Personal Data Protection Notice

  1. This Personal Data Notice (“Notice”) sets out how FFM Berhad and its subsidiaries and/or associated companies (collectively, “Company”, “we”, “us”, or “our”) process your personal data in respect of commercial transactions in accordance with the Personal Data Protection Act 2010 (“PDPA”) and other applicable laws of Malaysia. The terms “personal data”, “processing” and “commercial transactions” used in this Notice shall have the meaning prescribed in the PDPA.


  2. By providing your personal data to us, you are consenting to the collection, use and processing of your personal data as described in this Notice. We may also process your personal data if and to the extent permitted by law.


  3. We may modify this Notice at any time at our sole discretion, and such modification shall be effective immediately upon being published on our website (https://www.ffmb.com.my) and/or made available to you through other reasonable means, such as at our office or via direct communication. You agree to review this Notice periodically to be aware of such modifications, and you accept and consent to be bound by the modified Notice.


  4. If you are under the age of 18, you must ensure that your parent(s) or legal guardian(s) consent to the processing of your personal data by us as described in this Notice.


  5. Are you subject to this Notice?

    1. This Notice applies to you if:

      • you are a customer, supplier, service provider, prospective customer, prospective supplier or prospective service provider;
      • you have requested for credit facilities from us pursuant to a commercial agreement with us;
      • you use and/or enquire about our company, products and/or services;
      • you participate in promotional event, survey, promotion, competition, campaign, contest or loyalty program organised by us or on our behalf;
      • you visit or access premises/ facilities owned, operated or managed by us or on our behalf (“Our Premises”);
      • you use websites or mobile applications owned and/or managed by us or on our behalf;
      • you interact with us directly whether in person or via electronic communications such as through email, text and other electronic messages; or
        (individuals who fall within items (a) to (f) above are collectively referred to as “Users” and each, a “User”
      • you apply for employment with us (“Job Applicant”) or are a family member of a Job Applicant whose personal data is processed in the course of applying for employment with us.

  6. Description of Personal Data

    1. “Personal data” is defined in the PDPA and refers to any information that relates directly or indirectly to you, from which you may be identified.

      In respect of Users, the personal data collected and/or voluntarily provided by you during your course of dealings with us in any way or manner including pursuant to any commercial transactions and/or communications made from/with us such as at events organized or participated by the Company, in our forms, agreements, website, and/or other similar documents may include:

      • your personal details (such as name, age, date of birth, gender, a copy of Malaysian National Registration Identification Card (“NRIC”), NRIC number, a copy of passport, passport number);
      • contact details (such as home address, email address and phone numbers);
      • occupation details;
      • photographs and CCTV images and recordings; and
      • any other personal information provided by you regardless of whether such information is provided at the Company’s request.
    2. In respect of Job Applicants, in addition to the information in paragraph 6.1(a) to (e) above, the other personal data collected are:

      • Other personal details such as your nationality, gender, religion and race;
      • Family information such as your marital status, details of your family members and next-of-kin;
      • Employment-related information such as your employment history, job title or position, employment location, role description, date of employment, and employment references;
      • Sensitive personal data including your religious beliefs, details of physical or mental health or condition, political opinion and criminal conviction records; and
      • Any other personal information provided by you regardless of whether such information is provided at the Company’s request including information contained in your resume or curriculum vitae.

  7. Source of Personal Data

    1. Your personal data is collected from you as a User when you:

      • communicate with us (for example when you submit a request form with your personal data or when you contact us with any enquiries);
      • enter into agreements or other documents including those for the purpose of obtaining credit facilities;
      • use and/or enquire about our products and/or services;
      • participate in promotional event, survey, promotion, competition, campaign, contest or loyalty program;
      • respond to any marketing materials we send out;
      • visit Our Premises (including through recordings via CCTV);
      • browse our websites;
      • interact with us via emails and our social media platforms;
      • lodge complaints with us; and
      • provide feedback to us.
    2. Your personal data is collected from you as a Job Applicant when you:

      • use or interact with us on our websites;
      • submit information to us whether directly or indirectly (such as when you submit your information through recruitment agencies) or when you contact us for information; and
      • apply for employment.
    3. Other than the personal data we obtain from you as detailed above, we may also obtain your personal where otherwise lawfully permitted.

      data from third parties we deal with or are connected with you (for example, credit reference/ reporting agencies, government department or agencies, public registries), and from such other sources where you have given your consent for the disclosure of personal data relating to you, and/or where otherwise lawfully permitted.


  8. Purposes of Processing your Personal Data

    1. We will process your personal data, including any additional information you may subsequently provide, for the following purposes (hereinafter referred to as the “Purposes”), which include:

      • communicating and interacting with you including to deliver notice and/or information you require;
      • providing you with our product and/or service, or receiving your product and/or service, including:
        1. i. preparing and executing all necessary documents and agreements with you (including but not limited to sale and purchase agreements, service agreements, letters of appointment) and carrying out the obligations under the agreement;
        2. ii.providing credit facilities or performing review of credit limit and/or credit term;
        3. iii.conducting background check of yourself with the relevant credit reference/ reporting agencies; and
        4. iv.conducting and administering our business such as for sales administration or credit management purposes;
      • marketing, promoting and managing customer/contractor relationship;
      • granting access to Our Premises;
      • complying with legal or regulatory requirements, including:
        1. i.regulatory compliance, including adherence to industry regulations, such as those related to data protection, consumer protection, and anti-money laundering;
        2. ii.law enforcement cooperation, including assisting law enforcement agencies in investigations, as required by law; and
        3. iii.dispute resolution, including resolving disputes with customers and our partners.
      • those purposes incidental to the commercial transaction entered with the Company for the provision of any product and/or service offered by the Company;
      • liaising with insurance companies for any insurance claims;
      • to investigate, respond to, and/or defend claims made against, or involving the Company;
      • for security and audit purposes;
      • in relation to Job Applicants, specifically,:
        1. i.to evaluate your suitability for the position applied for at our Company, for the general record keeping purposes of the Human Resources Department;
        2. ii.for any background checks on job applicants, including but not limited to education verification, previous employment record checks, reference checks, bankruptcy history, credit verification, and/or criminal background screening; and
        3. iii.other purposes relating or incidental to employment with the Company, whether or not you are subsequently employed; and
      • Any other purposes relating or incidental to any of the above.

  9. Disclosure of Personal Data to Third Parties

    1. Your personal data as a User may be disclosed to third parties (within or outside Malaysia), where required, including but not limited to:

      • any entities within the Company;
      • the Company’s lawyers or auditors;
      • any person or party that acts as the agents, contractors, service providers, consultants and/or professional advisers of the Company;
      • regulatory bodies, government agencies, the police, law enforcement bodies and courts, both within and outside Malaysia;
      • credit reporting agencies and background check agencies;
      • other third parties for any of the Purposes;
      • such persons or bodies to whom the Company is legally required to disclose to; and/or
      • storage facility and records management service providers for our storage, hosting back-up (whether disaster recovery or otherwise) of your personal data, whether within and/or outside Malaysia.

  10. Transfer of your personal data to places outside Malaysia

    The Company may, where necessary, transfer your personal data to a place outside Malaysia if the classes of persons in paragraph 9 above are located or have processing facilities in countries outside of Malaysia. Your personal data may be transferred to any place outside Malaysia for any of the above Purposes. You consent to us transferring your personal data to a place outside Malaysia in these instances. We may also transfer your personal data to places outside Malaysia where permitted by law.


  11. Your right to access, correct and transmit your personal data

    You have the right to request access to personal data in our possession, or to correct such personal data.

    You may also request for your personal data to be transmitted to another entity subject to our technical capability, feasibility and compatibility with the receiving entity.

    You may make such request by contacting us in writing using the details set out below.

    The Company may decline to comply with your data access, data correction, or data portability request, but will notify you of the reasons for not being able to do so.


  12. Your right to exercise choices over your personal data

    You may choose to limit the use or the extent of use of your personal data and personal data relating to other persons who may be identified from that personal data.

    You may also withdraw your consent to the processing of your personal data. However, withdrawing your consent may affect our ability to provide you with certain products and/or services, or prevent us from communicating or continuing to communicate with you, or affect the evaluation of your employment application.

    You may exercise your rights as mentioned above by contacting us using the details set out below, and put your request in writing for security reasons and verification purposes.

    Notwithstanding the foregoing, we reserve our rights to rely on any contractual rights, statutory exemptions and exceptions to collect, use and disclose your personal data.


  13. Personal data of minors

    For your child to participate in our site visits, promotions, contests or other relevant activities, or where you provide your child’s personal data in connection with our products and/or services or your employment application, we may need to collect, use, disclose and process your child’s personal data as described in this Notice.

    We may also collect information as described in the Notice such as your contact details including your name, identification number, mobile number or email address, in order to verify your status as the parent or legal guardian and to request your consent as a parent or legal guardian.


  14. Your obligations

    You are responsible for providing accurate, complete and up-to-date personal data, including any thirdparty personal data you provide. This obligation is a condition for us to continue our communication with you, or for the evaluation of your employment application.

    It is obligatory to provide your personal data to enable us to process it for the Purposes. Should you decline to provide such personal data, it may, among others, prevent us from communicating or continuing to communicate with you, provide goods, services and credit facilities to you or affect the evaluation of your employment application.

    If you provide personal data on behalf of others (e.g. family members), you confirm and represent that you have informed them of this Notice and have their consent or legal authority to disclose their personal data to us for us to process in accordance with the terms of this Notice.


  15. Security of Personal Data

    The Company, when it deems necessary and appropriate, will take practical steps when processing your personal data to protect your personal data from any loss, misuse, modification, unauthorised or accidental access or disclosure, alteration or destruction, including but not limited to:

    • implementing appropriate security practices and policies such as encryption of personal data;
    • periodically reviewing and updating our security practices and policies; and/or
    • entering into appropriate contracts with third parties to ensure that security measures are in place.

  16. Retention of Personal Data

    The Company will keep your personal data for the duration that is necessary to carry out the purpose for which your personal data was collected and also for the other purposes set out in this Notice. The Company will take all reasonable steps to ensure that your personal data is destroyed or permanently deleted once it is no longer required for the purpose for which it was to be processed.


  17. Cookies

    Cookies are packets of information stored in your computer or device which assist your website navigation by customising site information tailored to your needs. The cookies will not collect personal data that could be used to identify a specific user. You may configure your browser to notify you of cookies and to prevent installation of cookies on your computer.


  18. Contact us

    You may submit your complaints, data access request, data correction request, data portability request, request to limit the processing of your personal data, request to withdraw your consent for the processing of your personal data, and any enquiries regarding your personal data by contacting:

    Data Protection Officer

    Name:Andrea Ng
    Phone number: 03 6145 7888
    Email address:[email protected]
    Postal address:FFM Berhad
    PT 45125, Batu 15 ½, Sungai Pelong
    47000 Sungai Buloh
    Selangor

    In accordance with the terms of the PDPA, the Company may charge a reasonable fee for the processing of any data access and data portability request. The chargeable fee will take into account the time needed for verifying, locating, retrieving, reviewing and copying the information requested as well as any other associated costs and expenses that may arise from conducting such retrieval. You will be notified of the anticipated fee chargeable, prior to the retrieval of your Personal Data.


  19. Inconsistency or Conflict

    In the event of any inconsistency or conflict between the English language version and the Bahasa Malaysia version of this Notice, the English language version shall prevail.


  20. Other Rights

    For avoidance of doubt, nothing in this Notice shall limit such other rights of yourself or the Company under the PDPA.