Privacy policy
Gaiöra, operated by Stillnergy Enterprise
1. About This Notice
1.1 This Privacy Policy is issued by Stillnergy Enterprise (Business Registration No. 126697, Sarawak), trading as Gaiöra ("we", "us", "our").
1.2 It is a written notice given under section 7 of the Personal Data Protection Act 2010 (Act 709), as amended by the Personal Data Protection (Amendment) Act 2024 ("PDPA"). It explains how we collect, use, disclose, transfer, store, and protect your personal data when you visit our website, place an order, or communicate with us.
1.3 For the purposes of the PDPA, Stillnergy Enterprise is the data controller in respect of the personal data described in this Policy.
1.4 Please read this Policy carefully. By providing your personal data to us, placing an order, or continuing to use our website, you acknowledge that you have read and understood this Policy.
1.5 If there is any conflict between this Policy and our Terms and Conditions, this Policy prevails in relation to the processing of personal data.
2. Personal Data We Collect
"Personal data" means information that relates to you and by which you are identified or identifiable, as defined in section 4 of the PDPA. Depending on how you interact with us, we may collect and process:
- Identity and contact data: name, billing address, delivery address, email address, telephone or mobile number, WhatsApp number, and social media handle where you contact us through such a platform.
- Transaction data: order number, items purchased, quantities, prices, order date, delivery details, order history, returns and exchanges, and correspondence relating to a transaction.
- Payment data: payment method, payment reference, transaction status, partial card details (such as the last four digits and card type), and proof of payment you send to us. We do not collect or store your full card number, CVV, or online banking credentials. These are handled directly by our payment service providers.
- Account data: username, encrypted password, saved addresses, preferences, wishlist, and marketing subscription status.
- Communications data: the content of your enquiries, customer service messages, WhatsApp conversations, emails, product reviews, and any information you volunteer in them.
- Technical and usage data: IP address, device type, browser type and version, operating system, referring URL, pages viewed, time spent, search terms used on the site, and cookie identifiers.
- Marketing and preference data: your responses to campaigns, your fragrance preferences where you tell us, and your consent status. Sensitive personal data
2.1 "Sensitive personal data" under the PDPA includes data concerning physical or mental health, political opinions, religious beliefs, the commission of an offence, and, following the 2024 amendments, biometric data.
2.2 We do not seek to collect sensitive personal data. If you voluntarily disclose health-related information to us, for example by describing a skin sensitivity or allergic reaction to a fragrance, we
will process it only to respond to your enquiry, address a product safety concern, or comply with a legal obligation, and only where you have given your explicit consent or another lawful basis under section 40 of the PDPA applies.
2.3 Please do not send us sensitive personal data unless it is necessary for us to assist you.
3. Where We Obtain Your Personal Data
We obtain personal data:
- Directly from you, when you create an account, place an order, complete a form, subscribe to marketing, participate in a live sale, contact us by email or WhatsApp, leave a review, or enter a promotion.
- Automatically, through cookies and similar technologies when you use our website.
- From service providers, such as our e-commerce platform, payment processors, and couriers, who provide us with transaction, delivery, and fraud-screening information.
- From third parties, such as social media or advertising platforms, where you have interacted with our content and their settings permit that disclosure.
4. Consequence of Not Providing Personal Data
Providing certain personal data is obligatory in order for us to accept and fulfil an order, specifically your name, contact details, delivery address, and payment information. If you do not provide this data, we will be unable to process your order or provide customer service. All other personal data is voluntary. Declining to provide it will not affect your ability to purchase from us, though it may limit certain features such as personalised recommendations.
5. Purposes of Processing
We process your personal data for the following purposes, on the bases indicated:
- To process, verify, and fulfil your order and take payment: performance of a contract with you.
- To arrange delivery and communicate with couriers: performance of a contract.
- To handle exchanges, returns, refunds, and complaints: performance of a contract, and our legitimate interest.
- To create and administer your account: performance of a contract.
- To respond to enquiries and provide customer support: performance of a contract, and our legitimate interest.
- To detect, prevent, and investigate fraud, abuse, and unauthorised transactions: our legitimate interest, and compliance with law.
- To maintain business records and comply with tax, accounting, and regulatory obligations: compliance with a legal obligation.
- To send marketing and promotional communications: your consent.
- To personalise content, recommendations, and advertising: your consent, where cookies or tracking are used.
- To analyse website performance and improve our products and services: our legitimate interest.
- To establish, exercise, or defend legal claims: our legitimate interest, and compliance with law.
- To address product safety matters and adverse reaction reports: legal obligation, and vital interests.
6. Direct Marketing and Your Right to Opt Out
6.1 We will send you marketing communications by email, SMS, WhatsApp, or post only where you have consented, or where you are an existing customer and we are marketing similar products, as permitted by law.
6.2 You have the right under section 43 of the PDPA to require us, at any time and at no cost, to stop processing your personal data for direct marketing purposes.
6.3 You may exercise this right by:
- clicking the unsubscribe link in any marketing email;
- replying "STOP" to a marketing message; or
- emailing official@gaiora.net with the subject "Opt Out".
6.4 We will action your request without undue delay. You will continue to receive transactional messages, such as order confirmations, delivery updates, and refund notices, as these are necessary to service your order and are not direct marketing.
7. Disclosure of Personal Data
7.1 In accordance with section 8 of the PDPA, we may disclose your personal data to the following classes of third party:
- Technology and platform providers: our e-commerce and hosting platform (Shopify), website analytics providers, email and messaging service providers, and IT support and cloud storage providers.
- Payment service providers and financial institutions: to process payments, verify transactions, issue refunds, and manage chargebacks.
- Logistics and courier companies: to whom we disclose your name, delivery address, and contact number in order to deliver your order.
- Professional advisers: accountants, auditors, insurers, and legal advisers, under duties of confidentiality.
- Regulatory and enforcement authorities: including the Personal Data Protection Commissioner, the Ministry of Domestic Trade and Cost of Living, the National Pharmaceutical Regulatory Agency, the Royal Malaysia Police, the Inland Revenue Board, and any court or tribunal, where required or permitted by law.
- Customs and border authorities: where you place an international order, we disclose the recipient's name, delivery address, contact number, and a description and declared value of the Products on the customs declaration accompanying the parcel, as required by the destination country and by the carrier.
- Marketing and advertising partners: where you have consented to personalised advertising.
- A successor entity: in connection with a sale, merger, transfer, or reorganisation of our business, subject to the recipient being bound by terms no less protective than this Policy.
7.2 We require third parties who process personal data on our behalf to act only on our instructions, to implement appropriate security measures as required under section 9 of the PDPA, and not to use your data for their own purposes.
7.3 We do not sell your personal data.
8. Relationship with Shopify
8.1 Our website is hosted on the Shopify platform. When you use our website, information you submit is transmitted to and processed by Shopify and its sub-processors in order to provide the service to us.
8.2 Shopify may process certain data as an independent controller for its own platform security, fraud prevention, and service-improvement purposes. In respect of that processing, Shopify's own privacy notice applies, and any rights you wish to exercise in relation to it should be directed to Shopify.
8.3 We remain the data controller in respect of your order and customer data.
9. Cross-Border Transfer
9.1 Some of our service providers, including our e-commerce platform, cloud hosting, and email providers, store or process data on servers located outside Malaysia, including in Singapore, the United States, the European Union, and other jurisdictions.
9.2 Section 129 of the PDPA, as amended in 2024, permits such transfers where the receiving jurisdiction has laws substantially similar to the PDPA or provides an adequate level of protection, or where one of the specified exceptions applies, including where the transfer is necessary for the performance of a contract with you, or where you have given your consent.
9.3 Where we transfer personal data outside Malaysia, we take reasonable steps to ensure the recipient is bound by contractual obligations to protect the data to a standard consistent with the PDPA.
9.4 By placing an order, you consent to the transfer of your personal data outside Malaysia for the purposes described in this Policy.
10. Data Security
10.1 In accordance with the Security Principle under section 9 of the PDPA, we take practical steps to protect personal data from loss, misuse, modification, unauthorised or accidental access, disclosure, alteration, or destruction. These include encryption of data in transit, restricted access on a need-to- know basis, use of reputable platform and payment providers, and periodic review of our security arrangements.
10.2 No method of transmission or storage is completely secure. While we take reasonable measures, we cannot guarantee absolute security. You should not transmit sensitive or confidential information to us through unsecured channels.
10.3 You are responsible for keeping your account password confidential and for any activity conducted through your account.
11. Data Breach Notification
11.1 Section 12B of the PDPA requires data controllers to notify the Personal Data Protection Commissioner of a personal data breach.
11.2 Where a personal data breach occurs and causes or is likely to cause significant harm to affected individuals, or is of a significant scale, we will notify the Commissioner as soon as practicable and in any event within seventy-two (72) hours of becoming aware of it.
11.3 Where the breach results in or is likely to result in significant harm to you, we will notify you without unnecessary delay and in any event within seven (7) days of notifying the Commissioner, and will describe the nature of the breach, the likely consequences, and the steps we are taking and that you may take.
12. Data Retention
12.1 In accordance with the Retention Principle under section 10 of the PDPA, we retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law.
12.2 Our indicative retention periods are as follows:
- Order, transaction, and accounting records: seven (7) years from the end of the relevant year of assessment, in accordance with the Income Tax Act 1967.
- Customer account data: for the life of the account, and up to twenty-four (24) months after it becomes inactive.
- Customer service correspondence: twenty-four (24) months from resolution.
- Marketing consent records: until consent is withdrawn, plus twenty-four (24) months as evidence of the withdrawal.
- Website analytics and cookie data: up to twenty-four (24) months.
- Records relating to a dispute or claim: until the matter is resolved and any applicable limitation period under the Limitation Act 1953 has expired.
12.3 When personal data is no longer required, we will take reasonable steps to permanently delete or anonymise it.
13. Data Integrity
We take reasonable steps under section 11 of the PDPA to ensure that personal data is accurate, complete, not misleading, and kept up to date, having regard to the purpose for which it was collected. Please notify us of any change to your details.
14. Your Rights
Subject to the exceptions permitted under the PDPA, you have the following rights:
- Right of access (section 30): to be informed whether we hold personal data about you and to be supplied with a copy.
- Right to correct (section 34): to require correction of personal data that is inaccurate, incomplete, misleading, or out of date.
- Right to withdraw consent (section 38): to withdraw, by written notice, consent previously given for processing. Withdrawal does not affect the lawfulness of processing carried out before withdrawal, and may mean we can no longer supply certain services to you.
- Right to prevent processing likely to cause damage or distress (section 42): to require us to cease or not begin processing where it is causing or likely to cause substantial, unwarranted damage or distress to you or another person.
- Right to prevent processing for direct marketing (section 43): as set out in clause 6 above.
- Right to data portability (section 43A): introduced by the Personal Data Protection (Amendment) Act 2024, to request that we transmit your personal data to another data controller of your choice, where technically feasible and compatible with the format in which the data is held. How to exercise your rights Submit a written request to official@gaiora.net, marked "Data Subject Request", stating clearly which right you wish to exercise. The following apply:
- We may require proof of identity before acting on a request, in order to protect your data.
- We may charge a prescribed fee for a data access request, as permitted under the PDPA.
- We will respond within twenty-one (21) days of receiving a valid request. Where more time is needed, we will inform you and may extend the period by up to fourteen (14) days, giving reasons.
- Where we decline a request, we will give you written reasons.
15. Cookies
15.1 Our website uses cookies and similar technologies to enable core functionality, such as your shopping cart and login session, to remember your preferences, to measure site performance, and, where you consent, to deliver personalised advertising.
15.2 Strictly necessary cookies are required for the website to function and cannot be disabled.
15.3 You may control or delete cookies through your browser settings. Disabling cookies may affect the functionality of the website, including checkout.
16. Children
16.1 Our products and website are intended for persons aged eighteen (18) and above.
16.2 We do not knowingly collect personal data from children. Where a person under the age of eighteen wishes to purchase from us, the transaction must be conducted by a parent or legal guardian.
16.3 If you are a parent or guardian and believe that a child has provided personal data to us, please contact us at official@gaiora.net and we will take reasonable steps to delete it.
17. Third-Party Websites
Our website may link to third-party sites and platforms. This Policy does not apply to them. We are not responsible for their privacy practices, and we encourage you to read their privacy notices before providing personal data.
18. Complaints
18.1 If you are concerned about how we have handled your personal data, please contact us first at official@gaiora.net. We will investigate and respond.
18.2 If you remain dissatisfied, you may lodge a complaint with the Department of Personal Data Protection (Jabatan Perlindungan Data Peribadi) at Level 8, Galeria PjH, Jalan P4W, Persiaran Perdana, Precinct 4, 62100 Putrajaya, Malaysia, or through its website at www.pdp.gov.my.
19. Data Protection Contact
We are not currently required to appoint a Data Protection Officer under section 12A of the PDPA, as our processing does not meet the thresholds set out in the Commissioner's Guideline on the Appointment of a Data Protection Officer. Should those thresholds be met, we will appoint and register a Data Protection Officer and update this Policy. All privacy enquiries should be directed to official@gaiora.net.
20. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices or in the law. The revised version will be published on this website with an updated "Last updated" date. Where a change is material, we will provide additional notice as required by law.
21. Contact
Stillnergy Enterprise (Gaiöra) 1st Floor, SL.8, Rock Commercial Centre, Jalan Green, 93150 Kuching, Sarawak, Malaysia Email: official@gaiora.net WhatsApp: +60 12-891 6681