TISHA’S takes its responsibilities in relation to protecting your Personal Data and compliance with Applicable Laws very seriously. We are committed to properly managing, protecting and processing your Personal Data in accordance with this Policy, which shall apply to all Personal Data we collect from you through our Platforms.
Please read and review this Policy, which will inform you how we collect, use, process and disclose your Personal Data. We may also collect and process your Personal Data under any exceptions to Applicable Laws, which are not set out in this Policy. We trust that it will assist you in making an informed decision whether to provide us with any of your Personal Data.
For the purposes of understanding TISHA’S Personal Data Protection Policy (“Policy”), capitalised terms used in this Policy shall have the following meanings:
- Applicable Laws” means Malaysia’s Personal Data Protection Act 2010 and its subsidiary legislations and regulations as amended from time to time;
- Personal Data” means any data, whether true or not, which is (a) about an individual who can be identified (i) from that data; or (ii) from that data and other information to which we have or are likely to have access and would include data in our records as may be updated from time to time, or (b) defined as “personal data” or “personal information” under any applicable Data Protection Laws.
- Platforms” means collectively TISHA’S Social Media and Website, and any other websites or applications which we may own or operate from time to time;
- Social Media” means TISHA’S pages and accounts on third party social media platforms such as Instagram and Facebook;
- Website” means the TISHA’S website accessed at the following address at [email protected];
During our relationship with you, we may collect Personal Data from you. Examples of the types of Personal Data we may collect include your name, contact details, mailing and delivery addresses, email address, birthday, network and device data, your shopping or browsing behaviours, facial image, voice recording (for customer service calls) and any other personally identifiable information which you have provided us in any forms you may have submitted to us, or in the course of any other forms of interaction between you and us.
If you provide us with Personal Data relating to a third party by submitting such Personal Data to us, you represent to us that you have obtained the consent of the third party to provide us with their Personal Data for the respective purposes.
By (1) clicking “Yes” on our Policy pop-up or any web form referring to this Policy on any of our online platforms, (2) submitting your Personal Data to us when signing up for an account on the Website, (3) browsing our Website, or (4) ordering any of our products and services, you are agreeing to the terms of this Policy.
We may update this Policy to ensure that it is consistent with industry trends and/or any changes in legal or regulatory requirements. You agree to be bound by the prevailing terms of the Policy as updated from time to time. We will endeavour to notify you by email or by notice on the Website of any material changes to the Policy.
HOW DO WE COLLECT YOUR PERSONAL DATA?
We collect Personal Data from you when:
- You register an account on the Website;
- You browse our products and services or otherwise interact with our Website;
- You accept our cookies on your device;
- You interact with our customer experience team or other representatives, for example, via our webform, emails, telephone calls, letters, or face-to-face meetings;
- You interact with us on our Social Media, such as liking our posts, commenting on our posts, private messaging us on our Social Media;
- You participate in our promotions, lucky draws, initiatives or any request for additional Personal Data such as customer surveys;
- We receive references from business partners and third parties, for example, where they referred you to us to enjoy the benefits of a joint promotion or collaboration or to redeem a voucher you purchased through them;
- Your authorized representative submits your Personal Data to us for any purpose reasonably authorized by you, for example if such representative is purchasing our product or service to be delivered to you or as a gift;
- Our third-party analytics and other service providers provide your Personal Data to us, which was collected and processed by them and disclosed to us pursuant to their separate privacy policies; or
- When you voluntarily submit your Personal Data to us for any reason.
However, we may collect your bank account details to process refunds.
Please also take note of our Cookies Policy below in respect of the data collected and used by third-party cookies and trackers on our Website.
We may also collect your Personal Data in circumstances where such collection does not require consent under Applicable Laws.
Please ensure that all Personal Data submitted to us is complete, accurate, true and correct. Failure to do so may result in our inability to provide you with the products and services you have requested.
HOW WILL YOUR PERSONAL DATA BE USED?
We may use and disclose your Personal Data for purposes necessary to provide you with our products as services, including to:
- register and maintain your user account and to verify your identity or age;
- process your order for our products or services, process or collect your payment for the order;
- deliver or perform the products or services you purchased, including our couriers calling or messaging you to obtain your delivery instructions;
- process your returns or refunds in accordance with our Terms of Service;
- provide you with supporting services and functions related to your user account, such as saved items in cart, wish list, brand or product notifications;
- communicate with you in relation to (i) your queries, requests and feedback, (ii) material changes to our Website Terms of Service, Policy or other terms and conditions, and (iii) matters relating to the operation of your account;
- personalise and improve your customer experience when you visit the Website, for example by prioritizing products and services appearing in your search results or feed;
- monitor and enforce compliance with our Terms of Service, including dispute resolution;
- comply with (i) internal risk controls, (ii) the terms of our access to payment processing, financial or banking services such as credit card disputes, fraud, billing errors, or (iii) any applicable law; and
- ensure our Website function properly and to improve their performance, by carrying out activities such as debugging, statistical analyses for optimizing our Website.
(collectively, the “Purposes”)
In addition, we may use and disclose your Personal Data for the following purposes, to:
- send you marketing communications in relation to our sales, products, services, promotions or the Platforms;
- send you marketing communications in relation to the sales, products, services or promotions of business partners, including promotional mail together with your order;
- process your participation in our promotions, lucky draws, initiatives or any request for additional Personal Data such as customer surveys;
- process your participation in our business partners’ loyalty or point redemption programs;
- conduct market and customer research, analysis or tracking;
- promote our products and services on our Platforms;
- manage the administrative and business operations of TISHA’S and complying with internal policies and procedures;
- improve your customer experience across all touchpoints and training our customer experience team, such as by recording and monitoring phone calls; and
- any specific purpose in relation to a particular product or service, which we may separately notify you on the product or service page;
(collectively, the “Additional Purposes”)
We may also use your Personal Data (a) for other purposes which are reasonably related to the Purposes and where we have obtained and maintain related consent, the Additional Purposes; or (b) in circumstances where such use does not require consent under Applicable Laws.
Note: If you withdraw your consent for us to use and process your Personal Data the Purposes or the Additional Purposes, we may no longer be able to provide you with the related products, services or benefits associated with our promotion.
WHO WILL YOUR PERSONAL DATA BE SHARED WITH?
In relation to our use of your Personal Data for the Purposes or Additional Purposes, we may disclose your Personal Data to our:
- employees, consultants, temporary workers;
- payment processors, who process your payment on the Website;
- logistics providers, such as courier services which will deliver your order to you;
- business partners or vendors in connection with the processing of any promotion, event or service organised by us;
- professional advisers and consultants;
- agents, contractors or service providers who provide operational services to us, such as online cloud storage and processing, marketing optimization, information technology, telecommunications, security or other relevant services which requires their collection, use or disclosure of your Personal Data; and
- any other party whom you authorize us to disclose your Personal Data to.
We may also disclose your Personal Data (a) for other purposes which are reasonably related to the Purposes and where we have obtained and maintain related consent, the Additional Purposes; or (b) in circumstances where such disclosure does not require consent under the Applicable Laws.
We do our best to minimize the disclosure of your Personal Data to the information necessary to perform the related Purpose or Additional Purpose.
HOW CAN I ACCESS OR CORRECT MY PERSONAL DATA?
You may access or correct your name, e-mail address, birthday, shipping and billing addresses and contact numbers by logging in to your user account on the Website under “Account Information” and clicking the “Edit” button under each relevant field.
REQUEST TO WITHDRAW CONSENT
If you wish to withdraw your consent for us to send you sales, marketing or promotional information, please inform us as follows:
- to withdraw consent from receiving SMS promotions: please unsubscribe by following the steps provided in the promotional SMS;
- to withdraw consent from promotional emails: please click on the Unsubscribe link in the promotional emails;
- to withdraw consent from receiving promotional material with your order package: please email our Data Protection Officer at the email address provided below.
Once we receive notification that you wish to withdraw your consent for receiving marketing or promotional materials or communications, it may take up to thirty (30) days for your withdrawal to be reflected in our systems. Therefore, you may still receive marketing or promotional materials or communications during this period.
If you withdraw your consent to receive marketing or promotional materials through a specific communication mode (e.g. SMS), we may still contact you for other purposes in relation to the products and services via other communication modes you have subscribed to (e.g. email).
You may withdraw your consent for the collection, use and/or disclosure of any of your Personal Data in our possession or under our control. Note that, depending on the nature of the consent withdrawal, we may not be able to continue to provide you with some or all of our products or services. We will process such a request within a reasonable time from receiving notice from you of your withdrawal of consent. Once the processing is complete, we will no longer collect, use and/or disclose your Personal Data, except to the extent we retain your Personal Data for compliance, regulatory or other legal purposes.
ADMINISTRATION AND MANAGEMENT OF PERSONAL DATA
We will make reasonable efforts to ensure Personal Data likely to be used by us or disclosed by us to another organization is accurate and complete. However, you should update us of any changes in your Personal Data. We will not be responsible for relying on inaccurate or incomplete Personal Data if you have not updated us of changes.
We will also put in place reasonable security arrangements to ensure that your Personal Data is adequately protected and secured. This includes putting in place reasonable measures to prevent any unauthorized access, collection, use, disclosure, copying, modification, leakage, loss, damage or alteration of your Personal Data. However, we will not be responsible for any unauthorized use of Personal Data by third parties which is attributable to factors beyond our control.
When Personal Data in our possession is (i) no longer required for any reason connected to the purpose it was originally collected or (ii) retention by us is no longer necessary for any other legal or business purposes, we will exercise measures to ensure such Personal Data is destroyed, permanently deleted or anonymised.
If Personal Data is transferred out of Malaysia, we will comply with Applicable Laws in doing so. This includes: (i) obtaining your consent, unless an exception exists under Applicable Laws or any other laws, and (ii) taking reasonable steps to ascertain whether the foreign recipient of the Personal Data is bound to comply with standards of protection that are at least comparable to the Applicable Laws.
This Policy and your use of this Website shall be governed in all respects by the laws of Malaysia.
UPDATES ON DATA PROTECTION POLICY
As part of our efforts to ensure that we properly manage, protect and process your Personal Data, we will be reviewing our policies, procedures and processes from time to time. In this regard, TISHA’S may update this Policy to ensure that it is consistent with industry trends and any changes in legal or regulatory requirements.
We reserve the right to amend the terms of this Policy at our absolute discretion.
Subject to your rights at law, you agree to be bound by the prevailing terms of the Policy as updated from time to time on our Website. Any amended Policy will be posted on our website and can be viewed on our website. By continuing to use our Platforms and/or services after the Policy has been amended, you hereby agree to be bound by the terms of such amended Policy.
You are encouraged to visit the above Website from time to time to ensure that you are well-informed of our latest policies in relation to Personal Data protection.