Privacy Policy

Privacy Policy m2cuci — Protection Personal Data Member

Your privacy is more than a formality. We clearly explain how your personal data is collected, used, stored and protected in compliance with Malaysia's Personal Data Protection Act 2010 (PDPA).

Last Updated: 1 January 2026
256-bit SSL
PDPA Compliance
No Data Sales
Member Access Rights
1

Introduction

M2cuci operates as an online entertainment platform offering slot games, live casino and sports betting for adult users in Malaysia. We understand that your trust in us depends not only on the security of your funds, but also on how we handle the personal information you entrust to us.

This Privacy Policy is written to explain clearly — not in hard-to-read legal language — how m2cuci collects, processes, stores, and protects your personal data. It has been drafted in compliance with the provisions of the Personal Data Protection Act 2010 (PDPA) Malaysia and global information security industry best practices.

By registering and using the m2cuci platform, you agree to the terms of this Privacy Policy. If you disagree with any part of this policy, please discontinue use of the platform and contact us to close your account. We do not pressure anyone to stay — we would rather you understand and agree wholeheartedly.

Our commitment: m2cuci has never sold, rented or traded members' personal data to any third party for marketing or commercial purposes, and never will. Your data belongs to you.
2

Data We Collect

M2cuci only collects data that is genuinely required for clear and legitimate purposes. We do not collect excessive or irrelevant data beyond what is necessary to operate the platform. The following are the categories of data we process:

Data Categories Example Information Primary Purpose
Identity Information Full name, date of birth, national ID / passport number Identity verification (KYC), fraud prevention
Contact Information Email address, mobile phone number Account communications, transaction notifications
Financial Information Bank account number, bank name, e-wallet details Processing deposits and withdrawals
Usage Data Game logs, betting history, transaction records Account management, legal compliance
Technical Data IP address, device type, web browser, session data Platform security, fraud detection
Communication Data Support chat logs, emails, complaint tickets Complaint resolution, service improvement

Data is collected through three main channels: (1) information you provide directly during registration and platform use; (2) data automatically generated as you interact with our platform; and (3) information from authorized third parties such as payment providers for transaction verification purposes.

Note on KYC: Identity verification documents uploaded for KYC purposes are stored in an encrypted, access-restricted environment. These documents are used solely for identity verification and anti-money laundering (AML) compliance, and for no other purpose.
3

How We Use Your Data

Every piece of data we collect has a clear purpose. m2cuci uses your personal data for the following purposes on valid legal grounds under PDPA 2010:

  • Service provision: To manage your account, process deposits and withdrawals, and ensure a smooth and secure gaming experience on the m2cuci platform.
  • Identity verification: To fulfil KYC requirements and ensure all members are verified individuals, preventing the use of false identities or fraud.
  • Security and fraud prevention: To identify suspicious activity, unauthorised access attempts or abnormal wagering patterns that may indicate improper use.
  • Legal compliance: To meet reporting obligations under applicable laws, including anti-money laundering (AML) requirements and reporting obligations to relevant authorities.
  • Service communications: To send transaction notifications, account updates, security alerts and responses to your enquiries or complaints.
  • Platform improvements: To analyse usage patterns in aggregate (not individually) in order to improve platform performance, interface and overall experience.
  • Relevant promotions: To inform you about bonuses and offers that may be relevant to you — only if you have consented to receive them. You may withdraw this consent at any time.

M2cuci does not make automated decisions that significantly affect you based solely on data processing without any human involvement. Every important decision, such as account closure or withdrawal rejection, involves a review by our team.

4

Data Sharing

M2cuci does not share, sell or disclose your personal data to third parties except in limited circumstances and on valid legal grounds as outlined below:

  • Payment providers: Required financial information is shared with authorised payment providers such as local banks and e-wallet operators (Touch 'n Go, Boost) solely for the purpose of processing your deposit and withdrawal transactions.
  • Game software providers: Minimum required game data is shared with licensed game software providers to ensure game integrity and the resolution of technical disputes.
  • Technical service providers: Third-party companies supporting our technical infrastructure — such as cloud computing services, security analytics and customer support — may have limited access to data required for their tasks. All such third parties are bound by strict confidentiality agreements.
  • Legal authorities: m2cuci will disclose personal data to relevant authorities when required by law, court order or official directive from Malaysian authorities.
Our guarantee: All third parties working with m2cuci are required to meet data protection standards equal to or higher than our own. We conduct regular due diligence reviews on all data processing partners.
5

Data Security

Protecting your personal data is m2cuci's top priority. We continuously invest in security infrastructure and industry best practices to ensure your data is always safeguarded against both internal and external threats.

The technical and organisational security measures we implement include:

  • Encryption of data in transit: All communications between your device and m2cuci's servers are protected with TLS 1.3 and 256-bit SSL encryption — the same standard used by leading financial institutions worldwide.
  • Encryption of data at rest: Sensitive data stored in our databases, including financial information and KYC documents, is encrypted using AES-256 encryption algorithms.
  • Role-based access control: Only staff with a legitimate business need are permitted to access member personal data. All access is logged and audited on a regular basis.
  • Continuous security monitoring: Our monitoring system operates 24 hours a day to detect any anomalies or suspicious access attempts in real time.
  • Two-factor authentication (2FA): Administrative access to m2cuci's internal systems is protected by multi-factor authentication to prevent unauthorized access even if a password is compromised.
  • Regular penetration testing: m2cuci conducts regular security testing by independent cybersecurity experts to identify and remediate system vulnerabilities before they can be exploited.

While we take all reasonable measures to protect your data, no system is entirely 100% secure against all threats. Should any data security breach affect you, m2cuci will notify you within the timeframe required by applicable law.

6

Cookies & Tracking

M2cuci uses cookies and similar tracking technologies to enhance your experience on our platform. Cookies are small text files stored on your device when you visit our website. They help us recognise you on subsequent visits and tailor your experience to your preferences.

Types of cookies we use:

  • Essential cookies: Required for basic platform operations such as maintaining your login session and ensuring security. These cookies cannot be disabled without affecting core platform functionality.
  • Performance cookies: Helps us understand how users interact with our platform — which pages are visited most, and where users encounter issues — so we can keep improving your experience.
  • Functional cookies: Allows the platform to remember your preferences such as language, display theme, and other personal settings for a more comfortable experience.

You can manage your cookie settings through your web browser at any time. Please note that disabling certain cookies may affect the functionality of some parts of the m2cuci platform.

Cookie notice: m2cuci does not use cookies to track your activity across other websites or to sell your behavioural data to advertisers. Our tracking is limited solely to activity within the m2cuci platform.
7

Your Rights

Under Malaysia's Personal Data Protection Act 2010 (PDPA), you have the following rights regarding your personal data held by m2cuci. We are committed to making it easy for you to exercise these rights without unnecessary obstacles:

8

Data Retention

M2cuci retains your personal data for as long as your account is active and for the required period after account closure in accordance with applicable legal obligations. In general, our data retention policy is as follows:

  • Active account data: Retained for the full duration of your active account and continuously updated in line with your activity.
  • Financial transaction data: Deposit, withdrawal and financial activity records are retained for 7 years after the transaction date or account closure, in accordance with Malaysia's financial legislation and AML compliance requirements.
  • KYC Documents: Retained for the duration of the active account period plus 5 years after account closure in accordance with anti-money laundering compliance requirements.
  • Support communication logs: Chat records and support tickets are retained for 2 years to assist in resolving any disputes that may arise subsequently.
  • Technical data and security logs: Retained for 12 months for fraud detection and security forensics purposes.

Once the designated retention period expires, your data will be securely deleted using methods that ensure it cannot be recovered. We conduct periodic data retention reviews to ensure we do not hold data longer than necessary.

9

Third-Party Links

The m2cuci platform may contain references or information relating to the payment providers and services we use. Please note that this Privacy Policy applies solely to the m2cuci platform and does not cover the privacy practices of any third parties, who maintain their own privacy policies.

M2cuci is not responsible for the privacy practices or content of any third-party services. We encourage you to read the privacy policy of each third-party service you use before providing them with any personal information.

Caution: If you receive a message, email, or call claiming to be from m2cuci and asking for your personal information or password, do not provide any details. The m2cuci team will never ask for your password through any communication channel.
10

Contact Us

If you have any questions, concerns, or complaints regarding this Privacy Policy or how we manage your personal data, m2cuci's Data Protection Officer (DPO) team is ready to assist you.

You can reach us via:

  • Email: [email protected] (response within 2 business days)
  • Live Chat: Available 24/7 directly on the m2cuci platform

For official requests regarding your personal data rights — such as access, correction, or deletion — please use the email channel with the subject line "Personal Data Rights Request" to ensure your request is handled by the right team within the designated timeframe.

M2cuci is committed to responding to all privacy-related enquiries within 14 working days from the date of receipt. For more complex cases, we will keep you informed of progress and the expected resolution timeline.

Policy Updates: m2cuci reserves the right to update this Privacy Policy from time to time to reflect changes in operations, legislation or industry best practices. All amendments will be published on this page with a clear update date. Continued use of the m2cuci platform after any amendment takes effect constitutes your acceptance of the updated terms.

Full Control Over Your Personal Data

M2cuci recognises and facilitates every right granted to you under the Personal Data Protection Act 2010.

Right of Access

You have the right to request a copy of the personal data we hold about you. We will provide this information in a clear, readable format within 21 days of your request.

Right to Rectification

If the personal data we hold about you is inaccurate or outdated, you have the right to request a correction. We will update our records promptly upon verification.

Right to Erasure

You may request deletion of your personal data under certain conditions. Please note that some data must be retained to fulfil legal obligations.

Right to Restrict Processing

You may object to or request restriction of your data processing in certain circumstances, particularly where processing is carried out for direct marketing purposes.

Right to Data Portability

You have the right to receive your personal data in a structured, machine-readable format for transfer to another service provider where applicable.

Withdraw Consent

Where data processing is based on your consent, you may withdraw that consent at any time without affecting the validity of any processing carried out prior to withdrawal.

How m2cuci Protects Your Privacy

Six layers of protection working simultaneously to keep your personal data secure at all times.

End-to-End Encryption

Every bit of data transmitted between your device and m2cuci's servers is encrypted with TLS 1.3 and 256-bit SSL. Third parties cannot intercept or read your communications even if they manage to access them.

Strict Access Control

The "need-to-know" principle applies at every level — only staff who require data access for their specific tasks are permitted. All access is logged and audited automatically at all times.

PDPA 2010 Compliance

M2cuci operates in full compliance with Malaysia's Personal Data Protection Act 2010. Our internal policies and procedures are reviewed periodically by legal advisors to ensure ongoing compliance.

No Data Sales

Your personal data is never sold, rented, or traded to advertisers or any third party for commercial purposes. This is not just our policy — it is a core business commitment of m2cuci.

24/7 Monitoring

Our security monitoring system operates around the clock to detect threats and anomalies in real time. Any suspicious activity is flagged and immediately investigated by our security team.

Rapid Incident Response

In the event of any security incident, m2cuci has a structured incident response plan to minimise impact, notify affected members and report to the relevant authorities within the timeframe required by law.

Trusted Platform

Join the m2cuci Members Who Are Play Responsibly

Your privacy is protected. Your data is secure. Focus on the game — let m2cuci handle your information security with full accountability.

Our Privacy Commitment
Data encrypted with 256-bit SSL
Full PDPA 2010 compliance
No sale of data to third parties
Member data access & deletion rights
24/7 security monitoring
Secure & encrypted KYC
Bahasa Melayu