This notice is for readers of the e-Sarah web app. It supports Malaysia PDPA 2010 and, where it applies, GDPR-style access and erasure.
Email address, display name, device identifiers, book assignments, login times, IP address on security events, and encrypted ebook packages you are entitled to read. If you pay for licences, we also store your name, email, phone, the ebooks and seat counts you asked for, and an encrypted copy of the payment slip.
We do not log page turns, searches, or reading duration. We do not take payment card numbers.
To authenticate you, enforce device limits, deliver assigned books, watermark pages with your email, and detect abuse.
Account data until you delete the account or an admin revokes it. Security logs about 12 months. Book files while the organisation publishes that title. Rejected payment slips are deleted after 90 days. Approved slips and invoices are kept for 7 years for accounting, then the slip file is destroyed. Deleting your reader account replaces your name, email and phone on any order you placed; the invoice amounts stay.
The payment form uses Google reCAPTCHA. Completing that check sends technical data (including your IP address) to Google, which may be outside Malaysia. That is the only routine cross-border transfer from this form. Microsoft sign-in, where an administrator uses it, sends the administrator to Microsoft. We do not send ebook contents to either company.
After you sign in, open Security to download a copy of your personal data or delete your account (password required). Deletion removes devices and licenses and revokes the login. It does not uninstall a copy you already decrypted on a device.
Ask the organisation that assigned your ebook (the data user). This software operator should list a contact in their staging/production privacy addendum.