1. Introduction
Welcome to the 1irm Privacy Policy. The 1irm platform, accessible via 1irm.app, fully committed to protecting the privacy and security of every member's personal data when using our services in Malaysia.
This Privacy Policy is intended to provide a clear and transparent understanding of our data handling practices — from how we collect information and the purposes for which it is used, to the measures we take to keep it secure. We recognise that your trust is our most valuable asset, and we take that responsibility very seriously.
This policy was drawn up in compliance with Personal Data Protection Act 2010 (PDPA) Malaysia and relevant international security standards. By registering and using the 1irm platform, you hereby agree to the terms set out in this Privacy Policy.
If you disagree with any part of this policy, you are encouraged to discontinue use of the platform and contact us for further clarification before making any decision.
2. Information We Collect
1irm collects your personal information through several channels during your use of our platform. We only collect data that is genuinely necessary for legitimate, stated purposes.
2.1 Information You Provide Directly
2.2 Automatically Collected Information
When you use the 1irm platform — whether via the website or mobile app — our systems automatically record certain technical information to ensure security and smooth operation:
- IP Address — used for security verification and detection of suspicious access locations
- Device type and version — helps us optimize platform display according to your device
- Session data and activity logs — records pages visited, session duration, and actions taken within your account
- Cookie and tracker information — enables site usage personalization features and analytics
- App usage data — crash reports and performance logs for app improvement
2.3 Information from Third Parties
In certain situations, 1irm may receive information about you from legitimate business partners, including payment service providers (such as DuitNow, TNG eWallet, and GrabPay) and approved identity verification agencies. This information is used solely for transaction processing and KYC compliance purposes.
3. How We Use Your Data
Every piece of data we collect is used for a specific and legitimate purpose. 1irm does not use your data for purposes beyond the scope stated in this policy without obtaining your prior consent.
- Account management and identity verification — processes registration, secure login, and KYC verification to ensure only authorized account owners can gain access
- Financial transaction processing — facilitates deposits, withdrawals, and all monetary transactions on the platform quickly and securely
- Fraud prevention and security — detects unusual activity patterns, monitors unauthorized access attempts, and protects your account from threats
- Legal compliance — fulfills obligations under PDPA, anti-money laundering (AML) requirements, and directives from relevant authorities
- Personalise the user experience — tailors content, promotions, and recommendations based on your usage habits and preferences
- Service communications — sends transaction notifications, account updates, promotional information, and customer support responses
- Platform enhancements — analyzes aggregate usage data to improve platform performance, interface, and new features
4. Information Sharing
1irm will not sell, rent, or transfer your personal data to any third party for their own commercial purposes. This is our absolute commitment to every member.
However, there are certain situations where 1irm needs to share your information with carefully selected parties to ensure the platform operates properly:
4.1 Approved Service Providers
We work with selected third-party service providers to support platform operations. All providers are bound by strict confidentiality agreements and are only permitted to use your data for specified purposes:
- Payment gateway providers — DuitNow, TNG eWallet, GrabPay, Boost, and banks to process financial transactions
- Cloud infrastructure providers — for secure data hosting with world-class security standards
- KYC service providers — licensed identity verification agencies to process member verification documents
- Analytics platforms — data analytics tools used to understand usage patterns anonymously
4.2 Legally Required Disclosures
1irm may be required to disclose your information to relevant authorities when mandated by law, court order, or in official investigations involving illegal activity or threats to public safety. In such circumstances, we will endeavour to notify you in advance where permitted by law.
5. Data Security
The security of your personal data is a responsibility we take very seriously. 1irm continuously invests in the latest security infrastructure to ensure your information is always protected against unauthorised access, loss, misuse, or disclosure.
5.1 Technical Security Measures
- 256-bit SSL/TLS Encryption — all data transmitted between your device and 1irm servers is fully encrypted using the latest industry-standard encryption protocols
- Two-factor authentication (2FA) — an additional security layer requiring identity verification via OTP code each time you log in
- 24/7 security monitoring — an intrusion detection system (IDS) operates around the clock to identify and respond to threats in real time
- Data segregation — financial information and personal data are stored in isolated server environments with strict access controls
- Regular data backups — data is automatically and periodically backed up to secure data centres to ensure service continuity
- Independent security audit — security assessments and penetration testing are conducted periodically by independent security experts
5.2 Your Responsibilities
While 1irm implements comprehensive security measures, the security of your account also depends on your own actions. We recommend that you:
- Use a strong, unique password that is not used for any other account
- Enable two-factor authentication (2FA) on your account
- Do not share your login credentials with anyone, including those claiming to be 1irm staff
- Ensure your device is running the latest operating system and apps with up-to-date security patches
- Use a secure and trusted Wi-Fi network when accessing your 1irm account
6. Cookies & Tracking Technology
The 1irm platform uses cookies and similar tracking technologies to enhance your user experience, ensure smooth platform functionality, and analyse usage patterns for continuous improvement.
6.1 Types of Cookies Used
- Essential Cookies — required for core platform functions such as login verification, session management, and security. These cookies cannot be disabled as they are essential to your account security
- Performance Cookies — collects anonymous information about how you use the platform, helping us identify areas that need improvement
- Functional Cookies — saves your preferences such as language, display settings, and region to deliver a more personalized experience
- Analytics Cookies — helps us understand aggregate traffic patterns and user behavior for platform improvement purposes
6.2 Cookie Management
You may manage or delete cookies through your web browser settings at any time. Please note that disabling certain cookies may affect the functionality and user experience of the 1irm platform, particularly essential cookies related to login security.
7. Your Rights as a Data Subject
Under Malaysia's Personal Data Protection Act 2010 (PDPA), you as a data subject have several important rights regarding your personal information held by 1irm. We are committed to making it easy to exercise these rights through a straightforward and transparent process.
Right of Access
You have the right to request and receive a copy of the personal data we hold about you at any time.
Right to Rectification
If any of your information is inaccurate or outdated, you have the right to request an immediate correction or update.
Right to Erasure
You may request the deletion of your personal data, subject to applicable legal record-keeping obligations.
Right to Object
You have the right to object to the processing of your data for direct marketing or profiling purposes at any time.
Right to Data Portability
You may request your data in a structured, machine-readable format for transfer to another platform.
Right to Restrict Processing
In certain circumstances, you may request that we restrict the processing of your data while an investigation or dispute is being resolved.
8. Data Retention Period
1irm retains your personal data only for as long as necessary to fulfil the purposes stated in this policy or to comply with applicable legal requirements. The following are our data retention guidelines:
- Active account data — retained for as long as your account is active and for a period of 7 years after account closure to meet financial record-keeping and legal requirements
- Financial transaction records — retained for a minimum of 7 years in compliance with the Companies Act requirements and anti-money laundering (AML) regulations
- KYC Documents — retained for 5 years after the business relationship ends as required by Malaysia's KYC regulations
- Customer support communication logs — retained for 3 years for reference purposes and dispute resolution
- Technical log data — retained for 12 months for security purposes and technical troubleshooting
- Marketing data and communication preferences — retained until you withdraw consent or close your account
Once the designated retention period has expired, your data will be securely deleted or anonymised in accordance with established data disposal procedures.
9. Protection of Minors
The 1irm platform is strictly for individuals aged 18 years and above. We do not intentionally collect, process, or store any personal data from individuals under the age of 18.
If we discover or become aware that personal data of a minor has been collected without valid age verification, we will take immediate action to delete that data and close the relevant account. Parents or guardians who suspect their child has registered on this platform are encouraged to contact us immediately.
10. Privacy Policy Amendments
1irm reserves the right to amend or update this Privacy Policy at any time to reflect changes in our data collection practices, new legal requirements, or platform improvements.
When significant changes are made to this policy, we will notify you via:
- In-app notifications on 1irm and pop-up alerts during login
- Email to your registered email address at least 7 days before the amendment takes effect
- Notification banner on the 1irm.app homepage
Continued use of the 1irm platform after the effective date of any amendment will be considered your acceptance of the changes made. Previous versions of the Privacy Policy may be requested via email from our support team for reference.
11. Contact Us
If you have any questions, concerns, or wish to exercise your rights regarding personal data, the 1irm Data Protection team is ready to assist you. We are committed to providing accurate and comprehensive responses within the stipulated timeframe.
For unresolved data protection complaints, you also have the right to submit a complaint to Department of Personal Data Protection (JPDP) Malaysia under the Ministry of Communications and Digital.