Privacy Policy

Privacy Policy Surga22 – Member Personal Data Protection

We understand that your privacy is not something to be taken lightly. This document clearly explains how surga22 manages, protects, and respects the personal information of every member.

Updated: 1 January 2026
Language: Malay (Malaysia)
SSL 256-bit Protected
9 Key Sections
Data Encrypted
No Data Selling
Full Right of Access
PDPA Compliant
This Privacy Policy describes surga22's data management practices in accordance with Malaysia's Personal Data Protection Act 2010 (PDPA). By using the surga22 platform, you agree to this policy. Please review this page periodically as we may update it from time to time.

1. Introduction — Surga22's Commitment to Your Privacy

Surga22 takes the personal data privacy of its members with the utmost seriousness. We understand that when you entrust us with your information, you expect it to be handled with full integrity, transparency, and security. That trust is not something we take lightly.

This Privacy Policy applies to all users who access surga22.vu, use the surga22 mobile app or interact with any of the services we offer. It describes the types of data we collect, why it is collected, how it is used, and the rights you hold regarding that data.

We operate on a "privacy by design" principle — meaning data protection is built into every system and process we develop from the ground up, not added as an afterthought. This is the foundation of trust we build with every surga22 member.

surga22 fully complies with Malaysia's Personal Data Protection Act 2010 (PDPA). We do not sell, rent, or share your personal data with third parties for marketing purposes without your explicit consent.

2. Types of Personal Data We Collect

Surga22 only collects data that is strictly necessary to provide quality, secure services and to comply with legal requirements. Below are the categories of data we may collect:

2.1 Data You Provide Directly

  • Full name as shown on official identification documents
  • Date of birth for age verification (must be at least 18 years old)
  • Active email address for account communications
  • Mobile number for two-factor authentication (2FA)
  • Bank account number or e-wallet details for payment processing
  • Copies of KYC documents such as identity card or passport when requested
  • Current residential address for legal compliance purposes

2.2 Data Collected Automatically

  • IP address and location information derived from it
  • Device type, operating system, and browser version used
  • Session data including login times, session duration and in-platform actions
  • Betting history and gaming activity
  • Financial transaction records including deposits and withdrawals
  • Cookie data and related tracking technologies (see Section 6)

2.3 Data From Third-Party Sources

In certain situations, we may receive information about you from payment service providers, identity verification agencies or partner platforms working with surga22 solely for verification and security purposes.

All collected data is stored on servers protected with military-grade encryption. We only retain data that is necessary and securely delete it when it is no longer relevant in accordance with our retention policy.

3. How We Use Your Data

Collected data is used solely for legitimate and transparent purposes. Surga22 does not use your data for any purpose beyond the scope stated below without first obtaining additional consent from you.

Purpose of Use Data Type Legal Basis
Account management and verification Name, email, date of birth Contract performance
Deposit and withdrawal processing Bank details, transaction records Contract performance
Identity verification (KYC/AML) ID documents, address Legal obligation
Security and fraud prevention IP address, device data, login patterns Legitimate interests
Customer Support Email, phone number, account history Contract performance
Promotional communications (with consent) Email, phone number Consent
Platform improvement and analytics Anonymous usage data Legitimate interests

Specifically regarding marketing communications, you may opt out of receiving promotional emails at any time via the "unsubscribe" link in any email or by updating your communication preferences in your surga22 account settings.

4. Information Sharing and Disclosure

Surga22 does not sell or rent your personal data to any third party. However, there are limited situations where we need to share certain information to enable us to deliver our services properly:

4.1 Trusted Service Providers

We work with carefully selected third-party service providers to help operate the platform, including payment processors, KYC service providers, cloud computing companies, and gaming software providers. All parties are bound by strict confidentiality agreements and are only permitted to use your data for specified purposes.

4.2 Legal Requirements

Surga22 may be required to disclose information to government authorities or law enforcement agencies when mandated by law, court order, or to comply with valid legal proceedings. We will always endeavour to notify you of such disclosures where permitted by law.

4.3 Protection of Rights and Safety

In situations where there is a serious threat to the safety of other users or the integrity of the platform, relevant information may be shared with appropriate parties for prevention or investigation purposes.

surga22 will never sell your personal data to advertising companies, data brokers, or any third party for commercial purposes. If you receive any communication claiming to be from surga22 but appears suspicious, please contact our support team immediately.

5. Data Security Measures

Protecting your data is one of the most significant investments surga22 makes. We implement multiple layers of technical and organisational security to ensure your data is always protected against unauthorised access, loss, or misuse.

5.1 Technical Security

  • 256-bit SSL Encryption for all communications between your browser and surga22 servers
  • Encryption of data at rest (AES-256) for all sensitive data stored in the database
  • Two-factor authentication (2FA) available and strongly recommended for all accounts
  • 24/7 Monitoring by an integrated cybersecurity team
  • Penetration testing periodically by independent security firms
  • PCI-DSS Standard adhered to for all payment data processing

5.2 Access Controls

Access to member personal data within the surga22 system is strictly limited to staff who require it to perform their duties. All access is logged and monitored. All staff undergo regular data protection training and are bound by binding confidentiality agreements.

While no system can guarantee absolute security, surga22 employs the best available technology and industry practices. In the event of any security incident involving your data, we will notify you within 72 hours in line with data protection best practices.

6. Cookies, Tracking and Related Technologies

Surga22 uses cookies and similar tracking technologies to enhance user experience, maintain session security, and understand how our platform is used. Below is an explanation of the types of cookies we use:

6.1 Essential Cookies (Required)

These cookies are required for core platform functions such as login session authentication, security, and language preferences. The platform will not function properly without these cookies and they cannot be disabled.

6.2 Performance and Analytics Cookies

We use analytics tools to understand overall platform usage patterns for improvement purposes. This data is collected in aggregate and anonymised — it does not identify you personally.

6.3 Functional Cookies

These cookies remember your preferences such as language, display currency, and interface settings so you do not need to reselect them on every visit.

6.4 Managing Cookie Preferences

You can manage or delete cookies through your browser settings at any time. Please note that disabling certain cookies may affect the functionality of some parts of the surga22 platform.

7. Your Rights Regarding Personal Data

Under Malaysia's PDPA and international data protection best practices, you have the following rights regarding your personal data held by surga22. We are committed to facilitating the exercise of these rights at no unreasonable cost:

Right of Access

You have the right to request a copy of the personal data we hold about you. Requests will be processed within 21 business days.

Right to Rectification

If your data is inaccurate or incomplete, you may request a correction through your account settings or by contacting our support team.

Right to Erasure

In certain circumstances, you may request the deletion of your personal data, subject to legal retention obligations.

Right to Restriction

You may request that we restrict the processing of your data in certain circumstances while a dispute is being resolved.

Right to Object

You may object to the processing of your data for direct marketing purposes at any time, without conditions.

Right to Data Portability

You have the right to receive your data in a machine-readable format for transfer to another service provider.

To exercise any of the above rights, please contact the surga22 Data Protection Officer (DPO) team via the in-platform live chat or our support email. We will process your request promptly and within the timeframe required by law.

8. Data Retention Period

Surga22 retains your personal data only for as long as necessary to fulfil the purposes stated in this policy, or as required by applicable law. Below are our general retention period guidelines:

  • Active account data: Retained for the duration of your active account and up to 7 years after account closure for AML compliance purposes.
  • Financial transaction records: Retained for 7 years in accordance with Malaysian legal requirements.
  • KYC documents: Retained for the duration of the active account and 5 years after account closure or resolution of any active cases.
  • Customer support communication logs: Retained for 3 years after the last interaction.
  • Anonymous analytics data: Can be retained indefinitely as it contains no personally identifiable information.

Once the retention period expires, your data will be securely deleted or anonymised using industry-recognised methods.

9. Contact Us and Data Protection Officer Information

If you have any questions, concerns, or complaints regarding how surga22 handles your personal data, or if you wish to exercise any of the rights stated in this policy, you may contact us through the following channels:

We are committed to responding within 5 business days for all privacy-related inquiries. For more complex matters such as data access requests, the response period is 21 business days as required under PDPA.

If you are not satisfied with our response, you have the right to lodge a complaint with the Malaysia Personal Data Protection Department or the relevant authority in your region.

This Privacy Policy may be updated from time to time to reflect changes in our practices or legal requirements. The "Updated" date at the top of this page will indicate the date of the latest version. Continued use of the surga22 platform after any changes constitutes acceptance of the updated terms.

How Surga22 Protects Your Data Every Day

Not just a promise — this is the data protection system we actively implement

End-to-End Encryption

Every bit of data transmitted between your device and surga22 servers is protected with SSL 256-bit encryption — on par with what leading banking institutions use.

Secure KYC Identity Verification

Our KYC process uses advanced document verification technology. All documents you submit are stored with encryption and securely deleted once the requirement period ends.

Active 24/7 Monitoring

The surga22 cybersecurity team monitors our systems around the clock. Any unusual activity is detected and acted upon immediately before it can affect your data.

Malaysia PDPA Compliance

Our privacy policy is designed in full compliance with Malaysia's Personal Data Protection Act 2010 (PDPA), ensuring your rights as a Malaysian user are fully respected.

No Personal Data Selling

Surga22 has never and will never sell member personal data to advertisers or data brokers. Your data is used solely to enhance your experience on our platform.

Full Control in Your Hands

Through your surga22 account settings, you can manage your privacy preferences, marketing communications, and data rights at any time — no need to contact support.

Security Standards We Comply With

Surga22 invests in internationally recognised security technology and standards

🔐
SSL 256-bit

Communication channel encryption on par with international banking standards.

💳
PCI-DSS

All payment processing complies with the Payment Card Industry Data Security Standard.

🛡️
AES-256

Data at rest encrypted using the 256-bit Advanced Encryption Standard (AES-256).

📋
Malaysia PDPA

Full compliance with the Personal Data Protection Act 2010 to safeguard the rights of Malaysia users.

🔒✅🎯

Play with Peace of Mind — Your Privacy is Protected at Surga22

Now you know how we protect your data. Register a surga22 account today and enjoy a safe, fair, and transparent gaming experience alongside thousands of members across Malaysia.

By registering, you agree to the Terms and Conditions and Privacy Policy ours.

Bahasa Melayu