Privacy Policy
This Privacy Policy describes how D'Corp Tech [Company Registration No. 202603087380 (003837724-U)] ("Company," "We," "Us," or "Our"), a sole proprietorship duly registered in Malaysia under the Registration of Businesses Act 1956 and the exclusive operator of the global luxury brand Munyu Munyu, founded and owned by Aredaran (known publicly as Prince D), collects, uses, stores, and protects personal data submitted through this Platform, including the #CONNECT Campaign and the Karma Contest.
Who Is Responsible for Your Data
The sole data controller for all personal data collected through this Platform is:
- Entity: D'Corp Tech [202603087380 (003837724-U)], operating as Munyu Munyu
- Legal Form: Sole Proprietorship registered under the Registration of Businesses Act 1956, Malaysia
- Data Protection Contact: love@munyu.my
- Primary Jurisdiction: Malaysia โ with PDPA 2010 as the primary governing framework
Why We Are Permitted to Process Your Data
We process personal data on the following lawful bases under PDPA 2010 (Malaysia) and GDPR (EU/EEA participants):
| Purpose | Legal Basis (PDPA) | Legal Basis (GDPR Art.) |
|---|---|---|
| Contest administration & winner verification | Consent / Contractual necessity | Art. 6(1)(b) โ Performance of contract |
| Fraud prevention & rate-limiting | Legitimate interest | Art. 6(1)(f) โ Legitimate interests |
| Prize fulfilment & communication | Consent | Art. 6(1)(a) โ Consent |
| Legal compliance & dispute resolution | Legal obligation | Art. 6(1)(c) โ Legal obligation |
Categories of Personal Data Collected
3.1 Data You Provide Directly
- Identity Data: Full name and social media username(s) submitted on the entry form;
- Contact Data: Email address used for prize notification and campaign communications;
- Contest Submission Data: Your cryptographically encrypted Karma Contest entry payload.
3.2 Data Collected Automatically
- Rate-Limiting Data: A hashed (non-reversible) representation of your IP address, retained for a maximum of 24 hours for anti-abuse purposes and then permanently deleted;
- Technical Data: Browser type and device type (collected anonymously for compatibility purposes).
3.3 Data We Do NOT Collect
- Financial data, payment card details, or bank account information;
- Government-issued identification numbers;
- Sensitive personal data (as defined under PDPA 2010 and GDPR Art. 9);
- Location tracking data or biometric data;
- Third-party social media credentials or passwords.
Purposes of Processing
- To receive, validate, and administer Karma Contest entries;
- To verify winner eligibility and conduct identity confirmation prior to prize release;
- To communicate campaign results, prize fulfilment logistics, and important campaign updates;
- To prevent fraudulent, automated, or duplicate contest submissions;
- To comply with applicable legal obligations in Malaysia and other jurisdictions;
- To defend legitimate legal claims or enforce our rights under this Agreement.
We do not use your data for unsolicited marketing, profiling for advertising, or sale to third parties. We do not share your personal data with any third party for commercial marketing purposes.
How Long We Keep Your Data
Personal data is retained only for as long as necessary to fulfil the stated purposes and comply with legal obligations:
- Contest entry data (name, email, submission): Retained for a maximum of 24 months from the campaign close date (26 July 2026), then permanently deleted;
- Winner communication data: Retained for 7 years for audit and legal compliance purposes;
- Hashed IP data for rate-limiting: Retained for a maximum of 24 hours, then permanently purged;
- Upon expiry of the applicable retention period, data is securely destroyed using irreversible deletion methods.
How We Protect Your Data
We implement a layered, industry-standard security architecture to protect all personal data:
- Encryption in Transit: All data transmitted between your browser and our server is protected by HTTPS enforced with TLS 1.3;
- Payload Encryption: Contest submissions are encrypted on the client-side using AES-256-GCM authenticated encryption with a key derived via PBKDF2 (100,000 iterations);
- Token Validation: Entries are validated using an Argon2id memory-hard hashing proof-of-work system to prevent automated submissions;
- Rate Limiting: Automated rate-limit controls prevent brute-force and spam submission attempts;
- Access Control: Personal data access is strictly limited on a need-to-know basis (principle of least privilege);
- Honeypot Anti-Bot: Invisible form fields detect and reject automated bot submissions before any data is processed.
While we apply all reasonable technical and organisational safeguards, no system is infallible. In the unlikely event of a data breach that poses a risk to your rights, we will notify you and the relevant authority within the timeframe required by applicable law.
Your Data Subject Rights
Subject to applicable law, you hold the following rights regarding your personal data:
| Right | Description |
|---|---|
| Access | Request a copy of the personal data we hold about you. |
| Rectification | Request correction of inaccurate or incomplete data. |
| Erasure | Request deletion of your personal data ("Right to be Forgotten"), subject to legal retention obligations. |
| Restriction | Request that we limit how we process your data in certain circumstances. |
| Portability | Request receipt of your data in a structured, machine-readable format. |
| Objection | Object to processing based on legitimate interests. |
| Withdraw Consent | Withdraw consent at any time without affecting prior lawful processing. |
To exercise any of these rights, submit a written request to: love@munyu.my. We will respond within 30 calendar days. We may require identity verification before processing your request.
Cross-Border Data Processing
If you are accessing this Platform from outside Malaysia โ including from the European Union, European Economic Area, United Kingdom, or any other jurisdiction โ your personal data may be transferred to and processed in Malaysia or on servers located in other countries. By participating, you expressly consent to such international transfer.
For participants in the EU/EEA, where required under GDPR Chapter V, we ensure appropriate safeguards are in place, including the use of Standard Contractual Clauses (SCCs) approved by the European Commission, or an equivalent transfer mechanism, to protect your data during cross-border transfers.
Cookies Policy
This Platform uses no third-party tracking cookies, advertising pixels, or analytics beacons. We do not deploy Google Analytics, Meta Pixel, or any similar tracking technology that profiles your browsing behaviour. The Platform is a static website โ no session cookies are set beyond what is technically necessary for security (e.g., CSRF prevention on form submission). You are not tracked across websites.
Jurisdiction & Regulatory Authority
This Privacy Policy is governed by the laws of Malaysia. The primary regulatory authority for data protection complaints is the Personal Data Protection Commissioner of Malaysia, reachable through the Ministry of Digital. For EU/EEA participants, you may also lodge a complaint with your local EU Supervisory Authority (Data Protection Authority) under GDPR Art. 77.
For any privacy-related queries, concerns, or data subject requests, please contact: love@munyu.my
Music Licensing, Attribution & Copyright Compliance
11.1 Pixabay Music Licence
All background music and audio tracks utilised across the Munyu Munyu website, the #CONNECT Campaign, and all associated digital media are licensed royalty-free under the Pixabay Content Licence. Munyu Munyu maintains full compliance with this licence, which permits use for personal and commercial purposes.
11.2 No Music Ownership Claim
Munyu Munyu and D'Corp Tech expressly disclaim any proprietary ownership of musical compositions used under the Pixabay Licence. No copyright claim is made over any third-party audio content featured on this platform.
11.3 DMCA Safe Harbour & Copyright Takedowns
Munyu Munyu operates in full, good-faith compliance with the DMCA safe harbour provisions and equivalent international copyright frameworks. If you believe any content on this platform infringes your copyright, you may submit a formal written takedown notice to love@munyu.my. Include: (i) identification of the work claimed to be infringed; (ii) identification of the material at issue; (iii) your contact details; (iv) a good-faith statement; and (v) a declaration of accuracy under penalty of perjury. We will investigate and respond within 14 business days.
11.4 User Content & Audio
Any participant who creates, shares, or publishes user-generated content incorporating Munyu Munyu campaign assets or music assumes sole responsibility for copyright compliance in their own jurisdiction. Munyu Munyu accepts no liability for any participant's independent copyright infringement.
ยฉ 2026 Munyu Munyu โ operated exclusively by D'Corp Tech [202603087380 (003837724-U)]. All Rights Reserved Globally & Perpetually.
Terms & Conditions ยท Legal Framework ยท #CONNECT ยท Home