1Introduction
This Data Processing Agreement / Data Protection Addendum ("Addendum") forms part of the Terms of Service / Merchant Technology Services Agreement between EXICASH SDN BHD ("EXICASH", "we", "us", or "our") and the merchant, organisation, company, sole proprietor, partnership, association, NGO, or other accepted entity using EXICASH services ("Merchant", "you", or "your").
This Addendum explains how personal data is processed when you use EXICASH's technology services, including our merchant dashboard, APIs, plugins, webhooks, payment links, QR payment tools, reconciliation dashboard, settlement report display, fraud monitoring tools, white-label frontend, onboarding support, KYB/KYC document collection, technical support, and related services.
This Addendum should be read together with EXICASH's Terms of Service, Privacy Policy, Partner / Third-Party Payment Provider Disclosure, Information Security Policy or Security Statement, AML/CFT & Sanctions Compliance Statement, Anti-Bribery / Anti-Corruption Policy, Referral Partner Agreement, and any other policies, agreements, or notices issued by EXICASH from time to time.
2Important Role Clarification
EXICASH provides technology, integration, dashboard, reporting, onboarding support, communication support, and technical support only.
Regulated payment processing, acquiring, settlement, payout, refund processing, chargeback handling, transaction reversal, transaction holding, and related regulated payment services are provided by licensed or registered banks, acquirers, e-money issuers, payment gateways, payment processors, wallet providers, BNPL providers, card schemes, payment networks, and other regulated payment partners where applicable ("Licensed Payment Partners").
For personal data processing, EXICASH may act in different capacities depending on the situation:
- as a data processor when processing certain personal data on behalf of the Merchant to provide EXICASH services;
- as a data controller / data user where EXICASH determines the purpose and manner of processing for its own business, security, compliance, billing, risk, legal, accounting, audit, fraud prevention, service improvement, or regulatory purposes;
- as a facilitator of data sharing with Licensed Payment Partners, who may act as independent data controllers / data users for regulated payment, onboarding, settlement, risk, compliance, refund, chargeback, and regulatory purposes.
3Purpose of This Addendum
The purpose of this Addendum is to:
- set out each party's responsibilities for personal data protection;
- describe the personal data processed through EXICASH services;
- explain how Merchant, Consumer, Authorised User, KYB/KYC, transaction, API, webhook, support, and fraud data may be processed;
- confirm the Merchant's responsibility to provide privacy notices and obtain required consent;
- set out security, confidentiality, breach notification, sub-processor, data retention, and deletion requirements;
- support compliance with the Personal Data Protection Act 2010 of Malaysia, as amended from time to time, and other applicable data protection laws.
4Definitions
For the purpose of this Addendum:
"Account" means the account, dashboard access, API access, or service profile created for a Merchant to use EXICASH services.
"Authorised User" means any person authorised by the Merchant to access or use the EXICASH account, dashboard, API, plugin, reports, or services.
"Consumer" or "Payer" means an individual or entity making payment to a Merchant through payment flows supported by EXICASH technology and Licensed Payment Partners.
"Data Controller" or "Data User" means the party that determines the purposes and means of processing personal data.
"Data Processor" means the party that processes personal data on behalf of a Data Controller / Data User.
"Data Subject" means an individual whose personal data is processed.
"Licensed Payment Partner" means any licensed bank, registered merchant acquirer, e-money issuer, payment gateway, financial institution, card processor, e-wallet provider, BNPL provider, payout provider, or other regulated payment partner involved in payment processing, acquiring, settlement, refund, chargeback, payout, risk review, or related regulated services.
"Personal Data" means any information relating directly or indirectly to an identified or identifiable individual.
"Processing" means collecting, recording, holding, storing, organising, adapting, altering, retrieving, using, disclosing, transmitting, transferring, sharing, blocking, erasing, destroying, analysing, or otherwise handling personal data.
"Sub-Processor" means a third-party service provider engaged by EXICASH to process personal data in connection with EXICASH services.
"Transaction Data" means information relating to payment attempts, payment status, payment references, payment method type, transaction history, settlement reports, refund status, chargeback status, reversals, IP address, device data, API logs, webhook logs, fraud signals, risk indicators, and related payment metadata.
5Scope of Processing
This Addendum applies to personal data processed by EXICASH in connection with the provision of EXICASH services, including:
- merchant onboarding;
- KYB/KYC document collection;
- dashboard access;
- API and webhook integration;
- payment link creation;
- QR payment integration;
- FPX, DuitNow QR, card, e-wallet, BNPL, payout, and disbursement connectivity;
- recurring billing and subscription tools;
- split payment configuration;
- reconciliation and settlement report display;
- fraud monitoring tools;
- technical support;
- white-label payment frontend;
- support ticket handling;
- Licensed Payment Partner communication;
- service security and monitoring.
This Addendum does not apply to personal data processed independently by the Merchant outside EXICASH services, or personal data processed independently by Licensed Payment Partners under their own terms and privacy policies.
6Categories of Data Subjects
The personal data processed under this Addendum may relate to:
- Merchants;
- directors;
- shareholders;
- beneficial owners;
- business owners;
- office bearers;
- authorised representatives;
- Authorised Users;
- employees or contractors of the Merchant;
- Consumers or Payers;
- referral partners;
- business partners;
- service provider representatives;
- support contacts;
- any other individual whose personal data is provided to EXICASH by or on behalf of the Merchant.
7Categories of Personal Data
The personal data processed under this Addendum may include:
7.1 Merchant and Business Contact Data
- company or business name;
- business registration number;
- business address;
- business email;
- business phone number;
- website, social media, or store URL;
- business category;
- nature of business;
- product or service information.
7.2 Authorised User Data
- full name;
- email address;
- mobile number;
- job title or role;
- username;
- encrypted password credentials;
- access permissions;
- dashboard activity;
- login records;
- security logs;
- support history.
7.3 Director, Shareholder, Beneficial Owner, and Representative Data
- full name;
- NRIC or passport details;
- date of birth;
- nationality;
- address;
- contact details;
- role or designation;
- ownership percentage;
- identification documents;
- proof of address;
- politically exposed person or sanctions screening information, where applicable;
- beneficial ownership information.
7.4 KYB/KYC and Onboarding Documents
- SSM statutory documents;
- company profile;
- director and shareholder documents;
- NRIC or passport copies;
- bank statements;
- business bank account details;
- licences, permits, or approvals;
- tax information;
- proof of business address;
- website or product information;
- onboarding forms;
- compliance declarations;
- any other documents requested by EXICASH or Licensed Payment Partners.
7.5 Consumer and Payer Data
- payer name;
- payer email address;
- payer phone number;
- payment reference;
- transaction amount;
- transaction date and time;
- payment method type;
- payment status;
- masked payment details, where applicable;
- IP address;
- device information;
- payment page activity;
- fraud or risk indicators;
- receipt or payment confirmation details.
7.6 Transaction, API, and Technical Data
- transaction history;
- payment attempts;
- successful, failed, pending, cancelled, refunded, reversed, or disputed transactions;
- transaction reference numbers;
- acquirer or payment partner references;
- settlement report information;
- reconciliation data;
- API request and response logs;
- webhook logs;
- plugin logs;
- sandbox and production environment activity;
- IP address;
- device information;
- browser information;
- error codes;
- system response data;
- fraud monitoring data;
- risk scoring information.
7.7 Support and Communication Data
- support ticket details;
- email correspondence;
- phone or chat records, where applicable;
- screenshots;
- technical logs;
- issue descriptions;
- resolution notes;
- feedback;
- complaint information.
8Nature and Purpose of Processing
EXICASH may process personal data for the following purposes:
- providing technology services;
- creating and managing merchant accounts;
- creating sub-user or admin access upon request;
- providing dashboard, API, webhook, plugin, and white-label frontend access;
- supporting payment gateway integration;
- generating payment links;
- displaying transaction status;
- displaying reconciliation and settlement reports;
- assisting with onboarding and KYB/KYC document collection;
- submitting documents to Licensed Payment Partners;
- supporting payment method approval;
- providing technical support;
- maintaining platform security;
- monitoring API usage and webhook activity;
- detecting fraud, suspicious activity, credential compromise, and prohibited business activity;
- supporting AML/CFT and sanctions compliance controls;
- maintaining billing and invoice records;
- managing monthly subscriptions, MDR markups, integration fees, and API usage fees;
- responding to partner, regulator, law enforcement, or legal requests;
- complying with legal, audit, tax, accounting, and regulatory obligations;
- improving EXICASH services.
9Duration of Processing
EXICASH will process personal data for as long as necessary to provide services, fulfil the purposes described in this Addendum and the Privacy Policy, comply with legal and regulatory obligations, support Licensed Payment Partner requirements, resolve disputes, prevent fraud, maintain audit records, enforce agreements, and protect legal rights.
Certain records, including transaction records, KYB/KYC documents, bank account records, onboarding documents, support records, fraud monitoring records, API logs, webhook logs, invoices, and compliance records, may be retained for up to seven (7) years or such longer period as may be required or permitted by law, regulatory requirements, partner requirements, tax obligations, accounting obligations, audit requirements, dispute handling, or legal proceedings.
10Merchant Instructions
Where EXICASH acts as a Data Processor, EXICASH will process personal data in accordance with:
- these Terms;
- the Terms of Service;
- the Privacy Policy;
- this Addendum;
- the Merchant's documented instructions;
- applicable partner requirements;
- applicable law.
The Merchant's documented instructions include instructions given through the dashboard, APIs, webhooks, plugins, payment links, onboarding forms, email communication, support requests, service configurations, and written agreements.
EXICASH is not required to follow any instruction that is unlawful, technically impossible, inconsistent with these Terms, inconsistent with Licensed Payment Partner requirements, or likely to expose EXICASH to security, legal, regulatory, financial, operational, or reputational risk.
11EXICASH as Independent Controller / Data User
EXICASH may process certain personal data as an independent Data Controller / Data User for its own legitimate business, operational, security, compliance, legal, regulatory, accounting, audit, and risk management purposes.
This may include processing personal data for:
- account administration;
- billing and invoice management;
- internal record keeping;
- fraud prevention;
- suspicious activity review;
- AML/CFT and sanctions compliance support;
- legal defence;
- regulatory cooperation;
- service security;
- platform improvement;
- partner reporting;
- audit;
- enforcement of EXICASH's Terms and policies;
- investigation of prohibited or restricted business activity;
- business continuity and disaster recovery.
Where EXICASH acts as an independent Data Controller / Data User, EXICASH will process personal data in accordance with its Privacy Policy and applicable law.
12Licensed Payment Partners as Independent Parties
Licensed Payment Partners may act as independent Data Controllers / Data Users for their own regulated payment, onboarding, settlement, payout, refund, chargeback, risk, compliance, fraud prevention, AML/CFT, sanctions, reporting, and legal purposes.
EXICASH may share personal data with Licensed Payment Partners where necessary to support onboarding, merchant approval, payment method approval, transaction processing support, settlement reporting, fraud monitoring, dispute handling, partner compliance, or legal requirements.
The Merchant acknowledges that Licensed Payment Partners may process personal data under their own terms, privacy policies, legal obligations, regulatory requirements, and risk controls.
EXICASH is not responsible for the independent processing activities of Licensed Payment Partners, except to the extent required by applicable law or agreed in writing.
13Merchant Responsibilities
The Merchant is responsible for ensuring that all personal data provided to EXICASH is collected, used, disclosed, and transferred lawfully.
The Merchant must:
- provide appropriate privacy notices to Consumers, Payers, Authorised Users, directors, shareholders, beneficial owners, representatives, employees, contractors, and other relevant individuals;
- obtain all required consents, authorisations, and approvals;
- ensure that personal data provided to EXICASH is accurate, complete, current, and not misleading;
- ensure that Consumers understand that payment and transaction data may be processed by EXICASH and Licensed Payment Partners;
- ensure that KYB/KYC documents are submitted lawfully;
- ensure that personal data is not excessive, irrelevant, or unnecessary;
- comply with applicable personal data protection laws;
- respond to data subject requests where the Merchant is responsible for the relevant data;
- maintain appropriate security controls for its own systems, websites, devices, plugins, API keys, credentials, and staff access;
- notify EXICASH promptly of any actual or suspected data breach, API key leak, unauthorised access, security compromise, or misuse that may affect EXICASH services or data processed through EXICASH.
14Consumer Privacy Notices
The Merchant must make available a clear privacy notice or privacy policy to Consumers and Payers.
The Merchant's privacy notice should explain, where applicable, that:
- the Merchant collects Consumer and payment-related data;
- payment-related data may be processed through EXICASH technology;
- payment processing may be handled by Licensed Payment Partners;
- transaction data may be used for payment confirmation, fraud monitoring, dispute handling, refunds, chargebacks, reconciliation, reporting, compliance, and security;
- EXICASH and Licensed Payment Partners may process limited Consumer payment information where necessary;
- Consumers should contact the Merchant for goods, services, delivery, refund, cancellation, warranty, or customer service matters.
The Merchant remains responsible for its relationship with Consumers and for compliance with consumer-facing privacy obligations.
15Restrictions on Personal Data Submitted to EXICASH
The Merchant must not submit unnecessary, excessive, unlawful, false, misleading, or unauthorised personal data to EXICASH.
Unless specifically requested by EXICASH or a Licensed Payment Partner, the Merchant must not submit sensitive personal data, health data, religious information, political opinions, biometric data, criminal offence data, children's data, or other sensitive information through support tickets, APIs, webhooks, forms, emails, or documents.
If sensitive personal data is required for a lawful and specific purpose, the Merchant must ensure that all required notices, consents, and safeguards are in place.
16Security Measures
EXICASH will implement reasonable technical, organisational, and administrative security measures to protect personal data processed through EXICASH services.
Such measures may include:
- access controls;
- authentication controls;
- role-based permissions;
- encryption where appropriate;
- secure hosting;
- monitoring and logging;
- backup procedures;
- vulnerability management;
- incident response procedures;
- API security controls;
- internal access restrictions;
- staff confidentiality obligations;
- system maintenance;
- service provider due diligence;
- secure transmission protocols where appropriate.
EXICASH may update its security measures from time to time to address changes in technology, threats, legal requirements, partner requirements, and business operations.
17PCI and Payment Data Security
EXICASH maintains PCI certification relevant to its role and service scope.
Where card payment functionality is made available, card processing may be handled by Licensed Payment Partners, payment processors, tokenisation providers, or other authorised payment service providers.
The Merchant must not collect, store, process, transmit, expose, or misuse cardholder data or sensitive authentication data except through authorised EXICASH or Licensed Payment Partner payment flows and in accordance with PCI DSS requirements, Licensed Payment Partner rules, card scheme rules, and EXICASH instructions.
The Merchant is solely responsible for any cardholder data or sensitive payment data handled outside authorised payment flows.
18API Key, Credential, and Integration Security
The Merchant is responsible for keeping API keys, tokens, passwords, webhook secrets, login credentials, dashboard access, plugin credentials, and integration details confidential and secure.
The Merchant must:
- restrict access to authorised personnel only;
- use secure systems and devices;
- rotate credentials where necessary;
- immediately revoke access for former staff or unauthorised users;
- monitor suspicious activity;
- secure webhook endpoints;
- protect plugins and websites from compromise;
- notify EXICASH immediately of any suspected credential leak, unauthorised access, API misuse, or system compromise.
If API keys, credentials, webhooks, plugins, or Merchant systems are leaked, compromised, shared, stolen, exposed, or used for prohibited activity, the Merchant shall bear responsibility for the consequences, except to the extent caused by EXICASH's proven negligence or wilful misconduct.
EXICASH may suspend, rotate, revoke, restrict, or disable API access where necessary for security, partner instruction, compliance, investigation, prohibited activity, or suspected misuse.
19Confidentiality
EXICASH will ensure that personnel authorised to process personal data are subject to appropriate confidentiality obligations.
The Merchant must also ensure that its employees, officers, Authorised Users, contractors, developers, service providers, and representatives who access EXICASH services or personal data are subject to appropriate confidentiality obligations.
Confidentiality obligations survive termination of the Merchant's use of EXICASH services.
20Sub-Processors and Service Providers
The Merchant authorises EXICASH to engage Sub-Processors and service providers where necessary to provide EXICASH services.
Sub-Processors may include providers of:
- cloud hosting;
- database storage;
- cybersecurity;
- monitoring and logging;
- email delivery;
- SMS or notification services;
- customer support tools;
- fraud monitoring;
- device intelligence;
- KYB/KYC verification;
- sanctions screening;
- analytics;
- backup and disaster recovery;
- technical infrastructure;
- professional services.
EXICASH will take reasonable steps to ensure that Sub-Processors handling personal data are subject to appropriate confidentiality, security, and data protection obligations.
EXICASH remains responsible for its Sub-Processors to the extent required by applicable law and subject to the limitations in the Terms of Service.
21Data Sharing with Licensed Payment Partners
The Merchant authorises EXICASH to share personal data with Licensed Payment Partners where necessary for:
- onboarding;
- KYB/KYC review;
- merchant approval;
- payment method approval;
- transaction processing support;
- settlement reporting;
- fraud monitoring;
- risk review;
- refund support;
- chargeback support;
- dispute support;
- suspicious activity investigation;
- compliance review;
- legal or regulatory requirements.
Licensed Payment Partners may request additional documents or information directly from the Merchant or through EXICASH.
EXICASH may withhold, delay, restrict, or suspend service access if required information is not provided, if a Licensed Payment Partner requires additional review, or if data sharing is necessary to comply with partner or legal requirements.
22International Transfers
EXICASH is based in Malaysia and supports Malaysia-based Merchants. However, personal data may be processed, stored, accessed, or transferred outside Malaysia where EXICASH, Licensed Payment Partners, Sub-Processors, cloud providers, fraud monitoring providers, verification providers, or support providers operate internationally.
Where personal data is transferred or accessed internationally, EXICASH will take reasonable steps to ensure that appropriate safeguards are in place and that the transfer complies with applicable data protection requirements.
The Merchant must ensure that it has provided all necessary notices and obtained all necessary consents for such transfers where required.
23Data Subject Requests
If EXICASH receives a request from a Data Subject relating to personal data processed on behalf of the Merchant, EXICASH may:
- direct the Data Subject to contact the Merchant;
- notify the Merchant of the request where appropriate;
- assist the Merchant on a reasonable and commercially practicable basis;
- respond directly where EXICASH acts as an independent Data Controller / Data User;
- respond as required by law or regulatory authority.
The Merchant remains responsible for responding to Data Subject requests where the Merchant is the Data Controller / Data User.
The Merchant must provide reasonable assistance to EXICASH where a Data Subject request relates to data processed by EXICASH as an independent Data Controller / Data User or where required for legal compliance.
24Data Breach and Security Incidents
If EXICASH becomes aware of a personal data breach or security incident affecting personal data processed through EXICASH services, EXICASH will assess the incident and take reasonable steps to contain, investigate, remediate, and document the incident.
Where required by applicable law, EXICASH may notify the relevant authority and/or affected Data Subjects within the required timeframe.
If the breach relates to personal data processed on behalf of the Merchant, EXICASH will notify the Merchant without undue delay after becoming aware of the breach, where legally and practically possible.
The Merchant must notify EXICASH immediately if it becomes aware of any actual or suspected:
- personal data breach;
- unauthorised access;
- API key leak;
- credential exposure;
- webhook compromise;
- plugin compromise;
- malware infection;
- system compromise;
- fraud incident;
- unauthorised transaction activity;
- suspicious activity affecting EXICASH services.
The Merchant must cooperate with EXICASH in investigating, containing, remediating, and reporting security incidents.
25Audit and Compliance Support
Upon reasonable written request, EXICASH may provide information reasonably necessary to demonstrate compliance with this Addendum, subject to confidentiality, security, legal, commercial sensitivity, and operational restrictions.
EXICASH is not required to disclose information that may compromise security, reveal confidential information of other merchants, breach legal obligations, expose trade secrets, or interfere with EXICASH operations.
Where an audit is required by law or agreed in writing, the scope, timing, method, confidentiality requirements, and costs must be agreed in advance.
The Merchant is responsible for its own audit, legal, data protection, cybersecurity, PCI, and compliance obligations.
26Return, Deletion, and Retention of Data
Upon termination of EXICASH services, the Merchant may request deletion or return of personal data processed by EXICASH on behalf of the Merchant, subject to technical feasibility, legal requirements, partner requirements, retention obligations, security needs, audit requirements, dispute handling, fraud prevention, accounting requirements, tax requirements, backup retention, and EXICASH's legitimate business purposes.
EXICASH may retain personal data where necessary to:
- comply with law;
- comply with partner requirements;
- maintain transaction and audit records;
- resolve disputes;
- prevent fraud;
- support AML/CFT and sanctions compliance;
- enforce agreements;
- protect legal rights;
- maintain accounting and tax records;
- investigate suspicious activity;
- meet security and operational requirements.
Personal data retained after termination will remain protected in accordance with this Addendum, the Privacy Policy, and applicable law.
27Accuracy and Updates
The Merchant must ensure that personal data provided to EXICASH is accurate, complete, current, and not misleading.
The Merchant must promptly update EXICASH if there are changes to:
- company information;
- authorised representatives;
- directors;
- shareholders;
- beneficial owners;
- business address;
- bank account details;
- contact details;
- nature of business;
- product or service information;
- licences or permits;
- website or social media information;
- data protection contact;
- security contact.
EXICASH is not responsible for onboarding delays, rejected applications, failed communications, inaccurate reports, partner rejection, payment method issues, or service interruptions caused by inaccurate, incomplete, or outdated information provided by the Merchant.
28Merchant Use of Reports and Transaction Data
EXICASH may provide transaction reports, settlement report display, reconciliation dashboards, fraud monitoring indicators, and payment status information.
Such information is provided for operational and reconciliation purposes only and may depend on data received from Licensed Payment Partners.
The Merchant must use reports and transaction data lawfully and only for legitimate business purposes, including reconciliation, accounting, customer support, fraud prevention, refund handling, chargeback evidence, and compliance.
The Merchant must protect reports and transaction data against unauthorised access, disclosure, misuse, alteration, or loss.
29Processing for Fraud, AML/CFT, and Sanctions Purposes
EXICASH may process personal data and transaction data for fraud prevention, prohibited business checks, AML/CFT support, sanctions screening support, risk monitoring, suspicious activity detection, and compliance cooperation.
This may include sharing relevant information with Licensed Payment Partners, banks, acquirers, payment networks, e-wallet providers, BNPL providers, verification providers, fraud monitoring providers, regulators, law enforcement agencies, or professional advisers where necessary.
The Merchant agrees to cooperate with EXICASH and Licensed Payment Partners by providing information, documents, explanations, transaction evidence, customer details, fulfilment records, and other materials reasonably required for investigation or compliance purposes.
30Limitation of Liability
The liability of each party under this Addendum shall be subject to the limitations and exclusions of liability set out in the Terms of Service, unless such limitation is not permitted by applicable law.
Nothing in this Addendum limits liability that cannot be limited under applicable law.
31Indemnity
The Merchant agrees to indemnify and hold harmless EXICASH, its directors, officers, employees, agents, service providers, and partners from and against any claims, losses, penalties, fines, damages, costs, liabilities, and expenses arising from:
- the Merchant's breach of this Addendum;
- unlawful collection or disclosure of personal data by the Merchant;
- failure to provide privacy notices or obtain required consent;
- inaccurate, incomplete, excessive, or misleading personal data provided by the Merchant;
- unauthorised submission of sensitive personal data;
- Consumer complaints relating to the Merchant's privacy practices;
- Merchant system compromise;
- leaked or compromised API keys caused by the Merchant;
- unauthorised access caused by the Merchant, its staff, contractors, or systems;
- breach of data protection laws by the Merchant;
- claims by Consumers, Authorised Users, directors, shareholders, beneficial owners, regulators, Licensed Payment Partners, or third parties arising from the Merchant's handling of personal data.
32Conflict
If there is any conflict between this Addendum and the Terms of Service regarding the processing of personal data, this Addendum shall prevail only to the extent of that conflict.
If there is any conflict between this Addendum and the Privacy Policy regarding EXICASH's own processing of personal data as an independent Data Controller / Data User, the Privacy Policy shall prevail.
If there is any conflict between this Addendum and the terms of a Licensed Payment Partner regarding the Licensed Payment Partner's independent processing of personal data, the Licensed Payment Partner's terms shall prevail for that partner's processing activities.
33Changes to This Addendum
EXICASH may update, amend, or replace this Addendum from time to time to reflect changes in law, regulation, partner requirements, data protection practices, security standards, technology, or business operations.
The updated Addendum may be published on EXICASH's website, dashboard, or notified by email or other communication channels.
Your continued use of EXICASH services after the updated Addendum becomes effective means that you accept the revised Addendum.
34Governing Law
This Addendum shall be governed by and interpreted in accordance with the laws of Malaysia.
Any dispute arising from or relating to this Addendum shall be handled in accordance with the dispute resolution and governing law provisions in EXICASH's Terms of Service.
35Contact
For questions about this Addendum or personal data processing matters, please contact:
EXICASH SDN BHD
Company Registration No.: 202601015752 (1677849-M)
Address: 16-19, Menara Mutiara Sentral, No. 2, Jalan Desa Aman 1, Cheras Business Centre, 56000 Kuala Lumpur, Malaysia
Email: support@exicash.com
Website: www.exicash.com