神墨珠心算 隐私声明
一、先说最重要的:孩子的资料属于学校,不属于我们
「神墨珠心算」App(下称「App」)是孩子所在的学校/校区(下称「学校」)提供给学生使用的珠心算学习工具。
- 学校通过其校务系统(由【校务系统运营方】运营,下称「校务系统」)登记和管理孩子的资料:姓名、学号、生日、班级、家长联系方式、学习级别(Level)、作业、成绩等。在法律上,学校是这些资料的数据控制者——由学校决定收集哪些资料、用于什么目的。
- 我们是 App 的运营方,按学校的指示、为学校处理这些资料,是数据处理者。我们只拿到完成教学功能所需的最少资料,并且尽量不在我们这里保存。
- 因此,如果您想查阅、更正或删除孩子的资料,最直接的方式是联系学校。您也可以联系我们,我们会转给学校并协助处理(见第九节)。
我们自己作为数据控制者处理的,只有:管理端工作人员(总部、校长、老师)的账号资料、系统安全所需的审计日志与服务器日志。本声明对这两部分也作了说明。
二、本声明适用于谁
- 家长/监护人:使用学校发放的账号登录 App,陪孩子学习、查看作业与报告;
- 学生(4–13 岁):在家长或老师登录后使用 App;我们另有一份写给孩子看的简短说明(《给小朋友的隐私说明》);
- 老师、校长、总部人员:使用 App 或网页管理端。
三、我们处理哪些资料
1. 关于孩子(学校的资料,我们代学校处理)
| 资料 | 从哪里来 | 我们怎么处理 |
|---|---|---|
假名编号(studentRef) |
校务系统生成 | 一串没有含义的编号,不是学号、身份证号或邮箱。我们只用它来区分不同孩子。 |
| 班级编号、所在校区、学习级别(Level)、课程解锁进度、经验值(XP)、作业完成情况 | 校务系统 | 用于在 App 中显示正确的课程和进度。按对接方式二选一:(a)校务系统推送给我们,作为临时缓存保存,30 天没有更新即自动清除,学校可随时要求立即清除;或(b)每次需要时向校务系统实时读取,只在服务器内存中保留约 60 秒,不写入数据库。 |
| 孩子的显示名(如名字或昵称) | 校务系统 | 用于在 App 和管理端中显示。默认不保存,只在请求时临时传递。【若学校选择允许缓存显示名,请改写此行:与上一行相同的缓存规则。】 |
| 练习记录(训练模式、答对题数、总题数、用时、获得的 XP、时间) | App 中产生 | 经由我们的「待发送队列」(outbox)转交给校务系统;送达后立即删除,如因故无法送达,最长 7 天后删除。 |
| 测验答卷(试卷编号、作答内容、用时) | App 中产生 | 同上:转交校务系统,送达即删,最长 7 天。 |
| 关卡结果(关卡、答对题数、题数、正确率、是否达标、用时) | App 中产生,由我们的服务器判分 | 同上:转交校务系统(关卡完成情况以学校为准),送达即删,最长 7 天;另按假名编号保留每个关卡的最好成绩,30 天没有新结果即删除。 |
| 游戏化记录:宝石余额与增减流水、生命、已获得的徽章与进度、已解锁的游戏、已拥有的服装(含见面礼选择)、换装选择、打卡日期(只到“天”)与连续天数、游戏成绩与每周最好成绩、每周 XP 联赛记录(所在周、段位、所在小组、本周 XP、结算后的名次与升级 / 保级 / 降级结果)、排行榜名次与奖励、App 内通知、「参加排行榜」开关、限时活动进度(活动期间的练习次数 / 打开 App 的天数,只记日期)与已领取的活动奖励 | App 中产生,由我们的服务器计算 | 由我们保存在服务器上,只按假名编号(studentRef)保存,不含姓名,用于计算奖励并在 App 中显示。学校删除该学生(或其不再出现在校务系统中)时一并删除;每一局游戏的明细保存 60 天;每周联赛记录保存 60 天(每个孩子保留最近一条,用于确定当前段位);活动的逐人进度在活动结束 30 天后删除(只保留参与人数等汇总数),打开 App 的日期最多保存 100 天。这些记录不送回校务系统。另外 App 会在本设备上缓存换装外观,方便下次打开时显示(见第七节)。 |
2. 关于家长/监护人(学校的资料,我们代学校处理)
| 资料 | 我们怎么处理 |
|---|---|
| 登录邮箱和密码 | 您在 App 中输入的邮箱和密码由校务系统验证。【对接方式 A:我们的服务器把它原样转交给校务系统,不保存、不写入日志。】【对接方式 B:您直接在校务系统的登录页登录,我们完全看不到密码。】 |
家长假名编号(guardianRef)及您可查看的孩子编号 |
写入一个登录凭证(连续 14 天未使用即失效,使用期间自动续期),用来确认您只能看到自己孩子的资料。我们不另行保存家长档案。 |
| 家长联系方式 | 我们不保存。如学校允许,老师/校长在管理端查看时,系统会实时从校务系统读取,只在当次显示中使用。 |
3. 关于老师、校长、总部人员(我们自己的资料)
姓名、工作邮箱、角色、所属校区和班级、加密存储的密码(不可还原)、账号状态、登录时间;以及审计日志——记录哪位人员在何时、出于何种用途、查看了哪个学生编号的哪一类资料(不记录资料内容本身)。
4. 技术资料
为保障服务安全运行,我们的服务器会产生访问日志(如 IP 地址、请求时间、请求路径、错误代码)。日志会自动去除密码、登录凭证、邮箱、姓名等内容,保存 30 天后删除。【如启用崩溃上报:崩溃报告会去除身份信息,只包含设备型号、系统版本、App 版本和错误信息。】
四、我们不做的事
- ❌ 不展示任何广告;
- ❌ 不使用第三方追踪、统计或广告 SDK,不做跨 App 追踪,不建立兴趣画像;
- ❌ 没有任何真钱购买:App 里的「宝石」只能靠学习获得(完成练习、获得徽章、小游戏每周排行榜前 3 名),不能用钱买,没有任何金钱价值,不能换成现金或实物、不能转让;只能在 App 内用来解锁小游戏、补充游戏生命、给小伙伴换衣服。经验值(XP)只是学习记录(只累计、不消费);
- ❌ 排行榜(每个小游戏一个每周排行榜,另有每周 XP 联赛)不显示真实姓名:榜上只显示昵称和吉祥物形象(以及成绩或本周 XP),使用本 App 的其他孩子可能会看到。每周 XP 联赛:孩子在一周内第一次练习得到 XP 时加入,与同段位的其他孩子(可能来自其他校区、其他级别)分在一组,按本周 XP 排名,每周一(马来西亚时间)结算升级或降级,不发宝石。昵称可以由孩子自己取(最多 12 个字,例如「超级小火箭 #23」),没取过时由系统生成;App 会提醒孩子不要使用真名、电话或地址,并自动拦截网址、电话号码和不当用语,学校发现不合适的昵称可以重置;家长可随时在 App「家长区」关闭「参加排行榜」,关闭后孩子不上任何排行榜、不参加联赛、不得排名奖励;
- ❌ 没有聊天、留言、上传照片等用户之间的交流功能;
- ❌ 不获取位置信息;
- ❌ 不使用摄像头,不录音。听算、闪电算等训练中的语音是在设备上合成播放的,App 只「说」,不「听」;
- ❌ 不把资料出售或出租给任何人;
- ❌ 不把孩子的资料用于学校教学以外的目的(例如我们自己的营销)。
五、为什么处理这些资料(用途)
- 让孩子能登录并使用适合自己级别的课程、练习、测验,以及徽章、宝石、生命、小游戏、每周排行榜与每周 XP 联赛、打卡、换装和限时活动等学习激励功能;
- 让家长查看孩子的作业和学习报告;
- 把练习和测验结果交回学校,以便老师布置作业、评估学习、生成报告(这些结果由学校在校务系统中保存);
- 让老师、校长、总部在学校授权的范围内查看学习情况(可见字段由「数据可见范围」设置控制);
- 维护系统安全、排查故障、防止滥用、满足法律要求。
我们只在学校的书面指示范围内为上述第 1–4 项处理孩子与家长的资料。
六、我们会把资料交给谁
| 接收方 | 什么资料 | 原因 |
|---|---|---|
| 学校 / 校务系统(【校务系统运营方】) | 练习记录、测验答卷、登录验证请求 | 学校是资料的控制者,资料本来就属于学校 |
| 为我们提供服务的子处理者(云托管、内容分发、邮件发送【、崩溃上报】) | 仅为提供该服务所必需的资料 | 名单见《子处理者清单》,并受合同保密与安全义务约束 |
| 执法或监管机关 | 依法要求的资料 | 仅在法律要求时,并会先通知学校(法律禁止者除外) |
我们不会把资料提供给广告商、数据经纪商或其他商业第三方。
七、本设备上保存了什么
- 换装外观缓存:按孩子的假名编号保存所选伙伴、装扮、已拥有道具和 XP 数,不含姓名。退出登录时会清除。(宝石、徽章、排行榜等以服务器为准,见第三节。)
- 登录凭证:保存在手机的系统安全存储中(iOS 钥匙串 / Android Keystore),退出登录即删除;连续 14 天未使用自动失效。
- 训练设置(如题数、速度):可能保存在本设备上,不含个人资料。
- 我们不使用广告标识符(IDFA / Android 广告 ID)。
网页管理端只使用维持登录所必需的存储(见 App 内《Cookie 与本地存储说明》),不使用统计或广告 Cookie。
八、资料存放在哪里,保存多久
- 我们的服务器位于【托管区域】,由【托管服务商】提供。如资料存放或传输到马来西亚以外,我们只会在法律允许的情况下进行(例如目的地有与马来西亚实质相似的个人数据保护法律,或资料能得到同等程度的保护),并与服务商签订保护条款。
- 主要保留期限:
| 资料 | 保存多久 |
|---|---|
| 校务系统推送来的学习状态缓存 | 30 天无更新自动清除;学校要求删除时立即清除 |
| 实时读取的学生资料 | 仅内存中约 60 秒 |
| 待送回学校的练习/测验记录 | 送达即删;最长 7 天 |
| 游戏化记录(宝石、生命、徽章、服装、打卡、排行榜与每周 XP 联赛记录、通知、活动进度与领取;按假名编号,不含姓名) | 孩子在学校登记期间保存;学校删除该学生(或其不再出现在校务系统中)时一并删除(24 小时内);每一局游戏的明细 60 天;每周联赛记录 60 天(每个孩子保留最近一条,用于确定当前段位);活动逐人进度在活动结束后 30 天、打开 App 的日期 100 天 |
| App 登录凭证 | 连续 14 天未使用即失效 |
| 本设备换装缓存 | 退出登录时清除 |
| 人员账号 | 账号停用后 90 天删除 |
| 审计日志 | 2 年 |
| 服务器日志 | 30 天(已去除敏感内容) |
| 备份 | 滚动【35】天,期满自动覆盖 |
学校在校务系统中保存资料的期限,由学校决定,请向学校查询。
九、您的权利
依据马来西亚个人数据保护法,您(作为家长/监护人代孩子行使,或作为人员本人)有权:
- 查阅资料,并获得副本;
- 更正不准确、不完整或过时的资料;
- 撤回同意,或要求停止/限制处理(注意:撤回后孩子可能无法继续使用 App);
- 要求删除资料(在法律允许的范围内);
- 要求把资料以结构化格式转移给另一个机构(数据可携权,以技术可行为限);
- 就资料处理投诉,包括向马来西亚个人数据保护专员(Personal Data Protection Commissioner)投诉。
怎么行使:
- 孩子和家长的资料 → 请先联系学校(学校掌握完整资料并负责决定)。您也可以写信到【DPO 联系邮箱】,我们会在 2 个工作日内转交学校,并协助学校在法律规定期限内回复您。
- 人员账号资料 → 直接联系【DPO 联系邮箱】。
- 为保护孩子,我们或学校会先核实您的身份及您与孩子的关系。
十、资料是必须提供的吗
- 孩子使用 App 必须由学校在校务系统中为其登记,并提供假名编号、班级与级别;家长登录必须提供学校登记的邮箱和密码。不提供将无法使用 App。
- 宝石、徽章、生命、小游戏、排行榜、换装等是学习激励功能,不需要额外提供个人资料;家长可在「家长区」关闭「参加排行榜」。
十一、安全
我们采取的措施包括:全程加密传输(TLS);数据库与备份加密存储;与校务系统之间的每次通信都经过签名验证并防重放;按角色和校区/班级严格限制工作人员可见范围;所有查看学生资料的操作留有审计日志;日志自动脱敏;员工保密协议与培训。详见我们向学校提供的《技术与组织安全措施》。
如发生可能影响您资料的安全事件,我们会立即通知学校,并协助学校依法通知个人数据保护专员和受影响的家庭。
十二、关于儿童
App 面向 4–13 岁儿童。孩子必须由学校登记、在家长或老师登录后才能使用。依马来西亚法律,未满 18 岁者的个人资料处理须取得父母、监护人或对其负有父母责任者的同意;该同意由学校在报名/注册时取得。首次登录时,App 会向家长或老师展示隐私摘要。我们给孩子准备了一份简短易懂的说明。
十三、本声明的更新
我们有权不时更新本声明。如有更新,我们会在 App 和官网发布新版本并更新生效日期。若属重大变更(例如新增资料类别、新增用途、新增第三方),我们会在下次登录时提示家长,并在需要时由学校重新取得同意。
十四、联系我们
- 数据保护官:【DPO 姓名】,【DPO 联系邮箱】
- 客服:【客服邮箱】
- 邮寄地址:【公司名称】,【地址】
- 您也可以向马来西亚个人数据保护部门(Jabatan Perlindungan Data Peribadi)提出投诉。
Shenmo Abacus — Privacy Notice
1. The most important point: your child's data belongs to the school, not to us
The Shenmo Abacus app (the "App") is an abacus and mental-arithmetic learning tool provided to students by their school or learning centre (the "School").
- The School registers and manages your child's information — name, student number, date of birth, class, parent contact details, level, homework, results — in its school management system (operated by 【校务系统运营方】, the "SIS"). In law, the School is the data controller of that information: it decides what is collected and why.
- We operate the App and process that information on the School's behalf and on its instructions. We are a data processor. We receive only the minimum information needed for the learning features, and we avoid storing it wherever possible.
- So if you want to access, correct or delete your child's information, the most direct route is to contact the School. You may also contact us and we will pass your request on and help the School respond (see section 9).
We act as a data controller in our own right only for: the accounts of admin staff (HQ, principals, teachers), and the audit logs and server logs we need to keep the service secure. These are also covered below.
2. Who this notice is for
- Parents and guardians who sign in to the App with the account issued by the School, to support their child's learning and see homework and reports;
- Students (aged 4–13), who use the App after a parent or teacher has signed in. There is a separate short notice written for children;
- Teachers, principals and HQ staff who use the App or the web admin console.
3. What information we process
3.1 About your child (School data, processed on the School's behalf)
| Information | Source | How we handle it |
|---|---|---|
Pseudonymous ID (studentRef) |
Generated by the SIS | A meaningless code — never a student number, NRIC/MyKid number or email. We use it only to tell children apart. |
| Class code, campus, level, unlocked lessons, experience points (XP), homework completion | SIS | Used to show the right lessons and progress. Depending on the integration mode chosen by the School: (a) the SIS sends it to us and we keep it as a temporary cache that is automatically deleted after 30 days without an update, and immediately on the School's request; or (b) we read it live from the SIS each time and keep it only in server memory for about 60 seconds, never in our database. |
| Child's display name | SIS | Shown in the App and admin console. Not stored by default — passed through only when needed. 【If the School opts in to caching display names, replace with: same cache rules as the row above.】 |
| Practice results (training mode, correct answers, total questions, time taken, XP earned, time of practice) | Created in the App | Passed back to the SIS through our delivery queue ("outbox"); deleted as soon as it is delivered, and in any event no later than 7 days. |
| Test answers (test ID, answers, time taken) | Created in the App | As above: delivered to the SIS, deleted on delivery, 7 days maximum. |
| Level (node) results (which learning node, questions answered correctly, number of questions, accuracy, whether the node was passed, time taken) | Created in the App, marked by our server | As above: delivered to the SIS (the School's records decide which nodes are completed), deleted on delivery, 7 days maximum; we also keep each node's best result under the pseudonymous ID and delete it after 30 days without a new result. |
| Game records: gem balance and gem transactions, lives, badges earned and badge progress, unlocked mini-games, outfit items owned (including the welcome-gift choice), outfit choices, check-in dates (day only) and streak, game scores and weekly best scores, weekly XP league records (week, tier, group, XP earned that week, and after the weekly settlement the rank and whether the child moved up, stayed or moved down), leaderboard ranks and rewards, in-app notices, the "join the leaderboard" setting, limited-time event progress (practices during the event / days the App was opened — date only) and event rewards claimed | Created in the App and calculated by our server | Kept by us on our servers, only under the pseudonymous ID (studentRef) — no name — to calculate rewards and show them in the App. Deleted together with the student when the School deletes the student (or the student no longer appears in the SIS); individual game rounds are kept for 60 days; weekly league records are kept for 60 days (the latest record for each child is kept to know their current tier); per-child event progress is deleted 30 days after the event ends (only totals such as the number of participants are kept) and App-open dates are kept for at most 100 days. These records are not sent back to the SIS. The App also caches the outfit on the device so it shows next time (see section 7). |
3.2 About parents and guardians (School data, processed on the School's behalf)
| Information | How we handle it |
|---|---|
| Sign-in email and password | Verified by the SIS. 【Mode A: our server forwards them to the SIS unchanged and does not store or log them.】【Mode B: you sign in on the SIS's own sign-in page and we never see your password.】 |
Guardian pseudonymous ID (guardianRef) and your children's IDs |
Placed in a sign-in token (expires after 14 days without use; renewed automatically while you use the App), used to make sure you only see your own children. We do not keep a separate parent profile. |
| Parent contact details | Not stored by us. Where the School allows it, staff viewing them in the admin console see them read live from the SIS for that view only. |
3.3 About teachers, principals and HQ staff (our own data)
Name, work email, role, campus and classes, password (stored only as a one-way hash), account status, sign-in times; and an audit log recording which staff member viewed which category of data about which student ID, when, and for what purpose (the data itself is not recorded).
3.4 Technical data
Our servers create access logs (e.g. IP address, time, request path, error codes) to keep the service running securely. Passwords, tokens, emails and names are automatically removed from logs, and logs are deleted after 30 days. 【If crash reporting is enabled: crash reports are de-identified and contain only device model, OS version, app version and error details.】
4. What we do not do
- No advertising of any kind;
- No third-party tracking, analytics or advertising SDKs; no cross-app tracking; no interest profiling;
- No real-money purchases: in-app "gems" can only be earned by learning (completing practice, earning badges, finishing in the top 3 of a weekly mini-game leaderboard). Gems cannot be bought with money, have no monetary value, cannot be exchanged for cash or goods and cannot be transferred; they can only be used in the App to unlock mini-games, refill game lives and dress up the companion. Experience points (XP) are only a learning record (they add up and are never spent);
- Leaderboards (a weekly leaderboard for each mini-game, plus the weekly XP league) never show real names: they show only a nickname and the mascot image (with the score or the week's XP), and other children using the App may see them. Weekly XP league: a child joins when they first earn XP from practice in a week, is placed in a group with other children of the same tier (who may be from other campuses and other levels), is ranked by XP earned that week, and moves up or down a tier at the weekly settlement on Monday (Malaysia time); the league gives no gems. Children may type their own nickname (max 12 characters, e.g. "Super Rocket #23"); otherwise one is generated. The App warns children not to use their real name, phone number or address, blocks links, phone numbers and offensive words, and school staff can reset an unsuitable nickname. Parents can switch off "join the leaderboard" in the App's parent area at any time — the child is then not listed on any leaderboard, does not join the league and receives no ranking rewards;
- No chat, comments, photo uploads or any other user-to-user communication;
- No location data;
- No camera use and no audio recording. Voices in listening and flash training are synthesised on the device — the App speaks, it does not listen;
- We never sell or rent personal data;
- We never use children's data for anything other than the School's educational purposes (for example, not for our own marketing).
5. Why we process it (purposes)
- To let your child sign in and use lessons, practice and tests suited to their level, and the learning-motivation features (badges, gems, lives, mini-games, weekly leaderboards and the weekly XP league, check-in streaks, outfits and limited-time events);
- To let parents see homework and learning reports;
- To return practice and test results to the School, so teachers can assign homework, assess learning and produce reports (the School keeps those results in the SIS);
- To let teachers, principals and HQ see learning information within the scope the School has authorised (controlled by the "data visibility" settings);
- To keep the service secure, fix problems, prevent misuse and comply with the law.
We process children's and parents' data for purposes 1–4 only within the School's written instructions.
6. Who we share information with
| Recipient | What | Why |
|---|---|---|
| The School / SIS (【校务系统运营方】) | Practice results, test answers, sign-in verification requests | The School is the controller; the data is the School's |
| Our sub-processors (cloud hosting, content delivery, email delivery【, crash reporting】) | Only what each needs to provide its service | Listed in our Sub-processor List; bound by contractual confidentiality and security obligations |
| Law-enforcement or regulators | What the law requires | Only where legally required, and we will tell the School first unless the law forbids it |
We never give data to advertisers, data brokers or other commercial third parties.
7. What is stored on the device
- Outfit cache: under the child's pseudonymous ID — chosen companion, outfit, items owned and XP total. No name. Cleared when you sign out. (Gems, badges and leaderboards are kept on our server — see section 3.)
- Sign-in token: kept in your phone's secure system storage (iOS Keychain / Android Keystore); deleted when you log out, and expires after 14 days without use.
- Training settings (e.g. number of questions, speed): may be stored on the device; contain no personal data.
- We do not use advertising identifiers (IDFA / Android Advertising ID).
The web admin console uses only storage strictly necessary to keep staff signed in (see the in-app "Cookies and local storage" statement); no analytics or advertising cookies.
8. Where information is stored and for how long
- Our servers are located in 【托管区域】 and provided by 【托管服务商】. If personal data is stored in or transferred outside Malaysia, we do so only where the law allows (for example where the destination has a law substantially similar to Malaysia's, or the data will be adequately protected) and under contractual safeguards with the provider.
- Main retention periods:
| Data | Kept for |
|---|---|
| Learning-status cache pushed by the SIS | Deleted after 30 days without update; immediately on the School's request |
| Student data read live | ~60 seconds in memory only |
| Practice / test records awaiting delivery | Deleted on delivery; 7 days maximum |
| Game records (gems, lives, badges, outfits, check-ins, leaderboards and weekly XP league records, notices, event progress and claims; pseudonymous ID only, no name) | While the child is registered with the School; deleted together with the student (within 24 hours) when the School deletes the student or the student no longer appears in the SIS; individual game rounds 60 days; weekly league records 60 days (the latest record for each child is kept to know their current tier); per-child event progress 30 days after the event ends; App-open dates 100 days |
| App sign-in token | Expires after 14 days without use |
| Outfit cache on device | Cleared on sign-out |
| Staff accounts | Deleted 90 days after deactivation |
| Audit log | 2 years |
| Server logs | 30 days (sensitive content removed) |
| Backups | Rolling 【35】 days, then overwritten |
How long the School keeps data in the SIS is decided by the School — please ask the School.
9. Your rights
Under Malaysian personal data protection law, you (as parent/guardian on behalf of your child, or as a staff member for yourself) may:
- access the data and obtain a copy;
- correct data that is inaccurate, incomplete or out of date;
- withdraw consent, or ask that processing stop or be limited (your child may then be unable to use the App);
- ask for data to be deleted (to the extent the law allows);
- ask for data to be transmitted in a structured format to another organisation (data portability, where technically feasible);
- complain about how your data is handled, including to Malaysia's Personal Data Protection Commissioner.
How to exercise them:
- Child and parent data → please contact the School first (it holds the complete record and decides). You may also write to 【DPO 联系邮箱】; we will forward your request to the School within 2 business days and help it reply within the legal time limit.
- Staff account data → contact 【DPO 联系邮箱】 directly.
- To protect children, we or the School will verify your identity and your relationship with the child.
10. Is providing information compulsory?
- To use the App, a child must be registered by the School in the SIS with a pseudonymous ID, class and level, and a parent must sign in with the email and password registered with the School. Without these the App cannot be used.
- Gems, badges, lives, mini-games, leaderboards and outfits are learning-motivation features and need no additional personal data; parents can switch off "join the leaderboard" in the parent area.
11. Security
Our measures include encryption in transit (TLS); encryption of databases and backups at rest; signed, replay-protected communications with the SIS; strict role- and campus/class-based limits on what staff can see; an audit log of every staff view of student data; automatic log redaction; and staff confidentiality agreements and training. Details are in the Technical and Organisational Measures we provide to Schools.
If a security incident may affect your data, we will notify the School immediately and help it notify the Personal Data Protection Commissioner and affected families as required by law.
12. Children
The App is designed for children aged 4–13. A child can use it only after being registered by the School and after a parent or teacher signs in. Under Malaysian law, processing personal data of a person under 18 requires the consent of a parent, guardian or person with parental responsibility; this consent is obtained by the School at enrolment. On first sign-in the App shows a privacy summary to the parent or teacher. We also provide a short, child-friendly notice.
13. Changes to this notice
We may update this notice from time to time. We will publish updates in the App and on our website and update the effective date. For material changes (e.g. new data categories, new purposes, new third parties) we will tell parents at their next sign-in and, where needed, the School will obtain fresh consent.
14. Contact us
- Data Protection Officer: 【DPO 姓名】, 【DPO 联系邮箱】
- Support: 【客服邮箱】
- Post: 【公司名称】, 【地址】
- You may also complain to Malaysia's Personal Data Protection Department (Jabatan Perlindungan Data Peribadi).