FO2U Phase 1 — ASEAN Manufacturer Onboarding & Market Validation

Privacy Policy and Personal Data Protection Notice

For customers, merchants, representatives, website users and business contacts

Last updated: 2026-08-26

This Privacy Policy explains how FO2U collects, uses, discloses, retains, transfers and protects personal data in connection with the marketplace, merchant onboarding, payment processing, fulfilment and related business activities.

Company
FO2U Global Sdn Bhd
Company No.
202601015413 (1677510-D)

FO2U Global Sdn Bhd (Company No. 202601015413 (1677510-D)) (“FO2U”, “we”, “us” or “our”) respects your privacy. This Privacy Policy explains how we collect, use, disclose, retain, transfer and protect personal data in connection with the FO2U marketplace, merchant onboarding, payment processing, fulfilment and related business activities.

1. Scope and Data Controller

1.1 This Policy applies to customers, prospective customers, Merchants, directors, shareholders, beneficial owners, authorised representatives, website visitors, job or service applicants, service-provider contacts and other persons whose personal data FO2U processes in commercial transactions.

1.2 FO2U generally acts as the data controller for information collected for its own marketplace, compliance, customer-service and business purposes. A Merchant or service provider may separately act as a data controller for its own lawful purposes.

1.3 This Policy is intended to comply with the Personal Data Protection Act 2010 and applicable amendments, regulations, standards, circulars and guidelines in Malaysia.

2. Personal Data We May Collect

  • Identity data — name, date of birth, nationality, identification or passport details, photograph and signature;
  • Contact data — address, email, telephone number, WhatsApp number and communication preferences;
  • Account data — username, encrypted credentials, account settings and verification status;
  • Order data — Products, quantity, customer-facing Product price, Merchant base price and service-allocation data where operationally required, customer-paid logistics charge, delivery address, invoices, order history, refund and complaint details;
  • Payment data — payment method, transaction reference, payment status, bank-account information for Merchants, settlement and Chargeback information. FO2U does not intend to store complete card numbers or security codes;
  • Merchant KYC data — company records, directors, shareholders, beneficial owners, authorised representatives, licences, tax information, bank evidence and risk-screening results;
  • Product and compliance data — certificates, test reports, labels, ingredients, manufacturing location, regulatory approvals and complaint or recall information;
  • Logistics and customs data — shipment records, tracking, delivery proof, customs declarations and recipient details;
  • Technical data — IP address, browser, device identifiers, cookies, log files, approximate location derived from IP and security events;
  • Usage data — pages viewed, searches, clicks, interactions and shopping behaviour;
  • Communication data — emails, chats, calls, survey responses, support messages and complaint evidence;
  • Marketing data — consent status, campaign interaction and preferences; and
  • Other data you voluntarily provide or that is reasonably required by law or a service partner.

3. Sources of Personal Data

We may collect personal data directly from you, from your company or authorised representative, through the Platform, from Merchants, payment and logistics providers, identity-verification providers, company registries, regulators, sanctions and adverse-information databases, cookies and analytics tools, publicly available sources, business partners and lawful third parties.

4. Purposes of Processing

FO2U may process personal data for the following purposes:

  • Creating and administering accounts;
  • Merchant application, KYC, beneficial-ownership verification and product approval;
  • Processing Orders, payments, settlements, refunds and Chargebacks;
  • Arranging export, import, customs clearance, delivery, returns and fulfilment;
  • Handling customer service, complaints or disputes;
  • Preventing fraud, abuse, money laundering, sanctions breaches, prohibited trade and security incidents;
  • Complying with law, court orders, regulatory requests and service-partner requirements;
  • Maintaining transaction, tax, accounting, audit and corporate records;
  • Improving the Platform, testing systems, analysing performance and conducting research;
  • Protecting the rights, safety, property and integrity of FO2U, users, Merchants and others;
  • Communicating service messages, policy updates and operational notices;
  • Sending marketing where consent or another lawful basis applies, with an opt-out facility; and
  • Establishing, exercising or defending legal claims.

6. Mandatory and Optional Information

Information marked mandatory, or reasonably required for an Order, payment, delivery, refund, Merchant KYC or legal obligation, must be provided. If you do not provide it, FO2U may be unable to create an account, approve a Merchant, process an Order, make settlement, handle a complaint or comply with law. Optional information may be omitted unless you choose to provide it.

7. Disclosure of Personal Data

FO2U may disclose relevant personal data, on a need-to-know and lawful basis, to:

  • Merchants and their authorised fulfilment personnel;
  • Payment gateways, acquiring banks, issuing banks, banks, regulated payment and foreign-exchange providers;
  • Logistics, customs, courier, warehousing, fulfilment, return and insurance providers;
  • Cloud, hosting, cybersecurity, identity-verification, analytics, communication and customer-support providers;
  • Professional advisers, auditors, insurers and financiers;
  • FO2U affiliates, successors or potential transaction counterparties under confidentiality controls;
  • Government departments, customs, tax authorities, regulators, law-enforcement agencies and courts where required or permitted; and
  • Other persons you authorise or whose involvement is reasonably necessary for the stated purposes.

FO2U does not sell personal data to advertisers.

8. Cross-Border Transfer

Because FO2U connects Malaysian customers with overseas ASEAN manufacturers, personal data may be transferred to or accessed from Indonesia, Thailand, Vietnam, the Philippines and other countries where service providers operate. FO2U will take reasonable steps to ensure a permitted transfer basis and appropriate contractual, organisational and technical safeguards, taking into account the Personal Data Protection Commissioner’s cross-border transfer guidance.

9. Payment Security

Payments are processed by approved payment providers. FO2U aims to use hosted, redirected or tokenised payment methods and does not intend to store full payment-card numbers or card security codes. Payment providers may conduct fraud, authentication and regulatory checks under their own privacy notices.

10. Cookies and Similar Technologies

FO2U may use necessary cookies for login, checkout, security and preferences; analytics cookies to understand Platform use; and marketing cookies where permitted. You may control cookies through browser or consent settings, but disabling necessary cookies may affect functionality. A separate Cookie Notice may provide more detail.

11. Direct Marketing

FO2U may send marketing messages where you have consented or where otherwise permitted by law. You may unsubscribe through the message, account settings or by contacting FO2U. Operational messages about Orders, security, legal terms or account administration are not marketing and may continue where necessary.

12. Retention

FO2U retains personal data only as long as reasonably necessary for the stated purposes and legal obligations. In particular:

  • Online marketplace supplier and electronic transaction records will generally be retained for at least three years where required by electronic-trade regulations;
  • Accounting, tax, contract, settlement and corporate records may be retained for up to seven years or another period required by law;
  • Merchant KYC, screening and investigation records may be retained for seven years after termination or longer where required by a payment partner, legal hold or authority;
  • Complaint, refund, Chargeback, safety and recall records may be retained while claims remain possible; and
  • Technical logs and marketing data are retained for shorter operational periods unless security or legal needs require longer.

When data is no longer required, FO2U will delete, anonymise or securely dispose of it where reasonably practicable.

13. Security

FO2U will use reasonable administrative, physical and technical safeguards appropriate to the nature and risk of the data, which may include access controls, least-privilege permissions, encryption in transit, secure credential storage, logging, backups, vendor controls, staff confidentiality and incident-response procedures. No internet system can be guaranteed completely secure.

14. Data Breach Response

FO2U will investigate suspected personal data breaches, take reasonable containment and remediation steps, maintain incident records, and notify the Personal Data Protection Commissioner and affected persons where required. Where a notifiable breach occurs, FO2U will aim to meet the applicable notification timeframe, including the current 72-hour requirement for notifying the Commissioner where the notification criteria are met.

15. Your Rights

Subject to applicable law and permitted exceptions, you may request:

  • Access to personal data held by FO2U;
  • Correction of inaccurate, incomplete, misleading or outdated personal data;
  • Information about processing and disclosures;
  • Withdrawal of consent where processing is based on consent;
  • Cessation of direct marketing;
  • Restriction or objection where provided by law;
  • Data portability where the statutory right applies and is operationally available; and
  • Review of certain automated decisions where applicable.

FO2U may verify your identity, request additional information and charge a lawful fee where permitted. Some requests may be refused or limited where law, another person’s rights, fraud prevention, legal claims or recordkeeping obligations require continued processing.

16. Children

The Platform is intended for adults. FO2U does not knowingly allow a person under 18 to contract independently. A parent or legal guardian should place Orders and provide any required consent for a minor.

17. Merchant and Third-Party Responsibilities

Merchants and service providers must process personal data only for authorised purposes and protect it appropriately. Some may be independent data controllers and are responsible for their own notices and legal obligations. FO2U is not responsible for independent processing outside its reasonable control, but may investigate misuse connected with the Platform.

18. Data Protection Officer and Governance

FO2U will appoint and register a Data Protection Officer when the statutory thresholds or monitoring criteria apply. Until then, privacy matters will be managed by an authorised compliance contact. FO2U will periodically review whether registration as a prescribed class of data controller or appointment of a Data Protection Officer is required.

19. Changes to This Policy

FO2U may update this Policy to reflect legal, operational or technology changes. The current version will be published on the Platform. Material changes may be notified through the Platform, email or another appropriate channel.

20. Contact

  • Company: FO2U Global Sdn Bhd
  • Company registration number: 202601015413 (1677510-D)
  • Website: www.fo2u.com
  • Privacy and general enquiries: info@fo2u.com
  • WhatsApp: +60 10 335 2345
  • Postal address: A-05-09 Empire Tower, Jalan SS16/1, 47500 Subang Jaya, Selangor Darul Ehsan, Malaysia

Please state “Privacy Request” in the subject and provide enough information for FO2U to verify your identity and understand the request.