Last updated:

Privacy Policy for KGT Mobile and ednd.my

This Privacy Policy explains how Kelantan Gold Trade Sdn Bhd ("KGT", "we", "us" or "our") collects, uses, discloses, protects and retains personal data when you use KGT Mobile, ednd.my and related KGT services. It applies to customers, applicants, account holders, parents or guardians using child-account services, introducers and saudagar.

1. Personal data we collect

Depending on the services you use, we may collect:

  • Account and contact information: name, email address, telephone number, account or customer reference, role, referral information and login credentials.

  • Identity and KYC information: MyKad, passport or SSM details, identity number, date of birth, address, city, postcode, country, identity-document images, company documents and a selfie submitted for verification.

  • Child-account information: parent or guardian details and a child's name, identity details, date of birth, relationship and supporting documents where those services are used.

  • Financial and transaction information: bank name and account number, payment and billing references, wallet balances, precious-metal holdings, purchases, sales, transfers, exchanges, withdrawals, delivery or collection details, fees and transaction history.

  • Support and communication information: support category, subject, message, correspondence, notification preferences and records needed to respond to a request.

  • Device, session and security information: a randomly generated mobile installation identifier, device or session name, access-token and session records, IP address, timestamps, app version, request records and security or fraud-prevention logs.

KGT Mobile may access the camera or photos you select to scan transfer QR codes or submit KYC documents. Document photos are uploaded for AI processing when you consent and select Read document & continue, before completing your KYC submission. Your documents and selfie are also uploaded when you submit KYC. Face ID is processed by Apple's operating system on your device; KGT Mobile receives only the authentication result and does not receive or store your Face ID biometric template.

2. How we use personal data

We use personal data where necessary to:

  • register, verify, administer and secure your account;

  • perform KYC, identity, eligibility, fraud-prevention and regulatory checks;

  • provide wallet, precious-metal, payment, transfer, exchange, withdrawal, delivery, child-account, introducer and saudagar services;

  • process and reconcile transactions, maintain ownership and audit records, issue receipts and respond to disputes;

  • send service, security, transaction and account communications, and promotional alerts where you have enabled them;

  • provide customer support, diagnose technical issues and improve the reliability and safety of our services; and

  • comply with applicable legal, tax, accounting, audit, anti-fraud, anti-money-laundering and regulatory obligations.

KGT Mobile does not use personal data for third-party advertising or to track you across apps and websites owned by other companies.

3. When we disclose personal data

We may disclose only the data reasonably needed to:

  • Service providers: operate hosting, secure storage, communications, email, SMS, customer support and other technology used for KGT services.

  • AI processing provider: OpenAI processes document photos for KGT AI with your explicit consent, as explained below.

  • Payment providers: create and reconcile payments. When ToyyibPay is used, transaction amount, reference, name and contact details required for the payment may be provided to ToyyibPay. Information entered directly on a payment provider's page is also governed by that provider's privacy policy.

  • KGT-authorised personnel and professional advisers: verify accounts, service transactions, investigate issues, perform audits and obtain legal, accounting or compliance advice.

  • Authorities and other parties required by law: respond to lawful requests, enforce rights, prevent fraud, protect users or satisfy regulatory obligations.

  • Corporate transactions: support a lawful merger, restructuring or transfer, subject to appropriate confidentiality and data-protection requirements.

We do not sell or rent personal data.

3A. AI document processing (KGT AI)

KGT AI uses OpenAI as an external processing provider. With your consent, KGT sends your MyKad front and back photos, passport photo page or SSM document photo to OpenAI. This includes information visible in the images, such as your name, identity or registration number, address, printed date of birth and document portrait, where present. This document-reading request does not include your separately captured KYC selfie, bank-account details, password or transaction history.

OpenAI reads the printed details and checks document type, image quality and visible consistency. KGT uses the results to prefill details for you to check and correct, support preliminary eligibility checks and identify submissions needing review. These checks do not prove document authenticity or verify that a face belongs to you. Automated and KGT administrator reviews are recorded separately; administrator approval is still required for full transaction access.

The scan screen asks for your explicit consent before sending the photos for AI processing. If you do not consent, the photos are not sent through this scan step and you cannot continue the current KYC flow. Contact KGT Support for assistance or to withdraw consent for future processing. Withdrawal cannot undo processing already completed.

Processing may take place outside Malaysia. KGT disables storage of the generated response for later retrieval from OpenAI. This does not mean zero retention: OpenAI may retain content in abuse-monitoring logs for up to 30 days by default, with longer retention for legal or safety reasons and exceptions for image inputs. OpenAI does not use API data to train its models by default, unless the API customer explicitly opts in. See OpenAI's API data controls for details. KGT's retention of submitted KYC documents, extracted details and review records is covered by section 4 below.

4. Data retention and account deletion

We retain personal data only for as long as reasonably needed for the purposes described above and to meet applicable legal, financial, audit, dispute-resolution, fraud-prevention and regulatory requirements. Retention depends on the type of record and the service or obligation involved.

You can request account deletion from Profile > Delete Account in KGT Mobile or through our web account deletion page. Once the request is successfully verified, account access is closed and active API sessions are revoked. Transaction, precious-metal ownership, payment, identity, KYC, audit and dispute records may be retained where needed to comply with law, protect users and KGT, prevent fraud, or establish and exercise legal rights. Data that is no longer required will be deleted or anonymised in accordance with applicable requirements and our retention processes.

5. Security

We use reasonable administrative, technical and organisational safeguards appropriate to the nature of the data, including encrypted network transmission, authentication, access controls and session management. Mobile access tokens are stored using platform-protected storage. No method of storage or transmission is completely risk-free, so users should protect their password, transaction PIN and device and notify KGT of suspected unauthorised access.

6. Your choices and rights

Subject to applicable law and verification of your request, you may:

  • request access to or correction of your personal data;

  • update eligible profile and bank-account information through KGT services;

  • change available communication or promotional-alert preferences;

  • withdraw consent where processing is based on consent, noting that this may affect services that require the data; and

  • request account deletion as described above.

We may need to verify your identity before fulfilling a request and may retain information where an applicable exception or legal obligation requires it.

7. Children and dependent accounts

A parent or legal guardian must have authority to provide and manage personal data for a child or dependent account. The responsible adult should use KGT's child-account process and provide accurate relationship and supporting information. Contact KGT if you believe child information was submitted without appropriate authority.

8. International processing and external services

Some service providers may process data in locations outside Malaysia. Where this occurs, we take reasonable steps to require appropriate confidentiality and data-protection safeguards, subject to applicable law. Links opened to third-party services are governed by the privacy terms of those services.

9. Changes to this policy

We may update this policy when our services, providers or legal obligations change. The updated date will be shown above. Material changes may also be communicated through KGT Mobile, ednd.my or another appropriate channel.

10. Contact us

For privacy questions or requests, use the Support section in KGT Mobile or the official support channels published through KGT services. You may also contact Kelantan Gold Trade Sdn Bhd at Tingkat 3, Bangunan PMBK, Jalan Kuala Krai, 15050 Kota Bharu, Kelantan, Malaysia.