1.2 "Personal Data" or "personal data" means data, whether true or not, about an individual who can be identified from that data, or from that data and other information to which an organisation has or is likely to have access. Common examples of personal data could include name, identification number and contact information.
2. WHEN WILL CAROMA COLLECT PERSONAL DATA?
2.1 We will/may collect personal data about you:
2.1.1 when you register and/or use our Services or Site, or open an account with us;
2.1.2 when you submit any form, including, but not limited to, application forms or other forms relating to any of our products and services, whether online or by way of a physical form;
2.3 when you enter into any agreement or provide other documentation or information in respect of your interactions with us, or when you use our products and services;
2.4 when you interact with us, such as via telephone calls (which may be recorded), letters, fax, face-to-face meetings, social media platforms and emails;
2.5 when you use our electronic services, or interact with us via our application or use services on our website. This includes, without limitation, through cookies which we may deploy when you interact with our application or website;
2.6 when you carry out transactions through our Services;
2.7 when you provide us with feedback or complaints;
2.8 when you register for a contest; or
2.9 when you submit your personal data to us for any reason.
The above does not purport to be exhaustive and sets out some common instances of when personal data about you may be collected.
3. WHAT PERSONAL DATA WILL CAROMA COLLECT?
3.1 The personal data that CAROMA may collect includes but is not limited to:
3.1.2 Email Address/;
3.1.3 Date Of Birth;
3.1.4 Billing Address;
3.1.5 Telephone Number;
3.1.6 any other information about the User when the User signs up to use our Services or website, and when the User uses the Services or website, as well as information related to how the User uses our Services or website; and
3.1.7 aggregate data on content the User engages with.
3.2 If you do not want us to collect the aforementioned information/personal data, you may opt out at any time by notifying our Data Protection Officer in writing about it. Further information on opting out can be found in the section below entitled "How can you opt-out, remove, request access to or modify information you have provided to us?" . Note, however, that opting out of us collecting your personal data or withdrawing your consent for us to collect, use or process your personal data may affect your use of the Services. For example, opting out of the collection of location information will cause its location-based features to be disabled.
4. SETTING UP AN ACCOUNT
In order to use certain functionalities of the Services, you will have to create a user account which requires you to submit certain personal data. When you register and create an account, we require you to provide us with your name and email address as well as a user name that you select. We also ask for certain information about yourself such as your telephone number, email address, shipping address, Upon activating an account, you will select a user name and password. Your user name and password will be used so you can securely access and maintain your account.
5. VIEWING WEB PAGES
As with most websites, your computer sends information which may include personal data about you that gets logged by a web server when you browse our Site. This typically includes without limitation your computer's IP address, operating system, browser name/version, the referring web page, requested page, date/time, and sometimes a "cookie" (which can be disabled using your browser preferences) to help the site remember your last visit. If you are logged in, this information is associated with your personal account. The information is also included in anonymous statistics to allow us to understand how visitors use our site.
We may from time to time implement "cookies" or other features to allow us or third parties to collect or share information that will help us improve our Site and the Services we offer, or help us offer new services and features. “Cookies” are identifiers we transfer to your computer or mobile device that allow us to recognize your computer or device and tell us how and when the Services or website are used or visited, by how many people and to track movements within our website. We may link cookie information to personal data. Cookies also link to information regarding what items you have selected for purchase and pages you have viewed. This information is used to keep track of your shopping cart, for example. Cookies are also used to deliver content specific to your interest and to monitor website usage.
7. VIEWING AND DOWNLOADING CONTENT AND ADVERTISING
As with browsing web pages, when you watch content and advertising and access other software on our Site or through the Services, most of the same information is sent to us (including, without limitation, IP Address, operating system, etc.); but, instead of page views, your computer sends us information on the content, advertisement viewed and/or software installed by the Services and the website and time.
8. COMMUNITY & SUPPORT
We provide customer service support through email, SMS and feedback forms. In order to provide customer support, we will ask for your email address and mobile phone number. We only use information received from customer support requests, including, without limitation, email addresses, for customer support services and we do not transfer to or share this information with any third parties.
From time-to-time, we may request information from Users via surveys. Participation in these surveys is completely voluntary and you therefore have a choice whether or not to disclose your information to us. Information requested may include, without limitation, contact information (such as your email address), and demographic information (such as interests or age level). Survey information will be used for the purposes of monitoring or improving the use and satisfaction of the Services and will not be transferred to third parties, other than our contractors who help us to administer or act upon the survey.
10. HOW DO WE USE THE INFORMATION YOU PROVIDE US?
10.1 We may collect, use, disclose and/or process your personal data for one or more of the following purposes:
10.1.1 to consider and/or process your application/transaction with us or your transactions or communications with third parties via the Services;
10.1.2 to manage, operate, provide and/or administer your use of and/or access to our Services and our website, as well as your relationship and user account with us;
10.1.3 to manage, operate, administer and provide you with as well as to facilitate the provision of our Services, including, without limitation, remembering your preferences;
10.1.4 to tailor your experience through the Services by displaying content according to your interests and preferences, providing a faster method for you to access your account and submit information to us and allowing us to contact you, if necessary;
10.1.5 to respond to, process, deal with or complete a transaction and/or to fulfil your requests for certain products and services and notify you of service issues and unusual account actions;
10.1.6 to enforce our Terms of Service or any applicable end user license agreements;
10.1.7 to protect personal safety and the rights, property or safety of others;
10.1.8 for identification and/or verification;
10.1.9 to maintain and administer any software updates and/or other updates and support that may be required from time to time to ensure the smooth running of our Services;
10.1.10 to deal with or facilitate customer service, carry out your instructions, deal with or respond to any enquiries given by (or purported to be given by) you or on your behalf;
10.1.11 to contact you or communicate with you via voice call, text message and/or fax message, email and/or postal mail or otherwise for the purposes of administering and/or managing your relationship with us or your use of our Services, such as but not limited to communicating administrative information to you relating to our Services. You acknowledge and agree that such communication by us could be by way of the mailing of correspondence, documents or notices to you, which could involve disclosure of certain personal data about you to bring about delivery of the same as well as on the external cover of envelopes/mail packages;
10.1.12 to allow other users to interact or connect with you on the Platform, including to inform you when another User has sent you a private message or posted a comment for you on the Site;
10.1.13 to conduct research, analysis and development activities (including, but not limited to, data analytics, surveys, product and service development and/or profiling), to analyse how you use our Services, to improve our Services or products and/or to enhance your customer experience;
10.1.14 to allow for audits and surveys to, among other things, validate the size and composition of our target audience, and understand their experience with Caroma’s Services;
10.1.15 where you give us your prior consent, for marketing and in this regard, to send you by various modes of communication such as postal mail, email, location-based services or otherwise, marketing and promotional information and materials relating to products and/or services (including, without limitation, products and/or services of third parties whom Caroma may collaborate or tie up with) that Caroma (and/or its affiliates or related corporations) may be selling, marketing or promoting, whether such products or services exist now or are created in the future.
10.1.16 to respond to legal processes or to comply with or as required by any applicable law, governmental or regulatory requirements of any relevant jurisdiction, including, without limitation, meeting the requirements to make disclosure under the requirements of any law binding on Caroma or on its related corporations or affiliates;
10.1.17 to produce statistics and research for internal and statutory reporting and/or record-keeping requirements;
10.1.18 to carry out due diligence or other screening activities (including, without limitation, background checks) in accordance with legal or regulatory obligations or our risk management procedures that may be required by law or that may have been put in place by us;
10.1.19 to audit our Services or Caroma business;
10.1.20 to prevent or investigate any actual or suspected violations of our Terms of Service, fraud, unlawful activity, omission or misconduct, whether relating to your use of our Services or any other matter arising from your relationship with us.
10.1.21 to store, host, back up (whether for disaster recovery or otherwise) of your personal data, whether within or outside of your jurisdiction;
10.1.22 to deal with and/or facilitate a business asset transaction or a potential business asset transaction, where such transaction involves Caroma as a participant or involves only a related corporation or affiliate of Caroma as a participant or involves Caroma and/or any one or more of Caroma's related corporations or affiliates as participant(s), and there may be other third party organisations who are participants in such transaction. A “business asset transaction” refers to the purchase, sale, lease, merger, amalgamation or any other acquisition, disposal or financing of an organisation or a portion of an organisation or of any of the business or assets of an organisation; and/or
10.1.23 any other purposes which we notify you of at the time of obtaining your consent.(collectively, the “Purposes”).
10.2 As the purposes for which we will/may collect, use, disclose or process your personal data depend on the circumstances at hand, such purpose may not appear above. However, we will notify you of such other purpose at the time of obtaining your consent, unless processing of the applicable data without your consent is permitted by the Privacy Laws.
11. SHARING OF INFORMATION FROM THE SERVICES
Our Services enable Users to share personal information with each other, in almost all occasions without Caroma’s involvement, to complete transactions. In a typical transaction, Users may have access to each other’s name, user ID, email address and other contact and postage information. Our Terms of Service require that Users in possession of another User’s personal data (the “Receiving Party”) must (i) comply with all applicable Privacy Laws; (ii) allow the other User (the “Disclosing Party”) to remove him/herself from the Receiving Party’s database; and (iii) allow the Disclosing Party to review what information have been collected about them by the Receiving Party.
12. HOW DOES CAROMA PROTECT AND RETAIN CUSTOMER INFORMATION?
12.1 We implement a variety of security measures and strive to ensure the security of your personal data on our systems. User personal data is contained behind secured networks and is only accessible by a limited number of employees who have special access rights to such systems. However, there can inevitably be no guarantee of absolute security.
13. DOES CAROMA DISCLOSE THE INFORMATION IT COLLECTS FROM ITS VISITORS TO OUTSIDE PARTIES?
13.1 In conducting our business, we will/may need to disclose your personal data to our third party service providers, agents and/or our affiliates or related corporations, and/or other third parties, whether sited in Malaysia for one or more of the above-stated Purposes. Such third party service providers, agents and/or affiliates or related corporations and/or other third parties would be processing your personal data either on our behalf or otherwise, for one or more of the above-stated Purposes. Such third parties include, without limitation:
13.1.1 our subsidiaries, affiliates and related corporations;
13.1.2 other users of our Platform for one or more of the above-stated Purposes;
13.1.3 contractors, agents, service providers and other third parties we use to support our business. These include but are not limited to those which provide administrative or other services to us such as mailing houses, telecommunication companies, information technology companies and data centres;
13.1.4 a buyer or other successor in the event of a merger, divestiture, restructuring, reorganization, dissolution or other sale or transfer of some or all of Caroma’s assets, whether as a going concern or as part of bankruptcy, liquidation or similar proceeding, in which personal data held by Caroma about our Service Users is among the assets transferred; or to a counterparty in a business asset transaction that Caroma or any of its affiliates or related corporations is involved in; and
13.1.5 third parties to whom disclosure by us is for one or more of the Purposes and such third parties would in turn be collecting and processing your personal data for one or more of the Purposes
13.2 This may require, among other things, share statistical and demographic information about our Users and their use of the Services with suppliers of advertisements and programming. This would not include anything that could be used to identify you specifically or to discover individual information about you.
13.3 For the avoidance of doubt, in the event that Privacy Laws or other applicable laws permit an organisation such as us to collect, use or disclose your personal data without your consent, such permission granted by the laws shall continue to apply.
13.4 Third parties may unlawfully intercept or access personal data transmitted to or contained on the site, technologies may malfunction or not work as anticipated, or someone might access, abuse or misuse information through no fault of ours. We will nevertheless deploy reasonable security arrangements to protect your personal data as required by the Privacy Laws; however there can inevitably be no guarantee of absolute security such as but not limited to when unauthorised disclosure arises from malicious and sophisticated hacking by malcontents through no fault of ours.
14. INFORMATION ON CHILDREN
The Services are not intended for children under the age of 13. We do not knowingly collect or maintain any personal data or non-personally-identifiable information from anyone under the age of 13 nor is any part of our Site or other Services directed to children under the age of 13. As a parent or legal guardian, please do not allow such children under your care to submit personal data to Caroma. In the event that personal data of a child under the age of 13 in your care is disclosed to Caroma, you hereby consent to the processing of the child's personal data and accept and agree to be bound by this Policy on behalf of such child. We will close any accounts used exclusively by such children and will remove and/or delete any personal data we believe was submitted without any parental consent by any child under the age of 13.
15. INFORMATION COLLECTED BY THIRD PARTIES
15.2 We, and third parties, may from time to time make software applications downloads available for your use on or through the Services. These applications may separately access, and allow a third party to view, your identifiable information, such as your name, your user ID, your computer's IP Address or other information such as any cookies that you may previously have installed or that were installed for you by a third party software application or website. Additionally, these applications may ask you to provide additional information directly to third parties. Third party products or services provided through these applications are not owned or controlled by Caroma. You are encouraged to read the terms and other policies published by such third parties on their websites or otherwise.
16. DISCLAIMER REGARDING SECURITY AND THIRD PARTY SITES
16.1 WE DO NOT GUARANTEE THE SECURITY OF PERSONAL DATA AND/OR OTHER INFORMATION THAT YOU PROVIDE ON THIRD PARTY SITES. We do implement a variety of security measures to maintain the safety of your personal data that is in our possession or under our control. Your personal data is contained behind secured networks and is only accessible by a limited number of persons who have special access rights to such systems, and are required to keep the personal data confidential. When you place orders or access your personal data, we offer the use of a secure server. All personal data or sensitive information you supply is encrypted into our databases to be only accessed as stated above.
16.2 In an attempt to provide you with increased value, we may choose various third party websites to link to, and frame within, the Site. We may also participate in co-branding and other relationships to offer e-commerce and other services and features to our visitors. These linked sites have separate and independent privacy policies as well as security arrangements. Even if the third party is affiliated with us, we have no control over these linked sites, each of which has separate privacy and data collection practices independent of us. Data collected by our co-brand partners or third party web sites (even if offered on or through our Site) may not be received by us.
16.3 We therefore have no responsibility or liability for the content, security arrangements (or lack thereof) and activities of these linked sites. These linked sites are only for your convenience and you therefore access them at your own risk. Nonetheless, we seek to protect the integrity of our Site and the links placed upon each of them and therefore welcome any feedback about these linked sites (including, without limitation, if a specific link does not work).
17. HOW CAN YOU OPT-OUT, REMOVE, REQUEST ACCESS TO OR MODIFY INFORMATION YOU HAVE PROVIDED TO US?
17.1 Opting Out and Withdrawing Consent
17.1.1 To modify your email subscriptions, please let us know by sending an email to our Personal Data Protection Officer at the address listed below. Please note that due to email production schedules, you may still receive emails that are already in production.
17.1.3 Once we have your clear withdrawal instructions and verified your identity, we will process your request for withdrawal of consent, and will thereafter not collect, use and/or disclose your personal data in the manner stated in your request. If we are unable to verify your identity or understand your instructions, we will liaise with you to understand your request.
17.1.4 However, your withdrawal of consent could result in certain legal consequences arising from such withdrawal. In this regard, depending on the extent of your withdrawal of consent for us to process your personal data, it may mean that we will not be able to continue providing the Services to you, we may need to terminate your existing relationship and/or the contract you have with us, etc., as the case may be, which we will inform you of.
17.2 Requesting Access and/or Correction of Personal Data
17.2.1 If you have an account with us, you may personally access and/or correct your personal data currently in our possession or control through the Account Settings page on the Site. If you do not have an account with us, you may request to access and/or correct your personal data currently in our possession or control by submitting a written request to us. We will need enough information from you in order to ascertain your identity as well as the nature of your request so as to be able to deal with your request. Hence, please submit your written request by sending an email to our Personal Data Protection Officer at the email address listed below in Section 19.2.
17.2.2 For a request to access personal data, once we have sufficient information from you to deal with the request, we will seek to provide you with the relevant personal data within 30 days (or, if you are resident in Malaysia, 21 days). Where we are unable to respond to you within the said 30 days (or, if you are resident in Malaysia, 21 days), we will notify you of the soonest possible time within which we can provide you with the information requested. Note that Privacy Laws may exempt certain types of personal data from being subject to your access request.
17.2.3 For a request to correct personal data, once we have sufficient information from you to deal with the request, we will:
18.104.22.168 correct your personal data within 30 days (or, if you are resident in Malaysia, 21 days). Where we are unable to do so within the said period, we will notify you of the soonest practicable time within which we can make the correction. Note that Privacy Laws may exempt certain types of personal data from being subject to your correction request as well as provides for situation(s) when correction need not be made by us despite your request; and
22.214.171.124 we will send the corrected personal data to every other organisation to which the personal data was disclosed by us within a year before the date the correction was made, unless that other organisation does not need the corrected personal data for any legal or business purpose.
17.2.4 Notwithstanding sub-paragraph (b) immediately above, we may, if you so request, send the corrected personal data only to specific organisations to which the personal data was disclosed by us within a year before the date the correction was made.
17.2.5 We will/may also be charging you a reasonable fee for the handling and processing of your requests to access your personal data. If 17 we so choose to charge, we will provide you with a written estimate of the fee we will be charging. Please note that we are not required to respond to or deal with your access request unless you have agreed to pay the fee.
17.2.6 We reserve the right to refuse to correct your personal data in accordance with the provisions as set out in Privacy Laws, where they require and/or entitle an organisation to refuse to correct personal data in stated circumstances.
17.3This may require, among other things, share statistical and demographic information about our Users and their use of the Services with suppliers of advertisements and programming. This would not include anything that could be used to identify you specifically or to discover individual information about you.
17.4 For the avoidance of doubt, in the event that Privacy Laws or other applicable laws permit an organisation such as us to collect, use or disclose your personal data without your consent, such permission granted by the laws shall continue to apply.
17.5 Third parties may unlawfully intercept or access personal data transmitted to or contained on the site, technologies may malfunction or not work as anticipated, or someone might access, abuse or misuse information through no fault of ours. We will nevertheless deploy reasonable security arrangements to protect your personal data as required by the Privacy Laws; however there can inevitably be no guarantee of absolute security such as but not limited to when unauthorised disclosure arises from malicious and sophisticated hacking by malcontents through no fault of ours.
18. QUESTIONS, CONCERNS OR COMPLAINTS? CONTACT US
If you have any questions or concerns about our privacy practices or your dealings with the Services, please do not hesitate to contact: [email protected]
If you have any complaint or grievance regarding how we are handling your personal data or about how we are complying with Privacy Laws, we welcome you to contact us with your complaint or grievance.
Please contact us through email with your complaint or grievance:
E-mail: [email protected] and Attention it to the "Personal Data Protection Officer".
19. TERMS AND CONDITIONS
Please also read the Terms of Service establishing the use, disclaimers, and limitations of liability governing the use of the Site and the Services and other related policies.