1. Introduction
GigHala Tech Sdn Bhd ("we", "us", "our") is committed to protecting your personal data in accordance with the Personal Data Protection Act 2010 (PDPA) and its amendments. This Privacy Policy explains how we collect, use, disclose, and protect your personal data when you use the GigHala mobile app ("App") as a freelancer, client, or visitor.
We process personal data only for lawful purposes related to providing gig matching, payment facilitation, and app services.
Data Protection Officer (DPO):
Email: dpo@gighala.my
Contact: privacy@gighala.my
2. Personal Data We Collect
We collect the following types of personal data:
- Basic Information: Full name, phone number, email, profile photo, date of birth.
- Identity Verification: NRIC/Passport details (staged: last 4 digits initially; full for payouts > RM500), selfie for verification.
- Financial Data: Bank account/e-wallet details (e.g., Touch 'n Go), transaction history.
- Gig-Related Data: Skills, video pitches, location (for matching), earnings records, ratings/reviews.
- Device/Usage Data: IP address, device ID, app usage logs.
Sensitive personal data (e.g., religious preferences for halal matching) is collected only with your explicit consent.
3. Purposes of Processing
We process your personal data to:
- Facilitate gig matching, applications, and communications.
- Process payments and payouts (via licensed gateways like iPay88/SenangPay).
- Verify identity and prevent fraud (KYC/AML compliance).
- Provide earnings summaries and tax reports (aligned with LHDN and Gig Workers Bill 2025).
- Improve app features and send notifications (with consent).
- Comply with legal obligations (e.g., SOCSO contributions, dispute resolution).
4. Consent and Withdrawal
By registering or using the App, you consent to this processing. You may withdraw consent at any time via app settings or by emailing us—this may limit app functionality (e.g., no payouts without financial data).
5. Disclosure to Third Parties
We may share data with:
- Payment gateways and banks for transactions.
- Service providers (e.g., cloud storage, analytics—bound by PDPA).
- Authorities (e.g., LHDN, PDPC, Gig Workers Tribunal) as required by law.
No sale of data to marketers without explicit opt-in.
6. Data Security and Breach Notification
We use encryption (256-bit for NRIC/financial data) and secure servers. In case of a breach likely to cause significant harm, we will notify you and the Personal Data Protection Commissioner (PDPC) as per 2025 guidelines.
7. Your Rights
Under PDPA, you have the right to:
- Access and correct your data.
- Request data portability (export in structured format).
- Limit processing (e.g., opt-out of marketing).
- Delete your account and data (subject to legal retention).
Submit requests to privacy@gighala.my—we respond within 30 days.
8. Data Retention
We retain data only as needed (e.g., 7 years for financial records per tax laws) or until account deletion.
9. Changes to This Policy
We may update this Policy—significant changes notified via app/email.
Last Updated: December 2025