Gamuda Berhad, its subsidiaries, associates, jointly controlled entities and affiliates (including but not limited to Gamuda Group of Companies and Gamuda Group of Companies’ associates, jointly controlled entities, affiliates and including but not limited to those mentioned in First Schedule hereto) (collectively, “Group”), respects the privacy of individuals with regard to personal data. This Privacy Notice is formulated in accordance with the Personal Data Protection Act 2010 (“Act”). For the purpose of this Privacy Notice, “Personal Data” shall have the meaning as ascribed to it in the Act and “we” and “us” shall refer to any of the companies within the Group and “you” shall refer to yourself and/or such other persons or companies represented by you of which you are providing Personal Data.
View in Bahasa Malaysia
This privacy notice describes how your personal data is collected, used and disclosed by Gamuda Berhad and other companies in Gamuda Berhad’s group, including its subsidiaries, associates, jointly controlled entities and affiliates which are incorporated in the UK, EU or in Malaysia (including but not limited to Gamuda Group of Companies and Gamuda Group of Companies' associates, jointly controlled entities, affiliates and including but not limited to those mentioned here) a (collectively "Group ", "we", “our” or "us").
It applies to personal data we obtain from or about you when you (i) visit all digital and mobile platforms (including but not limited to websites, social media and mobile apps) operated by us that link to this privacy notice (collectively, the “Sites“); (ii) interact with us (e.g. complete printed collateral or forms, use search tools, participate in surveys or competitions, communicate with us); (iii) participate in our events; or (iv) visit our offices.
It also describes your data protection rights, including the right to object to some of the processing which we carry out. More information about your rights, and how to exercise them, is set out in the “Your choices and rights” section.
We may provide additional information about our privacy practices at other points, for example, when we ask you to provide personal data in connection with a particular service or when you apply for a job, and where this will help us provide more relevant and timely information.
We may collect and process the following categories of personal data from and about you:
Category | Details |
---|---|
Account Information | Your username and password, photograph, and information collected when you register or update your online profile or when you fill in or update your information with us. |
Contact Information | Your name, address, email address and phone number |
Marketing and Personalisation Information | Your marketing preferences, including any consents you have given us |
Device and Usage Information | Information related to (i) the browser or device you use to access our Sites, the website or source that linked or referred you to the Sites, your IP address or device ID (or other identifier that identifies your computer or mobile device on the Internet) from which we may derive your general location, the operating system of your computer or mobile device, device screen size and other similar technical information and (ii) your visit and interactions with our Sites and advertisements, including the content viewed and content interacted with, the dates and times of access, hardware and software information and device event information. We may use cookies or similar technologies to capture this information. If you want to know more, please refer to our Cookie Notice. |
Submitted Information | Information included in all printed and electronic forms or documents you submit to us through printed materials or our Sites. This includes information entered into online tools like search tools and calculators, and any messages or comments you send us. |
Survey Information | Information submitted if you participate in surveys or competitions. |
Sometimes, we receive information about you from third parties. In particular: we may collect data from sources such as professional social media platforms, where we obtain professional information like your job title, company, work history, and professional skills; credit reporting services, which provide us with financial and credit-related information, including credit scores, credit history, and business credit reports; and government websites, from which we gather publicly available information such as company registration details, directorships, and other regulatory filings.
We will only use your personal data for the purposes and legal bases set out below:
Personal Data Category | Purpose | Legal Basis |
---|---|---|
Account Information Contact Information Submitted Information Financial Information | Provide you with our services. | It is necessary for us to process your personal data in order to perform our contract with you, or to take steps at your request prior to entering into a contract with you. |
Account Information Contact Information Submitted Information | To manage our relationship with you, including to send you service messages. | We have a legitimate interest in effectively managing our client relationships and ensuring efficient communication regarding our services. |
Account Information Contact Information Financial Information | To facilitate payment for services, including processing invoices and payments [(including card payments)]. | It is necessary for us to process your personal data in order to perform our contract with you. |
Account Information Contact Information Financial Information | To complete our financial reporting and disclosure obligations to our parent company, tax agencies and regulators. | When we have a legal obligation under EEA, Member State or UK law, we process the data in order to comply with applicable law and regulations. When we have a legal obligation under laws outside the EEA /UK (such as Malaysian laws) or our processing is not pursuant to a legal obligation, we have a legitimate interest in protecting our business interests and legal rights, and the interests and legal rights of our users. |
Account Information Contact Information Submitted Information | To manage our customer loyalty programmes. | We have a legitimate interest in fostering customer loyalty and enhancing client engagement through our loyalty programmes. |
All Categories | To monitor customer accounts to prevent, investigate and/or report fraud, terrorism, misrepresentation, security incidents or crime, in accordance with applicable law. | When we have a legal obligation under EEA, Member State or UK law, we process the data in order to comply with applicable law and regulations. When we have a legal obligation under laws outside the EEA/UK (such as Malaysian laws) or our processing is not pursuant to a legal obligation, we have a legitimate interest in protecting our business interests and legal rights, and the interests and legal rights of our users. |
Account Information Contact Information Submitted Information Marketing and Personalisation Information Device Information | To send you direct marketing in relation to the Group’s products and services. This includes the sending of any updates, new products, special offers, advertising, promotional material and/or commercial material to you (including emails, targeted advertising, SMS or other means). | Your consent. We have a legitimate interest in promoting our services to our clients. |
Account Information Contact Information Submitted Information Device Information | To manage and operate our Sites, including to keep them updated and relevant, to operate, administer and develop our offices and business and to inform our marketing and advertising strategy. | Your consent (where necessary for the use of certain cookies and tracking technologies). We have a legitimate interest in operating and managing our Sites, offices and our business and improving their operation. |
Account Information Contact Information Submitted Information Device Information | To conduct research, develop new products and services and to improve or modify our existing services. This includes performing statistical analytics. We reserve the right to disclose aggregate or anonymous data to third parties for lawful purposes. | Your consent (where necessary for the use of certain cookies and tracking technologies). We have a legitimate interest in innovating and enhancing our product and service offerings through research and analytics. |
Account Information Contact Information Submitted Information Survey Information | To invite you to take part in and manage customer surveys, reviews and other market research activities carried out by the Group. | We have a legitimate interest in gathering customer insights to inform our business strategies and improve our offerings. |
All Categories | To conduct due diligence checks (including in relation to international sanctions) on business contacts and to enforce compliance with any agreements, our terms of use and other policies, or otherwise in connection with legal claims, compliance, regulatory and investigatory purposes, as necessary (including disclosure of such information in connection with government agency requests, legal process or litigation). | Where we have EEA or UK legal obligations to meet these requests or requirements, it is necessary for us to comply with our legal obligations. Otherwise, it is in our legitimate interests to meet the relevant requests or purposes. |
Video recordings captured through security cameras. | To ensure the safety and security of our offices, staff and visitors, and to prevent, deter and investigate unauthorised or unlawful activities, trespassing or misconduct. | We have a legitimate interest in safeguarding our premises, staff and visitors, investigating security incidents and preventing potential offences. |
Video and audio recordings of meeting participants (including images and voices) | To document discussions, decisions and actions taken during meetings for reference, training, or accountability purposes. This may also include sharing recordings with participants or relevant stakeholders who were unable to attend. | We have a legitimate interest in recording meetings for business continuity, training, or evidentiary purposes. In certain circumstances, we may rely on your consent (for instance, if local law requires explicit permission to record audio or video). |
There are instances where we have a legitimate interest to use your data. Our legitimate interest will vary depending on what we are using your data for, and we explain above what the interest is and how it relates to the processing operations that we are carrying out. Where we process personal data on the basis of a legitimate interest, then – as required by data protection law – we have carried out a balancing test to document our interests, to consider what the impact of the processing will be on individuals and to determine whether individuals’ interests outweigh our interests in the processing taking place. You can obtain more information about this balancing test by using the contact details at the end of the notice.
We may share your data with the following categories of recipients:
Personal Data Category | Category of Recipient | Why? |
---|---|---|
Account Information Contact Information Device Information Submitted Information | Group companies | To operate, improve, and develop our services. |
All Categories | Third party service providers | We employ other companies and individuals to perform functions on our behalf. Examples include organizations who provide archival, auditing, background and credit checks, professional advisory, debt collection, insurance, banking, marketing, advertising, mail house, IT services, delivery, recruitment, call centre, technology, research, utility, loyalty programmes and security services. |
Any relevant personal data | Agents, accountants, consultants, solicitors, professional advisors, auditors | To provide professional services and advice. |
Account Information Contact Information Submitted Information | Partners & joint venture partners | To collaborate on joint projects and initiatives. |
Contact Information Marketing and Personalisation Information Device Information | Advertisers | To provide targeted advertising and marketing. |
Any relevant personal data | Any relevant authorities (governmental and/or non-governmental), embassies, statutory bodies, regulatory bodies, law enforcement and fraud prevention agencies and/or any relevant financial institutions | To prevent, investigate and/or report fraud, terrorism, misrepresentation, security incidents or crime, in accordance with applicable law. |
Any relevant personal data | Actual or proposed assignees or transferees or buyers of any of rights/businesses/assets of the companies within the Group and their advisors | In the event that the business is sold or integrated with another business, your details will be disclosed to our advisers and any prospective purchaser’s adviser and will be passed to the new owners of the business. |
We may transfer your data to some third parties which host or access personal data outside of the UK and EEA. In the event such an organisation is in a country which is not subject to an adequacy decision by the EU Commission or the UK government or otherwise considered adequate as determined by applicable data protection laws, we take steps to ensure your personal data is adequately protected, including by adopting standard contractual clauses, unless we can rely on a relevant exemption. A copy of the relevant mechanism can be obtained for your review on request by using the contact details below.
You have the following rights:
Right | Summary |
---|---|
The right of access | Enables you to receive a copy of your personal data |
The right to rectification | Enables you to correct any inaccurate or incomplete personal data we hold about you |
The right to erasure | Enables you to ask us to delete your personal data in certain circumstances |
The right to restrict processing | Enables you to object to us processing your personal data on the basis of our legitimate interests (or those of a third party), including processing for direct marketing purposes or profiling for purposes of direct marketing, or where we are performing a task in the public interest - your objection will be upheld, and we will cease processing your personal data, unless the processing is based on compelling legitimate grounds or is needed for the exercise or defence of legal claims that may be brought by or against us. |
The right to object | Information included in all printed and electronic forms or documents you submit to us through printed materials or our Sites. This includes information entered into online tools like search tools and calculators, and any messages or comments you send us. |
The right to data portability | Enables you to request us to transmit personal data that you have provided to us, to a third party without hindrance, or to give you a copy of it so that you can transmit it to a third party, where technically feasible |
These rights may be limited, for example if fulfilling your request would reveal personal data about another person, or if you ask us to delete information which we are required by law or have compelling legitimate interests to keep.
If you wish to exercise any of these rights, please contact us at the contact details set out below.
Wherever we rely on your consent, you have the right to withdraw that consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal. We may however have other legal grounds for processing your data for other purposes, such as those set out above.
In some cases, we are able to send you direct marketing without your consent, where we rely on our legitimate interests. You have an absolute right to opt-out of direct marketing, or profiling we carry out for direct marketing, at any time. You can do this by following the instructions in the communication where this is an electronic message, or by contacting us using the details set out below.
We do not carry out any solely automated decision making which produces legal or significantly similar effects.
If you have unresolved concerns, you have the right to complain to a data protection authority in the country that you reside in or, the country of your place of work or the country where the alleged infringement took place. In the UK, this is the ICO who can be contacted here. In the EU, information about how to contact your local supervisory authority is available here.
For providing our services, the provision of information is mandatory: if relevant data is not provided, then we will not be able to provide you with our services. The provision of all other information is optional.
Where we process registration data, we do this for as long as you are an active user of our Sites and for 3 years after this.
Where we process personal data for marketing purposes or with your consent, we process the data until you ask us to stop and for a short period of 30 days after this (to allow us to implement your requests). We also keep a record of the fact that you have asked us not to send you direct marketing or to process your data indefinitely so that we can respect your request in future.
Where we process personal data for Site security purposes, we retain it for 6 months.
Where we process personal data in connection with performing a contract or for a survey, we keep the data for 6 years from your last interaction with us.
The security of your personal data is important to us. We implement appropriate technical and organisational measures to safeguard the information you entrust to us, preventing its loss, misuse, unauthorized access or disclosure, alteration, and destruction, addressing threats from both external and internal sources.
We reserve the right to update this privacy notice at any time, and we will provide you with a new privacy notice when we make any substantial updates. We may also notify you in other ways from time to time about the processing of your personal information.
Your information is controlled by Gamuda Berhad and group companies. The contact details of the Group Data Protection Officer are as follows:
Data Controller | Contact Details |
---|---|
Gamuda Berhad | Menara Gamuda Muhamad Khairie Bin Othman Email: DPO.Gamuda@gamuda.com.my Tel No: 603-74918288 |