Case information is collected to administer reports and platform services. Reports and uploaded evidence are not automatically published. Access is restricted according to purpose, role and authorisation.
1. Who operates KitaJagaKita
KitaJagaKita is a business protection and case-management platform operated by the Malaysian Sub-Contractors Association (MSCA). References to “KitaJagaKita”, “MSCA”, “we”, “us” or “our” in this Notice refer to the organisation responsible for the relevant platform processing activity.
2. Scope of this Notice
This Notice applies when you visit the website, create or use an account, submit a concern, upload evidence, check a case, respond to a concern, request assistance, communicate with us or otherwise use KitaJagaKita services.
Additional notices or consent statements may be shown for a specific form, service or processing activity. Where applicable, those statements should be read together with this Notice.
3. Personal data we may collect
Depending on how you use the platform, we may collect:
- name, contact number, email address, correspondence address and preferred contact method;
- account credentials, authentication information and account activity;
- identity or identification information where reasonably and lawfully required;
- business, organisation, company, SSM, CIDB or membership information;
- employment, professional, contractual, tenancy or business-relationship information;
- concern details, case references, timelines, amounts, requested outcomes, responses and case status information;
- agreements, invoices, receipts, payment records, notices, correspondence, messages, screenshots, photographs and other supporting records;
- communications with us, including support requests and records of service interactions;
- device, browser, IP address, login, security, cookie and website usage information.
4. Sensitive and higher-risk information
A concern or supporting document may contain information that is sensitive, confidential or capable of affecting another person’s rights or reputation. This may include identification documents, financial records, alleged misconduct, health-related information or information concerning possible offences.
Only provide information that is relevant to the stated concern and that you are lawfully permitted to provide. Do not upload passwords, banking credentials, full payment-card details, unnecessary medical information or unrelated identification documents.
Where possible, conceal unrelated account numbers, identification numbers, signatures, personal addresses and information about uninvolved individuals before uploading a document.
5. Why we process personal data
We may process personal data for purposes including:
- creating, authenticating and administering user accounts;
- receiving, recording and administratively reviewing concern submissions;
- assessing completeness, relevance and the appropriate case pathway;
- requesting clarification, verification or additional supporting information;
- communicating with reporters, named parties, respondents, authorised representatives and relevant support personnel;
- allowing an appropriate response, correction or update process;
- managing case references, status updates, resolution and closure;
- preventing misuse, fraud, harassment, unauthorised access and other security threats;
- maintaining operational, audit, dispute and compliance records;
- responding to lawful requests and meeting applicable legal or regulatory obligations;
- improving platform reliability, accessibility, security and service delivery.
6. Sources of personal data
Personal data may be obtained:
- directly from you;
- from an authorised representative acting for you;
- from a reporter, respondent or another person involved in a documented matter;
- from submitted documents, records and communications;
- from account, website, support and security interactions;
- from lawful public or official sources where relevant and permitted.
Information obtained from another person is not automatically treated as accurate, complete or verified.
7. Information about another person or organisation
When you provide information about another individual, you must have a genuine and lawful reason for doing so. You should provide only information that is relevant, accurate to the best of your knowledge and obtained through lawful means.
Do not submit fabricated allegations, revenge complaints, harassment, defamatory content, unlawfully obtained records or personal data unrelated to the concern.
Where appropriate, the named party may be contacted and allowed to respond, correct information or provide supporting records. A reporter may also be asked to clarify or update the submission.
8. Who may access or receive personal data
Personal data may be accessed or disclosed on a need-to-know basis to:
- authorised MSCA or KitaJagaKita personnel responsible for administration, support, review, governance or security;
- contracted technology, hosting, communications, authentication, document-management or professional service providers;
- the named party, respondent or authorised representative where disclosure is necessary for a fair response process;
- lawyers, auditors, insurers or other professional advisers where reasonably necessary;
- law-enforcement agencies, regulators, courts or other competent authorities where required or permitted by law;
- another organisation involved in a restructuring or transfer of the platform, subject to appropriate confidentiality and legal controls.
We seek to limit disclosure to information reasonably necessary for the relevant purpose. A person’s full submission or all supporting documents will not necessarily be disclosed to every recipient.
9. Technology and service providers
KitaJagaKita may use third-party services for website hosting, account authentication, databases, customer relationship management, case administration, document storage, email, messaging, analytics, security, backups and technical support.
These providers may process personal data only to the extent needed to provide their services, support the platform or comply with applicable obligations. Provider access should be governed by appropriate contractual, confidentiality and security controls.
10. Case records, reports and publication
A submitted concern, allegation or supporting document is not automatically published, verified or treated as proof of wrongdoing. Case records are initially handled within the relevant administrative workflow.
Any future disclosure, searchable record, summary or publication must be subject to the applicable review process, purpose, authorisation, accuracy considerations, response rights and legal requirements.
A case status reflects an administrative stage only. It does not represent a court decision, legal judgment, financial guarantee or endorsement of any person or organisation.
11. Security measures
We seek to apply reasonable administrative, organisational and technical safeguards appropriate to the nature of the personal data and platform risk. Measures may include access controls, authentication, role-based permissions, logging, backups, confidentiality requirements, system maintenance and security monitoring.
No website, transmission method or storage environment can be guaranteed to be completely secure. Users are responsible for protecting their login credentials, devices and case-reference information and for notifying us if unauthorised access is suspected.
Additional operational information is available through the Security Notice.
12. Personal data breaches and security incidents
Where a personal data breach or security incident is identified, we may investigate, contain and assess the incident, take corrective action and make notifications where required under applicable Malaysian personal-data-protection requirements.
Users who believe their account, submitted documents or case information may have been accessed without authorisation should contact us promptly using the privacy contact details below.
13. How long we retain personal data
Personal data is retained for as long as reasonably necessary for the purpose for which it was collected and for related operational, security, audit, dispute, legal, regulatory and recordkeeping requirements.
Retention periods may differ according to the record type, case status, legal risk, sensitivity, limitation period, required audit trail and whether a deletion or correction request can lawfully be fulfilled. Information may be securely deleted, anonymised or restricted when it is no longer required.
14. Your privacy requests and rights
Subject to applicable law, identity verification and relevant exceptions, you may contact us to:
Ask whether we process your personal data and request access to information that can lawfully be provided.
Ask us to correct personal data that is inaccurate, incomplete, misleading or outdated.
Ask questions about how personal data has been obtained, used, disclosed, secured or retained.
Where processing relies on consent, request withdrawal, subject to legal, contractual and operational consequences.
Ask us to consider restricting or deleting information where permitted and where no overriding lawful need requires retention.
Where appropriate, submit a correction, response, supporting record or resolution update concerning a case.
We may require sufficient information to verify your identity, authority and relationship to the relevant account or case before processing a request. Some information may be withheld or retained where disclosure or deletion would affect another person’s rights, compromise security, prejudice an investigation or conflict with an applicable legal obligation.
15. Cookies and similar technologies
The website may use cookies or similar technologies for essential functionality, authentication, session management, security, preferences, performance measurement and analytics.
Browser or device settings may allow you to block or delete some cookies. Disabling essential cookies may prevent account login, secure forms or other website functions from operating correctly.
16. Processing or storage outside Malaysia
Some technology or service providers may process, support or store personal data outside Malaysia. Where cross-border processing occurs, we seek to consider the purpose, destination, provider, contractual terms, security measures and applicable Malaysian requirements.
17. Children and minors
KitaJagaKita is designed primarily for adults, businesses and organisations. A person under 18 should not independently submit sensitive case information or identification documents without the involvement of a parent, legal guardian or authorised adult where appropriate.
18. Changes to this Privacy Notice
We may update this Notice when platform services, processing practices, technology, providers or applicable requirements change. The current version will be published on this page with its effective date.
Material changes may also be communicated through the website, account, email or another appropriate channel.
19. Contacting us about privacy
Privacy requests should identify the requester, the relevant account or case where applicable, the information concerned and the action requested. Do not send passwords or unnecessary identification documents by ordinary email.
Malaysian Sub-Contractors Association (MSCA)
KitaJagaKita Privacy Contact
6A Office Suites, Scott Sentral Service Suites,
28, Jalan Scott, Brickfields,
50470 Kuala Lumpur, Malaysia
Email:
support@kitajagakita.my
Case Support:
+60 17-623 3423