Legal
Effective date: 1 April 2026 · Last updated: 1 April 2026
This Privacy Policy describes how CreditDesk ("we", "our", or "us") collects, uses, and protects your personal data in accordance with Malaysia's Personal Data Protection Act 2010 (PDPA).
CreditDesk is a Malaysian mortgage intelligence platform that provides free home loan eligibility checks for buyers and property valuation tools for owners, alongside a professional management platform for licensed mortgage consultants and agencies.
For data protection enquiries, contact us at privacy@credit-desk.com or via WhatsApp at +60189560388.
We collect different data depending on how you use CreditDesk:
BuyerPass (Home Loan Eligibility Check)
OwnerPass (Property Valuation)
Consultant & Agency Accounts
We process your personal data for the following purposes:
We do not sell, rent, or trade your personal data to any third party for marketing purposes.
Under the PDPA 2010, we process your data on the basis of your consent (given when you submit BuyerPass or OwnerPass forms) and legitimate interests (for consultants using the DeskPro platform under their agency agreement).
We share limited data with trusted service providers solely to operate CreditDesk:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database and authentication hosting | Singapore (AWS) |
| OpenAI | AI document OCR (payslips, CTOS) | United States |
| Vercel | Website hosting and delivery | Global CDN |
| 360dialog | WhatsApp messaging | Germany |
All providers are contractually obligated to protect your data and process it only for the stated purpose.
You have the right to:
To exercise any of these rights, contact us at privacy@credit-desk.com. We will respond within 21 days as required by the PDPA.
CreditDesk uses essential cookies only — for authentication sessions and form draft saving (via localStorage). We do not use advertising or tracking cookies. No third-party analytics scripts are loaded on the site.
All data is transmitted over HTTPS (TLS 1.2+). Passwords are hashed using bcrypt via Supabase Auth. Access to personal data is restricted to authorised personnel only. AI document processing does not store raw documents beyond the immediate API call.
We may update this Privacy Policy from time to time. We will notify users of material changes by updating the effective date at the top of this page. Continued use of CreditDesk after changes constitutes acceptance of the updated policy.