Privacy Policy
Effective Date: August 1, 2026 (version 2026-08-01)
MY1ST ("we," "us," or "our") is operated by Apply IT Sdn. Bhd. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and related services (collectively, the "Service"). Please read this policy carefully.
We process personal data in accordance with Malaysia's Personal Data Protection Act 2010 ("PDPA"). You give your consent by ticking the consent box presented when you create an account (or by continuing past the equivalent notice beside the sign-in-with-a-provider buttons), and we record which version of this policy you accepted and when. Continuing to use the Service is not, by itself, how we obtain your consent. You may withdraw consent at any time — see Section 6.
Where the person whose data we hold is under 18, the consent required by the PDPA is given by their parent or legal guardian, or by the Educator's own confirmation that they hold it. Section 7 explains exactly how this works and what a parent or guardian can ask us to do.
1. Information We Collect
1.1 Information You Provide
- Account Information: When you create an account, we collect your name, email address, and password. You may also provide a profile photo.
- Educator Profile: Business name, teaching subjects, contact details, and professional information. Where you use the e-Invoice feature, this also includes your Tax Identification Number (TIN) and business registration number.
- Student Data: Names, contact details, enrollment information, attendance records, and academic progress of students you manage through the platform.
- Guardian Information: Names and email addresses of guardians you invite to connect with student profiles.
- Financial Records: Payment records, invoices, and financial data related to your teaching services that you enter into the platform.
- Course Content: Course names, descriptions, schedules, and related educational materials you create.
- Feedback & Attachments: Student feedback, progress reports, and any photo attachments you upload.
- Communications: Messages you send through the platform and any correspondence with our support team.
1.2 Information Collected Automatically
- Device Information: Device type, operating system, unique device identifiers, and mobile network information.
- Usage Data: Features used, actions taken, time and date of access, and app performance data.
- Log Data: IP address, browser type, access times, and referring URLs when accessing our web services.
1.3 Information from Third Parties
If you choose to sign in using a third-party service (Google, Microsoft, or Facebook), we receive your name, email address, and profile picture as permitted by your account settings on that service.
2. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service
- Create and manage your account
- Enable you to manage your students, courses, attendance, and finances
- Send transactional emails (account verification, password resets, guardian invitations)
- Generate reports and analytics for your teaching business
- Respond to your requests, comments, and questions
- Monitor and analyze usage trends to improve user experience
- Detect, prevent, and address technical issues and security threats
- Submit e-Invoices to LHDN's MyInvois platform on your behalf where you use the e-Invoice feature (see Section 3)
- Comply with legal obligations
2.1 Our Lawful Bases
Under the PDPA we rely on the following bases:
- Your consent, given by ticking the consent box at registration — for creating and operating your account and for processing the data you enter. For a student under 18, that consent is given by their parent or legal guardian (see Section 7).
- Performance of our contract with you — to deliver the features you signed up for, such as scheduling, attendance, invoicing and messaging.
- The Educator's instructions, where we process student records that an Educator created; the Educator is responsible for the consent behind those records (see Section 7).
- Compliance with a legal obligation — including the e-Invoice and tax record-keeping duties described below.
- Our legitimate interests in keeping the Service secure and functioning — for example detecting abuse and diagnosing faults — where doing so does not override your rights.
Where we process and transmit e-Invoice data to LHDN, our lawful basis for doing so is compliance with a legal obligation under Malaysian tax law (including the Income Tax Act 1967 and the LHDN e-Invoice mandate), and the performance of our role as your authorized MyInvois intermediary at your instruction.
3. How We Share Your Information
We do not sell your personal information. We may share your information in the following circumstances:
- With Guardians: When you invite guardians to connect with student profiles, they will have access to relevant student information you choose to share.
- Service Providers: We use third-party services for hosting, email delivery, and object storage. These providers are contractually bound to protect your data and only process it on our behalf.
- LHDN (MyInvois): Where you use the e-Invoice feature, we transmit invoice and taxpayer data — including your Tax Identification Number (TIN), business registration number, transaction amounts, and buyer details — to the Inland Revenue Board of Malaysia (LHDN) via its MyInvois platform, as required by Malaysian tax law. As your authorized intermediary, we also retain records of these submissions and LHDN's responses (see Section 5).
- Legal Requirements: We may disclose your information if required by law, regulation, legal process, or governmental request.
- Business Transfers: In connection with a merger, acquisition, or sale of assets, your information may be transferred as a business asset.
- With Your Consent: We may share information with third parties when you explicitly consent to such sharing.
4. Data Storage and Security
Your data is stored on secure servers protected by encryption in transit (TLS 1.2+) and industry-standard security measures. We use PostgreSQL for structured data and S3-compatible object storage for files such as profile photos and attachments. Access to data is restricted to authenticated users through JWT-based authentication.
While we implement commercially reasonable security measures, no method of electronic storage or transmission over the Internet is 100% secure. We cannot guarantee absolute security of your data.
If a personal data breach occurs that causes or is likely to cause you significant harm, we will notify the Personal Data Protection Commissioner within 72 hours of the breach, and inform the affected users within 7 days of that notification, as required by the Personal Data Protection Act 2010 as amended in 2024. Where the affected person is a student under 18, we notify their parent or guardian. Our Data Protection Officer (Section 11) owns this process.
5. Data Retention
We retain your personal information for as long as your account is active or as needed to provide you with the Service. If you request account deletion, we will delete your personal data within 30 days, except where we are required to retain it for legal or regulatory purposes. Anonymized and aggregated data that cannot identify you may be retained indefinitely.
In particular, e-Invoice records and related submission logs are subject to statutory retention obligations under Malaysian tax law. As an authorized MyInvois intermediary, we are required to retain these records for the minimum period required by law (currently seven (7) years). These records will be retained for that period even after you request account deletion, and this obligation overrides the 30-day deletion timeframe above for the affected records only.
6. Your Rights and Choices
Under the PDPA, and depending on your jurisdiction, you have the following rights. A parent or legal guardian may exercise every one of them on behalf of their child under 18 (see Section 7).
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your personal data (see our Account Deletion page).
- Data Portability: Request a machine-readable copy of your data.
- Withdrawal of Consent: Where processing is based on consent, you may withdraw consent at any time.
- Objection: Object to processing of your personal data for certain purposes.
To exercise any of these rights, contact us at privacy@myfirsts.ai.
7. Students Under 18
MY1ST is used to run classes for learners of every age, and many of those learners are school-age children. We therefore do process the personal data of people under 18. There are two distinct situations, and the consent works differently in each.
1. A student record created by an Educator. The student holds no account. The Educator enters the record as part of running their teaching practice, and is responsible for having obtained the parent or guardian consent required to do so — this is their obligation under Section 5.3 of our Terms of Service. For these records we act on the Educator's instructions.
2. A Student account held by the student. The student can sign in themselves. Where that student is under 18, the parent or legal guardian must have read and accepted our Terms and this policy on the student's behalf; the account holder confirms this by ticking the consent box at registration. We record which version of the policy was accepted and when.
We do not collect a date of birth and we do not verify age. This is a deliberate choice: a self-declared birth date proves nothing, and holding one would mean collecting more personal data about children than we need. We rely on the confirmation given at registration, and on acting promptly when we are told it was wrong.
If you are a parent or legal guardian and your child holds an account you did not consent to, or you want your child's data corrected or erased, write to privacy@myfirsts.ai. We will verify that you are connected to the child's record, then suspend the account and delete the personal data, and we will do this whether the data sits in the child's own account or in an Educator's student record. The Account Deletion page sets out the procedure and timelines. You do not need the Educator's permission to make this request.
8. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place to protect your data in accordance with this Privacy Policy and applicable data protection laws.
9. Third-Party Links and Services
The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any personal information.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy within the app, updating the "Effective Date" and version above, and — where the change materially affects how we use your personal data — by email.
Where a change materially alters what you consented to, we will ask for your consent again rather than treating continued use as agreement. For other changes, the updated policy applies from its Effective Date, and if you do not agree with it you may withdraw your consent or delete your account.
11. Contact Us and Our Data Protection Officer
Apply IT Sdn. Bhd. (company no. 202501006499) is the data user responsible for the personal data described in this policy. We are registered with Malaysia's Department of Personal Data Protection (JPDP) under registration no. PD2026-04359. We have appointed a Data Protection Officer as the single point of contact for privacy matters, including access, correction and deletion requests, requests made by a parent or guardian about a child, and withdrawals of consent.
- Data Protection Officer: dpo@myfirsts.ai
- Privacy requests: privacy@myfirsts.ai
- General Support: support@myfirsts.ai
We aim to acknowledge a privacy request within 7 days and to resolve it within 21 days. If you are not satisfied with our response you may complain to the Personal Data Protection Commissioner of Malaysia.
