PERSONAL DATA PROTECTION NOTICE

This Personal Data Protection Notice (“Notice”) sets out how EP Plus Group Sdn Bhd and its subsidiary/affiliated and related companies (collectively referred to as “we” or “us”) collect, store and handle personal information or personal data (“Personal Data”). This Notice applies to personal data in our possession or under our control, including personal data in the possession of third-party organisations, agencies or companies which we have engaged to collect, use, disclose or process personal data for our purposes.

COLLECTION OF PERSONAL DATA

By providing your Personal Data, purchasing our products, using / browsing our website (“the Website”), or by interacting with us in any manner, you are consenting to this Notice and the collection, use, access, transfer, storage and processing of your Personal Data as described in this Notice. In the event of any conflict between the English and other language versions, the English version shall prevail.

Please note that we may amend this Notice at any time without prior notice to you. By continuing to communicate with us, purchasing our products, using / browsing our website, or by interacting with us in any manner, following the modifications, updates or amendments to this Notice, shall signify your acceptance of such modifications, updates or amendments.

NATURE OF PERSONAL DATA

Depending on the nature of your interaction with us, some examples of “Personal Data” which we may collect from you include your name, address, telephone number, NRIC, date of birth, email address, your personal preferences, your skin concerns, your hair concerns, your health conditions, financial information such as credit card numbers, debit card numbers and bank account information, nationality, gender, photographs and other audio-visual information, employment information and any information which may identify you, your spouse or family members that has been or may be collected, stored, used and processed by us from time to time.

MODE OF COLLECTION OF PERSONAL DATA

In addition to the Personal Data you provide to us directly (i.e. during your communications with us and/or when you are using our website), we may also collect your Personal Data via a third party who has been duly authorised by you to disclose your personal data to us, or from a variety of sources, including without limitation at any events, contest, survey, seminars or talks organised or sponsored by us and/or from the cookies used on the Website. Some cookies are used by third parties to provide us with data on the effectiveness of its engagements and promotions. The cookies used by the Website not in any way collect personal data that could be used to identify a specific user. If you do not wish for your Personal Data to be collected via cookies on the Website, you may deactivate cookies in your browser.

The provision of your Personal Data is voluntary. However, if you do not provide your Personal Data, we may not be able to (i) update you on our latest products; (ii) communicate with you; (iii) provide you the products or services you require; or (iv) provide access to you for certain sections of the Website where log in is required.

PURPOSES OF COLLECTING AND PROCESSING OF PERSONAL DATA

We may collect and use your personal data for any or all of the following purposes:

Performing obligations in the course of or in connection with our provision of the products / goods and/or services requested by you;
Verifying your identity;
Communicate with you and responding to, handling, and processing queries, requests, applications, complaints, and feedback from you;
For internal administrative / record purposes;
Sending your marketing information about our products / goods or services including notifying you of our marketing events, contest, initiatives and promotions, lucky draws, membership and rewards schemes and other promotions (if any);
Any other purposes for which you have signify when providing the information; and
Transmitting to any unaffiliated third parties including our third party service providers and agents, and relevant governmental and/or regulatory authorities, for the aforementioned purposes;
Transmitting to any unaffiliated third parties including our third party service providers and agents, and relevant governmental and/or regulatory authorities, for the aforementioned purposes;
Complying with any applicable laws, regulations, codes of practice, guidelines, or rules, statutory and government requirements or to assist in law enforcement and investigations conducted by any governmental and/or regulatory authoritiesy;
To send you materials such as newsletters, articles, write-ups as well as other updates;
For prevention of crime;
For any marketing purposes;
Processing payment or credit transactions;
For user or customer relationship management procedures;
In order for you to enter into the contract to purchase the products from us;
Any other incidental business purposes related to or in connection with the above.

The purposes listed in the above clauses, e.g. complying with laws, may continue to apply even in situations where your relationship with us (for example, pursuant to a contract) has been terminated or altered in any way, for a reasonable period thereafter (including, where applicable, a period to enable us to enforce our rights under any contract with you).

We will seek your consent before collecting any additional personal data and before using your personal data for a purpose which has not been notified to you in this Notice (except where permitted or authorised by law).

TRANSFER OF PERSONAL DATA TO OTHER JURISDICTIONS

As our business / products / services may be extended to other jurisdictions, your Personal Data may be transferred to, stored, used and processed in a jurisdiction other than Malaysia / Singapore. You understand and consent to the transfer of your Personal Data out of Malaysia / Singapore as described herein.

DISCLOSURE TO THIRD PARTIES

We may engage other companies, service providers or individuals to perform functions on our behalf, and consequently we may provide access or disclose to your Personal Data to the third parties appointed by us such as those listed below (not exhaustive):

Regulatory and governmental authorities in order to comply with statutory and government requirements; or
Any professional advisors and external auditors;
Insurance providers;
Courier / freight and/or any delivery service providers;
Actual or prospective purchasers in the event we decide to divest part or all of our business through sale, merger or acquisition;
Banks and financial institutions;
Storage facility providers;
Data entry service providers;
Website maintenance and/or any information technology (IT) service providers;
Any business partners of EP Plus Group Sdn Bhd;
Any related, affiliated, subsidiaries, successors in title of EP Plus Group Sdn Bhd, including those established in the future;
Any other parties where such disclosure is required for the purposes stated above or for performing obligations in the course of or in connection with our provision of the products/goods or services requested by you.
PROTECTION OF PERSONAL DATA

To safeguard your personal data from unauthorised access, collection, use, disclosure, copying, modification, disposal or similar risks, we have introduced appropriate administrative, physical and technical measures and we endeavour, where practicable, to implement the appropriate procedures to prevent unauthorized or unlawful processing of your Personal Data and the accidental loss or destruction of, or damage to, your Personal Data.

However, you should be aware, that no method of transmission over the Internet or method of electronic storage is completely secure. While security cannot be guaranteed, we strive to protect the security of your information and are constantly reviewing and enhancing our information security measures.

ACCESS & CORRECTION REQUESTS AND INQUIRIES

Subject to any exceptions under applicable laws, you may at any time hereafter request: (i) for access to your Personal Data (ii) for correction or rectification of your Personal Data; (iii) to limit the processing of your Personal Data; or (iv) to seek further information from us regarding the processing of your Personal Data by submitting your request in writing or via email to our manager at the contact details provided below:

EP Plus Group Sdn Bhd
Block C-3-1, Plaza Mont Kiara, 2 Jalan Kiara
Mont Kiara, 50480 Kuala Lumpur, Malaysia.
Tel: +(60)3 – 6205 2728
Fax: +(60)3 – 6205 2729
Email: [email protected]

We will respond to your request as soon as reasonably possible. If we are unable to make a correction requested by you, we shall generally inform you of the reasons why we are unable to do so (except where we are not required to do so under the law).

In respect of your right to access and/or correct your Personal Data, we have the right to refuse your requests to access and/or make any correction to your Personal Data for the reasons permitted under law, such as where the expense of providing access to you is disproportionate to the risks to your privacy.

WITHDRAWING YOUR CONSENT

The consent that you provide for the collection, use and disclosure of your personal data will remain valid until such time it is being withdrawn by you in writing. You may withdraw consent and request us to stop using and/or disclosing your personal data for any or all of the purposes listed above by submitting your request in writing or via email to our manager at the contact details provided above.

Upon receipt of your written request to withdraw your consent, we may require reasonable time (depending on the complexity of the request and its impact on our relationship with you) for your request to be processed and for us to notify you of the consequences of us acceding to the same, including any legal consequences which may affect your rights and liabilities to us. In general, we shall seek to process your request within ten (10) business days of receiving it.

Whilst we respect your decision to withdraw your consent, please note that depending on the nature and scope of your request, we may not be in a position to continue providing our products / goods or services to you and we shall, in such circumstances, notify you before completing the processing of your request. Should you decide to cancel your withdrawal of consent, please inform us in writing in the manner described above.

Please note that withdrawing consent does not affect our right to continue to collect, use and disclose personal data where such collection, use and disclose without consent is permitted or required under applicable laws.

RETENTION OF PERSONAL DATA

We may retain your personal data for as long as it is necessary to fulfil the purposes for which it was collected, or as required or permitted by applicable laws.

We will cease to retain your personal data or remove the means by which the data can be associated with you, as soon as it is reasonable to assume that such retention no longer serves the purposes for which the personal data was collected and is no longer necessary for legal or business purposes.

ACKNOWLEDGEMENT AND CONSENT

By communicating, purchase or use the Company’s products / goods, website and services, you acknowledge that you have read and understood this Notice and agree and consent to the use, processing, disclosure and transfer of your Personal Data by us as described in this Notice. Any email we send to you will contain an automated unsubscribe link so that you can opt-out of the mailing list. You can also withdraw your consent by written notice or email.