Privacy Policy - Harrington Bookshop

Privacy Policy

Comprehensive Data Protection and Privacy Guidelines

Company No: 202501013611 / 1615025-A
Effective Date: 10th October 2025

1. Introduction

1.1 Scope and Application

This Privacy Policy details the practices of HARRINGTON BOOKSHOP SDN. BHD., its affiliates, and related corporate bodies ("Harrington Bookshop," "we," "us," or "our") concerning the collection, usage, disclosure, retention, and protection of Personal Data. This document applies universally to all individuals ("you" or "Customer") who engage with our services, whether through our official Website www.harringtonbookshop.com, authorized third-party marketplaces (including Shopee, Lazada, and TikTok Shop), or via direct correspondence.

1.2 Regulatory Compliance

We are committed to complying with the Personal Data Protection Act 2010 (PDPA Malaysia) and the Personal Data Protection Act 2012 (PDPA Singapore), together with any subsidiary regulations, standards, and guidelines issued by the respective data-protection authorities.

This Policy also anticipates alignment with comparable data-protection frameworks in other Southeast Asian jurisdictions where we may later operate or deliver goods.

1.3 Informed Consent

By accessing or transacting with Harrington Bookshop, you acknowledge and confirm that you have been notified of, and you provide your informed, explicit, and unambiguous consent to, the Processing of your Personal Data as set forth herein.

2. Definition and Classification of Personal Data

2.1 Definition of Personal Data

Personal Data is defined as any information that relates directly or indirectly to an individual, from which the identity of the individual is apparent or can be reasonably and directly ascertained. This includes, but is not limited to, data capable of being processed electronically and retained in our records.

2.2 Data Classification Categories

We classify Personal Data into specific categories to ensure proper handling:

(a) Identity Data (name, NRIC/passport, date of birth)
(b) Contact Data (physical address, email, phone number)
(c) Transactional Data (purchase details, payment receipts, bank details)
(d) Technical and Usage Data (IP addresses, browsing activity, device information)

2.3 Sensitive Personal Data

Sensitive Personal Data, which includes information regarding an individual's physical or mental health, political opinions, religious beliefs, or commission of offenses, is not routinely collected by us. If such data is ever required, we will seek separate, specific, and explicit consent for its Processing.

2.4 Technical and Behavioural Data

We may also collect limited technical and behavioural data (such as device type, IP address, and browsing interactions) through cookies or analytics tools, solely to improve our Website's functionality and user experience.

3. Detailed Mechanism of Data Collection

3.1 Data Provided Directly by You

We collect data when you actively and voluntarily engage with our platforms. This includes, but is not limited to, when you:

  • (a) Register an account on our Website;
  • (b) Place an order for new or refurbished electronic devices;
  • (c) Subscribe to our newsletter or promotional mailing lists;
  • (d) Complete online forms for customer support, warranty claims, or product reviews; or
  • (e) Communicate with us via email, telephone, or social media messaging.

3.2 Data Collected Automatically

As you interact with our Website, we automatically collect Technical and Usage Data about your equipment, browsing actions, and patterns. This data is collected using server logs, Cookies, and other tracking mechanisms, which helps us secure and improve the platform.

3.3 Data from Third-Party Sources

We receive limited Personal Data from third-party marketplace platforms such as Shopee, Lazada, and TikTok Shop, as well as payment processors (e.g., Razorpay) and analytics or logistics partners. Only the data strictly necessary to fulfil your transaction—typically your name, contact details, delivery address, and transaction reference—is imported to our systems. These marketplaces remain independent data controllers for information they collect directly from you; their privacy practices are governed by their own published policies.

3A. Legal Basis and Consent

By using our Website, placing an order, or subscribing to our newsletter, you consent to the collection and processing of your Personal Data as described herein. Where consent is required for marketing communications, you may withdraw it at any time by emailing harringtonbookshop@gmail.com or using the unsubscribe link provided in our emails.

4. Legal Basis and Specific Purposes for Processing

4.1 Legal Bases for Processing

Our Processing of Personal Data is underpinned by legitimate legal bases as required by the PDPA:

(a) Consent: Your explicit agreement to specific processing activities, particularly marketing;

(b) Contractual Necessity: Processing essential for the performance of a contract of sale with you (e.g., delivery);

(c) Legal Obligation: Processing required to comply with Malaysian laws (e.g., tax documentation); and

(d) Legitimate Interests: Processing required to safeguard our business interests (e.g., fraud prevention, business analysis).

4.2 Specific Purposes for Processing

• Order and Logistics Management: Essential for processing your purchase, validating payment, packaging, generating shipping labels, and tracking product delivery.

• Post-Sale Services: Managing the lifecycle of your product, including honoring the 3-month limited warranty for refurbished items and processing returns or refunds under our stated Policies.

• System Integrity and Security: Monitoring Website traffic, identifying security vulnerabilities, and protecting against cyber threats or fraudulent activities.

• Financial Reporting: Maintaining comprehensive business, accounting, and tax records as required by the Companies Act 2016 and tax regulations.

5. Data Integrity and The Principle of Minimisation

5.1 Data Accuracy Standards

We implement all reasonable practical steps to ensure that the Personal Data we hold is accurate, complete, not misleading, and up-to-date, particularly before it is used for decision-making purposes or disclosed to a third party.

5.2 Data Minimisation Principle

In accordance with the principle of data minimisation, we limit the collection of Personal Data to only that which is strictly necessary and relevant for the defined purposes stated in Section 4. We do not engage in the collection of excessive or irrelevant data.

5.3 Customer Data Responsibility

You bear the primary responsibility for ensuring that any data you directly provide to us (e.g., during account registration or checkout) is accurate and complete, and you must promptly inform us of any changes to your Contact Data or Identity Data.

5.4 Customer Liability and Indemnity

You are responsible for ensuring that all Personal Data provided to the Company is accurate and up to date. The Company shall not be liable for any loss arising from incorrect or unauthorized information supplied by you. You agree to indemnify and hold the Company harmless from any claims resulting from such misuse.

6. Retention of Personal Data

6.1 Retention Duration Principle

We will only retain your Personal Data for the duration necessary to fulfill the stated purposes of collection, or as mandated by statutory, legal, or regulatory requirements in Malaysia.

6.2 Retention Criteria

The length of the retention period is determined by several factors, including:

  • (a) The duration of our contractual relationship with you;
  • (b) The existence of ongoing legal or warranty claims;
  • (c) Mandatory record-keeping periods prescribed by tax or consumer protection laws; and
  • (d) The necessity of the data for effective fraud detection.

6.3 Secure Deletion Process

Once the retention period expires, we are committed to promptly and securely deleting, destroying, or anonymizing the Personal Data to prevent any further identification or unauthorized use.

6.4 Specific Retention Timeline

We retain customer records for up to seven (7) years from the last transaction date or as required by accounting, taxation, or warranty obligations. Thereafter, data will be anonymized or securely deleted.

7. Disclosure to Third Parties

We may disclose Personal Data only to trusted partners essential to the sale, payment, or delivery of products. Each partner is bound by written terms ensuring PDPA-equivalent protection.

7.1 Disclosure Guarantee

We guarantee that your Personal Data will only be disclosed to third parties under explicit conditions that strictly adhere to the PDPA, and primarily for the efficient performance of the contract of sale.

7.2 Categories of Third-Party Disclosure

• Logistics and Shipping Agents: To courier and postal services for the execution of delivery.

• External Data Processors: Cloud storage providers, IT maintenance contractors, and customer relationship management (CRM) software providers who process data strictly on our instructions.

• Financial and Payment Institutions: Banks, credit card companies, and payment gateways (e.g., Razorpay) for transaction authorization, processing, and anti-money laundering compliance.

• Auditors and Legal Consultants: To professional services firms for the purposes of statutory audit, due diligence, or obtaining legal advice.

7.3 Third-Party Service Provider Obligations

We require all third-party service providers to respect the security of your Personal Data and to treat it in accordance with the law, forbidding them from using your Personal Data for their own independent purposes.

7.4 Third-Party Platform Limitations

While we verify PDPA compliance, the Company is not responsible for data breaches or security incidents occurring on third-party platforms outside our control.

8. Cross-Border Data Transfer Protocol

8.1 Primary Storage Location

As a Malaysian company, we prioritize the storage and Processing of Personal Data within Malaysia.

8.2 Regional Transfer Conditions

Because we operate in both Malaysia and Singapore and may expand regionally, your Personal Data may be transferred across borders within Southeast Asia for order fulfilment, hosting, or customer-service purposes.

Transfers will occur only where (a) the receiving country has data-protection laws substantially similar to Malaysia's or Singapore's PDPA; or (b) appropriate contractual safeguards are in place; or (c) you have expressly consented to the transfer.

8.3 Transfer Examples and Safeguards

Examples include storage on regional cloud servers and logistics data shared with shipping agents operating in Singapore, Thailand, or Indonesia. All such transfers are handled under strict confidentiality and security protocols.

Where such a cross-border transfer occurs, Harrington Bookshop undertakes to implement appropriate safeguards, such as contractual clauses, to ensure the continued protection and integrity of the Personal Data post-transfer.

8.4 PDPA Compliance Standards

All cross-border data transfers are conducted in compliance with Section 129(1) of the PDPA 2010 and equivalent safeguards under Singapore's PDPA to ensure comparable levels of protection.

9. Data Subject Rights: Access and Correction

9.1 Right to Access

You are entitled to request confirmation from us as to whether your Personal Data is being Processed and, if so, to gain access to that data, subject to any prescribed fees under the PDPA.

9.2 Right to Correction

You have the right to require us to correct any Personal Data that is inaccurate, incomplete, or misleading. This right is critical to maintaining data integrity (Section 5).

9.3 Circumstances for Request Refusal

We may refuse to comply with an access or correction request under specific circumstances permitted by the PDPA, such as when the burden of providing the data is disproportionate to the risk to the data subject's privacy, or if the request is frivolous.

10. Data Subject Rights: Withdrawal of Consent (Opt-Out)

10.1 Principle of Choice

You have the fundamental right to choose whether or not to allow the Processing of your Personal Data, particularly for non-essential functions such as marketing.

10.2 Withdrawal Mechanism

You may, at any time, withdraw your consent to the Processing of your Personal Data for any specified purpose(s) by:

  • (a) Clicking the 'unsubscribe' link present in any marketing email; or
  • (b) Submitting a formal, written notice to our Data Protection Officer (Section 20).

10.3 Effect of Consent Withdrawal

The withdrawal of consent will take effect upon receipt and verification of your notice. Please note that this withdrawal does not affect the legality of processing carried out prior to the withdrawal, nor does it affect our continued Processing of data required for legal obligations (e.g., fulfillment of an outstanding order).

11. Security and Technical Safeguards

11.1 Security Commitment

We have implemented rigorous administrative, physical, and technical measures to safeguard your Personal Data against unauthorized access, theft, loss, damage, alteration, or misuse.

11.2 Technical Measures Include

(a) The use of secure socket layer (SSL) encryption for all data transmission on the Website;

(b) Firewall protection and intrusion detection systems;

(c) Periodic security assessments and penetration testing; and

(d) Secure, access-controlled data storage facilities.

11.3 Security Limitations and User Responsibility

While we exert maximum effort to maintain security, you acknowledge that no data transmission or storage system can be guaranteed to be 100% secure. You must also maintain the confidentiality of your account password and notify us immediately of any known or suspected unauthorized use.

11.4 Data Breach Notification Protocol

In the event of a data breach posing a real risk of harm, we will promptly contain the incident and, where required, notify the Malaysian Personal Data Protection Commissioner, the Personal Data Protection Commission of Singapore, and affected individuals without undue delay.

11.5 Liability Disclaimer for Security

While we implement appropriate technical and organizational measures to protect your Personal Data, no electronic storage or transmission method is entirely secure. The Company disclaims all liability for unauthorized access, disclosure, or loss arising from events beyond its reasonable control.

12. Management of Technical and Usage Data

12.1 Purpose of Technical Data Collection

We collect Technical and Usage Data to improve the functionality and performance of our services. This data assists us in:

  • (a) diagnosing server problems;
  • (b) administering the Website;
  • (c) analyzing customer preferences to optimize refurbished product listings; and
  • (d) ensuring the compatibility of our site across various browsers and devices.

12.2 Anonymized Data Usage

To the extent that Technical and Usage Data is aggregated or anonymized and cannot reasonably be used to identify you, it will be treated as non-personal data and may be used freely by us for research and business intelligence.

12A. Administrative Fees for Requests

The Company reserves the right to refuse or charge a reasonable administrative fee for data access or correction requests that are manifestly unfounded, repetitive, or excessive, as permitted under Section 30(3) of the PDPA.

13. Processing for Direct Marketing

13.1 Marketing Consent Requirement

We will only process Personal Data for the purpose of direct marketing (e.g., promotions for e-readers) if you have provided your explicit consent through a separate, opt-in mechanism.

13.2 Third-Party Marketing Prohibition

We will not disclose, or threaten to disclose, Personal Data to a third party for the purpose of direct marketing without obtaining your consent.

13.3 Free Opt-Out Mechanism

In every direct marketing communication, we will provide you with a clear, free-of-charge, and easy mechanism to cease or withdraw consent for future communications.

13A. Legal Disclosure Requirements

We may disclose Personal Data when required by law, court order, or government regulation. This includes cooperation with enforcement authorities, fraud investigations, or to protect the Company's legal rights.

14. Detailed Cookie Policy Integration

14.1 Cookie Usage Overview

Our Website utilizes Cookies (small text files placed on your device) to differentiate you from other users and enhance your personalized shopping experience.

14.2 Categories of Cookies Used

(a) Strictly Necessary Cookies: Essential for the operation of the e-commerce functionality (e.g., maintaining your shopping cart);

(b) Analytical/Performance Cookies: Allow us to recognize and count the number of visitors and see how visitors move around our site; and

(c) Functionality Cookies: Used to recognize you when you return to our Website (e.g., remembering login details).

14.3 Cross-Border Cookie Data Transfer

Some analytical cookies (for example, Google Analytics 4 or Meta Pixel) may involve limited cross-border transfer of anonymised Technical Data to servers located in the United States or Singapore. Such transfers are governed by contractual clauses ensuring protection equivalent to the PDPA requirements.

Full details regarding the types, purposes, and management of Cookies are comprehensively detailed in our separate Cookie Policy, which is governed by this Privacy Policy. By continuing to use our Website, you consent to the use of Cookies described in that Policy.

15. Links to External and Third-Party Websites

15.1 Third-Party Website Links

Our service may contain hyperlinks or advertising that leads to websites, products, or services operated by third parties (e.g., the original manufacturer's website, or independent review platforms).

15.2 No Control or Responsibility

Harrington Bookshop exercises no control over, and assumes no responsibility for, the content, security, or privacy practices of any third-party website. The inclusion of a link does not constitute an endorsement.

15.3 User Caution Advisory

We strongly advise all users to exercise caution and review the privacy policies of any external website before submitting any Personal Data to them.

16. Data of Minors and Parental Consent

16.1 Age Eligibility Requirement

Our Website and services are strictly intended for users who are eighteen (18) years of age or older, possessing the legal capacity to enter into binding contracts in Malaysia.

16.2 Mandatory Parental Consent

If you are under the age of 18, we require that you obtain consent from your parent or legal guardian before submitting any Personal Data.

16.3 Inadvertent Collection Protocol

If we become aware that we have inadvertently collected Personal Data from a child under 18 without verifiable parental consent, we will take immediate and reasonable steps to delete or destroy that information.

17. Exemption from Liability for Third-Party Marketplaces

17.1 Independent Platform Acknowledgment

Customers purchasing our products via authorized marketplaces (Shopee, Lazada, TikTok Shop) acknowledge that those platforms are independent entities with their own privacy policies.

17.2 Limited Company Responsibility

While we ensure our data handling processes comply with the PDPA during fulfillment, we are not responsible for the data protection practices, data security failures, or policy enforcement actions taken by the marketplace platform itself.

18. Amendments and Policy Governance

18.1 Right to Modify Policy

We reserve the unqualified right to review, update, or modify this Privacy Policy at our sole discretion, particularly to remain current with legislative changes under the PDPA.

18.2 Notification of Material Changes

Any material changes will be communicated by posting an updated version of the Policy with a revised Effective Date on our Website. Continued use of our services following such modifications constitutes your acknowledgement and acceptance of the revised terms.

19. Governing Law and Severability

19.1 Applicable Governing Law

This Privacy Policy shall be governed by and construed exclusively in accordance with the laws of Malaysia, without regard to its conflict of law principles.

19.2 Severability Clause

Should any provision of this Policy be deemed invalid, unlawful, or unenforceable by a court of competent jurisdiction, that provision shall be severed to the minimum extent necessary, and the remaining provisions shall continue in full force and effect.

19.3 Mediation Before Litigation

Any disputes relating to this Privacy Policy shall first be submitted for mediation at the Asian International Arbitration Centre (AIAC) in Kuala Lumpur before court proceedings.

20. Contact Information and Data Protection Officer

Contact Our Data Protection Officer

For any inquiries, requests for access or correction, complaints, or legal notices concerning this Privacy Policy or the Processing of your Personal Data, please contact our designated Data Protection Officer:

HARRINGTON BOOKSHOP SDN. BHD.
Attention: Data Protection Officer

Email: harringtonbookshop@gmail.com

Registered Office:
A-3-3, Plaza Bukit Jalil (Aurora Place)
No. 1, Persiaran Bukit Jalil 1
Bandar Bukit Jalil
57000 Kuala Lumpur
W.P. Kuala Lumpur, Malaysia

21. Precedence and Updates

In the event of inconsistency between this Privacy Policy and the Terms & Conditions of Sale and Use, the stricter consumer-protection clause shall prevail. The Company reserves the right to amend this Policy at any time, with updates effective upon publication on our Website.

HARRINGTON BOOKSHOP SDN. BHD.
Company Registration No.: 202501013611 (1615025-A)
Incorporated on: 28 March 2025 under the Companies Act 2016 (Malaysia)
Registered Office: A-3-3, Plaza Bukit Jalil (Aurora Place), No. 1, Persiaran Bukit Jalil 1, Bandar Bukit Jalil, 57000 Kuala Lumpur, W.P. Kuala Lumpur, Malaysia