Last updated: July 2026
Phi Software Sdn Bhd (Registration No. 202401040912) ("we," "our," or "us") operates the FeeCollec platform ("the Service"). This Privacy Policy explains how we collect, use, disclose, and protect your personal data when you use our website and services.
We are committed to protecting your privacy in compliance with the Malaysian Personal Data Protection Act 2010 (PDPA) and applicable international data protection standards.
2.1 Account Data
2.2 Customer Data (uploaded by you)
When you use the Service to send bills, you upload data about your customers, including:
Important: You are responsible for obtaining necessary consent from your customers before uploading their data to our platform.
2.3 Payer Data
When a customer completes a payment via the gateway, we receive from the gateway callback only:
Note: We do not collect, process, or store credit card numbers, bank account details, or any sensitive financial credentials. All payment data is handled directly between the payer and the client's own third-party payment gateway account. Our platform never touches or handles the funds — we only receive transaction status updates from the gateway to update the collection record.
2.4 Technical Data
2.5 Communications
We use collected data for the following purposes:
Under the PDPA, we process personal data based on the following grounds:
We do not sell, trade, or rent your personal data. We may share data only in the following circumstances:
5.1 Service Providers
5.2 Legal Requirements
5.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your data may be transferred as part of the transaction. We will notify you of any such change.
Storage Location: Data is stored on servers located in Malaysia (OVHcloud). Email notifications are sent through AWS SES.
No Payment Data Storage: We do not store credit card numbers, bank account details, or any sensitive financial credentials on our servers. Payment gateway API keys are encrypted at rest and used solely for payment status lookup. We never handle, process, or hold funds. All payment transactions occur directly between the payer and the client's own payment gateway account. Chargebacks, refunds, and disputes are handled entirely between the client, their gateway provider, and the payer.
Encryption:
Access Control: Per-tenant database isolation ensures your data is not accessible by other tenants. Access to servers is restricted to authorized personnel via SSH key authentication.
Backups: We recommend maintaining your own backups of uploaded CSV data. We do not guarantee point-in-time recovery.
Under the Malaysian Personal Data Protection Act 2010, you have the following rights:
To exercise any of these rights, contact us at [email protected]. We will respond within 21 days as required by the PDPA.
We use essential cookies for authentication and session management. We do not use tracking cookies or third-party analytics cookies. You may configure your browser to refuse cookies, but this may affect platform functionality.
The Service is intended for business use and is not directed at individuals under the age of 18. We do not knowingly collect data from minors. If you believe a minor has provided us with personal data, please contact us.
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. For material changes, we will notify you via email or platform notification.
If you have questions, concerns, or requests regarding this Privacy Policy or your data, please contact our Data Protection Officer:
Email: [email protected]
Business Address: Phi Software Sdn Bhd, Malaysia
Website: www.phisoft.my
If you are not satisfied with our response, you have the right to lodge a complaint with the Department of Personal Data Protection Malaysia (JPDP).