Section 1
Introduction
kayu33 ("we", "us", "our") is committed to protecting the privacy and personal data of all individuals who access or use the kayu33 platform, including registered members, visitors, and prospective members (collectively, "you" or "users"). This Privacy Policy sets out in detail the types of personal information we collect, the purposes for which we process it, the parties with whom it may be shared, the security measures we employ to protect it, and the rights you have in relation to your personal data.
This Policy applies to all personal data collected through kayu33.asia and all associated sub-domains, mobile-optimised web interfaces, live chat systems, customer support channels, and any other touchpoint through which you interact with kayu33. It should be read in conjunction with the kayu33 Terms & Conditions, which govern the contractual relationship between you and kayu33.
If you have questions about this Privacy Policy or wish to exercise any of your data rights, please contact kayu33 using the details provided in Section 14 of this Policy. We are committed to responding to all data-related enquiries promptly and transparently.
Section 2
Personal Data We Collect
kayu33 collects personal data through various means, including directly from you during account registration, through your use of the Platform, and through automated technical mechanisms. The categories of personal data we collect include:
- Identity Data: Full legal name, date of birth, gender, and copies of government-issued identification documents (such as MyKad or passport) where provided for identity verification purposes.
- Contact Data: Email address, Malaysian mobile phone number, and residential address.
- Account Credentials: Username and encrypted password hash. kayu33 does not store your password in plain text under any circumstances.
- Financial Data: Payment method details submitted for deposit and withdrawal transactions, including bank account numbers, e-wallet identifiers (Touch 'n Go, Boost, GrabPay), FPX transaction references, and cryptocurrency wallet addresses where applicable. Full card numbers are not stored by kayu33; payment card processing is handled by PCI-DSS compliant third-party payment processors.
- Transaction Data: Records of all deposits, withdrawals, bets, wagers, game play sessions, bonus redemptions, and related financial activity on your kayu33 account.
- Technical Data: IP address, browser type and version, operating system, device identifiers, time zone, referring URL, pages visited, session duration, and other technical data collected automatically when you access the Platform.
- Usage Data: Information about how you use the kayu33 Platform, including game preferences, betting patterns, session frequency, and feature usage.
- Communications Data: Records of your interactions with kayu33 customer support, including live chat transcripts, email correspondence, and any written complaints or feedback you submit.
- Responsible Gaming Data: Any deposit limits, loss limits, self-exclusion periods, or other responsible gaming preferences you have configured on your kayu33 account.
We collect only the personal data that is necessary for the purposes described in this Policy. You are not obligated to provide personal data to kayu33, but failure to provide required information may prevent you from registering an account or accessing certain services.
Section 3
How We Use Your Personal Data
kayu33 uses the personal data we collect for the following purposes:
- Account Management: To register and maintain your kayu33 account, authenticate your identity at login, and manage your account preferences and settings.
- Service Delivery: To provide you with access to the kayu33 sportsbook, casino, slots, and all other platform features and content.
- Transaction Processing: To process your deposits, withdrawals, wagers, and bonus transactions, and to maintain accurate financial records.
- Identity Verification & Fraud Prevention: To verify your identity and age in compliance with our anti-money laundering and responsible gaming obligations, and to detect, investigate, and prevent fraudulent or suspicious activity.
- Customer Support: To respond to your enquiries, resolve disputes, process complaints, and communicate with you about your account.
- Regulatory Compliance: To meet our obligations under applicable laws and licensing requirements, including anti-money laundering (AML) and know-your-customer (KYC) regulations.
- Platform Improvement: To analyse usage patterns, diagnose technical issues, and improve the performance, security, and content of the kayu33 Platform.
- Responsible Gaming: To monitor gambling activity for indicators of problem gambling and to administer responsible gaming tools including self-exclusion and deposit limits.
- Marketing Communications: To send you promotional offers, bonus notifications, and news about kayu33 products and services, where you have provided consent to receive such communications or where we have a legitimate interest in doing so. You may opt out of marketing communications at any time.
Section 4
Legal Basis for Processing
kayu33 processes your personal data on the following legal bases:
- Contractual Necessity: Processing required to perform our contractual obligations to you under the kayu33 Terms & Conditions, including account management, transaction processing, and service delivery.
- Legal Obligation: Processing required to comply with applicable laws and regulations, including AML/KYC obligations, age verification requirements, and licensing conditions.
- Legitimate Interests: Processing necessary for kayu33's legitimate business interests, including fraud prevention, platform security, business analytics, and responsible gaming monitoring, where such interests are not overridden by your rights and interests.
- Consent: Processing based on your explicit consent, including the sending of direct marketing communications. Where processing is based on consent, you have the right to withdraw your consent at any time without affecting the lawfulness of processing carried out before withdrawal.
Section 5
Data Sharing & Third-Party Disclosure
kayu33 does not sell, rent, or trade your personal data to third parties for their own marketing purposes. We may share your personal data with the following categories of third parties, strictly for the purposes described in this Policy:
- Payment Processors: Third-party payment service providers (including e-wallet operators such as Touch 'n Go and Boost, and Malaysian banking institutions via FPX and DuitNow) for the purpose of processing your financial transactions. These providers are contractually bound to process your data only as directed by kayu33 and in accordance with applicable data protection standards.
- Identity Verification Providers: Third-party KYC and identity verification service providers engaged to assist kayu33 in meeting its age verification and anti-money laundering obligations.
- Game Software Providers: Licensed gaming software providers whose games are hosted on the kayu33 Platform may receive certain technical and gameplay data necessary for game delivery and fairness auditing.
- Customer Support Platforms: Third-party live chat and CRM platforms used to manage customer support interactions. These providers process data only on kayu33's behalf and under data processing agreements.
- Legal & Regulatory Authorities: We may disclose personal data to law enforcement agencies, regulatory bodies, courts, or other government authorities where required by applicable law, court order, or legal process.
- Professional Advisers: Lawyers, auditors, and other professional advisers engaged by kayu33 in connection with legal proceedings, compliance obligations, or business operations, subject to confidentiality obligations.
All third-party service providers with whom kayu33 shares personal data are contractually required to implement appropriate technical and organisational security measures and to process personal data only for the specified purpose and in accordance with kayu33's instructions.
Section 6
Cookies & Tracking Technologies
kayu33 uses cookies and similar tracking technologies on the kayu33 Platform to enhance your experience, analyse usage, and support Platform functionality. A cookie is a small text file placed on your device by a web server when you access a website.
The types of cookies kayu33 uses include:
- Strictly Necessary Cookies: Essential for the Platform to function correctly, including session authentication, security tokens, and load balancing. These cookies cannot be disabled without affecting your ability to use the Platform.
- Performance & Analytics Cookies: Used to collect anonymised data about how users interact with the Platform, including page views, session duration, and error rates, to help us improve Platform performance.
- Functional Cookies: Used to remember your preferences, such as language settings and display preferences, to provide a more personalised experience.
- Session Management Cookies: Used to maintain your login session and protect your account from unauthorised access.
You can control cookie settings through your browser settings. Disabling certain categories of cookies may affect the functionality of the kayu33 Platform. By continuing to use the Platform without disabling cookies, you consent to our use of cookies as described in this Policy.
Section 7
Data Retention
kayu33 retains personal data for as long as necessary to fulfil the purposes for which it was collected, to meet our legal and regulatory obligations, and to resolve disputes and enforce our agreements. Specific retention periods vary by data category:
- Account identity and registration data is retained for the duration of your account and for a minimum of five years following account closure, to meet AML and KYC record-keeping obligations.
- Financial transaction records are retained for a minimum of seven years in accordance with applicable financial record-keeping requirements.
- Customer support communications are retained for three years from the date of the interaction.
- Technical log data and usage analytics are typically retained for up to 24 months.
- Marketing consent records are retained for the period during which marketing is conducted plus three years following opt-out.
Where personal data is no longer required for any lawful purpose, kayu33 will securely delete or anonymise it in accordance with our data disposal procedures.
Section 8
Data Security
kayu33 implements a comprehensive set of technical and organisational security measures designed to protect your personal data against unauthorised access, accidental loss, destruction, alteration, or disclosure. These measures include:
- SSL/TLS encryption for all data transmitted between your device and kayu33 servers;
- Encryption of sensitive data at rest, including financial data and account credentials;
- Role-based access controls limiting staff access to personal data to those with a legitimate business need;
- Regular security audits, vulnerability assessments, and penetration testing of the kayu33 Platform;
- Multi-factor authentication for administrative access to kayu33 internal systems;
- Intrusion detection and monitoring systems operating 24/7.
Notwithstanding the above, no method of electronic transmission or storage is 100% secure. kayu33 cannot guarantee absolute security of your personal data. In the event of a personal data breach that poses a risk to your rights and freedoms, kayu33 will notify affected individuals and relevant authorities as required by applicable law.
You are responsible for keeping your kayu33 login credentials confidential. Never share your password. If you suspect unauthorised access to your account, contact kayu33 support immediately.
Section 9
Your Data Rights
Subject to applicable law, you have the following rights in respect of your personal data held by kayu33:
- Right of Access: You have the right to request a copy of the personal data kayu33 holds about you and information about how it is processed.
- Right to Rectification: You have the right to request correction of inaccurate or incomplete personal data. You may update certain account information directly through your kayu33 account settings.
- Right to Erasure: You have the right to request deletion of your personal data in certain circumstances, including where the data is no longer necessary for the purpose for which it was collected. This right is subject to overriding legal obligations, such as AML record-keeping requirements, that may require us to retain certain data.
- Right to Restriction of Processing: You have the right to request that we restrict the processing of your personal data in certain circumstances, such as while a rectification request is being assessed.
- Right to Data Portability: You have the right to receive personal data you have provided to us in a structured, commonly used, machine-readable format in certain circumstances.
- Right to Object: You have the right to object to processing of your personal data based on legitimate interests, including direct marketing. You may opt out of marketing communications at any time by contacting support.
- Right to Withdraw Consent: Where processing is based on your consent, you may withdraw that consent at any time without affecting the lawfulness of processing based on consent before withdrawal.
To exercise any of these rights, please contact kayu33 using the details in Section 14. We will respond to all verifiable data rights requests within 30 days. In some cases, we may need to verify your identity before processing your request.
Section 10
Children & Minors
The kayu33 Platform is strictly intended for adults aged 21 years and above. kayu33 does not knowingly collect personal data from individuals under the age of 21. Our registration process includes age verification steps to prevent minors from accessing the Platform.
If kayu33 becomes aware that personal data has been collected from a person under the age of 21, we will take immediate steps to delete that data and terminate the associated account. If you are a parent or guardian and believe your child has registered an account with kayu33, please contact us immediately using the details in Section 14.
Section 11
International Data Transfers
kayu33 may transfer your personal data to servers or third-party service providers located outside Malaysia. Where personal data is transferred internationally, kayu33 ensures that appropriate safeguards are in place to protect your data, including contractual data protection clauses with the recipient organisations that require them to provide an equivalent standard of data protection to that applicable in Malaysia.
By using the kayu33 Platform, you consent to the transfer of your personal data to servers and third-party service providers in other jurisdictions, subject to the protections described in this Policy.
Section 12
Third-Party Links
The kayu33 Platform may contain links to third-party websites, payment portals, or game providers. This Privacy Policy applies only to the kayu33 Platform. kayu33 is not responsible for the privacy practices or content of any third-party websites. We encourage you to read the privacy policies of any third-party services you access through or in connection with the kayu33 Platform.
Section 13
Changes to This Privacy Policy
kayu33 reserves the right to update or amend this Privacy Policy at any time. Material changes will be communicated to registered members via the email address on file or through a prominent notice on the Platform. The "Last Updated" date at the top of this page reflects the date of the most recent revision.
Continued use of the kayu33 Platform following notification of any material change to this Policy constitutes your acceptance of the updated Policy. We encourage you to review this Policy periodically to stay informed about how kayu33 protects your personal data.
Section 14
Contact & Data Enquiries
For all privacy-related enquiries, data rights requests, or concerns regarding the handling of your personal data by kayu33, please contact our Data Protection team:
Email: [email protected] (plain text only — not a clickable link)
Please include your registered username and a clear description of your request. kayu33 will acknowledge all data protection enquiries within 48 hours and provide a substantive response within 30 days. Where a request is complex or relates to a large volume of data, we may extend this period by up to a further 30 days, with notification to you of the extension and reasons.