This policy explains what we collect, why, and what we will never do. It is
written to be read, not to be survived. It applies to www.kalsadermaga.com and to the
apps and booking links run from it.
Who is responsible for your data
HAP INT L RESOURCES (202303003933 (IP0579988-T)), of No 17A, Level 1, Jalan Plumbum R7/R, Seksyen 7, 40000 Shah Alam, Selangor, is the data user
for payments and customer records. Kalsa Dermaga Sdn. Bhd. (202601008662 (1670760-T)) is the
data user for the platforms themselves. Both can be reached at
management@kalsadermaga.com or 012-3454520. We handle
personal data in accordance with the Personal Data Protection Act 2010 (Malaysia).
What we collect, and only when you give it
- When you fill in a form: your name, email, phone number and
whatever you wrote in the message. Nothing else.
- When you enrol a child: the child's name and age, and any medical
or dietary note you choose to tell us, so the session is safe for them.
- When you pay: the amount, the time, a reference, and what it was
for. We never see or store your card number — that is handled entirely
by our payment gateway.
- When you join a match: your name and phone number, so the squad
list means something and the organiser can reach you.
- When you book a treatment or a venue: your name, phone number and
the time you booked.
What the website counts, and what it deliberately does not
We count visits so we know which pages are worth keeping. That counter is our own and
it is unusually restrained:
- No cookie. No localStorage. Nothing at all is written to your device.
That is why this site has no cookie banner to dismiss — there is nothing to consent to.
- Nothing goes to Google, Meta or any third party. No advertising
pixels, no trackers, no analytics service. The only copy of the numbers is on our own
server.
- We record the page path, whether you are on a phone or a laptop, and the website
you arrived from — reduced to just its name, never the full address.
- Your IP address is turned into an unreadable one-way value so we can tell one
visitor from two. The key used to do that is destroyed every night, so
yesterday's visitors cannot be re-identified, by us or by anybody who takes the
database. This is why a returning visitor counts again the next day.
What we do with it
Answer you. Take your payment and give you what you paid for. Run the session, the
match, the booking or the order. Keep the records the law requires us to keep. That is
the whole list.
What we will never do
- We do not sell your data. Not to anybody, at any price.
- We do not send you marketing you did not ask for.
- We do not build advertising profiles or share anything with ad networks.
Who else sees it, and why
- Our payment gateway processes the payment. They see what they need
to take money safely. We see only the outcome.
- The venue, club or school you dealt with sees the booking, the
squad list or the order that concerns them, and nothing beyond it. One stall cannot see
another stall's customers.
- Our form provider delivers enquiry forms to our inbox.
- A court or a regulator, if the law requires it. We would tell you
unless we are forbidden to.
Nobody else. Our servers are in Malaysia.
How long we keep it
- Enquiries: 24 months, then deleted.
- Payment and accounting records: 7 years, because Malaysian tax law
requires it.
- Bookings, matches and enrolments: while your account or membership
is active, and 24 months after.
- Visit counts: the events are aggregated, and the means of linking
them back to a person is destroyed nightly as described above.
Your rights
Under the PDPA you may ask us what we hold about you, correct anything wrong, withdraw
consent, or ask us to delete it. Write to management@kalsadermaga.com and we will
answer within 21 days. There is no charge. Some records we must keep for the tax period
above even after you ask — we will say so plainly if that applies.
Children
Little Marine Scientists is a programme for children, and a parent or guardian enrols
them. We collect the least we can — a name, an age, and anything you tell us that keeps
them safe on the day. We never contact a child directly and never publish a child's name
or photograph without the parent's permission.
Keeping it safe
Everything travels over an encrypted connection. Passwords are hashed, never stored as
you typed them. Access is limited to the people who need it to do the job. If a breach
ever affected you, we would tell you and the authorities rather than hope you did not
notice.
Changes
If this policy changes materially we will date it again at the top and say what
changed. Carrying on using the site after that means you accept the new version.