1.2 This Policy applies to personal information about individuals (customers, vendors, distributors, suppliers, service providers, joint venture/business partners, job applicants, employees) held by us. We will only process your Personal Data in accordance with the Personal Data Protection Act 2010, the applicable regulations, guidelines, orders made under the Personal Data Protection Act 2010 and any statutory amendments or re-enactments made of the Personal Data Protection Act 2010 from time to time (collectively referred to as the “PDPA”) as well as this Policy.
1.3 The PDPA requires us to inform you of your rights in respect of your Personal Data that is being processed or that is to be collected and further processed by us and the purposes for the data processing. The PDPA also requires us to obtain your consent to the processing of your Personal Data. In light of the PDPA, we are committed to protecting and safeguarding your Personal Data.
1.4 By providing your Personal Data to us and/or continuing access to our website (“Site”), you declare that you have read and understood this Policy and agree to us processing your Personal Data in accordance with the manner as set out in this Policy.
1.5 We reserve the right to modify, update and/or amend this Policy from time to time with reasonable prior notice to you. We will notify you of any amendments via announcements on the Site or other appropriate means. Please check the Site from time to time to see if there are amendments to this Policy. Any amendments to this Policy will be effective upon notice to you. By continuing to use the services and/or access to the Site after being notified of any amendments to this Policy, you will be treated as having agreed to and accepted those amendments.
1.6 If you do not agree to this Policy or any amendments to this Policy, we may not be able to render all services to you and you may be required to terminate your relevant agreement with us and/or stop accessing or using the Site.
- COLLECTION OF PERSONAL DATA
2.1 The term “Personal Data” means any information in our possession or control that relates directly or indirectly to an individual to the extent that the individual can be identified or are identifiable from that and other information in our possession, such as name, address, telephone number, Identification/Passport number, date of birth, photograph, email address, household information, etc. as well as Sensitive Personal Data as defined under the PDPA, which includes but is not limited to, information pertaining to the physical or mental health or condition of a data subject and religious beliefs.
The types of Personal Data collected depend on the purpose of collection. We may “process” your Personal Data by way of collecting, recording, holding, storing, using and/or disclosing it.
2.2 Your Personal Data may be collected from you during your course of dealings with us in any way or manner including pursuant to any transactions and/or communications made from/with us. We may also collect your Personal Data from a variety of sources, including without limitation, Some examples of how personal data can be collected:
- When you register your details on our website, apps or kiosks;
- When you complete purchase/register/join trips on our websites;
- When you communicate with us directly via our customer service centre, or directly via our co-workers within our stores in relation to our products and services (in person, by email, telephone, direct mail or any other means);
- When you conduct certain types of transactions such as refunds;
- When you enter, and when you interact with us during promotions, contests, and special events;
- Subscribe to newsletter,
- Participate in surveys and other types of research;
- Purpose Of Acquiring And Processing Your Personal Data
The Personal Data as provided/furnished by you to us or collected by us from you or through such other sources as may be necessary for the fulfilment of the purposes at the time it was sought or collected, may be processed for the following purposes (collectively referred to as the “Purposes”):
- to communicate with you;
- to maintain and improve customer relationship;
- to assess, process and provide products and services to you;
- to administer and process any payments related to services requested by you;
- to respond to your enquiries or complaints and resolve any issues and disputes which may arise in connection with any dealings with us;
- to provide you with information and/or updates on our products, services, upcoming promotions offered by us and/or events organised by us and selected third parties which may be of interest to you from time to time;
- for direct marketing purposes via SMS, phone call, email, fax, mail, social media and/or any other appropriate communication channels
- to facilitate your participation in, and our administration of, any events including contests, promotions or campaigns;
- to maintain and update internal record keeping;
- for internal administrative purposes;
- to send you seasonal greetings messages from time to time;
- to send you the invitation to join our events and promotions and product launch events;
- to monitor, review and improve our events and promotions, products and/or services;;
- to process any payments related to your commercial transactions with us;
- to process and analyse your Personal Data either individually or collectively with other individuals;
- to conduct market research or surveys, internal marketing analysis, customer profiling activities, analysis of customer patterns and choices, planning and statistical and trend analysis in relation to our products and/or services;
- to share any of your Personal Data with the auditor for our internal audit and reporting purposes;
- to share any of your Personal Data pursuant to any agreement or document which you have duly entered with us for purposes of seeking legal and/or financial advice and/or for purposes of commencing legal action;
- to share any of your Personal Data with our joint venture/business partners to jointly develop products and/or services or launch marketing campaigns;
- to share any of your Personal Data with insurance companies necessary for the purpose of applying and obtaining insurance policy(ies), if necessary;
- for audit, risk management and security purposes;
- for detecting, investigating and preventing fraudulent, prohibited or illegal activities;
- for enabling us to perform our obligations and enforce our rights under any agreements or documents that we are a party to;
- to transfer or assign our rights, interests and obligations under any agreements entered into with us;
- for meeting any applicable legal or regulatory requirements and making disclosure under the requirements of any applicable law, regulation, direction, court order, by-law, guideline, circular or code applicable to us;
- to enforce or defend our rights and your rights under, and to comply with, our obligations under the applicable laws, legislation and regulations;
- for other purposes required to operate, maintain and better manage our business and your relationship with us, which we notify you of at the time of obtaining your consent; and you agree and consent to us using and processing your Personal Data for the Purposes in the manner as identified in this Policy. If you do not consent to us processing your Personal Data for one or more of the Purposes, please notify us at the contact details below.
- Consequences Of Not Consenting To This Policy
The collection of your Personal Data by us may be mandatory or voluntary in nature depending on the Purposes for which your Personal Data is collected. Where it is obligatory for you to provide us with your Personal Data, and you fail or choose not to provide us with such data, or do not consent to the above or this Policy, we will not be able to provide products and/or services or otherwise deal with you.
- Disclosure Of Your Personal Data
We will not sell, rent, transfer or disclose any of your Personal Data to any third party without your consent. However, we may disclose your Personal Data to the following third parties, for one or more of the above Purposes:
- your immediate family members and/or emergency contact person as may be notified to us from time to time;
- successors in title to us;
- any person under a duty of confidentiality to which has undertaken to keep your Personal Data confidential which we have engaged to discharge our obligations to you;
- any party in relation to legal proceedings or prospective legal proceedings;
- our auditors, consultants, lawyers, accountants or other financial or professional advisers appointed in connection with our business on a strictly confidential basis, appointed by us to provide services to us;
- any party nominated or appointed by us either solely or jointly with other service providers, for purpose of establishing and maintaining a common database where we have a legitimate common interest;
- data centres and/or servers located within or outside Malaysia for data storage purposes or otherwise;
- payment channels including but not limited to financial institutions for purpose of assessing, verifying, effectuating and facilitating payment of any amount due to us in connection with your purchase of our products and/or services;
- Government agencies, law enforcement agencies, courts, tribunals, regulatory bodies, industry regulators, ministries, and/or statutory agencies or bodies, offices or municipality in any jurisdiction, if required or authorised to do so, to satisfy any applicable law, regulation, order or judgment of a court or tribunal or queries from the relevant authorities;
- our joint venture/business partners, third-party product and/or service providers, suppliers, vendors, contractors, data processors or agents, that provide related products and/or services in connection with our business, or discharge or perform one or more of the above Purposes and other purposes required to operate and maintain our business
- Retention Of Your Personal Data
Any of your Personal Data provided to us is retained for as long as the purposes for which the Personal Data was collected continues; your Personal Data is then destroyed from our records and system in accordance with our retention policy in the event your Personal Data is no longer required for the said purposes unless its further retention is required to satisfy a longer retention period to meet our operational, legal, regulatory, tax or accounting requirements.
- Security Of Your Personal Data
7.1 We are committed to ensuring that your Personal Data is stored securely. In order to prevent unauthorised access, disclosure or other similar risks, we endeavour, where practicable, to implement appropriate technical, physical, electronic and procedural security measures in accordance with the applicable laws and regulations and industry standard to safeguard against and prevent the unauthorised or unlawful processing of your Personal Data, and the destruction of, or accidental loss, damage to, alteration of, unauthorised disclosure of or access to your Personal Data.
7.2 We will make reasonable updates to its security measures from time to time and ensure the authorised third parties only use your Personal Data for the Purposes set out in this Policy.
7.3 The Internet is not a secure medium. However, we will put in place various security procedures with regard to the Site and your electronic communications with us. All our employees, joint venture/business partners, agents, contractors, vendors, suppliers, data processors, third-party product and/or service providers, who have access to, and are associated with the processing of your Personal Data, are obliged to respect the confidentiality of your Personal Data.
7.4 Please be aware that communications over the Internet, such as emails/webmails are not secure unless they have been encrypted. Your communications may be routed through a number of countries before being delivered – this is the nature of the World Wide Web/Internet.
7.5 We cannot and do not accept responsibility for any unauthorised access or interception or loss of Personal Data that is beyond our reasonable control.
- Personal Data From Minors And Other Individuals
To the extent that you have provided (or will provide) Personal Data about your family, spouse and/or other dependents, you confirm that you have explained to them that their Personal Data will be provided to, and processed by, us and you represent and warrant that you have obtained their consent to the processing (including disclosure and transfer) of their Personal Data in accordance with this Policy and, in respect of minors (i.e. individuals under 18 years of age) or individuals not legally competent to give consent, you confirm that they have appointed you to act for them, to consent on their behalf to the processing (including disclosure and transfer) of their Personal Data in accordance with this Policy.
9.1 External links
- If any part of the Site links you to other websites, those websites do not operate under this Policy and we do not accept any responsibility or liability arising from those websites.
- Likewise, if you subscribe to an application, content or a product from our strategic partner and you subsequently provide your Personal Data directly to that third party, that Personal Data will be subject to that third party’s privacy/personal data protection policy (if they have such a policy) and not to this Policy.
- We recommend you to read and understand the privacy/personal data protection statement/policy posted on those other websites in order to understand their procedures for collecting, processing, using and disclosing personal data and before submitting your Personal Data to those websites.
- We employ an industry standard technology called “cookies”. The cookie is a small piece of information stored on the hard drive of your computer or device for record-keeping purposes and is used by us to track your visits to the Site. Cookies may be used to save your preferences for your ease and convenience when using the Site. Third party advertising networks may issue their separate cookies to your hard drive when serving advertisements.
- The type of anonymous clickstream data collected by us through the cookies may include your Internet Protocol address, web browser software, date and time of visit to the Site, and whether your requests (including search requests and clicking on links to parts of the Site) were met with success. All such information collected through cookies is not Personal Data and you cannot be identified from this information. Such information is only used for the purpose of managing and creating a better user experience and to identify areas for improvement on the Site.
If you have any questions about this Policy, or have any further queries, or would like to make a complaint or data access or correction request in respect of your Personal Data, you may contact us at email@example.com