Privacy & PDPA

Privacy & Personal Data Protection Policy

Effective Date: 12 August 2026Last Updated: 12 August 2026

1. Introduction

This Privacy & Personal Data Protection Policy (“Privacy Policy”) explains how Little Grappy Running Academy (“LGRA”, “we”, “us” or “our”) collects, records, stores, uses, discloses, transfers, retains and otherwise processes personal data in connection with:

  • www.lgrarunning.com and related LGRA webpages;
  • LGRA customer and family accounts;
  • class, private-coaching and event bookings;
  • packages, credits, wallet balances and memberships;
  • online training plans, assessments and coaching services;
  • enquiries, communications, promotions and testimonials; and
  • any other LGRA service that refers to this Privacy Policy.

LGRA is operated by:

LITTLE GRAPPY SERVICES
Trading as Little Grappy Running Academy (LGRA)
Registration No.: 202003072394
Business Address: 3-1, Jalan Metro Avenue 1, Metro Avenue, 43000 Kajang, Selangor, Malaysia

For the personal data described in this Privacy Policy, LITTLE GRAPPY SERVICES is the data controller.

We process personal data in accordance with Malaysia's Personal Data Protection Act 2010 (Act 709), as amended (“PDPA”), and other applicable Malaysian laws.

2. Meaning of Personal Data

“Personal data” means information that relates directly or indirectly to an identifiable individual. It may include information supplied by the individual, a parent or guardian, a person booking on the individual's behalf, an LGRA coach, or a service provider.

“Sensitive personal data” may include health conditions, injuries, disabilities, medical information and other information treated as sensitive under the PDPA.

3. Personal Data We May Collect

Depending on how you interact with LGRA, we may collect the following categories of personal data.

3.1 Identity and contact information

  • full name;
  • age or date of birth;
  • gender, where relevant to the requested programme;
  • email address;
  • telephone or WhatsApp number;
  • residential or billing address;
  • identity-verification information, where reasonably required; and
  • emergency-contact details.

3.2 Account and family-profile information

  • account or login identifier;
  • membership number or student ID;
  • profile information and preferences;
  • linked parent, guardian, child or dependant profiles;
  • membership tier and eligibility;
  • account activity and history; and
  • authentication and account-security records.

3.3 Booking and coaching information

  • selected class, coach, date, time and location;
  • attendance, cancellation, rescheduling and no-show records;
  • waitlist status and queue position;
  • training background, goals and preferences;
  • race history and performance information;
  • assessment results, coaching notes and progress records;
  • training-plan information; and
  • communications with coaches, administrators and customer support.

3.4 Payment and transaction information

  • products and services purchased;
  • amounts paid or payable;
  • payment status and transaction reference;
  • invoices and receipts;
  • uploaded manual-payment receipts;
  • package, credit and wallet transactions;
  • voucher, promotion and referral information; and
  • refund, reversal and payment-verification records.

Complete card or online-banking credentials are generally processed directly by the relevant payment provider and are not stored by LGRA, unless clearly stated otherwise.

3.5 Health and safety information

Where relevant to safe participation, we may collect information about:

  • injuries, pain or physical restrictions;
  • medical conditions;
  • allergies;
  • medications;
  • disabilities or accessibility needs;
  • medical clearance or supporting documents;
  • emergency incidents; and
  • other health information voluntarily disclosed by the participant, parent or guardian.

Health information may be sensitive personal data. LGRA will seek explicit consent where required and restrict access to people who reasonably need the information for participant safety, coaching, emergency response or legal compliance.

3.6 Children's information

For a participant under 18, we may collect:

  • the child's identity, age and contact information;
  • parent or guardian identity and contact information;
  • the relationship between the adult and child;
  • consent and authority records;
  • health, allergy and emergency information;
  • authorised collection arrangements; and
  • booking, attendance and coaching records.

3.7 Photographs, videos, testimonials and feedback

We may collect:

  • coaching or running-form videos;
  • event, class or attendance photographs;
  • incident-related photographs or recordings;
  • testimonials and success stories;
  • screenshots showing testimonial permission;
  • survey responses; and
  • customer feedback and correspondence.

Promotional use of a participant's image, video, name, testimonial or success story requires separate consent. For a participant under 18, promotional consent must be provided by a parent or legal guardian.

3.8 Website and technical information

When you use our website, we may collect:

  • IP address;
  • browser and device type;
  • operating system;
  • login, authentication and security logs;
  • cookie or similar identifiers;
  • pages viewed and functions used;
  • referral source;
  • approximate location derived from technical data; and
  • website error, performance and fraud-prevention information.

4. How We Collect Personal Data

We may collect personal data:

  • directly from you when you register, enquire, book, pay, attend or contact us;
  • from a parent, guardian, family-account holder or person booking for a participant;
  • from LGRA coaches, administrators or authorised personnel;
  • automatically through the website, cookies and security tools;
  • from payment, authentication, communication, hosting or other service providers;
  • from an event organiser, venue or business partner where you have authorised the disclosure or it is otherwise permitted by law; and
  • from publicly available sources where lawful and relevant.

If you provide another person's personal data, you confirm that you are authorised to provide it and that you have informed the person about this Privacy Policy. Where the information concerns a child, the information must be provided or approved by an authorised parent or legal guardian where required.

5. Why We Process Personal Data

LGRA may process personal data for the following purposes:

  • creating, authenticating, maintaining and securing accounts;
  • managing family profiles and identifying the correct participant;
  • responding to enquiries and recommending suitable classes or coaches;
  • processing bookings, attendance, waitlists, cancellations and rescheduling;
  • processing purchases, payments, receipts, invoices, refunds and manual-payment verification;
  • administering packages, memberships, credits, wallet balances, promotions, vouchers and referrals;
  • delivering classes, private coaching, online training plans, assessments, reports, workshops and events;
  • monitoring progress and providing coaching feedback;
  • supporting participant health, safety and emergency response;
  • communicating confirmations, reminders, schedule changes, payment updates and service notices;
  • preventing fraud, misuse, duplicate trial redemptions, security incidents and unauthorised access;
  • maintaining business, accounting, tax, insurance, safeguarding and legal records;
  • investigating complaints, incidents and disputes;
  • improving our website, services, programmes and customer experience;
  • administering surveys, approved testimonials and success stories;
  • sending marketing communications where you have consented or where otherwise permitted by law;
  • establishing, exercising or defending legal rights; and
  • complying with legal, regulatory and public-authority requirements.

6. Mandatory and Optional Information

When LGRA requests personal data, we may indicate whether the information is mandatory or optional.

Information is generally mandatory where it is necessary to:

  • create or secure an account;
  • identify the participant;
  • communicate about a booking;
  • process or verify payment;
  • provide a requested service;
  • protect participant health and safety; or
  • comply with legal requirements.

If mandatory information is not provided, LGRA may be unable to create an account, complete a booking, process payment or safely provide the requested service.

Optional information may be declined without preventing access to ordinary services, unless that information later becomes reasonably necessary for a specific request.

8. Children's Privacy

LGRA offers services that may be used by children and teenagers.

A parent or legal guardian must provide or approve a child's personal data and booking where required. LGRA may take reasonable steps to verify the adult's identity and authority.

Parents and guardians must ensure that information concerning a child is accurate and updated, especially:

  • allergies and medical conditions;
  • emergency contacts;
  • authorised collection persons; and
  • custody or collection restrictions relevant to the child's safety.

LGRA does not knowingly use a child's personal data for direct marketing or promotional publication without the required parent or guardian consent.

9. Photographs, Videos and Coaching Analysis

LGRA may create limited photographs or recordings where reasonably necessary for:

  • coaching analysis or running-form review;
  • attendance or event administration;
  • safety and incident documentation; or
  • delivery of a service requested by the participant.

LGRA will request separate consent before using identifiable participant media for advertising, public success stories, social media or other promotional publication.

Promotional consent is voluntary and may be withdrawn for future use. Withdrawal will not invalidate lawful use completed before the withdrawal or require LGRA to recall printed materials already distributed. LGRA will take reasonable steps concerning promotional content that remains under its control.

10. Direct Marketing

With your consent, or where otherwise permitted by law, LGRA may send information about classes, programmes, events, memberships, offers and academy news by email, telephone, SMS, WhatsApp or similar channels.

You may opt out at any time by:

  • using an unsubscribe option provided in the communication;
  • replying with an opt-out request where appropriate; or
  • contacting LGRA using the details at the end of this Privacy Policy.

Opting out of marketing will not stop necessary service messages, including booking confirmations, class changes, payment notices, safety information or responses to your enquiry.

11. Who We May Disclose Personal Data To

LGRA may disclose relevant personal data to:

  • LGRA coaches, employees, administrators and authorised contractors on a need-to-know basis;
  • payment gateways, banks, accounting providers and fraud-prevention services;
  • website hosting, cloud storage, database, authentication, email, messaging, analytics, customer-support and IT-security providers;
  • event organisers, venues and programme partners where necessary for the booked activity;
  • insurers, auditors, lawyers, accountants and other professional advisers;
  • emergency contacts, medical responders or authorities where necessary to protect health or safety;
  • a genuine purchaser, successor or adviser involved in a proposed or completed business restructuring, subject to appropriate confidentiality measures; and
  • courts, regulators, law-enforcement agencies or public authorities where required or permitted by law.

We do not sell personal data.

Service providers acting as data processors must process personal data only for authorised purposes and apply appropriate confidentiality and security safeguards.

12. Payment Providers

Online payments may be handled by an independent payment provider. The payment provider may collect payment-card, online-banking, billing, fraud-prevention and transaction information under its own privacy notice.

LGRA normally receives transaction status, amount, reference and limited customer details required to match and administer the payment.

Where you choose manual payment, LGRA may collect and retain the uploaded receipt and information necessary to verify the payment, maintain financial records and investigate suspected misuse.

13. Google Sign-In and Other Authentication Services

If you choose Google Sign-In or another third-party authentication method, the provider may send LGRA information such as your name, email address, profile identifier and authentication status, depending on your settings and the provider's rules.

LGRA uses that information to identify you, create or access your account, support security and preserve your selected booking flow. The authentication provider's own privacy terms also apply to its processing.

14. Cookies and Similar Technologies

The LGRA website may use cookies, pixels, local storage and similar technologies for:

  • essential website functions;
  • login and account sessions;
  • checkout and booking continuity;
  • security and fraud prevention;
  • remembering preferences;
  • website performance and analytics; and
  • marketing, where enabled and consented to as required.

Essential cookies are required for functions such as account login, checkout and security.

Where required, non-essential analytics or marketing cookies will be used only after consent. You may manage available cookie choices through the website or your browser settings. Disabling essential cookies may prevent parts of the website from functioning correctly.

15. Overseas and Cloud Processing

Some technology and service providers may store or process personal data outside Malaysia.

Where personal data is transferred outside Malaysia, LGRA will take reasonable steps to ensure that the transfer is permitted under the PDPA and that appropriate safeguards apply. These may include:

  • assessing the destination's level of protection;
  • contractual data-protection obligations;
  • security controls;
  • limiting the data transferred; and
  • obtaining consent where required.

16. Security

LGRA takes reasonable administrative, physical and technical measures appropriate to the nature of the personal data. These may include:

  • access controls and role-based permissions;
  • account authentication;
  • secure transmission where available;
  • limiting health information to authorised personnel;
  • staff and contractor confidentiality requirements;
  • vendor review and contractual safeguards;
  • backups, logging and monitoring;
  • security updates; and
  • procedures for responding to suspected data incidents.

No internet transmission or storage system can be guaranteed completely secure. You should use a strong, unique password and notify LGRA promptly if you suspect unauthorised access to your account.

17. Personal-Data Breaches

LGRA maintains procedures to assess and respond to suspected personal-data breaches.

Where a breach is likely to cause significant harm, LGRA will notify the Personal Data Protection Commissioner and affected individuals within the periods and in the manner required by applicable Malaysian law.

LGRA may also take steps to contain the incident, reduce possible harm, preserve evidence, investigate the cause and prevent recurrence.

18. Retention of Personal Data

LGRA retains personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, including:

  • providing services and maintaining accounts;
  • participant safety and safeguarding;
  • handling complaints and disputes;
  • preventing fraud and misuse; and
  • meeting accounting, tax, insurance, contractual and legal requirements.

Different categories of personal data may have different retention periods.

When personal data is no longer reasonably required, LGRA will take reasonable steps to securely delete, destroy or anonymise it unless continued retention is required or permitted by law.

19. Accuracy and Updates

LGRA takes reasonable steps to keep personal data accurate, complete, not misleading and up to date.

You should update your account information or notify LGRA promptly when information changes, particularly:

  • telephone number or email address;
  • emergency contact;
  • health conditions or participation restrictions;
  • child collection arrangements; and
  • parent or guardian authority.

20. Your Rights

Subject to the PDPA and any lawful exceptions, you may:

  • request access to personal data held about you;
  • request correction of inaccurate, incomplete, misleading or outdated personal data;
  • withdraw consent where processing is based on consent;
  • request that LGRA stop or not begin direct marketing;
  • ask questions or make a complaint about LGRA's handling of personal data; and
  • exercise data-portability rights where and to the extent those rights are applicable and in force.

LGRA may need to verify your identity or authority before acting on a request. A fee may apply to a formal access request where permitted by law.

LGRA may refuse or limit a request where permitted by the PDPA, including where disclosure would affect another person's personal data or a lawful exception applies. Where required, LGRA will explain the reason.

For a child's personal data, a request must generally be made by an authorised parent or legal guardian. LGRA may request evidence of identity, guardianship or authority.

21. How to Make a Data Request

To request access or correction, withdraw consent, opt out of marketing, ask a privacy question or make a complaint, contact LGRA using the details in Section 25.

Please provide:

  • your full name and contact details;
  • the participant's name, if different;
  • your relationship to the participant;
  • enough information to identify the relevant account or records;
  • a clear description of the request; and
  • proof of identity or authority where reasonably required.

LGRA will respond within the period required by applicable law.

22. Complaints

If you believe LGRA has mishandled personal data, please contact us first so that we can investigate and respond.

You may also contact or submit a complaint to Malaysia's Personal Data Protection Commissioner through the official channels published at www.pdp.gov.my.

23. Third-Party Websites and Services

The LGRA website may contain links to maps, calendars, social media, messaging services, payment providers, event websites or other third-party services.

Those third parties control their own processing and privacy practices. LGRA's Privacy Policy does not govern an independent third party's website or service. You should review the relevant third-party privacy notice before providing personal data.

24. Changes to This Privacy Policy

LGRA may update this Privacy Policy to reflect changes in law, technology, operations or services.

The latest version and effective date will be posted on the LGRA website. LGRA will provide additional notice or obtain renewed consent where required by law.

Material changes will apply prospectively unless applicable law permits otherwise.

25. Contact LGRA

For privacy requests, questions or complaints, contact:

LITTLE GRAPPY SERVICES
Trading as Little Grappy Running Academy (LGRA)
Registration No.: 202003072394
Business Address: 3-1, Jalan Metro Avenue 1, Metro Avenue, 43000 Kajang, Selangor, Malaysia
Telephone / WhatsApp: +60 17-699 5214