1) Introduction
This notice explains how R&R AUTHENTICS SDN. BHD. (Co. No: 202201046089 (1491786-V)), trading as Luxury Branded Outlet (LBO), processes your personal data in accordance with the Personal Data Protection Act 2010 (Act 709), as amended in 2024.
2) Categories of personal data
Identity & contact: name, phone, email, shipping/billing address.
Transaction: ordered items, amounts, payment status, transaction IDs (not full card numbers).
Communications & preferences: inquiries, support history, subscription choices.
Technical: IP address, device/browser info, cookies/identifiers (for site functionality and analytics).
Sensitive (only if provided): special delivery notes. We do not request health/biometric data.
3) Purposes & legal bases
Contract: order placement, payment processing, delivery/returns/warranty.
Legal obligation: tax and accounting records; responding to lawful requests.
Legitimate interests: site security, fraud prevention, service improvement, performance analytics.
Consent: marketing (promotions, offers, campaigns). You can withdraw consent anytime.
4) Marketing & your choices
Manage preferences anytime: click Unsubscribe in emails, reply βSTOPβ on WhatsApp/SMS, or email rrashopper@gmail.com. We keep a record of consent and withdrawals.
5) Sharing & international transfers
We share data only with:
Couriers/fulfilment partners (shipping and tracking),
Payment gateways (we do not store full card numbers),
Hosting/email/CRM/analytics providers (e.g., platform, email and analytics tools),
Professional advisers/authorities where required by law.
Where transfers occur outside Malaysia, we implement appropriate safeguards (data processing agreements, security controls, risk assessments).
6) Retention
Accounting/tax records: [e.g., 7 years].
Order & customer service records: [e.g., 3β7 years].
Marketing data: until you opt out or after [e.g., 24 months] of inactivity.
Data is securely deleted or anonymized when no longer needed.
7) Security
We apply reasonable technical and organizational measures (encryption-in-transit where applicable, access controls, audit logs, staff training). No system is 100% secure, but we work to minimize risk.
8) Your rights
You may request access to your data, correction of inaccuracies, restriction/objection (where applicable), data portability (where technically feasible), and you may withdraw marketing consent at any time. We may need to verify your identity before actioning a request.
9) Children
If a customer is under 18, consent should be provided by a parent/guardian.
10) Cookies & similar technologies
We use essential cookies for site functionality and, where permitted, analytics/advertising cookies. Manage preferences via your browser or our [Cookie Settings] page.
11) Data breaches
We maintain an incident response process. If an incident risks your rights, we will notify the relevant authority and affected individuals in a timely manner as required by law.
12) How to contact us
Data Controller: R&R AUTHENTICS SDN. BHD. (Co. No: 202201046089 (1491786-V))
Registered Address: 130-1, Jalan BMU2, Bandar Baru Merlimau Utara, 77300 Merlimau, Melaka, Malaysia.
Data Protection Officer (DPO): Dr. Rohaizu β rrashopper@gmail.com, +60182889653
Permanent Privacy Notice: https://luxurybrandedoutlet.com/privacy-policy/
13) Changes to this notice
We may update this notice from time to time. The latest version will always be available at the link above.
Effective date: 14 Aug 2025 | Last updated: 14 Aug 2025