Apa yang sistem ini tahu tentang anda dan anak anda, berapa lama ia disimpan, siapa boleh melihatnya, dan apa hak anda.
Dasar Privasi ini disediakan dalam Bahasa Melayu dan Bahasa Inggeris. Sekiranya terdapat sebarang percanggahan maksud antara dua versi ini, versi Bahasa Melayu akan terpakai dan diutamakan.
Bahagian ini meringkaskan keseluruhan dasar. Bahagian 2 hingga 12 memberikan butiran penuh, dan bahagian-bahagian itulah yang mengikat.
jemput.app ialah sistem automasi jemputan murid yang dikendalikan oleh MFZ DIGITAL, No. Pendaftaran SSM 202603210023 (003878100-V), selepas ini dirujuk sebagai "kami".
Sekolah anak anda menggunakan sistem ini untuk menguruskan waktu jemputan. Pembahagian tanggungjawab antara sekolah dan kami adalah penting, kerana ia menentukan kepada siapa anda perlu merujuk apabila ada permintaan atau aduan.
Peranan ini menentukan siapa yang mengarahkan pemprosesan. Ia tidak bermakna kami tiada tanggungjawab sendiri: pindaan PDPA 2024 meletakkan kewajipan keselamatan dan pemberitahuan pelanggaran data secara terus ke atas pemproses data. Bahagian 8 menerangkan apa yang kami lakukan di bawah kewajipan itu.
Kami menggunakan Pengawal Data kerana itulah istilah yang digunakan oleh Akta 709 hari ini. Pindaan PDPA 2024 menggantikan istilah lama Pengguna Data dengan Pengawal Data di seluruh Akta. Kedua-duanya merujuk perkara yang sama — pihak yang menentukan tujuan dan cara maklumat peribadi diproses, iaitu sekolah dalam susunan ini.
Permintaan berkaitan maklumat peribadi anda — melihat, membetulkan, atau memadam — hendaklah dikemukakan kepada pihak sekolah, bukan kepada kami secara terus. Sekolah kemudian mengarahkan kami untuk bertindak. Cara ini bukan untuk menyukarkan anda; ia mencerminkan hakikat bahawa sekolahlah yang memegang hubungan dengan anda dan yang berhak mengesahkan identiti anda.
Jika sekolah tidak memberi respons, anda tetap boleh menghubungi kami terus — butiran dalam Bahagian 12. Apa yang kami lakukan dengan permintaan itu dinyatakan di sini supaya anda tahu apa yang dijangka: kami tidak mengubah, membetulkan, atau memadam data secara sebelah pihak atas permintaan terus, kerana kami memproses maklumat itu bagi pihak sekolah dan sekolah yang berhak mengesahkan identiti anda. Sebaliknya kami memajukan permintaan anda kepada pentadbir sekolah dalam masa 3 hari bekerja — komitmen operasi kami, bukan tempoh berkanun — dan memberitahu anda bahawa ia telah dimajukan.
Selepas sekolah mengesahkan permintaan itu, tempoh tindak balas 21 hari dalam Bahagian 9 terpakai. Jika sekolah tetap tidak bertindak, anda boleh mengemukakan aduan terus kepada Jabatan Perlindungan Data Peribadi — lihat Bahagian 12.
Hampir semua maklumat dalam sistem ini adalah mengenai kanak-kanak bawah umur — nama yang dilaungkan, kelas yang dipaparkan, dan rekod bila mereka dijemput. Oleh itu ibu bapa atau penjaga yang sah bertindak bagi pihak mereka dalam perkara berkaitan maklumat peribadi anak.
Perintah mahkamah, penjagaan berkongsi, atau pertikaian mengenai siapa yang berhak menjemput seorang murid adalah perkara yang mesti diuruskan oleh pihak sekolah, bukan melalui tetapan dalam sistem ini. Maklumkan kepada sekolah dan mereka akan melaraskan akses akaun yang berkenaan.
Setiap sekolah beroperasi pada pangkalan data, folder audio, dan proses aplikasi yang berasingan sepenuhnya. Tiada jadual data dikongsi antara sekolah. Kesan praktikalnya: sistem direka dengan pengasingan data antara sekolah bagi menghalang akses silang antara sekolah melalui sistem ini.
Senarai lengkap kategori maklumat yang sistem ini kumpul pada masa ini. Sistem tidak menyediakan medan untuk kategori lain — tiada ruang untuk nombor kad pengenalan, alamat, atau apa-apa yang tidak tersenarai di sini. Beberapa medan (nama, nama panggilan, kelas, dan nota ringkas pentadbir pada nombor telefon) ialah medan teks bebas, jadi apa yang ditaip ke dalamnya bergantung kepada orang yang menaipnya — tetapi sistem tidak meminta, memproses, atau menggunakan apa-apa di luar kategori di bawah.
| Maklumat | Bila diberikan | Nota |
|---|---|---|
| Nama penuh anda | Semasa mendaftar akaun | Dipaparkan kepada pentadbir sekolah dan disimpan dalam rekod sejarah jemputan. |
| Nombor telefon anda | Semasa mendaftar akaun | Berfungsi sebagai nama pengguna. Mesti sudah wujud dalam senarai kebenaran sekolah. |
| Kata laluan | Semasa mendaftar akaun | Disimpan dalam bentuk yang tidak boleh dibaca semula (hash bcrypt). Kami tidak dapat melihat kata laluan sebenar anda, dan tidak boleh memulihkannya — hanya menetapkan yang baharu. |
| Nama penuh anak | Semasa menambah anak | Dipaparkan dalam dashboard anda dan panel admin sekolah. |
| Nama panggilan anak | Semasa menambah anak | Nama yang dilaungkan melalui pembesar suara dan dipaparkan di skrin TV. Wajib diisi — sistem tidak menerima medan ini kosong, supaya nama penuh anak tidak pernah dilaungkan secara tidak sengaja. |
| Kelas anak | Semasa menambah anak | Disebut bersama nama supaya murid dengan nama serupa dapat dibezakan. |
| Maklumat | Nota |
|---|---|
| Senarai nombor telefon dibenarkan | Sekolah memuat naik nombor telefon ibu bapa yang dibenarkan mendaftar, kadangkala bersama nota ringkas pentadbir. Nombor anda mungkin berada dalam sistem sebelum anda mendaftar akaun. |
| Senarai kelas | Bukan maklumat peribadi. Digunakan untuk menu pilihan kelas. |
| Pembetulan sebutan audio | Pentadbir sekolah boleh menetapkan ejaan sebutan bagi nama yang disebut salah oleh suara automatik. Ia mengubah bunyi sahaja, bukan nama yang dipaparkan. |
| Maklumat | Nota |
|---|---|
| Rekod jemputan | Setiap kali anda memanggil anak: nama anak, nama panggilan, kelas, nama anda, nombor telefon anda, waktu panggilan, dan sama ada ia panggilan biasa atau "Di Depan Pagar". Rekod ini disalin sebagai teks penuh supaya ia kekal sebagai rekod sekolah walaupun akaun dipadam kemudian. |
| Fail audio (MP3) | Satu rakaman suara bagi setiap anak, menyebut nama panggilan dan kelas. Nama fail hanya nombor — tiada nama di dalam nama fail. |
| Log pelayan web | Alamat IP anda, waktu, halaman yang diminta, dan jenis pelayar. Ini direkod secara automatik oleh pelayan web, seperti mana-mana laman web. Alamat IP dikira maklumat peribadi di bawah PDPA apabila ia boleh dikaitkan dengan seseorang. |
| Log aplikasi | Rekod teknikal untuk mengesan masalah. Ia mencatat nombor ID sahaja — tiada nama murid atau ibu bapa. |
| Maklumat | Status | Akibat jika tidak diberikan |
|---|---|---|
| Nama penuh anda · nombor telefon · kata laluan | Wajib | Akaun tidak boleh dibuka. Ketiga-tiganya diperlukan untuk mengenal pasti pemilik akaun dan melindunginya. |
| Nama penuh anak · kelas | Wajib | Anak tidak boleh didaftarkan, jadi anda tidak boleh memanggil mereka melalui sistem. |
| Nama panggilan anak | Wajib | Anak tidak boleh didaftarkan. Medan ini wajib supaya anda yang menentukan nama yang dilaungkan di khalayak ramai, bukan sistem memilih nama penuh bagi pihak anda. |
| Menggunakan sistem ini langsung | Pilihan | Tiada. Penggunaan sistem ini adalah pilihan dan bukan sebahagian daripada pendaftaran anak anda di sekolah. Kaedah lain untuk menjemput murid tertakluk kepada prosedur yang ditetapkan oleh pihak sekolah. |
Nombor kad pengenalan · alamat rumah · alamat e-mel · tarikh lahir · rekod akademik · rekod kesihatan · lokasi GPS · senarai kenalan · gambar murid · maklumat pembayaran atau kad kredit. Sistem tidak mempunyai tempat untuk menyimpan mana-mana daripadanya.
Nama panggilan yang anda tetapkan akan dilaungkan melalui pembesar suara sekolah dan dipaparkan di skrin TV yang boleh dilihat oleh ibu bapa lain di kawasan menunggu. Anda bertanggungjawab memastikan nama yang anda tetapkan sesuai untuk diumumkan secara terbuka. Sekolah menyelenggara senarai perkataan larangan, boleh mengubah nama panggilan yang tidak sesuai tanpa notis terlebih dahulu, dan boleh menghadkan keupayaan anda mengubah nama panggilan sekiranya ia disalahgunakan.
Di bawah PDPA, maklumat peribadi hanya boleh dikumpul untuk tujuan yang dinyatakan dan tidak boleh melebihi keperluan tujuan itu. Jadual ini menyatakan tujuan setiap medan.
| Maklumat | Tujuan |
|---|---|
| Nombor telefon anda | Pengenalan akaun (nama pengguna) dan kawalan kebenaran — hanya nombor yang sekolah benarkan boleh membuka akaun. Ini menghalang orang yang tidak berkaitan daripada memanggil murid keluar. Ia juga menjadi saluran hubungan pihak sekolah untuk sokongan teknikal, seperti urusan menetapkan semula kata laluan — hubungan dibuat terus oleh sekolah, bukan melalui perkhidmatan SMS atau e-mel (lihat Bahagian 7). |
| Nama penuh anda | Membolehkan pejabat sekolah mengenal pasti pemilik akaun, dan merekodkan siapa yang menjemput seorang murid pada satu-satu hari. |
| Kata laluan | Melindungi akaun anda daripada digunakan oleh orang lain. |
| Nama penuh anak | Pengenalan murid yang tepat oleh pihak sekolah, terutamanya apabila dua murid mempunyai nama panggilan yang sama. |
| Nama panggilan anak | Nama yang dilaungkan dan dipaparkan. Wujud supaya nama panjang tidak perlu disebut penuh, dan supaya sebutan lebih jelas. |
| Kelas anak | Disebut bersama nama untuk membezakan murid, dan membantu guru mengenal pasti murid yang dipanggil. |
| Rekod jemputan | Rekod keselamatan sekolah — catatan siapa menjemput murid mana, pada pukul berapa. Ini yang boleh dirujuk jika berlaku pertikaian mengenai penjagaan atau pelepasan murid. |
| Fail audio | Membolehkan hebahan dimainkan serta-merta tanpa menghantar apa-apa ke internet pada waktu jemputan. |
| Alamat IP (log pelayan) | Keselamatan dan penyelesaian masalah teknikal — mengesan percubaan log masuk berulang dan gangguan perkhidmatan. |
Maklumat dalam sistem ini tidak digunakan untuk pemasaran, tidak dianalisis untuk membina profil, dan tidak dikongsi dengan mana-mana pihak untuk tujuan komersial. Ia digunakan semata-mata untuk menjalankan proses jemputan bagi pihak sekolah.
Setiap tempoh di bawah disahkan terhadap konfigurasi sistem sebenar pada tarikh versi dasar ini, bukan disalin daripada templat. Angka yang bertanda ≈ memang anggaran, dan sebabnya diterangkan di tempatnya.
| Maklumat | Tempoh | Apa yang memadamnya |
|---|---|---|
| Giliran jemputan harian | Sehingga tengah malam hari yang sama | Proses automatik pada pukul 00:00 setiap malam: rekod diarkibkan sebagai sejarah, kemudian senarai giliran dikosongkan sepenuhnya. |
| Rekod sejarah jemputan | 12 bulan dari tarikh panggilan | Proses automatik yang sama, setiap malam. Rekod melebihi 12 bulan dipadam tanpa campur tangan manusia. |
| Akaun anda | Selagi ia wujud | Pentadbir sekolah memadamnya atas permintaan anda, atau semasa pembersihan hujung tahun. Tiada pemadaman automatik. |
| Rekod anak anda | Selagi anak berdaftar | Anda boleh memadam anak anda sendiri melalui dashboard. Pentadbir sekolah juga boleh memadam murid, seluruh kelas, atau sekumpulan keluarga yang telah keluar dari sekolah. |
| Fail audio anak | Mengikut rekod anak | Dipadam serentak apabila rekod anak dipadam. |
| Nombor anda dalam senarai kebenaran | Selagi sekolah mengekalkannya | Dipadam oleh tindakan pentadbir sekolah. Ambil perhatian: memadam akaun anda sahaja tidak membuang nombor anda daripada senarai ini — ini sengaja, supaya anda boleh mendaftar semula tanpa perlu dimasukkan semula. Untuk membuang kedua-duanya sekali, permintaan pemadaman penuh perlu dibuat (Bahagian 9). |
| Permintaan reset kata laluan | 90 hari | Proses automatik setiap malam memadam semua permintaan melebihi 90 hari, sama ada sudah diuruskan atau belum. |
| Log aplikasi | ≈ 7 hari | Diputar setiap tengah malam; hanya 7 salinan terakhir disimpan. Log ini mengandungi nombor ID sahaja, bukan nama. |
| Log pelayan web (alamat IP) | Sehingga 15 hari | Diputar setiap hari; 14 salinan lama disimpan dalam bentuk dimampatkan, kemudian dipadam sendiri. |
| Salinan backup | 7 salinan terakhir (≈ 7 hari) | Salinan lama dipadam secara automatik apabila salinan baharu dibuat. |
Kami membuat salinan backup harian bagi melindungi data sekolah daripada kerosakan perkakasan. Apabila maklumat dipadam daripada sistem langsung, ia masih wujud dalam salinan backup sehingga kira-kira 7 hari sebelum salinan itu luput sendiri.
Ini bermakna kami tidak boleh berkata "data anda dipadam serta-merta dan sepenuhnya". Ayat yang tepat ialah: dipadam daripada sistem langsung serta-merta, dan hilang sepenuhnya daripada semua salinan dalam masa kira-kira seminggu.
Salinan backup digunakan semata-mata untuk pemulihan sistem, keselamatan, dan kesinambungan perkhidmatan. Ia bukan sumber rujukan operasi harian dan tidak dibuka untuk mendapatkan semula maklumat seseorang individu.
Satu tahun persekolahan Malaysia (Januari–November) ditambah margin. Ia cukup panjang untuk sekolah merujuk semula rekod tahun semasa sekiranya berlaku pertikaian, dan cukup pendek untuk memenuhi prinsip PDPA bahawa maklumat tidak disimpan lebih lama daripada yang perlu.
Sesetengah sekolah mungkin meminta tempoh berbeza. Jika sekolah anak anda berbuat demikian, tempoh sebenar yang terpakai akan dinyatakan oleh sekolah tersebut.
12 bulan ialah tempoh penyimpanan standard, bukan had mutlak. Rekod tertentu boleh perlu disimpan lebih lama apabila ia dikehendaki oleh undang-undang, oleh perintah mahkamah atau arahan pihak berkuasa, atau kerana ia berkaitan dengan pertikaian atau siasatan yang sedang berjalan. Keputusan itu dibuat oleh sekolah sebagai pengawal data, dan hanya bagi rekod yang berkenaan — bukan bagi keseluruhan sejarah. Dalam praktik ia bermakna sekolah menyimpan salinan rekod tersebut sebelum ia luput, atau menetapkan tempoh penyimpanan yang berbeza; pemadaman automatik itu sendiri tidak tahu tentang pertikaian.
| Siapa | Apa yang mereka nampak | Kawalan yang wujud |
|---|---|---|
| Anda | Akaun anda dan anak-anak anda sahaja | Setiap permintaan ke pelayan disemak dan diskop kepada akaun anda, termasuk apabila alamat halaman diubah secara manual — pemeriksaan itu dibuat di pelayan, bukan disembunyikan pada skrin sahaja. Ia direka supaya anda tidak boleh melihat atau mengurus anak ibu bapa lain. |
| Pentadbir sekolah | Semua akaun ibu bapa, semua murid, sejarah jemputan penuh | Akses pentadbir memerlukan akaun berperanan khas. Sekolah bertanggungjawab menentukan siapa dalam organisasi mereka mendapat akses ini. |
| Kakitangan di pejabat sekolah | Senarai giliran semasa dan nama yang sedang dilaungkan | Skrin ini memaparkan giliran hari ini sahaja, bukan sejarah atau maklumat akaun. |
| Sesiapa yang melihat skrin TV | Nama panggilan dan kelas murid yang sedang dipanggil | Ini adalah tujuan sistem — ia paparan awam di kawasan menunggu. Nama ibu bapa tidak dipaparkan di TV. |
| Sesiapa dalam jarak pendengaran | Nama panggilan dan kelas yang dilaungkan | Sama seperti di atas — hebahan pembesar suara adalah terbuka secara semula jadi. |
| Ibu bapa lain | Tiada akses kepada akaun atau data anda | Mereka hanya melihat dan mendengar apa yang dipaparkan atau dilaungkan secara awam, sama seperti orang lain di kawasan menunggu. |
| Kakitangan teknikal kami | Akses pentadbiran pelayan, termasuk pangkalan data | Akses terhad kepada keperluan penyelenggaraan, pemulihan gangguan, dan pemadaman data atas arahan sekolah. Kami tidak melihat data sekolah dalam operasi harian. |
| Penyedia hos pelayan (VPS) | Akses fizikal kepada cakera pelayan | Sub-pemproses — penyedia infrastruktur. Sama seperti mana-mana penyedia hos. Mereka tiada akaun dalam aplikasi dan tiada akses kepada antara muka sistem. |
Maklumat dalam sistem ini tidak pernah dijual, disewakan, atau ditukar,
dan tidak dikongsi untuk tujuan pemasaran atau apa-apa tujuan komersial yang tidak berkaitan
dengan menjalankan sistem ini — oleh kami mahupun oleh sekolah melalui sistem ini.
Maklumat memang diproses oleh penyedia perkhidmatan dan sub-pemproses yang
menjalankan sistem, dan boleh didedahkan apabila undang-undang menghendakinya. Kedua-duanya
bukan pengecualian tersembunyi kepada ayat di atas: yang pertama diterangkan sepenuhnya
dalam Bahagian 7, dan yang kedua dalam perenggan di bawah.
Kami boleh mendedahkan maklumat jika dikehendaki oleh undang-undang, perintah mahkamah, atau permintaan sah pihak berkuasa. Dalam keadaan itu, kami akan memaklumkan pihak sekolah melainkan undang-undang melarangnya.
Hanya satu pihak ketiga diberi maklumat murid untuk diproses secara aktif — perkhidmatan suara Google, bagi menjana rakaman audio, dan hanya sedikit maklumat sahaja. Satu lagi boleh menerima nombor telefon anda apabila pihak sekolah memilih untuk menghubungi anda melalui WhatsApp. Penyedia hos pelayan pula memproses data sebagai sebahagian daripada perkhidmatan infrastruktur, bukan sebagai penerima yang menggunakan maklumat itu. Ketiga-tiganya diterangkan di bawah.
Untuk menghasilkan rakaman suara yang menyebut nama anak anda, teks nama dihantar kepada perkhidmatan suara Google Cloud, yang mengembalikan fail audio. Fail itu kemudian disimpan pada pelayan kami.
| Perkara | Keadaan sebenar |
|---|---|
| Apa yang dihantar | Nama panggilan anak yang anda tetapkan sendiri, bersama nama kelas — diulang dua kali. Contoh teks sebenar: Imran 2 Zubair. Imran 2 Zubair. |
| Apa yang TIDAK dihantar | Nombor kad pengenalan · alamat · nombor telefon · nama ibu bapa · sebarang pengenalan akaun · rekod jemputan |
| Bila ia dihantar | Hanya apabila rakaman perlu dibuat atau dibuat semula: semasa anak ditambah, apabila nama panggilan atau kelasnya diubah, apabila pentadbir sekolah membetulkan sebutan, dan apabila kami menjana semula audio sedia ada (contohnya selepas menukar suara atau peraturan sebutan). Bukan setiap kali anak dipanggil — panggilan harian hanya memainkan fail yang sudah tersimpan pada pelayan kami. |
| Lokasi pemprosesan | Sistem menetapkan titik akhir serantau Singapura milik Google, jadi permintaan suara diproses di dalam Asia Tenggara dan bukan dihalakan ke seluruh dunia secara automatik. Ini ditetapkan dalam kod, bukan bergantung pada tetapan setiap sekolah. Singapura berada di luar Malaysia — lihat nota di bawah jadual ini. |
| Penyimpanan oleh Google | Penggunaan kami tertakluk kepada Google Cloud Data Processing Addendum, iaitu perjanjian kontrak yang mengawal cara Google mengendalikan data pelanggan perkhidmatan berbayar. Kami telah menyemak dan menerima terma tersebut bagi akaun yang digunakan untuk perkhidmatan ini. Rujuk dokumen itu untuk terma penuh. |
Pelayan yang menghoskan sistem ini berada di Malaysia pada tarikh dasar ini. Jadi akaun anda, rekod jemputan, dan fail audio yang tersimpan semuanya berada di dalam negara.
Satu pengecualian sahaja: penjanaan suara. Menetapkan titik akhir Singapura mengehadkan pemprosesan itu kepada rantau Asia Tenggara, tetapi ia tidak bermakna maklumat kekal di dalam Malaysia — nama panggilan dan nama kelas anak anda diproses di luar negara pada saat fail audio dijana. Kami menyatakannya dengan jelas kerana "diproses di rantau ini" dan "kekal di Malaysia" bukan perkara yang sama.
Sebarang maklumat peribadi yang dihantar kepada penyedia perkhidmatan di luar Malaysia, atau yang menyebabkan pemprosesan berlaku di luar Malaysia, dikendalikan mengikut keperluan undang-undang perlindungan data peribadi yang terpakai bagi pemindahan rentas sempadan pada masa pemindahan itu berlaku.
Dua perkara mengehadkan pemindahan itu dalam praktik. Skop: hanya nama panggilan dan nama kelas dihantar, semata-mata untuk menjana fail audio — tiada nama ibu bapa, nombor telefon, atau rekod jemputan (lihat jadual di atas). Kontrak: pemprosesan oleh Google tertakluk kepada Google Cloud Data Processing Addendum yang telah kami semak dan terima.
Asas undang-undang bagi pemindahan ini adalah tanggungjawab sekolah sebagai pengawal data, sama seperti pemprosesan lain dalam sistem ini (Bahagian 2). Peranan kami ialah memastikan pemindahan itu sesempit mungkin dan dilindungi secara kontrak.
Jika fail audio gagal dijana, peranti pejabat sekolah beralih kepada enjin suara terbina dalam pelayar Chrome (bunyi lebih robotik). Ini berjalan sepenuhnya pada peranti tersebut — ia bukan perkhidmatan awan, tiada apa dihantar ke internet, dan ia tidak tertakluk kepada perjanjian pemprosesan data Google.
Dua pihak sahaja bertindak sebagai sub-pemproses kepada kami: Google Cloud (penjanaan suara, diterangkan di atas) dan penyedia hos pelayan (infrastruktur). Kami hanya melantik penyedia yang benar-benar diperlukan untuk menjalankan sistem, dan mengambil langkah kontrak dan teknikal yang munasabah bagi memastikan maklumat dilindungi. Selebihnya dalam jadual di bawah disenaraikan kerana orang lazimnya menjangka ia wujud — dan ia memang tiada.
Senarai ini boleh berubah. Kami boleh melantik atau menggantikan penyedia perkhidmatan dan sub-pemproses yang diperlukan untuk menjalankan sistem, tertakluk kepada keperluan perlindungan data yang terpakai. Perubahan yang melibatkan kategori penerima baharu atau jenis maklumat baharu yang diproses akan dinyatakan melalui kemas kini dasar ini — lihat Bahagian 11 untuk cara kemas kini dimaklumkan. Senarai di bawah menerangkan kedudukan pada tarikh versi ini.
| Perkhidmatan | Kedudukan |
|---|---|
| Penyedia hos pelayan (VPS) | Sub-pemproses — penyedia infrastruktur. Menghoskan pelayan dan pangkalan data. Mempunyai akses fizikal kepada cakera, seperti mana-mana penyedia hos. Tiada akaun dalam aplikasi dan tiada akses kepada antara mukanya. |
| Google Analytics / piksel iklan | Tiada. Sistem tidak memuatkan sebarang skrip penjejakan pihak ketiga. |
| Fon web luaran | Tiada. Semua fon dihoskan sendiri — tiada permintaan dibuat ke Google Fonts atau perkhidmatan serupa. |
| Perkhidmatan SMS / e-mel | Tiada. Reset kata laluan dikendalikan bersemuka oleh pejabat sekolah, bukan melalui SMS atau e-mel. Nombor telefon anda tidak dihantar ke mana-mana penyedia mesej. |
| Pemproses pembayaran | Tiada dalam sistem. Bayaran langganan diuruskan sepenuhnya di luar aplikasi. Ibu bapa tidak membuat sebarang pembayaran melalui sistem ini. |
| WhatsApp (Meta) |
Panel pentadbir mempunyai butang yang membuka WhatsApp untuk menghubungi
ibu bapa mengenai permintaan reset kata laluan. Apabila kakitangan sekolah menekannya,
nombor telefon anda dihantar kepada WhatsApp sebagai sebahagian daripada
alamat pautan, bersama satu mesej pembuka yang sama bagi setiap permintaan
— ayat sapaan yang bertanya sama ada anda benar-benar memohon reset kata laluan, tanpa
nama sesiapa di dalamnya — supaya perbualan dapat dibuka.
Ini berlaku hanya apabila kakitangan sekolah menekannya — bukan secara automatik, dan tidak pernah semasa anda menggunakan sistem. Tiada nama murid, kelas atau rekod jemputan dihantar. Sistem tidak memuatkan sebarang kod WhatsApp; ia hanya membuka aplikasi WhatsApp pada peranti kakitangan tersebut. |
| Media sosial lain | Tiada. Tiada butang kongsi, tiada log masuk media sosial, tiada piksel penjejakan. |
Ketiadaan skrip penjejakan, fon luaran, dan perkhidmatan pihak ketiga bermakna tiada maklumat murid mengalir ke mana-mana pihak ketiga selain satu permintaan suara kepada Google, dan itu pun hanya apabila rakaman perlu dibuat atau dibuat semula. Butang WhatsApp di atas membawa nombor telefon anda sahaja, tidak pernah maklumat anak anda, dan hanya apabila kakitangan sekolah menekannya. Melayari sistem ini tidak memberitahu sesiapa di luar bahawa anda menggunakannya.
| Perlindungan | Apa yang ia lakukan |
|---|---|
| Kata laluan tidak boleh dibaca | Kata laluan disimpan sebagai hash bcrypt — bentuk yang tidak boleh diterbalikkan. Walaupun pangkalan data terdedah, kata laluan sebenar anda tidak boleh dibaca. Kami sendiri tidak dapat melihatnya. |
| Sambungan disulitkan | Semua trafik antara telefon anda dan pelayan menggunakan HTTPS dengan sijil SSL yang sah. |
| Pendaftaran terkawal | Hanya nombor telefon yang telah dimasukkan oleh sekolah ke dalam senarai kebenaran boleh membuka akaun. Orang luar tidak boleh mendaftar sendiri. |
| Had percubaan log masuk | Percubaan log masuk yang gagal berulang kali daripada sumber yang sama akan disekat sementara, bagi menghalang tekaan kata laluan. |
| Pengasingan setiap akaun | Setiap pertanyaan data diskop kepada akaun yang membuat permintaan. Tiada halaman atau alamat yang boleh diubah secara manual untuk melihat anak ibu bapa lain. |
| Pengasingan setiap sekolah | Setiap sekolah mempunyai pangkalan data dan proses aplikasi yang berasingan sepenuhnya. Tiada jadual dikongsi. |
| Pembatalan akses serta-merta | Menukar kata laluan akan melog keluar semua peranti lain serta-merta. Akaun yang digantung atau dipadam oleh sekolah ditolak pada permintaan berikutnya, walaupun peranti itu masih menyimpan sesi lama. |
| Salinan backup harian | Melindungi data sekolah daripada kerosakan perkakasan atau kesilapan pemadaman. Salinan lama dipadam secara automatik. |
Perlindungan teknikal tidak dapat menggantikan penjagaan akaun. Sila:
Sekiranya berlaku insiden keselamatan yang menjejaskan maklumat peribadi, kami akan memaklumkan pihak sekolah tanpa kelewatan yang tidak munasabah dan — sebagai komitmen operasi kami — dalam masa 24 jam selepas insiden itu dikenal pasti sebagai insiden yang mungkin melibatkan maklumat peribadi, bersama maklumat tentang apa yang terjejas dan langkah yang diambil. Kami juga akan memberikan maklumat dan bantuan yang munasabah bagi membolehkan pihak sekolah melaksanakan kewajipan pemberitahuannya sendiri.
24 jam itu ialah standard yang kami tetapkan sendiri, bukan tempoh yang dikenakan ke atas kami oleh undang-undang. Kewajipan pemproses data untuk memberitahu pengawal data bersifat kontraktual, bukan tempoh berkanun yang dikenakan terus ke atas kami. Kami menyatakannya di sini supaya ia boleh dipegang, bukan supaya ia kelihatan seperti keperluan statutori.
Selepas itu, pemberitahuan kepada Pesuruhjaya Perlindungan Data Peribadi dan kepada individu yang terjejas ialah tanggungjawab sekolah sebagai pengawal data. Sama ada pemberitahuan itu dikehendaki, dan kepada siapa, bergantung pada penilaian sekolah terhadap jenis dan tahap risiko pelanggaran tersebut — bukan setiap insiden mencetuskan setiap pemberitahuan.
Sebagai rujukan: di bawah Pekeliling Pesuruhjaya Perlindungan Data Peribadi Bilangan 2 Tahun 2025 (seksyen 12B Akta Perlindungan Data Peribadi 2010), sebagaimana ia berkuat kuasa pada tarikh dasar ini, tempoh yang terpakai kepada pengawal data ialah 72 jam kepada Pesuruhjaya dan 7 hari selepas itu kepada individu yang terjejas, sekiranya pelanggaran itu berkemungkinan mengakibatkan kemudaratan yang ketara. Tempoh sebenar yang mengikat sekolah ialah tempoh yang berkuat kuasa pada masa insiden itu berlaku.
Di bawah Akta Perlindungan Data Peribadi 2010, anda mempunyai hak tertentu ke atas maklumat peribadi anda dan anak anda.
| Hak anda | Apa maksudnya | Cara menggunakannya |
|---|---|---|
| Hak akses | Meminta salinan maklumat peribadi yang disimpan tentang anda dan anak anda | Kemukakan permintaan kepada pihak sekolah |
| Hak pembetulan | Membetulkan maklumat yang salah atau tidak lengkap | Maklumat anak anda (nama penuh, nama panggilan, kelas) boleh anda betulkan sendiri dalam dashboard. Untuk nama atau nombor telefon anda sendiri, hubungi sekolah — pentadbir boleh membetulkannya tanpa memadam akaun anda. Jika keupayaan anda menyunting maklumat anak telah dihadkan oleh sekolah, pentadbir juga boleh membetulkannya bagi pihak anda. |
| Hak memadam | Meminta maklumat anda dipadam apabila ia tidak lagi diperlukan | Kemukakan permintaan kepada pihak sekolah. Lihat had di bawah. |
| Hak menarik balik persetujuan | Berhenti menggunakan sistem ini | Maklumkan kepada sekolah. Anda boleh terus menjemput anak anda mengikut kaedah biasa sekolah. |
| Hak membuat aduan | Mengemukakan aduan kepada Jabatan Perlindungan Data Peribadi (JPDP) | Kami menggalakkan anda menghubungi sekolah dan kami dahulu, tetapi hak ini tidak bersyarat. |
Kami akan bertindak ke atas permintaan yang disahkan oleh sekolah dalam masa 21 hari dari tarikh permintaan diterima. Kami menggunakan tempoh yang sama bagi semua jenis permintaan dalam bahagian ini, dengan menjajarkannya kepada tempoh yang ditetapkan oleh Seksyen 12 Akta Perlindungan Data Peribadi 2010 bagi permintaan akses data, sebagaimana ia berkuat kuasa pada tarikh dasar ini — supaya angkanya datang daripada Akta dan bukan direka sendiri.
Jika permintaan itu rumit, memerlukan masa lebih lama, atau memerlukan maklumat tambahan bagi mengesahkan identiti anda, kami akan memaklumkan perkara itu kepada anda dalam tempoh yang sama, sebagaimana yang dibenarkan oleh undang-undang yang terpakai.
Rekod jemputan mencatat siapa menjemput murid mana, pada pukul berapa. Ia adalah rekod keselamatan pihak sekolah, bukan milik satu pihak sahaja. Memadamnya atas permintaan seorang ibu bapa akan menghapuskan bukti sekolah sekiranya berlaku pertikaian mengenai penjagaan atau pelepasan murid — termasuk pertikaian yang melibatkan ibu bapa lain.
Atas sebab itu, rekod sejarah jemputan disimpan 12 bulan untuk tujuan keselamatan dan tidak dipadam atas permintaan individu. Permintaan pemadaman tertakluk kepada keperluan dan pengecualian yang ditetapkan oleh undang-undang yang terpakai: dalam keadaan tertentu, rekod perlu dikekalkan bagi tujuan keselamatan, pematuhan, penyelesaian pertikaian, siasatan, atau kewajipan undang-undang. Rekod tersebut tetap luput dengan sendirinya selepas 12 bulan — ia bukan simpanan tanpa had. Satu pengecualian sempit dijelaskan dalam Bahagian 5: rekod yang terikat dengan pertikaian, siasatan, atau kehendak undang-undang boleh disimpan lebih lama.
Jika sekolah hanya memadam akaun anda melalui fungsi biasa, nombor telefon anda kekal dalam senarai kebenaran — supaya anda boleh mendaftar semula tanpa perlu dimasukkan semula oleh pejabat. Itu berguna dalam kes biasa, tetapi ia bukan pemadaman penuh.
Apabila anda membuat permintaan pemadaman di bawah PDPA, nyatakan dengan jelas bahawa anda mahu nombor telefon dibuang sekali. Sistem mempunyai fungsi khusus untuk itu, dan pihak sekolah tahu cara menggunakannya.
Selepas pemadaman, anda tidak lagi boleh log masuk atau memanggil anak anda melalui sistem ini. Anda perlu menjemput anak mengikut kaedah biasa yang ditetapkan sekolah. Jika anda mahu menggunakan sistem semula kemudian, sekolah perlu memasukkan nombor anda ke dalam senarai kebenaran sekali lagi.
Sebahagian maklumat disimpan pada peranti anda sendiri, bukan pada pelayan kami. Ini penting untuk anda ketahui kerana kawalan ke atasnya berbeza daripada kawalan ke atas pelayan kami.
| Di mana | Apa yang disimpan | Bila ia hilang |
|---|---|---|
| Telefon anda — simpanan pelayar | Sesi log masuk anda (mengandungi ID akaun, nama penuh dan nombor telefon anda), serta senarai anak yang disimpan sementara untuk paparan lebih pantas | Apabila anda menekan butang log keluar, atau apabila anda menukar kata laluan pada peranti lain |
| Telefon anda — cache aplikasi | Halaman dan fail aplikasi supaya ia dapat dibuka dengan pantas | Apabila versi aplikasi dikemas kini, atau apabila anda membersihkan data pelayar |
| Peranti pejabat sekolah — laptop atau tablet | Fail audio murid yang pernah dimainkan | Apabila versi aplikasi dikemas kini. Antara kemas kini, fail audio anak yang sudah dipadam daripada pelayan masih boleh wujud dalam cache peranti tersebut. |
| Skrin TV sekolah | Tiada simpanan kekal — hanya paparan sementara dalam ingatan | Apabila halaman dimuat semula (berlaku secara automatik setiap pukul 3:00 pagi) |
"Di luar kawalan kami" bukan bermakna tiada sesiapa bertanggungjawab. Peranti pejabat sekolah dan skrin TV ialah milik dan di bawah kawalan pihak sekolah: akses fizikal kepadanya, siapa dibenarkan menggunakannya, akaun pengguna pada peranti itu, dan pembersihan storan tempatannya adalah tanggungjawab sekolah — sama seperti mana-mana komputer pejabat mereka yang lain.
Bahagian kami ialah mekanismenya, dan ia wujud: cache aplikasi pada peranti pejabat dikosongkan secara automatik apabila kami mengeluarkan versi baharu aplikasi, dan kami boleh mengeluarkan versi baharu apabila sekolah perlu cache itu dikosongkan lebih awal — contohnya selepas permintaan pemadaman. Kakitangan sekolah juga boleh mengosongkannya sendiri pada bila-bila masa melalui tetapan pelayar peranti tersebut.
Satu butiran teknikal yang kami nyatakan kerana ia benar: selain cache aplikasi itu, pelayar menyimpan fail audio dalam simpanan sementaranya sendiri selama sehingga 7 hari, dan simpanan itu luput mengikut masa, bukan mengikut versi aplikasi. Jadi tempohnya setara dengan salinan backup — kira-kira seminggu, bukan serta-merta.
Anda kekal log masuk sehingga anda menekan butang log keluar — ini disengajakan, supaya anda tidak perlu memasukkan kata laluan setiap kali hendak memanggil anak. Kesannya: sesiapa yang memegang telefon anda yang tidak berkunci boleh memanggil anak anda keluar.
Jika telefon anda hilang atau dicuri, tukar kata laluan anda dari peranti lain — ini melog keluar telefon tersebut serta-merta. Jika anda tidak dapat berbuat demikian, hubungi sekolah dan minta akaun anda digantung.
Sistem ini tidak menggunakan kuki penjejakan. Maklumat sesi log masuk disimpan dalam simpanan tempatan pelayar anda, bukan dalam kuki yang dihantar ke pelayan lain, dan ia tidak digunakan untuk menjejak anda merentas laman web.
Dasar ini boleh dikemas kini apabila sistem berubah atau apabila kehendak undang-undang berubah. Setiap versi mempunyai nombor versi dan tarikh, dipaparkan pada bahagian bawah halaman ini.
Bagi perubahan yang material — contohnya tempoh penyimpanan yang lebih lama, kategori maklumat baharu, atau penerima pihak ketiga baharu — kami akan memaklumkan pihak sekolah terlebih dahulu, dan sekolah akan memaklumkan ibu bapa. Bagi pembetulan kecil seperti penjelasan ayat, versi dikemas kini tanpa notis berasingan.
| Versi | Tarikh | Perubahan |
|---|---|---|
| 1.0 | 12 Ogos 2026 | Versi pertama. |
Untuk permintaan berkaitan maklumat peribadi (akses, pembetulan, pemadaman), hubungi pihak sekolah anak anda terlebih dahulu. Sekolah ialah pengawal data dan memegang hubungan dengan anda.
Jika sekolah tidak memberi respons, atau jika anda mempunyai soalan tentang cara sistem ini mengendalikan maklumat, hubungi kami:
| Nama entiti | MFZ DIGITAL No. Pendaftaran SSM: 202603210023 (003878100-V) |
| E-mel | [email protected] |
| Telefon | 017-252 2273 |
| Alamat surat-menyurat | 5, Jalan 33/10, Taman Koperasi Polis, 68100 Batu Caves, Selangor |
Anda juga berhak mengemukakan aduan terus kepada Jabatan Perlindungan Data Peribadi (JPDP), Kementerian Digital Malaysia.
Kami tidak melantik Pegawai Perlindungan Data buat masa ini. Kami menyatakannya dengan jelas kerana menyenaraikan jawatan yang tidak wujud lebih buruk daripada tidak menyenaraikannya langsung.
MFZ DIGITAL menjalankan penilaian berterusan mengenai keperluan pelantikan Pegawai Perlindungan Data di bawah seksyen 12A Akta 709 dan pekeliling yang berkuat kuasa, termasuk kewajipan yang terpakai terus kepada pemproses data. Penilaian ini dikemas kini apabila bilangan sekolah, jumlah individu yang datanya kami proses, atau sifat pemprosesan berubah. Jika kewajipan pelantikan terpakai kepada kami, MFZ DIGITAL akan melantik Pegawai Perlindungan Data dan memaparkan butiran hubungannya dalam dasar ini serta melalui saluran rasmi kami.
Sementara itu, semua pertanyaan dan urusan pematuhan perlindungan data dikendalikan terus oleh pengurusan kami melalui saluran rasmi di atas, dan saluran itu dipantau.
What this system knows about you and your child, how long it is kept, who can see it, and what your rights are.
This Privacy Policy is provided in both English and Malay. In the event of any inconsistency or conflict between the two versions, the Malay version shall prevail.
This section summarises the whole policy. Sections 2 to 12 give the full detail, and it is those sections that are binding.
jemput.app is a school pickup automation system operated by MFZ DIGITAL, SSM Registration No. 202603210023 (003878100-V), referred to below as "we".
Your child's school uses this system to manage pickup times. The division of responsibility between the school and us matters, because it determines who you should turn to when you have a request or a complaint.
These roles determine who directs the processing. It does not mean we carry no responsibility of our own: the 2024 PDPA amendments place security and data breach notification obligations directly on data processors. Section 8 explains what we do under those obligations.
We use Data Controller because that is the term Act 709 uses today. The 2024 PDPA amendments replaced the older term Data User with Data Controller throughout the Act. Both refer to the same thing — the party that determines the purposes and means of processing personal information, which in this arrangement is the school.
Requests concerning your personal information — to see it, correct it, or delete it — should be made to the school, not directly to us. The school then instructs us to act. This is not to make things difficult for you; it reflects the fact that it is the school that holds the relationship with you and that is entitled to verify your identity.
If the school does not respond, you may still contact us directly — details in Section 12. What we do with such a request is set out here so that you know what to expect: we do not change, correct, or delete data unilaterally on a direct request, because we process that information on the school's behalf and it is the school that is entitled to verify your identity. Instead we forward your request to the school administrator within 3 working days — our own operational commitment, not a statutory period — and inform you that it has been forwarded.
Once the school confirms the request, the 21-day response period in Section 9 applies. If the school still takes no action, you may lodge a complaint directly with the Personal Data Protection Department — see Section 12.
Almost all the information in this system concerns minors — the name that is announced, the class that is displayed, and the record of when they were collected. Parents or lawful guardians therefore act on their behalf in matters concerning the child's personal information.
Court orders, shared custody, or disputes over who is entitled to collect a pupil are matters that must be handled by the school, not through settings in this system. Inform the school and they will adjust the relevant account access.
Each school runs on an entirely separate database, audio folder, and application process. No data tables are shared between schools. In practical terms: the system is designed with data isolation between schools in order to prevent cross-school access through this system.
A complete list of the categories of information this system collects at present. The system provides no field for other categories — there is no space for an identity card number, an address, or anything not listed here. Several fields (name, nickname, class, and the administrator's short note against a phone number) are free-text fields, so what is typed into them depends on the person typing — but the system does not ask for, process, or use anything outside the categories below.
| Information | When provided | Notes |
|---|---|---|
| Your full name | When registering an account | Shown to school administrators and stored in the pickup history records. |
| Your phone number | When registering an account | Serves as your username. Must already exist on the school's authorised list. |
| Password | When registering an account | Stored in a form that cannot be read back (a bcrypt hash). We cannot see your actual password, and cannot recover it — only set a new one. |
| Your child's full name | When adding a child | Shown in your dashboard and in the school admin panel. |
| Your child's nickname | When adding a child | The name announced over the public address system and shown on the TV screen. Required — the system does not accept this field empty, so that your child's full name is never announced by accident. |
| Your child's class | When adding a child | Announced together with the name so that pupils with similar names can be told apart. |
| Information | Notes |
|---|---|
| The authorised phone number list | The school uploads the phone numbers of parents permitted to register, sometimes with a short administrative note. Your number may be in the system before you register an account. |
| The class list | Not personal information. Used for the class selection menu. |
| Audio pronunciation corrections | School administrators can set a pronunciation spelling for a name the automated voice says incorrectly. It changes the sound only, not the name that is displayed. |
| Information | Notes |
|---|---|
| Pickup records | Each time you call your child: the child's name, nickname and class, your name, your phone number, the time of the call, and whether it was a normal call or a "Di Depan Pagar" (at the front gate) call. This record is copied as plain text so that it remains a school record even if the account is deleted later. |
| Audio files (MP3) | One voice recording per child, saying the nickname and class. The file name is only a number — there is no name inside the file name. |
| Web server logs | Your IP address, the time, the page requested, and the browser type. These are recorded automatically by the web server, as on any website. An IP address counts as personal information under the PDPA where it can be linked to an individual. |
| Application logs | Technical records for tracing problems. They record ID numbers only — no pupil or parent names. |
| Information | Status | Consequence if not provided |
|---|---|---|
| Your full name · phone number · password | Required | An account cannot be opened. All three are needed to identify the account holder and to protect the account. |
| Your child's full name · class | Required | The child cannot be registered, so you cannot call them through the system. |
| Your child's nickname | Required | The child cannot be registered. This field is mandatory so that you decide the name announced in public, rather than the system choosing the full name on your behalf. |
| Using this system at all | Optional | None. Use of this system is optional and is not part of your child's enrolment at the school. Other ways of collecting a pupil are subject to the procedures set by the school. |
Identity card numbers · home addresses · email addresses · dates of birth · academic records · health records · GPS location · contact lists · photographs of pupils · payment or credit card information. The system has nowhere to store any of them.
The nickname you set will be announced over the school's public address system and displayed on the TV screen that other parents in the waiting area can see. You are responsible for ensuring the name you set is appropriate to be announced publicly. The school maintains a list of prohibited words, may change an inappropriate nickname without prior notice, and may restrict your ability to change the nickname if it is misused.
Under the PDPA, personal information may only be collected for stated purposes and may not go beyond what those purposes require. This table states the purpose of each field.
| Information | Purpose |
|---|---|
| Your phone number | Account identification (username) and access control — only a number the school permits can open an account. This prevents unrelated persons from calling a pupil out. It is also the school's channel for technical support, such as a password reset request — contact is made by the school directly, not through any SMS or email service (see Section 7). |
| Your full name | Allows the school office to identify the account holder, and records who collected a pupil on a given day. |
| Password | Protects your account from being used by someone else. |
| Your child's full name | Accurate identification of the pupil by the school, particularly where two pupils have the same nickname. |
| Your child's nickname | The name that is announced and displayed. It exists so that a long name need not be said in full, and so that the pronunciation is clearer. |
| Your child's class | Announced together with the name to tell pupils apart, and to help teachers identify the pupil being called. |
| Pickup records | A school safety record — a note of who collected which pupil, and at what time. This is what can be referred to if a dispute arises over custody or the release of a pupil. |
| Audio files | Allow the announcement to be played immediately without sending anything to the internet at pickup time. |
| IP address (server logs) | Security and technical troubleshooting — detecting repeated login attempts and service disruptions. |
Information in this system is not used for marketing, is not analysed to build profiles, and is not shared with any party for commercial purposes. It is used solely to run the pickup process on the school's behalf.
Each period below has been verified against the actual system configuration as at the date of this version of the policy, not copied from a template. Figures marked ≈ are indeed estimates, and the reason is explained where they appear.
| Information | Period | What deletes it |
|---|---|---|
| The daily pickup queue | Until midnight the same day | An automated process at 00:00 every night: the records are archived as history, then the queue list is cleared completely. |
| Pickup history records | 12 months from the date of the call | The same automated process, every night. Records older than 12 months are deleted without human intervention. |
| Your account | For as long as it exists | A school administrator deletes it at your request, or during the end-of-year cleanup. There is no automatic deletion. |
| Your child's record | For as long as the child is registered | You can delete your own child through the dashboard. A school administrator can also delete a pupil, a whole class, or a group of families who have left the school. |
| Your child's audio file | Follows the child's record | Deleted at the same time as the child's record. |
| Your number on the authorised list | For as long as the school keeps it | Deleted by school administrator action. Please note: deleting your account alone does not remove your number from this list — this is deliberate, so that you can register again without having to be re-added. To remove both together, a full deletion request must be made (Section 9). |
| Password reset requests | 90 days | An automated process each night deletes every request older than 90 days, whether it has been dealt with or not. |
| Application logs | ≈ 7 days | Rotated every midnight; only the last 7 copies are kept. These logs contain ID numbers only, not names. |
| Web server logs (IP addresses) | Up to 15 days | Rotated daily; 14 older copies are kept in compressed form, then deleted automatically. |
| Backup copies | The last 7 copies (≈ 7 days) | Older copies are deleted automatically as new ones are made. |
We make daily backup copies to protect the school's data against hardware failure. When information is deleted from the live system, it still exists in the backup copies for about 7 days before those copies expire on their own.
This means we cannot say "your data is deleted immediately and completely". The accurate statement is: deleted from the live system immediately, and gone from every copy within about a week.
Backup copies are used solely for system recovery, security, and service continuity. They are not a day-to-day operational reference and are not opened in order to retrieve an individual's information.
One Malaysian school year (January–November) plus a margin. It is long enough for the school to look back at the current year's records if a dispute arises, and short enough to meet the PDPA principle that information is not kept for longer than is necessary.
Some schools may ask for a different period. If your child's school does so, the period that actually applies will be stated by that school.
12 months is the standard retention period, not an absolute limit. Certain records may need to be kept longer where they are required by law, by a court order or the direction of an authority, or because they relate to an ongoing dispute or investigation. That decision is made by the school as data controller, and only for the records concerned — not for the entire history. In practice it means the school keeps a copy of those records before they expire, or sets a different retention period; the automatic deletion itself knows nothing about disputes.
| Who | What they see | Controls in place |
|---|---|---|
| You | Your account and your own children only | Every request to the server is checked and scoped to your account, including when the page address is altered by hand — that check is made on the server, not merely hidden on the screen. It is designed so that you cannot see or manage another parent's children. |
| School administrators | All parent accounts, all pupils, the full pickup history | Administrator access requires an account with a special role. The school is responsible for deciding who within their organisation is given this access. |
| Staff in the school office | The current queue and the name being announced | This screen shows today's queue only, not the history or account information. |
| Anyone who sees the TV screen | The nickname and class of the pupil being called | This is the purpose of the system — it is a public display in the waiting area. Parents' names are not shown on the TV. |
| Anyone within earshot | The nickname and class announced | As above — a public address announcement is open by its very nature. |
| Other parents | No access to your account or your data | They see and hear only what is displayed or announced publicly, the same as anyone else in the waiting area. |
| Our technical staff | Server administration access, including the database | Access is limited to what maintenance, incident recovery, and deletion of data on the school's instructions require. We do not look at school data in day-to-day operations. |
| The server hosting provider (VPS) | Physical access to the server's disks | Sub-processor — infrastructure provider. As with any hosting provider. They have no account in the application and no access to the system's interface. |
Information in this system is never sold, rented, or traded, and is not
shared for marketing or for any commercial purpose unrelated to running this system —
neither by us nor by the school through this system.
Information is processed by the service providers and sub-processors that run the
system, and may be disclosed where the law requires it. Neither is a hidden exception to
the sentence above: the first is explained fully in Section 7, and the second in the
paragraph below.
We may disclose information where required by law, by a court order, or by a lawful request from an authority. In those circumstances we will inform the school unless the law prohibits us from doing so.
Only one third party is given pupil information to process actively — Google's speech service, in order to generate the audio recordings, and only a small amount of information at that. One other may receive your phone number when the school chooses to contact you through WhatsApp. The server hosting provider processes data as part of an infrastructure service, not as a recipient that uses the information. All three are described below.
To produce the voice recording that says your child's name, the name text is sent to the Google Cloud speech service, which returns an audio file. That file is then stored on our server.
| Item | The actual position |
|---|---|
| What is sent | The child's nickname that you set yourself, together with the class name — repeated twice. Example of the actual text: Imran 2 Zubair. Imran 2 Zubair. |
| What is NOT sent | Identity card numbers · addresses · phone numbers · parents' names · any account identifier · pickup records |
| When it is sent | Only when a recording needs to be made or remade: when a child is added, when their nickname or class is changed, when a school administrator corrects the pronunciation, and when we regenerate existing audio (for example after changing the voice or the pronunciation rules). Not every time a child is called — the daily call only plays a file already stored on our server. |
| Where processing takes place | The system specifies Google's Singapore regional endpoint, so speech requests are processed within South-East Asia rather than being routed worldwide automatically. This is set in the code, not left to each school's settings. Singapore is outside Malaysia — see the note below this table. |
| Storage by Google | Our use is subject to the Google Cloud Data Processing Addendum, the contractual agreement that governs how Google handles customer data for its paid services. We have reviewed and accepted those terms for the account used for this service. Refer to that document for the full terms. |
The server hosting this system is located in Malaysia as at the date of this policy. So your account, the pickup records, and the stored audio files are all within the country.
There is one exception only: speech generation. Specifying the Singapore endpoint confines that processing to the South-East Asia region, but it does not mean the information stays within Malaysia — your child's nickname and class name are processed outside the country at the moment the audio file is generated. We state this plainly because "processed within this region" and "stays in Malaysia" are not the same thing.
Any personal information sent to a service provider outside Malaysia, or which causes processing to take place outside Malaysia, is handled in accordance with the requirements of the applicable personal data protection law on cross-border transfers at the time that transfer takes place.
Two things limit that transfer in practice. Scope: only the nickname and the class name are sent, solely in order to generate the audio file — no parent name, phone number, or pickup record (see the table above). Contract: processing by Google is subject to the Google Cloud Data Processing Addendum, which we have reviewed and accepted.
The lawful basis for this transfer is the responsibility of the school as data controller, as with the other processing in this system (Section 2). Our role is to keep that transfer as narrow as possible and contractually protected.
If the audio file fails to generate, the school office device falls back to the speech engine built into the Chrome browser (which sounds more robotic). This runs entirely on that device — it is not a cloud service, nothing is sent to the internet, and it is not subject to Google's data processing agreement.
Only two parties act as sub-processors to us: Google Cloud (speech generation, described above) and the server hosting provider (infrastructure). We appoint only the providers genuinely needed to run the system, and take reasonable contractual and technical steps to ensure information is protected. The remainder in the table below are listed because people generally expect them to be there — and they genuinely are not.
This list may change. We may appoint or replace the service providers and sub-processors needed to run the system, subject to the applicable data protection requirements. A change involving a new category of recipient or a new type of information processed will be stated through an update to this policy — see Section 11 for how updates are communicated. The list below describes the position as at the date of this version.
| Service | Position |
|---|---|
| Server hosting provider (VPS) | Sub-processor — infrastructure provider. Hosts the server and the database. Has physical access to the disks, as with any hosting provider. Has no account in the application and no access to its interface. |
| Google Analytics / advertising pixels | None. The system loads no third-party tracking script. |
| External web fonts | None. All fonts are self-hosted — no request is made to Google Fonts or any similar service. |
| SMS / email services | None. Password resets are handled face to face by the school office, not by SMS or email. Your phone number is not sent to any messaging provider. |
| Payment processors | None in the system. Subscription payments are handled entirely outside the application. Parents make no payment through this system. |
| WhatsApp (Meta) |
The administrator panel has a button that opens WhatsApp in order to
contact a parent about a password reset request. When school staff press it,
your phone number is sent to WhatsApp as part of the link address,
together with a single opening message that is the same for every request
— a greeting asking whether you did in fact request a password reset, with nobody's
name in it — so that the conversation can be started.
This happens only when school staff press it — not automatically, and never while you are using the system. No pupil name, class or pickup record is sent. The system does not load any WhatsApp code; it simply opens the WhatsApp application on that staff member's device. |
| Other social media | None. No share buttons, no social media login, no tracking pixels. |
The absence of tracking scripts, external fonts, and third-party services means that no pupil information flows to any third party other than a single speech request to Google, and even then only when a recording needs to be made or remade. The WhatsApp button above carries your phone number only, never your child's information, and only when school staff press it. Browsing this system tells nobody outside it that you are using it.
| Protection | What it does |
|---|---|
| Passwords cannot be read | Passwords are stored as a bcrypt hash — a form that cannot be reversed. Even if the database were exposed, your actual password could not be read. We cannot see it ourselves. |
| Encrypted connections | All traffic between your phone and the server uses HTTPS with a valid SSL certificate. |
| Controlled registration | Only a phone number the school has added to the authorised list can open an account. Outsiders cannot register themselves. |
| Login attempt limits | Repeated failed login attempts from the same source are blocked temporarily, to prevent password guessing. |
| Per-account isolation | Every data query is scoped to the account making the request. There is no page or address that can be altered by hand in order to see another parent's children. |
| Per-school isolation | Each school has an entirely separate database and application process. No tables are shared. |
| Immediate revocation of access | Changing your password logs out every other device immediately. An account suspended or deleted by the school is rejected on its next request, even if that device still holds an old session. |
| Daily backup copies | Protect the school's data against hardware failure or deletion by mistake. Older copies are deleted automatically. |
Technical protection cannot take the place of looking after your account. Please:
In the event of a security incident affecting personal information, we will inform the school without undue delay and — as our own operational commitment — within 24 hours of the incident being identified as one that may involve personal information, together with information about what has been affected and the steps taken. We will also provide reasonable information and assistance to enable the school to carry out its own notification obligations.
Those 24 hours are a standard we set ourselves, not a period imposed on us by law. A data processor's obligation to notify the data controller is contractual, not a statutory period imposed directly on us. We state it here so that it can be held to, not so that it looks like a statutory requirement.
After that, notification to the Personal Data Protection Commissioner and to the affected individuals is the responsibility of the school as data controller. Whether that notification is required, and to whom, depends on the school's assessment of the nature and level of risk of the breach — not every incident triggers every notification.
For reference: under Personal Data Protection Commissioner Circular No. 2 of 2025 (section 12B of the Personal Data Protection Act 2010), as it is in force at the date of this policy, the periods that apply to a data controller are 72 hours to the Commissioner and 7 days thereafter to the affected individuals, where the breach is likely to cause significant harm. The period that actually binds the school is the one in force at the time the incident occurs.
Under the Personal Data Protection Act 2010, you have certain rights over your own and your child's personal information.
| Your right | What it means | How to exercise it |
|---|---|---|
| Right of access | To request a copy of the personal information held about you and your child | Make the request to the school |
| Right of correction | To correct information that is wrong or incomplete | Your child's information (full name, nickname, class) can be corrected by you in the dashboard. For your own name or phone number, contact the school — an administrator can correct it without deleting your account. If your ability to edit your child's information has been restricted by the school, an administrator can also correct it on your behalf. |
| Right of deletion | To request that your information be deleted when it is no longer needed | Make the request to the school. See the limits below. |
| Right to withdraw consent | To stop using this system | Inform the school. You may continue to collect your child by the school's usual method. |
| Right to complain | To lodge a complaint with the Personal Data Protection Department (JPDP) | We encourage you to contact the school and us first, but this right is unconditional. |
We will act on a request that has been confirmed by the school within 21 days of the date the request is received. We apply the same period to all types of request in this section, aligning it with the period set by Section 12 of the Personal Data Protection Act 2010 for data access requests, as it is in force at the date of this policy — so that the figure comes from the Act rather than being one we invented.
If a request is complex, takes longer, or requires additional information in order to verify your identity, we will tell you so within the same period, as permitted by the applicable law.
Pickup records note who collected which pupil, and at what time. They are a safety record belonging to the school, not to one party alone. Deleting them at one parent's request would destroy the school's evidence in the event of a dispute over custody or the release of a pupil — including a dispute involving another parent.
For that reason, pickup history records are kept for 12 months for safety purposes and are not deleted on an individual request. Deletion requests are subject to the requirements and exceptions set by the applicable law: in certain circumstances, records must be retained for purposes of safety, compliance, resolving a dispute, an investigation, or a legal obligation. Those records still expire on their own after 12 months — this is not indefinite retention. One narrow exception is explained in Section 5: records tied to a dispute, an investigation, or a legal requirement may be kept longer.
If the school deletes only your account through the ordinary function, your phone number remains on the authorised list — so that you can register again without the office having to re-add it. That is useful in the ordinary case, but it is not full deletion.
When you make a deletion request under the PDPA, state clearly that you want the phone number removed as well. The system has a specific function for that, and the school knows how to use it.
After deletion you can no longer log in or call your child through this system. You will need to collect your child by the usual method set by the school. If you wish to use the system again later, the school will need to add your number to the authorised list once more.
Some information is stored on your own device rather than on our server. This is important for you to know because the controls over it are different from the controls over our server.
| Where | What is stored | When it goes |
|---|---|---|
| Your phone — browser storage | Your login session (containing your account ID, full name and phone number), and the list of children stored temporarily for faster display | When you press the log out button, or when you change your password on another device |
| Your phone — application cache | Application pages and files, so that they open quickly | When the application version is updated, or when you clear your browser data |
| The school office device — laptop or tablet | Pupil audio files that have been played | When the application version is updated. Between updates, the audio file of a child who has already been deleted from the server may still exist in that device's cache. |
| The school TV screen | Nothing stored permanently — only a temporary display held in memory | When the page is reloaded (which happens automatically at 3:00 a.m. each day) |
"Outside our control" does not mean nobody is responsible. The school office device and the TV screen are owned by and under the control of the school: physical access to them, who is permitted to use them, the user accounts on those devices, and clearing their local storage are the school's responsibility — the same as any other office computer of theirs.
Our part is the mechanism, and it exists: the application cache on the office device is cleared automatically when we release a new version of the application, and we can release a new version when a school needs that cache cleared sooner — for example after a deletion request. School staff can also clear it themselves at any time through that device's browser settings.
One technical detail we state because it is true: apart from that application cache, the browser keeps audio files in its own temporary storage for up to 7 days, and that storage expires by time, not by application version. So the period is comparable to the backup copies — about a week, not immediate.
You stay logged in until you press the log out button — this is deliberate, so that you do not have to enter your password every time you want to call your child. The consequence: anyone holding your unlocked phone can call your child out.
If your phone is lost or stolen, change your password from another device — this logs that phone out immediately. If you cannot do so, contact the school and ask for your account to be suspended.
This system does not use tracking cookies. Login session information is kept in your browser's local storage, not in a cookie sent to other servers, and it is not used to track you across websites.
This policy may be updated when the system changes or when legal requirements change. Every version has a version number and a date, shown at the bottom of this page.
For a material change — for example a longer retention period, a new category of information, or a new third-party recipient — we will inform the school first, and the school will inform parents. For minor corrections such as clarifying wording, the version is updated without separate notice.
| Version | Date | Changes |
|---|---|---|
| 1.0 | 12 August 2026 | First version. |
For requests concerning your personal information (access, correction, deletion), contact your child's school first. The school is the data controller and holds the relationship with you.
If the school does not respond, or if you have a question about how this system handles information, contact us:
| Entity name | MFZ DIGITAL SSM Registration No.: 202603210023 (003878100-V) |
| [email protected] | |
| Phone | 017-252 2273 |
| Correspondence address | 5, Jalan 33/10, Taman Koperasi Polis, 68100 Batu Caves, Selangor |
You also have the right to lodge a complaint directly with the Personal Data Protection Department (JPDP), Ministry of Digital Malaysia.
We have not appointed a Data Protection Officer at this time. We state this plainly because listing a role that does not exist is worse than not listing it at all.
MFZ DIGITAL carries out an ongoing assessment of whether a Data Protection Officer must be appointed under section 12A of Act 709 and the circulars in force, including the obligations that apply directly to data processors. That assessment is updated as the number of schools, the number of individuals whose data we process, or the nature of the processing changes. If an appointment obligation applies to us, MFZ DIGITAL will appoint a Data Protection Officer and publish their contact details in this policy and through our official channels.
In the meantime, all data protection enquiries and compliance matters are handled directly by our management through the official channels above, and those channels are monitored.