Baca dokumen ini dalam Bahasa Melayu

Last Updated: 21/02/2022

We take your privacy seriously and are committed to providing a safe online experience. We believe in being transparent about our practices, which is why we have provided this Privacy & Cookies Policy (“Policy”) to explain how we collect, use and disclose your Personal Data (described below), and how you have control over your Personal Data.

All abbreviations or definitions used in our Terms of Service are adopted herein.

1. This Policy

This Policy describes how your information, including Personal Data, will be collected, processed, used and shared in connection with your use of our Site and/or Services, our legal basis for doing so as well as your rights and choices regarding the information you provide to us. This Policy is intended to meet the requirements of the Personal Data Protection Act 2010 and its statutory re-enactments, amendments, regulations, guidelines, and orders hereafter collectively referred to as the Personal Data Protection Act (“PDPA”).


We reserve the right to modify, amend and/or update this Policy from time to time. You should periodically visit this page to review the current terms of this Policy so that you are aware of any updated terms to which you are bound. If we do so, we will either notify you via e-mail or post the changes to this Policy on this page and update the “Last Updated” date at the top of this Policy as the effective date of change. However, any changes will not apply retrospectively.


By using, or continuing to use, our Site and/or Services after being notified of any modifications, amendments and/or updates to this Policy, you will be treated as having agreed that you have read and understood this Policy in its latest iteration, and you consent to our use of your information in accordance with this Policy in its latest iteration.


If you have any questions about this Policy or our practices, please contact our Data Protection Officer (“DPO”) at [email protected] (“DPO Contact”)

2. Your Rights

You have the following rights under this Policy to:

  1. Request access to your Personal Data. Subject to the exceptions provided under the PDPA, this enables you to receive a copy of the Personal Data we hold about you.
  2. Request correction of the Personal Data that we hold about you. This enables you to have any incomplete or inaccurate information we hold about you corrected. We have however the right to refuse your request to access and correct your Personal Data for reasons permitted under PDPA, in event the expense of providing access to you is disproportionate to the risk of your privacy being infringed, or where the rights of others may also be infringed, amongst other reasons.
  3. Request erasure of your Personal Data. This enables you to ask us to delete or remove Personal Data where there is no good reason for us continuing to process it.
  4. Withdraw consent. This enable you to withdraw your consent given to us to process your Personal Data. If you withdraw your consent, we may not be able to provide you with access to the certain specific functionalities of our Site and/or Services. Depending on the extent of your withdrawal, it may mean that we would not be able to continue with our contractual relationship with you and the contract that you have with us will be terminated. We will advise you if this is the case at the time you withdraw your consent.
  5. Limit Processing of Personal Data. You have the right to request us to limit the processing and use of your Personal Data, such as requesting us to limit or to stop sending you any marketing and promotional material or contacting you for such purposes.

3. How to exercise your rights

If you wish to exercise the rights under paragraph 2 above, please:

  1. address your request in writing to the DPO Contact;
  2. provide us with sufficient information, or we may request for further information, for us to verify your identity as our security measures to ensure that Personal Data is not disclosed to any person who has no right to receive it; and
  3. specify the right which you wish to exercise and identify the relevant Personal Data for this purpose.


We will endeavor to respond to all legitimate requests within thirty (30) days unless your request is particularly complex or you have made multiple requests. Typically, you will not have to pay a fee to access your Personal Data (or to exercise any of the other rights). However, if your request is clearly unfounded, repetitive or excessive, we may charge a reasonable administrative fee or refuse to comply with your request in these circumstances.

4. Types of Data that we collect

Personal Data that you provide directly to us. When you use our Site and/or Services, your Personal Data may be collected by us through your voluntary submission during your course of dealings with us in any medium such as but not limited to our customer service centre, emails, telephone calls, the data entry required for any transactions performed with us, the data entry required for the creation of your account on our Site, when you participate in events and surveys organised by or sponsored by us, and during your usage of third party platforms such as when you link your social media platform or external account with us, or when you follow us on social media.

Personal Data” means data that may enable us to identify you personally, including data about a person who can be identified (i) from that data, or (ii) from that data and other information to which we have or are likely to have access such as but not limited to your name, address, telephone number, Identification Number, date of birth, photograph, email address and household information.


Personal data from third party sources. We may also collect certain of your Personal Data from third party sources, for example, from credit reporting agencies, social media sites, our affiliates, analytics providers, advertisers, data brokers, and identity verification and compliance service providers in line with our legal obligations.


Non-Identifiable or Aggregated Data. When you interact with us through our Site, we may receive and store certain personally non-identifiable information. Such information, which is collected passively using various technologies, cannot presently be used to specifically identify you. We may store such information itself or such information may be included in databases owned and maintained by our affiliates, agents or service providers. We may use such information and pool it with other information to track, for example, the total number of visitors to the Site, the number of visitors to each page of the Site, the domain names of our visitors' Internet service providers, and how users use and interact with our Services. Also, in an ongoing effort to better understand and serve users of our Services, we often conduct research on our customer demographics, interests and behavior based on Personal Data and other information provided to us. This research may be compiled and analyzed on an aggregate basis. We may share such non-identifiable and aggregate data with our affiliates, agents and business partners, but this type of non-identifiable and aggregate information does not identify you personally. We may also disclose aggregated user statistics in order to describe our Services to current and prospective business partners, and to other third parties for other lawful purposes. However, if we combine or connect such non-identifiable or aggregated data with your Personal Data so that it can directly or indirectly identify you, we treat the combined data as Personal Data which will be used in accordance with this Privacy.

5. Consent and Withdrawal

By interacting with us using your Personal Data, or voluntarily submitting your Personal Data to us when using the Site and/or Services, you agree and consent to providing your Personal Data and the manner in which your Personal Data will be handled as set forth in this Policy.


You may, by notice in writing to us, withdraw your consent to providing your Personal Data to us. We shall endeavor to cease processing your Personal Data, destroy or delete the information, or remove the means by which the data can be associated with you within thirty (30) days from the receipt of the said notice, unless its retention is required to satisfy legal, regulatory, accounting or other business requirements or to protect our interests.


You may decline to provide us with your Personal Data. If you choose not to provide any Personal Data whenever required by us, this may limit your ability to use certain features of the Site and/or Services, or we might not be able to adequately deliver our Services to you.

6. How we use your Personal Data

Our primary objective in collecting and using your Personal Data is to provide, facilitate, personalise and/or improve our Site and/or Services. Below are the more detailed examples of relevant purposes for which we may use your Personal Data:

  1. Providing, updating, and maintaining the Site and/or Services, business and client database, including to facilitate and fulfil our transactions with you, including to process payment transactions;
  2. Conducting research and development, including to perform market, demographic or trend analysis/survey for research and marketing purposes, and for data aggregation and analytics;
  3. Communicating with users about our Services, including to interact with you via social media platforms, and to improve or personalise your online experience with us;
  4. Providing customer support, including to contact you regarding any complaints, feedback, queries or requests;
  5. Enhancing security, including to facilitate investigations into any suspicious prohibited fraudulent or illegal activity on the Site or relating to the use of our Services;
  6. Communicating with you for the purposes of marketing, promoting and driving engagement in respect of our Services and third-party products and services which may be of interest to you based on your interactions with us. Such communication may be in the form of postal mails, emails, text messages, social media channels, newsletters, brochures or other printed or digital communication;
  7. Complying with applicable law, legal process and regulations and protecting legitimate business interests;
  8. Internal administrative and management purposes;
  9. any purposes exempted under the applicable laws;
  10. To award points in a loyalty or rewards programme;
  11. To conduct credit reference checks and establishing your credit worthiness, if required, in providing you with the Products and Services; and
  12. Any other purposes reasonably related to the aforesaid for the purposes of improving and better manage our business and the User’s relationship with us


If we intend to use, handle or process any Personal Data in any manner that is not consistent with this Policy, you will be notified in accordance with paragraph 1.2 above.

7. Use of Cookies and Similar Technologies


In order to improve our Services, we may collect data by way of “cookies”. A cookie is a small text file containing small amounts of information which are automatically downloaded into your computer (or other electronic device) when you access to the Site. Cookies help us to measure the number of visits, average time spent, page views and other statistics relating to your access to the Site. This information allows us to better administer the Site, and provide a more tailored and user-friendly service to users. Cookies also enable you to use or access certain features or services of the Site. Each time you visit the Site from the same computer or device, the cookie will be retrieved from your computer or device, enabling the Site to recognise your computer or device as having previously visited the Site and thereby increase the functionality of the Site on your computer or device. Therefore, generally, we use cookies to:

  1. recognise your browser as a previous visitor and save any preferences that may have been set during your last visit to the Site;
  2. obtain information about your preferences, online movements and use of the Internet;
  3. track website analytics and carry out research and statistical analysis to help improve our content, products and services and to help us better understand our visitors’ or customers’ requirements and interests;
  4. customise and target our marketing and advertising campaigns and those of our partners more effectively by providing personalised interest-based advertisements;
  5. measure and research the effectiveness of our interactive online content, features, advertisements, and other communications;
  6. make your online experience more efficient and enjoyable.

The information we obtain from our use of cookies will not usually contain your Personal Data. Although we may obtain information about your computer or other electronic device such as your IP address, your browser and/or other internet log information, this will not usually identify you personally.

In most cases, we will obtain your consent in order to use cookies on the Site. The exception is where the cookies are strictly necessary in order for us to operate the Site and/or to provide you with a service you have requested. Most web browsers and devices can be set to notify you when you receive a cookie or to prevent cookies from being sent. If you use these features, you may limit the functionality we can provide you when you visit the Site. You are free to block, delete, or disable the cookies if your device permits so. You can manage your cookies and your cookie preferences in your browser or device settings. Further information about cookies, including how to see what cookies have been set on your computer or device and how to manage and delete them, visit and


Third-Party Cookies

Third-party cookies are set by third-party sites separate from the Site. We work with third-party service providers who are authorised to place third-party cookies and may also set cookies on the Site. These third-party service providers are responsible for the cookies they set on the Site. If you want further information, please visit the website of the relevant third party. If you would like to opt-out of all other types of technologies we employ on the Site, you may do so by changing your browser settings to block, delete or disable these technologies as your browser or device permits.


Log Files

Log file information is automatically reported by your browser each time you access a web page. When you use the Site, our servers automatically record certain information your web browser sends whenever you visit any website. These server logs may include information such as your web request, Internet Protocol address, browser type, referring / exit pages and URLs, number of clicks, domain names, landing pages, pages viewed, and other such information.


Clear GIFs Information (Web Beacons)

When you use the Site, we may employ clear GIFs (also known as web beacons or tracking pixels) to anonymously track online usage patterns. No personally identifiable information about you is collected using these clear GIFs. In addition, we may also use clear GIFs in HTML-based emails sent to our users to track which emails are opened by recipients. The information collected is used to enable more accurate reporting and make the Site better for users.

8. How we share your information

We are not in the business of selling transferring or disclosing your information to any third party without your consent. There are, however, certain circumstances in which we may share your Personal Data with certain third parties without further notice to you, such as with:

  1. Our Affiliates and Third-Party Partners. Certain authorised affiliates may access your Personal Data to help us develop, maintain and provide our Services and help manage our customer relationships (including providing customer support, customer liaison, delivery service, etc). We may also share your Personal Data with our business partners whom we collaborate in providing our Services, in which case these third parties are prohibited from using your Personal Data for purposes not relevant to their engagement or services.
  2. Our Service Providers. Our service providers provide us support for our Services, including, for example, website and application development, hosting, maintenance, security, backup, storage, virtual infrastructure, payment processing, analysis, identity verification, background and compliance reviews, banking services, delivery services and other services for us, which may require them to access or use Personal Data about you. These third parties are prohibited from using your Personal Data for purposes not relevant to their engagement or services.
  3. Our Professional Advisors. Our lawyers, accountants, bankers, auditors and insurers may need to review your Personal Data to provide consultancy, compliance, banking, legal, insurance, accounting and similar services. These third parties are prohibited from using your Personal Data for purposes not relevant to their engagement or services.
  4. Governmental Authorities or Agencies. We may disclose your Personal Data to governmental authorities or agencies if we believe it is reasonably necessary to comply with a law, regulation, order, subpoena, rule of a self-regulatory organization or audit or to protect the safety of any person, to address fraud, security or technical issues, or to protect our legal rights, interests and the interests of others, such as, for example, in connection with the acquisition, merger or sale of securities or a business (e.g. due diligence). We will not share your Personal Data with non-governmental entities, except where such entities have been duly authorised to carry out specific governmental activities.
  5. Our successors in title.
  6. Our Data Centres. Your Personal Data may be stored in data centres or servers located within or outside of Malaysia for data storage purposes or otherwise;
  7. Payment Channels. We may disclose your information to financial institutions, merchants, credit card organisations, payment gateway facilitators and organisations of similar nature and intent for purposes of verifying, assessing, and facilitating payment due to us strictly in connection with your commercial transaction with us;
  8. Nominated Third Parties. Any party under a duty of confidentiality to which has undertaken to keep your Personal Data confidential with whom we have engaged to discharge our obligations to you
  9. General Public. We may disclose your Personal Data to the public if you become a winner in a contest by limiting disclosure to your name, photographs and relevant Personal Data without compensation for advertising and publicity purposes


As we develop our business, we might sell or buy businesses or assets. In the event of a proposed, potential and/or actual corporate sale, merger, reorganization, dissolution, winding up, consolidation, funding exercise or events of similar eventnature and intent, your Personal Data may be part of the transferred assets as a result of or in connection with the above .


We may also share non-Personal Data without any specific reference that can identify you personally (such as anonymous usage data, referring/exit pages and URLs, platform types, number of clicks, etc.) with interested third parties to help them understand the usage patterns for certain Services or conduct independent research based on such anonymous usage data.


If you request that we remove your Personal Data in exercise of your rights, we will convey that request to any third-party with whom we have shared your data. We are not, however, responsible for revising or removing your Personal Data obtained by any third party who has previously been provided your information by us in accordance with this Policy or any third party to whom you have provided such information (whether by sharing your login and password, or otherwise).


Recipients of your Personal Data may be located outside Malaysia. You agree that we may transfer your Personal Data to our affiliates, subsidiaries and/or other authorised third parties located outside of Malaysia, as long as the Personal Data is handled in accordance with this Policy and relevant applicable laws.

9. Period of retention

Personal Data provided by you will be retained and stored as long as the purpose for which the data was required continues, unless you request that we remove your Personal Data in exercise of your rights. Thereafter, we will destroy or delete the information, or remove the means by which the data can be associated with you, unless its retention is required to satisfy legal, regulatory, accounting, tax or other business requirements or to protect our interests. We will however periodically review the data we hold, and erase or anonymise it when we no longer need it in accordance with our retention policy.

10. Accuracy of your Personal Data

It is a condition of us providing the Products and Services to you that the Personal Data that you submit to us are accurate, updated, complete and not misleading and that you have not withheld any Personal Data that may be material for our provision of our Products and Services to you and that you promptly update us as and when the Personal Data provided earlier to us becomes inaccurate, outdated, incomplete and misleading by contacting our DPO contact.

11. Information About Others

If you give us information on behalf of someone else, you warrant that you have explained to them that their Personal Data will be provided to, processed by, and stored by us and warrant that you have obtained the authorisation from that person to provide such Personal Data on his/her behalf and that other person has agreed that you can act on his or her behalf and (i) give consent on his or her behalf to the processing of his or her Personal Data in accordance with this Policy; (ii) receive on his or her behalf any data protection notices; and (iii) give consent to the use and transfer of his or her Personal Data abroad in accordance with this Policy. You agree to indemnify and hold harmless FortyTwo Home Sdn. Bhd. and our shareholders, directors, officers, employees, agents, contractors or affiliates from any claim that such authority did not exist.

12. Security

We use industry-standard physical, managerial, and technical safeguards to preserve the integrity and security of your Personal Data from loss, misuse, and unauthorised access or collection, disclosure, alteration, or destruction. All our employees, agents, contractors, vendors, suppliers, data processors, third party product or service providers who have access to your Personal Data are subject to a contractual duty of confidentiality. We cannot, however, ensure or warrant the security of any information you transmit to us or guarantee that your information through our Services may not be accessed, disclosed, altered, or destroyed by a breach of any of our physical, managerial, or technical safeguards.


While we will use all reasonable efforts to safeguard Personal Data, you acknowledge that the use of the Internet is not entirely secure and for this reason we cannot guarantee the security or integrity of any Personal Data that are transferred from you or to you via the Internet. Please be aware that communications over the Internet are not secure unless encrypted. Your communications may be routed through a number of countries before being delivered to us. We cannot therefore and do not accept responsibility or liability for any unauthorised interception, loss, or access of your Personal Data that is beyond our reasonable control.


Our data storage centre may be located at other jurisdictions outside of Malaysia, and this may result in your Personal Data being stored on servers located outside of Malaysia. In addition, your Personal Data may be disclosed or transferred to entities located outside Malaysia or where you access the Site from countries outside Malaysia. Please note that these foreign entities may be established in countries that might not offer a level of data protection that is equivalent to that offered in Malaysia under the laws of Malaysia. You hereby expressly consent to us transferring your Personal Data outside of Malaysia for such purposes. We shall endeavour to ensure that reasonable steps are taken to procure that all such third parties outside of Malaysia shall not use your Personal Data other than for that part of the Purposes and to adequately protect the confidentiality and privacy of your Personal Data.

13. Monitoring and Checking

We may monitor and record communications with you (such as telephone conversations and emails) for the purpose of quality assurance, training, fraud prevention and compliance.


For the prevention of fraud and money laundering, we may search the files of credit reference from fraud prevention agencies (who will record the search). If you provide false or inaccurate information and we suspect fraud, we may disclose information about how your interaction with the Site and/or Services to such agencies and if the situation warrants it, we may have to report to law enforcement authorities.


We may preserve the content of any email or "Contact Us" or other electronic message that we receive. Any Personal Data contained in those messages will only be used or disclosed in the manners set out in this Policy.

The message content may be monitored by our service providers or employees for purposes, including but not limited to, compliance, auditing and maintenance or where email abuse is suspected.

14. Exclusions

This Policy applies to all users of the Site and/or Services only. While you may encounter links on the Site to other websites, such as those relating to our third party partners, advertisers and other parties whom we collaborate with (“Third Party Platforms”), this Policy does not apply to the activities of such Third Party Platforms that may collect your Personal Data when you access or use such third party’s services. The privacy practices of those third parties are not covered by this Policy. The links from the Site do not imply that we endorse or have reviewed the policies of such Third Party Platforms. We suggest you to contact those platforms directly for information on their terms and conditions or policies.


This Policy shall not apply to any unsolicited information you provide to us through the Site or any other means. This includes, but not limited to, information posted to any public areas of the Site, such as message boards, any ideas or feedback, and other unsolicited submissions (collectively, “Unsolicited Information”). All Unsolicited Information shall be deemed to be non-confidential and we shall be free to reproduce, use, disclose, distribute and exploit such Unsolicited Information without limitation or attribution.

15. Governing Law and Dispute Resolution

Irrespective of the country from which you access or use the Site and/or Services, to the extent permitted by law, this Policy shall be governed in accordance with the laws of Malaysia without regard to choice or conflicts of law principles, and you hereby agree to submit to the exclusive jurisdiction of the courts of Malaysia to resolve any claims or disputes which may arise in connection with this Policy.

16. Conflict

In the event of any conflict between this English language Privacy & Cookies Policy and its corresponding Bahasa Malaysia Privacy & Cookies Policy, the terms in this English language Privacy & Cookies Policy shall prevail.