Privacy Policy
This policy explains the personal data we collect, how we use it, and your rights — for both the TecerTools web application and the Parent Portal.
Last updated: 3 Julai 2026 / 3 July 2026
View the PBD Extension Privacy Policy →1. Introduction
TecerTools ("we", "us", "the app") is a teacher task-management platform for teachers in Malaysia. This Privacy Policy covers two parts of the service: (a) the TecerTools web application used by teachers, and (b) the Parent Portal that lets parents/guardians view their child’s records.
The data controller responsible for your personal data is TECERTOOLS DIGITAL SOLUTION (address: Indahria Apartment, Persiaran Teknologi Subang, Seksyen 22, 40300 Shah Alam, Selangor), the operator of TecerTools. Please contact us at the address in the final section of this policy for any privacy-related questions.
This policy is prepared in accordance with Malaysia’s Personal Data Protection Act 2010 (PDPA) and its 2024 amendments now in force, including the requirements on data breach notification, data portability, and a Data Protection Officer. Read Act 709 on pdp.gov.my
2. Data we collect
(a) Teacher account data. When you register and use the app, we collect:
- Your name, email address, and (if you sign in with Google) your Google display name and profile photo
- Teacher profile details: school, subjects, classes, and schedule settings
- In-app activity records such as error logs for maintenance purposes
(b) Student and parent data entered by teachers. As part of your official duties, the app stores data you enter about students:
- Student names and identity card (IC) numbers
- Marks, grades, mastery levels (PBD / classroom assessment), attendance records, observations, and character tokens
- Assignment or project evidence (including photos) that is uploaded
- Parent/guardian contact numbers recorded for class communication
Some of this data concerns children (minors) and IC numbers, which we treat as sensitive and protect with additional safeguards.
(c) Parent Portal data. When a parent/guardian accesses the portal, we process the class code entered, part of an IC number to verify the child’s identity, an anonymous session created for access, and any evidence uploaded by the parent. Parents do not need to create an account.
3. Purposes of processing
We process personal data only for the following purposes, in line with the PDPA’s Notice & Choice and Purpose principles:
- Providing the app’s core functions: class management, scheduling, assessment, attendance, and reporting
- Authenticating users and maintaining a secure signed-in session
- Allowing parents/guardians to view their child’s performance records via the Parent Portal
- Maintaining, debugging, and improving the security and reliability of the service
We do not sell your personal data, do not display advertising, and do not use your data for third-party marketing.
4. Legal basis & consent
Teachers enter student data in the course of their official duties as educators. Teachers are responsible for ensuring the collection of student data complies with school and Ministry of Education Malaysia policies. For the Parent Portal, parents/guardians provide consent by accessing the portal and verifying their child’s identity.
You may withdraw consent at any time by contacting us, although this may limit your ability to use parts of the service.
5. Sharing & data processors
We use Google Firebase (Firebase Authentication, Cloud Firestore, and Firebase Storage) as data processors to store and manage data securely. Google processes this data on our behalf under its data protection terms.
Cross-border transfer: Data is stored in Google Cloud data centres in the asia-southeast region (Singapore). This means your data may be processed outside Malaysia. We take reasonable steps to ensure the data is protected to a standard comparable with the PDPA during such transfers.
We do not share personal data with any other third parties except where required by law or a valid court order.
6. Storage & retention
- Student data (names, IC, marks, attendance, PBD, evidence) is retained through the school year and deleted at the end of the school year.
- Teacher account data is retained while your account is active, and deleted when you request account deletion.
- Anonymous parent sessions are temporary and are not linked to a permanent account.
7. Security
We protect data with technical measures including Firestore security rules that restrict access to the data owner (the authenticated teacher) only, email verification for teacher accounts, parent access through anonymous sessions with IC verification, and encrypted data transmission (HTTPS). No system is entirely risk-free, however; we encourage you to keep your sign-in details confidential.
8. Your rights
Under the PDPA, you have the right to:
- Access the personal data we hold about you
- Correct data that is inaccurate or incomplete
- Withdraw consent and request deletion of data
- Request data portability (transfer of your data in a readable format) in line with the PDPA 2024 amendments
To exercise any of these rights, contact us at the address in the final section of this policy.
9. Data breach notification
In line with the PDPA 2024 amendments, in the event of a personal data breach that may cause significant harm, we will notify the Personal Data Protection Commissioner and, where required, affected individuals, within the timeframe set by law.
10. Contact us about personal data
For any questions, access/correction requests, or complaints regarding your personal data, please contact TECERTOOLS DIGITAL SOLUTION at: tecertools@gmail.com
11. Changes to this policy
If this policy changes, the "Last updated" date above will be revised. Material changes will be shown here before they take effect.