Privacy Policy

Click here to view our Privacy Policy in Malay

This website (“Website”) is operated by AFT Pharmaceuticals (SE Asia) Sdn. Bhd. and its affiliated parent company (referred to on the Website as “AFT”, “we”, “our” or “us”). AFT Pharmaceuticals (SE Asia) Sdn. Bhd. is a private limited company registered in Malaysia under company number 962386U and we have our registered office at Suite 9.01, Level 9, Menara Summit, Persiaran Kewajipan, USJ 1, UEP Subang Jaya, 47600 Subang Jaya, Selangor, Malaysia.

We have developed this privacy notice to inform you of the data we collect, what we do with your information, what we do to keep it secure as well as the rights and choices you have over your personal data, in accordance with the Personal Data Protection Act 2010 of Malaysia and its subsidiary legislation.

AFT Pharmaceuticals (SE Asia) Sdn. Bhd. is part of the AFT Pharmaceuticals Limited group of companies which is comprised of different companies, details of which can be found at www.aftpharm.com.

Throughout this policy, we refer to Data Protection Legislation which means the Personal Data Protection Act 2010 of Malaysia (“PDPA”) and any legislation implemented in connection with the aforementioned legislation. This includes any replacement legislation coming into effect from time to time.

Your continued use of our Website and our provision of the products and/or services offered on our Website to you, are only possible with your acceptance and consent to the terms of this Privacy Policy.

By accepting the terms of this Privacy Policy, you expressly consent to the processing of your personal data (as defined in the PDPA) by AFT, or any of its authorised agents, employees, partners and/or contractors for the Purposes above.

Where possible, express acceptance and consent to collection and processing of your personal data shall be evidenced by you clicking or checking or indicating accordingly on the relevant consent portions of any pop-up windows, registration forms or other documents provided to you.

If you are under the age of 18, you must ensure that your parents or legal guardian consent on your behalf to AFT’s processing of your personal data.

You also hereby authorise and consent to the processing by, and disclosure of your personal data to, third parties as identified and set out in this Privacy Policy for the purposes we have outlined in this Privacy Policy. For the avoidance of doubt, you also consent to the collection, processing and disclosure of any sensitive personal data (as defined in the PDPA) relevant for such purposes.

What Personal Data do we Collect and When?

The type of personal data that we will collect from you, and you voluntarily provide to us on this website may include some or all of the following depending on the type of user you are:

Website Users

Businesses and individuals that visit and interact with our website.

Storage TypeWhat we Store
User-Generated Content/DataName, Email Address, Free Format Text (Subject and Message for “Contact us” submission)
Website Usage DataIP Address, Browser Type and Version, Operating System, Device Information (e.g., device type, screen resolution), Date and Time of Website Visits, Pages Visited on the Website, Clickstream Data (User’s navigational path)
Cookies and Tracking DataCookies (e.g., session cookies, persistent cookies), User Tracking Information (for analytics and personalisation)

Why and How We Use Your Personal Data

To Operate, Improve and Maintain our Business, Products, and Services

We use the personal data you provide to us to operate our business. For example, when you make a purchase, we use that information for accounting, audits, and other internal functions. We may use personal data about how you use our website to enhance your user experience and to help us diagnose technical and service problems and administer our platform.

To Protect Our or Others’ Rights, Property, or Safety

You agree that we may also use personal data about how you use our website and platform, to prevent, detect, or investigate fraud, abuse, illegal use, violations of our Terms of Use, and to comply with court orders, governmental requests, or applicable law.

Using Your Personal Data: The Lawful Basis and Purposes

To process your personal data, we rely on certain lawful bases, depending on how you interact with our website, platform, or services.

If we do process your personal data, you agree that we may use one or more of the following lawful bases for processing:

As Necessary for Our Own Legitimate Interests or Those of Other Persons and Organisations, Including:

  • For market research, analysis, and developing statistics
  • To ensure the security of our website
  • To fulfil our contractual obligations to you

As Necessary to Comply with a Legal Obligation, Including but not limited to:

  • When you or any of your related persons exercise available rights under data protection law and make requests
  • For compliance with legal and regulatory requirements and related disclosures
  • For the establishment and defence of legal rights
  • Where we have been requested to collect and/or disclose such personal data in accordance with a request or order of a court of law or relevant regulatory authority

Sharing of Your Personal Data

We do not sell your personal data and shall share and/or disclose your personal data only in accordance with this Privacy Policy and the Data Protection Legislation.

You agree that we may share your personal data with other organisations in the following circumstances:

  • We use data processors who are third parties who provide elements of services for us. We have Data Processing Agreements in place with our data processors. This means that they cannot do anything with your personal information unless we have instructed them to do it. They will not share your personal information with any organisation apart from us or further sub-processors who must comply with our Data Processing Agreement. They will hold your personal data securely and retain it for the period we instruct, and all processing of your personal data shall be conducted in accordance with the relevant Data Protection Legislation.
  • Aft Pharmaceuticals Limited entities for the purposes and under the conditions outlined above. This includes its subsidiaries, and affiliated companies.

Our website contains links to websites owned and operated by third parties. If you use these links, you leave our Website. These links are provided for your information and convenience only and are not an endorsement by AFT Pharmaceuticals (SE Asia) Sdn. Bhd. of the content of such linked websites or third parties. AFT Pharmaceuticals (SE Asia) Sdn. Bhd. has no control over the contents of any linked website and is not responsible for these websites or their content or availability.

Cookies

We use cookies, which are small text files stored on your device. Using cookies is a way for us to make sure that our website is continuously improved, meets your needs and can be used as a tool to optimise our marketing strategy. For us to do this, we place functional cookies to make the website function as well as marketing cookies which help us target the right people and show them advertisements. Some of these cookies track your use of our website and visits to other websites and allow us to show you advertisements when you browse other websites.

Please view our Cookie Policy for more information on our use of cookies.

Rights under Data Protection Legislation

The Right to be Informed about our Collection and Use of Personal Data

You have the right to be informed about the collection and use of your personal data. We ensure we do this with our internal data protection policies and through our external website privacy notice. These are regularly reviewed and updated to ensure these are accurate and reflect our data processing activities.

Right to Access Your Personal Information

You have the right to access the personal information (ie. your personal data) that we hold about you in many circumstances, by making a request. This is sometimes termed ‘Subject Access Request’. If we agree that we are obliged to provide personal information to you (or someone else on your behalf), and in accordance with the PDPA, we will provide it to you or them free of charge and aim to do so within 1 month from when your identity has been confirmed.

We may ask for proof of identity and sufficient information about your interactions with us that we can locate your personal information.

If you would like to exercise this right, please contact us as set out below.

Right to Correction of Your Personal Information

If any of the personal information we hold about you is inaccurate, incomplete, or out of date, you have the right to request for us to correct it.

If you would like to exercise this right, please contact us as set out below.

Right to Stop or Limit Our Processing of Your Data

You have the right to withdraw your consent or to object to us processing your personal information for particular purposes, to have your information deleted if we are keeping it too long or have its processing restricted in certain circumstances.

You may, at any time, withdraw your consent to AFT’s processing of any personal data of yours or to any part or portion of the processing by sending a written notice of withdrawal to AFT at the address set out below. AFT shall take all necessary measures to give effect to your withdrawal of consent within the period prescribed under the Data Protection Legislation, to the extent that such withdrawal does not conflict with any other legal obligations that may be applicable to AFT.

You can ask us to restrict processing your data, for example where:

  • you’re contesting the accuracy of your personal data.
  • we no longer need to process your personal data, but you want us to keep it for use in legal claims.
  • you’ve objected to the processing by asking us to stop using your data, but you’re waiting for us to tell you if we have overriding grounds which mean we’re allowed to keep on using it.

If you would like to exercise this right, please contact us as set out below.

Right to Portability

The right to portability gives you the right to receive personal data you have provided to a controller in a structured, commonly used, and machine-readable format. It also gives you the right to request that a controller transmits this data directly to another controller.

If you would like to exercise this right, please contact us as set out below.

Rights in Relation to Automated Decision Making and Profiling

You have rights around automated decision-making and profiling. Automated decision-making means a decision made solely by automated means, without any human involvement. Profiling means the automated processing of your personal information to evaluate certain things about you. You have the right to information about these kinds of processing, and the right to ask for human intervention or to challenge an automated decision.

If you would like to exercise this right, please contact us as set out below.

For More Information About Your Data Protection Rights

The Personal Data Protection Commissioner regulates data protection matters in Malaysia.

You may make a complaint to the Personal Data Protection Commissioner at any time about the way we use your information. However, we hope that you would consider raising any issue or complaint you have with us first. Your satisfaction is extremely important to us, and we will always do our very best to solve any problems you may have.

Third-Party Processors and Service Providers

Our carefully selected partners and service providers may process personal information about you on our behalf as described below:

ServiceDescription
Security VendorsThese trusted experts employ advanced cybersecurity measures, such as intrusion detection, threat monitoring, and malware scanning, to protect your personal data from unauthorized access and cyber threats.
Customer Support ProvidersWe work with dedicated customer support providers. They assist in addressing your queries, resolving issues by securely managing and accessing relevant customer data.
Content Delivery Networks (CDNs)To optimize the speed and reliability of our online services, we rely on Content Delivery Networks (CDNs). CDNs efficiently deliver web content to you by strategically distributing it across global servers. Your data is cached and served from the nearest server, reducing latency, and enhancing your overall experience.
Content Management SystemsTo assist us in the creation, management, and design of our website.
Analytics and AdvertisingTo improve our products and provide you with relevant content and advertisements, we collaborate with analytics and advertising partners. They analyze user behavior, preferences, and demographics to personalize your experience and deliver targeted ads.
Hosting ServicesProviding the facilities needed to create and maintain our website, as well as make it accessible through the internet.
Third PartyService ProvidedDescription of Service
PodcomIT infrastructure and development servicesPodcom offers managed IT support and development services for AFT Group.
FastlyContent Delivery Network and Web protection servicesFastly offers web efficiency and protection services for our platform.  Fastly – Privacy Policy
P29Website Management and AdministrationP29 offer website design and management services for our product. Platform29 – Privacy Policy
WordPressContent ManagementWordPress offers web content management systems. WordPress – Privacy Policy

How Long We Keep Your Information

We will only retain your personal data for as long as necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements, and in accordance with the Data Protection Legislation. Where the same record has to be kept for more than one purpose and there is a different retention period for each of those purposes, the record is kept for the longer period.

To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.

Security

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorized way, altered, or disclosed. Platforms, systems, and facilities in which personal data are processed are protected by secure network architectures that contain firewalls and intrusion detection devices.

In addition, we limit access to your personal data to those employees, agents, contractors, and other third parties who have a business need to know. They will only process your personal data on our instructions, and they are subject to a duty of confidentiality.

Where We Store Your Personal Information and International Data Transfers

You hereby agree that the personal data that we hold about you will be stored in Malaysia and may also be transferred to or stored in other jurisdictions besides Malaysia. Your personal data may also be shared with third-party service providers based outside Malaysia. Some of the data recipients with whom AFT shares your personal data with may be located in countries other than the country in which your personal data originally was collected.

Where we transfer your data outside Malaysia, we ensure a similar degree of protection is provided to the transfer by ensuring at least one of the following safeguards is implemented:

  • we will only transfer your personal data to countries that have at least a similar, or higher, legal standard of data protection as the standards set out in the Data Protection Legislation in Malaysia.
  • We shall take appropriate measures to safeguard your personal data in accordance with all applicable Data Protection Legislation.
  • where we use certain service providers, we shall ensure that we contractually bind and hold these service providers to an adequate level of protection and obligations to protect personal data as required by the relevant Data Protection Legislation, as well as any additional security measures as required.

Please contact us if you want further information on the specific mechanism used by us when transferring your personal data out of Malaysia.

Contact Us

If you would like to exercise one of your rights as set out above, or you have a question or a complaint about this policy, the way your personal information is processed, please contact us by one of the following means:

AFT Pharmaceuticals (SE Asia) Sdn. Bhd., FAO Data Protection Officer (DPO)
Regus, Level 9, Menara Summit, Persiaran Kewajipan, USJ 1, UEP, 47600 Subang Jaya, Selangor, Malaysia.
infoasia@aftpharm.com
Contact: +6013 6839288