PDPA Redi2Infaq

This Notice and Consent is issued to all our current or prospective customers and/or members pursuant to the requirements of the Personal Data Protection Act 2010 (“PDPA”) in Malaysia. We, REDIPAY and Redi2Infaq (referred hereinafter to as “RP”) wish to inform you that we maintain certain personal information about you as part of our records. We appreciate your support for our services and value our relationship with you. We would like to continue communicating for further information on our products, service, promotions and matters relating to the primary purposes above, which we may consider to be interesting to you time to time.

Please find the following notice in English and Bahasa Malaysia stating the reasons we will collect information, the type of information collected, our disclosure to third parties (if any) and who you may contact for access to your information. RP reserves the right to amend this Notice to client at any time and will place notice of such amendments on the company website (www.redipay.com.my) or via any other mode the company views suitable, which will be clearly informed to you.

1. Purpose of Information CollectedWe will collect information about you when you interact actively with us, be it directly or indirectly, for example when you contact us for further information, conducting payment transactions, or take part in any of our online activities. The use of this information is for the following primary purposes:
a. Enter into relevant sale and purchase agreement;

c. Payment transaction processing;
d. Settlement of fund, Refund or Cancellation, Dispute and/or Chargeback of the payment transaction;
e. Recurring payment service and/or tokenization;
f. General administration;
g. Manage and maintain your account(s) and facility(ies) with us;
h. Respond to your enquiries and complaints and to generally resolve disputes;
i. Update, consolidate and improve the accuracy of our records;
j. Produce data, reports and statistics which have been aggregated in a manner that does not identify you as an individual;
k. Conduct research and survey, which solely for analytical purposes including but not limited to data mining and analysis of your transactions with us;
l. Meet the disclosure requirements of any law binding on us;
m. For audit, compliance and risk management purposes;
n. Any other purpose that we deem necessary and/or as required or permitted by any law, regulations, guidelines and/or relevant regulatory authorities.

2. Type of Information CollectedPersonal data that we may collect:
a. Name, Age, Race, Gender, Nationality, IC Number, Passport Number, Date of Birth;
b. Contact Details such as House Number, Mobile Number; Email; Home Town Address; Correspondence Address; Delivery Address; Region or State of staying;
c. Credit Card details;
d. Bank Account number;
e. Any other information supplied by you that can indirectly or directly identify you, in order for us to carry out our contract with you.

3. Consequences of not providing Personal DataThe failure to supply us with the required personal data will potentially:
a. Result in us being unable to enter into a service contract or agreement with you;
b. Result in us being unable to communicate notices, value added services and updates to you;
c. Affect our capacity to accomplish the above stated purposes.

4. DisclosureYour personal data will be kept confidential but you consent and authorise us to provide or share your Personal data to the following class of users:
a. Persons/Organisations required under law or in response to government requests;
b. Related, subsidiaries, holdings of RP, including future entities under RP;
c. Government agencies, statutory authorities, enforcement agencies under law;
d. Auditors, accountants, lawyers under RP;
e. Banks, financial institutions, card associations;
f. Contractors, sub-contractors, affiliates, business partners of RP;
h. Persons under a duty of confidentiality to the RP;
i. Any other purpose that we deem necessary and/or as required or permitted by any law, regulations, guidelines and/or relevant regulatory authorities.Data shared will be for the purpose as stated in this notice, or purposes not stated but directly related to the primary purpose of collection.We may also share your Personal Data where required by law or where disclosure is necessary to comply with applicable laws, legal processes or queries from the relevant authorities.

5. Data SecurityWe shall take necessary steps to store and process your personal data securely. Reasonable security measures have been implemented to prevent the loss, misuse or unauthorised access of data. We limit access to your personal data on a need to know basis. Nevertheless, please understand that the transmission of information via the internet is not completely secure.Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted through any online means, therefore, any transmission remains at your own risk. We undertake the following security steps:
a. Implementation of a formal information security policy and necessary technology controls such as firewall, password controls, physical security, logging and monitoring etc;
b. Process controls such as segregation of duties, defined roles and responsibilities and need to know basis for staff;
c. Third party providers and contractors storing or processing personal data has implemented similar acceptable standards of security.

6. Retention of Personal DataYour personal data will be stored for only the period as necessary to fulfil the purposes stated above after which we proceed to ensure that your personal data is destroyed, anonymized or permanently deleted if it is no longer necessary to store. Reasons to further store your information even after the fulfilment of the purposes includes:
a. to satisfy legal, regulatory or accounting requirements;
b. to protect the interest of RP.

7. Direct Marketing

8. Rights of Access and CorrectionUnder PDPA, you reserve the right to access your personal data and request for correction of the personal data that might be inaccurate, obsolete, incomplete or misleading. In respect to this, you may:

a. Request to check and access your personal data in our records;
b. Request that we correct any of your inaccurate, obsolete, incomplete or misleading personal data;
c. Request copies of the data from us. Once we receive a request, we will acknowledge the receipt of such request. For data amendment and correction, we will consider if the information requires amendment. If there is any disagreement, then we specify the reason in clearly stated terms such as where rights of others will be violated, or regulatory functions will be affected.

In accordance with the PDPA, and to the extent not limited by any other applicable law, we may
a. Charge an administration fee for processing your request for access or correction to the Personal Data, in compliance to the fees stated in PDPA sub-regulation; and
b. Refuse to comply with your request for access or correction to the Personal Information and give you a written reason for such an action.

9. Transfer Of Your Personal Information Outside MalaysiaIt may be necessary for us to transfer your personal data outside Malaysia if any of our service providers or strategic partners who are involved in providing part of a services are located in countries outside Malaysia. You consent to us transferring your personal information outside Malaysia in the instances whereby it is necessary to fulfil the execution of the service/products that you signed up for. We shall take necessary steps to ensure that any such partners are contractually bound not to use your personal information for any reason other than to provide the Products and/or Services they are contracted by us, to safeguard your personal information.

10. Contact UsFor further information or clarification regarding personal data access, correction, deletion or any other information in relation to PDPA, you can contact us through the following details:
Email: [email protected]

11. LanguageAs per Section 7(3) of the PDPA, this notice and consent form is issued in both English and Bahasa Malaysia. In the event of any inconsistency, the terms of the English version shall prevail.

12. Acknowledgement of this formBy agreeing with to give your consent, you have fully read and understood the contents of this Notice to authorize us to collect, store and process your personal information in accordance with the terms above.

13. Declaration of ConsentBy clicking YES/SUBMIT, you provide us with your consent for us to process your personal information for, or directly related to, the purposes stated above.