COLLECTION OF YOUR PERSONAL DATA
1. We collect personal data during the course of our ordinary business and activities and we will only process such personal data which is necessary and relevant to our business, functions or activities. Some of the necessary and relevant information of you include:-
- contact information such as names, addresses, telephone numbers and email addresses;
- unique information such as your NRIC or Passport Number, photograph, contact preferences, date of birth etc; and
- transaction history.
HOW PERSONAL DATA IS COLLECTED
2. Some examples of how personal data can be collected:-
- register your details on our website or apps;
- when you complete purchase orders, requests for applications for our products or services (by phone, in person, e-chat or electronically);
- when you conduct certain types of transactions such as refunds;
- participate in surveys and other types of research.
PURPOSES FOR COLLECTION, USE, DISCLOSURE AND PROCESSING OF PERSONAL DATA
3. The personal data which we collect from you may be collected, used, disclosed and/or processed for various purposes, depending on the circumstances for which we may/will need to process your personal data, including:-
- to communicate with you;
- to maintain and improve customer relationship;
- to assess, process and provide products, services and/or facilities to you;
- to establish your identity and background;
- to respond to your enquiries or complaints and resolve any issues and disputes which may arise in connection with any dealings with us;
- to provide you with information and/or updates on our products, services, upcoming promotions offered by us and/or events organised by us and selected third parties which may be of interest to you from time to time;
- for direct marketing purposes via SMS, phone call, e-mail, fax, mail, social media and/or any other appropriate communication channels to members of our loyalty programmes;
- to facilitate your participation in, and our administration of, any events including contests, promotions or campaigns;
- to award points in loyalty or rewards programme;
- to maintain and update internal record keeping;
- for internal administrative purposes;
- to send you seasonal greetings messages from time to time;
- to send you invitation to join our events and promotions and product launch events;
- to process and analyse your Personal Data either individually or collectively with other individuals;
- to conduct market research on surveys, internal marketing analysis, customer profiling activities, analysis of customer patterns and choices, planning and statistical and trend analysis in relation to our products and/or services;
- for detecting, investigating and preventing fraudulent, prohibited or illegal activities;
- for meeting any applicable legal or regulatory requirements and making disclosure under the requirements of any applicable law, regulation, direction, court order, by law, guideline, circular or code acceptable to us.
(collectively referred to “the Purposes” and the list is non-exhaustive).
4. As the purposes for which we may or will collect, use, disclose or process your personal data depend on the circumstances at hand, such purpose may not appear above. However, we will notify you of such other purpose at the time of obtaining your consent, unless processing of your personal data without your consent is permitted by PDPA.
5. For the smooth operation of our business, we may also be disclosing the personal data you have provided to us to our third party service providers, agents and/or our affiliates or related corporations, and/or other third parties (including but not limited to our logistics partners and couriers) whether situated in Malaysia or outside of Malaysia, for one or more of the above Purposes. Such third party service providers, agents and/or affiliates or related corporations and/or other third parties who would be processing your personal data either on our behalf or otherwise, for one or more of the above stated Purposes.
SPECIFIC ISSUES FOR THE DISCLOSURE OF PERSONAL DATA TO THIRD PARTIES
6. We respect the confidentiality of the personal data you have provided to us. The Company does not share, sell, rent or release any personal data collected to any parties. Any information we collect is used strictly for our own purposes as described in this policy.
7. The third parties whom we conduct business are only authorised to use your information to perform the service for which they were hired. As part of our agreement with them, they are required to follow the PDPA law and policies that we provide, and to take reasonable measures to ensure your personal data is secure. In this regard, we will not disclose your personal data to third parties without first obtaining your consent permitting us to do so. However, please note that we may disclose your personal data to third parties without first obtaining your consent in certain situations, including without limitation, the following:-
- cases in which the disclosure is required or authorised based on the applicable laws and/or regulations;
- cases in which the purpose of such disclosure is clearly in your interests, and if consent cannot be obtained in a timely manner;
- cases in which the disclosure is necessary to respond to an emergency that threatens the life, health or safety of yourself or another person;
- cases in which the disclosure is necessary for any investigation or proceedings;
- cases in which the personal data is disclosed to any officer of a prescribed law enforcement agency, upon production of written authorisation signed by the authorised personnel of that law enforcement agency certifying that the personal data is necessary for the purposes of the functions or duties of the authorised personnel;
- where such disclosure without your consent is permitted by PDPA or by law.
8. The instances listed above is not intended to be exhaustive.
9. Where we disclose your personal data to a third party without your consent, we will employ our best effort to require such third party protects your personal data.
REQUEST FOR ACCESS AND/OR CORRECTION OF PERSONAL DATA
10. You may request to access and/or correct the personal data currently in our possession by submitting your request to our Privacy and Data Protection Care Unit at email@example.com
11. For a request to access personal data, we will provide you with the relevant personal data within thirty (30) days from the date of receipt of such request.
12. Where a request cannot be complied within the above time frame, we will inform you of the reasonably soonest time in which we will respond.
13. For a request to correct personal data, we will correct your personal data as soon as practicable after the request has been made unless we have reasonable grounds not to do so.
14. Depending on the scope and nature of the work required to process your access request, we may be required to impose a fee to recover our administrative costs. This will be assessed on a case by case basis by our Policy and Data Protection Care Unit. Where such a fee is to be imposed, we will provide you with a written estimate of the fee for your consideration. Please note that we will only process your request once you have agreed to the payment of fee. In certain cases, we may also require a deposit from you before we process the access request. You will be notified that a deposit is required in the written estimate of the fee, if any.
REQUEST TO WITHDRAW CONSENT
15. You may withdraw your consent for the collection, use and/or disclosure of your personal data in our possession or under our control by submitting your request to our Privacy and Data Protection Care Unit at firstname.lastname@example.org
16. We will process your request within a reasonable time from such a request for withdrawal of consent being made, and will thereafter not collect, use and/or disclose your personal data in the manner stated in your request.
17. However, your withdrawal of consent could result in certain legal consequences arising from such withdrawal. In this regard, depending on the extent of your withdrawal of consent for us to process your personal data, it may mean that we will not be able to continue with your existing relationship with us.
18. The collection of your Personal Data by us may be mandatory or voluntary in nature depending on the Purposes for which your Personal Data is collected. Where it is obligatory for you to provide us with such data, or do not consent to the above or this Policy, we will not be able to provide the Products and/or Services or otherwise deal with you.
ADMINISTRATION AND MANAGEMENT OF PERSONAL DATA
19. We will take reasonable efforts to ensure that your personal data is accurate and complete, if your personal data is likely to be used by the Company to make a decision that affects you, or disclosed to another entity. However, this means that you must also update us of any changes in your personal data that you had initially provided us with. We will not be responsible for relying on inaccurate or incomplete personal data arising from your not updating us of any changes in your personal data that you had initially provided us with.
20. We will also put in place reasonable security arrangements to ensure that your personal data is adequately protected and secured. Appropriate security arrangements will be taken to prevent any unauthorised access, collection, use, disclosure, copying modification, leakage, loss, damage and/or alteration of your personal data. However, we cannot assume responsibility for any unauthorised use of your personal date by third parties which are entirely attributable to factors beyond our control.
21. We will also put in place measures such that your personal data in our possession or under our control is destroyed and/or anonymized as soon as it is reasonable to assume that (I) the purpose for which that personal data was collected is no longer being served by the retention of such personal data; and (ii) retention is no longer necessary for any other legal or business purposes.
25. If you have any complaint or grievance or feedback regarding how we are handling your personal data or about how are complying with PDPA, we welcome you to channel your complaint or grievance or feedback to our Privacy and Data Protection Care Unit at email@example.com