Sistem Kutipan Yuran (SKY4ALL) — Personal Data Protection Act 2010 (Act 709)
Notice version: 1.0 | Effective: 5 Ogos 2026
This notice explains how your personal data is collected, used, disclosed and protected when you use the SKY4ALL fee collection system. Please read it carefully before providing your personal data.
Personal data of Members and Sub-Members is collected and controlled by the organisation or association you are dealing with, acting as the Data Controller.
MJ Solutions is the provider of the SKY4ALL system and acts as the Data Processor — we process personal data solely on the organisation's instructions, and are subject to the security obligations under Section 9 of Act 709.
For system subscription data (organisation details and contact officers), MJ Solutions acts as the Data Controller.
Sub-Members: full name, identity card / birth certificate number, date of birth, gender, place of birth, race, religion, number of siblings, community and session year, and fee and payment records.
Members: full name, identity card number, mobile number, email address, home address, occupation, workplace address, workplace telephone number, income range, citizenship, religion and race.
System users (organisation staff): name, username, password (stored hashed), email, telephone number and position.
Technical data: IP address, login times and in-system activity, recorded for security and audit purposes.
Religion is sensitive personal data under Section 4 of Act 709 and is processed only with your explicit consent, or where permitted by law.
Providing religion and race information is voluntary unless required by the organisation for administrative purposes. You may leave these fields blank without affecting your registration.
Personal data is obtained directly from you (online registration forms, printed forms keyed in by the organisation, or updates you make yourself in the Member portal), or from the organisation's existing Member records.
Data marked mandatory in the forms is required to enable registration, fee computation and receipt issuance. If mandatory data is not supplied, the organisation may be unable to process your registration or payment.
Other data (e.g. occupation, income range, religion, race) is optional and leaving it blank will not affect registration, unless the organisation states otherwise.
Your personal data may be disclosed to the following classes of parties, only to the extent necessary:
We do not sell your personal data and do not use it for third-party marketing.
Certain supporting services (email hosting and cloud infrastructure) may involve the transfer or storage of data outside Malaysia. Such transfers are made only where protection comparable to Act 709 is in place, through binding contractual terms with the relevant service providers.
We implement reasonable technical and organisational measures, including encrypted connections (HTTPS/TLS), bcrypt password hashing, two-step verification via OTP, login rate limiting, data isolation between organisations, role-based access control, and regular backups.
No system is completely secure, however. You remain responsible for keeping your own password and OTP codes confidential.
Records in this system are not deleted automatically. Sub-Member records are tied to receipts and payment records — once a receipt has been issued, the record forms part of the accounting records that must be kept for at least 7 years under the Income Tax Act 1967 and the Companies Act 2016.
You may request correction of your data or restriction of processing at any time. Deletion requests can only be accommodated to the extent that they do not conflict with applicable accounting and legal record-keeping obligations.
Subject to Act 709, you have the right to:
Requests will be answered within 21 days of receipt. A prescribed fee may apply to data access requests, as permitted by the Act.
Where a Sub-Member is under 18 years of age, consent for the processing of their data is given by a parent or lawful guardian at registration. Parents/guardians may review and request correction of the Sub-Member's data at any time through the organisation or the Member portal.
This system uses session cookies solely to maintain your login session and protect against request forgery. These cookies are not used for advertising or cross-site tracking, and expire when you log out or close your browser.
Requests for access, correction, data portability or complaints concerning Member and Sub-Member personal data should be addressed to your organisation as Data Controller.
The organisation's contact details can be found on any letter, receipt or registration link issued by the organisation.
If you are not satisfied with our response, you may lodge a complaint with the Personal Data Protection Department (JPDP), Ministry of Digital Malaysia — www.pdp.gov.my.
This notice may be amended from time to time. The current version is always published on this page. Material changes will be communicated through the system or by email. The version of the notice you consented to at registration is recorded for reference.