Our commitment to protecting personal data under Malaysian law.
This PDPA Statement sets out how IT Paradise Solutions Sdn. Bhd., the operator of SMS-LAH, complies with the Personal Data Protection Act 2010 (Act 709) of Malaysia ("PDPA"). It should be read together with our full Privacy Policy.
The PDPA regulates the processing of personal data in commercial transactions in Malaysia. IT Paradise Solutions Sdn. Bhd. is a registered data processor and, for the personal data of our platform users, also acts as a data user (controller) under the PDPA.
We take our obligations under the PDPA seriously. We have implemented technical, administrative, and physical safeguards to protect all personal data processed through the SMS-LAH platform.
Our data handling practices are guided by the seven principles of the PDPA:
Personal data is processed only with the data subject's consent and for lawful purposes.
Data subjects are informed of the purposes for which their data is collected, and may choose whether to provide it.
Personal data is not disclosed to third parties without the data subject's consent, except as required by law.
Practical steps are taken to protect personal data from loss, misuse, modification, and unauthorised access.
Personal data is not retained longer than necessary for the purposes for which it was collected.
Reasonable steps are taken to ensure personal data is accurate, complete, and up to date.
Data subjects may request access to their personal data and request corrections where necessary.
SMS-LAH operates in a dual capacity under the PDPA:
When you register and use SMS-LAH, we hold the following personal data about you:
This data is used solely to provide and maintain the Service, communicate with you about your account, and comply with our legal obligations. We do not use it for third-party marketing without your explicit consent.
When you upload contact lists to SMS-LAH, you are the Data User responsible for that personal data under the PDPA. By using our platform to send SMS to those contacts, you represent and warrant that:
We process contact data strictly on your instructions. We do not use your contact lists for our own purposes and do not sell or share this data with any third party except telecommunications carriers for the sole purpose of delivering the SMS you have authorised.
As the Data User, you are responsible for ensuring consent compliance. We recommend the following best practices for Malaysian businesses:
To deliver SMS to international destinations, message content and recipient phone numbers are passed to international telecommunications carriers. This may involve data being processed in countries outside Malaysia.
We ensure that any such transfer is conducted with appropriate safeguards, including contractual clauses with carriers that bind them to confidentiality and data protection standards no less stringent than those required under Malaysian law.
As our customer, you have the following rights under the PDPA:
Submit requests by email to it@mobile360.cc with the subject line "PDPA Data Request". We will acknowledge within 5 business days and respond substantively within 21 days.
In the event of a personal data breach that poses a risk to data subjects, we will:
If you discover or suspect a breach involving data on our platform, please contact us immediately at it@mobile360.cc.
Our designated Personal Data Compliance contact is responsible for overseeing PDPA compliance within IT Paradise Solutions Sdn. Bhd. All data protection queries, access requests, and complaints should be directed to:
You also have the right to lodge a complaint with the Department of Personal Data Protection (JPDP) of Malaysia if you believe your personal data rights have been violated.
⚠️ Disclaimer: This PDPA Statement is provided for informational purposes. It is not a substitute for legal advice. If you have specific compliance questions, we recommend consulting a qualified legal professional familiar with Malaysian data protection law.