Biomedia Data Privacy Policy
The Personal Data We Collect From You
- Identity data, such as your name, gender, and date of birth;
- Contact data, such as billing address, delivery address, email address, and phone numbers;
- Transaction data, such as details of products and services you have purchased from us;
- Technical data, such as internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access the platform;
- Profile data, such as your username and password, purchases or orders made by you, your interests, preferences, feedback and survey responses;
- Usage data, such as information on how you use the platform, products and services; and
- Marketing and communications data, such as your preferences in receiving marketing from us and our third parties and your communication preferences.
Personal Data means any information, whether recorded in a material form or not, from which the identity of an individual is apparent or can be reasonably and directly ascertained by the entity holding the information, or when put together with other information would directly and certainly identify an individual.
We may collect the following personal data from you:- When you create an account with us;
- When you apply for any of our services or purchase any products available on the platform;
- When you use any of the features or functions available on our platform or services;
- When you subscribe to our publications or marketing collaterals;
- When you enter a competition, promotion or survey;
- When you log in to your account on our platform or otherwise interact with us via an external service or application, such as Facebook or Google; and
- When you interact with us offline, including when you interact with our customer service agents.
During the course of your use of the platform and the provision of the services, we may receive personal data from you in the following situations:
You must only submit personal data which is accurate and not misleading and you must keep it up to date and inform us of changes. We shall have the right to request for documentation to verify the personal data provided by you as part of our customer verification processes.
We will only be able to collect your personal data if you voluntarily submit the personal data to us. Unfortunately, if you choose not to submit your personal data to us or subsequently withdraw your consent to our use of your personal data, we may not be able to provide you with our services or access to the platform.
You may access and update your personal information submitted to us at any time as described below. If you provide personal data of any third party to us, you represent and warrant that you have obtained the necessary consent from that third party to share and transfer his/her personal data to us, and for us to collect, use and disclose that data in accordance with this Privacy Policy.
Use and Disclosure of Personal Data
- To facilitate your use of the services or access to the platform, including responding to your queries, feedback, claims or disputes through our customer service agents;
- To process orders you submit through the platform, whether the products are sold by us or a third party seller;
- Payments that you make through the platform for products, whether sold by us or a third party seller, will be processed by our agent;
- To deliver the products you have purchased through the platform, whether sold by us or a third party seller. We may pass your personal information on to a third party in order to make delivery of the product to you (for example to our courier or supplier), whether the product is sold through the platform by us or a third party seller;
- To update you on the delivery of the products, whether sold through the platform by us or a third party seller, and for customer support purposes;
- To compare information, and verify with third parties in order to ensure that the information is accurate;
- To administer your account (if any) with us;
- To verify and carry out financial transactions in relation to payments you make online;
- To audit the downloading of data from the platform;
- To improve the layout or content of the pages of the platform and customise them for users;
- To identify visitors on the platform;
- To carry out research on our users’ demographics and behaviour;
- To provide you with information we think you may find useful or which you have requested from us, including information about our or third party sellers’ products and services, provided you have indicated that you have not objected to being contacted for these purposes;
- Subject to having obtained your consent in accordance with applicable law, we may also use your personal information to send you marketing or promotional materials about our or third party sellers’ products and services from time to time; and
- We may also conduct automated-decision making processes in accordance with any of these purposes.
The personal data we collect from you may be used by us, or shared with or transferred to third parties (including related companies, third party service providers and their service providers and related companies, and third party sellers), for some or all of the following purposes:
You may unsubscribe from receiving marketing information at any time by using the unsubscribe function within the electronic marketing material. We may use your contact information to send newsletters from us and from our related companies.
In exceptional circumstances, we may be required to disclose personal information, such as when there are grounds to believe that the disclosure is necessary to prevent a threat to life or health, or for law enforcement purposes, or for fulfilment of legal and regulatory requirements and requests.
We may share and permit the sharing of your personal data with third parties and our affiliates for any of the abovementioned purposes, including but not limited to, facilitating your use of the Services, completing a transaction with you, managing your account and our relationship with you, marketing and fulfilling any legal or regulatory requirements and requests as deemed necessary by us. In sharing your personal data with them, we endeavour to ensure that the third parties and our affiliates keep your personal data secure from unauthorised access, collection, use, disclosure, or similar risks and retain your personal data only for as long as they need your personal data to achieve the abovementioned purposes.
If you are located in Malaysia, we may transfer or permit the transfer of your personal data outside of Malaysia for any of the purposes set out in this Privacy Policy. In disclosing or transferring, or permitting the transfer of, your personal data to third parties or our affiliates located overseas, we take steps to ensure that the receiving party has in place a standard of protection accorded to personal data that is comparable to the protection under or up to the standard of the data protection laws as are applicable to us.
Withdrawal of Consent and Deletion or Anonymisation of Personal Data
You may communicate the withdrawal of your consent to the continued use or disclosure of your personal data for any of the purposes and in the manner as stated above at any time, or request the deletion or anonymisation of your personal data, by contacting our Data Protection Officer Mr Martin Suryadi at martin.suryadi@biomediaholdings.com.
Please note that if you communicate your withdrawal of your consent to our use or disclosure of your personal data for the purposes and in the manner as stated above, or request the deletion or anonymisation of your personal data, we may not be in a position to continue to provide our products or services to you or perform on any contract we have with you, and we will not be liable in the event that we do not continue to provide our products or services to, or perform our contract with you. Our legal rights and remedies are expressly reserved in such an event.
Updating Your Personal Data
It is important that the personal data you provide to us is accurate. You are responsible for informing us of changes to your personal data, or in the event you believe that the personal data we have about you is inaccurate, incomplete, misleading or out of date. You can update your personal data anytime by accessing your account on the platform. If you are unable to update your personal data through your account, you can do so by contacting our Data Protection Officer using the contact details provided above.
We take steps to share the updates to your personal data with third parties and our affiliates with whom we have shared your personal data if your personal data is still necessary for the above-stated purposes.
Accessing Your Personal Data
If you would like request information about your personal data which we have collected, or inquire about the ways in which your personal data may have been used or disclosed by us within the past year, please contact our Data Protection Officer using the contact details provided above. In order to facilitate processing of your request, it may be necessary for us to request further information relating to your request.
We reserve the right to charge a reasonable administrative fee for retrieving your personal data records. If so, we will inform you of the fee before processing your request.
We will respond to your request as soon as reasonably possible. Should we not be able to respond to your request within twenty-one (21) days from the date of your request, we will inform you in writing. If we are unable to provide you with any personal data or to make a correction requested by you, we shall generally inform you of the reasons why we are unable to do so (except where we are not required to do so under the applicable data protection laws).
Security of Your Personal Data
- Restricting access to personal data to individuals who require access;
- Maintaining technology products to prevent unauthorised computer access;
- Deleting or anonymising your personal data in compliance with the standards mandated by applicable law, when it is no longer needed for any legal or business purpose; and
- Using 128-bit SSL (secure sockets layer) encryption technology when processing your financial details.
To safeguard your personal data from unauthorised access, collection, use, disclosure, copying, modification, disposal or similar risks, we have introduced appropriate administrative, physical and technical measures such as:
If you believe that your privacy has been breached by the platform, please contact our Data Protection Officer using the contact details provided above.
You should be aware, however, that no method of transmission over the internet or method of electronic storage is completely secure. While security cannot be guaranteed, we strive to protect the security of your information and are constantly reviewing and enhancing our information security measures.
Your password is the key to your account. Please use unique numbers, letters and special characters, and do not share your platform password to anyone. If you do share your password with others, you will be responsible for all actions taken in the name of your account and the consequences. If you lose control of your password, you may lose substantial control over your personal data and other data submitted to the platform. You could also be subject to legally binding actions taken on your behalf. Therefore, if your password has been compromised for any reason or if you have grounds to believe that your password has been compromised, you should immediately contact us and change your password. You are reminded to log out of your account and close the browser when you are finished with using a shared computer.
Retention of Personal Data
We will only retain your personal data for as long as we are either required to by law or as is relevant for the purposes for which it was collected.
We will cease to retain your personal data, or remove the means by which the data can be associated with you, as soon as it is reasonable to assume that such retention no longer serves the purposes for which the personal data was collected, and is no longer necessary for any legal or business purpose.