Privacy & Data Security

Privacy Policy Sesetoto – Member Personal Data Protection

At Sesetoto, your privacy is more than a legal obligation — it is our sincere commitment to every member. This document transparently explains how we collect, use, store, and protect your personal information at all times.

Updated: 1 January 2026
Bahasa Melayu (Malaysia)
Malaysia PDPA Compliance
Our Privacy Commitment

Six Core Principles of Personal Data Protection at Sesetoto

Sesetoto complies with Malaysia's Personal Data Protection Act 2010 (PDPA). The following are the six core principles that form the foundation of how we handle your data.

Minimum Data Collection

We only collect data that is strictly necessary to provide Sesetoto services to you. No excess data is collected. Every piece of information we request has a clear and legally valid purpose.

Military-Grade Encryption

All personal data and financial transactions are protected with 256-bit SSL encryption — the same standard used by leading banking institutions worldwide. Your data is stored on servers secured by multi-layered firewalls.

Full Control in Your Hands

As a Sesetoto member, you have the full right to access, correct, and request deletion of your personal data at any time. Requests will be processed within 14 business days.

No Sale of Data to Third Parties

Sesetoto has never and will never sell, rent, or transfer your personal data to third parties for marketing purposes without your explicit consent. Your data belongs entirely to you.

Full Transparency

We are committed to being fully transparent about our data collection practices. This Privacy Policy is written in plain, easy-to-understand language — not complex legal jargon — so you know exactly what happens with your data.

Malaysia PDPA Compliance

All of Sesetoto's data handling practices fully comply with Malaysia's Personal Data Protection Act 2010 (PDPA). We undergo periodic privacy compliance audits to ensure the highest standards are consistently maintained.

1. Introduction

Welcome to the Sesetoto Privacy Policy. This document is an agreement between you as a member and Sesetoto as the responsible data controller under Malaysia's Personal Data Protection Act 2010 (PDPA). By registering and using our platform at sesetoto.fun, you acknowledge that you have read, understood, and agreed to the terms of this Privacy Policy.

Sesetoto is an online entertainment platform offering a wide range of games and betting opportunities to Malaysian users aged 18 and above. In our daily operations, we collect certain personal information necessary to provide a safe, fair, and responsible service to each of our members.

This Privacy Policy applies to all Sesetoto service channels — including the sesetoto.fun website, Android and iOS mobile apps, and any other official communication channels. The effective date of this policy is as indicated in the hero section of this page.

Our Commitment to You

We believe that trust is the foundation of the long-term relationship between Sesetoto and its members. Your data privacy is more than a legal obligation — it is a moral responsibility we take seriously every day.


2. Personal Data We Collect

Sesetoto collects various types of personal data depending on your interactions with our platform. This data is divided into several main categories:

Identity Data

Full Name MyKad / Passport No. Date of Birth Gender Residential Address Phone Number Email Address

Financial & Transaction Data

Bank Name & Account No. Deposit Records Withdrawal Records Transaction History Digital Wallet ID

Technical & Usage Data

IP Address Browser Type Device Type Activity Logs Location Data Platform Usage Data
Important Note

Sesetoto does not store credit or debit card information directly. All card processing is handled by third-party payment providers compliant with PCI-DSS standards. We receive only a transaction reference token, not your actual card data.


3. How We Collect Personal Data

Your personal data is collected through several different methods as you interact with the Sesetoto platform:

  • Account Registration — When you register a new account at Sesetoto, you voluntarily provide basic personal information such as your name, email, phone number, and date of birth.
  • KYC Process — To comply with AML and KYC legal requirements, we collect copies of identity documents such as MyKad and proof of address during the identity verification process.
  • Financial Transactions — Every deposit and withdrawal you make on the platform leaves a transaction record, which we retain for compliance and security purposes.
  • Platform Usage — Our system automatically logs technical data such as your IP address, device type, and usage patterns while you use the platform.
  • Support Communications — Any communications you have with the Sesetoto support team, whether via live chat or email, may be recorded for training and quality control purposes.
  • Cookies and Tracking Technologies — Our platform uses cookies and similar tracking technologies to enhance the user experience and analyze usage patterns.

4. Purpose of Personal Data Use

Sesetoto uses your personal data solely for legitimate and clearly stated purposes. Below is a complete table of data usage purposes and their underlying legal bases:

Purpose of Use Data Type Legal Basis
Identity verification & KYC Personal identification, official documents Legal obligation (AML)
Processing deposits & withdrawals Financial, banking data Contract performance
Customer Support Name, email, communication records Legitimate interests
Security & fraud prevention IP address, activity logs, usage patterns Legitimate interests
Regulatory compliance All data categories Legal obligation
Platform improvement Technical, analytics data Legitimate interests
Marketing communications Email, phone number Your explicit consent

We will not use your data for any purpose other than those stated above without first obtaining your renewed consent. If you wish to withdraw consent for marketing purposes at any time, you may do so through your account settings or by contacting our support team.


5. Data Sharing with Third Parties

Sesetoto does not sell your personal data to anyone. However, in the course of operating the platform, we may need to share certain data with trusted third parties for legitimate reasons. All such data sharing is subject to strict confidentiality agreements.

Payment Service Providers

Required financial data is shared with payment providers such as FPX, Touch 'n Go, and GrabPay solely to securely process your deposit and withdrawal transactions.

KYC Verification Providers

Identity documents are shared with accredited third-party identity verification services to fulfil KYC and AML requirements as prescribed by Malaysian law.

Analytics Platform

Anonymised usage data is shared with analytics platforms to help us understand how users interact with the platform and make continuous improvements.

Relevant Authorities

Where required by law or court order, Sesetoto will disclose the necessary data to regulatory authorities or law enforcement agencies.

Our Guarantee

All third parties we work with are required to sign data processing agreements obligating them to protect your data to a standard equal to or higher than this Sesetoto Privacy Policy.


6. Data Security Measures

Protecting your personal data from unauthorised access, loss, or misuse is Sesetoto's absolute priority. We continuously invest in the latest security infrastructure to ensure your data remains safe at all times:

  • 256-bit SSL Encryption — All data transmitted between your browser or app and the sesetoto servers is protected with 256-bit SSL encryption, ensuring no third party can intercept or read your data.
  • Multi-Layer Secure Server — Your data is stored in data centers secured with firewalls, intrusion detection systems, and strict physical access controls. Only authorized personnel may access the servers.
  • Two-Factor Authentication (2FA) — We provide and encourage the use of 2FA for all member accounts to add a significant additional layer of protection against unauthorized access.
  • Round-the-Clock Monitoring — Sesetoto's cybersecurity team monitors the platform 24 hours a day, 7 days a week to detect and respond to any suspicious activity immediately.
  • Regular Security Audits — We conduct periodic independent security audits by accredited third parties to identify and address any system vulnerabilities before they can be exploited.

While we take all reasonable steps to protect your data, no system can be guaranteed 100% secure. In the event of a material data breach, we will notify affected members and the relevant authorities within the timeframe required by law.


7. Cookie Policy

Sesetoto uses cookies and similar tracking technologies to enhance your experience on our platform. Cookies are small text files stored on your device when you visit our website. They allow our platform to recognize you, remember your preferences, and provide a better and more personalized experience.

Cookie Type Purpose Can Be Disabled?
Essential Cookies Required for core platform functions such as login and secure sessions No (required)
Preference Cookies Remembers your settings and preferences such as language and time zone Yes
Analytics Cookies Helps us understand how the platform is used for improvement purposes Yes
Security Cookies Detects fraudulent activity and protects your account No (required)

You can manage and delete cookies through your browser settings. Please note, however, that disabling essential cookies may affect the functionality of the Sesetoto platform and prevent you from accessing certain features.


8. Your Rights as a Data Subject

Under Malaysia's Personal Data Protection Act 2010 (PDPA), you have several important rights regarding the personal data Sesetoto holds. We fully respect these rights:

1
Right of Access

You have the right to request and receive a copy of the personal data Sesetoto holds about you. Requests will be processed within 14 business days.

2
Right to Rectification

If any personal data we hold about you is inaccurate or outdated, you have the right to request immediate correction at no charge.

3
Right to Erasure

You may request the deletion of your personal data, subject to legal retention obligations that may prevent full deletion in certain cases.

4
Right to Object

You have the right to object to the processing of your data for direct marketing purposes at any time. The objection will be actioned immediately.

5
Right to Data Portability

You may request your data in a structured, machine-readable format for transfer to another service provider should you choose to do so.

6
Right to Withdraw Consent

If the processing of your data is based on consent, you may withdraw that consent at any time without affecting the validity of any processing carried out prior to the withdrawal.

To submit any request relating to the rights above, please contact our privacy team via the in-platform live chat or through our official email. We will respond to your request within 14 business days.


9. Data Retention Period

Sesetoto retains your personal data only for as long as it is needed for the purposes it was collected, or as required by Malaysian law. The following are our general data retention guidelines:

  • Active Account Data — Personal data for active accounts is retained for as long as your account remains active and for a period of 7 years after the account is closed, for legal compliance purposes.
  • Financial Transaction Records — Records of all financial transactions are retained for a minimum of 7 years from the transaction date, in line with the requirements of Malaysia's Anti-Money Laundering Act (AMLA).
  • KYC Documents — Identity verification documents are retained for 5 years after the business relationship with the member ends, or longer if required by the relevant authorities.
  • Support Communication Logs — Communication records with the support team are retained for 3 years for quality control and dispute resolution purposes.
  • Analytics Data — Anonymized usage data may be retained indefinitely for platform improvement purposes, as no personally identifiable information is involved.

Upon expiry of the retention period, your data will be securely deleted or anonymised using industry-standard methods. Deletion is carried out systematically and regularly in accordance with our records management schedule.


10. Child Protection

Sesetoto is an online entertainment platform exclusively for adults aged 18 and above. We take the protection of minors extremely seriously and do not accept registrations from anyone under 18 years of age under any circumstances.

All new account applicants are required to verify their age during registration and go through a rigorous KYC process. If we determine that an account was registered by someone under 18 years of age, the account will be closed immediately and all balances will be returned in accordance with established procedures.

Notice to Parents and Guardians

If you believe a minor has registered or is using the Sesetoto platform, please contact our support team immediately via the in-platform 24/7 live chat. We will investigate and take prompt action to close the account.


11. Amendments to This Privacy Policy

Sesetoto reserves the right to update or amend this Privacy Policy from time to time to reflect changes in our privacy practices, new legal requirements, or improvements to our platform. All amendments will take effect immediately upon publication on this page.

If the amendments made are material and significant — for example, changes to the types of data collected or how data is shared — we will notify you by email or in-app notification at least 14 days before the amendments take effect. This gives you sufficient time to review the changes and make an informed decision.

We encourage you to review this Privacy Policy page periodically to ensure you are always informed about how we protect your information. The date of the latest revision is always displayed at the top of this page. Continued use of the Sesetoto platform after any amendment is published will be considered your acceptance of the revised Privacy Policy.


12. Contact Us for Privacy Inquiries

If you have any questions, concerns, or complaints regarding this Privacy Policy or how Sesetoto handles your personal data, our privacy team is ready to assist you at any time.

24/7 Live Chat

The fastest way to get help. Click the chat icon on the platform to connect with our agents.

Official Email

Send your privacy enquiries to us at: [email protected]

Response Time

We aim to respond to all privacy-related enquiries within 2 business days or sooner.

If you are not satisfied with our response, you have the right to lodge a complaint with the Department of Personal Data Protection Malaysia (JPDP) or the relevant data protection authority under PDPA 2010.

FAQ

Frequently Asked Questions about the Sesetoto Privacy Policy

Answers to the most frequently asked questions by Sesetoto members regarding privacy and personal data protection.

No, absolutely not. Sesetoto has never and will never sell, rent, or transfer your personal data to any third party for marketing or commercial purposes. Your data is only shared with necessary operational partners (such as payment providers and KYC services) solely to enable us to deliver our services to you, and all of this is subject to strict confidentiality agreements.

You may submit a data access request via the 24/7 live chat on the Sesetoto platform or by emailing [email protected] with the subject line "Personal Data Access Request". Include your full name and account number to expedite the process. We will verify your identity before processing the request, and a copy of your data will be sent to you within 14 business days.

When you close your Sesetoto account, your personal data will not be deleted immediately. Under the Anti-Money Laundering Act (AMLA) and other regulatory requirements, we are obligated to retain your financial transaction records and KYC documents for a minimum of 7 years following account closure. Once this mandatory retention period expires, your data will be permanently and securely deleted from our systems.

Yes, you can opt out of receiving marketing communications from Sesetoto at any time. Click the "Unsubscribe" link at the bottom of any of our promotional emails, or log in to your account and adjust your notification settings under your Profile. You may also contact our support team to make this change. Please note that you will still receive important transactional emails related to your account.

Yes. The Sesetoto mobile app for Android and iOS applies the same level of security as our website — including 256-bit SSL encryption for all data communications, optional two-factor authentication, and round-the-clock security monitoring. We recommend downloading the app only from official sources and always updating to the latest version to benefit from the most current security protections.
Ready to Get Started?

Your Data Is Safe With Us — Register and Enjoy the Best Entertainment at Sesetoto

Thousands of Malaysian members have trusted Sesetoto as their online entertainment platform of choice. With top-tier data protection and 24/7 customer support, you can play with complete peace of mind and confidence.

PDPA Compliant

Malaysia 2010

SSL 256-bit

Full Encryption

No Data Sales

Guaranteed Privacy

24/7 Support

Bahasa Melayu

Bahasa Melayu