Last Updated: 22 August 2021

GoWaus may collect your personal data and information to provide you with the best experience in using the Platform and to improve our Services. In Malaysia, the Personal Data Protection Act 2010 (“PDPA”) regulates the processing of personal data in commercial transactions and requires us to inform you of your rights in respect of your personal data that is being processed, the purposes for the data processing as well as obtain your consent to the processing of your personal data. Be assured that we are committed to respecting and protecting your privacy and the personal data that you provide to us and/or we collect.

Please review this Privacy Policy (“Privacy Policy or “Policy”), which is incorporated and forms part of GoWaus’s Terms of Use (“Terms”), to understand how GoWaus collects, uses, discloses and/or processes your personal data and to assist you in making an informed decision before providing us with any of your personal data. BY ACCESSING OR USING THE PLATFORM AND/OR OUR SERVICES OR OPENING AN ACCOUNT, YOU ACKNOWLEDGE AND AGREE THAT YOU ACCEPT THE PRACTICES, REQUIREMENTS, AND POLICIES OUTLINED IN THIS PRIVACY POLICY, AND YOU HEREBY CONSENT TO US COLLECTING, USING, DISCLOSING AND/OR PROCESSING YOUR PERSONAL DATA AS DESCRIBED HEREIN. IF YOU DO NOT CONSENT TO THE PROCESSING OF YOUR PERSONAL DATA AS DESCRIBED IN THIS PRIVACY POLICY, PLEASE DO NOT ACCESS AND/OR USE THE PLATFORM OR SERVICES OR OPEN AN ACCOUNT.

We reserve the right to amend this Privacy Policy at any time. To the fullest extent permissible under applicable law, your continued use of the Platform or Services, including placing of any bookings, shall constitute your acknowledgement, consent and acceptance of the changes made to this Privacy Policy. This Privacy Policy applies in conjunction with other notices, contractual clauses, consent clauses that apply in relation to the collection, storage, use, disclosure and/or processing of your personal data by us (if any) and is not intended to override those notices or clauses unless we state expressly otherwise.

1.1  Definitions

 

“device” means any device that can access the Platform or Services such as a computer, laptop, mobile phone and digital tablet;
“PDPA”means the Personal Data Protection Act 2010;
“personal data”shall have the same meaning ascribed to it in the PDPA;
“Privacy Policy” or “Policy”means this Privacy Policy;
“Social Media Account”means a social media account including but not limited to a Facebook, Twitter and Instagram account; and
“Terms” means GoWaus’s Terms of Service.

 

 

1.2  Definitions and Interpretation Provided in the Terms

Except where the context otherwise requires, or unless this Privacy Policy otherwise provides, all terms words and expressions used or referred to in this Privacy Policy shall have the same meanings as provided for in the Terms and the principles of interpretation therein shall also apply to this Policy.

 

1.3   Application

This Privacy Policy applies to all Users (both Hosts and Customers) except where expressly stated otherwise.

2.1  Common Instances When Personal Data is Collected

 

The following are some common instances of when GoWaus may collect personal data about you (this list does not purport to be exhaustive):

(a) when you access and/or use the Platform or Services or open an Account;

 

(b) when you provide or submit any documentations, information or forms relating to the Platform or any of the Services whether online, through the Platform or physically;

 

(c) when you interact with GoWaus such as via telephone calls (which may be recorded), letters, fax, face-to-face meetings, social media platforms and emails, including when you interact with our customer service agents;

 

(d) when you grant permissions on your device to share information with GoWaus;

 

(e) when you link your Account with your Social Media Account or other external account;

 

(f) when you provide us with feedbacks or complaints;

 

(g) when you register for a contest or promotion; or

 

(h) when you submit your personal data to us for any reason.

 

2.2  Personal Data Provided by You

 

GoWaus collects personal data that you provide to us including but not limited to:

(a) Personal Details: name, telephone or mobile number, postal, billing or delivery address, email address, date of birth, gender and profile photo;

 

(b) Identity Verification: government issued identification number (including image of the same) or other verification information required for our identity verification, due diligence, know your customer or fraud prevention purposes;

 

(c) Accommodation or Activity: information or documents regarding the Accommodation or Activity required for our due diligence, verification or fraud prevention purposes;

 

(d) Payment information and/or documents: bank account number or statement, payment information, tax identification number; and

 

(e) Other Information: User Content that you share with us, your health information, details of the guests you invite to an Accommodation or Activity.

 

2.3  Personal Data or Information Provided by Third Parties

 

GoWaus collects personal data that third parties provide to us including:

(a)  Third Party Services: if you link, connect or login to the Platform or Account with your Social Media Account or other external service, you direct the service to send us information such as your registration, friends list and profile information as controlled by that service or as authorized by you via your privacy settings at that service;

 

(b)  Background Information: to the extent permitted by applicable laws and with your consent where required, we may obtain reports from public records of criminal convictions or background. We may use your information, including your full name and date of birth, to obtain such reports;

 

(c)  Referrals and Guests: if you are included as a Guest for any Accommodation or Activity, the Customer who invited you can submit personal information about you such as your email address or other contact information;

 

(d)  Other Sources: to the extent permitted by applicable law, we may receive additional information about you, such as demographic data or information to help detect fraud and safety issues from third party service providers and/or partners and combine it with information we have about you. For example, we may receive background check results or fraud warnings from identity verification service providers for use in our fraud prevention and risk assessment efforts. We may receive information about you and your activities on and off the Platform, or about your experiences and interactions from our partners. We may receive health information, including but not limited to health information related to contagious diseases.

 

2.4   Personal Data or Information Collected through Your Use of the Platform

 

Your device automatically sends information that gets logged by a web server when you use our Platform or Services including but not limited to:

(a)  Geo-location Information such as precise or approximate location determined from your IP address or device’s GPS depending on your device settings. We may also collect this information when you’re not using the mobile app if you enable this through your settings or device permissions;

 

(b)  Usage Information such as the pages or content you view, searches for Listings, bookings you have made and other actions on the Platform;

 

(c)  Log Data and Device Information such as details about how you use the Platform (including if you clicked on links to third party applications), IP address, access dates and times, hardware and software information, device information, device event information, unique identifiers, crash data, cookie data, and the pages you have viewed or engaged with before or after using the Platform. We may collect this information even if you have not created an Account or logged in;

 

(d)  Cookies and Similar Technologies as described below;

 

(e)  Marketing and Communications Data such as your preferences in receiving marketing from us and third parties, your communication preferences and history of communications with us, our service providers and other third parties; and

 

(f)  Payment Transaction Information such as payment instrument used, date and time, payment amount, payment instrument expiration date and billing postcode, your address and other related transaction details.

3.1  Cookies

When you access or use the Platform, your device will automatically be issued with “cookies”. Cookies are text files with small pieces of data that are stored on and used to identify your device. Cookies record data about your device and how and when the Platform or Services are accessed or used, by how many people and other activity within our Platform. We may link cookie information to personal data. Cookies also link to information such as Listings, Contents or web pages you have viewed or searched for, Accommodation or Activity that you have selected for purchase and bookings that you have made.  The information retrieved from our cookies are used in line with the purposes set out in this Privacy Policy and more specifically:-

(a)  To save and retrieve passwords used on the Platform so that you will not have to re-enter information upon every new visit to the Platform;

 

(b)  To track information such as your shopping cart, the frequency and duration of your access and/or use of the Platform, your clickstream as you go through the Platform and to determine whether you came to the Platform from a particular internet link or banner advertisement; and

 

(c)  To analyse the profile of Users to help us in providing you with better access and/or use of the Platform, to enhance the Platform, to offer new Services and to enable us and our third-party advertising partners to serve more personalized and relevant content including advertisements to you.

 

3.2  Disabling Cookies

You may refuse the use of cookies by selecting the appropriate settings on your browser or device. However, please note that if you do this you may not be able to use the full functionality of our Platform or the Services.

 

3.3  Third Party Cookies

While serving advertisements when you access and/or use the Platform, a third-party may place or recognize a unique cookie in your device. Such third party may use information retrieved from their cookies to provide advertisements on the Platform and other product and services that may be of interest to you. WE HAVE NO ACCESS TO OR CONTROL OVER THE THIRD-PARTY COOKIES AND THEY ARE NOT SUBJECT TO OUR PRIVACY POLICY. PLEASE REVIEW THEIR PRIVACY POLICY FOR DETAILS. If you want to prevent such third party from sending and reading cookies on your device, you will need to visit each of their websites individually to request that you be removed from that system.

4.1  Purposes

We may collect, use, disclose and/or process your personal data for one or more of the following purposes (collectively referred to as “Purposes”):

 

(a)  To provide, improve and develop the Platform and/or Services:

(i)    enable you to access the Platform;

(ii)   enable you to communicate with other Users;

(iii)  perform analytics, debug and conduct research;

(iv)  provide customer service;

(v)   send you messages, updates, security alerts, and account notifications;

(vi)  if you provide us with your contacts’ information such as your friends or Guests, we may process this information to facilitate your referral invitations, to share your Accommodation or Activity details and facilitate planning, for fraud detection and prevention and to facilitate your requests or for any other purpose you authorize; and

(vii) personalize and customize your experience based on your interactions with the Platform, your search and booking history, your profile information and preferences, and other content you submit;

 

(b)  To help facilitate bookings and interactions between Users or other interactions connected with bookings:

(i)   facilitating and coordinating bookings;

(ii)  handling of disputes;

(iii) hosting or co-hosting of Accommodations or Activities;

(iv)  inviting of additional guests to an Accommodation or Activity;

(c)  To create and maintain a trusted and safer environment:

(i)     detect and prevent fraud, spam, abuse, security and safety incidents, and other harmful activity;

(ii)    study and combat discrimination;

(iii)   conduct security investigations and risk assessments;

(iv)   verify or authenticate information provided by you;

(v)    conduct checks against databases and other information sources, including background or police checks;

(vi)   comply with our legal obligations, protect the health and well-being of our Customers, Hosts, Hosts’ employees and members of the public;

(vii)  resolve disputes with our Users;

(viii) enforce our Terms and Policies and our agreements with third parties;

(ix)   comply with law, respond to legal requests, prevent harm and protect our rights;

(x)    in connection with the activities above, we may conduct profiling based on your interactions with the Platform, your profile information and other content you submit to GoWaus, and information obtained from third parties. In limited cases, automated processes could restrict or suspend access to the Platform if such processes detect activity that we think poses a safety or other risk to GoWaus, our community or third parties. If you would like to challenge the decisioning based on the automated process, please contact us via the Contact Us section below.

 

(d) To provide, personalize, measure and improve our advertising and marketing:

(i)    send you promotional messages, marketing, advertising and other information that may be of interest to you based on your preferences and social media advertising through social media platforms;

(ii)   personalize, measure, and improve our advertising;

(iii)  administer referral programs, rewards, surveys, sweepstakes, contests, or other promotional activities or events sponsored or managed by GoWaus or its third-party partners;

(iv)  analyze characteristics and preferences to send you promotional messages, marketing, advertising and other information that we think might be of interest to you; and

(v)   invite you to events and relevant opportunities.

 

(e) To provide and improve payment services:

(i)   enable you to make and receive payments;

(ii)  detect and prevent money laundering, fraud, abuse, security incidents;

(iii) conduct security investigations and risk assessments;

(iv)  comply with legal obligations; and

(v)   enforce payment terms and other payment policies.

 

4.2  Other Purposes

As the purposes for which we collect, use, disclose or process your personal data depend on the circumstances at hand, such purpose may not appear above. However, we will notify you of such other purpose(s) prior to or at the time at which the personal data is collected.

5.1  Disclosure

We will or may need to disclose your personal data to the following third parties for one or more of the abovementioned Purposes:

 

(a) our subsidiaries, affiliates and related corporations;

 

(b) Hosts (including third party service providers used by Hosts), Customers or other Users you have transacted with or interacted with on the Platform or in connection with your use of the Services for the abovementioned Purposes;

 

(c) contractors, agents, service providers and other third parties we use to support our business including but not limited to mailing houses, financial services providers, advertising and marketing partners, third-party suppliers of advertisements, telecommunication companies, information technology companies, programming companies and data centres;

 

(d) a buyer or other successor in the event of a merger, divestiture, restructuring, reorganization, dissolution or other sale or transfer of some or all of GoWaus’s assets, whether as a going concern or as part of bankruptcy, liquidation or similar proceeding, in which personal data held by GoWaus about our Users is among the assets transferred; or to a counterparty in a business asset transaction that GoWaus or any of its affiliates or related corporations is involved in;

 

(e) governmental or regulatory authorities having jurisdiction over GoWaus or as otherwise permitted under Clause 5.2 below; and

 

(f) third parties to whom disclosure by us is for one or more of the Purposes and such third parties would in turn be collecting and processing your personal data for one or more of the Purposes.

 

5.2 Disclosure Pursuant to Law etc.

You acknowledge, consent and agree that GoWaus may access, preserve and disclose your personal data or information if required to do so by law or by any courts, law enforcement, governmental, public, regulatory or tax authorities or authorized third parties or in a good faith belief that such access, preservation or disclosure is permitted by law or reasonably necessary:

 

(a) to comply with legal process or our legal obligations;

 

(b) to comply with a valid legal request including but not limited to request relating to a criminal investigation to address alleged or suspected illegal activity or to respond to or address any other activity that may expose us, you or any other User to legal or regulatory liability;

 

(c) to respond to any threatened or actual claims asserted against GoWaus or other claim that any Content violates the rights of third parties;

 

(d) to enforce these Terms or this Privacy Policy;

 

(e) to respond to your requests for customer service; or

 

(f) to protect the rights, property or personal safety of GoWaus, its employees, its Users and/or the public.

Where appropriate, we may notify Users about legal requests unless providing notice is prohibited by the legal process itself, by the court order we receive, or by applicable law, or we believe that providing notice would be futile, ineffective, create a risk of injury or bodily harm to an individual or group, or create or increase a risk of fraud upon or harm to GoWaus, our Users or expose GoWaus to a claim of obstruction of justice.

THE PLATFORM AND/OR SERVICES ARE NOT INTENDED FOR MINORS UNDER EIGHTEEN (18) YEARS OF AGE. WE DO NOT KNOWINGLY COLLECT OR MAINTAIN ANY PERSONAL DATA OR NON-PERSONALLY IDENTIFIABLE INFORMATION FROM ANYONE UNDER THE AGE OF 18 NOR IS ANY PART OF OUR PLATFORM OR OTHER SERVICES DIRECTED TO MINORS UNDER THE AGE OF 18. AS A PARENT OR LEGAL GUARDIAN, PLEASE DO NOT ALLOW SUCH MINORS UNDER YOUR CARE TO SUBMIT PERSONAL DATA TO GOWAUS. IN THE EVENT THAT PERSONAL DATA OF A MINOR UNDER THE AGE OF 18 IN YOUR CARE IS DISCLOSED TO GOWAUS, YOU HEREBY CONSENT TO THE PROCESSING OF THE MINOR’S PERSONAL DATA AND ACCEPT AND AGREE TO BE BOUND BY THIS PRIVACY POLICY ON BEHALF OF SUCH MINOR.  WE WILL CLOSE ANY ACCOUNTS USED EXCLUSIVELY BY SUCH MINOR AND WILL REMOVE AND/OR DELETE ANY PERSONAL DATA WE BELIEVE WAS SUBMITTED WITHOUT PARENTAL CONSENT BY ANY MINOR UNDER THE AGE OF 18.

7.1 Third Party Websites

To provide you with increased value, we may choose various third-party websites to link to, and frame within, the Platform. We may also participate in co-branding and other relationships to offer e-commerce and other services and features to our Users. These linked sites have separate and independent privacy policies as well as security arrangements. Even if the third party is affiliated with us, we have no control over these linked sites, each of which has separate privacy and data collection practices independent of us. Data collected by our co-brand partners or third-party web sites (even if offered on or through our Platform) may not be received by us.

 

7.2 Disclaimer

We have no responsibility or liability for the content, security arrangements (or lack thereof) and activities of these linked third-party sites and WE DO NOT GUARANTEE THE SECURITY OF PERSONAL DATA AND/OR OTHER INFORMATION THAT YOU PROVIDE TO SUCH THIRD-PARTY SITES. These linked sites are only for your convenience, and you therefore access them at your own risk. Nonetheless, we seek to protect the integrity of our Platform and the links placed upon each of them and therefore welcome any feedback about these linked sites (including, without limitation, if a specific link does not work).

8.1 Location of your Personal Data

In most cases, your personal data will be processed in Malaysia where our servers are located.

 

8.2 Transfer of Personal Data Overseas

It may be necessary to transfer your personal data to our affiliates and/or authorised third party located outside of Malaysia to be stored and/or processed. This may happen where our affiliate and/or authorised third party is based outside of Malaysia or where you access and/or use the Platform from countries outside of Malaysia. By continuing to access and/or use the Platform, you consent to such transfer of your personal data.

9.1 Self-Access

If you have an Account, you may personally access and/or correct some of your personal data through the Account settings page on the Platform. If you connected your Account to your Social Media Account or a third-party service, you can change your settings and unlink from that service in your Account settings. You are responsible for keeping your personal information up to date.

 

9.2 Request to Access and/or Correct

If you do not have an Account or are unable to access and/or correct your personal data through the Account settings page on the Platform, you may request to access and/or correct your personal data currently in our possession or control by submitting a written request to us at the email address provided in the “Contact Us” section below. We will need enough information from you in order to ascertain your identity as well as the nature of your request so as to be able to deal with your request.

(a) For a request to access personal data, once we have sufficient information from you to deal with the request, we will seek to provide you with the relevant personal data within thirty (30) days. Where we are unable to respond to you within the said thirty (30) days, we will notify you of the soonest possible time within which we can provide you with the information requested. Note that applicable laws may exempt certain types of personal data from being subject to your request for access.

 

(b) For a request to correct personal data, once we have sufficient information from you to deal with the request, we will:

(i) correct your personal data within thirty (30) days. Where we are unable to do so within the said period, we will notify you of the soonest practicable time within which we can make the correction. Note that applicable laws may exempt certain types of personal data from being subject to your request for correction as well as provide for situations when correction need not be made by us despite your request; and

(ii) we will send the corrected personal data to every other organisation to which the personal data was disclosed by us within a year before the date the correction was made unless that other organisation does not need the corrected personal data for any legal or business purpose.

 

9.3 Request to Send Corrected Personal Data to Specific Organisations

Notwithstanding Clause 9.2(b)(ii) above, we may, if you so request, send the corrected personal data only to specific organisations to which the personal data was disclosed by us within a year before the date the correction was made.

 

9.4 Handling and Processing Fee

We may charge you a reasonable fee for the handling and processing of your request to access your personal data. If we so choose to charge, we will provide you with a written estimate of the fee we will be charging. Please note that we are not required to respond to or deal with your access request unless you have agreed to pay the fee.

 

9.5 Right to Refuse

We reserve the right to refuse to comply with your request for access and/or correction in accordance with the provisions of the PDPA or other applicable laws.

10.1 Withdrawal

You may opt out of or withdraw your consent for the collection, use and/ or disclosure of your personal data in our possession or under our control by sending us an email at the email address provided in the “Contact Us” section below.

10.2 Process of Withdrawal

Once we have your clear withdrawal instructions and verified your identity, we will process your request for withdrawal of consent, and will thereafter not collect, use and/or disclose your personal data in the manner stated in your request. If we are unable to verify your identity or understand your instructions, we will liaise with you to understand your request.

 

10.3 Consequences of Withdrawal

You acknowledge that your opting out or withdrawal of consent for the collection, use and/or disclosure of your personal data could result in certain consequences and depending on the extent of your withdrawal, it may mean that we will not be able to continue providing the Services to you and may terminate your existing relationship and/or the agreement you have with us, which we will inform you of.

11.1 Protection

We implement a variety of security measures and strive to ensure the security of your personal data on our servers. The personal data of all Users are contained behind secured networks and are only accessible by a limited number of employees who have special access rights to such servers. However, third parties may unlawfully intercept or access personal data transmitted to or contained on the Platform, technologies may malfunction or not work as anticipated, or someone might access, abuse or misuse information through no fault of ours and there can inevitably be no guarantee of absolute security. We will nevertheless continuously implement and update administrative, technical and physical security measures to help protect your personal data against unauthorized access, loss, destruction or alteration.

 

11.2 Retention and Disposal

 

We will retain personal data as follows:-

(a) We will destroy or anonymize your personal data as soon as it is reasonable to assume that:

(i)  the Purpose for which that personal data was collected is no longer being served by the retention of such personal data; and

(ii) retention is no longer necessary for any legal or business purposes;

 

(b) If you cease using the Platform, or your permission to use the Platform and/or the Services is terminated or suspended, we may continue storing, using and/or disclosing your personal data in accordance with this Privacy Policy:

(i) as necessary for our legitimate business interests, such as prevention of money laundering, fraud detection and prevention, and enhancing safety. For example, if we suspend an Account for fraud or safety reasons, we may retain information from that Account to prevent that User from opening a new Account in the future; and

(ii) to the extent necessary to comply with our legal obligations. For example, GoWaus may keep information for tax, legal reporting and auditing obligations;

 

(c) Information you have shared with others such as reviews will continue to be publicly visible on the Platform even after your Account is cancelled. However, attribution of such information to you will be removed. Some copies of your information (e.g., log records) will remain in our database, but are disassociated from personal identifiers; and

 

(d) Residual copies of your personal data may not be removed from our backup systems for a limited period of time as we take measures to protect data from accidental or malicious loss and destruction.

 

11.3 Disposal without Notice

Subject to applicable law, we may securely dispose of your personal data without prior notice to you.

GoWaus reserves the right to change, modify, add to and delete this Privacy Policy at any time. If we modify this Policy, we will post the revised Policy on the Platform and update the “Last Updated” date at the top of this Policy. Please check this Policy every time you use the Platform to ensure that you have reviewed the current version. We will also provide you with notice of any material changes at least thirty (30) days before the date they become effective. If you disagree with the revised Policy, you may terminate this agreement immediately as provided in our Terms. If you do not terminate your agreement before the date the revised Policy become effective, your continued access to or use of the Platform will constitute acceptance of the revised Policy.

If you have any requests, questions, concerns, complaints or grievances with respect to this Privacy Policy or our privacy practices, please do not hesitate to contact us:

World And Us Tourism Sdn Bhd

Suite 7.02, Menara Summit, Persiaran Kewajipan,

USJ 1, 47600, Subang Jaya, Selangor, Malaysia

 

Tel: 012 970 6051

Email: [email protected]