PDPA Compliant

Privacy Policy

Effective: 05 March 2026 Version 1.0 Reviewed Annually
Pay Direct Technology Sdn Bhd ("Bold.Remit") — Company No: 201701027329 (1241495-V)
Level 23A Menara Allianz Central, Kuala Lumpur, Malaysia
Compliance: compliance@boldremit.com  ·  Support: support@boldremit.com

This Privacy Policy explains how Bold.Remit collects, retains, processes, shares and transfers your Personal Data in connection with its B2B outbound remittance services, in line with the Personal Data Protection Act 2010 (PDPA). By registering for or using our Services, you acknowledge and consent to the practices described herein.

1. Introduction and Scope

Bold.Remit is an appointed money services business agent of MoneyMatch Sdn Bhd for remittance business providing services from Malaysia. We are committed to protecting the privacy and Personal Data of our clients, their representatives, directors, shareholders, ultimate beneficial owners ("UBO"), and all other individuals whose Personal Data we process in the course of providing our Services.

Who This Privacy Policy Applies To

This Policy applies to Personal Data processed in relation to:

  • Directors and authorized representatives of business client entities;
  • Shareholders and UBOs of business clients;
  • Authorized users (makers and checkers) of the Bold.Remit Platform;
  • Beneficiaries of outbound remittance transactions;
  • Visitors to the Bold.Remit website and Platform;
  • Any other individuals whose Personal Data is provided to Bold.Remit in connection with KYB, KYC, or transaction processes.

2. Personal Data of Minors

The Platform and Services are intended exclusively for registered business entities and corporate clients. We do not knowingly collect or process Personal Data of individuals under the age of 18 years. If we become aware that Personal Data of a minor has been collected inadvertently, we will take immediate steps to delete such data.

If you believe we have inadvertently collected Personal Data relating to a minor, please contact us at compliance@boldremit.com.

3. Personal Data We Collect

3.1 Identity and Verification Data

  • Full legal name;
  • NRIC/MyKad number or passport number;
  • Date of birth;
  • Nationality and country of residence;
  • Photograph or biometric facial image (for KYC/KYB liveness verification);
  • Occupation, position, and role within the business client entity;
  • Personal tax identification number (TIN) where applicable.

3.2 Contact Information

  • Residential address and correspondence address;
  • Mobile phone number;
  • Personal and business email addresses;
  • Proof of address.

3.3 Financial and Transaction Data

  • Business bank account details (account name, number, bank name, branch);
  • Transaction history, including amounts, currencies, dates, and beneficiary details;
  • Source of funds and source of wealth declarations;
  • Audited financial statements and management accounts provided during KYB processes;
  • Exchange rate confirmations and fee receipts.

3.4 Corporate and Ownership Data

  • Percentage of shareholding in the business client entity;
  • UBO declaration information;
  • Information on politically exposed person ("PEP") status;
  • Adverse media, sanctions, and watchlist screening results.

3.5 Platform Usage and Technical Data

  • IP address and device identifiers;
  • Browser type and operating system;
  • Login timestamps, session duration, and Platform activity;
  • Transaction actions taken within the Platform (submission, approval, rejection).

4. How We Collect Personal Data

SourceHow Personal Data is Collected
KYB / KYC ApplicationDirectly from the business client and its authorized representatives during account registration and verification.
Platform RegistrationThrough completion of registration forms, profile setup, and submission of authorized user credentials.
Transaction SubmissionThrough remittance requests and associated beneficiary information submitted by makers and approved by checkers.
Automated Verification (Shufti Pro)Through document scanning and liveness detection conducted by our third-party identity verification partner.
Third-Party Data SourcesFrom public registries (e.g., Companies Commission of Malaysia), sanctions lists and commercially available adverse media databases.
CorrespondenceThrough email, chat messages, or any other communications with our team.
Regulatory BodiesInformation received from Bank Negara Malaysia ("BNM"), law enforcement, or other competent authorities in connection with compliance obligations.

5. Purposes of Personal Data Processing

PurposeDescriptionLegal Basis (PDPA)
KYB & KYC VerificationIdentity verification of directors, shareholders, and authorized users prior to account activation.Contractual necessity; Legal obligation
Account ManagementCreating and maintaining business account, authorized user profiles, and checker/approver assignments.Contractual necessity
Transaction ProcessingExecuting outbound remittance transactions, communicating with correspondent banks, and delivering funds to beneficiaries.Contractual necessity
AML/CFT ComplianceScreening against sanctions lists, monitoring transactions for suspicious activity, filing STRs and CTRs with BNM's Financial Intelligence Unit.Legal obligation (AMLA 2001)
Regulatory ReportingReporting to BNM, PDPD, MACC, and other competent authorities as required by law.Legal obligation
Customer SupportResponding to queries, complaints, and service requests from business clients.Legitimate interests; Contractual necessity
Fraud Prevention & SecurityDetecting, investigating, and preventing fraud, identity theft, cybersecurity threats, and unauthorized access.Legitimate interests; Legal obligation
Risk ManagementAssessing operational risk and AML/CFT risk associated with business clients and transactions.Legitimate interests; Legal obligation
Legal ClaimsEstablishing, exercising, or defending legal claims, regulatory proceedings, or disputes.Legitimate interests; Legal obligation
Marketing & PromotionsSending service updates, product announcements, and promotional materials (with consent where required).Consent

If you wish to withdraw your consent to the processing for the above purposes, we will not be able to provide you with our Services.

6. Disclosure and Sharing of Personal Data

Bold.Remit does not sell your Personal Data to third parties. We may share Personal Data only in the following circumstances:

6.1 Service Providers and Partners

Category of RecipientPurpose of Disclosure
Identity VerificationKYC/KYB document verification and biometric liveness detection.
Correspondent & Intermediary BanksExecution of outbound remittance transactions to beneficiary accounts.
Cloud Infrastructure ProvidersSecure hosting of the Platform and storage of transaction and customer data.
Sanctions Screening ProvidersReal-time screening against international sanctions, PEP, and adverse media databases.
Payment Processing PartnersProcessing fund transfers and exchange rate execution.
Legal and Audit AdvisorsLegal advice, compliance audits, and statutory audit purposes.
Cybersecurity & Fraud DetectionMonitoring, detecting, and preventing fraud and cybersecurity threats.

6.2 Regulatory and Law Enforcement Authorities

Bold.Remit is legally required to disclose Personal Data to:

  • BNM and its Financial Intelligence and Enforcement Department;
  • Personal Data Protection Department of Malaysia (PDPD);
  • Royal Malaysia Police (PDRM) and MACC;
  • Any court, tribunal, or arbitral body in connection with legal proceedings;
  • Foreign financial intelligence units or regulatory bodies pursuant to mutual legal assistance treaties or BNM directives;
  • Any other competent authority with lawful authority to require disclosure.

6.3 Cross-Border Data Transfers

Execution of outbound remittance transactions necessarily involves the transfer of beneficiary Personal Data to financial institutions in destination countries outside Malaysia. Bold.Remit implements appropriate safeguards for cross-border transfers, including contractual data protection clauses with correspondent banks and transfer to jurisdictions with adequate data protection standards recognized by the PDPA.

6.4 Business Transfers

In the event of a merger, acquisition, restructuring, or sale of Bold.Remit's business, Personal Data may be transferred to the successor entity, subject to equivalent data protection obligations.

7. Third-Party Data Processors

Processor CategoryRole and Data Processing Activity
Identity VerificationProcesses identity documents, facial biometric data, and liveness verification during KYB/KYC. Data processed in accordance with Shufti Pro's GDPR-compliant privacy policy.
Cloud Hosting ProviderHosts the Platform and stores encrypted customer and transaction data. Subject to ISO 27001 or equivalent security certification.
Sanctions & PEP ScreeningProcesses names, NRIC/passport numbers, and nationality data against global sanctions, watchlist, and adverse media databases.
Correspondent Banking NetworkProcesses beneficiary names, account numbers, and transaction amounts to execute outbound remittances.
Email and Communication ServicesProcesses contact information and communication content for service-related notifications and customer support.
Analytics & Platform MonitoringProcesses aggregated and pseudonymized usage data to monitor platform performance and improve user experience.

The current list of sub-processors is available upon written request to compliance@boldremit.com.

8. Data Retention

Bold.Remit retains Personal Data only for as long as necessary for the purposes for which it was collected, or as required by applicable law.

Category of DataRetention Period
KYB/KYC documentation and identity recordsMinimum 7 years from account closure / execution, completion or termination of business relationship, transaction, or activity (whichever is latest)
Remittance transaction records and receipts
STR/CTR filings and supporting records
Account access logs and audit trailsMinimum 7 years
Customer correspondence and support records3 years from last interaction
Biometric verification data (Shufti Pro)Per Shufti Pro's data retention policy (typically 5–7 years)
Marketing consent recordsUntil consent is withdrawn + 1 year

After the applicable retention period, your Personal Data will be securely deleted or destroyed in accordance with our data disposal procedures.

9. Data Security

9.1 Security Measures

Technical Measures:

  • Encryption of sensitive data at rest using AES-256 or equivalent standards;
  • Multi-factor authentication (MFA) for all authorised user platform access;
  • Role-based access controls limiting Personal Data access to personnel who require it;
  • Regular penetration testing and vulnerability assessments;
  • Intrusion detection and prevention systems;
  • Secure software development lifecycle (SDLC) practices.

Organizational Measures:

  • Data protection training for all staff handling Personal Data;
  • Internal data protection policies, procedures, and incident response plans;
  • Vendor due diligence for all third-party data processors;
  • Annual review and audit of data protection practices.

9.2 Data Breach Response

In the event of a Personal Data breach, Bold.Remit will take immediate steps to contain and investigate the breach. Where required under the PDPA or BNM regulations, we will notify the PDPD and affected data subjects accordingly.

Security Reminder: Bold.Remit will never ask you to provide your password, OTP, or security credentials via email, telephone, or chat. If you receive such a request claiming to be from Bold.Remit, treat it as suspicious and report it immediately.

9.3 Limitation of Responsibility

While we are dedicated to securing our systems and Services, you are responsible for securing and maintaining the privacy of your password(s) and account/profile registration information and verifying that the Personal Data we maintain about you is accurate and current.

10. Cookies and Tracking Technologies

Cookie TypeBasisPurpose
Strictly NecessaryRequired (no opt-out)Session management, authentication, security tokens, CSRF protection. Essential for Platform operation.
FunctionalRequiredSaving your language preferences, time zone settings, and session state.
Security MonitoringRequiredBot detection and login anomaly detection.

11. Your Privacy Choices

You have choices when it comes to the privacy practices and communications described in this Privacy Policy. Many of your choices may be explained at the time you sign up for or use a Service or in the context of your use of a Site.

11.1 Choices Relating to Personal Data We Collect

  • Personal Data. You may decline to provide Personal Data when it is requested by Bold.Remit, but certain Services or all of the Services may be unavailable to you.
  • Location and device-level information. The device you use to access the Sites or Services may collect information about you, including geolocation information and user usage data that Bold.Remit may then collect and use.

12. Business Client's Data Protection Obligations

As a business client using the Bold.Remit Platform, you act as a data controller in respect of the Personal Data of your authorised users, directors, employees, and beneficiaries that you provide to Bold.Remit. In this capacity, you are responsible for:

  • Ensuring you have a lawful basis for collecting and sharing Personal Data of individuals with Bold.Remit, including obtaining necessary consents;
  • Providing adequate privacy notices to your directors, UBOs, authorised users, and transaction beneficiaries;
  • Ensuring all Personal Data provided to Bold.Remit is accurate, up to date, and complete;
  • Promptly notifying Bold.Remit of any corrections or updates to Personal Data provided;
  • Maintaining your own data protection policies and practices in compliance with the PDPA where applicable to your business;
  • Not providing to Bold.Remit any Personal Data that you are not lawfully authorized to disclose.

13. Marketing Communications and Consent

With your consent, Bold.Remit may contact you with service updates, new product features, promotional offers, industry news, and event invitations.

You may opt out at any time by clicking the "Unsubscribe" link in any marketing email or updating your communication preferences in the Platform settings. Opting out of marketing communications does not affect transactional or service-related communications.

14. Your Rights Under the PDPA

RightDescription and How to Exercise
Right to AccessRequest access to the Personal Data we hold about you. Submit your request to compliance@boldremit.com. We will respond within 21 days.
Right to CorrectionIf the Personal Data we hold is inaccurate, incomplete, or out of date, submit a correction request to compliance@boldremit.com. We will rectify within 21 days or notify you of reasons for declining.
Right to Withdraw ConsentWhere processing is based on your consent, you may withdraw consent at any time. Withdrawal does not affect the lawfulness of prior processing and may limit our ability to provide certain Services.
Right to be InformedYou have the right to be informed of the purposes for which your Personal Data is collected and processed, which is fulfilled by this Privacy Policy.
Right to ObjectYou may object to processing your Personal Data for marketing purposes at any time by contacting us at compliance@boldremit.com.
Right to Data PortabilityWhere technically feasible and permitted by law, you may request a copy of your Personal Data in a structured, machine-readable format.
Right to ComplainIf you believe your rights under the PDPA have been violated, you may lodge a complaint with the PDPD at www.pdp.gov.my.
Regulatory Limitation: Certain rights under the PDPA are subject to exemptions where processing is required for the prevention or detection of crime, AML/CFT compliance, or where disclosure is ordered by a court or competent authority.

15. Contact Us

Data Protection Officer

Pay Direct Technology Sdn Bhd (Bold.Remit)

Compliance: compliance@boldremit.com

Support: support@boldremit.com

You may be required to verify your identity before we process your request. Requests submitted on behalf of another person must be accompanied by written authorisation from that person.

16. Changes to This Privacy Policy

Bold.Remit reviews and updates this Privacy Policy periodically to reflect changes in our practices, regulatory requirements, and business operations. Material changes will be communicated to business clients by email notification and/or a prominent notice on the Platform at least fourteen (14) days before the change takes effect.

Your continued use of the Services after the effective date of any updated Policy constitutes your acceptance of the revised terms. All previous versions are available upon written request to compliance@boldremit.com.

17. Governing Law and Jurisdiction

This Privacy Policy is governed by and construed in accordance with the laws of Malaysia. Any dispute arising from or in connection with this Privacy Policy shall be subject to the exclusive jurisdiction of the courts of Malaysia.