Privacy Policy
Last updated 9 August 2026
This Privacy Policy explains how Zedd Labs Enterprise (SSM registration no. 202603050314) ("we", "us", "our") collects, uses, discloses, and protects personal data in connection with Seratus Pro(the "Service"). We are committed to handling personal data in accordance with Malaysia's Personal Data Protection Act 2010 ("PDPA") and, where they apply, the EU/UK General Data Protection Regulation ("GDPR") and the California Consumer Privacy Act as amended ("CCPA/CPRA").
1. Our two roles
As a controller: for personal data of merchants and website visitors (account, billing, and usage data), we decide how and why the data is processed.
As a processor:for personal data that a merchant collects about its own End Customers through the Service (for example, membership records containing name, date of birth, phone, and email), the merchant is the controller and we process that data on the merchant's behalf and instructions. Merchants are responsible for having a lawful basis and, where required, obtaining consent and providing notice to their End Customers.
2. Personal data we collect
- Account & contact data: name, business name, email, phone, and login credentials.
- Billing data: subscription plan, transaction records, and limited payment metadata (card details are handled by our payment partners, not stored by us).
- Merchant Content: data you enter into the Service, including End Customer records (e.g. member name, date of birth, phone, email), bookings, and sales.
- Usage & device data: IP address, device and browser information, and analytics about how the Service is used.
3. Why we use personal data (purposes & legal bases)
- To provide, operate, secure, and support the Service (performance of a contract; legitimate interests).
- To process payments and manage subscriptions (performance of a contract; legal obligation).
- To communicate service, security, and account notices (legitimate interests; legal obligation).
- To improve and develop features, and for analytics (legitimate interests; consent where required).
- To send marketing communications, where you have opted in and may opt out at any time (consent).
- To comply with law and enforce our terms (legal obligation; legitimate interests).
Under the PDPA, we process personal data on the basis of your consent and the other grounds permitted by the Act. Under the GDPR, we rely on the legal bases noted above.
4. Data-collection consent for members
When a merchant enrols a member through the Service, the merchant confirms that the End Customer has consented to the collection and processing of their personal data for membership management. We record the time of that confirmation to support the merchant's accountability obligations. Merchants must ensure this consent is validly obtained and honour any withdrawal of consent.
5. Sharing & disclosure
We share personal data only as needed:
- Service providers / sub-processors: hosting, databases, payment gateways, SMS and email delivery, and analytics — bound by confidentiality and data-protection obligations.
- Legal & safety: where required by law, regulation, or valid legal process, or to protect rights, safety, and security.
- Business transfers: in connection with a merger, acquisition, or asset sale, subject to this Policy.
We do not sell personal data.
6. International transfers
We and our sub-processors may process data in countries other than your own. Where personal data is transferred across borders, we take steps to ensure a comparable level of protection, including contractual safeguards such as standard contractual clauses where applicable.
7. Data retention
We keep personal data for as long as needed to provide the Service and for legitimate business or legal purposes (such as accounting and dispute resolution). Merchant Content is retained while the Account is active and deleted or anonymised within a reasonable period after termination, subject to law. Merchants can request deletion of specific records.
8. Security
We use technical and organisational measures — including encryption in transit, access controls, and row-level security — to protect personal data. No system is completely secure; we cannot guarantee absolute security.
9. Your rights
Subject to applicable law, you may have the right to access, correct, update, port, restrict, or delete your personal data, to withdraw consent, and to object to certain processing.
- PDPA (Malaysia): rights of access and correction, to withdraw consent, and to limit processing for direct marketing.
- GDPR (EU/UK): rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with a supervisory authority.
- CCPA/CPRA (California):rights to know, delete, correct, and opt out of "sale" or "sharing" of personal information, without discrimination for exercising them. As noted, we do not sell personal data.
Where we act as a processor for a merchant, please direct requests to the merchant; we will assist them in responding. To exercise rights for data we control, contact us using the details below.
10. Cookies & analytics
We use essential cookies to operate the Service and, with consent where required, analytics cookies to understand usage. You can control cookies through your browser settings and any consent controls we provide.
11. Children
The Service is intended for businesses and is not directed at children. We do not knowingly collect personal data directly from children. Where a merchant records data about a minor End Customer, the merchant is responsible for any parental/guardian consent required by law.
12. Changes to this Policy
We may update this Policy from time to time. We will post the updated version here with a new "last updated" date and, for material changes, provide reasonable notice.
13. Contact us
For privacy questions or to exercise your rights, contact:
Zedd Labs Enterprise (SSM 202603050314)
Email: hello@seratuspro.com