Privacy Policy
GRAND SURF SDN BHD (547143-T)
Data Protection Notice
This Notice is issued by Grand Surf Sdn Bhd (547143-T) (“MCSB”, we”, “us”, or “our”) to all our customer customers, prospective customers and/or any person who browse use access visit our website https://redpay.com.my or our mobile applications with the name of RedPay Mobile App or such other names so determined by us from time to time.
This Notice describes how we process (includes collect, record, hold or store) your data and your rights with regards to your data that is being and/or will be, collected, processed and retained by us, including: –
  1. Description of Data That We Are Collecting and Processing
  2. Purposes of Your Personal Data is being or to be Collected and Processed
  3. Sources of Your Personal Data
  4. Persons to whom Your Data may be Disclosed
  5. Retention and Security of Your Personal Data
  6. Your Rights to Your Personal Data
  7. Your Obligations in Providing Your Personal Data
  8. How to Change Your Personal Data Processing Method Unless otherwise expressly provided herein or the context so requires, the words used in this Notice shall have the same meanings stipulated in the Personal Data Protection Act 2010 (“PDPA”) or our Terms of Use, as the case may be

1. Description of Data That We Are Collecting and Processing

In order for us to provide you the Service and/or to achieve the purposes as set out in Item 2 below, we need and/or may need to process your personal data and ancillary information.

1.1 Personal data means any information that relates directly or indirectly to you, by which you will be identified or identifiable from that information or from that and other information that we have on you.

1.2 Examples of personal data that you are required and/or will be required to provide to us includes your full name, identity card number or passport number, nationality, gender, email address, mobile phone number, mailing address, date of birth and such additional information and/or supporting documents may be required to achieve the Purposes as set out in Item 2 below.

2. Purposes of Your Personal Data is being or to be Collected and Processed

The purposes of your personal data being or to be collected and processed shall include:-

2.1 Provision of Services

  • Creation and maintenance of your RedPay Account; » Provision of the Services;
  • Your identification as RedPay Account user;
  • Facilitation of all transactions between you and the Merchant including purchase of products or services;
  • Notification of payment status, order notification and confirmations, account balance, security or support and maintenance advisories, changes on Terms of Use and such other administrative notification;
  • Redemption of MRewards;
  • Responding to your query and request

2.2 Merchant Services & Products

  • Delivery or facility the delivery of the services or products by the Merchant;
  • Facilitation of communication between you and Merchant;

2.3 Marketing and Promoting

  • Promotion of our Services and/or products and services;
  • Research, benchmarking and statistical analysis of our Services;
  • Promotion of products and services we think may be of interest to you
  • Improve, personalise and customize the quality of experience when you use our Services;
  • Delivery of offers and promotional materials related to our Services and for other marketing purposes;
  • Tracking of user-specific information on accessed or visited pages;

2.4 Record and Administration

  • Internal record keeping;
  • Improve administration of our Services;
  • Operation and administrative purposes including account management, billing and collection, audits;
  • Compliant handlings;
  • Security and internal audit purposes;
  • Staff training purpose;

2.5 Legal Compliance

  • Conducting of customer due diligence;
  • Prevention, hindrance, reporting of any crime or possible criminal activities including but not limited to fraud, suspicious actions, bribery and money laundering;
  • Compliance to any legal or regulatory requirements relating to the provision of our Services;
  • Enforcement or defending our legal rights and/or obtaining legal advice;

2.6 Others

  • For such other purposes as may be directed or consented to by you; and
  • For all other purposes in relation to or incidental to the above.

3. Sources of Your Personal Data

We collect your data through information you provide and share with us, the technology and/or third party sources.

3.1 Data required by us

  • You are or may be required to provide us information in order to create the RedPay Account, to use our Services, to interact with the Merchants and to participate in our marketing and promotional activities.
  • Examples of where you provide your data to us include registration form when you create your RedPay Account, your response to our survey forms, your submitted content to our website, your interactions with the Merchants, products and/or services purchase order and your request and feedback to us.

3.2 Data gathered by technology

  • We may gather information via technology, through our platform, website and mobile applications.
  • Examples of technologies we use to gather and record information includes:
  • Cookies and URL information to record the date and time of your visit and the information for which you searched and viewed. You may remove persistent Cookies by following the website browser’s directions.
  • Information from corresponding technologies used in connection with mobile phones, including the Android ID, to record date, time, search and viewing information related to your mobile phone.
  • Third party analytics services such as Google Analytics (https://www.google.com/analytics) or Google AdSense (https://www.google.com/adsense). Such third party analytics services may use Cookies to gather information such as the pages you visited, your IP address and date and time of your visit.

3.3 Third party sources

  • We may collect data through third-party sources where you have given your consent to disclose and share your information.
  • Examples of third-party sources include social media platform, third party service providers, merchant affiliation and such other third-party websites or mobile apps.

4. Persons to whom Your Personal Data may be Disclosed

We commit to ensure your personal data with us will be kept confidential. Your personal data with us shall remain private and not disclosed or used by any third party, save for the following categories of third parties:

4.1 Related Companies

We may disclose and/or share your personal data with our associates, subsidiary and/or related companies for internal record, administration and operation purposes. Our related companies are required to comply with this Notice.

4.2 Third Party Service Providers

We may disclose and/or share your personal data with our sub-contractors or third-party service or product providers, who may be located within or outside Malaysia, who provide outsourcing services to us including accounting services, technology development and management, marketing activities.

4.3 Business Partners

We may disclose and/or your personal data with our payment gateway service providers, logistic partners, Merchants and such other parties who require to facilitate the provision and supply of our Services to you;

4.4 Consultants

We may disclose and/or share your personal data with our auditors, business consultants, accountants, lawyers or other professional advisers and/or consultants;

4.5 Competent Authorities

We may disclose and/or share your personal data any person to whom we are compelled to or required under law or in response to a local or state or federal authority, industry regulator, enforcement agency, statutory authority, court of laws, tribunal, arbitration centre, commission or council or association legally authorized by law.

4.6 Third Party on Direction

We may disclose and/or share your personal data with any persons directed by or consented to by you. This may include sharing of your activities on your social media sites.

We do not share your personal data with advertisers. However, if you interact with certain advertisements, the advertisers (or the company which the advertiser works with, for example, its advertising agency or an advertising network) may determine certain characteristics about you as such advertisements are directed at certain group of users. For examples users within certain age group, gender, interest and/or certain geographic location.

5. Retention and Security of Your Personal Data

5.1 Security and Confidentiality

We commit to safeguard your personal data in accordance with the provisions in this Notice, the PDPA and the relevant laws and regulations. Save as otherwise expressly provided herein, your personal data remains private and not viewed or used by those unauthorised to do so. Your personal data will be maintained in a secured manner and protected from unauthorised viewing or modification during transmission and storage.

We shall cause and procure necessary system updates and upgrades to ensure the accuracy, reliability and completeness of your personal data being processed, stored or transmitted within our system.

5.2 Retention Policy

Your personal data will be retained in accordance with the provisions in this Notice, the PDPA, the relevant laws and regulations, the duration of your relationship with us and/or such period as may be deemed necessary for fulfillment of the purposes as stated in this Notice. Your personal data will not be kept longer than it is necessary. We shall take all reasonable steps to destroy and/or delete your personal data if it is no longer required for the purposes as stated in this Notice. Notwithstanding the foregoing and to the extent permitted by law, we may retain your data for fraud prevention or similar purposes required by laws.

5.3 Third Party Websites

We have no control over and accept no responsibility for the content of any site to which a link from our website or mobile applications exists. Such linked sites are provided “as is” for your convenience only with no warranty, express or implied, for the information provided within them. We do not provide any endorsement or recommendation of any third party site to which our website or mobile applications provides a link. This Notice does not apply to these third party site.

6.Your Rights to Your Personal Data

6.1 Access and Request to Correction of Personal Data You may to request to access to your personal data that in our possession or control. You may also request to correct your personal data where the personal data is inaccurate, misleading or not-up-to-date. Any request of access may be subjected to a fee and we will reply to such request within 21 days from the date of receipt of such request. We reserve the right to request for further information and/or reject any request to access to personal data if:

  • you do not supply us with sufficient information to your identification;
  • such access will constitute a violation of an order of court;
  • such access will disclose confidential commercial information; or 
  • such access is regulated under other laws, regulations or rules.

6.2 Limit processing of personal data You may request to limit the processing of your personal data by expressly withdrawing your consent given, for examples consent to subscribe for newsletters, notification of latest promotions and such other marketing and promotional activities. But you may not withdraw and/or opt-out fully from of communications from us related to the terms and conditions of the Services, including any updates to our Terms of Use or Privacy Notice unless you deactivate the use of the Services.

7. Your Obligations in Providing Personal Data

In order to create the RedPay Account and to use the Services, you must provide your personal information to us and all the information provided shall be accurate, complete and at all time remains up-to-date. We take that all personal data you have provided as true and correct unless you inform us otherwise.

You may choose to limit and/or withdraw your consent for us to process your personal data. Nonetheless, such limitation and/or withdrawal may result that we are unable to response to your request, to provide you with the Service or to achieve the purposes as stipulated in this Notice.

8. How to Change Your Personal Data Processing Method

If you intend to change how your personal data being processed by us or to make inquiries pertaining to your personal data, our policies, procedures in relation to processing your personal data, you may contact the relevant department as follows:

Department:
Customer Service

Contact no.:
03-76603991

Email Address:
support@redpay.com.my

Postal Address:
D-28-01, Block Empire Soho 2, Empire Damansara, Petaling Jaya, 47820 Selangor Darul Ehsan

We may amend, modify or vary the provisions in this Notice, including the mode of processing, purposes of processing as well as our retention and security policy in relation to your data from time to time. A reasonable prior notice will be served to you. By continuing using, accessing and utilizing the Services after the effective date of such amendments, modifications or variations of this Notice, you shall be deemed to have consented to the same.

Data Protection Notice as of 2018.