Privacy Policy Surga22 – Your Information Is Fully Protected

At surga22, your privacy is more than a legal obligation β€” it's a personal commitment we stand by. This document transparently explains how we collect, use, store, and protect the personal information of every Malaysian member.

Last updated: 1 July 2026 256-bit SSL Malaysia PDPA Compliant
πŸ” Data Protection Summary
πŸ”’
Full Encryption

256-bit SSL for all data

🚫
No Data Selling

Your data is never sold to anyone

πŸ‡²πŸ‡Ύ
Malaysia PDPA

Compliant with Malaysia's Personal Data Protection Act

βš™οΈ
Full Control

You may access, amend, or delete your data

Surga22 takes our responsibility to every member's privacy and data security seriously. This Privacy Policy is drawn up in accordance with the requirements of Malaysia's Personal Data Protection Act 2010 (PDPA) and reflects best practices in the fintech and online entertainment industry.

By using the surga22 platform β€” including the surga22.ws website, mobile app, and any related services β€” you agree to the collection and use of your information as described in this Privacy Policy. If you do not agree, please discontinue use of our platform.

πŸ’‘ Quick Summary: We only collect data that is strictly necessary, we do not sell your data to anyone, and you have full rights to access, amend, or request deletion of your data at any time.
πŸ“œ
Section 1

Introduction & Scope of Privacy Policy

This Privacy Policy applies to all personal information collected by surga22 across every channel of interaction between you and our platform. This includes the account registration process, gaming activity, financial transactions, customer support interactions, and general use of the surga22 website or app.

Surga22 acts as the data controller and is fully responsible for all personal information collected. We ensure that all data processing is carried out lawfully, fairly, and transparently, in line with Malaysia's PDPA principles.

This policy applies to all users accessing surga22 from Malaysia, including registered members, website visitors, and any individual who interacts with surga22's official communication channels such as support@surga22.ws.

πŸ“‹
Section 2

Types of Information Collected

Surga22 collects several categories of information to enable us to deliver services that are secure, legally compliant, and high in quality. Below is a full breakdown of the data we collect:

Data Category Example Information Requirement
Personal Identity Full name, MyKad number, date of birth, gender, nationality Mandatory
Contact Information Malaysian phone number, email address, residential address Mandatory
Financial Data E-wallet account IDs (Touch 'n Go, GrabPay, DuitNow), FPX bank account details for withdrawals Mandatory
Gaming Data Betting history, wins, losses, favourite games, play duration Automatic
Technical Data IP address, device type, browser version, operating system, session cookies Automatic
Communications Customer support chat records and emails sent to surga22 Contextual
KYC Documents Front and back copy of MyKad, verification selfie, proof of address Required for withdrawals
Note: surga22 will never ask for your bank account password, PIN, or credit card CVV. Never share this information with anyone claiming to represent surga22.
πŸ”
Section 3

How We Collect Information

Surga22 collects your information through several different channels. Understanding how this collection works helps you make informed decisions about the data you share with us.

  • Account Registration: Basic information you fill in when opening a new surga22 account β€” name, Malaysian phone number, email, and password.
  • KYC Verification: The identity document you uploaded during the account verification process prior to making your first withdrawal.
  • Financial Transactions: Data generated when you make a deposit using Touch 'n Go, GrabPay, Boost, ShopeePay, DuitNow, FPX Maybank2u, CIMB Clicks, or other supported Malaysian payment methods.
  • Platform Activity: Automatic records of the games you play, bets you place, and your interactions with the surga22 interface.
  • Cookies & Tracking Technologies: Technical data collected automatically when you browse the website or use the surga22 app.
  • Customer Support: Information you provide when contacting the surga22 support team via email or live chat.
  • Authorised Third Parties: Verification information received from Malaysian payment providers and recognised identity verification systems.
🎯
Section 4

How Your Information Is Used

Surga22 uses collected information only for legitimate purposes that are necessary to operate our services. Every use of data has a clear legal basis under Malaysia's PDPA.

  • Account Management: Creating and maintaining your surga22 account, processing logins, and ensuring secure access.
  • Transaction Processing: Processing your deposits and withdrawals through your chosen local Malaysian payment channels.
  • Legal Compliance (AML/KYC): Fulfilling surga22's obligations under Malaysian anti-money laundering laws.
  • Platform Security: Detecting and preventing fraud, unauthorised access, and misuse of the surga22 platform.
  • Customer Support: Resolving enquiries, complaints, and support requests you submit to surga22.
  • Service Improvements: Analysing usage patterns to improve the gaming experience and surga22 platform functionality.
  • Responsible Gaming: Monitoring gaming activity to identify signs of problem gambling and provide appropriate support.
  • Marketing Communications: Sending surga22 promotional information and offers β€” only to members who have given their consent.
Purpose Limitation Principle: surga22 will not use your data for any purpose beyond what is stated here without first obtaining your renewed consent.
🀝
Section 5

Sharing Information with Third Parties

Surga22 does not sell, rent, or trade members' personal information to any third party for marketing or commercial purposes. This is a commitment we uphold without exception.

However, in the course of operating the platform, surga22 may need to share certain data with the following parties within strictly controlled boundaries:

  • Malaysian Payment Providers: Transaction details required to process deposits and withdrawals via Touch 'n Go, GrabPay, DuitNow, FPX, and any other payment method you choose.
  • Certified Game Providers: Gaming data required by providers such as Pragmatic Play and Evolution Gaming to ensure games function correctly.
  • Identity Verification Services: KYC documents required to fulfil legal compliance obligations.
  • Malaysian Authorities: Information required under Malaysian law, including relevant enforcement agencies and regulatory bodies.
  • Technical Service Providers: Cloud infrastructure and cybersecurity providers that help keep the surga22 platform running securely.
Data Protection Agreement: All third parties working with surga22 are required to sign strict data protection agreements and adhere to privacy standards equal to or higher than our own.
πŸ›‘οΈ
Section 6

Data Security & Protective Measures

Surga22 invests seriously in cybersecurity infrastructure to ensure your data remains protected at all times. We employ multiple complementary layers of security to deliver comprehensive protection.

  • 256-bit SSL/TLS Encryption: All communications between your device and surga22's servers are encrypted using the same standard employed by Malaysia's leading banks.
  • Stored Data Encryption: Sensitive data stored in surga22's databases is encrypted using the AES-256 algorithm.
  • Two-Factor Authentication (2FA): Available to all member accounts and required for sensitive operations such as password changes and withdrawals.
  • 24/7 Monitoring: Automated security systems monitor platform activity around the clock to detect and respond to any threats.
  • Regular Security Assessments: Penetration testing and security audits are conducted regularly by independent cybersecurity experts.
  • Employee Access Controls: Access to member data is restricted to surga22 staff with a legitimate operational need only, with full audit logging in place.
Data Breach Notification: In the event of a data breach that may affect the security of your information, surga22 is committed to notifying you and the relevant authorities within 72 hours of the breach being discovered.
πŸ—„οΈ
Section 7

Data Storage & Retention Period

Surga22 retains your personal information only for as long as necessary for the purposes stated in this Privacy Policy, or as required under applicable Malaysian law.

Data Type Retention Period Reason
Active account information For as long as your account remains active Service operations
Financial transaction records 7 years after transaction PDPA compliance & Malaysian tax laws
KYC Documents 5 years after account closure Malaysia AML Obligations
Game logs 3 years Dispute resolution
Customer support records 2 years Service quality & referrals
Marketing data (with consent) Until you withdraw your consent Marketing communications

Once the retention period expires, your data will be securely deleted using methods that prevent any possibility of recovery, or fully anonymised for analytical purposes.

βš–οΈ
Section 8

Your Rights as a Data Subject

Under Malaysia's Personal Data Protection Act 2010 (PDPA), you have clearly defined rights regarding the personal data held by surga22. We fully respect and facilitate the exercise of these rights.

πŸ‘οΈ
Right of Access

Request a complete copy of the personal data surga22 holds about you at any time.

✏️
Right to Rectification

Request corrections to inaccurate or incomplete data via your account settings or by emailing our support team.

πŸ—‘οΈ
Right to Erasure

Request deletion of your data (subject to ongoing legal obligations).

⏸️
Right to Restriction

Request that surga22 restrict the processing of your data in certain circumstances.

πŸ“¦
Data Portability Rights

Receive your data in a structured format for transfer to another platform should you wish.

🚫
Right to Object

Object to the processing of your data for direct marketing purposes at any time.

How to Exercise Your Rights: Send your request to support@surga22.ws with the subject line "PDPA Data Rights Request". surga22 will respond within 21 business days as required under Malaysia's PDPA.
πŸͺ
Section 9

Cookies & Tracking Technologies

Like most modern websites, surga22 uses cookies and similar tracking technologies to enhance the user experience, maintain session security, and understand how our platform is used.

Cookie Type Purpose Duration
Session Cookies Keeping you logged in during an active session and ensuring secure navigation Expires when browser is closed
Preference Cookies Saving your language preference, theme, and display settings 1 year
Analytics Cookies Helping surga22 understand how users interact with the platform 2 years
Security Cookies Detecting and preventing fraudulent activity and unauthorised access 30 days

You can manage cookies through your browser settings. Please note that disabling certain cookies may affect the functionality of the surga22 platform, particularly session cookies required for login.

πŸ’³
Section 10

Financial Data & KYC Process

Handling financial data requires stricter security and privacy standards. surga22 complies with all obligations under Malaysia's anti-money laundering (AML) laws and the Financial Services Act 2013.

When you use Malaysian payment methods such as Touch 'n Go eWallet, GrabPay, Boost, ShopeePay, DuitNow, or FPX via Maybank2u or CIMB Clicks, transactions are processed through payment gateways compliant with PCI-DSS (Payment Card Industry Data Security Standard). surga22 does not store your full card number or e-wallet password β€” only encrypted transaction tokens are retained in our systems.

The KYC (Know Your Customer) process is a legal requirement that requires you to verify your identity before your first withdrawal can be processed. Documents collected β€” including copies of your MyKad and proof of address β€” are stored in an encrypted environment with access strictly restricted to surga22's compliance team only.

⚠️ Security Notice: surga22 will never contact you to request your password, e-wallet PIN, OTP, or bank card details. If you receive such a request, it is a scam. Report it immediately to support@surga22.ws.
πŸ‘Ά
Section 11

Children's Privacy & Minor Protection

Surga22 has a zero-tolerance policy toward use of the platform by individuals under the age of 18. Our platform is not designed for minors and we do not knowingly collect personal information from underage individuals.

  • A multi-layered age verification system is applied during registration to identify and block underage users.
  • Should surga22 discover that personal information has been collected from an individual under the age of 18, we will promptly delete that information and close the account in question.
  • Parents and guardians are encouraged to install parental control software on devices used by children to prevent access to the surga22 platform.
  • If you have reason to believe that a minor has registered a surga22 account, please contact support@surga22.ws immediately.
πŸ“¬
Section 12

Contact Us About Privacy

If you have any questions, concerns, or requests regarding surga22's Privacy Policy or how we handle your personal data, our privacy team is ready to assist.

  • Privacy Email: support@surga22.ws (use the subject line "Data Privacy Inquiry")
  • Response Time: Within 3 business days for general inquiries; within 21 business days for formal PDPA data rights requests
  • Language of Communication: Bahasa Melayu or English accepted
  • Policy Amendments: We will notify you via your registered email address if any material changes are made to this Privacy Policy
Complaints to Authorities: If you are unsatisfied with how surga22 has handled your data after contacting us, you have the right to lodge a complaint with Malaysia's Department of Personal Data Protection (JPDP) under the Personal Data Protection Act 2010.

Why You Can Trust surga22 with Your Data

More than just a written policy β€” these are the day-to-day operational standards we uphold at every moment

πŸ”
Banking-Grade Encryption

256-bit SSL encryption protects every byte of data transmitted between your device and surga22's servers β€” the same standard used by Maybank, CIMB, and Malaysia's major banks.

πŸ‡²πŸ‡Ύ
PDPA Malaysia Compliant

All of surga22's data handling practices comply with Malaysia's Personal Data Protection Act 2010. Your rights as a data subject are fully respected and upheld.

🚫
Zero Data Selling Policy

Surga22 has never sold, rented, or traded members' personal information to any third party for commercial purposes β€” and we never will. This is our unwavering commitment.

πŸ”
Regular Security Audits

Surga22's systems undergo penetration testing and cybersecurity audits by independent experts on a quarterly basis. Audit findings are used to drive continuous improvements.

βš™οΈ
Your Data, Your Control

Access, correct, download, or request deletion of your data at any time. surga22 processes data rights requests within the timeframes set by Malaysia's PDPA.

πŸ“’
Transparent in Everything

No confusing fine print, no hidden data collection. surga22 clearly explains every type of data collected and the reason behind it.

πŸ” Your Data Is Safe β€” Ready to Play at surga22?

With strict privacy protection and bank-grade security, surga22 is the safest choice for your online entertainment experience in Malaysia.

Other surga22 Policies & Guidelines

Bahasa Melayu