Friday, 14 August 2026Malaysia EditionSign in
Ledger & Signal

Tech and finance for Malaysia — financial literacy without the product pitch, and technology coverage that says whether it matters.

Privacy Notice

How Ledger & Signal handles your personal data, under the Personal Data Protection Act 2010 (Malaysia) as amended in 2024.

Last updated: 11 August 2026

Who we are

Ledger & Signal is the data controller for the personal data described here. Questions, requests and complaints go to our Data Protection Officer at [email protected].

What we collect

We collect only what the service needs to function.

If you subscribe to the newsletter

We use your address for the newsletter and nothing else. We do not sell it, rent it, or pass it to any advertiser. Every newsletter carries a one-click unsubscribe link that needs no account and no reply, and we keep a record that you unsubscribed so that a later import cannot add you back.

If you buy a ticket

We do not collect or store card numbers, CVV codes, or bank login credentials. Payment is made by DuitNow transfer directly to our bank, or through a licensed payment service provider. We never see your banking credentials.

If you create an account

If you just read the site

Nothing that identifies you. We do not use advertising trackers, and we do not sell or share reader data. Server logs record requests for security and debugging; IP addresses in those logs are truncated before storage, and email addresses are masked.

Why we use it

We do not use your data for automated decision-making or profiling, and we do not send marketing email unless you explicitly ask for it.

Who we disclose it to

We share personal data only with processors that make the service work:

We may also disclose data where required by law, a court order, or a lawful request from a regulator. We do not sell personal data to anyone, ever.

Transfers outside Malaysia

Some of our processors operate outside Malaysia. Where that happens we rely on contractual safeguards with the processor and transfer only what the processor needs. If you want to know which processors are involved and where they are located, ask our DPO and we will tell you.

How long we keep it

Your rights

Under the PDPA you may:

Write to [email protected]. We will respond within 21 days.

A note on erasure

When you ask us to erase your data, we anonymise your account rather than deleting the row outright. Your name, email and contact details are removed. What remains is the financial record of any transaction, stripped of anything identifying you.

We do this because accounting records must remain intact and internally consistent to satisfy tax law, and because our financial ledger is append-only by design — an entry, once written, is never edited or deleted. Erasure removes you from the record; it does not rewrite history.

Security

Traffic is encrypted in transit. Data is encrypted at rest. Passwords are hashed with Argon2id. Session tokens and API keys are stored only as hashes, so a database leak does not hand over working credentials. Access to production data is role-based, and every privileged action is written to an append-only audit log.

If something goes wrong

If a breach affecting your personal data occurs, we notify the Personal Data Protection Commissioner within 72 hours of becoming aware of it, as the PDPA requires. If the breach is likely to cause you significant harm we will also notify you directly, within 7 days.

Changes

If we change this notice we will update the date at the top. Where a change materially affects how we handle your data, we will tell affected users directly rather than relying on you to re-read this page.

Complaints

Raise it with our DPO first at [email protected]. If you are not satisfied with our response, you may complain to the Personal Data Protection Department (Jabatan Perlindungan Data Peribadi), Malaysia.