Ombak Festival

Privacy Statement

Updated as at January 2024

1.Introduction

This Privacy Statement sets out how Desaru Development Holdings One Sdn Bhd and/or its subsidiaries (collectively referred to as “DH1”, “us”, “our” or “we”) collect, use and share information about you when you interact on our website (www.desarucoast.com) and mobile application (collectively “Sites”) or otherwise in your dealings with us. 

This Privacy Statement describes the information we collect, how it is used, and when it may be shared with others, how we are committed to protect its confidentiality and security, and also your right to access and update your personal information.

2.Consent

Your consent to the terms of this Privacy Statement will be obtained when you make booking or purchase products and services offered by us, registering for marketing communications or otherwise corresponding with us via the Sites, or if required by applicable law. Otherwise, when you voluntarily disclose personal data to us or your continued use of the Sites will constitute your deemed consent to the terms of this Privacy Statement.

You consent to our use of your personal information shall be processed in accordance with this Privacy Statement unless and until you inform us to the contrary. Except as disclosed in this Privacy Statement or as required or permitted by applicable law, we will not disclose or share your personal information to third parties without your consent.

By providing us personal information of any third party individual(s), you represent and warrant that the individual(s) has been informed of and consents to the terms and conditions of this Privacy Statement, as may be amended from time to time. Personal information of children below 18 years of age can only be provided if you are the parent or legal guardian.

3.Defining Personal Information 

Personal information refers to any information which relates directly or indirectly to you. This includes any information that can be used to distinguish, identify or contact you and it may include sensitive personal information which relates to your health, political opinions, religious beliefs and others sensitive information which is necessary for the purposes as identified in this Privacy Statement.

4.Personal Information We Collect

We collect and maintain personal information that you have provided in our Sites or provided to us in any other way. You can choose not to provide certain personal information, but you may not be able to enjoy all the features of our Sites, or the products and services offered by us. Here are the types of personal information that we collect:

  1. Personally identifiable information such as name, date of birth, identification supporting documents (including NRIC or passport number), gender, nationality and race, preferred language; 
  2. Contact information such as address, phone numbers, fax number and email address;
  3. Payment information such as credit or debit card information and bank account details;
  4. Transaction information such as information relating to your booking or purchase of our products or services, recording of calls placed by you to our help desk in connection with our products and services; and
  5. Technical information such as ID and location of the electronic device you use when accessing our Sites, IP address, search preferences and geographical data.

5.When and how we collect your Personal Information?

We may collect personal information directly from you or from your authorised representatives (i.e. persons whom you have authorised, persons who have been validly identified as being you or your authorised representative), from third parties (e.g. agents or service providers) or the personal information of your family members where you disclose the same on their behalf. 

Information may be collected when you:

  1. Use any of our products or services, or access our Sites;
  2. Communicate with us such as by telephone (e.g. call may be recorded for quality and reference purpose which includes the usage of the recordings for internal training, fraud detections and security purposes), email, in writing or through our customer services page, official business messaging and social media platform; 
  3. Register, participate or subscribe to any of our marketing and promotional newsletter, surveys, marketing promotions and campaigns such as competition, special event, loyalty programmes that offered by us; or
  4. Commence a business relationship with us (e.g. as a service provider/business partner).

Other than personal information obtained from you directly (as detailed above), we may also obtain your personal information from third party such as our affiliated entities, business partners or other third party providers (e.g. when you make reservation with one of our business partners, we may receive certain personal information such as your name, contact and reservation details in order for us to process your reservation with us) or other lawful sources as permitted by the laws. For example, if you access or sign in to our Site through third party social media or messaging platforms, certain personal information such as your username, email account and other information made available in such platforms may be shared with us. In general, your ability to provide such information is through the relevant third parties themselves and you can change those settings in your account settings of the relevant third parties.

6.How we use your Personal Information

We may collect and use personal information received from you or from third parties identified in this Privacy Statement, for the following purposes: -

  1. Necessary for the fulfilment and completion of your transaction with us in relation to our products and services such as processing your reservation, identity verification, contacting you about the products or services requested, billing your credit card for advance reservations or deposits, customer support, responding to your inquiries, complaints and other communications;
  2. Sending you marketing communications such as updates, news, events and promotions about our products and services if you choose to receive such communications;
  3. Business development purposes such as business analytics to produce data, reports and statistics which shall be anonymized or aggregated in a manner that does not identify you as an individual, quality assurance, customer surveys to improve our existing and future products and services;
  4. Compliance with the applicable legal and regulatory requirements;
  5. Financial purpose such as payment card verification, assessment of credit worthiness, accounting or audit; and
  6. Maintenance and improvement of the Sites such as tailor the user experience by customising the content in our Sites to display products and services that may be relevant to you, internal training.

7.Sharing of your Personal Information

In connection with your use of our Sites, products and services, we may share your personal information as follows:

  1. Fulfilment of transaction with third party suppliers of products and services such as tour operator, transportation and accommodation providers, insurance and activity providers, where you have requested or subscribed for their products or services;
  2. Payment network operators and credit card verification providers (e.g. VISA, MasterCard);
  3. Business partners with whom we may jointly offer certain products and services, or whose products or services may be offered on our Sites. If you choose to access these optional products or services, we will on occasion share your personal information with those partners. Examples of business partners would be (i) a third-party loyalty program that you will earn points for, through a booking, or (ii) a third-party tour or activity provider that we share information with in connection with tours/activities you book through our Sites;
  4. Trusted third party service providers who provide data processing services for us. Our third party service providers will only process information as needed to perform their functions, based on our instructions and in compliance with any other appropriate security and confidentiality measures. They are not permitted to share or use the information for any other purpose;
  5. Our affiliated group of companies who have access to this information with our permission and who need to know or have access to this information in order for us to: (i) provide you with products and services on a consistent basis; (ii) internal audit or investigations; or (iii) as otherwise required or permitted by applicable law;
  6. Where required or permitted by law, we may disclose your personal information if we have a good faith belief that the disclosure is reasonably necessary for us to: (i) comply with any applicable law, regulation, legal process or enforceable governmental request or legal demands; (ii) protect our legitimate interests such as to enforce or apply the terms and conditions applicable to our products and services, or to detect, investigate, prevent or otherwise address any fraud, illegality, security or other wrongdoings; or (iii) protect against harm to the rights, property or safety of DH1, our users, or others; and
  7. Corporate restructuring or exercise such as any sale, transfer or assignment of our business, assets or liabilities to another party, or transition of our products and services to another service provider. We will seek your consent if required by applicable law.

8.Marketing Communications

You can choose how you receive marketing communications from us. All marketing communications we send to you will provide you with a way to withdraw your consent to future marketing. If you no longer wish to receive marketing, you can opt out of receiving marketing communications from us at any time by using the "Unsubscribe" link or opt out mechanism in our marketing communication or channels. We will honor your request within a reasonable time upon receiving it or sooner if required by applicable law. Please note that if you unsubscribe from marketing communications you will still receive operational and service messages from us regarding your booking and responses to your enquiries made to us, and that we may hold your details so we do not send you marketing communications in the future.

9.Protecting Your Personal Information

We maintain reasonable physical and electronic security measures to protect your personal information against accidental or unlawful disclosure, access, alteration, loss or destruction. We will secure the storage of your personal information in compliance with the minimum security measures prescribed under the Malaysian Personal Data Protection Act 2010, its regulation and standards, in the following ways:

  1. register those who have access to the personal information;
  2. control and limit access based on necessity;
  3. maintain proper record of access, sharing and transfer of personal information;
  4. ensure our employees involved in the collection or processing of personal information to protect confidentiality of the same;
  5. establish physical security procedures;
  6. bind third parties involved in processing of personal information; 
  7. do not use removable device and cloud computing service to transfer or store personal information unless with written consent from our top management; and
  8. conduct awareness programmes to all employees on responsibility to protect personal information.

10.How long We Keep Your Personal Information

Whenever we collect or process your personal information, we will only keep it for as long as necessary to provide our Products and/or Services, to exercise our legal rights, to protect our or other’s interests, and to comply with all relevant legal or regulatory obligations. Where there is no sufficient justification to retain your personal information, such personal information will be deleted, disposed of, blocked and/or anonymised for example by aggregation with other data so that it can be used in a non-identifiable way for statistical analysis.

11.Your Rights

You may submit a request to withdraw your consent at any time by contacting us. However, if you choose not to provide certain personal information, or consent to its use and disclosure, this may limit the products and services that we can offer you and, on some occasions, restrict our ability to fulfil your transactions with us. 

Please note that, in certain circumstances, we may not be able to allow you access, modify or update certain personal information (e.g. if your personal information is connected with personal information of other persons, or for legal reasons), or required to retain some of your personal information after you have requested for deletion, to satisfy our legal or contractual obligations.

12.Online dealings with DH1’s Cookies

We collect information about your use of our Sites from cookies. Cookies are packets of information stored in your device which assist your website navigation by customizing site information tailored to your needs. Cookies in themselves do not identify the individual user, just the computer used. You are not obliged to accept cookies. If you are concerned, you can set your computer either to accept all cookies, to notify you when a cookie is issued, or not to receive cookies at any time. However, rejection of cookies may affect your use of our Sites as we will be unable to personalize aspects of your use of the Sites.

13.Links to Third Party Websites

We may provide links to other websites or platforms (including social messaging platforms such as WhatsApp, Facebook Messenger, etc) that are not owned by operated by us (“Third Party Sites”) in our Sites. If you access such Third Party Sites using the links provided, the operators of these Third Party Sites may collect your personal information.  To determine how they deal with your personal information, you should read their respective privacy statements as we are not responsible for other Third Party Sites or their privacy practices. We do not assume responsibility or liability of any nature whatsoever for the activities conducted or information contained in the Third Party Sites. 

14.Transfer of your Personal Information outside Malaysia

We may transfer and store your personal information outside Malaysia in accordance with the terms and standards as set out in this Privacy Statement. Where your personal information is transferred to other third parties as described above outside Malaysia, we shall take reasonable steps to ensure that such personal information is transferred with adequate security and processed in accordance with the applicable law to maintain your privacy.

15.Updates to our Privacy Statement 

We may revise and update this Privacy Statement from time to time and without notice to reflect changes in the law, new or unanticipated uses not previously disclosed in our Privacy Statement, changes in our privacy practices, or advances in technology. Any revision or changes would be posted in this Privacy Statement and therefore you should review our Privacy Statement periodically so that you are aware of our most current privacy practices. 

16.Contact Us

If you have any enquiries about this Privacy Statement, our privacy practices or wish to exercise any of your rights as described above, please contact us at the address below:

Desaru Development Holdings One Sdn Bhd
Laman Desaru Coast, Jalan Desaru, Desaru Coast, 
81930 Bandar Penawar, Johor Darul Ta’zim, Malaysia