Official Data Protection Document

Privacy Policy Dafa Malaysia

At dafa, your privacy is not merely a legal obligation — it is a core commitment we have upheld from day one. This document clearly explains how we handle your personal data in accordance with Malaysia's Personal Data Protection Act 2010 (PDPA).

Last updated: 1 January 2026 Estimated reading time: 8 minutes Language: Malay (ms-MY)

Data Collected Minimally

Dafa only collects information strictly necessary to deliver its services — name, email, phone number, and payment details. No data is collected without a clear and defined purpose.

256-bit SSL Encryption

All data transmitted between your device and dafa's servers is protected with industry-standard 256-bit SSL encryption. Stored data is further secured through hashing and additional encryption methods.

Right of Access & Correction

You have the right to access, correct, or request deletion of your personal data at any time. Contact the dafa privacy team and we will process your request within 30 days.

PDPA 2010 Compliance

Dafa's privacy policy is designed in full compliance with Malaysia's Personal Data Protection Act 2010. We do not process your personal data without a valid legal basis.

No Sale of Data to Third Parties

Dafa has never sold and will never sell your personal data to advertisers or unrelated third parties. Data sharing is strictly limited to partners required for the operation of the platform.

Marketing Communications Control

You may choose whether to receive marketing communications from dafa. You can unsubscribe at any time through your account settings or via the unsubscribe link in any email you receive.

1

Introduction

Welcome to the Privacy Policy dafa. This document sets out in detail how dafa (operated via dafa-khelo.com) collects, processes, stores, and protects your personal data as a member of our platform in Malaysia.

We understand that your trust is not something to be taken lightly. Whether you are depositing funds via Touch 'n Go eWallet or GrabPay, placing a bet on your favourite EPL match, or playing live casino baccarat late at night — every one of those interactions involves your personal data, and we take full responsibility for keeping it safe.

This Privacy Policy is drafted in accordance with Personal Data Protection Act 2010 (PDPA) Malaysia and international data protection best practices. By using the dafa platform, you acknowledge that you have read and understood this policy.

Quick Summary: Dafa collects only the data it needs, uses it to deliver the best possible service, protects it with the latest technology, and never sells it to anyone. You have full control over your data.
2

Personal Data We Collect

Dafa collects personal data from various sources when you interact with our platform. Below are full details of the types of data we collect:

A. Data You Provide Directly

  • Registration information: Full name, email address, Malaysian mobile number, date of birth, and encrypted password.
  • Identity information (KYC): National identity card number (MyKad), copies of identification documents, and proof of current address where required for account verification.
  • Financial information: Details of the payment method you use — including your Touch 'n Go eWallet account number, GrabPay, DuitNow, Boost, ShopeePay, or FPX Maybank2u / CIMB Clicks account. dafa does not store full debit/credit card numbers.
  • Contact information: Messages you send to our customer support team.

B. Automatically Collected Data

  • Technical data: IP address, browser type, device operating system, screen resolution, and language settings.
  • Usage data: Pages you visit, products you use (football, cricket, badminton, slots, live casino), time spent, and betting patterns.
  • Transaction data: A complete record of all deposits, withdrawals, bets, and winnings made through your account.
  • Approximate location data: Based on your IP address for regional verification and legal compliance purposes.
  • Cookie data: Session information, user preferences, and analytics data (further detailed in Section 8).
Note: Dafa does not collect sensitive data such as medical information, religious beliefs, or political views. Biometric data is also not collected through our platform.
3

How We Use Your Personal Data

The personal data we collect is used for the following purposes only, and we will not use your data for any other purpose without notifying you in advance:

Purpose of Use Data Involved Legitimate Interest
Account management and verification Name, email, MyKad Required
Deposit & withdrawal processing Payment information, transaction records Required
Fraud detection & security IP, betting patterns, device data Required
Customer support Communication records, account history Required
Dafa marketing & promotions Email, game preferences Options
Analytics & product improvement Anonymised usage data Options
4

Legal Basis for Data Processing

Under the Personal Data Protection Act 2010 (PDPA) of Malaysia, dafa processes your personal data on the following legal bases:

  • Consent: For marketing communications and non-essential cookies, we require your active consent. You may withdraw this consent at any time.
  • Contractual Necessity: Data required to operate dafa's services — such as processing deposits via DuitNow or FPX, verifying member identity, and processing bets — is handled on this basis.
  • Legitimate Interest: For fraud prevention, platform security, and product improvement purposes, we process data on the basis of legitimate business interests, balanced against your privacy rights.
  • Legal Obligation: For anti-money laundering (AML) compliance, tax obligations, and directives from lawful authorities.
5

Data Sharing with Third Parties

Dafa does not sell your personal data to any third party. However, we do share data in the following limited circumstances to enable the platform to operate:

  • Payment processors: Transaction details required for processing are shared with payment providers such as Touch 'n Go, GrabPay, FPX banking partners (Maybank, CIMB), DuitNow, and others to facilitate your deposits and withdrawals.
  • Technology service providers: Cloud infrastructure, security systems, and analytics tools used by dafa may process your data, but they are bound by strict confidentiality agreements.
  • Law enforcement authorities: We disclose data when required by court order, Malaysian law, or a legitimate request from authorities in connection with fraud or money laundering investigations.
  • Business recipients: Should dafa be involved in any merger, acquisition, or asset sale transaction, members' personal data may be transferred to the new entity with appropriate notice given to members.
All third parties that receive data from dafa are bound by data protection agreements and are required to uphold security standards equivalent to or higher than those set by dafa.
6

Data Security Measures

Dafa continuously invests in security infrastructure to ensure your personal data remains protected at all times. Key measures we have implemented include:

  • Transmission encryption: All data transmitted between your device and dafa's servers is protected by TLS 1.3 with 256-bit encryption — the same standard used by Malaysia's leading financial institutions.
  • Storage encryption: Sensitive data such as passwords are stored as bcrypt hashes that cannot be decrypted. Payment details are stored as encrypted tokens.
  • Access controls: Access to members' personal data is granted to dafa employees on a strictly need-to-know basis, with access records subject to regular audits.
  • Two-factor authentication (2FA): Available and recommended for all dafa member accounts as an added layer of security.
  • 24/7 Monitoring: Intrusion detection systems (IDS) and around-the-clock monitoring of suspicious activity to detect and respond to any security threats.
  • Regular security audits: dafa conducts regular penetration testing and independent security audits.
While we take all reasonable measures to protect your data, no security system is completely impenetrable. Should a data breach involving your personal data occur, we will notify you within 72 hours as required by law.
7

Data Retention Period

Dafa retains your personal data for as long as necessary to fulfil the purpose for which it was collected, or as required under Malaysian law:

Data Type Retention Period Reason
Active account data For the duration of the active account Service operations
Financial transaction records 7 years after transaction AML & tax regulatory requirements
Closed account data 5 years after account closure Regulatory requirements
Customer support log 3 years Dispute resolution
Marketing data (with consent) Until consent is withdrawn Consent-based

Once the retention period expires, data will be securely deleted or anonymised so that it can no longer be identified.

8

Cookies & Tracking Technologies

Platform dafa uses cookies and similar tracking technologies to enhance your experience. The following are the types of cookies we use:

Cookie Type Purpose Duration Status
Essential Cookies Login, session, security Session / 30 days Mandatory
Preference Cookies Language, theme, preferences 1 year Mandatory
Analytical Cookies Usage statistics, improvement 2 years Options
Marketing Cookies Relevant advertising, remarketing 90 days Options

You can manage your cookie settings through your browser. Please note that disabling essential cookies may affect the functionality of the dafa platform.

9

Your Rights Under PDPA 2010

As a data subject under Malaysia's Personal Data Protection Act 2010, you have the following rights regarding your personal data held by dafa:

👁️
Right of Access
Request a copy of the personal data we hold about you
✏️
Right to Rectification
Correct inaccurate or incomplete data
🗑️
Right to Erasure
Request data deletion under certain circumstances
⏸️
Right to Restrict Processing
Restrict how we process your data
↩️
Right to Withdraw Consent
Withdraw marketing consent at any time
📦
Data Portability Rights
Receive a copy of your data in a readable format

To exercise any of the rights above, please contact the dafa privacy team by email at privacy@dafa-khelo.com or via our customer support page. We will process your request within 30 days from the date of receipt.

In certain cases, we may be unable to fulfil your request in full if doing so would breach our legal obligations — for example, financial record-keeping requirements under Malaysia's AML laws.
10

International Data Transfers

In the course of its operations, dafa may transfer your personal data to servers located outside Malaysia. When this occurs, we ensure:

  • The recipient country or region maintains an adequate level of data protection, or
  • Appropriate safeguards are in place, including Standard Contractual Clauses that bind data recipients to protection standards equivalent to Malaysia's PDPA 2010.
  • Any international transfers are solely for the purpose of operating the dafa service and do not exceed the scope required.
11

Children's Privacy

Platform dafa is intended solely for individuals aged 18 years and above. We do not knowingly collect or process personal data from minors.

Should we discover that personal data belonging to a person under the age of 18 has been collected without valid parental or guardian consent, we will take immediate steps to delete that data and close the account in question.

Parents or guardians who believe their child has registered on the dafa platform are required to contact us immediately at support@dafa-khelo.com.

12

Amendments to This Privacy Policy

Dafa reserves the right to update this Privacy Policy from time to time to reflect changes in our privacy practices, applicable laws, or improvements to our services.

Any material changes to this Privacy Policy will be communicated to you via:

  • An email notification to your registered address at least 14 days before the changes take effect.
  • A prominent notice on the dafa platform homepage.
  • Updating the "Last Updated" date at the top of this document.

Continued use of the dafa platform after any changes take effect constitutes your acceptance of the amended Privacy Policy.

13

Contact Us About Privacy

If you have any questions, concerns, or complaints regarding this Privacy Policy or how we handle your personal data, please contact our Data Protection Officer (DPO) dafa:

Privacy Email
privacy@dafa-khelo.com
Response within 3 business days
Customer Support
support@dafa-khelo.com
24/7 – Bahasa Melayu

This Privacy Policy was last updated on 1 January 2026 and supersedes all previous versions.

🔒

Your Data Is in Safe Hands Dafa

We take every aspect of your personal data protection seriously. Register with dafa today and enjoy a safe, fair, and exciting sports betting and casino experience — with the peace of mind that your privacy is always protected.

PDPA 2010 Compliance
256-bit SSL Encryption
No Data Sales
Bahasa Melayu