AOC Logo

The Art Of Crypto

Privacy Policy

Effective date: 25 August 2026  |  Last updated: 25 August 2026

AOC SDN. BHD. (Company Registration No. 202201031727), trading as The Art of Crypto

1. Who we are

AOC SDN. BHD. (Company Registration No. 202201031727), trading as The Art of Crypto (“AOC”, “we”, “us” or “our”), controls the personal data described in this Privacy Policy. Our business address is 7-2, Plaza Danau 2, Jalan 2/109F, Taman Danau Desa, 58100 Kuala Lumpur, Malaysia. You can contact us about privacy at support@theartofcrypto.co or by telephone at +60 17 266 0386.

This Policy applies to theartofcrypto.co, billing.theartofcrypto.co, our application forms, member services, communications and related online services. It does not govern independent third parties that determine their own purposes for processing personal data.

2. Information we collect

Information you provide

  • Identity and contact data, including your name, email address, telephone or WhatsApp number, country and communication preferences.
  • Application data, including your trading experience, objectives, available time, challenges, answers to programme-fit questions and appointment details.
  • Account data, including login identifiers, authentication records, profile details, programme access and account preferences.
  • Transaction data, including the product, plan, price, currency, taxes, payment status, invoices, refunds and limited payment metadata. Payment providers process full card or wallet credentials; AOC does not need to store full card numbers.
  • Communications, support, complaint and privacy-request records, including messages sent through email, WhatsApp, Telegram, forms or support channels.
  • Community and learning data, including attendance, lesson progress, submissions, journal information, session participation and moderation records.
  • Testimonial and results evidence that you choose to provide, including recordings, images, certificates, payout or prop-firm records and signed publication permissions.

Information collected automatically

  • Device and network data, such as IP address, browser, operating system, language, approximate location, timestamps and security identifiers.
  • Usage data, such as pages viewed, referring page, campaign source, button or form interactions, video engagement, account access and diagnostic events.
  • Cookies, pixels, local storage and similar identifiers used for security, functionality, analytics and advertising, as described in section 6.

Information from other sources

We may receive information from Typeform or another form provider, scheduling services, customer-management systems, communications providers, payment providers, analytics and advertising platforms, member-platform providers, referral partners and public sources. We may also receive confirmation from a third-party prop firm or platform when you ask us to verify a result.

Please do not send brokerage passwords, seed phrases, private keys, full card details, identity documents or detailed financial information unless we specifically request the information through an approved secure process and explain why it is required.

3. Why we use personal data

  • To respond to enquiries, assess applications, schedule calls and communicate about an application or appointment.
  • To create and administer accounts, supply purchased programmes, provide lessons, community access and support, and maintain service records.
  • To process payments, invoices, renewals, cancellations, refunds, fraud checks and accounting or tax obligations.
  • To send service communications and, only where permitted, optional email or WhatsApp marketing. Marketing consent is separate from applying or purchasing.
  • To secure our services, authenticate users, prevent abuse, investigate incidents and maintain operational logs.
  • To measure and improve website, programme and campaign performance and to personalise advertising where the required choice or consent has been obtained.
  • To verify and publish testimonials or results only under a separate, documented permission and evidence process.
  • To establish, exercise or defend legal claims and comply with law, regulators, courts and lawful requests.

Under Malaysian law, we process personal data for the purposes notified to you, with consent where required, and subject to the Personal Data Protection Act 2010 and applicable amendments. If another jurisdiction applies, we rely on the legal grounds available there, such as performing a contract, complying with law, legitimate interests that do not override your rights, or consent. We do not treat applying for a programme or accepting Terms as consent to unrelated marketing.

4. When information is required

Fields marked as required are needed to assess an application, create an account, complete a transaction or provide the requested service. If you do not provide required information, we may be unable to complete that step. WhatsApp and promotional marketing choices are optional; an email-only application and booking path must remain available.

5. Marketing and communications

We may send application, appointment, account, payment, programme, security and support messages because they are necessary to handle your request or provide the service. We send promotional email or WhatsApp messages only when permitted by applicable law and the recorded preference for that channel. You may unsubscribe from email using the message link, reply STOP to WhatsApp, or email support@theartofcrypto.co. Withdrawing marketing consent does not stop necessary service messages.

6. Cookies, analytics and advertising technologies

Our services use necessary technologies for security, authentication, load balancing, fraud prevention and user-requested functions. We also use or may use analytics, advertising and media technologies supplied by Framer, Google, Meta, DataFast, Typeform and video or member-platform providers. These technologies may collect device, page, campaign and interaction data and may involve transfers outside Malaysia.

Where applicable law requires a choice before optional analytics or advertising technologies operate, we request that choice through the site’s tracking controls. Optional categories are not required to use the application form or checkout. You can reopen the “Manage tracking” control to change a recorded choice. Blocking or deleting browser storage may affect the control and some functionality. Email and WhatsApp preferences must be changed separately as described in section 5.

7. Who receives personal data

We disclose only the information reasonably necessary for the relevant purpose to:

  • hosting, website, video and content-delivery providers, including Framer and embedded-media providers;
  • form, scheduling, CRM, email, WhatsApp, Telegram and customer-support providers;
  • billing, payment, banking, fraud-prevention, accounting and tax providers;
  • analytics and advertising providers, including Google, Meta and DataFast, subject to the applicable tracking choice;
  • member-platform, authentication, security, backup and technical-support providers;
  • professional advisers, auditors, insurers, regulators, courts, law-enforcement bodies and other recipients required by law;
  • a buyer, investor or successor in a genuine corporate transaction, subject to confidentiality and applicable law.

We do not sell personal data for money. Advertising disclosures and audience matching may be regulated as a sale, sharing or targeted advertising in some jurisdictions; where those rules apply, we provide the legally required control.

8. International transfers

Some providers and their infrastructure are located outside Malaysia. We assess and document the transfer condition required by Malaysian law and, where relevant, use contractual safeguards, adequacy decisions, consent or another permitted mechanism. You may ask support@theartofcrypto.co for more information about the destinations and safeguards relevant to your data.

9. Retention

We keep personal data only for as long as reasonably necessary for the stated purpose, legal obligations and genuine disputes. Our proposed operational schedule is:

  • Unsuccessful applications and related scheduling records: 12 months after the last interaction.
  • Customer account, programme and support records: for the relationship and 3 years after it ends.
  • Orders, invoices, payments, refunds and tax records: 7 years after the transaction or longer if law requires.
  • Marketing preferences and suppression records: while marketing continues and for 7 years after the last recorded choice, solely to evidence and honour the preference.
  • Security and access logs: up to 12 months, unless an incident or legal claim requires longer.
  • Testimonials, releases and substantiation records: while the claim is published and 6 years after removal or withdrawal, restricted to evidence and disputes.
  • Cookie and analytics event data: according to the configured vendor duration, not exceeding the period disclosed in the tracking interface and internal data register.

We delete, anonymise or restrict information when the retention period ends. Backup copies are removed through the backup lifecycle and are not restored for ordinary business use after deletion.

10. Security and data breaches

We use organisational and technical controls appropriate to the nature of the data and risk, including access controls, authentication, vendor review, logging, backups and incident response. No system is completely secure. If a personal-data breach occurs, we investigate, preserve relevant evidence and notify the Malaysian Commissioner and affected individuals when and within the time required by applicable law.

11. Your rights

Subject to applicable law and permitted exceptions, you may ask whether we process your personal data, request access or correction, withdraw consent, object to or prevent direct marketing, and ask us to stop processing likely to cause damage or distress. Additional rights may apply where you live, including deletion, restriction, objection or data portability.

To exercise a right, email support@theartofcrypto.co with enough information for us to identify the relevant account or interaction. We may verify identity proportionately. We do not require you to provide more personal data than necessary, and we do not charge unless the law permits a reasonable fee. Withdrawing consent does not invalidate processing already lawfully completed and may affect services that genuinely require the information.

12. Children

Our programmes and services are intended for adults aged 18 or older. We do not knowingly solicit personal data from children. If you believe a child has provided personal data, contact us so we can investigate and take appropriate action.

13. Complaints and contact

Contact support@theartofcrypto.co first so we can investigate a privacy concern. You may also complain to the Personal Data Protection Commissioner of Malaysia or another competent supervisory authority where applicable. Our contact details appear in section 1.

14. Changes to this Policy

We may update this Policy when our services, vendors or legal obligations change. We will update the date above and provide additional notice where a change materially affects your rights or requires a new choice. The version linked to an order or recorded consent remains retrievable for evidentiary purposes.

© 2026 AOC SDN. BHD. All rights reserved.