Privacy Policy
This Privacy Policy sets out how FLAVORLAB GLOBAL SDN BHD, (collectively referred to as “Yum Yeah”, “we”, “us” or “our”) process personal data. This Privacy Policy outlines our practices in relation to the collection, use and protection of the personal data you provide through our websites, apps, forms, devices, products or brand pages on social media or otherwise (collectively referred as “Platform”), or when you interact with us at our premises including our offices and retail outlets. This Privacy Policy also explains your rights and the choices available to you regarding the use of, your access to, and how to update and correct your personal data.
By providing your personal data to us and/or continuing access to the Platform and accepting the Terms of Use, you consent to the collection, transfer, processing, storage, disclosure and other uses described in this Privacy Policy
Collection of Personal Data
In the course of your dealings with us, we may request that you provide information about yourself or any other person for the purposes stated in this Privacy Policy. We collect only personally identifiable information (“Personal Data”) that is specifically and voluntarily provided by you.
In your interaction with us or by continuing to access or use the Platform, we may collect Personal Data including, but not limited to, your name, phone number, email address, mailing address, social media profile, images (including photographs) information in audio and/or video format, closed-circuit television (CCTV) and security recording, personal preferences and shopping habits, purchase history, transaction information, payment information, user generated content, location, device information, Internet Protocol (IP) address, website or app usage information, information collected through the use of cookies and other information permitted by applicable laws.
In cases where we collect or use your geolocation data or any other personal data in the course of providing any additional products and/or services, we are not required to provide you with any notices or obtain your prior consent unless applicable laws provide otherwise. If you provide us Personal Data about other individuals, you represent and warrant that they have appointed you to act on their behalf and have agreed that you can:
Give consent on their behalf to the processing of their Personal Data;
Receive on their behalf any data protection notices; and
Warrant that you have obtained their consent for us to store their Personal Data, or have the right to allow us to process their Personal Data.
In the event that you are a minor (i.e. individuals under the age of 18) and intend to provide your Personal Data to us, you hereby confirm and acknowledge that you have obtained your parent or legal guardian’s agreement to be bound by this Privacy Policy.
Cookies and Other Tracking Technologies
Cookies (small text files placed on your device) and similar technologies may be used on some pages of the Platform to enable us to streamline your experience of using the Platform, to enable effective provision of the Platform, and to help collect usage and performance data. Cookies allow us to help us recognise when you return, store your personal preferences and settings, enable you to sign in, combat fraud, and analyse how the Platform is performing.
We may also use small pieces of code called “web beacons” or “clear gifs” to collect anonymous and aggregate advertising metrics such as counting page views, promotion views, or advertising responses. A web beacon is an electronic image called a single-pixel or clear gif. Web beacons can recognise certain types of information, such as a user’s cookie number, time and date of a page view, and description of the page where the web beacon is placed. These web beacons may be used to deliver cookies that conform to our cookies policy. Such cookies, web beacons and clear gifs may come from third parties.
We may further use cookies for the following purposes:
Security enhancement of our systems;
Storage of your personal preferences and providing customised services to you; and
Helping us understand how people use these services and improving them.
If you access our websites or apps with your login credentials through a social media login, or if you otherwise agree to associate your account on our websites and/or apps (“Account”) with such account, we may receive Personal Data about you from the operator of such account in accordance with their terms of use and privacy notice. This is to enable us to establish your Account and tailor our products and/or services to you. We may add this to the data we have already collected from you via other aspects of our websites and/or apps.
You may choose to accept or refuse the use of cookies including cookies associated with the Platform, or to indicate when a cookie is being set by us. You may refuse the use of cookies by selecting the appropriate setting on your browser. However, if you select this setting you may be unable to use the full functionality of the Platform. After termination of the visit to the Platform, you can always delete the cookie from your system if you wish.
Cookies and other tracking technologies may also be used to support analytics by other third parties.
By continuing accessing or using the Platform, you consent to our use of cookies and other similar technologies in accordance with this Privacy Policy.
Source of Personal Data
The Personal Data collected, used and processed by us are sourced from wholly legitimate and transparent means, including, but not limited to:
Your access or use of the Platform;
When you complete purchase orders, requests or applications for our products and/or services;
Any emails or correspondence that we receive from you;
During conversations between you and our representatives;
When completing any applications or forms for transactional or other purposes;
When you participate in any event, prize draws, or competitions run by us or indirectly through a third party;
When completing any surveys that we send to you for research purpose;
Loyalty or rewards programme;
Referral programme;
Video or recordings of events and/or activities at our premises including our offices and retail outlets;
Authorised third parties, including, but not limited to, credit reporting agencies, regulatory and enforcement agencies and other government entities;
Our contractors, business partners and related entities;
Marketing services providers or partners; and
Mailing lists
Purpose of Collection of Personal Data
We may collect, use and process your Personal Data which shall include, but not limited to the following purposes:
To administer your Account;
To provide you with our products and services;
To process any orders that you make with us;
To process payments and prevent fraudulent transactions;
To inform and update you on the delivery of the products and/or services;
To offer you a loyalty or rewards programme;
To offer you a referral programme;
To award points in a loyalty or rewards or referral programme;
To enable us to provide, facilitate, perform, personalise and improve the Platform to meet your current and future needs;
To help us understand and develop a customised user experience based on your preferences, behaviour and activities;
To contact and communicate with you;
To respond to your enquiries or complaints, and to provide customer support;
To resolve disputes or to investigate any complaints you made or made against you;
To prevent, detect or investigate any potential breaches, illegal activities or prohibited content on the Platform;
To monitor and analyse your use of the Platform;
To research, evaluate and develop the Platform;
To promote or communicate information, updates and news about the Platform or new products and services of ours, our subsidiary companies and other third parties, and such communications may be initiated from us or through third parties;
To deliver online behavioural advertising (i.e., to show you online advertisements for products and/or services which may be of interest to you based on your previous behaviour, and to show you advertisements and content on social media platforms);
To be used in, to provide and/or to improve the Platform, competitions, promotions, and/or market surveys you choose to participate, processing invoices and payment, and client profiling activities regarding the Platform;
For internal functions such as evaluating the effectiveness of marketing, market research, statistical analysis and modelling, reporting, and audit and risk management;
To develop, show, measure and track advertising (including, but not limited to, content, survey and promotions of the Platform or new products and services of ours, our subsidiary companies and other third parties), and to collect information about you and on how you interact with it while you use the Platform;
To maintain our operations or client relationship management systems;
To maintain and upkeep customer or company records and development in the ordinary course of business;
For our internal record keeping;
For prevention and detection of crime;
To conduct client due diligence, to verify your identity, to monitor, detect and deter unauthorised or fraudulent use or abuse of the Platform;
For the preparation and execution of all necessary documents, agreements and/or contracts for the Platform;
For general operation and maintenance of the Platform;
Those purposes specifically provided for in any particular product and/or service offered by us;
To enforce and exercise rights stated in this Privacy Policy or the Terms of Use; and
To meet any legal or regulatory requirements relating to all the commercial transactions, our conduct of the business or activities or our provision of products and/or services, and to make disclosure under the requirements of any law, regulations, directives, court orders, by law, guidelines, circulars or codes applicable to us or any member of our group of companies from time to time.
Consequences of Refusal or Failure to Provide Personal Data
Unless stated otherwise, the Personal Data provided to us are wholly voluntary in nature and you are not under any obligation or duress to do so. However, in some circumstances if you do not provide us with your Personal Data described in this Privacy Policy, we shall not be held liable for any of the consequences arising therefrom:
The inability for us to provide you with the products and/or services you requested, either to the same standard, or at all;
The inability for us to provide you with the information about the products and/or services that you may want, including information about discounts or special promotions, or our new products and/or services;
The inability for us to tailor the content of the Platform to your preferences and your experience of using the Platform may not be as enjoyable or useful;
The inability to complete commercial transactions in relation to the Platform; and
The inability to comply with any applicable law, regulation, direction, court order, by law, guideline and/or code applicable to us.
Disclosure of Personal Data
In order for us to fulfil the purposes listed above, the Personal Data may be disclosed to the following, but not limited to, classes of parties:
Our employees, partnerships, joint venture entities, contractors or third party service providers, third party management companies, subcontractors or other parties as may be deemed necessary by us to facilitate your dealings with us;
Our vendors, consultants, marketing partners, research firms and other service providers or business partners, including, but not limited to:
Payment processors and facilitators;
Background check and anti-money laundering service providers;
Cloud storage providers;
Marketing partners and marketing platform providers;
Data analytics providers;
Research partners;
Fleet and merchant partners; and
Insurance and financing partners;
Our holding, subsidiary or related companies, including those incorporated in the future and/or any member of our group of companies;
Our auditors, consultants, lawyers, accountants or other financial or professional advisors appointed in connection with our business;
Any person, government authority, statutory authority, industry regulator or other relevant third party whom we are compelled or required to do so pursuant to any law, or if we have good faith belief that such disclosure is necessary to protect and/or defend our rights and interests or in connection with an investigation of fraud, infringement, piracy, tax avoidance and evasion or other unlawful activity; and
Any person who is under a duty of confidentiality to which he/she has undertaken to keep such information confidential which we have engaged to fulfil our obligations to you.
Third parties are legally tasked with processing the Personal Data in line with the principles specified by us. Third parties are also held legally responsible for securing the Personal Data at an appropriate level of security in relation to applicable data protection laws and widely accepted industry standards.
The Personal Data may also be disclosed to third parties with the consent of the record subject.
If we or our business is acquired by or merged with another entity, or there is a proposed acquisition or merger, the Personal Data may be transferred to such entity as part of the proposed or actual merger or acquisition.
Protection of Personal Data
We ensure that all appropriate confidentiality obligations and technical and organisational security measures are in place to protect the confidentiality and security of your Personal Data collected through the various methods described in this Privacy Policy to prevent any unauthorised access, unauthorised or unlawful alteration, disclosure or processing of such information and data, and the accidental loss or destruction of or damage to such information and data. These efforts, include, but are not limited to:
Storing your Personal Data in systems that are protected by secured networks and operating environments that are not available to the public and are only accessible by our employees for the purpose of performing their official duties and authorised third parties who are contractually bound to take reasonable measures to keep your Personal Data secure;
Regularly monitoring our systems for possible vulnerabilities and attacks, and regularly review our information collection, storage and processing practices to update our physical, technical and organisational security measures; and
Verifying the identities of users before they can access the Personal Data we maintain about them.
Compliance with these provisions will be required by all authorised third parties who may access the Personal Data as described above.
Compliance with these provisions will be required by all authorised third parties who may access the Personal Data as described above.
Choices to Limit Processing of Personal Data
You have the right to limit in part or wholly any of the processes by which your Personal Data is subjected to, in terms of the operations allowed to be performed upon it, the period of time allowed, or alternatively, the deadline of the consent given.
The responsibility for compliance rests with us, who determines the purposes and means of processing your Personal Data.
You shall notify us in writing to request your Personal Data to be retained by us so long as it is necessary for the fulfilment of the purposes for which it was collected only, or inform us your objection to the use of your Personal Data for marketing purposes whereupon we will not use your Personal Data for such purpose. You may withdraw, in full or in part, your consent given to us. Your withdrawal in each case is subject to any applicable legal restrictions, contractual conditions, and a reasonable time period. Your withdrawal may also be subject to whether it would affect the operation of our business.
Your Rights
In respect of the Personal Data which you have submitted to us, you have the right at any time to:
Request for access to your Personal Data in our records;
Request to make correction of your Personal Data in our records in the event the information is inaccurate, misleading, out-of-date or incomplete upon validation and verification of the new information provided;
Request to cease processing your Personal Data for the purposes of marketing;
Object to the processing of your Personal Data, request to restrict or limit processing of your Personal Data, or request portability of your Personal Data;
Withdraw your consent for us to continue processing your Personal Data; and
Complain to a data protection authority about our collection and use of your Personal Data.
In respect of requests for access to or to make correction of your Personal Data in our records, or to cease processing your Personal Data for the purposes of marketing, such requests must be made in writing and supported with submission of the relevant documents as required by us in person from time to time to the address set out in the Contact Us section below. We will only make appropriate corrections based on the updated information provided by you. When requested and if it is practical, we will delete identifying information from our current operation systems. Your request may also be subject to payment of a fee in accordance with applicable legal requirements.
You may request for deletion of your Personal Data by us and we will use commercially reasonable efforts to honour your request. However, kindly note that we may be required to keep such information and not delete it (or to keep this information for a certain period time, in which case, we will comply with your deletion request only after we have fulfilled such requirements). When we delete any information, it will be deleted from the active database but may remain in our archives. We may also retain your information for fraud prevention and detection or similar purposes.
Retention of Personal Data
The Personal Data you submit to us will only be retained for as long as is required for the purpose for which it was collected or as permitted by applicable laws.
Even though our systems are designed to carry out data deletion processes according to the above guidelines, we cannot promise that all data will be deleted within a specific timeframe due to technical constraints. When we no longer need to use your Personal Data, it is removed from our systems and records or anonymised so that you can no longer be identified from it.
International Transfers of Personal Data
To provide our products and services, we may process and store your information on servers located in Malaysia or other jurisdictions where we deem it appropriate or desirable unless applicable laws provide otherwise. There may be a possibility that the data protection levels in other jurisdictions do not completely meet the requirements of the data protection laws in Malaysia, but all such transfers are performed in accordance with the requirements of applicable laws.
Links to Other Websites or Apps
The Platform may contain links to and from the websites or apps of our partner networks, advertisers and other third parties. If you click on a link to any of these websites or apps, you will leave the Platform and be redirected to the website or app you selected. As we cannot control the activities of third parties, we cannot accept responsibility for any use of your personally identifiable information by such third parties, and we cannot guarantee that they will adhere to the same privacy practices as us. We encourage you to review the privacy policy of these websites or apps before providing any personally identifiable information.
We may also offer you the opportunity to use your social media login. If you do so, please be aware that you share your profile information with us depending on your social media platform settings. We encourage you to visit the relevant social media platform and review its privacy policy to understand how your Personal Data is shared and used in this context.
Social Media and User Generated Content
Some of our websites and apps allow users to submit their own content. Please remember that any content submitted to one of our social media platforms can be viewed by the public, so you should be cautious about providing certain Personal Data, e.g. financial information or address details. We are not responsible for any actions taken by other individuals if you post Personal Data on our social media platforms and we recommend that you do not share such information.
Marketing and Promotions
We may use your Personal Data to market products, services, events or promotions of ours, our partners, sponsors and advertisers. We may communicate such marketing to you by post, telephone call, email, short messaging service (SMS), social media and/or any other appropriate communication channels. If you wish to unsubscribe to the
processing of your Personal Data for marketing and promotions, you may click on the “Unsubscribe” link in the relevant email or message you receive from us. Alternatively, you may also update your preferences in our websites and apps settings or contact us directly at the email address set out in the Contact Us section below. Please be aware that once we have received your request to unsubscribe, it may take up to fourteen (14) working days for us to process your request and to be reflected in our systems. Therefore, you may still receive marketing communications during this period of time.
Amendments to Privacy Policy
We shall have the right to modify, update and/or amend this Privacy Policy at any time. We will take reasonable steps to ensure amendments to this Privacy Policy are communicated by posting all amendments prominently on the Platform and other places we deem appropriate for a reasonable period of time. Amendments to this Privacy Policy will be effective immediately once published on any of the Platform unless otherwise noted. Your continued access or usage of the Platform following any amendments indicates your consent to the practices described in the revised Privacy Policy. If you do not agree, you should immediately discontinue your use of the Platform. We invite you to periodically review this Privacy Policy to be informed of any relevant amendments, especially before providing any information to us.
Contact Us
If you have any questions or concerns about this Privacy Policy, or if you would like to exercise your rights to your Personal Data, please contact us at: [email protected]