Spana

PRIVACY POLICY

SPANA Web and Mobile Application

Effective Date: January 21, 2026 | Last Updated: January 21, 2026

1. Introduction

SPANA ("we", "us", "our") operates a motorcycle roadside assistance platform through our web application and mobile applications (collectively, the "Platform"). We are committed to protecting your personal data and respecting your privacy in accordance with the Malaysia Personal Data Protection Act 2010 ("PDPA Malaysia") and the Singapore Personal Data Protection Act 2012 ("PDPA Singapore").

This Privacy Policy explains how we collect, use, disclose, and protect your personal data when you use our Platform, whether as a member (Ahli SPANA), non-member, service technician, or workshop partner.

By using our Platform, you consent to the collection, use, and disclosure of your personal data as described in this Privacy Policy. If you do not agree to this Privacy Policy, please do not use our Platform.

2. Data Controller

The data controller responsible for your personal data is:

Spana International Sdn. Bhd.

Operating as SPANA

Malaysia

Email: privacy@spana.my

3. Personal Data We Collect

We collect and process the following categories of personal data:

3.1 Identity and Registration Data

  • Full name as per identification document
  • National Registration Identity Card (NRIC) number or Passport number
  • Date of birth
  • Gender
  • Photograph (for identity verification purposes)
  • Biometric data for eKYC verification (facial recognition data)

3.2 Contact Data

  • Mobile phone number
  • Email address
  • Residential address
  • Emergency contact information

3.3 Vehicle Data

  • Motorcycle registration number
  • Motorcycle make, model, and year
  • Motorcycle colour
  • Vehicle chassis number (for verification purposes)

3.4 Location Data

  • Real-time GPS location during service requests
  • Historical location data related to service requests
  • Saved locations (home, workplace, frequently visited locations)

3.5 Financial and Transaction Data

  • Payment card details (processed securely through our payment gateway partners)
  • Bank account information (for technicians receiving payments)
  • Transaction history
  • Membership subscription details
  • Invoices and receipts

3.6 Technical Data

  • Device type, model, and operating system
  • Unique device identifiers
  • IP address
  • Browser type and version
  • App version
  • Log data and usage statistics

3.7 Service Data

  • Service request details and history
  • Communications between users and technicians
  • Service ratings and feedback
  • Photos of motorcycle condition (if uploaded during service request)
  • Customer support communications

3.8 Professional Data (For Technicians)

  • TVET certifications and qualifications
  • Driving license information
  • Work experience and skills
  • Service performance metrics
  • Background check results

4. Purposes for Collecting and Processing Personal Data

We collect and process your personal data for the following purposes:

4.1 Service Provision

  • Processing your registration and creating your account
  • Verifying your identity through eKYC processes
  • Matching you with available technicians for roadside assistance
  • Facilitating real-time location tracking during service requests
  • Processing payments and managing transactions
  • Managing your membership subscription (Ahli SPANA)
  • Providing customer support and responding to inquiries

4.2 Safety and Security

  • Ensuring the safety of riders, technicians, and the general public
  • Conducting background checks on technicians
  • Investigating and resolving incidents, disputes, or complaints
  • Detecting and preventing fraud, abuse, or other harmful activities
  • Maintaining platform integrity and security

4.3 Legal Compliance

  • Complying with applicable laws, regulations, and legal processes
  • Responding to requests from law enforcement and regulatory authorities
  • Establishing, exercising, or defending legal claims

4.4 Platform Improvement

  • Analysing usage patterns to improve our services
  • Conducting research and development
  • Testing and troubleshooting new features
  • Personalising your experience on the Platform

4.5 Communications

  • Sending service-related notifications (e.g., service confirmations, technician arrival updates)
  • Sending administrative communications about your account
  • Sending marketing communications (with your consent)
  • Conducting surveys and collecting feedback

5. Disclosure of Personal Data

We may disclose your personal data to the following categories of recipients:

5.1 Service Providers

  • Technicians and partner workshops providing roadside assistance services
  • Payment processors (e.g., Billplz)
  • Cloud hosting and infrastructure providers
  • eKYC verification providers (e.g., Didit)
  • SMS and communication service providers (e.g., Twilio)
  • Mapping and GPS service providers (e.g., Mapbox)
  • Customer support and analytics providers

5.2 Business Partners

  • Insurance companies (for insurance-related claims or coverage)
  • Affiliated workshops and service centres

5.3 Legal and Regulatory Authorities

  • Law enforcement agencies
  • Courts and tribunals
  • Government agencies and regulators
  • Personal Data Protection Commission (Malaysia and Singapore)

5.4 Corporate Transactions

In the event of a merger, acquisition, reorganisation, or sale of assets, your personal data may be transferred to the relevant third party as part of that transaction.

6. Cross-Border Data Transfer

As we operate in both Malaysia and Singapore, and use international service providers, your personal data may be transferred to, stored, and processed in countries outside of Malaysia or Singapore.

When transferring personal data internationally, we ensure that:

  • The receiving country has laws substantially similar to the PDPA or provides an adequate level of protection
  • Appropriate contractual safeguards are in place with the receiving party
  • You have consented to the transfer
  • The transfer is necessary for the performance of our services to you

7. Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable laws. Our retention periods are as follows:

Data CategoryRetention Period
Account DataDuration of account plus 7 years after account closure
Transaction Records7 years from the date of transaction
Service Request Data5 years from the date of service completion
Location Data2 years from the date of collection
Communication Records3 years from the date of communication
eKYC / Biometric DataDuration of account plus 1 year, or as required by law
Marketing PreferencesUntil consent is withdrawn
Technical / Log Data1 year from the date of collection

When personal data is no longer required, we will securely delete or anonymise it in accordance with our data retention policies.

8. Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:

  • Encryption of data in transit and at rest using industry-standard protocols
  • Secure authentication mechanisms including multi-factor authentication
  • Regular security assessments and penetration testing
  • Access controls limiting data access to authorised personnel
  • Employee training on data protection and security best practices
  • Secure data centres with physical security controls
  • Incident response and data breach notification procedures

9. Your Rights

Under the PDPA Malaysia and PDPA Singapore, you have the following rights regarding your personal data:

9.1 Right of Access

You have the right to request access to your personal data that we hold and to obtain information about how we have used or disclosed your personal data within the past year.

9.2 Right to Correction

You have the right to request correction of any personal data that is inaccurate, incomplete, misleading, or not up-to-date.

9.3 Right to Withdraw Consent

You may withdraw your consent for the collection, use, or disclosure of your personal data at any time by contacting us. Please note that withdrawal of consent may affect our ability to provide certain services to you.

9.4 Right to Data Portability

Under the PDPA Malaysia (effective June 2025), you have the right to request that your personal data be transmitted to another organisation in a commonly used machine-readable format.

9.5 Right to Object to Direct Marketing

You may opt out of receiving direct marketing communications from us at any time by clicking the unsubscribe link in our emails or contacting us directly.

To exercise any of these rights, please contact our Data Protection Officer using the contact details provided in Section 14 of this Privacy Policy. We will respond to your request within 21 days (Malaysia) or 30 days (Singapore) of receiving your request.

10. Sensitive Personal Data

Sensitive personal data includes information relating to physical or mental health, religious beliefs, political opinions, and biometric data. We collect the following sensitive personal data with your explicit consent:

  • Biometric data: Facial recognition data collected during eKYC verification for identity authentication purposes
  • Health information: If voluntarily provided by technicians for health and safety purposes

We will only process sensitive personal data where we have obtained your explicit consent, or where processing is necessary to protect your vital interests or for legal claims.

11. Data Breach Notification

In the event of a personal data breach that is likely to cause significant harm to affected individuals, we will:

  • Notify the Personal Data Protection Commissioner as soon as practicable
  • Notify affected individuals if the breach is likely to result in significant harm
  • Take immediate steps to contain and assess the breach
  • Implement measures to prevent future breaches

12. Cookies and Tracking Technologies

Our web application uses cookies and similar tracking technologies to enhance your browsing experience and analyse usage patterns. Types of cookies we use include:

  • Essential cookies: Required for the Platform to function properly
  • Performance cookies: Help us understand how visitors interact with our Platform
  • Functionality cookies: Remember your preferences and settings
  • Analytics cookies: Help us improve our services through usage analysis

You can manage your cookie preferences through your browser settings. Please note that disabling certain cookies may affect the functionality of our Platform.

13. Children's Privacy

Our Platform is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children. If you believe we have collected personal data from a child, please contact us immediately, and we will take steps to delete such information.

14. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or our data protection practices, please contact our Data Protection Officer:

Data Protection Officer

SPANA (operated by SPANA International)

Email: support@spana.my

Phone: +601170724747

You may also lodge a complaint with the relevant data protection authority:

Malaysia

Personal Data Protection Department (JPDP)

Website: www.pdp.gov.my

Email: aduan@pdp.gov.my

Singapore

Personal Data Protection Commission (PDPC)

Website: www.pdpc.gov.sg

Email: info@pdpc.gov.sg

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, services, or applicable laws. We will notify you of any material changes by:

  • Posting the updated Privacy Policy on our Platform
  • Sending you a notification through the mobile application
  • Sending you an email notification (for material changes)

Your continued use of the Platform after any changes to this Privacy Policy constitutes your acceptance of the updated policy.

16. Governing Law

This Privacy Policy shall be governed by and construed in accordance with the laws of Malaysia. For users in Singapore, the relevant provisions of the PDPA Singapore shall apply to the extent required by law.

17. Acknowledgement and Consent

By using the SPANA Platform, you acknowledge that you have read, understood, and agree to the collection, use, and disclosure of your personal data as described in this Privacy Policy.

For sensitive personal data, including biometric data collected during eKYC verification, your explicit consent will be obtained separately during the registration process.

--- End of Privacy Policy ---

Document Version: 1.0 | Effective: January 21, 2026