1. Consent and Agreement: Explicitly clarifies that using your site, buying cleaning products, or requesting professional consultations implies legal consent.
2. Deep Data Scope: Categorizes data collection into Identity, Contact, Transaction (including RM currency balances), and Technical/Usage Data for thorough legal compliance.
3. Collection Methodologies: Differentiates direct customer inputs, automated tracking mechanisms (cookies for shopping carts), and verified third-party logs (e.g., banks and logistics).
4. Granular Processing Intent: Details the legal grounds for handling data to manage bundle orders, deliver fast ready-stock items, and offer custom industrial hygiene advice.
5. Strict Disclosure Safeguards: Outlines protocols for sharing details only with trusted delivery services and auditing bodies while explicitly banning the sale of customer data.
6. Expanded PDPA User Rights: Clear sub-sections mapping out the user’s right to access, correct, restrict processing, or withdraw data processing consent entirely.
7. Data Breach Protocol & Policy Amends: Adds a proactive policy for handling unexpected data breaches (including notifying individuals and regulators) and sets guidelines for how amendments to the policy will be updated online.
8. Structured DPO Contact Information: Organizes a clear, professional placeholder block specifically for your Data Protection Officer (DPO) to receive legal and customer inquiries.