Privacy Policy

Last updated
May 2022
1.    Introduction

1.1.   The Personal Data Protection Act 2010 of Malaysia (“PDPA”) strives to protect personal data of individuals. It explains the type of data we collect or have collected and who we disclosed the data to and the choices available to you including how to access and correct your personal data.

1.2.   Ablr Sdn Bhd doing business as Ablr (“Ablr” or “we” or “our” or “us”) recognises and undertakes its responsibilities under PDPA. We recognize the importance of the personal data you have entrusted to us and believe that it is our responsibility and commitment to properly manage, protect and process your personal data.

1.3.   Please read this Data Protection and Privacy Policy (“policy”) to understand what personal data is collected or processed by us, and for what purposes it is used for, how we handle, collect, use, disclose and process personal data about you that you give us, or receive through third parties or that is in our possession.

1.4.   By communicating with us or by using our services or by virtue of your engagement with us, you acknowledge and agree that you have fully read and understood this policy, and are consenting to the collection, use, processing, transfer, and disclosure of your personal data as described in this policy.

1.5.   Without prejudice to any of the foregoing, if you provide the personal data of any other third party to us, you warrant and agree that such third party has fully read and understood this policy, and has consented to you disclosing his/her personal data to us for the collection, use and disclosure by us as described in this policy.

2.    Definition of Data Protection Terms

2.1.   Data is recorded information whether stored electronically, on a computer, or in certain paper-based filing systems.

2.2.   Data processors include any person who processes personal data on behalf of a data controller. Employees of data controllers are excluded from this definition, but it could include suppliers which handle personal data on behalf of the Company.

2.3.   Personal data means any data relating to an individual who can be identified from that data or from that data and other information to which we have or may have access to. Personal data can be factual (such as a name, address or date of birth) or it can be an opinion (such as a product review). It can even include a simple e-mail address. It is important that the information has the data subject as its focus and affects the individual's privacy in some way.

2.4.   Processing is any activity that involves use of the data. It includes obtaining, recording or holding the data, or carrying out any operation or set of operations on the data including organising, adapting, altering, amending, retrieving, combining, using, disclosing, erasing or destroying it. Processing also includes transferring personal data to third parties.

3.    Types of Personal Data We Collect

3.1.   We collect information about you when you use our website(s), website/IT portal(s)/mobile application(s), forms, surveys, and/or other channels and throughout other interactions, communications and services you have with us.

3.2.   Personal data which we may collect include but are not limited to:

a)    your personal information such as your name, National ID/Passport number, date of birth, marital status, gender;

b)    your contact information such as residential or postal addresses, email addresses, telephone, mobile phone and fax numbers;

c)    your past and present employment information such as organisation name, organisation type, industry sector, job function and responsibilities, designation, business telephone and fax numbers, business email addresses;

d)    your billing and payment information, including name of the credit/debit cardholder, credit/debit card number, security code and expiry date.

3.3.   Other information collected may include proof of income and financial details, photographs, videos and/or audio recordings collected from us through online (websites, emails, apps, etc.) or offline platforms (events, surveys, phone calls, etc).

3.4.   We may collect and store certain information automatically when you visit our website(s) or use our website(s)/IT portal(s)/mobile application(s). Examples include the internet protocol (IP) address used to connect your computer or device to the Internet, connection information such as browser type and version, your operating system and platform, a unique reference number linked to the data you enter on our system, login details, the full URL clickstream to, through and from the website(s) or website/IT portal(s)/mobile application(s) (including date and time), cookie identifier and your activity on our website(s) or website/IT portal(s)/mobile application(s), including the pages you visited, the searches you made and, if relevant, the services you purchase.

3.5.   We may receive information about you from third parties if you use any websites or social media platforms operated by third parties (for example, Facebook, Instagram, Twitter etc.) and, if such functionality is available, you have chosen to link your profile on our website(s) or website/IT portal(s)/mobile application(s) with your profile on those other websites or social media platforms.

4.    Cookies

The Website uses "cookies" to identify a user's session on the Website and thereby offers continuity as the member moves around the site. Cookies are only used on the Website to store non-critical data. Cookies are pieces of information that websites transfer to your computer's hard drive for record-keeping purposes.

Cookies allow websites to maintain user information across connections. They are small strings of characters used by many websites to deliver data to your computer, and in certain circumstances, return the information to the website.

Cookies contain only information that members volunteer, and they do not have the capability of infiltrating a user's hard drive and stealing personal information. The simple function of a cookie is that of helping the user navigate a website with as little obstruction as possible.

For further information on types of cookies and how they work, visit www.allaboutcookies.org

5.    Purposes for which the Personal Data is Collected, Used and Disclosed

5.1.   We will/may collect, use, disclose and/or process your personal data for one or more of the purposes which shall include, without limitation the following:

a). To consider and/or process your application to be our customer/user and/or to process your account with us;

b). To facilitate, process, deal with and/or administer your account with us;

c). For the supply of any goods and/or services which we may offer to you or that you may request, obtain or purchase from us, website registration, enabling sales and other transactions, processing payments and settlement, sending payouts, handing order, providing receipts, perform credit check;

d). To deal with, process and/or administer your use of the online services at any of our website(s), website/IT portal(s)/mobile application(s) and/or through other digital or telecommunication channels;

e). For identification and verification purposes in connection with any of the goods and/or services that may be supplied to you by us or that you may request from us;

f). To carry out your instructions, respond to any enquiry or deal with any feedback given by (or purported to be given by) you or on your behalf, including contacting you via phone/voice call, text message and/or fax, email and/or postal mail regarding your instructions, enquiries and/or feedback;

g). To conduct research, analysis and development activities (including but not limited to data analytics, surveys, focus groups and/or profiling) to improve our services and facilities for your benefit, or to improve any of our marketing programmes or events;

h). To deal with, process and/or administer marketing campaigns conducted by us or on our behalf which you have consented to participate in;

i). To contact you or communicate with you via various modes of communication such as phone/voice call, text message and/or fax message, forms, email and/or postal mail for the purposes of administering, dealing with and/or managing your account with us. You acknowledge and agree that such communication by us could be by way of the mailing of correspondence, documents or notices to you, which could involve disclosure of certain personal data about you to bring about delivery of the same as well as on the external cover of envelopes/mail packages;

j). To carry out due diligence or other screening activities (including security and background checks) in accordance with legal or regulatory obligations or our risk management procedures that may be required by law or that may have been put in place by us;

k). To detect, prevent or investigate any fraud, unlawful activity or omission or misconduct, whether or not there is any suspicion of the aforementioned; dealing with and/or investigating complaints, detecting and preventing violations of our legal agreements, and recovering debts and collections

l). To comply with or as required by any applicable law, governmental or regulatory requirements of any jurisdiction applicable to us or our affiliates/associated companies, including meeting the requirements to make disclosure under the requirements of any law binding on us or our affiliates/associated companies, and/or for the purposes of any guidelines issued by regulatory or other authorities (whether of Malaysia or elsewhere), with which we or our affiliates/associated companies are expected to comply;

m). To comply with or as required by any request or direction of any governmental authority; or respond to requests for information from hospitals, embassies, public agencies, ministries, statutory boards or other similar authorities;

n). For marketing purposes with your consent where we send you news, information, materials and/or updates about events, marketing campaigns, products and/or services that we and/or our business partners provide, or on our behalf. In this regard, we will be doing so by way of postal mail and/or electronic transmission and/or text messages to your address, email address(es) and/or the phone number(s) you provide. You may unsubscribe from this service in the manner set out in Clause 8 below;

o). To facilitate and/or deal with payment for goods and/or services provided by us or our subsidiaries, and/or a third party on our behalf including verification of credit card details with third parties and additionally, using the personal data you provide to conduct matching procedures against databases of known fraudulent transactions (maintained by us or third parties);

p). To deal with, handle and/or conduct disciplinary, security and quality assurance processes, matters and/or arrangements.

q). To perform internal administrative, operational and technology tasks to facilitate, administer or manage your account with us;

r). To produce statistics and research for internal and/or statutory reporting and/or record-keeping requirements and performing our policy/process reviews;

s). To disclose to a third party to comply with any law, legal requirements, orders, directions or requests from any court, authority or government body of any jurisdiction, which may be within or outside Malaysia;

t). To help us measure, improve and customizing our services to you; and/or

u). To store, host, back up (whether for disaster recovery or otherwise) of your personal data, whether within or outside Malaysia.

(collectively, referred to as the “Purposes”)

5.2.   We may/will need to disclose your personal data to third parties, including to banks, payment service providers and/or other payment gateways, whether located within or outside Malaysia, for one or more of the above Purposes, as such third parties, would be processing your personal data for one or more of the above Purposes. In this regard, you hereby acknowledge, agree and consent that we may/are permitted to disclose your personal data to such third parties (whether located within or outside Malaysia) for one or more of the above Purposes and for the said third parties to subsequently collect, use, disclose and/or process your personal data for or more of the above Purposes. Without limiting the generality of the foregoing, such third parties including but without limitation to:

a)    our associated/affiliated organisations or related corporations;

b)    any of our collaborative partners, agents, contractors or third party service providers that process or will be processing your personal data on our behalf including but not limited to those which provide administrative or other services to us such as mailing houses, telecommunication companies, information technology companies and data centres;

c)    third parties to whom disclosure by us is for one or more of the Purposes and such third parties would in turn be collecting and processing your personal data for one or more of the Purposes;

d)    Merchants concerned on a need-to-know basis to complete the sale transaction and handling of orders;

e)    Credit reporting agencies, third party service providers;

f)     Our auditors, lawyers, consultants, insurers, advisers, bankers and agents; and

g)    All other persons or bodies who provide us with services necessary and/ or incidental to our business.

5.3.   We may share your information with any member of our group (which means our subsidiaries, our ultimate holding company and its subsidiaries from time to time for one or more of the Purposes.

5.4.   You may withdraw your consent for the collection, use and/or disclosure of your personal data in our possession or under our control by contacting us. However, your withdrawal of consent could result in certain legal consequences arising from such withdrawal, including us being unable to perform the transactions requested by you on our website(s) or website/IT portal(s)/mobile application(s). Do note that your withdrawal of consent will not affect our ability to collect, use or disclose your personal data for a specific purpose without your consent, if the PDPA or a provision in applicable law permits us to.

5.5.   We may collect, use, disclose or process your personal data for other purposes that do not appear above. However, we will notify you of such other purposes at the time of obtaining your consent, unless processing of your personal data without your consent is permitted by the PDPA or by law.

5.6.   We may/will also be collecting from sources other than yourself, personal data about you, for one or more of the above Purposes, and thereafter using, disclosing and/or processing such personal data for one or more of the above Purposes. We may combine information we receive from other sources with information you give to us and information we collect about you. We may use this information and the combined information for the Purposes set out above (depending on the types of information we receive).

6.    Security of Personal Data

6.1.   Security of your personal data is important to us. We take appropriate action to protect personal data from loss, misuse, unauthorised access or disclosure, alteration or destruction using the same safeguards as we use for our own proprietary information. All information you provide to us is stored on secure servers and encrypted using the industry-standard AES-256 encryption algorithm. Where we have given you a one-time password (OTP) which enables you to access certain parts of our website(s) or website/IT portal(s)/mobile application(s), you are responsible for keeping this OTP confidential. We ask you not to share your OTP with anyone.

6.2.   We will put in place measures such that your personal data in our possession or under our control is destroyed and/or anonymized as soon as it is reasonable. Your financial data is processed by PCI DSS certified provider. However, you are advised to follow certain security practices yourself. You must never share your Account or OTP with anyone. If you are concerned that your account has been compromised, contact our Customer Service immediately.

6.3.   Some of our security features include the following:

a)    Firewall

b)    DDOS attack protection

c)    3DS Compliance

7.    Link to Other Websites

7.1.   Our website(s), website/IT portal(s)/mobile application(s) and other digital and telecommunication channels may contain links to other sites that are operated by third party companies with different privacy practices. You should remain alert and read the privacy statements of other sites. We have no control over personal data that you submit to or receive from these third parties.

8.    Withdrawal of Consent for Marketing Purposes

8.1.   You have the right to ask us not to use your personal data for marketing purposes. If you no longer wish to receive marketing messages from us, you may request to withdraw your consent by emailing or writing to us, or if applicable, using the unsubscribe facility contained in the marketing message.

9.    Data Access and Correction

9.1.   You have the right to access and/or correct any personal data that we hold about you, subject to the requirements of the PDPA. If you would like to request for a copy of your personal data being held by us (such right being subject to applicable exemptions), or to update and/or correct the personal data which you have previously provided to us, please email or write to us.

9.2.   We will need enough information from you in order to ascertain your identity as well as the nature of your request, so as to be able to deal with your request. We reserve the right, or may, charge a reasonable fee for the processing of any data access request.

9.3.   For a request to access personal data, once we have sufficient information from you to deal with the request, we will seek to provide you with the relevant personal data within 30 days. Where we are unable to respond to you within the said 30 days, we will notify you of the soonest possible time within which we can provide you with the information requested within 14 days.

9.4.   For a request to correct personal data, once we have sufficient information from you to deal with the request, we will correct your personal data within 30 days. Where we are unable to do so within the said 30 days, we will notify you of the soonest practicable time within 14 days which we can make the correction. Note that the PDPA exempts certain types of personal data from being subject to your correction request as well as provides for situation(s) when correction need not be made by us despite your request. We will send the corrected personal data to every other organisation to which the personal data was disclosed by us within a year before the date the correction was made, unless that other organisation does not need the corrected personal data for any legal or business purpose.

10.  Complaint Process

10.1. If you have any complaint or grievance regarding how we are handling your personal data or about how we are complying with the PDPA, we welcome you to contact us with your complaint or grievance by emailing or writing to our data protection officer.

10.2. When you are sending an email in which you are submitting a complaint, your indication at the subject header that it is a PDPA complaint would assist us in attending to your complaint speedily by passing it on to the relevant staff in our organisation to handle. For example, you could insert the subject header as “PDPA Complaint”.

10.3. We will certainly strive to deal with any complaint or grievance that you may have speedily and fairly.

11.  General

11.1. Your consent that is given pursuant to this Privacy Policy is additional to and does not supersede any other consents that you had provided to us with regard to processing of your personal data.

11.2. For the avoidance of doubt, in the event that Malaysia personal data protection law permits an organisation such as us to collect, use or disclose your personal data without your consent, such permission granted by the law shall continue to apply.

12.  Enquiries

12.1. For any enquiries on our privacy policy, please write to help@ablr.com

13.  We reserve the right to amend, vary or modify this policy with or without notice. Any changes to this policy will be effective after posting at the Website or notice to you. Continued use of Ablr’s service(s) indicates your re-acceptance of the revised policy. The most recent revision date of these terms is identified above.