PRIVACY & COOKIES POLICY

1.
Introduction
1.1
This is the Privacy and Cookies Policy ("Policy") of Pointsnet Sdn. Bhd. ("the Company" or "We" or "Us") who owns and operates eVoucha Digital Vouchers Application (eVoucha) and its Services. In the course of providing you with the Services or access to the Company’s Website, We will be collecting data, including your personal data.
1.2
This Policy is incorporated as part of the eVoucha’s Terms of Use. Your use of eVoucha and its Services is subjected to the Terms of Use and this Policy. Unless specifically defined in this Policy, the defined terms shall have the same meaning as defined in the Terms of Use
1.3
This Notice is issued in accordance with the Malaysian Personal Data Protection Act 2010.
1.4
This Policy sets out to keep you in the know about how We use, process and handle the data We collect and receive during the course of providing the Services or access to the Website by You. We will only collect, use and disclose your personal data in accordance with this Policy.
1.5
By accessing and/or signing up for our Services or using our Services to make transactions, specifically by tapping on "Submit" button or similar buttons, You acknowledge that You have been notified of and understood the terms of this Policy and that You have agreed to the collection and processing of your personal data as described and under the terms herein.
1.6
We may update this Policy from time to time. Any changes We make to this Policy in the future will be posted on this page and, where appropriate, notified to You by email, whereupon your continued use of the Services or access to the Website, shall constitute your acknowledgment and acceptance of the changes We make to this Policy.
1.7
This Policy applies only to your use of the Services and Website. The Services and Website may contain links to other websites. Please note that We have no control over how your data is collected, stored, or used by other websites and We advise You to check the privacy policies of any such websites before providing any data to them.
1.8
If You have any comments, suggestions or complaints in relation to your personal data, You can contact us by email at [email protected]
2.
The Personal Data We Collect From You & Purpose
2.1
We MAY collect the following personal data from You, depending upon your use of the Services and Website:
(a)
Identity data, such as your name, NRIC number, gender, and date of birth;
(b)
Contact data, such as billing address, delivery address, email address, and phone numbers;
(c)
Financial information such as transaction details
(d)
Loyalty program account information;
(e)
Transaction data, such as details about payments including products or services that You have purchased using the Services;
(f)
Technical data, such as internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices You use to access the Services;
(g)
Profile data, such as your username and password, purchases or orders made by You, your interests, preferences, feedbacks and survey responses;
(h)
Marketing and communications data, such as your preferences in receiving marketing materials from Us and our third parties and your communication preferences.
2.2
In addition, We may also receive, store and process your personal data which are provided or made available by any third parties whom You have authorized, i.e credit reference/reporting bodies, regulatory and law enforcement authorities, for reasons including delivery of the Services, performance of conditions of agreements and/or to comply with our legal and regulatory obligations.
2.3
Our use of your personal data will always have a lawful basis, either because it is necessary for the performance of our Services as requested by You, or because You have consented to our use of your personal data (e.g. by subscribing to emails), or because it is in our legitimate interest. Specifically, We may use your data in order to:
a.
Authenticate your identity
b.
Register You to receive the relevant Services You have requested
c.
Communicate with your loyalty program provider(s)
d.
Process transactions You have requested which involve 3rd party service providers, which include and not limited to
  • validate your purchases/reservations/bookings
  • process online banking, credit/debit card transactions
  • process online credit check for instalments approval
e.
Communicate with the Company’s merchants, affiliates and partners
f.
Send notification via emails, Internet messaging or SMS and replying emails from You
g.
Analyse your use of the Services and Website and gathering feedback to enable Us to continually improve the Services and Website and your user experience
h.
Provide You with marketing materials by email, telephone, SMS and/or by post, but only when You have given Us your permission to do so.
2.4
You must only submit personal data that is accurate and not misleading and You must keep it up to date and inform Us of any changes. We shall have the right to request for documentation to verify the personal data provided by You as part of our customer verification process.
2.5
We will only be able to collect your personal data if You voluntarily submit personal data to Us. Unfortunately, if You choose not to submit your personal data to Us or subsequently withdraw your consent to our use of your personal data, We may not be able to provide You with the Services.
2.6
If You provide personal data of any third party to Us, You represent and warrant that You have obtained the necessary consent from that third party to share and transfer his/her personal data to Us, and for Us to collect, use and disclose that data in accordance with this Policy.
3.
Recipients of Gift
When You choose to use the Services to send Gift to an individual, You represent that You have the recipient’s consent to provide Us the latter’s name, email address and/or mobile number. We will automatically send the recipient, a message via SMS, Internet messaging and/or email informing him/her of the Gift. Unless your recipient authorizes Us, We will only use your recipient’s name, email address and/or mobile number for the purpose of sending the Gift and reminders and maintaining an activity log of it.
4.
Security
4.1
We take your privacy seriously. We are committed to complying with all data protection laws as are applicable to Us to protect your personal data against unauthorized access, use or disclosure. Your personal data will be stored either in hard copies in the Company office or stored in a server operated by the Company or any of its service providers.
4.2
All Internet communication is secured using Secure Socket Layer (SSL) technology with high security 256bit encryption. Other security features include, Layer 7 Application firewall, Hardware firewall and 3D-Secure Compliance ("Verified by Visa" & "MasterCard SecureCode")
4.3
No data transmission over the Internet or any wireless network can be guaranteed to be 100% secure. While We take practical steps to protect your personal data, We cannot and do not accept responsibility for any unauthorized access, unlawful interceptions or loss of personal data transmitted during provision of the Services, and are not responsible for the actions of any third party that may receive such personal data.
4.4
The Company is PCI DSS Level 1 compliant. You are advised to implement security practices yourself. You must never share your account or login details with anyone. If You are concerned that any of your login details have been compromised, You can change them at any time You like once You are logged on, and immediately contact Us by email at [email protected]
5.
Withdrawal of Consent and Deletion of Personal Data
5.1
You may communicate the withdrawal of your consent to the continued use or disclosure of your personal data at any time, or request deletion of your personal data, by emailing us at [email protected]
5.2
Please note that if You communicate your withdrawal of your consent to our use or disclosure of your personal data in the manner as stated above, or request deletion of your personal data, we may not be in a position to continue to provide the Services.
6.
Updating Your Personal Data
6.1
It is important that the personal data You provide to Us is accurate. You are responsible for informing Us of any changes to your personal data, in the event You believe that the personal data We have about You is inaccurate, incomplete, misleading or out of date. You can update your personal data at anytime by accessing your Account. If you are unable to update your personal data through your Account, You can do so by emailing to us at [email protected]
6.2
We take steps to share the updates to your personal data with our merchants, affiliates and partners with whom We have shared your personal data with if your personal data is still necessary for the above-stated purposes.
7.
Retention of Personal Data
7.1
We will only retain your personal data for as long as We are either required to by law or as is relevant for the purposes for which it was collected.
7.2
We will cease to retain your personal data, or remove the means by which the data can be associated with You, as soon as it is reasonable to assume that such retention no longer serves the purpose for which the personal data was collected, and is no longer necessary for any legal or business purpose.
8.
Collection of Computer Data, Use of Cookies
The Website uses "cookies" to identify a User’s session on the Website and thereby offers continuity as the member moves around the Website. Cookies are only used on the Website to store non-critical data. Cookies are pieces of information that a website transfers to your computer’s hard drive for record-keeping purposes. Cookies allow websites to maintain user information across connections. They are small strings of characters used by many websites to deliver data to your computer, and in certain circumstances, return the information to the website. Cookies contain only information that users volunteer, and they do not have the capability of infiltrating a user’s hard drive and stealing personal information. The simple function of a cookie is that of helping the user navigate a website with as little obstruction as possible.
9.
The Company's Right to Disclose Personal Data
9.1
You acknowledge and agree that the Company has the right to disclose your personal data to any legal, regulatory, governmental, tax, law enforcement or other authorities, if the Company has reasonable grounds to believe that disclosure of personal data is necessary for the purpose of meeting any obligations, requirements or arrangements, whether voluntary or mandatory, as a result of cooperating with an order and investigation.
9.2
In the event of a potential, proposed or actual sale of business, disposal, acquisition and merger ("Transactions"), your personal data may be required to be disclosed and transferred to a 3rd party as a result of the Transaction. You hereby acknowledge that such disclosure and transfer may occur and in agreement to share your personal data to the relevant parties.
9.3
To the extent permissible by applicable law, You agree not to take any legal action and waive your rights to take any action against the Company for the disclosure of your personal data in these circumstances.

Privacy & Cookies Policy are updated as at 15th December 2019