Legal
Privacy Policy
How REMMU collects, uses, stores, processes and discloses personal data.
Effective: September 2026
This Privacy Policy explains how REMMU collects, uses, stores, processes and discloses personal data when you use the REMMU website, application and related services.
REMMU is a cloud-based management platform designed for education centres, tuition centres, academies, studios, sports clubs and other service providers.
REMMU is operated by:
Smart Web Solutions
Email: info@remmu.com
For the purposes of this Privacy Policy, “REMMU”, “we”, “us” and “our” refer to Smart Web Solutions and the REMMU platform.
1. Scope of This Privacy Policy
This Privacy Policy applies to personal data processed through:
- the REMMU website;
- the REMMU web application and supported applications;
- accounts created on REMMU;
- services provided to merchants using REMMU;
- bookings, registrations, subscriptions and payments made through REMMU; and
- communications with REMMU.
REMMU is used by independent education centres, academies, studios, clubs and other organisations (“Merchants”) to manage their operations and provide services to their customers, students, members, parents, guardians and other users.
Where a Merchant collects or manages personal data through REMMU for its own business purposes, the Merchant may also have its own privacy notice or privacy obligations relating to that data.
2. Personal Data We Process
The personal data processed through REMMU depends on how you use the platform and the information provided by you or the relevant Merchant. This may include:
Account and Contact Information
This may include:
- name;
- email address;
- telephone number;
- account and login information;
- organisation or Merchant name;
- role or account type; and
- other information provided when creating or managing an account.
Student, Member and Participant Information
Merchants may use REMMU to record and manage information about students, members, athletes or other participants, including:
- name;
- date of birth or age, where required;
- gender, where provided and relevant;
- contact information;
- parent or guardian information;
- enrolment information;
- classes, programmes or packages;
- attendance records;
- bookings;
- membership information; and
- other information reasonably required by the Merchant to manage its services.
Parent and Guardian Information
Where applicable, REMMU may process:
- parent or guardian name;
- contact number;
- email address;
- relationship to a student or member;
- linked family or member accounts; and
- billing and payment-related information.
Instructor, Coach and Staff Information
Merchants may use REMMU to manage instructors, teachers, coaches and other personnel. This may include:
- name;
- contact information;
- account details;
- roles;
- class or programme assignments;
- schedules and availability; and
- other information required to administer their work through the platform.
Billing and Transaction Information
When payments or billing functions are used, REMMU may process information such as:
- invoices and billing records;
- transaction amounts;
- payment status;
- transaction references;
- payment dates;
- refunds;
- credits or wallet transactions; and
- related payment information.
REMMU does not intentionally store full payment card details where those details are collected and processed directly by an authorised payment gateway or financial institution.
Communications and Content
Where REMMU’s communication or content features are used, we may process information submitted through those features, including messages, enquiries, announcements, files, media or other content uploaded to the platform.
Technical and Usage Information
When REMMU is accessed, certain technical information may be processed automatically, such as:
- IP address;
- browser and device information;
- operating system;
- login information;
- timestamps;
- application activity;
- error and diagnostic information;
- system logs; and
- information required for security and operation of the platform.
3. How We Collect Personal Data
Personal data may be collected:
- directly from you when you register or use REMMU;
- when you communicate with us;
- when you make a payment or transaction;
- when you make a booking or enrolment;
- from a Merchant with whom you have a relationship;
- from an authorised parent, guardian or representative;
- automatically when you access or use the platform; or
- from service providers involved in providing REMMU’s services.
For example, an education centre may enter student and parent information into REMMU as part of managing enrolments, classes, attendance and billing.
4. How We Use Personal Data
We may process personal data where reasonably necessary to operate REMMU and provide the services requested by our Merchants and users. This may include:
- creating and managing user accounts;
- providing access to REMMU;
- managing students, members and participants;
- managing classes, courses, programmes and memberships;
- managing instructors, teachers, coaches and staff;
- managing enrolments and attendance;
- managing schedules, availability and bookings;
- generating invoices and managing fees;
- processing and recording payments;
- managing refunds, credits and payment records;
- facilitating communications between Merchants and their users;
- providing customer support;
- sending transactional and service-related notifications;
- maintaining and improving the platform;
- monitoring system performance and reliability;
- protecting accounts and preventing unauthorised access, fraud or misuse;
- maintaining records and backups;
- troubleshooting technical issues;
- complying with legal and regulatory requirements; and
- establishing, exercising or defending legal rights where necessary.
We will not use personal data for purposes materially incompatible with the purposes for which it was collected unless permitted or required by applicable law.
5. Merchants Using REMMU
REMMU is a multi-tenant platform used by independent Merchants.
A Merchant may collect and process personal data through REMMU in connection with the services it provides to its own students, members, customers, parents, guardians, instructors or staff.
The Merchant is responsible for determining what information it requires for its services and for ensuring that it has the appropriate authority to collect and use that information.
Smart Web Solutions provides the REMMU technology and processes such information as necessary to provide, maintain, secure and support the platform and related services.
If you have a question about information collected by a particular Merchant, such as your child’s enrolment information, class attendance or membership records, you should normally contact that Merchant first.
6. Payment Processing and Payment Partners
REMMU enables Merchants and users to make and receive payments through supported payment services.
To facilitate these transactions, we may engage authorised third-party payment gateways, payment processors, banks, financial institutions and other payment service providers (“Payment Partners”).
Where necessary, relevant personal and transaction information may be disclosed to a Payment Partner for purposes including:
- processing payments;
- payment verification and authorisation;
- transaction settlement;
- transaction reconciliation;
- processing refunds;
- preventing or detecting fraudulent transactions;
- resolving payment disputes; and
- complying with legal, regulatory or financial requirements.
Information shared may include, where applicable, your name, contact information, transaction amount, transaction reference, payment status and other information reasonably required to process or manage the transaction.
Payment Partners may process certain payment information directly under their own privacy and security practices.
We seek to limit information shared with Payment Partners to information reasonably necessary for the relevant payment service.
7. Disclosure of Personal Data
We do not sell personal data.
Personal data may be disclosed where reasonably necessary to:
- the Merchant with whom the individual has an account or service relationship;
- authorised users within the relevant Merchant organisation;
- Payment Partners;
- cloud hosting and infrastructure providers;
- database, storage and backup providers;
- email, messaging and communications providers;
- technical and IT service providers;
- analytics, monitoring and security providers;
- professional advisers such as accountants, auditors or legal advisers; and
- government agencies, regulators, law enforcement authorities or other parties where disclosure is required or permitted by law.
Service providers are given access only to information reasonably required for the services they perform and are expected to handle personal data appropriately.
8. Personal Data Relating to Children
Because REMMU is used by education centres, academies and sports organisations, the platform may process personal data relating to children.
Such information may be provided or managed by a parent, guardian, Merchant or other authorised person.
Merchants using REMMU are responsible for obtaining any consent or authority required for the collection and processing of children’s personal data in connection with the services they provide.
We recognise that children’s personal data requires particular care and take reasonable measures to protect information stored within the REMMU platform.
REMMU does not knowingly use children’s personal data for independent advertising or sell children’s personal data.
9. Data Security
We take reasonable and appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, disclosure, alteration or destruction.
These measures may include, where appropriate:
- access controls and authentication;
- role-based permissions;
- secure communications;
- database and infrastructure security controls;
- system monitoring and logging;
- backups and recovery procedures;
- restrictions on administrative access;
- software and security updates; and
- other technical and organisational safeguards appropriate to the nature of the data processed.
No online service or electronic storage system can guarantee absolute security. However, we continually take reasonable measures appropriate to the nature of REMMU and the information processed through the platform.
Malaysia’s amended PDPA expressly imposes security obligations on both data controllers and data processors.
10. Data Breach
If we become aware of a personal data breach, we will investigate and take appropriate steps to contain and address the incident.
Where notification is required under applicable Malaysian data protection law, we will notify the relevant authorities and/or affected individuals in accordance with the applicable requirements.
Malaysia’s Personal Data Protection Commissioner currently provides specific guidance for data-breach notification.
11. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, including providing REMMU services, maintaining appropriate business and transaction records, resolving disputes and complying with legal, accounting and regulatory obligations.
Retention periods may vary depending on the type of information and the purpose for which it is processed.
Information managed by a Merchant may also be retained according to the Merchant’s requirements and applicable legal obligations.
When personal data is no longer reasonably required, we may delete, anonymise or otherwise securely dispose of it, subject to applicable legal and operational requirements.
12. Cross-Border Processing and Storage
Some service providers used to operate REMMU may process or store information using infrastructure located outside Malaysia.
Where personal data is transferred outside Malaysia, we will take reasonable steps to ensure that the transfer is handled in accordance with applicable Malaysian data protection requirements and that appropriate safeguards are used where required.
Malaysia’s Personal Data Protection Commissioner has published dedicated guidance concerning cross-border transfers of personal data.
13. Your Personal Data Rights
Subject to applicable Malaysian law and any permitted limitations or exceptions, individuals may have rights relating to their personal data, including rights to:
- request access to personal data held about them;
- request correction of inaccurate, incomplete, misleading or outdated personal data;
- withdraw consent where processing relies on consent, subject to applicable legal or contractual consequences;
- request information regarding the processing of their personal data;
- prevent certain processing in circumstances provided by law; and
- exercise other rights available under applicable Malaysian personal data protection laws.
Requests may be submitted to info@remmu.com. We may request reasonable information to verify the identity and authority of the person making the request before releasing or modifying personal data. Where the information is managed by a Merchant, the request may need to be handled by, or in cooperation with, that Merchant.
14. Cookies and Similar Technologies
The REMMU website and application may use cookies and similar technologies where necessary for:
- authentication and login;
- maintaining sessions;
- security;
- remembering preferences;
- application functionality;
- performance monitoring; and
- analytics.
Where required, additional information regarding cookies and tracking technologies may be provided through our Cookie Policy or consent management system.
15. Communications
We may use contact information to send communications necessary to operate REMMU, including account notifications, payment confirmations, security notices, service announcements and other transactional communications.
Merchants may also use REMMU to communicate with their own students, members, parents, guardians or customers.
Marketing communications, where used, will be handled in accordance with applicable requirements, and recipients may opt out of such communications where applicable.
16. Legal and Regulatory Compliance
REMMU processes personal data in accordance with applicable Malaysian laws, including the Personal Data Protection Act 2010 (Act 709), as amended from time to time, and applicable regulations, standards, guidelines and requirements issued under it.
The PDPA regulates processing of personal data in connection with commercial transactions in Malaysia.
Personal data may also be retained or disclosed where reasonably necessary to comply with applicable laws, lawful requests from authorities, court orders or regulatory obligations.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to REMMU, our services, technology, legal requirements or data-processing practices.
The latest version will be published on the REMMU website with the updated effective date.
Where changes materially affect how personal data is processed, we may provide additional notice where appropriate or required by law.
18. Contact Us
If you have questions about this Privacy Policy, how REMMU handles personal data, or wish to make a request relating to your personal data, please contact:
Smart Web Solutions
REMMU
70, Lorong Nenas 2A
Taman Nenas
09000 Kulim, Kedah
Malaysia
Email: info@remmu.com