Berkuat kuasa / Effective: 1 Jun 2025 | Kemaskini terakhir / Last updated: 3 Jun 2025
Allite (allite.space) menghormati privasi anda. Dasar ini menerangkan bagaimana kami mengumpul, menggunakan, menyimpan dan melindungi data peribadi anda selaras dengan Akta Perlindungan Data Peribadi 2010 (Akta 709) Malaysia.
1. Data Yang Kami Kumpul
| Jenis Data | Sumber | Tujuan |
| Nama, alamat emel | Google Sign-In | Pengesahan akaun, paparan profil |
| No. telefon | Borang pendaftaran | Komunikasi, pengesahan bayaran |
| Negeri | Borang pendaftaran | Statistik, kandungan sesuai |
| Nama sekolah (pilihan) | Borang pendaftaran | Statistik pendidikan |
| Rekod kuiz (markah, jawapan) | Penggunaan platform | Progress tracking, error book |
| Maklumat peranti | Automatik | Sokongan teknikal, keselamatan |
Kami tidak mengumpul nombor kad pengenalan (IC), nombor akaun bank, atau data kewangan sensitif.
2. Tujuan Pemprosesan
Data peribadi anda diproses untuk tujuan berikut sahaja:
- Menyediakan perkhidmatan kuiz dan latihan SPM
- Pengesahan identiti dan kawalan akses (percuma / premium)
- Memaparkan progress dan keputusan kuiz anda
- Berkomunikasi mengenai akaun, bayaran, atau kemaskini perkhidmatan
- Penambahbaikan platform berdasarkan statistik penggunaan
3. Storan Data
- Firebase / Google Cloud — data disimpan dalam pelayan Google yang mematuhi piawaian keselamatan antarabangsa (SOC 2, ISO 27001)
- LocalStorage / SessionStorage — cache sementara dalam pelayar anda untuk pengalaman lebih pantas (contoh: progress kuiz, tema paparan)
Data anda mungkin disimpan di pelayan di luar Malaysia. Google Cloud mematuhi piawaian perlindungan data antarabangsa.
4. Perkongsian Data
Kami tidak menjual, menyewa, atau berkongsi data peribadi anda dengan pihak ketiga kecuali:
- Penyedia perkhidmatan — Firebase (Google) untuk pengehosan dan pengesahan
- Keperluan undang-undang — jika dikehendaki oleh mahkamah atau pihak berkuasa Malaysia
5. Kuki & Penyimpanan Tempatan
Allite menggunakan:
- Kuki sesi Firebase — untuk pengesahan log masuk
- LocalStorage — menyimpan tema, tahun subjek pilihan, cache versi app
- SessionStorage — cache sementara akses pengguna
Kami tidak menggunakan kuki penjejak pihak ketiga (tiada Google Analytics, tiada Facebook Pixel).
6. Hak Anda (Seksyen 30, Akta 709)
Sebagai pengguna, anda berhak:
- Akses — meminta salinan data peribadi anda yang kami simpan
- Pembetulan — meminta pembetulan data yang tidak tepat
- Penarikan persetujuan — menarik balik kebenaran pemprosesan data pada bila-bila masa
- Penghapusan — meminta penghapusan akaun dan semua data berkaitan
Untuk melaksanakan hak anda, hubungi kami melalui maklumat di Seksyen 9.
7. Keselamatan Data
- Pengesahan melalui Google OAuth 2.0 (tiada kata laluan disimpan oleh Allite)
- Sambungan HTTPS disulitkan
- Peraturan keselamatan Firestore menghadkan akses data kepada pemilik sahaja
8. Tempoh Penyimpanan
- Akaun aktif — data disimpan selagi akaun anda aktif
- Akaun tidak aktif — data mungkin dihapuskan selepas 24 bulan tidak aktif
- Penghapusan akaun — semua data peribadi dihapuskan dalam 30 hari bekerja selepas permintaan
9. Hubungi Kami
Jika anda mempunyai sebarang soalan atau ingin melaksanakan hak anda berkaitan data peribadi:
10. Perubahan Dasar
Kami berhak mengemaskini dasar ini dari semasa ke semasa. Perubahan ketara akan dimaklumkan melalui platform. Tarikh kemaskini terakhir tertera di bahagian atas halaman ini.
Allite (allite.space) respects your privacy. This policy explains how we collect, use, store, and protect your personal data in accordance with Malaysia's Personal Data Protection Act 2010 (Act 709).
1. Data We Collect
| Data Type | Source | Purpose |
| Name, email address | Google Sign-In | Account authentication, profile display |
| Phone number | Registration form | Communication, payment verification |
| State (Negeri) | Registration form | Statistics, relevant content |
| School name (optional) | Registration form | Education statistics |
| Quiz records (scores, answers) | Platform usage | Progress tracking, error book |
| Device information | Automatic | Technical support, security |
We do not collect identity card (IC) numbers, bank account numbers, or sensitive financial data.
2. Purpose of Processing
Your personal data is processed solely for the following purposes:
- Providing SPM quiz and practice services
- Identity verification and access control (free / premium)
- Displaying your quiz progress and results
- Communicating about your account, payments, or service updates
- Improving the platform based on usage statistics
3. Data Storage
- Firebase / Google Cloud — data is stored on Google servers compliant with international security standards (SOC 2, ISO 27001)
- LocalStorage / SessionStorage — temporary browser cache for a faster experience (e.g., quiz progress, display theme)
Your data may be stored on servers outside Malaysia. Google Cloud complies with international data protection standards.
4. Data Sharing
We do not sell, rent, or share your personal data with third parties except:
- Service providers — Firebase (Google) for hosting and authentication
- Legal requirements — if required by Malaysian courts or authorities
5. Cookies & Local Storage
Allite uses:
- Firebase session cookies — for login authentication
- LocalStorage — storing theme, preferred subject year, app version cache
- SessionStorage — temporary user access cache
We do not use third-party tracking cookies (no Google Analytics, no Facebook Pixel).
6. Your Rights (Section 30, Act 709)
As a user, you have the right to:
- Access — request a copy of your personal data we hold
- Correction — request correction of inaccurate data
- Withdrawal of consent — withdraw data processing consent at any time
- Deletion — request deletion of your account and all associated data
To exercise your rights, contact us via the information in Section 9.
7. Data Security
- Authentication via Google OAuth 2.0 (no passwords stored by Allite)
- Encrypted HTTPS connections
- Firestore security rules restrict data access to owners only
8. Data Retention
- Active accounts — data is retained as long as your account is active
- Inactive accounts — data may be deleted after 24 months of inactivity
- Account deletion — all personal data is deleted within 30 business days of request
9. Contact Us
If you have any questions or wish to exercise your data rights:
10. Policy Changes
We reserve the right to update this policy from time to time. Significant changes will be notified through the platform. The last update date is shown at the top of this page.