Last updated: 19 August 2026
This Privacy Policy explains how your personal data is collected, used, disclosed, stored and protected when you use the Biller mobile application (the "App") on Android and iOS, and the services offered through it. The App lets you buy digitally supplied prepaid mobile airtime and data top-ups for supported Malaysian telcos and submit bill-payment orders for supported billers. There are no physical goods and no shipping.
"Biller" is the trading name of Kira Labs Sdn Bhd for this App.
This Policy is issued under the Personal Data Protection Act 2010 (Act 709), as amended by the Personal Data Protection (Amendment) Act 2024 ("PDPA"), and forms part of the written notice required by section 7 of the PDPA. Please read it before you use the App or provide any personal data.
A Bahasa Malaysia version of this Policy is available at https://biller.my/legal/privacy-bm/. The English and Bahasa Malaysia versions are intended to have the same meaning. If you identify any inconsistency, please contact our privacy contact below.
The data controller responsible for your personal data is:
In this Policy, "Biller", "we", "us" and "our" refer to Kira Labs Sdn Bhd. "You" and "your" refer to the individual whose personal data we process, whether you use the App as a guest, a registered distributor or a registered dealer.
Kira Labs remains responsible for its obligations under the PDPA. You may use the dedicated privacy business contact below to ask about this Policy or how we handle your personal data, make a complaint, or exercise your rights:
The personal data we collect depends on how you use the App. We collect only what we need for the purposes set out in Section 4.
Whether you use the App as a guest, a signed-in member, a registered distributor or a registered dealer, we collect:
When you buy as a guest, you do not create an account and you do not hold any stored balance. In addition to the data in Section 3.1, for each purchase we collect:
If you are a vetted business reseller with a Biller account, then in addition to the data in Section 3.1 we collect, through the App:
When you register as a dealer, we collect, through the App, the KYC document images you upload for verification, namely your SSM business-registration document and your identity card (IC). Distributors are onboarded by us directly and provide their identity document and signed agreement during that onboarding. We collect KYC as document images only; we do not perform facial recognition, liveness checks or biometric matching on them (see Section 3.4).
For registered resellers, we record Points funding, allocations and use as account-ledger data so that we can operate reseller accounts, fulfil purchases and maintain transaction records. The commercial terms governing Points are set out in the separate Distributor/Dealer Agreement. This Policy does not determine their regulatory characterisation.
Biller does not collect biometric data and does not use facial recognition, liveness checks or fingerprint matching for onboarding or any other flow.
One category of sensitive personal data may be incidentally contained in the IC/MyKad image collected for reseller identity and KYC verification: religion. We do not extract or use religion as a separate data field. We process the document only for identity/KYC verification, account security, fraud prevention and applicable record-keeping. Where we rely on consent under section 40, we obtain explicit, separately presented consent and retain a record of it. Before introducing other sensitive or biometric processing, we will identify the applicable section 40 condition, update this Policy before collection, and obtain explicit consent where consent is the applicable condition.
You can buy every product as a guest, without an account. If you choose to sign in and hold a free consumer account, then in addition to the data in Section 3.1 we collect:
The commercial terms governing Coins are set out in Section 8.4 of our Terms and Conditions. This Policy does not determine their regulatory characterisation.
We process your personal data for the following purposes, each of which is directly related to operating Biller, is necessary for that purpose, and is adequate but not excessive:
We process ordinary personal data with your consent or, where applicable, because processing is necessary to perform or enter into a contract with you, comply with a legal obligation, protect vital interests, administer justice, or exercise a function conferred by written law, as permitted by section 6(2) of the PDPA. Contract performance covers order fulfilment and reseller account administration; legal-obligation processing covers applicable tax and record-keeping duties. Where we rely on consent, we obtain it in a recordable form, present it distinctly where combined with other matters, and keep evidence of it. We document the applicable condition for each purpose.
You may decline to provide personal data, but some data is obligatory to provide the service (see Section 9). Where we rely on your consent, you may withdraw it (see Section 11), although withdrawal will not affect processing already carried out and may mean we can no longer provide the relevant service.
We obtain your personal data from the following sources:
We disclose your personal data only for the purposes in Section 4, or a directly related purpose, and only to the following classes of third parties:
We do not sell your personal data. We do not disclose your personal data to any party outside the classes above without your consent, except where the PDPA permits or requires it.
Where we engage data processors, we bind them by written agreement to protect your personal data, to process it only on our instructions, and to comply with the Security Principle. Data processors are themselves directly responsible for the security of personal data under the PDPA.
You can limit how we process your personal data by:
If you provide another person's data, you must first have that person's consent or other lawful authority and give them access to this Policy. Do not upload unrelated personal data; redact it where possible. We remain responsible for establishing a condition under section 6 of the PDPA and may request evidence of your authority.
Some personal data is obligatory: without it we cannot provide the service. In particular:
If required data is not provided, the relevant service cannot proceed. Fields expressly marked optional are voluntary. Transaction, security and audit records are generated when you use the service and cannot be opted out of while using it.
We keep personal data only for as long as it remains necessary for a lawful purpose and take reasonable steps to destroy or irreversibly anonymise it when it is no longer required. In practice:
Deleting an account or asking us to delete data does not necessarily result in immediate deletion of every record. We delete or irreversibly anonymise personal data when it is no longer required for a lawful purpose, while retaining only data that remains necessary for a specified legal, tax, fraud-prevention, security or dispute-resolution purpose.
Under the PDPA you have the following rights, which you can exercise by contacting our privacy contact (Section 2):
To help us locate your records and act on your request, please give us enough detail to identify the relevant data. If you used the App as a guest, you have no account with us, so please quote the order/transaction reference and the recipient and payment details of the transaction concerned; we may ask for further information to verify that the request genuinely relates to you. We will respond to your request within the time and in the manner required by law. We may need to verify your identity before acting on a request, and in limited cases the law allows us to decline or charge a prescribed fee.
Members and registered resellers may request account deletion in the App. Guests have no account and may contact our privacy contact about their transaction data. We will assess each request under the PDPA and this retention section; account closure does not override justified retention.
The App is a mobile application and does not use website browser cookies. It uses limited software components and services that process data on our behalf for:
We do not use third-party analytics, advertising or crash-reporting components in the App. The components described above process the device and anti-fraud signals described in Section 3 and do not access your contacts or files beyond what is needed for those functions.
The App and its services are intended for adults and are not directed at children. Consistent with our Terms and Conditions, we do not knowingly provide the Products to, or knowingly collect personal data from, anyone under 18. If you believe a child has provided us with personal data, please contact our privacy contact and we will take appropriate steps to delete it.
Nothing in this Policy limits or excludes the rights and guarantees you have as a consumer under the Consumer Protection Act 1999, which apply regardless of anything stated here. Our service commitments, including any resolution target for failed, incorrect or undelivered transactions, are in addition to, and do not replace, those statutory rights.
We take practical steps to protect your personal data against loss, misuse, modification, and unauthorised or accidental access, disclosure, alteration or destruction, having regard to the nature of the data, the place where it is stored, the security of our equipment, the reliability of our personnel, and the secure transfer of data. These measures include appropriate encryption, access controls, authentication, monitoring and logging safeguards, and secure transfer and storage procedures. We also require our data processors, by contract, to apply appropriate security measures.
No method of transmission or storage is completely secure, but we work to protect your personal data and to keep our safeguards under review.
Some service providers and other recipients process personal data outside Malaysia, so some of your personal data is transferred to and processed outside Malaysia. These transfers involve the following classes of recipients and purposes:
Processing may take place in Singapore, the United States, Indonesia and other jurisdictions in which the relevant providers operate. For every transfer, we ensure that at least one condition permitted under section 129 of the PDPA is satisfied and take all reasonable precautions and exercise due diligence to protect the data. Where consent is the applicable condition, we obtain and record it after providing the required notice. We keep and maintain an internal cross-border transfer record stating, for each receiver, its name, company registration number (if any), DPO or other contact details, destination country, the types of personal data transferred, the purposes of the transfer, the applicable section 129 condition, and records supporting that condition, in line with the Commissioner's Cross-Border Personal Data Transfer Guidelines.
We maintain an incident-response process for personal data breaches. If we have reason to believe a personal data breach has occurred, we will notify the Personal Data Protection Commissioner as soon as practicable, in the manner and form the Commissioner requires (under the Commissioner's current guidelines, within 72 hours). Where a breach causes or is likely to cause significant harm to affected individuals, we will also notify those individuals without unnecessary delay (under those guidelines, within seven days of notifying the Commissioner). We assess and document every breach, and we follow the timeframes and thresholds set out in the Commissioner's current guidelines.
We provide app stores with accurate privacy disclosures that are consistent with this Policy, including the categories of data we collect, the purposes for which we use it, sharing with service providers as described in Sections 7, 12 and 16, our security practices, and the availability of a data-deletion path. We do not use your data to track you across other companies' apps or websites, and the app-generated installation identifier is not used for tracking.
For any question, request or complaint about your personal data, please contact our privacy contact (Section 2) or our support team:
You may also lodge a personal-data complaint with the Personal Data Protection Commissioner through the official complaint channel.
We may update this Policy from time to time to reflect changes in our practices or in the law. We will post the updated Policy in the App and at our published Privacy Policy URL, and we will change the "Last updated" date above. Where the law requires, we will tell you about material changes and, where relevant, ask for your consent before collecting or using your personal data for a new purpose.
This Policy is governed by the laws of Malaysia.