Privacy Policy
Effective Date: 20 November 2024
We, Workshop2u and/or any of our subsidiaries, related companies, associates, affiliates, jointly controlled entities, shareholders, and any other entities within our group (hereinafter referred to as “Workshop2u Group of Companies”, “we”, “us”, “our” and other similar expressions), value and respect the privacy rights of all users of the websites (“Website”) and mobile applications (“App”) of the Workshop2u Group of Companies across all aspects of our business and we strive to protect your Personal Data (as defined hereunder) in compliance with the laws of Malaysia.
We will only collect and use your Personal Data (as defined hereunder) in accordance with the Personal Data Protection Act 2010 (and any other such laws that may be enacted in Malaysia related to the governance of personal data of consumers from time to time) and this privacy notice (hereinafter referred to as “Privacy Notice”) and such other term(s) in the agreement(s) that you may contract with us or have contracted with us.
For the purpose of this Privacy Notice, the term “Personal Data” shall refer to any information that relates directly or indirectly to an individual, from which the said individual may be identifiable, and shall include sensitive personal data and expressions of opinion about any individual. Sensitive Personal Data may include information such as physical or mental health or medical conditions, political opinions, religious or other similar beliefs, commission or alleged commission of any offence.
By providing your Personal Data to us, you consent to our collection, use, handling, retention, and disclosure of your Personal Data in accordance with this Privacy Notice.
Our Collection of Your Personal Data
We may collect your Personal Data directly from you including but not limited to when you:
- Register for an account on our Website and/or App;
- Contact us for information related to our Website and/or App;
- Communicate with us via any medium of communication;
- Interact with our Website and/or App;
- Take part in any of our digital or physical initiatives, such as promotions or feedback surveys.
We may also collect your Personal Data indirectly from you, when we obtain your information from third parties including but not limited to information from your referees, public records, or background check agencies who may be engaged to provide us with your Personal Data, including information regarding past criminal record(s), if any.
In the event that we are not provided with all the Personal Data that we request from you, you agree and acknowledge that we may not be able to provide you with our service(s) via our Website and/or App or continue to provide you with our service(s) via Website and/or App. For the avoidance of doubt, by providing your Personal data in any of our Platforms, you hereby agree to set up your account in all our Platforms.
The Extent and Type of Personal Data We Collect
The extent and type of Personal Data that we collect from you or any third party depends on the services you use and/or the purpose of the collection of the Personal Data. Some of the Personal Data that we collect may be sensitive in nature. This may include, but is not limited to the following:
- Personal Information: Name, government-issued identification (e.g., NRIC, passport), nationality, address, date of birth, age, gender, race, photograph, motor vehicle registration number, location information, driver’s license, background screening report, and insurance details.
- Contact Information: Residential, mailing and billing address, telephone/facsimile number, and email address.
- Transaction and Financial Details: Types of services used, credit/debit card details, and bank account information.
- Device Information: Device hardware, software, and network information, including IMEI number, UUID (unique identifier), and device model and version.
- E-Wallet Information: Balance, top-up history, and transaction information.
- Log Information: Geolocation, browser, IP address, and diagnostic data.
- Feedback and Opinions: Comments, reviews, and ratings of our services.
- Sensitive Data: Health, medical conditions, political opinions, or criminal records (if applicable and with your consent).
- If you are a company, we may collect Personal Data of your employees. You must ensure that consent is obtained from the employees before providing us with their Personal Data.
Use of Personal Data Collected
We may use the Personal Data collected for the following purposes:
- To analyse and identify users of our Website and App, potential users, and their representatives;
- To provide our services via our Website and App;
- To offer or provide related services on our Website and App, including our own value-added services or services of our business/strategic partners with whom we may collaborate. Where you choose to opt for our business/strategic partner’s services, we may share your Personal Data with them, and they may contact you as necessary to obtain additional information in order to facilitate and fulfil the provision of their services;
- To manage and maintain your account on our Website and App with us;
- For administration purposes including, but not limited to, processing, confirming, fulfilling and completing your transactions and requests made on our Website and App or any related services to our Website and App;
- To develop and/or implement initiatives including but not limited to carrying out research, benchmarking, statistical analysis, product analysis, customer profiling, analysis of customer patterns, behaviours, and choices, customer surveys, and interviews to help improve our Website and App. This also helps us better understand your requirements and interests, as well as to publish your comments, reviews, and ratings on our Website and App for advertising and marketing purposes;
- To seek your opinions or comments about our Website and App;
- To inform you about any promotions, offers and/or other benefits (including third-party benefits) that may become available, or to send you alerts, updates, newsletters, marketing and/or promotional materials, including from third parties (such as our subsidiaries, related companies, associates, affiliates, jointly controlled entities, shareholders, and any other entities within the group, business/strategic partners), through any communication channels deemed appropriate by Workshop2u, which may be of interest to you;
- To conduct internal diagnostics and related assessments to provide software updates, maintenance services, technical support, and other important updates, services, and support in relation to our Website and App;
- To conduct internal record-keeping and update any information database(s), customer service-related matters, and other administrative purposes;
- To conduct consumer and market research by analysing your usage of our Website and App, to improve our provision of new and personalised offers to you;
- To provide you with service support, management optimisation, customer support, and any other related services to our Website and App, including responding or following up on your inquiries, concerns, issues, or complaints;
- To verify your identity, conduct due diligence and background checks (including financial and criminal records check), or carry out any other monitoring or screening activities or risk management procedures that may be required by law or implemented by us;
- To detect the location of your vehicle or service-related equipment for safety and security purposes;
- To administer contests, redemptions, campaigns, or any similar promotions entered by you, including providing you with your rewards and/or prizes (monetary or non-monetary);
- To comply with our legal obligations, including responding to requests by any governmental, regulatory, or law enforcement bodies and authorities;
- For the purpose of any mergers, acquisitions, financing transactions, transfers, assignments, or joint ventures;
- For any other purpose(s) related to your relationship, requests, and transactions with us;
- For any purpose(s) required or permitted by any law, regulations, guidelines, and/or relevant regulatory authorities.
Processing of Personal Data
Where we rely on your consent to process Personal Data, you may at any time withdraw the previous consent you have provided for this processing by contacting us via email under the “Contact Us” section below. However, please note that by withdrawing your consent, it will not affect the lawfulness of the processing done based on the previous consent you provided prior to withdrawal.
There may be instances where we process your Personal Data on the basis of other lawful grounds (other than your consent) pursuant to the Personal Data Protection Act 2010. We do not seek your consent in these instances as we aim to provide you with the services offered on our Website and App in the most efficient way possible. In some cases, it may not be feasible for us to seek your consent, such as when we need to process your Personal Data for fraud detection or other necessary legal obligations.
References to consent given, or deemed to have been given, by an individual for the collection, use, or disclosure of personal data about the individual, include consent given, or deemed to have been given, by any person validly acting on that individual’s behalf for the collection, use, or disclosure of such personal data.
Sharing and Disclosure of Personal Data Collected
We shall use and disclose your Personal Data for the purpose(s) for which it was collected, as indicated above, and for any other secondary purpose(s). We may disclose your Personal Data to third parties (within or outside of Malaysia) whom we reasonably believe will require access to your information to provide you with assistance, information, or any services you may require from us. Such third parties may include:
- our Workshop2u Group of Companies;
- our contractors, sub-contractors, business or strategic partners (e.g., service providers or other third parties with whom we collaborate);
- financial service providers such as banks, credit card issuers, payment gateways, or payment service providers;
- search engine and analytics providers that assist us in optimizing or improving our Website and App;
- advertisers and advertising networks that may require information to select and serve relevant advertisements to you;
- any entities assisting with fraud investigations or processes;
- where Workshop2u or any of its related companies is involved in corporate exercises, for example, mergers, acquisitions, joint ventures, investments, funding exercises, asset sales, or other similar matters, including professional advisors or any third parties that may require the information for such purposes;
- any parties requiring such information in relation to legal proceedings;
- any governmental, regulatory, or law enforcement bodies and authorities; and
- any other third parties that we will inform you about at the point of collection of Personal Data, subject to obtaining your consent before such disclosure is made, and such disclosure shall only be provided to the extent as required by the applicable laws.
Storage of Your Personal Data
As part of the services provided through our Website and App, we may process, store, and/or transfer your Personal Data to countries outside of Malaysia. When we process, store, and/or transfer your Personal Data outside of Malaysia, we shall take reasonable steps to ensure that appropriate security measures are in place to protect your privacy rights as outlined in this Privacy Notice.
We are committed to protecting your Personal Data and therefore limit the number of employees who can access your data. Only employees who require access to your Personal Data to perform their daily responsibilities will be granted access. Our employees are always required to respect the confidentiality of your Personal Data.
We will take reasonable steps to ensure the security of your Personal Data and protect it from loss, misuse, or unauthorized alteration. To do this, we will implement both technical and organizational security measures to safeguard against such risks. While we cannot guarantee that loss, misuse, or unauthorized alteration of your Personal Data will never occur, we ensure that our systems adhere to industry-standard security practices to minimize these risks.
Access to, Correction or Deletion of Your Personal Data
You have the right to request access to, correct, or update your Personal Data that we hold. If you wish to do so, you may log into your account on our Website and App to view or modify your Personal Data.
If you are unable to access or view your Personal Data through your account on our Website and App, please send us a request through the provided form. Please note that we reserve the right to charge a reasonable fee as prescribed under the Personal Data Protection (Fees) Regulations 2013 for any access requests. Additionally, we reserve the right to refuse your request to access, correct, or update your Personal Data in certain situations as permitted by applicable laws. If we deny your request, we will inform you in writing and explain the reasons for our refusal (unless prohibited by law).
If you no longer wish to use our Website and/or App and would like to delete your account or withdraw your consent for us to process your Personal Data, you can go to the App > Account > View and Edit Profile > Tap on “Delete Account.” Please note that deleting your account on one of our Websites and/or Apps will result in the deletion of your accounts across all of our Websites and/or Apps.
Cookies
Cookies are small data files sent from a web server to your device when you visit a website. The use of cookies and similar technologies is common across web servers to recognize your online activities and personalize your experience on our Website and/or App.
If you prefer not to receive cookies, you can adjust your device settings to warn you before accepting cookies and reject them when prompted. You can also turn off all cookies by changing your device settings. By continuing to use our Website and/or App without adjusting these settings, you agree to accept cookies.
External and Third-Party Websites
Our Website and App may contain links to third-party websites or social media channels belonging to our business partners, service providers, or other external entities.
Please note that we do not operate, control, or endorse the contents of these third-party websites or social media channels. You are solely responsible for your use of these sites and should review their privacy notices and terms and conditions.
Changes to Our Privacy Notice
We may update or change this Privacy Notice at any time. Any updates will be posted on our Website and/or App, and the updated Privacy Notice will automatically replace the previous version. By continuing to use our Website and/or App or engaging with us after the updated Privacy Notice is posted, you agree to be bound by the revised terms.
Discrepancies
This Privacy Notice is available in both English and Bahasa Malaysia. In case of any discrepancies between the two versions, the English version will prevail.
Contact Us
If you have any questions or require further information regarding this Privacy Notice or your Personal Data (except for account deletion requests), please contact us at Customercare@workshop2u.com.my