CEOsCOMMUNITY HUBTOGETHER WE GROW
Back to home
PDPA notice

CEOS Privacy & Cookie Notice

This notice explains how CEOS processes personal data across its websites, Community Hub, Top-Up, WhatsApp, messaging, community, referral and support services.

1. Who we are

CEOS Enterprise provides community, management, support, messaging and Top-Up services. The data controller for the processing described in this notice is HLCEOS HOLDINGS SDN. BHD. (Company No. 1694865-X) (“CEOS”, “we”, “us” or “our”).

Contact: admin@ceosfamilysugo.com

2. Scope

This notice applies when you use or interact with CEOS websites, the CEOS Community Hub, CEOS Top-Up, CEOS WhatsApp and messaging services, community applications, referrals, support channels or other services that link to this notice (the “Services”).

It also explains how CEOS processes information received through Meta’s WhatsApp Business Platform, including webhook events for messages and message-status updates.

Third-party platforms have their own privacy notices. Meta’s and WhatsApp’s handling of information before it reaches CEOS, and their independent use of information, are governed by their policies.

3. Personal data we may process

Contact and account data

  • name, telephone number, email address and language preference;
  • CEOS account, role, Agency, referral and membership information;
  • SUGO, TOKI or other authorised platform IDs and display names;
  • profile images or other identity information you are authorised to provide; and
  • consent, opt-in, opt-out and communication preferences.

WhatsApp and Meta data

  • WhatsApp telephone number and profile name;
  • WhatsApp Business Account and Phone Number identifiers relevant to routing;
  • message identifiers, conversation identifiers and webhook event identifiers;
  • message text, replies, support requests and other content you send;
  • media and attachments you choose to send, including receipt images;
  • message timestamps, delivery, read, failed and other status events;
  • referral parameters or conversation-entry information supplied by Meta; and
  • technical information necessary to authenticate, deduplicate, secure and audit webhook processing.

CEOS does not ask you to provide your WhatsApp or Meta password, access token or verification code.

Order, payment and fulfilment data

  • order numbers, products, quantities, currency and amounts;
  • recipient IDs and customer confirmations;
  • payment method, bank or provider name, payment reference and timestamps;
  • receipt images and extracted receipt information;
  • duplicate, mismatch, fraud and risk-review indicators;
  • approval, rejection, refund, delivery, fulfilment and coin-release status; and
  • complaints, appeals and reconciliation records.

We do not ask for banking passwords, PINs, TACs, OTPs or full payment-card numbers. Do not send them.

Technical, security and audit data

  • IP address, browser or device characteristics and session identifiers;
  • authentication, CSRF, role and permission events;
  • timestamps, request identifiers, error records and security logs;
  • malware-scan, rate-limit, duplicate-detection and fraud-prevention results; and
  • staff actions, approvals and audit history.

4. How we obtain data

We may obtain data:

  • directly from you;
  • from a person you authorise, such as an Agent or Agency representative;
  • through CEOS websites and systems;
  • from Meta and the WhatsApp Business Platform when you message an approved CEOS number;
  • from payment or service providers where needed to verify a transaction;
  • from approved Agency or Host records; and
  • from security and operational systems that protect the Services.

If you provide another person’s data, you must have authority to do so and should inform them about this notice where appropriate.

5. Why we process data

CEOS may process personal data to:

  • provide customer service and respond to messages;
  • route conversations and maintain continuity between support interactions;
  • create, verify, track and fulfil authorised orders;
  • verify receipts and hold uncertain evidence for human review;
  • detect duplicate messages, receipts, orders and payment attempts;
  • prevent fraud, abuse, unauthorised access and duplicate fulfilment;
  • manage accounts, roles, permissions, Agencies, referrals and onboarding;
  • provide requested community, Host and Agency services;
  • record consent and honour communication preferences;
  • maintain accurate accounting, audit, complaint and reconciliation records;
  • secure, troubleshoot and improve the Services;
  • comply with law, lawful requests and dispute obligations; and
  • send marketing only where permitted and with the required consent.

We limit processing to purposes that are lawful and reasonably connected to the Service you requested, consented to or are authorised to use.

6. Automated processing, OCR and AI assistance

CEOS may use deterministic rules, approved Help Library content and automated routing for routine support and safety controls.

Receipt images may be processed using assisted optical character recognition, including Google Cloud Vision where enabled. OCR may extract visible receipt information, but it does not by itself approve a payment, complete an order or release coins.

Material decisions involving payment acceptance, fulfilment, account restrictions or coin release remain subject to CEOS controls and human review where required. You may request human review if an automated response appears incorrect or materially affects you.

Paid OpenAI and Luna access is not authorised or enabled, and CEOS does not send personal data to those services for the processing described in this version. Before any external generative-AI provider is enabled, CEOS must separately authorise the feature, confirm the approved data flow, minimise the information sent, implement contractual and technical safeguards, and update this notice where required.

7. Sharing and service providers

CEOS may share or make data available on a need-to-know basis to:

  • authorised CEOS personnel and authorised Agency personnel within their assigned roles;
  • Meta and WhatsApp for messaging, webhook delivery and platform administration;
  • Hostinger for hosting and related infrastructure services;
  • Google Cloud Vision for assisted receipt OCR where that function is enabled;
  • Telegram only when that communication channel is used;
  • banks and payment providers where necessary to verify, reconcile or investigate a payment;
  • professional advisers where necessary; and
  • regulators, courts, law-enforcement agencies and other lawful authorities where required or permitted by law.

Service providers are expected to process data only for authorised purposes and apply appropriate security controls. CEOS does not sell personal data.

8. International processing and transfers

Some service providers may process or store data outside Malaysia. Meta, WhatsApp, Hostinger, Google Cloud Vision and Telegram, when used, may operate infrastructure in multiple countries.

Where personal data is transferred outside Malaysia, CEOS will take steps required by applicable law, including assessing the destination and provider safeguards and using appropriate contractual, organisational or technical protections.

9. Security

CEOS uses proportionate safeguards that may include:

  • role-based access controls and least-privilege permissions;
  • multi-factor authentication for staff and protected systems;
  • protected secret storage and restricted configuration files;
  • encryption in transit and appropriate storage protections;
  • webhook authentication and request validation;
  • malware scanning and receipt safety checks;
  • duplicate detection and idempotency controls;
  • audit logging, monitoring, backups and recovery procedures; and
  • controlled release, migration and deployment processes.

No system is completely secure. Report suspected unauthorised access promptly without sending passwords, OTPs, tokens or other secrets.

10. Retention

CEOS keeps personal data only as long as reasonably necessary for the stated purposes, legal requirements, security, disputes and audit obligations. The confirmed operational periods are:

  • accounting, order and payment-reference records: 7 years;
  • receipt images and support records, including related WhatsApp conversation records: 2 years after closure;
  • unattached or abandoned uploads: 30 days;
  • security, session and technical logs: up to 24 months.

Data may be retained longer only where required by law or necessary for an active dispute or legal hold. Data no longer needed will be deleted, anonymised or securely isolated according to approved procedures.

11. Cookies and local storage

CEOS websites may use essential cookies or browser storage for authentication, security, CSRF protection, language, active role, order functions and installation preferences. Blocking essential storage may prevent secure login or use of protected features.

Any non-essential analytics, advertising or tracking technology must be disclosed and used with any consent required by law. This notice does not authorise new tracking.

12. Your choices and rights

Subject to the Malaysian Personal Data Protection Act 2010, its amendments and applicable exceptions, you may have the right to:

  • be informed whether and why CEOS processes your data;
  • request access to personal data held about you;
  • request correction of inaccurate or incomplete data;
  • withdraw consent where processing depends on consent;
  • object to or prevent certain processing that causes damage or distress;
  • opt out of direct marketing;
  • request human review of a significant automated decision where applicable; and
  • request deletion or restriction where CEOS no longer has a lawful reason to retain the data.

Withdrawing consent does not affect processing already lawfully completed and may prevent CEOS from providing a requested Service.

See the CEOS Data Deletion Instructions.

13. Children

The Services are not designed to collect personal data directly from children without appropriate parent or guardian involvement. If you believe a child has provided data without proper authority, contact CEOS so it can be reviewed.

14. Data incidents and complaints

CEOS will assess suspected personal-data incidents and make notifications required by applicable law. You may contact CEOS with a privacy complaint. You may also have the right to complain to Malaysia’s Personal Data Protection Commissioner.

15. Changes to this notice

CEOS may update this notice when Services, providers, data practices or laws change. The published version will show its effective date. Material changes will be communicated where reasonably required.

16. Contact

Privacy, access, correction, consent and deletion requests may be sent to:

CEOS Enterprise / HLCEOS HOLDINGS SDN. BHD.
Email: admin@ceosfamilysugo.com
Website: https://www.ceosfamilysugo.com/

Do not send passwords, banking PINs, TACs, OTPs, private keys or access tokens.