We take your data seriously.
Last updated on 27 September 2019
“Personal data” is data that can be used to identify a natural person, but does not include information that is anonymous, aggregated, or is no longer identifiable to a specific individual.
Please note that information we process may be transferred to, stored, and/or processed in Malaysia or any other jurisdictions in which we or our affiliates or service providers maintain operations. By using and providing information to us through HeyAlfred, you agree and consent to the transfer, storage, and processing of your information to any such jurisdictions.
Please further note that HeyAlfred may provide links to other third party websites, applications, products or services that do not present or otherwise link to this Privacy Statement. When visiting such third party web sites, applications, products or services, you should read their respective privacy policies which will apply separately.
HeyAlfred collects certain types of personal data, including but not limited to the following:
(a) Registration information
When you register for an account to use HeyAlfred, you will be asked for basic registration information, such as an email address and password.
(b) Identification information
You may also be asked to provide identification information to confirm your identity, including your name, username, address, and phone number.
(c) Payment account information: If you subscribe to use certain premium functions on HeyAlfred, you will be required to provide your account details for payment (for example, credit card number, expiration date and security code).
(d) Third party credentials: In order for us to work out a weekly budget for you, you will be required to sync one or more bank accounts with HeyAlfred, and for this purpose, you may be required to provide your credentials to access your bank statements maintained online by your bank(s) (“Third Party Sites”).
(e) Information from Third Party Sites: With your consent, we may collect, on your behalf, your account and other personal information from Third Party Sites that you sync with HeyAlfred in read-only mode.
(f) Mobile Device ID: As part of the verification of your registration information, HeyAlfred will detect and collect the unique device identifier assigned to your mobile device by the makers of the device or its operating system (“Device ID”).
(g) Contests and surveys: From time to time, you may be offered an opportunity to participate in a contest, survey, or other promotion. We may collect or you may submit information in connection with one of these promotions.
(h) Other information: We may request or receive other personal information such as feedback, questions, comments, suggestions, or ideas to provide you with other benefits or to improve our services. In such instances, you will be given the opportunity to provide or decline that information.
We would stress that if you sync your online banking account with HeyAlfred, HeyAlfred will only collect information stored on such Third Party Site (account statement showing your transaction details and other personal financial information) with your consent and in read-only mode; that is, HeyAlfred cannot and will not edit any such information that it is granted access to.
We use your personal data to:
(a) verify your identity or information you provide against third party databases or through other sources (whether done by us directly or by a third party service provider);
(b) access Third Party Sites on your behalf to retrieve your bank account information;
(c) aggregate your bank account information to work out your weekly and monthly budgets and provide you with other aggregated financial information;
(d) respond to your inquiries about HeyAlfred and/or our services;
(e) assess for HeyAlfred’s compatibility issues with your mobile device;
(f) analyse the use of HeyAlfred and improve on its design, architecture and functions;
(g) deliver to you notices or alerts and communications relevant to your use of HeyAlfred;
(h) offer you other products, programs or services that we believe may be of interest to you;
(i) perform troubleshooting and analysis of user behaviour;
(j) use your Device ID for security purposes (for example, monitor for suspicious activity and access from multiple mobile devices);
(k) detect and protect against errors, fraud, or other criminal activity;
(l) enforce our Terms of Service and as otherwise set forth in this Privacy Statement; and
(m) confirm your payment account (for paid subscription to premium functions) is valid and access funds from your accounts in connection with payment for functions that you subscribe to.
We may use your personal data to offer you products or services, including special offers, promotions, contests or entitlements that may be of interest to you or for which you may be eligible. Such marketing messages may be sent to you in various modes including but not limited to electronic mail, direct mailers, and mobile messaging services. In doing so, we will comply with the Personal Data Protection Act of Malaysia 2010 (“PDPA”) and other applicable data protection and privacy laws, such as the European Union General Data Protection Regulation (“GDPR”).
You may at any time request that we stop contacting you for marketing purposes via selected or all modes.
To find out more on how you can change the way we use your personal data for marketing purposes, please contact us.
In any event, please note that nothing in this section shall vary or supersede the terms and conditions that govern our relationship with you.
We may from time to time and in compliance with all applicable laws on data privacy, disclose your personal data to any of our personnel or to third parties, whether located in Malaysia or elsewhere, in order to carry out the purposes set out above. Please be assured that when we disclose your personal data to such parties, we require them to ensure that any personal data disclosed to them are kept confidential and secure.
For more information about the third parties with whom we share your personal data, you may, where appropriate, wish to refer to the agreement(s) and/or terms and conditions that govern our relationship with you or our customer. You may also contact us for more information.
We wish to emphasise that we do not sell personal data to any third parties and we shall remain fully compliant of any duty or obligation of confidentiality imposed on us under the applicable agreement(s) and/or terms and conditions that govern our relationship with you or our customer or any applicable law.
We may transfer, store, process and/or deal with your personal data outside Malaysia. In doing so, we will comply with the PDPA and other applicable data protection and privacy laws, such as the GDPR.
Any personal data you provide to HeyAlfred is kept on secure servers. HeyAlfred uses reasonable administrative, technical, personnel, and physical measures (a) to safeguard personal users’ information against loss, theft, unauthorized use, disclosure, or modification; and (b) to ensure the integrity of the users’ information. We take the security of your information seriously.
Your personal data is retained as long as the purpose for which it was collected remains and until it is no longer necessary for any other legal or business purposes.
You may request access or make corrections to your personal data held by us. We may charge a fee for processing your request for access. Such a fee depends on the nature and complexity of your access request. Information on the processing fee will be made available to you.
The GDPR also provides relevant individuals with additional rights including the right to obtain information on how we process your personal data, receive certain information provided in an electronic format and/or request that these be transmitted to a third party, request for your information to be erased, object or restrict the use or processing of your information in some circumstances. These will be subject to ongoing obligations imposed on us pursuant to any applicable law or regulation, and/or our legitimate reason or entitlement to continue processing your information, and/or to refuse that request.
Please contact us for details on how you may request access or correction to, or exercise your rights with respect to the processing of your personal data.
We may amend this policy from time to time to ensure that this policy is consistent with any developments to the way we use your personal data or any changes to the laws and regulations applicable to us. We will make available the updated policy on our web site (www.HeyAlfred.co/privacy-policy). All communications, transactions and dealings with us shall be subject to the latest version of this policy in force at the time.
To contact us on any aspect of this policy or your personal data or to provide any feedback that you may have, please get in touch with our data protection officer via email at holla@HeyAlfred.co.