Privacy Policy
This Privacy Policy outlines how Scam Kantoi manages information in accordance with the Malaysian Personal Data Protection Act 2010 (PDPA). As a public interest research project, we prioritize ethical data handling and the preservation of individual dignity.
1. Preservation of Individual Dignity
Our mission is to expose predatory business models, not to attack individuals.
- Proactive Redaction: We proactively redact the personal names, private contact details, and faces of low-level employees or individuals mentioned in our evidence.
- Focus on Systems: We focus our reporting on organizational practices and high-level decision-makers. We do not publish private, non-professional information that does not serve a direct public interest.
2. Legal Basis: Journalistic & Public Interest Exemption
Under Section 45 of the PDPA, the processing of personal data for journalistic, literary, or artistic purposes is exempt from certain principles if it is in the public interest.
- Public Interest: We process data to prevent financial loss to students and parents and to document high-pressure sales tactics.
- Freedom of Expression: This project exercises the right to inform the public about matters of significant social and financial concern.
3. Collection & Sources of Data
We only utilize data from the following sources:
- Public Domain: Information voluntarily published by organizations in advertisements, websites, or social media.
- Document Metadata: Data found within the metadata of files (e.g., PDF properties) distributed by organizations to the public.
- Whistleblower Submissions: Evidence (chat logs, emails, receipts) provided by individuals who have interacted with the organizations in question.
4. Tracking & Analytics
To monitor the reach of our consumer awareness campaigns, we use standard, non-invasive analytics:
- Non-Identifiable Data: We track page views, referral sources, and general city-level location. We do not track or store your personal identity.
- Opt-Out: Visitors can use “Do Not Track” settings or browser extensions to opt-out of analytics without any loss of site functionality.
5. Data Security & Retention
- Protection: We implement reasonable security measures to protect dignity of individuals.
- Retention: Data is only kept as long as it is necessary for research, evidence-based reporting, or until it is required by enforcement agencies (PDRM/MCMC).
6. Your Rights (Access & Correction)
Individuals mentioned in our reports have the right to request:
- Further Redaction: If you believe your personal dignity is disproportionately affected.
- Correction: If the data presented is factually inaccurate.
- Inquiries: To make a request, please contact us through our email.
Last updated: 4 January 2026