Privacy Policy Alpha8 —
Protection of Your Personal Data

Alpha8 is committed to protecting the privacy and data security of every member. This document clearly outlines how we collect, use, and safeguard your information in accordance with the Malaysian Personal Data Protection Act 2010 (PDPA).

Updated: 1 January 2026  |  Effective immediately
1

Introduction & alpha8's Privacy Commitment

Alpha8 ("we", "our platform") understands that your trust is our most valuable asset. When you entrust us with your personal data, we take that responsibility very seriously. This Privacy Policy explains in detail how alpha8 handles your personal information from the moment of registration through every daily interaction you have with our platform.

This policy applies to all services provided by alpha8, including the official website at alpha8.app, our mobile app for iOS and Android, and all our customer support channels. By using any alpha8 service, you agree to the collection and use of information as described in this Privacy Policy.

Legal Compliance: The alpha8 Privacy Policy is designed to fully comply with the Malaysian Personal Data Protection Act 2010 (PDPA). We respect every individual's right to privacy and strive to maintain high standards of data protection.

We periodically review and update this Privacy Policy to ensure it reflects our current practices and any changes in applicable legislation. The effective date of the current version is stated at the top of this document.

2

Types of Personal Data We Collect

Alpha8 only collects personal data necessary to deliver our services safely and effectively. The following are the categories of data we collect:

Identity Data

  • Full name as shown on official identification documents
  • Identity card number (MyKad) or passport number for foreign nationals
  • Date of birth for minimum age verification of 18 years
  • Full address including postcode and state
  • Phone number for account verification and communications
  • Email address that is active and reachable

Financial Data

  • Registered bank account number for deposits and withdrawals
  • Bank name and account type
  • Deposit, withdrawal, and wagering transaction records
  • Registered e-wallet details (Touch 'n Go, GrabPay, and others)

Platform Usage Data

  • Login history including date, time, and IP address
  • Device type, operating system, and web browser used
  • Gaming and wagering activity records
  • Account settings and communication preferences

Data Minimisation Principle: Alpha8 only collects data that is strictly necessary for the stated purposes. We do not collect sensitive personal data such as medical information, religious beliefs, or political views.

The following is a summary of data categories and their legal basis for collection:

Data Category Example Basis of Collection
Identity Verification Name, MyKad, date of birth Contractual requirement & KYC
Financial Bank accounts, transaction records Contractual & legal requirement
Platform Usage Login, IP, device Legitimate interests & security
Communications Support email, live chat Contractual requirement
Cookies & Analytics Browsing data, preferences User consent
3

How We Use Your Personal Data

Alpha8 uses your personal data only for lawful, transparent purposes directly related to the delivery of our services. The following are the primary purposes for which your data is used:

  • Account management: Creating, verifying, and maintaining your member account, including the required KYC (Know Your Customer) process.
  • Transaction processing: Processing deposits, withdrawals, and wagering activity securely and accurately.
  • Identity verification: Verifying that you meet the minimum age requirement and all other eligibility criteria.
  • Fraud prevention: Identifying and preventing fraudulent activity, money laundering, and unauthorised access to your account.
  • Customer support: Providing technical support and resolving any issues you encounter.
  • Service communications: Sending important notifications relating to your account, transactions, and policy changes.
  • Platform improvement: Analysing usage patterns to improve the overall user experience.
  • Legal compliance: Fulfilling reporting and compliance obligations to the relevant authorities.

We will NOT: Selling your personal data to third parties for marketing purposes, using your data for automated decision-making that significantly affects your rights, or sharing your data without a valid legal basis.

4

Data Sharing with Third Parties

Alpha8 does not sell, rent, or disclose your personal data to third parties for marketing purposes without your explicit consent. However, there are situations where data sharing may be necessary or permitted:

Trusted Service Providers

Alpha8 works with carefully selected third-party service providers to help operate the platform. These include payment processors, identity verification services, cloud computing providers, and analytics companies. All providers are bound by strict confidentiality agreements and are only permitted to use your data for specified purposes.

Legal & Regulatory Requirements

Alpha8 may be required to disclose your personal data to government authorities or law enforcement agencies where mandated by a court order, warrant, or lawful legal requirement. In such situations, we will notify you where permitted by law to do so.

Business Transfer

In the event of any merger, acquisition, or sale of company assets, members' personal data may be transferred as part of those assets. You will be notified in advance via email or an in-platform notification should this occur, and your rights under this Privacy Policy will continue to be upheld.

Our Commitment: Every third party that receives data from alpha8 is held to the same rigorous data protection standards as our own. We make no compromises on this.

5

Data Security and Protection Measures

The security of your personal data is alpha8's top priority. We continually invest in the latest security technologies and processes to protect your data from unauthorised access, loss, or unintended disclosure.

Technical security measures we employ:

  • 256-bit SSL/TLS Encryption: All data transmitted between your browser and alpha8's servers is protected with military-grade encryption.
  • Hashed password storage: Your password is never stored in plain text — we use a one-way, irreversible hashing algorithm.
  • Two-factor authentication (2FA): An additional security layer that can be enabled to protect your account from unauthorised access.
  • 24/7 Monitoring: Active security monitoring system that identifies and responds to threats in real time.
  • Regular security audits: Regular independent security assessments conducted by external experts to identify and address vulnerabilities.
  • Internal access controls: Only staff who require access to specific data to carry out their duties are authorised to do so.

Data Breach: In the event of a security breach affecting your personal data, alpha8 is committed to notifying you within 72 hours of becoming aware of the incident, in accordance with PDPA requirements.

6

Cookies, Analytics, and Tracking Technologies

Alpha8 uses cookies and similar tracking technologies to enhance your experience on our platform. Cookies are small text files stored on your device when you visit our website.

Types of Cookies We Use

  • Essential cookies: Required for core platform functions such as login, session management, and security. These cookies cannot be disabled without affecting platform functionality.
  • Performance cookies: Collecting information about how you use the platform to help us improve our services. This data is gathered in aggregate form and does not identify you individually.
  • Functional cookies: Remembering your preferences such as language, display settings, and login details for your convenience.
  • Analytics cookies: Helps us understand overall platform usage patterns for continuous improvement.

You can manage your cookie settings through your web browser at any time. However, disabling certain cookies may affect the functionality and user experience of the alpha8 platform. For more information on managing cookies, please refer to your web browser's help documentation.

7

Your Rights Over Personal Data

Under the Malaysian Personal Data Protection Act 2010 (PDPA), you have the following rights regarding your personal data held by alpha8:

Right to Access

You have the right to request a copy of the personal data we hold about you at any time.

Right to Rectification

If your data is inaccurate or outdated, you have the right to request immediate correction.

Right to Object

You may object to the processing of your data for direct marketing purposes at any time.

Right to Restriction

In certain situations, you may request that we temporarily restrict the processing of your data.

To exercise any of the above rights, contact our data protection team via the in-platform live chat or our support email. We will process your request within 21 calendar days in accordance with PDPA requirements.

Identity Verification Required: To protect your privacy, alpha8 may need to verify your identity before processing any requests relating to your personal data. This is a standard security measure to ensure your data is not disclosed to unauthorised parties.

8

Data Retention Period

Alpha8 retains your personal data only for as long as necessary for the purposes stated in this Privacy Policy, or as required by applicable law. The following are our data retention guidelines:

  • Active account data: Retained for the duration your account remains active and in use.
  • Financial transaction data: Retained for a minimum of 7 years in accordance with Malaysia's financial reporting and anti-money laundering legal requirements.
  • Support communication records: Retained for 3 years from the date of last interaction.
  • Closed account data: Basic data retained for 7 years after account closure for legal compliance purposes before being securely deleted.
  • Security logs: Retained for 12 months for the purpose of investigating any security incidents.

When data is no longer needed and there is no legal obligation to retain it, alpha8 will securely delete or anonymise that data using industry-recognised methods.

9

Cross-Border Data Transfers

In operating the alpha8 platform, your personal data may be processed and stored on servers located outside Malaysia. This typically occurs in the context of cloud computing services or international technology infrastructure providers.

When your data is transferred outside Malaysia, alpha8 ensures that:

  • The recipient country or region has a level of data protection comparable to Malaysia's PDPA.
  • Appropriate data transfer agreements are in place to protect your data, including recognised standard contractual clauses.
  • Third-party providers outside Malaysia that receive your data are bound by strict data protection obligations.

Global Standards: All cross-border data transfers by alpha8 comply with international data protection standards. Your data is never transferred to any jurisdiction that lacks adequate privacy protections.

10

Contact Us About Privacy

If you have any questions, concerns, or complaints regarding this Privacy Policy or how alpha8 handles your personal data, we encourage you to contact us directly. Our data protection team is ready to assist you.

How to contact us:

  • Live chat: The fastest way — click the chat icon within the alpha8 platform, available 24 hours a day, 7 days a week.
  • Email: Contact us at [email protected] for privacy and data protection-specific enquiries.
  • Response time: We commit to acknowledging every inquiry within 3 business days and providing a full response within 21 calendar days.

If you are not satisfied with how we handle your privacy complaint, you have the right to lodge a complaint with the Personal Data Protection Commissioner of Malaysia (PDPC) through their official channels.

How Alpha8 Protects Your Data

Six data security pillars we employ to ensure your privacy is protected at all times

End-to-End Encryption

All data transmitted between your device and alpha8's servers is protected with 256-bit SSL/TLS encryption. No one can intercept or eavesdrop on your information in transit.

Integrated & Secure KYC

Our identity verification (KYC) process uses the latest technology to verify your documents securely. KYC data is stored in a strictly controlled environment and is never shared without a legitimate reason.

Full PDPA Compliance

Alpha8's privacy policy and data handling practices are designed to fully comply with the Malaysian Personal Data Protection Act 2010. Your rights as a data subject are fully respected.

No Data Sales

Alpha8 has never and will never sell members' personal data to any third party for marketing purposes. Your data belongs to you — we only use it to provide you with a better service.

Responsible Data Retention

We only retain data for as long as it is genuinely necessary. Once data is no longer relevant and there is no legal obligation to keep it, it is securely deleted using industry-recognised data disposal methods.

Immediate Breach Notification

In the event of any security incident affecting your data, alpha8 is committed to notifying you within 72 hours. Transparency is a core value for us in critical situations.

Your Data is Safe. Your Gaming is Fun.

Join over 500,000 Malaysian members who trust alpha8 as their safe, fair, and transparent online gaming platform. Your privacy is our responsibility.

Full PDPA compliance 256-bit Encryption No data sales 24/7 Support
Bahasa Melayu