed directly through licensed Malaysian payment providers such as Touch 'n Go eWallet, GrabPay, DuitNow, FPX Maybank2u, CIMB Clicks, Boost, and ShopeePay. These providers maintain their own PCI-DSS security standards. pgtoto only receives transaction confirmation notifications and your account balance – not the underlying sensitive financial information.

When you close your pgtoto account, your data is not deleted immediately for legal reasons. Financial transaction records must be retained for 7 years in accordance with Malaysian law. Other data will be kept for 7 years from the date of closure before being permanently deleted. During this retention period, access to your data is strictly limited and controlled. All marketing communications from pgtoto will cease immediately upon account closure.

Your Data Is Safe with pgtoto – Begin Your Journey Today

Your privacy is fully protected. Register for a pgtoto account with confidence and claim your Welcome Bonus of up to RM1,000!

Bahasa Melayu