Official Privacy Policy

Privacy Policy apo388 — Your Personal Data Protection

Apo388 is committed to protecting every member's privacy. This document transparently explains how we collect, use, store, and protect your personal data in accordance with the Malaysia Personal Data Protection Act 2010.

Updated: 1 January 2026  |  Bahasa Malaysia
SSL 256-bit Encryption
PDPA Full Compliance
0 Third-Party Data Sales
24/7 Security Monitoring

Six Pillars Privacy Protection apo388

Privacy is more than a policy on paper — it is a daily practice we uphold to ensure your data remains safe and protected at all times.

256-Bit SSL Encryption

Every transaction and data transfer between your device and apo388 servers is protected by 256-bit SSL encryption — the same standard used by major Malaysian banks to safeguard their customers' financial information.

Secure Data Storage

Your personal data is stored on servers protected by multi-layered firewalls with strict access controls. Only authorised personnel with a legitimate job requirement are permitted to access such data — and every access is automatically logged.

No Data Sales

Apo388 has never and will never sell, rent, or trade members' personal data to any third party for marketing or commercial purposes. Your data belongs to you — not to us as a business asset.

PDPA 2010 Compliance

All data handling practices at apo388 fully comply with the Malaysia Personal Data Protection Act 2010. We conduct regular internal reviews to ensure ongoing compliance with applicable data protection laws.

Breach Notification

In the event of any security incident involving member data, we are committed to notifying affected members within 72 hours and taking immediate action to contain any potential damage.

Member Data Control

You have the full right to access, correct, transfer, or request deletion of your personal data at any time. Your request will be processed within 14 business days at no additional charge.

1. Introduction & Scope of This Policy

This Privacy Policy ("Policy") is published by apo388 ("we", "Platform") and applies to all users who access or use our services through apo388.pro and all associated channels.

We take your privacy very seriously. Your trust is the foundation of our relationship, and we understand that your personal information is sensitive and valuable. This policy has been developed to give you a clear and honest overview of how we handle your personal data.

By using the apo388 platform, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any part of this Policy, please discontinue use of our platform and contact us to close your account.

Note: This Policy should be read alongside the apo388 Terms and Conditions. In the event of any conflict between the two documents regarding data privacy, this Privacy Policy shall prevail.

2. Personal Data We Collect

Apo388 collects your personal data through several channels — directly from you during registration, automatically while you use the platform, and in limited cases, from trusted third-party sources for identity verification purposes.

Data you provide directly:

  • Full name as it appears on your official identity document
  • Date of birth for age verification
  • Malaysian email address and mobile phone number
  • Current residential address
  • Bank account details or eWallet payment method information
  • Copy of identity document (MyKad or Passport) for KYC verification
  • The username and password you create yourself

Data collected automatically:

  • IP address and general geographic location information
  • Device type, operating system and web browser version
  • Login session data including time, date, and duration
  • Gaming activity history and financial transaction records
  • Cookie data and device identifiers for account security
  • Interaction data with platform features such as games played and bonuses used

Guarantee: apo388 only collects data that is strictly necessary to provide our services and fulfil legal obligations. We do not collect excessive data or sensitive information unrelated to the platform's services.

3. Purpose of Data Collection & Use

Every piece of data we collect has a clear and legitimate purpose. apo388 uses your information for the following purposes:

  • Account management: To create, verify, and securely maintain your member account.
  • Transaction processing: To process deposits, withdrawals, and all financial transactions accurately and promptly.
  • KYC verification: To fulfil legal requirements related to identity verification and anti-money laundering.
  • Customer support: To handle member inquiries, complaints, and assistance requests efficiently.
  • Platform security: To detect and prevent fraud, multi-account usage, and suspicious activity.
  • Legal compliance: To fulfil our obligations under applicable Malaysian laws.
  • Service improvement: To analyse usage patterns and continuously improve the overall user experience.
  • Marketing communications: To send relevant offers and promotions — only if you have given your consent to receive them.

Apo388 will not use your data for any purpose other than those stated above without obtaining your prior consent.

4. Data Sharing with Third Parties

Apo388 does not sell, rent, or disclose your personal data to third parties for marketing purposes. However, in certain limited and defined situations, we may share your information with the following parties:

  • Payment processing providers: Partner banks, DuitNow providers, and eWallet providers used to securely process your financial transactions.
  • KYC service providers: Accredited third-party identity verification companies that validate the documents you submit.
  • IT service providers: Companies managing our platform's technical infrastructure, bound by strict confidentiality agreements.
  • Legal authority: If required by a court order or a valid request from the relevant authorities, we will disclose the necessary data.
  • Analytics providers: Anonymised data that cannot identify individuals may be shared for platform analytics and service improvement purposes.

All third parties that receive apo388 member data are bound by strict data protection agreements and are only permitted to use that data for the specified purposes.

Notice: If you receive any communication claiming to be from apo388 that requests your personal information or password via an external link, please disregard it and report it to our support team immediately.

5. Cookies & Tracking Technologies

Apo388 uses cookies and similar tracking technologies to enhance your experience on the platform. Cookies are small files stored on your device that allow the platform to remember your preferences and keep your login session secure.

Types of cookies we use:

  • Essential Cookies: Required for core platform functions such as secure login, session verification, and account security. These cookies cannot be disabled.
  • Performance Cookies: Collects anonymous information about how you use the platform to help us identify technical issues and improve the user experience.
  • Functionality Cookies: Stores your preferences such as interface language, display settings and your favourite game selections.
  • Analytics Cookies: Helps us understand platform usage patterns in aggregate for development and service improvement purposes.

You can manage your cookie settings through your web browser at any time. Please note that disabling essential cookies may affect platform functionality or prevent you from logging in securely.

6. Data Security Measures

Protecting your personal data is apo388's highest priority. We implement comprehensive technical and organisational security measures to prevent unauthorised access, loss, or misuse of your data:

  • 256-bit SSL encryption for all data in transit between your device and our servers
  • Personal data stored in our database is encrypted using the latest industry standards
  • 24/7 security monitoring by a dedicated cybersecurity team
  • Two-factor authentication (2FA) is available for all member accounts as an added layer of protection
  • Multi-layered firewall and automated intrusion detection system
  • Regular security audits and penetration testing by independent security experts
  • Mandatory data security training for all staff who handle member data
  • A strict access control policy ensuring only authorised personnel can access sensitive data

While we take all reasonable measures to protect your data, no security system is entirely foolproof. We encourage you to also help keep your account secure by using a strong password and never sharing your login credentials with anyone.

7. Data Retention Period

Apo388 retains your personal data only for as long as necessary to fulfil the purposes stated in this policy or as required by applicable law. The following is a general guide to our data retention periods:

  • Active account data: Retained for the duration your account is active and for 7 years after account closure for legal compliance purposes.
  • Financial transaction records: Retained for a minimum of 7 years in accordance with Malaysian accounting and tax legal requirements.
  • KYC Documents: Retained for 5 years from the date of verification or account closure, whichever is later.
  • Security logs: Retained for 2 years for security investigation purposes if required.
  • Support communication data: Retained for 3 years from the date of last interaction.

Upon expiry of the retention period, your data will be securely deleted or fully anonymised in accordance with our established data disposal procedures.

8. Your Rights Regarding Personal Data

As a member of apo388 and an individual whose personal data we handle, you have the following rights under the Malaysia Personal Data Protection Act 2010:

Right of Access

You have the right to request a copy of all personal data we hold about you. Requests will be processed within 14 business days.

Right to Rectification

If your data is inaccurate or outdated, you have the right to request immediate correction through your account settings or customer support.

Right to Erasure

You may request the deletion of your data under certain circumstances, subject to applicable legal retention obligations.

Right to Object

You have the right to object to the processing of your data for direct marketing purposes, and we will stop immediately upon request.

Right to Data Portability

You have the right to receive your personal data in a machine-readable format for transfer to another service provider.

Right to Restriction of Processing

In certain circumstances, you may request that we restrict how your data is processed while a dispute or request is being resolved.

To exercise any of the above rights, please contact our privacy team via in-platform support or our official email. We will verify your identity before processing your request to ensure the security of your data.

9. Policy Relating to Children

Apo388 is a platform intended solely for individuals aged 18 and above. We do not knowingly collect or process personal data of underage individuals.

If we discover that personal data of an underage individual has been collected without our knowledge, we will take immediate action to delete that data and close the account in question. If you believe your child has registered an account on our platform, please contact us immediately so we can take the appropriate steps.

10. Amendments to the Privacy Policy

Apo388 reserves the right to update or amend this Privacy Policy at any time to reflect changes in our practices, new legal requirements, or service improvements. The "Updated" date at the top of this policy indicates when the latest amendment was made.

For significant amendments that materially affect your privacy rights, we will provide clear notice via your registered email or an in-platform notification at least 14 days before the changes take effect. Continued use of the platform after an amendment takes effect constitutes your acceptance of the updated policy.

11. Contact Us Regarding Privacy

If you have any questions, concerns, or complaints regarding how apo388 handles your personal data, our Data Protection Officer (DPO) team is ready to assist you.

You can reach us via:

  • Live support: Via the live chat feature within the platform — available 24/7
  • Privacy email: [email protected]
  • Response time: Privacy inquiries are typically answered within 3 business days

If you are not satisfied with our response, you also have the right to lodge a complaint with the Malaysia Department of Personal Data Protection or any other relevant authority.

Our commitment: apo388 values your trust. We are committed to remaining honest, transparent, and accountable in all matters relating to your personal data. Your privacy is a responsibility we never take lightly.

Summary Data Handling apo388

A quick overview of data types, purposes of use, and retention periods on the apo388 platform.

Data Type Primary Purpose Retention Duration Status
Name & Identity Information Account verification & KYC 7 years after account closure Encrypted
Email Address & Phone Number Communications & account security Throughout the active account period Encrypted
Payment Information Deposit & withdrawal processing 7 years (legal requirement) Encrypted
KYC Documents (MyKad/Passport) Identity verification & compliance 5 years after verification Restricted Access
Transaction History Financial records & support 7 years (Malaysia law) Retained
Game Logs & Activity Security & platform improvements 2 years Retained
Cookie & Session Data Login security & functionality Until logout / session expiry Secure
Device & IP Information Fraud detection & security 2 years Restricted Access

Your Data is Safe with apo388

Join over 500,000 Malaysian players who have trusted apo388 as a safe, fair, and responsible online gaming platform.

256-bit SSL encryption PDPA 2010 Compliant No data sales 24/7 privacy support
Bahasa Melayu