Smootea Academy

Privacy Policy

Updated 28 August 2026

1. Introduction

This notice explains how Smootea Empire Sdn Bhd, 43000 Kajang, Selangor, Malaysia ("we", "us") collects, uses, discloses and protects your personal data, in line with the Personal Data Protection Act 2010 (Act 709) and its amendment (Act A1727, 2024). We are the data controller for this site. Using smooteaacademy.com means you acknowledge this notice.

2. Data we collect

Name, email address, phone number and password (stored hashed and irreversible). Your purchase and payment records, and course usage data such as lesson progress. If you join the affiliate programme, your bank name, account number and account holder name — the account number is encrypted at rest and only the last four digits are ever displayed. Credit and debit card details are NOT stored by us; they are handled directly by the payment gateway (CHIP). We do not collect sensitive data such as health, religion, political opinions or biometric data.

3. Purposes of use

To create and manage your account; to enrol you and give access to the classes you buy; to process payments and issue receipts and invoices; to send verification codes (OTP) and notifications by WhatsApp or email; to provide customer support; to pay affiliate commissions; and to comply with legal obligations including tax record keeping. Marketing material is only sent if you opt in separately — that consent is not bundled with consent to use the service, and can be withdrawn at any time in Settings.

4. Source of data

Your personal data is collected directly from you: when you register an account, when you make a purchase, and when you communicate with us. We do not buy lists of personal data from third parties.

5. Disclosure to third parties

The CHIP Collect payment gateway (chip-in.asia, Malaysia) processes your payments and receives your name, email and transaction amount. Resend handles our email delivery and receives your name and email address. WasenderAPI sends our WhatsApp messages and receives your phone number. Our cloud hosting provider stores the application database. All of them are data processors acting on our behalf only, and are bound by security obligations. We do NOT sell your personal data to anyone.

6. Cross-border transfers

Some of our processors operate servers outside Malaysia. This means data such as your name and email address is transferred abroad solely to deliver the service you asked for — receipts, verification codes and class notifications. We only use providers that offer protection comparable to that required under Act 709.

7. Obligation to supply data

Fields marked as required must be completed for us to provide the service — without your name and email we cannot create an account, issue a receipt or grant class access, and your request may not be able to be processed. Other fields are voluntary and do not affect your access to the service.

8. Security and retention

We take practical steps to protect your data: connections are encrypted with HTTPS, passwords are hashed and never stored in plain text, bank account numbers are encrypted in the database, and access to the admin panel is limited by role and protected by one-time verification codes. Account data is kept while your account is active. Payment and invoice records are kept for seven years as required by Malaysian tax law (LHDN). Verification codes are short-lived and deleted a week after expiry; affiliate click records are deleted after 180 days. After the relevant period, data is deleted or permanently destroyed. If a personal data breach occurs, we will notify the Personal Data Protection Commissioner within 72 hours, and notify you directly within 7 days after that if the breach is likely to cause you significant harm.

9. Your rights

You have the right to: (a) access your personal data; (b) correct it if it is inaccurate; (c) withdraw your consent; (d) prevent processing for direct marketing purposes; and (e) request a copy of your data be transferred to another party where technically feasible. The Settings → Data & privacy screen lets you download all your data as a JSON file and request deletion directly. You can also contact us at admin@smooteaacademy.com; we will respond to access requests within 21 days. Because tax law requires us to keep invoice records for seven years, a deletion request is carried out by anonymising your account: name, email, phone and bank details are permanently removed, while payment records remain without being linkable to you. This cannot be undone, and you will lose access to the classes you bought.

10. Cookies

Essential cookies are required for the site to function — login session, CSRF protection and language preference — and cannot be turned off without breaking the service. Non-essential cookies, including the 30-day affiliate referral cookie, are only stored after you consent through the banner. We do not use advertising or third-party tracking cookies.

11. Data Protection Officer (DPO) and complaints

Our Data Protection Officer is Shahril Nor, who can be reached at admin@smooteaacademy.com, or through admin@smooteaacademy.com, or in writing at 43000 Kajang, Selangor, Malaysia. If you are not satisfied with how we handle your data, please contact us first. You also have the right to complain directly to the Personal Data Protection Department (JPDP), Ministry of Digital Malaysia, at www.pdp.gov.my.

12. Changes to this notice

This notice may be updated from time to time. The current version is always available at smooteaacademy.com/privasi, and the date it was last updated is shown at the top of this page. Meaningful changes will ask for your consent again when you log in.

This document is for general compliance and is not legal advice.

Terms of Service Refund Policy