Privacy Policy
1. INTRODUCTION.

This Privacy Policy (“Policy”) describes how Supabaza Sdn Bhd (Company Registration No.: 202001025717(1382037-P)) with the registered address at Suite 13-10, Level 13, Johor Bahru City Square (Office Tower), 106-108, Jalan Wong Ah Fook 80000 Johor Bahru, Johor (“Supabaza” or “we” or “us”) and its affiliates collect and process your personal data in accordance with the Personal Data Protection Act 2010 of Malaysia (“Act”).

The capitalised terms shall have the same meaning ascribed to it under the Supabaza Terms and Conditions (available at https://www.supabaza.com/terms-and-conditions), unless stated otherwise.

2. INFORMATION WE COLLECT.

When you use the Services and/or work with us, you may be sharing your personal data with us. By continuing to access or use the Services and/or work with us, you expressly consent to our collection, storage, use and disclosure of your personal data as described in this Policy.

During the course of your usage of the Services and/or the performance of your obligations to us, the personal data that may be collected about you are as follows:

(a) As a customer:
- Your name, gender and date of birth;
- Your address, delivery address, email address and mobile number;
- Your purchase history, including the details of products that you have purchased on the Services;
- Your information that you have provided to us through the Services such as your ratings, review and feedback;
- The information on how you use our Services, including your login credentials, your IP address, and your preferences;
- Your account data such as bank account details, credit card details and payment details (which may be collected directly by us and/or third-party payment service providers); and
- Any other information you provide to us during your interaction with us and/or your use of the Services.

(b) As a CP:
- Your name, gender, NRIC number, date of birth;
- Your address, email address and contact number;
- Your information that you have provided to us through the Services such as your ratings, review and feedback;
- The information on how you use the Services, including your login credentials, your IP address, and your preferences;
- Your account data such as bank account details, credit card details and payment details (which may be collected directly by us and/or third-party payment service providers); and
- Any other information you provide to us during your interaction with us and/or the performance of your obligations with us.

(hereinafter collectively known as “Personal Data”).

You acknowledge that you provide your Personal Data to us voluntarily. You hereby declare that the Personal Data you submit to us is accurate and not misleading, and you undertake to keep it up to date and to inform us of any changes to the Personal Data that you have provided. Failure to provide such information may result in us not being able to provide you access to the Services or to allow you to continue working with us.

3. USE OF INFORMATION COLLECTED AND DISCLOSURE OF INFORMATION.

Your Personal Data will be collected for the following purposes:
- Enable you to use the Services;
- Verify your identity and maintain your account with us;
- Process your Order and facilitate the completion of the transaction;
- Process or arrange payment and/or shipping;
- Generate sales information;
- Offer you promotions and discounts;
- Send you targeted marketing communications regarding new products and offers;
- Carry out market research;
- Develop, maintain, promote and improve our services;
- Respond to your queries, feedback, claims or disputes;
- Prevent or investigate any actual or suspected violations of the Supabaza Terms, fraud, unlawful activity, omission or misconduct relating to your use of the Services;
- Provide you with information we think you may find useful or which you have requested from us;
- Allow you to provide your services or perform your contractual obligations to us; and/or
- To give effect to your commercial transactions with us.

If you are a customer, we may disclose your Personal Data to third parties (within and/or out of Malaysia) including but not limited to our affiliate companies, CPs or other third-party service providers and manufacturers for the above purposes. We may also disclose your Personal Data to parties involved in a mergers and acquisition discussion with us, including their service providers. Where such disclosure is necessary, we shall take reasonable steps to ensure that the third parties comply with the applicable data protection laws.

If you are a CP or service provider, we may disclose your Personal Data to the customers to facilitate the Fulfilment of the customers’ Orders. We may also disclose your Personal Data to parties involved in a mergers and acquisition discussion with us, including their service providers. Where such disclosure is necessary, we shall take reasonable steps to ensure that the third parties comply with the applicable data protection laws.

In any event, we will not transfer or assign your Personal Data to any natural or legal persons other than those indicated above.

4. WITHDRAWAL OF CONSENT.

You hereby expressly accept and authorise the collection and use of your Personal Data in accordance with this Policy. You may withdraw your consent to our collection of Personal Data at any time by emailing us at hello@supabaza.com.

In the event of such withdrawal of consent, we may not continue to grant you access to the Services, or allow you to continue to working with us.

5. RIGHTS OF THE PERSONAL DATA HOLDER.

You can request to access, review, update, correct and limit the processing of your Personal Data which we have collected by contacting us at hello@supabaza.com. We will respond within 21 days from the date of your request and we reserve the right to charge an administrative fee for retrieving your Personal Data which will be communicated to you upon your request. If we are unable to respond within 21 days from the date of your request, we will notify you in writing to inform you that we are unable to comply with your request and our reasons for not doing so.

Your Personal Data shall be retained with us for as long as it is required by law or to fulfil the above purposes that the Personal Data was collected for. We will cease to retain and remove all your Personal Data once it is ascertained that the retention of Personal Data is no longer necessary.

If you have any inquiries or complaints in respect of the collection of Personal Data, you may also contact us at hello@supabaza.com.

6. DATA ACCESSED BY CPs AND SERVICE PROVIDERS.

As a CP or a service provider of Supabaza, you acknowledge and accept that you will have access to certain Personal Data of the customers or other CPs / service providers. You acknowledge and accept that you will not use, reproduce, store, transfer, assign, disclose, or share, in whole or in part, such Personal Data (whether with your own personnel or any other persons that is not directly involved with the fulfilment of your obligations to us and/or the customers and/or other CPs / service providers), except as strictly necessary for the performance of your obligations. Additionally, should you receive or are in possession of any Personal Data (of customers, other CPs / service providers, or otherwise) that is not intended to be received by or possessed by you, you shall immediately delete, destroy, or shred such Personal Data.

You hereby agree to comply with the obligations as laid down in the Act in your fulfilment of your obligations to us and/or the customers and/or other CPs / service providers and shall indemnify and hold harmless Supabaza from and against any and all claims arising from your use of the Personal Data and any breach thereof.

7. DATA ACCESSED BY CUSTOMERS.

As a customer, you acknowledge and accept that you will have access to certain Personal Data of the CPs / service providers. You acknowledge and accept that you will not use, reproduce, store, transfer, assign, disclose, or share, in whole or in part, such Personal Data except as strictly necessary for the Fulfilment of your Order. Additionally, should you receive or are in possession of any Personal Data (of CPs, service providers, other customers or otherwise) that is not intended to be received by or possessed by you, you shall immediately delete, destroy, or shred such Personal Data.

You hereby agree to comply with the obligations as laid down in the Act in your use of the Services to us and shall indemnify and hold harmless Supabaza from and against any and all claims arising from your use of the Personal Data and any breach thereof.

8. MARKETING.

We may use your Personal Data to improve and personalise our services or content, and for marketing purposes. If you do not wish to receive marketing communications from us, please email us at hello@supabaza.com.

9. COOKIES.

The Services use cookies which are small data files that are installed on your device (personal computer, tablet, mobile phone, etc.) for a limited time in order to personalize your user experience. Cookies can be used to remember your access credentials, register your preferences and grant you faster access to the Services. We also use cookies to customize the services and offers available for you on the Services by sending information that may be of interest to you and personalising advertisements in the Services.

You can disable the use of cookies through your browser or device settings, in which case your preferences will not be maintained and some features of the Services may not be available.

10. WEB BEACONS.

The Services also use web beacons (or pixels) that transmit information from your device to a server, similar to cookies. Web beacons can be inserted in online content, videos and emails, and allow you to read certain type of information from your device, at what time and date a certain content or email has been accessed, and the IP address of your device. Web beacons are used in conjunction with cookies for the same purpose and to measure traffic patterns on the web and/or the Services.

11. INFORMATION SECURITY.

We store your Personal Data in third party servers, which may be located out of Malaysia. We value your Personal Data and make our best endeavours to protect your Personal Data against unauthorised access and disclosure. However, we cannot guarantee that there will be no unlawful interception from third parties or that your Personal Data will always remain secured with us.

If you believe that there has been a breach of your Personal Data, please contact us at hello@supabaza.com.

12. CONFIDENTIALITY.

Supabaza will use reasonable efforts to ensure that the CPs, our service providers, and/or other authorized transferors will treat confidentially all Personal Data and will not disclose it to unauthorized third parties.

13. COMPETENT AUTHORITY ORDERS.

If we have reasonable grounds to believe that disclosure of your Personal Data is necessary to comply with the applicable laws, order, or to cooperate in the investigation of any potential or ongoing criminal or civil wrongdoing, we reserve the right to disclose your Personal Data to such legal, governmental or regulatory enforcement bodies or the relevant right owners. We shall not be liable for damages or results arising from such disclosure, and you agree not to bring any action or claim against us for such disclosure.

14. CHANGES AND MODIFICATIONS.

We may modify and change the Policy from time to time. The updated version of this Policy will be available at https://www.supabaza.com/privacy-policy. Your continued use of the Services and/or provision of services to us constitutes your acknowledgment and acceptance of the changes made to this Policy.

In accordance with Section 7(3) of the Act, this Policy is issued in both English and Bahasa Malaysia. In the event of any inconsistencies or discrepancies between the English version and the Bahasa Malaysia version, the English version shall prevail.

---------------------------------------

NOTIS DATA PERIBADI INBODY

Notis data peribadi (“Notis Data Peribadi”) mengenai penggunaan data peribadi diterbitkan oleh Supabaza Sdn Bhd (“Syarikat” atau “Kami”) kepada:

- pengguna-pengguna https://www.supabaza.com dan aplikasi Supabaza (secara kolektif, “Perkhidmatan Kami”); dan
- Rakan Komuniti kami,

(secara kolektif, “Pengunna”)

selaras dengan keperluan Akta Perlindungan Data Peribadi 2010 (“PDPA”).

Sepanjang penggunaan Perkhidmatan Kami dan/atau apabila anda membekalkan perkhidmatan kepada kami, kami akan mengumpul data peribadi anda termasuk, tetapi tidak terhad kepada:

- nama anda;
- jantina anda;
- tarikh lahir anda;
- alamat anda;
- alamat e-mel anda;
- nombor telefon bimbit anda;
- sejarah pembelian anda;
- maklumat-maklumat lain yang diberi anda, seperti penilaian dan maklum balas anda;
- maklumat mengenai penggunaan Perkhidmatan Kami oleh anda, termasuk, tetapi tidak terhad kepada, alamat IP dan pilihan-pilihan anda;
- maklumat mengenai akaun anda, termasuk, tetapi tidak terhad kepada, maklumat akaun bank anda, maklumat kad kredit anda, dan maklumat pembayaran anda;
- danmaklumat-maklumat lain yang dibekalkan anda selama penggunaan Perkhidmatan kami.

(secara kolektif, “data peribadi”)

Kami akan mengumpul dan memproses data peribadi anda untuk tujuan-tujuan berikut:

- untuk membolehkan anda untuk menggunakan Perkhidmatan Kami;
- untuk mengesahkan identiti andauntuk mengekalkan akaun anda;
- untuk memproses pembelian anda;untuk memudahkan transaksi anda dalam Perkhidmatan Kami;
- untuk menjana maklumat jualan;untuk memaklumkan kepada anda tentang promosi dan diskaun kami;
- untuk menghantar maklumat pemasaran bersasar mengenai produk baru atau tawaran kami;
- untuk menjalankan penyelidikan pasaran;
- untuk mengembangkan, mengekalkan, mempromosi, dan memperbaiki Perkhidmatan Kami;
- untuk menjawab soalan anda, dan memberi maklum balas terhadap penilaian anda, dan untuk memberi maklum balas apabila berlakunya sebarang pertikaian;
- untuk mencegah atau menyiasat apa jua pelanggaran Terma Supabaza, penipuan, aktiviti-aktiviti haram, atau salah laku mengenai penggunaan Perkhidmatan Kami;
- untuk memberi maklumat lanjut yang berguna atau yang maklumat yang diminta anda;
- untuk membolehkan anda untuk membekalkan perkhidmatan kepada kami atau untuk melaksanakan obligasi kontraktual anda kepada kami; dan/atau
- untuk memberi kesan kepada transaksi komersial anta kami.

(secara kolektif, “Tujuan-tujuan”).

Sebagai pelanggan kami, kami akan mendedahkan data peribadi anda kepada pihak ketiga (di luar atau di dalam Malaysia) yang termasuk, tetapi tidak terhad kepada, syarikat bersekutu kami, Rakan Komuniti, atau pembekal perkhidmatan atau pengilang pihak ketiga untuk Tujuan-tujuan di atas. Kami juga akan mendedahkan data peribadi anda kepada pihak yang terbabit dalam transaksi percantuman dan pembelian dengan kami, termasuk pembekal perkhidmatan pihak-pihak tersebut.

Sebagai Rakan Komuniti kami, kami akan mendedahkan data peribadi anda kepada pelanggan-pelanggan. Kami juga akan mendedahkan data peribadi anda kepada pihak yang terbabit dalam transaksi percantuman dan pembelian dengan kami, termasuk pembekal perkhidmatan pihak-pihak tersebut.

Anda boleh menarik balik persetujuan anda terhadap pemprosesan data peribadi anda oleh kami dengan apa bila-bila masa dengan menghantar e-mel kepada hello@supabaza.com. Tetapi, anda mungkin tidak dapat mengakses Perkhidmatan Kami, atau meneruskan pembekalan perkhidmatan anda, sekiranya anda menarik balik persetujuan tersebut.

Kami akan memastikan bahawa data peribadi anda dilindungi dan akan disimpan dengan selamat. Anda berhak untuk meminta akses kepada data peribadi anda, atau meminta salinan data peribadi anda, atau meminta bahawa data peribadi anda dikemaskini atau dibetulkan.

Anda berhak untuk meminta bahawa kami mengehadkan pemprosesan data peribadi anda, tertakluk kepada apa-apa pengecualian undang-undang yang membolehkan kami untuk mengumpul, menggunakan, dan mendedahkan data peribadi anda.

Kami berhak untuk mengemaskini dan membuat pindaan kepada Notis Data Peribadi ini dari semasa ke semasa. Notis Data Peribadi yang dikemaskini atau dipinda akan diterbitkan di https://www.supabaza.com/privacy-policy. Penggunaan Perkhidmatan Kami selepas Notis Data Peribadi ini dikemaskini atau dipinda akan dianggap sebagai persetujuan anda terhadap pindaan yang dibuat terhadap Notis Data Peribadi ini.

Selaras dengan Seksyen 7(3) PDPA, Notis Data Peribadi ini disediakan dalam Bahasa Malaysia dan Privacy Policy kami disediakan dalam Bahasa Inggeris. Sekiranya wujud sebarang percanggahan antara Notis Data Peribadi ini dan Privacy Policy kami, Privacy Policy kami akan diguna pakai.

Jika anda ingin mengakses atau perlu mengemaskini data peribadi anda, sila menghubungi kami dengan menghantar e-mel kepada hello@supabaza.com.

6 Mac 2021