EN · BM

Privacy Policy

Updated 21 September 2026 · Version 2026-09-20-v1

Draft notice

Insan Fikir Sdn. Bhd. (trading as Emas Estate, "we") operates the Emas Estate app and websites at emas.estate and app.emas.estate. If you only read one thing: we collect account, wallet, KYC (including identity documents and biometric liveness data), and transaction data to run a digital-gold service. Email [email protected] to see, correct, or delete your data.

Who is responsible

Insan Fikir Sdn. Bhd.
Registration number: 202601010555 (1672653-H)
Registered postal address: 436, BLOCK 5, LAMAN SERI BUSINESS PARK, PERSIARAN SUKAN, SEKSYEN 13, 40100 SHAH ALAM SELANGOR MALAYSIA
Privacy / data-rights email: [email protected]
Data Protection Officer / PDPA officer: [email protected]

We are the data controller for commercial transactions on this service. This notice is given under Malaysia PDPA 2010 (as amended) section 7, and is also intended to meet the substance of a privacy policy for visitors outside Malaysia.

What we collect, from whom, and why

Account data — username or email, password hash, preferred name. From you, at signup. To create and run your account.

Date of birth — from you, at the age gate before an account is created. To enforce an 18+ rule and to avoid collecting children's data.

Wallet data — Ethereum address, signed login message. From you, at Web3 login. To authenticate you.

Encrypted wallet backup — ciphertext we cannot read. From you, if you enable backup.

KYC / identity — full name, NRIC or passport, date of birth, gender, address, nationality, face-match score, identity-document images, and selfie / liveness frames. From you and from our KYC vendor. Liveness uses on-device face landmarks (blink and head movement) and is biometric processing.

Gold and money — orders, certificates, redemptions, bank details you enter, delivery or collection details.

Device and connection — IP address, user-agent, timestamps. From your browser or app, automatically, including when the site is hosted on Cloudflare.

Supplying account, age, and (for regulated actions) KYC data is obligatory. Marketing email is voluntary; we do not operate a promotional mailer in this product today.

Children

The service is for people 18 or older. We do not knowingly collect personal data from anyone under 18. The age gate asks for date of birth (day, month, year) before an account is created. Contact [email protected] if an account belongs to a child.

Cookies, fonts, and analytics

We do not run session-replay or advertising pixels in this app.

Cloudflare (hosting and the API) sees IP addresses as part of delivering the site. Some Cloudflare accounts also inject Cloudflare Web Analytics (beacon.min.js / cdn-cgi/rum). That beacon is not in our source repository. If it is enabled on the Pages project, it should be turned off in the Cloudflare dashboard until a consent mechanism exists. A banner that does not block the beacon is not consent.

Fonts: the app is built to serve Inter, Playfair Display, and Source Code Pro from our own origin. If an older build still fetches fonts from fonts.gstatic.com, that call sends your IP to Google.

Flutter web may load a graphics engine (CanvasKit). We prefer to serve it from our origin; an older build may load it from gstatic.com.

KYC liveness may load a face-landmark model from a third-party CDN when you start identity verification.

Who we share data with

We do not sell personal data. Processors: Cloudflare (Pages, Workers, D1); kyc.ezy.link (identity verification, including documents, selfies, and liveness frames); the gold collection partner named in the app; the public blockchain (wallet address and certificate events).

How long we keep data

We keep personal data for these periods, then delete it (including from backups after the extra window):

Account, profile, and order records: for the life of the account and 7 years after the account closes.

KYC data, including NRIC, face images, liveness frames, and face-match scores: 7 years after the account closes.

App and server logs: 24 months.

Backups: the same period as the source record, plus 90 days, then delete.

Transfers outside Malaysia

Cloudflare, the KYC vendor, font or model CDNs, and the blockchain may process data outside Malaysia. We rely on the transfer being necessary for the contract and on your consent for KYC.

Your rights

You may request access, correction, portability (where feasible), and deletion, and you may withdraw consent for optional processing. You have an unconditional right to require us to stop processing for direct marketing.

Email [email protected]. This product does not yet expose a self-serve export or delete button — the inbox is the route in. You may complain to the Personal Data Protection Commissioner (Malaysia) or to your local authority.