OMA

OMA TECHNOLOGY SDN BHD

OMA Platform Privacy Notice

Employees • Gig Workers • Cross-Border Recipients • Expense Users • Administrators • Wallet/Card Applicants

  • Working draft
  • Malaysian law
  • Version dated 27 July 2026
  • Private & Confidential

Subject to completion of highlighted particulars and final execution-readiness review.

Language and publication: This is the English legal-review draft. Before personal data is collected in production, OMA must publish and serve a legally reviewed Bahasa Malaysia version together with this English version and complete all [●] fields.

This Privacy Notice explains how OMA TECHNOLOGY SDN BHD (Company No. 202501038728 (1640137-M)) (“OMA”, “we”, “us” or “our”) processes personal data through the OMA Platform and related services.

It applies to individuals who use or are identified in the platform, including corporate administrators, Employees, Gig Workers, cross-border recipients, beneficial owners, expense users, beneficiaries, payees and proposed MPay wallet or card users. “Corporate customer” means a duly incorporated or established body corporate and excludes an individual, sole proprietor, unincorporated partnership or unincorporated association. This Notice should be read with role-specific notices from your employer or engaging organisation and the separate notices and terms of MPay or another Approved Payment Provider.

For this Notice, “corporate customer” means a company, limited liability partnership, statutory body or other body corporate duly incorporated, established or registered under the laws of Malaysia or another jurisdiction approved by OMA. OMA does not onboard a natural person, sole proprietorship, unincorporated partnership, unincorporated association or any person acting principally in an individual or personal capacity as an enterprise customer.

Who controls your personal data

  1. OMA is a data controller where we determine why and how personal data is processed, including for direct account administration, platform security, fraud prevention, legal compliance, service analytics, support and our direct relationship with you.
  2. A corporate customer is generally the data controller for Employee, payroll, task, performance, budget, expense and payment information it submits or instructs OMA to process. For those activities, OMA generally acts as the customer’s data processor.
  3. MPay and another Approved Payment Provider may be independent data controllers for onboarding, KYC, regulated payment services, currency conversion, transaction monitoring, settlement, payout and account administration. Each provider supplies or makes available its own privacy notice and terms.
  4. Legal roles depend on the actual processing and Applicable Law. Contact us if you are unsure which organisation should handle a request.

Personal data we process

  1. Depending on your role and selected services, we may process:

    1. identity data, such as name, NRIC or passport details, nationality, date of birth, photograph, signature and platform identifier;
    2. contact and residence data, such as address, country of residence, telephone number, email and emergency contact;
    3. employment and engagement data, such as employer, role, employee number, work authorisation, contract type, place of service, task profile, qualifications, attendance and status;
    4. payroll, tax and financial data, such as salary, earnings, benefits, deductions, tax residence and identifier, withholding and contribution data, bank or wallet details and payment records;
    5. business and ownership data, such as incorporation, registration, licences, business activity, directors, controllers, authorised representatives and ultimate beneficial ownership;
    6. task and performance data, such as offers, acceptance, location where required, deliverables, completion evidence, ratings, acceptance decisions, disputes and grievances;
    7. budget and expense data, such as allocations, merchant and transaction information, receipts, invoices, explanations, approvals and reconciliation;
    8. wallet/card, cross-border payment and KYC data transmitted to or received from MPay or another provider, such as payer and recipient country, payment purpose, funding and payout currency, exchange-rate and fee information, source of funds or wealth, supporting contract or invoice, application status, account identifiers, transaction status, limits and risk or compliance requests;
    9. device, technical and usage data, such as IP address, device and session identifiers, operating system, app version, authentication events, logs, security signals and cookie or similar data;
    10. communications and support data, such as calls, messages, emails, complaints, survey responses and investigation records; and
    11. sensitive or higher-risk data where necessary, such as biometric or liveness results used for identity verification, health and safety incident information, alleged offences, sanctions or fraud indicators and financial information.
  2. Please do not provide sensitive or unrelated personal data unless it is requested for a stated lawful purpose.

How we obtain personal data

  1. We may obtain personal data:

    1. directly from you when you register, verify identity, accept terms, complete a task, submit an expense, contact support or use the platform;
    2. from the corporate customer that employs, engages, invites or pays you;
    3. from MPay and other Approved Payment Providers, banks, payment schemes, correspondents, intermediary or recipient institutions, identity-verification, fraud-prevention and compliance providers;
    4. from your device and use of the OMA Platform;
    5. from persons you authorise or information you make lawfully public; and
    6. from regulators, courts, law-enforcement agencies and other lawful sources.

Permissions required

The table below describes the permissions the App uses, whether they are required, and the impact if you deny them.

PermissionRequired?Usage scenarioImpact if denied
Network AccessRequiredLogin, API calls, data sync, file upload, KYC review, IP country detectionUnable to use most online features
Precise LocationRequiredLocation-based services and country/region determinationUnable to use location-dependent features
MicrophoneRequiredAudio capture for supported verification featuresUnable to use voice-dependent features
CameraAs neededQR scanning, receipt capture, ID/passport scanning, selfie verification, liveness detectionUnable to use scanning, photo upload, document scanning, or facial verification
Photo LibraryAs neededSelect QR/ID/receipt images from gallery; save “My QR Code” to galleryUnable to select images from gallery or save QR codes
Photo Library WriteAs neededSave “My QR Code” to system photo libraryUnable to save QR code images to gallery
File AccessAs neededSelect jpg, jpeg, png, or pdf files as vouchers or supporting documentsUnable to select and upload documents from file manager
ContactsAs neededContact selection for transfers and invitationsUnable to select or invite contacts in the app
SMS ReadingAs neededAutomatic reading of SMS verification codes where offeredVerification codes may need to be entered manually
Push NotificationAs neededService, payment, task and security notificationsMay miss time-sensitive notifications
Biometrics / Face ID / Touch IDOptionalPost-login identity check, sensitive operation confirmation, account securityCan use password/verification code; biometric quick verification unavailable
Google AccountOptionalGoogle Sign-InUnable to use Google Sign-In; other login methods remain available
Apple AccountOptionalApple Sign-InUnable to use Apple Sign-In; other login methods remain available

Additional notes

  • Camera: Used for QR scanning, document capture, selfie, and liveness verification. Liveness detection video is configured to not capture audio — microphone permission is not requested for this feature.
  • Photo Library: Only used when you actively select gallery images or save QR code images.
  • File Access: Reads only files you actively select via the system file picker; the App does not continuously access your entire file system.
  • Biometrics: Only activated after you explicitly enable the feature.
  • Network Access: A fundamental requirement for App operation; typically does not require a separate pop-up authorization.

Why we process personal data

  1. We process personal data as necessary and lawful to:

    1. create, verify, secure and administer accounts, permissions and organisations;
    2. provide payroll workflow, task and commission administration, budget and expense management, domestic and cross-border payment instructions, reporting and support;
    3. enable MPay or another Approved Payment Provider to conduct onboarding, wallet/card services, currency conversion, settlement or payout and communicate account or transaction status;
    4. verify payer, recipient, ownership, source of funds and payment purpose and support customer, tax, foreign-exchange and regulatory due diligence;
    5. authenticate users, prevent impersonation, fraud, misuse, money laundering, proliferation financing, sanctions breaches and security incidents;
    6. calculate, display and record wages, earnings, deductions, social-security contributions, expenses and payments based on customer instructions;
    7. match, sort or recommend tasks, apply eligibility and customer-configured rules, and provide human review where required;
    8. investigate complaints, disputes, safety incidents, unauthorised transactions and legal claims;
    9. communicate service, security, legal, consent, task, payment and support information;
    10. maintain records, conduct audits, comply with law and respond to courts, regulators and authorities;
    11. operate, monitor, troubleshoot, measure, secure and improve the OMA Platform; and
    12. send marketing only where permitted and honour your opt-out choices.

Consent and other processing conditions

  1. Where the Personal Data Protection Act 2010 requires consent, we or the responsible corporate customer will request it through an appropriate notice or affirmative action. Express consent will be requested for sensitive personal data where required.
  2. Some processing is necessary to perform a contract you request, to comply with law, for legal proceedings, to protect vital interests or under another statutory condition. We will rely on the condition applicable to the particular processing.
  3. You may withdraw consent by contacting us, subject to legal, contractual and technical limits. Withdrawal does not affect processing already lawfully completed and may mean that an optional or essential service can no longer be provided.

Mandatory and optional data

  1. Data marked mandatory, or reasonably required for identity, ownership, source of funds, payment purpose, security, payroll, task, payment, KYC, sanctions or legal compliance, must be provided for the relevant service. If it is not provided or cannot be verified, OMA, the corporate customer, MPay or another Approved Payment Provider may be unable to create an account, offer or pay a task, process payroll, issue a wallet/card or complete a transaction.
  2. Optional profile, survey and marketing data may be declined without losing unrelated core services.

Automated systems

  1. The OMA Platform may use automated rules or models to:

    1. check data consistency, identity-verification completeness, device risk and duplicate accounts;
    2. screen persons, countries, devices, behaviour and transactions for fraud, sanctions, financial crime, security, limits or unusual patterns;
    3. sort, filter or recommend tasks using profile, eligibility, availability, location or customer criteria;
    4. apply customer-configured permissions, budgets, approvals and deadlines; and
    5. flag an account, task or transaction for manual review.
  2. Automated outputs may affect visibility, delay, review or access. A corporate customer ordinarily makes final recruitment, task-performance and employment decisions. Where required by law, you may request non-automated review through [●].

Who may receive personal data

  1. We may disclose personal data, limited to what is reasonably necessary, to:

    1. the corporate customer that employs, engages, invites or administers you and its authorised personnel;
    2. MPay and other Approved Payment Providers, banks, Mastercard and other payment schemes, correspondents, intermediary and recipient institutions, foreign-exchange providers, merchants and payment recipients;
    3. identity-verification, KYC/KYB, beneficial-ownership, fraud-prevention, sanctions-screening, adverse-media and security providers;
    4. cloud hosting, communications, customer-support, analytics, software, professional and audit providers;
    5. PERKESO, tax, labour, occupational-safety, data-protection and other authorities where required or permitted;
    6. courts, law-enforcement agencies, regulators, insurers, auditors, lawyers and advisers;
    7. an acquirer, investor or successor involved in a bona fide corporate transaction, subject to confidentiality and lawful safeguards; and
    8. another person you authorise or where disclosure is otherwise required or permitted by law.
  2. We do not sell personal data. We do not disclose it for an unrelated third party’s marketing without the required consent.

Cross-border transfers

  1. Some approved service providers or support personnel may process personal data outside Malaysia in the following countries or regions: [●]. The current subprocessor and transfer record and, where applicable, the Corridor Notice or transaction disclosure identify the relevant recipient classes and locations.
  2. If you are involved in a cross-border payment, the minimum necessary identity, residence, tax, task, payment-purpose, source-of-funds, screening and transaction data may be processed in the payer country, recipient country and countries used by payment providers, schemes, correspondents or intermediary institutions. Those locations vary by corridor and transaction.
  3. Before a transfer, the responsible data controller will identify and document a condition permitted by section 129 of the Personal Data Protection Act 2010, such as substantially similar law, adequate protection, consent, contractual necessity or reasonable precautions and due diligence.
  4. Safeguards may include contractual data-protection clauses, transfer impact assessment, encryption, access controls, provider or subprocessor review and records of the countries, recipients, data, purpose, transfer condition and safeguards. If relied-on protection materially fails, we will suspend, refuse or remediate the transfer as required.

Security

  1. We use reasonable administrative, technical and physical safeguards appropriate to the nature and risk of processing. These may include role-based access, multi-factor authentication for privileged access, encryption, logging, monitoring, secure development, vulnerability management, backups, vendor controls and incident-response procedures.
  2. No system is completely secure. You must protect credentials, devices, cards, OTPs and exported records and immediately report suspected compromise through [●].

Retention

  1. We retain personal data only for as long as reasonably necessary for the stated purposes, the customer’s lawful instructions, pending transactions or disputes, fraud prevention, audit, defence of claims and legal or regulatory retention.
  2. Retention depends on the data and role. Criteria include the duration of the account, employment or task relationship; statutory payroll, tax, social-security, safety, KYC, sanctions and domestic or cross-border transaction periods; payment-provider requirements; limitation periods; legal holds; and secure backup cycles.
  3. When data is no longer required, we delete or irreversibly anonymise it. Controller records, audit and consent evidence, transaction evidence and de-identified analytics may be retained for lawful compliance purposes.

Your rights

  1. Subject to the Personal Data Protection Act 2010 and applicable exceptions, you may:

    1. ask whether we process your personal data and request access;
    2. request correction of inaccurate, incomplete, misleading or outdated data;
    3. withdraw consent for processing based on consent;
    4. request that processing likely to cause unwarranted damage or distress cease;
    5. object to or opt out of direct marketing; and
    6. request transmission of your personal data to another data controller where the statutory portability right applies, the requested format and destination are supported, and transmission is technically feasible; and
    7. complain to us or the Personal Data Protection Commissioner.
  2. Submit a request to connect@oma.xyz. We may verify your identity and authority, ask for clarification, charge a permitted fee, refuse or limit a request where law allows, and direct you to the corporate customer, MPay or another Approved Payment Provider where that organisation controls the data.

Data breach communications

  1. We maintain procedures to assess and respond to an actual or reasonably suspected personal data breach, including circumstances giving reasonable grounds to believe that a breach occurred. Where the law requires notification to affected data subjects, the responsible data controller will provide information about the breach, likely effects and protective steps through an appropriate channel.

Children

  1. The OMA Platform is intended for persons aged 18 or older. Do not create an account for a child. Contact us if you believe a child’s personal data has been provided without lawful authority.

Direct marketing

  1. Service, security, payroll, task, payment and legal messages are not marketing and may be necessary for the service. You may opt out of promotional messages using the unsubscribe function or contacting [●].

Changes to this notice

  1. We may update this Notice for legal, product, security or operational changes. We will publish the updated date and give reasonable notice of a material change. Where a new purpose requires consent, we will request it before that processing.

Contacts

Contacts
ContactDetails
OrganisationOMA TECHNOLOGY SDN BHD (Company No. 202501038728 (1640137-M))
Address30A, Jalan 17/155C, Bandar Bukit Jalil, 57000 Kuala Lumpur, Malaysia
Privacy contactconnect@oma.xyz
Phone+603 86914210
Personal Data Protection CommissionerRefer to the Commissioner’s current official contact and complaint channels

Last updated: 27 July 2026 (working draft).