Privacy Policy

1) Introduction
This notice explains how R&R AUTHENTICS SDN. BHD. (Co. No: 202201046089 (1491786-V)), trading as Luxury Branded Outlet (LBO), processes your personal data in accordance with the Personal Data Protection Act 2010 (Act 709), as amended in 2024.

2) Categories of personal data

  • Identity & contact: name, phone, email, shipping/billing address.

  • Transaction: ordered items, amounts, payment status, transaction IDs (not full card numbers).

  • Communications & preferences: inquiries, support history, subscription choices.

  • Technical: IP address, device/browser info, cookies/identifiers (for site functionality and analytics).

  • Sensitive (only if provided): special delivery notes. We do not request health/biometric data.

3) Purposes & legal bases

  • Contract: order placement, payment processing, delivery/returns/warranty.

  • Legal obligation: tax and accounting records; responding to lawful requests.

  • Legitimate interests: site security, fraud prevention, service improvement, performance analytics.

  • Consent: marketing (promotions, offers, campaigns). You can withdraw consent anytime.

4) Marketing & your choices
Manage preferences anytime: click Unsubscribe in emails, reply β€œSTOP” on WhatsApp/SMS, or email rrashopper@gmail.com. We keep a record of consent and withdrawals.

5) Sharing & international transfers
We share data only with:

  • Couriers/fulfilment partners (shipping and tracking),

  • Payment gateways (we do not store full card numbers),

  • Hosting/email/CRM/analytics providers (e.g., platform, email and analytics tools),

  • Professional advisers/authorities where required by law.
    Where transfers occur outside Malaysia, we implement appropriate safeguards (data processing agreements, security controls, risk assessments).

6) Retention

  • Accounting/tax records: [e.g., 7 years].

  • Order & customer service records: [e.g., 3–7 years].

  • Marketing data: until you opt out or after [e.g., 24 months] of inactivity.
    Data is securely deleted or anonymized when no longer needed.

7) Security
We apply reasonable technical and organizational measures (encryption-in-transit where applicable, access controls, audit logs, staff training). No system is 100% secure, but we work to minimize risk.

8) Your rights
You may request access to your data, correction of inaccuracies, restriction/objection (where applicable), data portability (where technically feasible), and you may withdraw marketing consent at any time. We may need to verify your identity before actioning a request.

9) Children
If a customer is under 18, consent should be provided by a parent/guardian.

10) Cookies & similar technologies
We use essential cookies for site functionality and, where permitted, analytics/advertising cookies. Manage preferences via your browser or our [Cookie Settings] page.

11) Data breaches
We maintain an incident response process. If an incident risks your rights, we will notify the relevant authority and affected individuals in a timely manner as required by law.

12) How to contact us
Data Controller: R&R AUTHENTICS SDN. BHD. (Co. No: 202201046089 (1491786-V))
Registered Address: 130-1, Jalan BMU2, Bandar Baru Merlimau Utara, 77300 Merlimau, Melaka, Malaysia.
Data Protection Officer (DPO): Dr. Rohaizu β€” rrashopper@gmail.com, +60182889653
Permanent Privacy Notice: https://luxurybrandedoutlet.com/privacy-policy/

13) Changes to this notice
We may update this notice from time to time. The latest version will always be available at the link above.

Effective date: 14 Aug 2025 | Last updated: 14 Aug 2025