Privacy Policy for KPSSK Mobile Staff App
- Details
- By KPSSK CMS Administrator
Privacy Policy for KPSSK Mobile Staff App
Effective Date: 17 July 2026
Last Updated: 17 July 2026
1. Introduction
Konsortium Pusat Sumber Sekolah Kebangsaan (“KPSSK”, “we”, “us” or “our”) operates the KPSSK Mobile Staff App (“the App”).
This Privacy Policy explains how the App accesses, collects, uses, processes, stores, discloses and protects information when it is used by authorised KPSSK staff and personnel from participating school resource centres.
The App is designed to support authorised library operations, including:
-
Staff authentication;
-
Library catalogue and item searches;
-
Patron searches;
-
Patron account verification;
-
Item check-out;
-
Item check-in;
-
In-house item use;
-
Barcode and QR-code scanning;
-
Hold shelf management;
-
Holds pull-list management;
-
Item and holdings management;
-
Circulation record management; and
-
Other authorised KPSSK library services.
By accessing or using the App, users acknowledge the practices described in this Privacy Policy.
2. Intended Users
The KPSSK Mobile Staff App is intended only for authorised personnel, including:
-
Library and Media Teachers;
-
School Resource Centre staff;
-
System Librarians;
-
Library administrators;
-
Authorised teachers;
-
Authorised KPSSK officers; and
-
Other personnel approved by KPSSK or a participating school.
The App is not intended for general public use.
Staff accounts are created and administered outside the App by KPSSK or authorised school resource centre administrators. Users cannot create a staff account directly through the App.
3. Information Accessed and Processed
The App may access and process information from the KPSSK Library Management System to provide authorised library services.
3.1 Staff Account Information
When a staff member signs in, the App may process:
-
Staff username;
-
Staff identification number;
-
Staff account ID;
-
Staff name;
-
Email address, where recorded;
-
School or organisational affiliation;
-
Assigned library or workstation;
-
Staff permissions and roles;
-
Account status;
-
Authentication credentials;
-
Login date and time; and
-
Security and access records.
The username and password are transmitted to the KPSSK server for authentication.
Passwords are used only to verify access to the staff account. Passwords should not be displayed, recorded in application logs or stored in readable form.
3.2 Patron Information
Authorised users may access patron information required to perform library services, including:
-
Patron name;
-
Patron or student identification number;
-
Library card number;
-
Patron barcode;
-
Patron category;
-
School, class or organisational affiliation;
-
Contact information, where maintained by the library;
-
Account status;
-
Membership expiry date;
-
Current loans;
-
Due dates;
-
Overdue items;
-
Fines, fees or charges;
-
Holds and hold status;
-
Circulation history;
-
Notices or account alerts; and
-
Other information maintained in the KPSSK Library Management System.
Access to patron information is restricted according to the staff member’s assigned role and permissions.
Staff must only access patron records for legitimate and authorised library purposes.
3.3 Library Item and Catalogue Information
The App may access and process:
-
Book or item titles;
-
Authors and contributors;
-
ISBNs;
-
Item barcodes;
-
Call numbers;
-
Bibliographic descriptions;
-
Summaries and notes;
-
Shelving locations;
-
Owning library;
-
Item availability;
-
Circulation status;
-
Hold status;
-
Item history; and
-
Other catalogue or holdings information.
Most catalogue information is not personal information. However, it may become associated with a patron when used in a circulation transaction.
3.4 Circulation Transaction Information
When authorised staff perform library transactions, the App may process and transmit:
-
Staff account identifier;
-
Patron account identifier;
-
Item barcode;
-
Check-out date and time;
-
Due date;
-
Check-in date and time;
-
Renewal information;
-
In-house use records;
-
Transaction location;
-
Workstation or library identifier;
-
Hold fulfilment information;
-
Circulation status changes; and
-
Transaction results or error messages.
These transactions are transmitted to and recorded in the KPSSK Library Management System.
3.5 Search Information
The App may process search information entered by staff, including:
-
Patron names or identification numbers;
-
Patron barcodes;
-
Item barcodes;
-
Book titles;
-
Authors;
-
Keywords;
-
ISBNs;
-
Call numbers;
-
Search filters; and
-
Catalogue records viewed.
Search information is used to return the requested library or patron information.
Staff members must not search for patron records unless the search is necessary for authorised library duties.
3.6 Camera and Scanner Information
The App may request access to the device camera to scan:
-
Library item barcodes;
-
Patron library card barcodes;
-
QR codes; and
-
Other approved identifiers.
Camera access is used only when the scanning function is activated.
The App does not intentionally record, retain or upload photographs or videos through the barcode-scanning feature.
Barcode or QR-code values may be transmitted to the KPSSK server to retrieve the related item, patron or circulation record.
Users may disable camera permission through their device settings. However, barcode and QR-code scanning features may not function without camera access.
3.7 Device and Technical Information
The App or its authorised service providers may automatically process limited technical information, including:
-
Device type;
-
Device manufacturer and model;
-
Operating system and version;
-
App version;
-
Device language;
-
Internet Protocol address;
-
Installation identifier;
-
Date and time of access;
-
Network connection information;
-
Authentication events;
-
Server request information;
-
App performance information;
-
Diagnostic information;
-
Error reports; and
-
Crash logs.
An Internet Protocol address may indicate an approximate country or region. The App does not use this information to identify a user’s precise physical location.
3.8 Analytics Information
Where analytics services are enabled, the App may collect anonymous or pseudonymous usage information, including:
-
Screens viewed;
-
Features used;
-
Buttons selected;
-
Session duration;
-
General usage patterns;
-
App performance;
-
Device and operating-system information; and
-
Technical events.
Analytics information is used to understand how staff use the App, identify operational issues and improve App functionality.
Analytics must not be used to evaluate staff employment performance unless this is separately disclosed and authorised under an applicable organisational policy.
3.9 Crash and Diagnostic Information
If the App crashes or encounters a technical error, diagnostic information may be collected, including:
-
Stack traces;
-
App state at the time of the error;
-
Device model;
-
Operating-system version;
-
App version;
-
Network request information;
-
Error codes; and
-
Technical logs.
This information is used to identify software defects, improve performance and maintain App stability.
Diagnostic logs should not intentionally include passwords or complete authentication credentials.
4. How Information Is Collected
Information may be collected or accessed:
-
When staff enter their login credentials;
-
When the App communicates with the KPSSK server;
-
When staff search for patrons or library materials;
-
When staff scan a barcode or QR code;
-
When staff perform check-in, check-out or in-house-use transactions;
-
When staff review or manage holds;
-
When the App records security or authentication events;
-
When the App reports technical errors or crashes; and
-
Through authorised third-party technical services integrated into the App.
Information retrieved from the KPSSK server may be displayed temporarily on the user’s device to perform authorised library duties.
5. Reasons for Collecting and Processing Information
Information is accessed and processed to:
-
Authenticate authorised staff;
-
Confirm staff roles and permissions;
-
Prevent unauthorised access;
-
Search and verify patron accounts;
-
Search library catalogue records;
-
Perform check-in and check-out transactions;
-
Record in-house item use;
-
Manage holds and hold-shelf items;
-
Update circulation and item statuses;
-
Display fines, due dates and account alerts;
-
Synchronise transactions with the KPSSK Library Management System;
-
Maintain transaction and security records;
-
Respond to technical support requests;
-
Diagnose errors and crashes;
-
Protect the security and integrity of the App;
-
Investigate suspected misuse;
-
Improve App functionality and user experience;
-
Comply with applicable operational, legal, audit and record-management requirements; and
-
Protect KPSSK, participating schools, staff, patrons and library resources.
6. Required and Optional Information
Staff authentication information is required to access the App.
Patron and circulation information is accessed only when required to perform an authorised library task.
Camera access is optional. Users may enter barcodes manually where the App supports manual entry.
Analytics or diagnostic information may be collected automatically where the relevant service has been enabled.
7. Information Sharing and Disclosure
KPSSK does not sell or rent personal information.
Information may be disclosed or made accessible only where reasonably necessary.
7.1 KPSSK and Participating Schools
Information may be accessible to:
-
KPSSK system administrators;
-
Authorised school resource centre staff;
-
Authorised library administrators;
-
School management personnel with appropriate authority;
-
Technical support personnel; and
-
Other authorised officers.
Access is limited to legitimate library, technical, security, audit or administrative purposes.
7.2 Technology Service Providers
Limited information may be processed by authorised service providers supporting:
-
Server hosting;
-
Authentication;
-
Library system integration;
-
Cloud infrastructure;
-
Analytics;
-
Crash reporting;
-
Push notifications;
-
Security monitoring; and
-
Application maintenance.
These providers must process information only to provide the contracted service and in accordance with applicable obligations.
7.3 Legal, Security and Regulatory Requirements
Information may be disclosed where reasonably necessary to:
-
Comply with applicable law or regulation;
-
Respond to a court order or lawful request;
-
Investigate unauthorised access or misuse;
-
Detect or prevent fraud or security incidents;
-
Protect the safety and rights of users;
-
Protect KPSSK or participating schools;
-
Protect library materials and systems; or
-
Establish, exercise or defend legal rights.
8. Third-Party Services
Depending on the final App configuration, the App may use third-party services such as:
-
Google Play services;
-
Firebase Analytics;
-
Firebase Crashlytics;
-
Firebase Cloud Messaging;
-
Apple Push Notification Service;
-
Barcode or QR-code scanning libraries;
-
Cloud-hosting providers; and
-
Other technical infrastructure providers.
Third-party services may process limited device, usage, notification or diagnostic information in accordance with their respective privacy terms.
KPSSK must ensure that the Google Play Data Safety declaration and Apple App Privacy disclosure accurately reflect every software development kit and service included in the published App.
9. Data Security
KPSSK applies reasonable technical, administrative and organisational safeguards designed to protect staff and patron information from:
-
Unauthorised access;
-
Accidental loss;
-
Misuse;
-
Unauthorised disclosure;
-
Unauthorised modification;
-
Destruction; and
-
Security incidents.
Safeguards may include:
-
HTTPS or TLS encryption;
-
Secure staff authentication;
-
Role-based access controls;
-
Staff permission management;
-
Session management;
-
Server access controls;
-
Security logging;
-
Restricted administrator access;
-
Software security updates;
-
Secure credential storage;
-
Database protection; and
-
Security monitoring.
All staff and patron information transmitted between the App and the KPSSK server should be encrypted in transit.
No electronic storage or transmission method is completely secure. Staff users must protect their login credentials and immediately report suspected unauthorised access.
10. Staff Responsibilities
Staff users must:
-
Keep their login credentials confidential;
-
Not share accounts or passwords;
-
Use only their assigned staff account;
-
Access patron information only for authorised purposes;
-
Not take screenshots of patron records unless officially required;
-
Not copy patron information to unauthorised applications or devices;
-
Not disclose patron information to unauthorised individuals;
-
Log out when using a shared device;
-
Protect mobile devices with an appropriate screen lock;
-
Report lost or stolen devices;
-
Report suspected unauthorised access;
-
Follow KPSSK and school privacy, security and circulation policies; and
-
Use the App only for official library duties.
KPSSK may suspend or terminate access where misuse or unauthorised activity is suspected.
11. Data Retention
Staff account, patron and circulation information is retained according to the operational, administrative, audit and record-management requirements of KPSSK and participating schools.
Circulation transaction records may be retained for purposes including:
-
Managing current loans;
-
Maintaining borrowing history;
-
Resolving disputes;
-
Managing fines or lost materials;
-
Conducting audits;
-
Producing library statistics;
-
Investigating misuse; and
-
Meeting legal or organisational requirements.
Analytics, crash and diagnostic information is retained only for as long as reasonably necessary to:
-
Analyse App usage;
-
Resolve technical issues;
-
Maintain security;
-
Improve App performance; or
-
Meet applicable legal requirements.
Some records may remain in backup systems for a limited period before being securely overwritten or deleted.
12. Account Deactivation and Data-Deletion Requests
Staff accounts are created and managed outside the App.
Staff users may request account deactivation, correction or deletion by contacting KPSSK or their participating school administrator.
Account deletion or deactivation may not result in the deletion of all historical records. KPSSK or the participating school may retain records required for:
-
Circulation transactions;
-
Security logs;
-
Audit trails;
-
System administration;
-
Active library matters;
-
Outstanding fines or lost materials;
-
Legal obligations;
-
Organisational record-management requirements; or
-
Investigation of suspected misuse.
Where information can be deleted without affecting legitimate operational or legal requirements, KPSSK will take reasonable steps to process the request.
Removing the App from a device does not automatically delete the staff account, patron records or circulation records stored on the KPSSK server.
13. Patron Data Requests
Patrons, parents or guardians who wish to request access, correction or deletion of patron information should contact the relevant participating school resource centre.
Staff users must not independently delete or change patron records unless they have the required authority and follow the approved procedures.
Requests involving student information may require identity and authority verification.
14. Children’s and Students’ Information
The App may allow authorised staff to access information belonging to school students, including children.
This information is processed only for legitimate school library and educational purposes.
KPSSK does not:
-
Sell student information;
-
Use student information for behavioural advertising;
-
Use circulation information for commercial profiling;
-
Intentionally collect precise student location information;
-
Allow public access to student patron records; or
-
Permit unrestricted communication between students through the App.
Access to student information is restricted to authorised staff with appropriate roles and responsibilities.
15. Data Location and International Processing
KPSSK data may be stored on KPSSK-controlled servers or infrastructure operated by authorised service providers.
Some technical service providers may process limited diagnostic, notification or analytics information on servers located outside Malaysia.
Where international processing occurs, reasonable measures will be taken to ensure that the information is handled with appropriate safeguards and in accordance with applicable requirements.
16. External Links
The App may provide links to:
-
KPSSK websites;
-
KPSSK Discovery;
-
KPSSK E-Book services;
-
KPSSK Repository;
-
School websites; and
-
Other authorised external resources.
External websites and services may operate under separate privacy policies.
KPSSK is not responsible for the privacy practices of third-party websites or services that it does not control.
17. Changes to This Privacy Policy
KPSSK may update this Privacy Policy when:
-
New App functions are introduced;
-
Data-processing practices change;
-
New third-party services are added;
-
Security practices change;
-
Legal or regulatory requirements change; or
-
Google Play or Apple App Store requirements change.
The latest version will be published with an updated effective date.
Material changes may also be communicated through the App, the KPSSK website or participating schools.
18. Contact Us
Questions, complaints or requests relating to this Privacy Policy may be submitted to:
Konsortium Pusat Sumber Sekolah Kebangsaan (KPSSK)
Email:
Website: https://web.kpssk.org
For staff-account matters, users may also contact their school resource centre administrator or KPSSK system administrator.
Users should not send passwords or other authentication credentials by email.
19. Privacy Complaints
A staff user or patron who believes that information has been accessed, used or disclosed improperly should contact KPSSK or the relevant participating school.
KPSSK will take reasonable steps to:
-
Review the complaint;
-
Verify the relevant circumstances;
-
Investigate suspected misuse;
-
Restrict access where necessary;
-
Correct inaccurate information where appropriate;
-
Address confirmed security issues; and
-
Communicate the outcome through an appropriate channel.