Privacy Policy of Classmethod Malaysia
Effective Date: November 1, 2025
Last Updated: November 1, 2025
1. Introduction
This Privacy Policy explains how Classmethod Malaysia Sdn. Bhd. (“we”, “us”, “our”) collects, uses, discloses, and otherwise processes your Personal Data in accordance with the Malaysian Personal Data Protection Act 2010 (“PDPA”).
We are committed to protecting your privacy and ensuring that your Personal Data is handled in a safe and responsible way. When we refer to “Services,” we mean the products, websites, applications, and services that we provide.
2. Who We Are
Classmethod Malaysia Sdn. Bhd.
Registered Address: Menara Pernas, Tower 7, Avenue 7, Bangsar South, Kuala Lumpur, Malaysia
Pursuant to the PDPA, we act as a Data Controller for all Personal Data collected through our Services.
In accordance with the PDPA, we have appointed a Data Protection Officer (“DPO”) to oversee compliance. We have notified the Personal Data Protection Commissioner of Malaysia of this appointment, as required by law.
3. Personal Data We Collect
Pursuant to PDPA, the term “Personal Data”refers to any information which directly or indirectly identifies you or makes you identifiable from such information and other information that we possessed, including any sensitive personal data and expression of opinion about you. For the avoidance of doubt, Personal Data does not include anonymized or aggregated data where your identity cannot be ascertained.
We may collect the following categories of Personal Data:
- Information you provide to us
- Name, mailing address, telephone number, email address, login credentials, identification number, date of birth, gender, profile photo
- Payment information such as credit card details, bank account, billing address
- Inquiries, feedback, and correspondence with us
- Information collected automatically
- Usage data such as access times, pages viewed, logs, browsing activity
- Device information such as IP address, device type, operating system, browser type/version, language settings
- Cookies or similar technologies
- Information from third parties
- Data obtained via social login or integration with third-party services
- Data from partners, service providers, or affiliates
- Sensitive Personal Data
- We do not collect sensitive personal data unless explicitly required by law or with your explicit consent. Under PDPA, sensitive personal data includes health information, religious beliefs or other beliefs of a similar nature, the commission or alleged commission of any offence, political opinions, financial details, biometric identifiers and any other personal data as may be specified in the laws and regulations.
- Where collected, we will apply enhanced safeguards such as restricted access, encryption, and shorter retention periods.
4. Purposes of Processing
We collect and process your Personal Data for the following purposes:
- To provide, operate, and maintain our Services.
- To process payments and manage billing.
- To improve,customize and personalize our Services.
- To communicate with you, including responding to inquiries, providing updates, and sending notifications.
- To protect our Services, users, and the public, including fraud prevention, security, enforcement of agreements.
- To comply with legal, regulatory, or contractual obligations
- For research, analytics, or statistical purposes
5. Legal Basis for Processing
Processing of your Personal Data is based on:
- Consent: where you have given explicit consent.
- Contractual Necessity: where the processing is necessary for the performance of a contract with you.
- Legitimate Interests: where the processing is required to meet our business needs, provided they do not override your rights.
- Legal Obligation: where the processing is required to comply with applicable laws and regulations.
6. Disclosure and Sharing of Personal Data
Your Personal Data will not be disclosed to any third party for purposes other than those for which it was originally collected, unless you have provided your explicit and informed consent to such disclosure.
We may disclose your Personal Data if it is necessary to protect your vital interests, or the vital interests of another person, where you are incapable of giving consent.
We may also disclose or share your Personal Data with:
- Our affiliates or subsidiaries within the Classmethod Group.
- Third-party service providers for payment processing, IT services, hosting, analytics, marketing, or support.
- Business partners in joint initiatives (only with your consent, if required).
- Law enforcement, regulators, or government authorities, where required by law.
- Third-Party processors. If we engage third-party service providers, we will ensure that such third-party processors are contractually required to:
- Implement appropriate technical and organisational measures to protect your Personal Data
- Process data only on our instructions.
- Promptly notify us of any actual or suspected personal data breach.
7. Joint Use within the Classmethod Group
We may jointly use your Personal Data within the Classmethod Group (including Classmethod Inc. in Japan, its subsidiaries, and affiliates in other countries) for the purposes described in this Privacy Policy.
- Scope of Data: Limited to the types of data collected as set out in this Privacy Policy.
- Purposes of Joint Use: Consistent with the purposes described herein (e.g., service delivery, support, customer management, marketing, etc.).
- Entities Involved: Classmethod Inc. (Japan), Classmethod Malaysia Sdn. Bhd. and other subsidiaries as listed on https://classmethod.jp/company/.
- Management Responsibility: Classmethod Malaysia Sdn. Bhd. is responsible for ensuring compliance and proper handling of jointly used data.
8. Data Security
We implement appropriate technical and organizational measures to safeguard your Personal Data from unauthorized access, disclosure, alteration, or loss. These measures may include encryption, access controls, secure storage, and regular security reviews.We also require all third-party processors to implement equivalent safeguards.
9. Retention of Personal Data
We retain Personal Data only as long as necessary to fulfill the purposes described in this Privacy Policy or as required by law. When retention is no longer necessary for the processing, we will delete or anonymize your data in a secure manner.
10. Your Rights
Under PDPA, you have the right to:
- Access and obtain a copy of your Personal Data. We will respond to your request within twenty-one (21) days of reciept.
- Request correction, update, or deletion of your Personal Data.
- Withdraw your consent for processing. We will stop processing your Personal Data within reasonable timeframe, subject to any legal, contractual obligations, or legitimate interests that require continued processig.
- Restrict or object to certain types of processing.
- File a complaint with the Malaysian Personal Data Protection Commissioner.
- Request transfer of your Personal Data to another data controller. We will transfer your Personal Data to another data controller without undue delay, subject to technically feasible.
You may direct your request to us by contacting our DPO. We may require verification of your identity.
We will response to your requests in accordance with the PDPA and any other applicable laws and regulations.
11. International Data Transfers
Your Personal Data may be transferred to, stored, or processed outside Malaysia, including in countries where other Classmethod Group companies or service providers are located. We will ensure that the recipient country provides protections substantially similar to those under the PDAPA. For all such transfers, we will take all necessary measures to ensure the security and confidentiality of your Personal Data, including the use of legally binding data transfer agreements.
12. Mandatory Data Breach Notification
In the event of a personal data breach, we will:
- Notify the Malaysian Personal Data Protection Commissioner as soon as practicable.
- Where the breach is likely to cause significant harm, notify you without undue delay.
- Provide you with information regarding the nature of the breach, the categories of the Personal Data affected, likely consequences, remedial measures, and contact details for any inquiries.
13. Links to Third-Party Websites
Our Services may contain links to websites, services, and content operated by third parties. We do not have control over these third-party websites and are not responsible for their privacy practices. You are advised to review the privacy policies of any third-party website you visit to understand their data collection and processing procedures.
14. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. Updates will be posted on our website, and significant changes will be made and communicated through appropriate channels.
15. Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights, please contact our DPO:
- Name / Title: Uomi Kentaro / Director
- Email: uomi.kentaro@classmethod.my
- Postal Address: Menara Pernas, Tower 7, Avenue 7, Bangsar South, Kuala Lumpur, Malaysia