Official Policy

Privacy Policy surg11 — Data Protection and Member Information

Surg11 respects the privacy of every member. This document transparently explains how we collect, store, use, and protect your personal information — in accordance with Malaysia's Personal Data Protection Act 2010 (PDPA).

Updated: January 2026 PDPA Compliance Bahasa Melayu

surg11 Privacy Commitment

  • Your data is not sold to third parties
  • 256-bit SSL encryption on all transactions
  • Limited data access for licensed staff
  • Right to data deletion upon member request
256-bit
SSL Encryption Active
0
Data Sold to Third Parties
24/7
Security Monitoring
PDPA
Full Malaysia Compliance
Our Privacy Commitment

How surg11 Protect Your Data

Six core principles that shape how we handle your personal information every day.

End-to-End Data Encryption

All data transmitted between your device and surg11's servers is protected by 256-bit SSL encryption. This means your personal and financial information cannot be intercepted or read by unauthorised parties during transmission.

Secure KYC Verification

Our identity verification (KYC) process uses systems that comply with international standards. Your identification documents are processed in a secure environment and are not retained longer than required by law.

Limited and Secure Data Storage

Your data is stored on servers protected by multi-layered firewalls and intrusion detection systems. Access to the member database is granted only to licensed staff with strict permission controls.

No Sale of Data to Third Parties

Surg11 does not sell, rent, or disclose members' personal information to any third party for marketing purposes without your explicit consent. Your data belongs to you — we only use it for purposes you have agreed to.

Member Data Control Rights

You have the full right to access, correct, transfer, or request deletion of your personal data at any time. Data rights requests can be submitted through surg11 customer support and will be processed within 14 working days.

Malaysia PDPA 2010 Compliance

The surg11 Privacy Policy is formulated in compliance with Malaysia's Personal Data Protection Act 2010 (PDPA). We regularly review this policy to ensure full compliance with the latest local legal requirements.

1 Privacy Policy Introduction and Scope

Surg11 is an online entertainment platform serving members in Malaysia. We take personal data protection seriously and are committed to handling your information transparently, responsibly, and securely.

This Privacy Policy applies to all personal information collected through the surg11 website, mobile app, and all our official communication channels. It covers how we collect, store, process, use, and in certain circumstances disclose your personal data.

By registering or using the surg11 platform, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any part of this policy, you should not use our services.

This policy may be updated from time to time. Any material changes will be communicated to members via email or in-platform notification at least 14 days before taking effect.

2 Types of Information We Collect

Surg11 collects various categories of information depending on how you interact with our platform. Below is a detailed explanation of the types of data we collect:

Data Category Example Information Purpose of Collection
Identity Data Full name, date of birth, identification card number, gender KYC identity verification, legal compliance
Contact Data Phone number, email address, residential address Account communications, security notifications
Financial Data Bank account number, bank name, transaction history Deposit and withdrawal processing
Usage Data Game history, betting records, active session logs Service improvement, responsible gaming
Technical Data IP address, browser type, device type, cookies Security, fraud detection, analytics

We only collect information that is strictly necessary to provide safe services and comply with relevant legal requirements. We do not collect sensitive information such as biometric data, health records, or political views.

3 How We Collect Information

Your personal information is collected through several key channels:

  • Account Registration: When you register, we collect basic information such as your name, email, phone number, and date of birth to create your account.
  • KYC Verification: To meet legal requirements and prevent fraud, we request identification documents such as a national ID or passport during the verification process.
  • Financial Transactions: Bank account or e-wallet information is collected when you make a deposit or withdrawal via FPX, DuitNow, Touch 'n Go, GrabPay, or Boost.
  • Gaming Activity: Our system automatically records your gaming activity for security, dispute resolution, and responsible gaming programme purposes.
  • Cookies and Tracking Technologies: Our website uses cookies to enhance your experience, remember your preferences, and analyse usage patterns in aggregate.
  • Communications with Support: When you contact our support team, conversations may be recorded for training and service quality improvement purposes.
surg11 has never purchased data lists or collected your personal information from third-party sources without your knowledge. All data we hold comes directly from your interactions with our platform.

4 Purpose of Personal Data Use

Surg11 uses your personal information only for legitimate and reasonable purposes, including:

  • Create and manage your member account securely
  • Process deposits and withdrawals accurately and promptly
  • Verify your identity to comply with AML (Anti-Money Laundering) legal requirements
  • Detect and prevent fraudulent activity, identity theft, and platform abuse
  • Send important notifications related to your account, transactions, and security
  • Provide effective customer support whenever needed
  • Improve the user experience based on aggregate usage pattern analysis
  • Fulfil Responsible Gaming programme obligations
  • Send promotional offers and bonus information — only if you have opted in to receive them
surg11 will not use your data to make automated decisions that have a material effect on your rights without appropriate human involvement. Any significant decisions will be reviewed by our team.

5 Data Sharing and Disclosure

Surg11 does not sell or rent your personal data to any third party. However, there are limited circumstances in which we may need to share certain information:

  • Payment Providers: Transaction information that must be shared with providers such as FPX, DuitNow, and e-wallet operators to process your payments.
  • Game Providers: Basic account information required by third-party game software providers to deliver games to you.
  • Legal Requirements: We may be required to disclose information to government authorities or regulatory bodies when mandated by law.
  • IT Service Providers: Our technical infrastructure providers who help operate the platform, subject to strict confidentiality agreements.

All third parties that receive your data from surg11 are required to uphold data protection standards equal to or higher than our own. We only share the minimum data necessary for the specific purpose.

All data sharing agreements with third parties are backed by legally binding data protection agreements (DPA). Third parties are not permitted to use your data for any purpose other than what has been agreed upon.

6 Data Storage and Retention Period

Surg11 retains your personal data for as long as necessary to fulfil the purpose of collection and to comply with legal obligations. The following are our retention period guidelines:

  • Active account data: Retained for as long as your account is active and for 5 years after account closure, in line with legal requirements.
  • Financial transaction records: Retained for a minimum of 7 years to comply with financial reporting and audit requirements.
  • Support communication logs: Retained for 2 years for reference and dispute resolution purposes.
  • Cookie and session data: Session cookies are deleted when you log out; preference cookies are stored for up to 12 months.
  • KYC verification documents: Retained for 6 years after the business relationship ends, in line with AMLA requirements.

Upon expiry of the retention period, your data will be securely deleted or anonymised. Anonymised data — which cannot be linked to any specific individual — may be retained longer for aggregate analytics purposes.

7 Your Rights as a Data Subject

Under Malaysia's Personal Data Protection Act 2010 (PDPA), you have the following rights regarding your personal data held by surg11:

  • Right to Access: You have the right to request a copy of the personal data we hold about you.
  • Right to Rectification: You have the right to request correction of any inaccurate or incomplete information.
  • Right to Erasure: In certain circumstances, you may request the deletion of your personal data.
  • Right to Restrict Processing: You may request that we limit how we process your data in certain circumstances.
  • Right to Object: You have the right to object to the processing of your data for direct marketing purposes.
  • Right to Withdraw Consent: If processing is based on your consent, you may withdraw that consent at any time.

To submit any data rights request, please contact our support team via live chat or email. We will process your request within 14 business days. In complex cases, this period may be extended up to 30 business days with prior notice to you.

Please note that some of these rights may be limited by our legal obligations. For example, we are unable to delete financial transaction records required for audit and legal compliance purposes.

8 Data Security and Protection Measures

Surg11 implements comprehensive technical and organisational security measures to protect your personal data from unauthorised access, loss, destruction, or disclosure:

  • 256-bit SSL Encryption: All data communications between your browser and our platform are protected by the highest level of encryption.
  • Two-Factor Authentication (2FA): 2FA option available for all accounts as an added layer of security during login.
  • 24/7 Monitoring: Our cybersecurity team continuously monitors the platform to detect suspicious activity or intrusion attempts.
  • Regular Security Audits: We conduct regular penetration testing and security audits performed by independent experts.
  • Internal Access Controls: Access to member data by surg11 staff is restricted based on the principle of least privilege.
  • Secure Data Backup: Your data is regularly backed up to a separate secure location to ensure service continuity.
While we implement robust security measures, no system can be guaranteed 100% secure. You are also responsible for keeping your account password safe and not sharing your login credentials with anyone.

9 Cookies and Tracking Technologies

Surg11 uses cookies and similar tracking technologies to enhance your experience on our platform. The following are the types of cookies we use:

  • Essential Cookies: Required for core platform functions such as login authentication and session security. These cookies cannot be disabled.
  • Preference Cookies: Store your preferences such as language, theme, and display settings to deliver a more personalised experience.
  • Analytics Cookies: Helps us understand how members use the platform in aggregate for continuous improvement purposes. This data is anonymised.
  • Security Cookies: Helps detect fraud attempts, suspicious logins, and unusual account activity.

You can manage your cookie settings through your web browser. However, disabling essential cookies may affect platform functionality. We do not use third-party cookies for advertising or cross-site tracking purposes.

10 Cross-Border Data Transfers

In the course of its operations, surg11 may transfer your personal data to servers located outside Malaysia. Any such data transfer is carried out with adequate safeguards in place, including:

  • Legally binding standard data transfer agreements
  • Selection of service providers that comply with recognised data protection standards
  • Security risk assessment before any data transfer is approved

Data transfer destinations are selected based on an assessment of their data protection adequacy. surg11 does not transfer data to countries without equivalent data protection without sufficient additional safeguards.

11 Contact Us Regarding Privacy

If you have any questions, concerns, or complaints regarding how surg11 handles your personal data, we welcome your feedback. Our Data Protection team is ready to assist.

You can reach us via:

  • Live Chat: Available 24 hours a day, 7 days a week via the chat button at the bottom corner of the platform
  • Support Email: [email protected] (response within 24 business hours)
  • Account Settings Section: For data rights requests such as access or correction of information
All privacy complaints will be acknowledged within 3 business days and resolved within 30 business days. If you are dissatisfied with our response, you have the right to lodge a complaint with the Department of Personal Data Protection Malaysia.
Your Account Security

Protect your account by enabling two-factor authentication and using a strong password.

Login Now
Certificates & Compliance
Malaysia PDPA 2010
SSL 256-bit Verified
Anti-Money Laundering (AML)
Third-Party Data Protection
Join surg11 Today

Play with Safe and Confident With surg11

Your personal data is fully protected at surg11. Register today and enjoy a safe, fair, and responsible online gaming experience with us.

PDPA-Protected Data SSL 256-bit Secure KYC 24/7 Support
Bahasa Melayu