Privacy Policy
Last revision - 29.07.2026
- Introduction
This Policy explains how Rock Wing Capital Sdn. Bhd and its related corporations, subsidiaries, associated companies and affiliates (collectively referred to as “Rock Wing”, “we”, “our”, or “us”) collect, use, disclose, store, and process, and outlines your rights in relation to your Personal Data when you interact with us in any capacity. This Policy is issued in compliance with the Personal Data Protection Act 2010 (Act 709), as amended by the Personal Data Protection (Amendment) Act 2024 (“the Act”) and related guidelines issued by the Personal Data Protection Commissioner (the “Commissioner”). By providing your Personal Data to us, you acknowledge that you have read and understood this Policy and agree to the collection, use, disclosure and processing of your Personal Data in accordance with this Policy and applicable law. Please note that we may update this Policy from time to time to reflect changes in legal requirements, industry practices or our internal processes. Where the changes are material or affect how we process your Personal Data, we will provide additional notice (e.g., via email or prominent website notice) and, where required by law, obtain your consent before applying the changes. For more information about your rights under Malaysian data protection law, please visit www.pdp.gov.my.
- Scope & Application
This Policy applies to all individuals whose Personal Data is processed by us and/or on our behalf, in connection with our business operations, including but not limited to loan applicants and borrowers; guarantors; referees and emergency contacts provided by applicants; directors, shareholders or authorised signatories of corporate applicants (where applicable); website users; individuals who communicate or transact with us; and other third parties. It applies to Personal Data in all formats, including paper, electronic records, CCTV recordings, and audio or video recordings. This Policy does not apply to employees of the Company, whose personal data is governed by internal employee privacy policies unless otherwise stated.
- Description of Personal Data
3.1 We may collect and process the following categories of Personal Data:
- Identity Information: Name, NRIC/ Identity Card number, passport number, date of birth and gender.
- Contact Information: E-mail address, mobile phone number and residential address.
- Financial Information: Bank account details, payment and repayment records, income information and credit information obtained from licensed credit reporting agencies.
- Technical and Device Information: Information sent by or associated with the device(s) used to access our services, including device identifiers, operating system, IP address, browser type, and usage data relating to access to our services.
- Verification Information: Government-issued identification documents or other information required for our due diligence, photographs or images collected for identity verification purposes and fraud prevention purposes.
- Marketing and Communications Information: Your preferences in receiving marketing from us and third parties, your communication preferences and history of communications with us, our authorised service providers and other third parties.
- Any other personal data collected in relation to the purpose set out in Clause 4 of this Policy.
3.2 In connection with our identity verification, know-your-customer (KYC), anti-money laundering (AML) compliance process, fraud prevention, and credit assessment, we may collect and process Sensitive Personal Data within the meaning of Act, including:
- biometric data (as introduced in the Act) derived from facial verification process including data contained in your identity document, processed through our authorised third-party provider;
- information relating to criminal records;
- physical or mental health or condition of a data subject;
- and any other personal data as the Minister may determine by order published in the Gazette.
Sensitive data will only be collected and processed: (a) with your explicit consent; (b) for the purpose of verifying your identity and complying with our legal and regulatory obligations; or (c) as otherwise permitted under applicable law. Where required, your explicit consent for the processing of Sensitive Personal Data, including biometric information, will be obtained prior to the collection of sensitive personal data.
3.3 You agree to ensure that all Personal Data submitted to us is accurate, complete and up to date, and you agree to inform us of any inaccuracies or changes to such information. We may request additional documentation to verify the information provided.
- Purposes for collection of personal data
We will use your Personal Data for the following purposes including but is not limited to:
- in all matters pertaining to the contract entered or to be entered into between you and us;
- for the purposes of processing your application, request and/or queries;
- for the purposes of providing you with our services;
- for the purposes of internal control and risk management;
- to conduct analysis and evaluation of our website and services in order to assist us to improve our website and services;
- to conduct research, analysis and development activities, to analyse how you use our services, to recommend products and/or services relevant to your interests, to improve our services or products and/or to enhance your experience;
- monitoring compliance with the agreement in paragraph (a) and our rules and policies for the time being in force, your access to our website and any other applicable laws;
- complying with the compliance and disclosure requirements of any and all governmental and/or quasi-government departments, agencies, regulatory and/or statutory bodies;
- complying with any legal obligation binding on us under any law, rule, regulation, by-law, order, guideline, directive, policy and such other requirements in force and as amended from time to time;
- enforcing our rights under the agreement in paragraph (a) and our rules and policies for the time being in force, your access to our website, or any other applicable laws to defend our rights;
- for the purposes of record-keeping in the ordinary course of our business;
- for the purposes of circulating, transmitting and/or delivering to you, by any means (including e-mails, short messaging services, regular mails and other means), promotional materials (including products, services, new launches, upcoming events, promotions, advertisements, marketing and commercial materials) relating to our services;
- and to carry out due diligence or other screening activities (including, without limitation, background checks) in accordance with legal or regulatory obligations or our risk management procedures that may be required by law or that may have been put in place by us;
- disclosure of your personal data and credit information to any credit reporting agency (including but is not limited to Credit Bureau Malaysia Sdn. Bhd., CTOS Data Systems Sdn Bhd and Experian Information Services (Malaysia) Sdn Bhd) for the purposes of obtaining a personal and/or business credit report or information from the credit bureau to assess your credit risk and creditworthiness and to obtain any credit repayment information;
- for any other purpose that is required or permitted by applicable laws or that is reasonably related to the purposes stated above.
- Sources of personal data
We may obtain/collect personal data about you from the following instances including but is not limited to:
- when you register and/or use our services;
- when you submit any application forms, whether online or by way of a physical form;
- when you enter into any agreement or provide other documentation or information in respect of your interactions with us, or when you use our products and services;
- when you interact with us, such as via telephone calls (which may be recorded), letters, fax, face-to-face meetings, social media platforms and e-mails, including when you interact with our customer service agents;
- when you use our electronic services, or interact with us via our application or use our services. This includes, without limitation, through cookies which we may deploy when you interact with our application or website;
- when you grant permissions on your device to share information with our application;
- when you provide us with feedback or complaints;
- any data and information from third parties (e.g. credit reference agencies, regulatory and enforcement agencies, employers, joint account holders, guarantors, legal representatives, spouses, parents, guardians, dependents and/or companies/partnership that you hold directorships, shareholdings or partnership in);
- and publicly available sources, including government databases, sanctions lists, public registers and online sources where permitted by law.
- Disclosure of personal data
We may disclose your Personal Data to the following categories of recipients where necessary for the purposes described in this Policy:
- our related corporations, subsidiaries and affiliates;
- professional advisers including auditors, lawyers and consultants;
- financial institutions and payment service providers
- credit reporting agencies;
- service providers supporting our business operations:
- identity verification and KYC service providers;
- fraud prevention and risk assessment service providers;
- electronic signature and digital certificate providers;
- cloud infrastructure and data storage providers;
- analytics and performance measurement providers;
- and regulators, government authorities or law enforcement agencies where required by law.
All third parties processing Personal Data on our behalf are contractually required to implement appropriate security measures and to process Personal Data only in accordance with our instructions and in compliance with the Act and related guidelines issued by the Commissioner.
6.1 Key third-party service providers
In the course of providing our services, we engage the following key third-party processors who may collect or process your personal data on our behalf:
(a) Experian Information Services (Malaysia) Sdn. Bhd. – We share your personal data with Experian Information Services (Malaysia) Sdn. Bhd. ("Experian"), a credit reporting agency regulated under the Credit Reporting Agencies Act 2010, for the purposes of (i) assessing your creditworthiness prior to and during the provision of our lending services, and (ii) verifying your identity through Experian's eKYC services where applicable. For credit assessment purposes, the personal data transmitted to Experian includes your full name, identity card number, date of birth, residential address, and contact details. Experian processes this information to generate a credit report which may include your credit history, outstanding financial obligations, repayment behaviour, and other credit-related data compiled from financial institutions and permitted third-party sources. Where identity verification is conducted through Experian's MyCreditInfo portal, Experian may additionally collect and process your nationality, residential address, a photograph and/or video recording of you, a photograph of your identity document, and biometric data including your facial features, facial contours, skin texture, and geometric and spatial measurements, for the purpose of generating a biometric template and verifying your identity by matching your facial data against your identity document. Experian acts as an independent data controller in respect of the credit information and biometric data it collects and processes. For more information on how Experian processes your personal data and your rights in respect of your credit and personal information, please refer to Experian's Privacy Statement at www.experian.com.my/privacy-statement. (b) CTOS Data Systems Sdn. Bhd. – We share your personal data with CTOS Data Systems Sdn. Bhd. ("CTOS"), Malaysia's leading private credit reporting agency licensed under the Credit Reporting Agencies Act 2010, for the purpose of assessing your creditworthiness prior to and during the provision of our lending services. The personal data transmitted to CTOS for this purpose includes your full name, identity card number, date of birth, residential address, and contact details. CTOS processes this information to generate a credit report and credit score, which may include your credit history, outstanding loan obligations, repayment behaviour, litigation records, bankruptcy status, and trade references compiled from financial institutions, public records, and other permitted sources. For more information on how CTOS processes your personal data and your rights in respect of your credit information, including your right to access and dispute inaccurate records, please refer to CTOS's Privacy Policy at www.ctoscredit.com.my/privacy-statement and your Summary of Rights under the Credit Reporting Agencies Act 2010 at www.ctoscredit.com.my/summary-of-rights. (c) Jumio Corporation – We use Jumio Corporation to perform identity verification and KYC/AML compliance services. When you register for or access our services, we use Jumio to verify your identity. For this purpose, Jumio processes your government-issued identity document (such as a passport, national ID card, or driving licence), a facial image (selfie), and associated metadata. Jumio may process your Sensitive Personal Data, including biometric data derived from your facial image solely for the purpose of confirming that the identity document belongs to you. Data collected through Jumio is processed in accordance with Jumio's Privacy Notice, available at https://www.jumio.com/privacy-center/privacy-notices/online-services-notice/. We have entered into a Data Processing Agreement with Jumio to ensure your data is handled in accordance with applicable privacy laws. (d) SEON Technologies Ltd. – We use SEON to assess fraud risk during account registration and transaction processing. For this purpose, SEON processes your email address, phone number, IP address, and device information. Specifically, SEON provides us with information on how many times these identifiers have been checked in their system and whether they have been flagged as associated with fraudulent activity. Data is processed in accordance with SEON's Privacy Notice, available at https://seon.io/legal-and-security/privacy/. (e) RiskSeal, Inc. – We use RiskSeal to assess credit risk and detect fraudulent applications. For this purpose, RiskSeal analyses publicly available digital signals linked to your email address, phone number, IP address, name, and where applicable, profile photo, across 200+ online platforms. RiskSeal does not access private communications or confidential information. Data is processed in accordance with RiskSeal's privacy policy, available at https://riskseal.io/privacy-policy. (f) MSC Trustgate.com Sdn. Bhd. – We use the services of MSC Trustgate.com Sdn. Bhd. ("Trustgate"), a licensed Certification Authority under the Digital Signature Act 1997 (Act 562), to facilitate the execution of your loan agreement by means of a legally binding digital signature. For the purpose of issuing a digital certificate in your name, Trustgate will process your full name, identity card number, email address, and phone number. No biometric data is collected in connection with this service. Trustgate is required by law to maintain records of issued digital certificates for a minimum period of ten (10) years from the date of the last entry, in accordance with Regulation 22 of the Digital Signature Regulations 1998 (P.U.(A) 359/98). During this period, Trustgate retains the personal data associated with your digital certificate independently of Adacash. For more information on how Trustgate processes your personal data, please refer to Trustgate's Privacy Notice at https://www.msctrustgate.com/privacy-notice-view. (g) We may engage additional or replacement service providers from time to time and this Policy shall apply to such providers.
- Security of personal data
We use strict procedures and security features to prevent unauthorized access wherever possible. We implement reasonable administrative, technical, and physical safeguards (access controls, encryption, network security, backups, logging, vendor due diligence, staff training, and least privilege access) to protect Personal Data against unauthorised or accidental loss, access, disclosure, alteration, or destruction. Personal data provided to us via our website or via any Applications, online credit card transactions are protected during transit using encryption. When personal data is stored by the Company, we use computer systems with limited access. Data stored in cloud services is in encrypted form including when we utilize third-party storage. The level of security of personal data which kept in a non-electronic environment are also treated with strict procedures and means. However, there can inevitably be no guarantee of absolute security.
- Retention of personal data
We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, or as required or permitted by applicable law, regulation, legitimate business purposes or contractual obligation. Retention periods may vary depending on the type of data and statutory requirements.
As a general guide:
• Personal data collected in connection with an active account or ongoing services will be retained for the duration of your relationship with us. • We retain personal data for at least seven (7) years after the end of the business relationship in accordance with applicable legal and regulatory requirements (including tax, financial reporting, accounting, and anti-money laundering regulations), after which it will be securely deleted or anonymised. • Personal data collected solely for marketing purposes will be retained until you withdraw your consent or opt out.
When Personal Data is no longer required for the purposes for which it was collected, we will take reasonable steps to securely dispose of it through permanent deletion, destruction, or anonymization, following our internal policies.
- Personal Data Breach Notification
In the event of a personal data breach that is likely to adversely affect your personal data or privacy, we will promptly assess the nature and scope of any suspected data breach and notify you without undue delay and, where feasible, within 72 hours of becoming aware of the breach, in accordance with the Act, where required by law. Notification will be provided to you individually by one or more of the following means: email to your registered email address, SMS to your registered mobile number, or prominent in-application notice. Such notification will include, to the extent known at the time: (a) a description of the nature of the breach and the personal data affected; (b) the likely consequences of the breach; (c) the measures taken or proposed to address the breach and mitigate its effects; and (d) the contact details of our Data Protection Officer should you wish to seek further information. We will also notify the Personal Data Protection Department of Malaysia (PDPD) of any breach as required under applicable law.
- Use of cookies
A cookie is a small file stored on your device that helps us deliver and improve our services. We use the following types of cookies: Functional cookies — essential for the operation of our services. These include an authentication token stored for up to 1 hour after login, and a temporary OTP session identifier linked to your phone number, retained for up to 2 minutes during the login or account recovery process. These cookies cannot be disabled without affecting your ability to use our services. Analytics cookies — We use tools such as Google Tag Manager, Google Analytics and other third-party services to collect aggregated and statistical information about how visitors use our website (such as pages visited, session duration and device type) to help us improve our services. These cookies are governed by Google's Privacy Policy. You may configure your browser to block or delete cookies at any time. Blocking functional cookies will prevent you from signing in or using core features of our services. By continuing to use our website, you consent to the use of cookies as described in this Policy.
- Cross-Border Transfer & Safeguards
11.1 In conducting our business, we may disclose or transfer your Personal Data to our service providers, business partners, professional advisers, affiliates or related corporations, which may be located within or outside Malaysia, for the purposes described in this Policy. Where Personal Data is transferred outside Malaysia, such transfer will only be undertaken in compliance with Section 129 of the the Act and applicable regulations. We will take reasonable precautions and exercise due diligence to ensure that the recipient provides a level of protection comparable to that required under Malaysian law, including through appropriate contractual safeguards and security measures. 11.2 Nothing in this Policy limits any rights or obligations under applicable laws that permit us to collect, use, disclose or process Personal Data without consent, including where such processing is necessary to comply with legal obligations, to perform a contract, to protect our legal rights, or as otherwise permitted under applicable law. 11.3 While we take reasonable technical and organisational measures to protect Personal Data, no system can be guaranteed to be completely secure. As such, we cannot ensure or warrant the absolute security of information transmitted to us electronically. Nevertheless, we will continue to review and enhance our security practices in accordance with applicable legal and regulatory requirements.
- Marketing and promotional purposes
Upon subscribing to our services, where you have consented to receive marketing communications from us, we may send you promotional materials, updates, or information relating to our products and services via email, telephone, SMS, or other communication channels. You may opt out of receiving such communications at any time by clicking the unsubscribe link in the relevant communication or by contacting us using the details set out in this Policy.
- Data Subject's Obligations
It is necessary for us to collect and to retain your Personal Data in order to provide our services. You are responsible for ensuring that the Personal Data you provide to us is accurate, complete and up to date. Where you choose not to provide required Personal Data, we may be unable to provide certain services or continue our business relationship with you.
- The Rights of Data Subjects
We respect and uphold your statutory rights under the Act. You have the following rights, subject to conditions under the Act:
(a) Right of Access
You have the right to request access to personal data that we hold about you. Upon receipt of a valid request, we will provide you with a description of the personal data we hold, the purposes for which it is being processed, and, where applicable, the categories of third parties to whom it has been disclosed. You can request information on your most recent loan through your personal account via our website or mobile application (where available). Requests for access to other information can be submitted through the "Contact Us" form available on our website or mobile application, or in writing to our Data Protection Officer at the contact details set out in this Policy.
- A prescribed administrative fee may apply where permitted by law.
- We will respond within a reasonable period of receiving a valid request or inform you if additional time is required.
(b) Right to Correction
You have the right to request for correction and/or update of your personal data that is inaccurate, incomplete or outdated. Requests for access to other information can be submitted through the "Contact Us" form available on our website or mobile application, or in writing to our Data Protection Officer at the contact details set out in this Policy.
(c) Right to Withdraw Consent and to Prevent or Restrict Processing
You may withdraw your consent to the processing of your Personal Data at any time by providing written notice to us. Upon receipt of such withdrawal, we will cease processing your Personal Data unless the processing is required or authorised under applicable law, necessary for the performance of a contract, or required for the establishment, exercise or defence of legal claims, subject to any legal or contractual restrictions.
(d) Right to data portability
In accordance with the Act, you have the right to request that we transmit your personal data directly to another data controller, where technically feasible. This right applies to personal data which you have provided to us and which we process on the basis of your consent or in connection with a contract between us.
(e) Right to File a Complaint
If you believe that we have not handled your personal data in accordance with the Act, you have the right to lodge a complaint with us in the first instance. If you remain dissatisfied following our response, you may escalate your complaint directly to the Personal Data Protection Department of Malaysia (PDPD) at www.pdp.gov.my.
Should you have any questions regarding this Policy, wish to access or correct your personal data, or wish to make a complaint, please contact our Data Protection Officer:
Contact Number: 0360430999
E-mail: dpo@adacash.my
We will respond to your request within 21 days of receipt. Where the request is complex or we receive multiple requests simultaneously, we may extend this period by a further 21 days, in which case we will notify you of the extension and the reasons for it.
We may decline your request where permitted under the Act, including where disclosure would reveal personal data of a third party, where the data is subject to legal privilege, or where disclosure would be prejudicial to an investigation or legal proceedings. Where we decline your request, we will inform you of the reasons in writing.
Address: D-18-3A, Menara Suezcap 1, Gateway No. 2, Jalan Kerinchi, Gerbang Kerinchi Lestari, 59200 Kuala Lumpur.
If you are dissatisfied with our response, you may lodge a complaint with the Personal Data Protection Department of Malaysia (PDPD): Website: www.pdp.gov.my Tel: +603-8911 5880
- Changes to Privacy Policy
We reserve the right to amend this Policy from time to time. Where changes are minor or administrative in nature, we will update this Policy on our website without separate notice. Where changes are material, we will endeavour to provide reasonable prior notice by way of a prominent notice on our website and/or mobile application before the changes take effect. Your continued use of our services after such notice period shall constitute your acceptance of the revised Policy. We encourage you to review this Policy periodically.
- Acknowledgment and consent
By accessing our website or mobile application, using our services, submitting your Personal Data, or by clicking ‘I Agree’ (where applicable), you are deemed to have read and understood the Privacy Policy of Rock Wing Capital Sdn. Bhd. and to have consented to Rock Wing and its affiliates collecting, storing, using, disclosing and processing your Personal Data for the purposes described in the Policy, and cross-border transfers where necessary and as described in the Policy.
- Contact / Data Protection Officer (DPO)
Data Protection Officer
Contact Number: 0360430999
E-mail: dpo@adacash.my
Address: D-18-3A, Menara Suezcap 1, Gateway No. 2, Jalan Kerinchi, Gerbang Kerinchi Lestari, 59200 Kuala Lumpur.