PRIVACY & COOKIE POLICY


Ralik Enterprise (“Ralik”, “we”, “us” or “our”) respects the privacy of our Customers, website visitors, business contacts and other individuals whose personal data we process.

This Privacy & Cookie Policy explains how we collect, use, store, disclose, protect and otherwise process personal data in connection with:

  • www.ralik.my;

  • enquiries and quotations;

  • purchases and payments;

  • delivery and collection;

  • warranty and aftersales support;

  • customer communications;

  • marketing;

  • website analytics;

  • fraud prevention;

  • accounting and business administration; and

  • other commercial dealings with Ralik.

This Policy is intended to be read together with the Ralik Terms of Service and other applicable policies.

Ralik processes personal data in accordance with applicable Malaysian personal data protection law, including the Personal Data Protection Act 2010 [Act 709] and applicable amendments, regulations, standards, guidelines and requirements.


PART A — WHO THIS POLICY APPLIES TO

1. Individuals Covered

This Policy may apply to personal data relating to:

  • Customers;

  • prospective Customers;

  • individual purchasers;

  • directors, employees or representatives of Business Customers;

  • authorised collectors;

  • recipients of goods;

  • warranty claimants;

  • website visitors;

  • newsletter subscribers;

  • suppliers and business contacts; and

  • other individuals who communicate or transact with Ralik.

Personal data generally relates to information about an identifiable living individual.


2. Business Customers

Where Ralik deals with a company, enterprise or other organisation, certain business information may not itself constitute personal data.

However, information relating to identifiable individuals within that organisation may constitute personal data, including information about:

  • directors;

  • employees;

  • authorised representatives;

  • purchasers;

  • accounts personnel; or

  • delivery recipients.

This Policy applies to such personal data where applicable.


PART B — PERSONAL DATA WE MAY COLLECT

3. Identity and Contact Information

Depending on the transaction, Ralik may collect:

  • name;

  • company name;

  • telephone number;

  • WhatsApp number;

  • email address;

  • billing address;

  • shipping address;

  • branch/location information;

  • job title or business role;

  • authorised representative information; and

  • other contact information.


4. Order and Transaction Information

We may collect information relating to:

  • quotation;

  • order;

  • invoice;

  • product purchased;

  • PC specification;

  • serial number;

  • warranty period;

  • delivery;

  • collection;

  • return;

  • refund;

  • service history;

  • trade-in;

  • repair;

  • replacement; and

  • Customer account records.


5. Payment and Financial Information

For payment verification, accounting, refund and fraud-prevention purposes, Ralik may process information including:

  • payment amount;

  • payment date;

  • payment method;

  • transaction reference;

  • payer name;

  • bank/payment-provider information;

  • payment receipt;

  • limited bank account information;

  • refund account information; and

  • payment reconciliation records.

Ralik does not require Customers to provide unnecessary confidential banking credentials such as online-banking passwords or PIN numbers.

Customers should redact unnecessary sensitive information before supplying bank documents where appropriate.


6. Warranty and Technical Support Information

When providing technical support, Ralik may process:

  • PC specifications;

  • component serial numbers;

  • hardware diagnostic information;

  • operating-system information;

  • screenshots;

  • error messages;

  • photographs;

  • video;

  • repair history;

  • warranty records;

  • support communications; and

  • information reasonably required to diagnose or resolve a technical issue.

Customers should avoid providing unrelated personal files, passwords or confidential information unless reasonably necessary for the requested service.


7. Website and Device Information

When you use www.ralik.my, certain technical information may be collected automatically, including:

  • IP address;

  • browser type;

  • device type;

  • operating system;

  • approximate location derived from technical information;

  • date and time of access;

  • pages viewed;

  • referring page or website;

  • interaction with the Site;

  • session information;

  • cookie identifiers; and

  • similar technical data.


8. Communications

Ralik may retain communications including:

  • WhatsApp messages;

  • email;

  • website enquiries;

  • customer-support messages;

  • quotation discussions;

  • complaints;

  • payment correspondence;

  • warranty discussions; and

  • other commercial communications.

Such records may be retained where reasonably necessary to manage the transaction, service request, dispute or business relationship.


9. Images, Video and Evidence

For shipping, return, warranty, fraud-prevention and dispute-resolution purposes, Ralik may collect photographs or video showing:

  • product condition;

  • packaging;

  • courier labels;

  • serial numbers;

  • damaged goods;

  • returned products; or

  • other relevant evidence.

Ralik may also create receiving/unboxing records when products are returned for inspection.


PART C — HOW WE COLLECT PERSONAL DATA

10. Sources

Ralik may collect personal data:

Directly from You

For example when you:

  • make an enquiry;

  • request a quotation;

  • place an Order;

  • make payment;

  • create an account;

  • subscribe to marketing;

  • contact support;

  • submit a warranty claim;

  • request a refund; or

  • communicate with Ralik.

From Your Organisation

Where you are acting on behalf of a Business Customer.

From Another Authorised Person

For example where:

  • another person purchases a product for you;

  • your employer places an Order;

  • an authorised representative communicates with Ralik; or

  • a payer makes payment on behalf of a Customer.

Automatically Through the Website

Through cookies, logs and similar technologies.

From Service Providers

Where reasonably necessary, such as:

  • payment providers;

  • couriers;

  • manufacturers;

  • distributors;

  • insurers; or

  • other parties involved in fulfilling or supporting a transaction.


PART D — PURPOSES FOR PROCESSING

11. Why Ralik Processes Personal Data

Ralik may process personal data for purposes including:

  • responding to enquiries;

  • preparing quotations;

  • accepting and managing Orders;

  • verifying payments;

  • issuing invoices;

  • processing refunds;

  • investigating duplicate or incorrect payments;

  • arranging delivery;

  • verifying collection authority;

  • providing technical support;

  • administering warranty;

  • managing RMA/repair/replacement;

  • managing trade-ins;

  • communicating service updates;

  • keeping accounting records;

  • complying with tax and e-Invoice obligations;

  • fraud prevention;

  • security;

  • dispute resolution;

  • debt and payment administration;

  • internal audit;

  • improving products and services;

  • website analytics;

  • marketing where permitted; and

  • complying with applicable legal obligations.

Ralik will not intentionally process personal data for an unrelated purpose that is incompatible with the reason it was collected without an appropriate legal basis, notice or consent where required.


PART E — CONSENT, NOTICE AND CHOICE

12. Consent

Where consent is required under applicable law, Ralik may request consent before or at the time personal data is collected or used for the relevant purpose.

Consent may be obtained through appropriate means including:

  • website forms;

  • checkbox;

  • written confirmation;

  • electronic communication; or

  • another appropriate method.

Certain processing may be necessary to complete or administer a transaction requested by the Customer or to comply with legal obligations.


13. Withdrawal of Consent

Where processing is based on consent and applicable law permits withdrawal, you may contact Ralik to withdraw that consent.

Withdrawal does not necessarily:

  • invalidate processing lawfully carried out before withdrawal;

  • require deletion of records which Ralik must retain by law; or

  • prevent processing which remains legally permitted or required for another applicable purpose.

Withdrawal may affect Ralik's ability to provide a service where the relevant personal data is reasonably necessary for that service.


PART F — MARKETING COMMUNICATIONS

14. Marketing

Where permitted, Ralik may send communications relating to:

  • products;

  • promotions;

  • upgrades;

  • trade-in programmes;

  • service plans;

  • newsletters;

  • events;

  • offers; or

  • other Ralik services.

Marketing may be sent through channels such as:

  • email;

  • WhatsApp;

  • SMS; or

  • other permitted communication methods.


15. Marketing Opt-Out

You may request to stop receiving marketing communications at any time through:

  • an unsubscribe facility where provided; or

  • contacting Ralik.

After opting out, Ralik may still send necessary non-marketing communications relating to matters such as:

  • Orders;

  • invoices;

  • payments;

  • refunds;

  • warranty;

  • support;

  • delivery;

  • security; or

  • existing contractual matters.


PART G — COOKIES & SIMILAR TECHNOLOGIES

16. What Cookies Are

Cookies are small data files which may be stored on a browser or device when a person visits a website.

Ralik may also use similar technologies such as:

  • pixels;

  • tags;

  • local storage;

  • web beacons; or

  • similar website technologies.


17. Types of Cookies We May Use

Depending on the technology enabled on www.ralik.my, cookies may include:

A. Strictly Necessary Cookies

Used for essential website functions such as:

  • security;

  • navigation;

  • shopping-cart functions;

  • session management; or

  • checkout.

Disabling these may prevent parts of the Site from operating correctly.

B. Preference / Functional Cookies

Used to remember choices or settings which improve the user experience.

C. Analytics Cookies

Used to understand:

  • traffic;

  • page usage;

  • Customer journeys;

  • website performance; and

  • general interaction patterns.

D. Advertising / Retargeting Cookies

Where enabled, these may help Ralik:

  • measure advertising effectiveness;

  • understand campaign performance;

  • display more relevant advertising; or

  • conduct retargeting.


18. Third-Party Analytics and Advertising

Depending on the services enabled from time to time, Ralik may use third-party tools such as:

  • Google Analytics;

  • Google advertising services;

  • Meta/Facebook advertising tools; or

  • Microsoft/Bing advertising tools.

These third parties may process data according to their own privacy policies and applicable contractual arrangements.

Ralik will review the third-party services it uses from time to time and should not be taken to use every service listed above at all times.


19. Cookie Choices

Where required by applicable law or implemented by Ralik, visitors may be given options to manage non-essential cookie preferences.

Users may also manage cookies through their browser/device settings.

Blocking cookies may affect certain website functions.

Where available, Customer preferences may be managed through:



20. Do Not Track Signals

Some browsers offer a “Do Not Track” or similar signal.

Because there is no single universally applied technical standard for such browser signals, the Site may not automatically respond to every Do Not Track signal.

Where Ralik provides a specific cookie-consent or preference mechanism, Customers should use that mechanism to manage applicable cookie choices.


PART H — DISCLOSURE OF PERSONAL DATA

21. Who Ralik May Share Data With

Ralik does not sell Customers' personal data as a commercial data list.

Where reasonably necessary, Ralik may disclose personal data to parties such as:

  • courier/logistics providers;

  • payment processors;

  • banks;

  • accountants;

  • auditors;

  • IT/hosting providers;

  • website service providers;

  • analytics providers;

  • marketing platforms;

  • manufacturers;

  • distributors;

  • warranty/RMA providers;

  • insurers;

  • professional advisers;

  • law firms;

  • regulators;

  • government agencies;

  • courts; or

  • law-enforcement authorities.

Disclosure will be limited to what is reasonably required for the applicable purpose and subject to applicable law.


22. Manufacturers, Distributors and Warranty Providers

Where necessary to process a warranty or RMA claim, Ralik may provide relevant information such as:

  • product serial number;

  • invoice information;

  • Customer contact information where necessary;

  • defect description;

  • photographs/video; and

  • technical information

to the relevant manufacturer, distributor or service provider.


23. Couriers and Logistics Providers

For delivery or reverse pickup, Ralik may provide information such as:

  • Customer/recipient name;

  • address;

  • telephone number;

  • shipment information; and

  • declared shipment value where applicable

to the relevant courier, logistics provider or insurer.


PART I — DATA PROCESSORS & SERVICE PROVIDERS

24. Service Providers

Ralik may engage service providers to process personal data on Ralik's behalf.

Where applicable, Ralik will take reasonable steps to use service providers that provide appropriate security and privacy safeguards.

Ralik may require appropriate contractual, confidentiality or data-protection obligations from service providers depending on the nature of the processing and applicable law.


PART J — CROSS-BORDER DATA TRANSFERS

25. Data Processed Outside Malaysia

Certain service providers, cloud platforms, manufacturers, analytics providers or technology providers used by Ralik may process or store data outside Malaysia.

Where personal data is transferred outside Malaysia, Ralik will take reasonable steps to ensure the transfer is permitted under applicable Malaysian law and subject to appropriate safeguards where required.

These may include consideration of:

  • applicable contractual protections;

  • security measures;

  • destination-country protections;

  • necessity of the transfer; and

  • other requirements under applicable Malaysian personal-data protection rules.


PART K — SECURITY

26. Security Measures

Ralik will take reasonable and practical steps to protect personal data against risks including:

  • loss;

  • misuse;

  • unauthorised access;

  • accidental disclosure;

  • alteration;

  • destruction; and

  • other unauthorised processing.

Measures may include, where appropriate:

  • access controls;

  • passwords/authentication;

  • restricted staff access;

  • secure systems;

  • software/security updates;

  • staff confidentiality;

  • backup controls;

  • secure disposal; and

  • appropriate controls for service providers.

No online or electronic system can be guaranteed to be completely secure.


27. Customer Security Responsibility

Customers should not send Ralik unnecessary confidential information such as:

  • passwords;

  • PIN numbers;

  • full payment-card credentials;

  • security codes; or

  • banking login information.

If Ralik receives information that is clearly unnecessary for the requested purpose, Ralik may take reasonable steps to remove, redact or securely dispose of it.


PART L — PERSONAL DATA BREACHES

28. Data Breach Management

Ralik will take reasonable steps to investigate suspected personal-data breaches involving data under its control.

Depending on the circumstances, Ralik may:

  • contain the incident;

  • investigate the cause;

  • assess affected data;

  • implement remediation;

  • preserve relevant records;

  • notify relevant service providers; and

  • take measures intended to reduce further risk.

Where a breach is required to be notified under Malaysian law, Ralik will make the applicable notification to the Personal Data Protection Commissioner and/or affected individuals within the legally prescribed timeframe.


PART M — DATA RETENTION

29. How Long We Retain Personal Data

Ralik will not intentionally retain personal data longer than reasonably necessary for the purposes for which it is processed.

Retention periods may differ depending on the information and purpose.

Records may need to be retained for purposes including:

  • accounting;

  • taxation;

  • e-Invoice;

  • warranty;

  • service history;

  • payment reconciliation;

  • fraud prevention;

  • dispute resolution;

  • legal proceedings;

  • regulatory obligations; or

  • legitimate business record keeping permitted by law.


30. Order Information

Order and transaction information will not automatically be deleted merely because a Customer requests deletion where Ralik remains legally or reasonably required to retain the information.

For example, Ralik may need to retain:

  • invoices;

  • payment records;

  • warranty records;

  • refund records;

  • tax records;

  • accounting documents; or

  • dispute evidence

for the applicable retention period.

Once personal data is no longer reasonably required and no lawful retention requirement remains, Ralik will take appropriate steps to delete, destroy, anonymise or otherwise cease unnecessary retention.


PART N — DATA ACCURACY

31. Keeping Data Accurate

Ralik will take reasonable steps to ensure personal data used for the relevant purpose is:

  • accurate;

  • complete;

  • not misleading; and

  • reasonably up to date.

Customers should inform Ralik if important information changes, particularly:

  • delivery address;

  • telephone number;

  • email;

  • company details; or

  • refund/payment instructions.


PART O — YOUR RIGHTS

32. Access

Subject to applicable law and permitted exceptions, you may request access to personal data Ralik holds about you.

Ralik may require reasonable verification of identity before responding.


33. Correction

You may request correction of personal data which is:

  • inaccurate;

  • incomplete;

  • misleading; or

  • out of date.


34. Withdrawal / Objection to Certain Processing

Where applicable, you may request:

  • withdrawal of consent;

  • cessation of direct marketing; or

  • restriction/cessation of particular processing where a right exists under applicable Malaysian law.

Some processing may need to continue where it is legally permitted or required.


35. Data Portability

Where a right to data portability applies under Malaysian law, an eligible individual may request applicable personal data to be transmitted in accordance with the requirements and limitations prescribed by law.

Ralik may require identity verification and sufficient information to process the request.


36. Deletion Requests

You may ask Ralik about deletion of personal data.

However, a request to delete data does not create an absolute right to erase every record immediately.

Ralik may retain information where reasonably required for:

  • an existing transaction;

  • warranty;

  • tax/accounting;

  • payment reconciliation;

  • fraud prevention;

  • legal obligations;

  • establishment, exercise or defence of legal rights; or

  • another lawful retention purpose.

Where there is no continuing reason or legal basis to retain the information, Ralik will take appropriate steps consistent with applicable law.


37. Identity Verification for Privacy Requests

Before granting access, correction, portability or another privacy request, Ralik may require reasonable proof of identity or authority.

For representatives acting on behalf of another individual, Ralik may request written authorisation.

This is intended to prevent unauthorised disclosure of personal data.


PART P — CHILDREN / MINORS

38. Minors

Ralik's products and commercial services are generally intended to be purchased by persons capable of entering into the relevant transaction or by an authorised parent, guardian or organisation.

Ralik does not intentionally seek unnecessary personal data from children.

Where Ralik becomes aware that additional consent or parental/guardian involvement is legally required, Ralik will take reasonable steps to address the matter.


PART Q — EXTERNAL WEBSITES

39. Third-Party Links

www.ralik.my may contain links to third-party websites or services.

Ralik does not control the privacy practices of independent third parties.

Customers should review the relevant third-party privacy policy before providing personal information to those services.


PART R — DATA PROTECTION GOVERNANCE

40. Data Controller

For personal data processed in connection with Ralik's commercial activities, Ralik Enterprise acts as the data controller where Ralik determines the purposes and manner of processing.


41. Data Protection Officer

Where Ralik becomes legally required to appoint a Data Protection Officer (“DPO”), Ralik will appoint and register the DPO in accordance with applicable Malaysian requirements.

Where no mandatory DPO appointment applies, privacy enquiries may continue to be handled through Ralik's designated contact channel.


PART S — COMPLAINTS

42. Privacy Complaints

If you believe your personal data has been handled improperly, please contact Ralik first so that the matter can be reviewed.

Please provide sufficient information to identify:

  • yourself;

  • the relevant transaction or communication;

  • the personal data involved; and

  • the concern or requested correction.

Nothing in this Policy prevents an individual from exercising any right to lodge a complaint with the relevant Malaysian authority where available.


PART T — CHANGES TO THIS POLICY

43. Policy Updates

Ralik may update this Privacy & Cookie Policy from time to time to reflect changes in:

  • legal requirements;

  • regulatory guidance;

  • technology;

  • service providers;

  • website functionality;

  • operational practices; or

  • business activities.

The current version and effective date will be published on www.ralik.my.

Where a material change requires additional notice or consent under applicable law, Ralik will take appropriate steps.


PART U — CONTACT

44. Contact Ralik

For privacy, access, correction, withdrawal, marketing opt-out or other personal-data enquiries:

Ralik Enterprise
PT820 Tingkat 2, Jalan Long Yunus
Pengkalan Chepa
15400 Kota Bharu
Kelantan, Malaysia

Telephone / WhatsApp: 011-2575 5989
Email: ralikdotmy@gmail.com
Website: www.ralik.my

If Ralik appoints a dedicated Data Protection Officer or privacy contact in the future, the applicable contact details may be published here.