Back

Privacy Policy

PRIVACY POLICY & PRIVACY NOTICE

PREMO Review System
Last Updated: 11 August 2026

PREMO Review System ("PREMO Review System", "we", "us", "our") respects your privacy and is committed to protecting the personal data that we collect, use, store and process when you use our website, software, platform and related services.

This Privacy Policy and Privacy Notice ("Privacy Policy") explains how we collect, use, disclose, store, retain and protect personal data when you:

  • visit our website;
  • register for an account;
  • subscribe to our Service;
  • use the PREMO Review System;
  • upload or submit information;
  • use our QR code and review-related features;
  • communicate with us;
  • make payments;
  • contact customer support; or
  • otherwise interact with us.

This Privacy Policy is intended to provide information regarding our personal data practices and is designed with reference to applicable Malaysian personal data protection requirements, including the Personal Data Protection Act 2010 ("PDPA"), as amended from time to time.

By using the Service or providing personal data to us, you acknowledge that you have read and understood this Privacy Policy.


1. WHO WE ARE

PREMO Review System operates a software-as-a-service ("SaaS") platform designed to assist businesses with review management, customer engagement, marketing content, QR code functionality, AI-assisted content generation and related business tools.

For the purposes of applicable data protection laws, PREMO Review System may act as a data user / data controller in relation to personal data that we collect and process for our own business purposes.

In certain circumstances, we may process personal data on behalf of our business Customers as part of providing the Service.

Where applicable, the Customer may remain responsible for determining the purpose and manner in which personal data is collected and used through the Customer's account.


2. PERSONAL DATA WE MAY COLLECT

Depending on how you use the Service, we may collect different categories of personal data.

2.1 Account Information

When you create an account, we may collect:

  • name;
  • business name;
  • company name;
  • email address;
  • telephone number;
  • username;
  • password or authentication information;
  • account ID;
  • subscription information; and
  • other information required to create and manage your account.

2.2 Business Information

If you subscribe to the Service as a business, we may collect information relating to your business, including:

  • business name;
  • business address;
  • business telephone number;
  • business email address;
  • website;
  • social media links;
  • Google Business Profile information;
  • business category;
  • business description;
  • business logo;
  • photographs;
  • QR code information;
  • review-related information;
  • marketing information; and
  • other information you choose to provide.

2.3 Customer and End-User Information

Customers using our Service may choose to collect or process information relating to their own customers.

This may include:

  • name;
  • review content;
  • comments;
  • feedback;
  • contact information;
  • customer-generated content;
  • photographs;
  • transaction-related information;
  • responses to forms;
  • QR code interactions; and
  • other information submitted by the end user.

Where a business Customer uses our Service to process personal data relating to its own customers, the business Customer is responsible for ensuring that the collection and use of such personal data complies with applicable laws and that any required notice or consent has been obtained.


2.4 Payment Information

When you subscribe to our Service, payments may be processed through a third-party payment service provider.

Depending on the payment method used, we may receive information such as:

  • transaction ID;
  • payment status;
  • payment amount;
  • payment date;
  • currency;
  • subscription status;
  • billing information;
  • masked card information; and
  • other transaction-related information.

Where payment processing is handled by a third-party payment provider, we do not intentionally store complete credit card numbers or CVV/security codes on our own servers.

Your payment information may be processed directly by the relevant payment provider according to its own privacy policy and terms.

Payments, subscription charges and recurring billing may be processed through authorised third-party payment service providers, such as Razorpay or other payment providers used by PREMO.

PREMO does not store complete credit card numbers, CVV/security codes or full card credentials on its own servers.

Payment information may be processed by the relevant payment provider in accordance with its own privacy policy, terms and security requirements.

PREMO may receive limited payment-related information such as transaction status, payment reference, subscription status or masked payment information for billing and account management purposes.


2.5 Technical and Device Information

When you access the Service, we may automatically collect certain technical information, including:

  • IP address;
  • browser type;
  • operating system;
  • device type;
  • device information;
  • screen resolution;
  • language settings;
  • time zone;
  • referring URL;
  • pages accessed;
  • date and time of access;
  • session information;
  • error logs;
  • system activity;
  • approximate location derived from technical information; and
  • other technical information generated through use of the Service.

This information may be used for security, analytics, troubleshooting, performance monitoring and service improvement.


2.6 Usage Information

We may collect information about how you interact with the Service, including:

  • login activity;
  • pages visited;
  • features used;
  • QR code scans;
  • links accessed;
  • subscription activity;
  • account activity;
  • system interactions;
  • feature usage;
  • error events; and
  • other usage information.

2.7 Customer Content

Customers may upload or submit content to the Service.

This may include:

  • business logos;
  • photographs;
  • review templates;
  • review content;
  • customer feedback;
  • marketing content;
  • business descriptions;
  • captions;
  • messages;
  • images;
  • documents;
  • customer information; and
  • other materials.

Such information may contain personal data depending on what the Customer chooses to upload.


2.8 Communications

When you contact us, we may collect information contained in your communication, including:

  • name;
  • email address;
  • telephone number;
  • message content;
  • attachments;
  • support requests;
  • technical information; and
  • communication history.

3. HOW WE COLLECT PERSONAL DATA

We may collect personal data through:

  • our website;
  • registration forms;
  • account creation;
  • subscription forms;
  • checkout pages;
  • the PREMO Review System dashboard;
  • QR codes;
  • customer support;
  • email;
  • WhatsApp or other communication channels;
  • uploaded files;
  • APIs;
  • cookies;
  • analytics tools;
  • payment providers;
  • third-party integrations; and
  • information provided directly by you.

We may also receive information from third-party service providers where permitted by applicable law.


4. PURPOSES OF COLLECTING AND USING PERSONAL DATA

We may collect, use and process personal data for the following purposes:

4.1 Account Management

To:

  • create your account;
  • authenticate your account;
  • manage your subscription;
  • provide access to the Service;
  • maintain your account;
  • manage user permissions; and
  • provide account-related support.

4.2 Providing the Service

We may use personal data to:

  • provide the Service;
  • operate the dashboard;
  • generate QR codes;
  • provide review-related features;
  • process Customer Content;
  • provide AI-assisted functionality;
  • maintain account settings;
  • provide customer support; and
  • operate related features.

4.3 Payment and Billing

We may process personal data to:

  • process payments;
  • manage recurring subscriptions;
  • verify transactions;
  • maintain billing records;
  • manage failed payments;
  • detect suspicious transactions;
  • issue invoices or receipts;
  • process refunds where applicable; and
  • manage subscription cancellations.

5. AUTOMATIC RECURRING PAYMENT INFORMATION

Where the Customer subscribes to a recurring Subscription, payment-related information may be processed for the purpose of automatically charging the Customer's registered payment method.

The Service may store or receive information necessary to determine:

  • whether a Subscription is active;
  • whether a payment was successful;
  • whether a payment failed;
  • the next billing date;
  • the Subscription plan;
  • the transaction ID; and
  • the payment status.

We do not intentionally store complete credit card numbers or CVV/security codes on our own servers where payment information is handled by an authorised third-party payment provider.


6. CUSTOMER SUPPORT

We may use personal data to:

  • respond to enquiries;
  • troubleshoot technical problems;
  • investigate account issues;
  • respond to billing questions;
  • process cancellation requests;
  • investigate disputes;
  • provide onboarding assistance; and
  • improve customer support.

7. SERVICE IMPROVEMENT

We may use information about how Customers use the Service to:

  • improve existing features;
  • develop new features;
  • identify technical problems;
  • analyse usage patterns;
  • improve performance;
  • improve user experience;
  • conduct internal research; and
  • maintain system reliability.

Where reasonably practicable, we may use aggregated or anonymised information for analytics and product improvement.


8. SECURITY AND FRAUD PREVENTION

We may process personal data to:

  • detect suspicious activity;
  • prevent fraud;
  • prevent abuse;
  • protect user accounts;
  • investigate security incidents;
  • protect our infrastructure;
  • enforce our Terms & Conditions; and
  • comply with applicable laws.

9. COMMUNICATIONS

We may use your contact information to send:

Service-related communications

These may include:

  • account notifications;
  • payment confirmations;
  • failed payment notifications;
  • subscription renewal information;
  • cancellation confirmations;
  • security alerts;
  • system notifications;
  • maintenance notices;
  • important policy updates; and
  • customer support communications.

These communications may be sent even if you have opted out of marketing communications because they are necessary for the operation of your account or Service.


10. MARKETING COMMUNICATIONS

Where permitted by applicable law, we may send marketing communications relating to:

  • new features;
  • new products;
  • promotions;
  • subscription plans;
  • educational materials;
  • business tools;
  • special offers; and
  • other PREMO products or services.

You may opt out of marketing communications by using the unsubscribe mechanism provided in the relevant communication or by contacting us.

Opting out of marketing communications will not prevent us from sending essential service-related communications.


11. AI AND ARTIFICIAL INTELLIGENCE

Certain features of the Service may use artificial intelligence or machine learning technologies.

AI may be used to assist with:

  • review suggestions;
  • review responses;
  • marketing content;
  • captions;
  • business descriptions;
  • messages;
  • templates;
  • content recommendations; and
  • other business-related content.

When you use an AI feature, information you provide may be processed by our AI technology providers where necessary to provide that feature.

We will take reasonable steps to use appropriate contractual, technical or organisational measures where applicable.

AI-generated content may contain inaccuracies or errors.

Customers should not submit highly sensitive personal information into AI features unless it is necessary for the Service and permitted by applicable law.

We do not intentionally use Customer Content to train a publicly available AI model unless separately disclosed or otherwise permitted by applicable law.


12. GOOGLE AND OTHER THIRD-PARTY PLATFORMS

The Service may interact with or provide tools relating to Third-Party Platforms such as:

  • Google;
  • Google Business Profile;
  • Google Reviews;
  • Xiaohongshu (XHS);
  • Meta;
  • Facebook;
  • Instagram;
  • WhatsApp;
  • TikTok;
  • search engines;
  • advertising platforms; and
  • other external platforms.

These Third-Party Platforms have their own privacy policies and terms.

We do not control how Third-Party Platforms collect, use or process information once information is submitted directly to those platforms.

Customers should review the privacy policies of the relevant Third-Party Platform before using their services.


13. GOOGLE REVIEW INFORMATION

Where the Service assists Customers with Google Review-related activities, certain information may be processed to provide the relevant functionality.

This may include:

  • business information;
  • review-related content;
  • review templates;
  • links;
  • customer-generated content; and
  • information voluntarily submitted by users.

We do not guarantee the availability, accuracy, retention or display of information on Google or other Third-Party Platforms.


14. XIAOHONGSHU / XHS

Where Customers use features or guidance relating to Xiaohongshu (XHS), information may be processed to provide the relevant functionality.

Customers remain responsible for complying with XHS's applicable terms, privacy policies and content requirements.

We do not control XHS's data processing activities.

Any information submitted directly to XHS may be processed according to XHS's own privacy policies.


15. THIRD-PARTY SERVICE PROVIDERS

We may use third-party service providers to help us operate the Service.

These may include:

  • payment processors;
  • hosting providers;
  • cloud infrastructure providers;
  • database providers;
  • AI providers;
  • email providers;
  • communication providers;
  • analytics providers;
  • security providers;
  • authentication providers;
  • customer support providers; and
  • other technology providers.

These providers may process personal data on our behalf where necessary to provide their services.

We aim to engage service providers that provide appropriate safeguards for personal data.


16. DISCLOSURE OF PERSONAL DATA

We may disclose personal data where reasonably necessary for the purposes described in this Privacy Policy.

This may include disclosure to:

Service Providers

We may disclose information to service providers that help us operate the Service.

Payment Providers

Payment-related information may be disclosed to payment processors to process transactions and recurring payments.

Technology Providers

Information may be processed by hosting, database, cloud, AI, analytics, security and other infrastructure providers.

Professional Advisors

We may disclose information to:

  • accountants;
  • auditors;
  • lawyers;
  • consultants; and
  • other professional advisors.

Legal and Regulatory Authorities

We may disclose information where required or permitted by law, regulation, court order, government authority or lawful request.

Business Transfers

If our business is sold, merged, reorganised, acquired or transferred, personal data may be transferred as part of the relevant transaction, subject to applicable law.


17. CROSS-BORDER DATA TRANSFERS

Some of our service providers, infrastructure providers or technology partners may operate outside Malaysia.

As a result, personal data may be stored, accessed or processed in countries outside Malaysia.

Where personal data is transferred internationally, we will take reasonable steps to ensure that appropriate safeguards are applied as required by applicable law.

Different countries may have different data protection laws.

By using the Service, you acknowledge that your information may be processed in locations outside Malaysia where necessary to provide the Service.


18. DATA RETENTION

We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy.

The retention period may depend on:

  • the purpose for which the data was collected;
  • whether your account remains active;
  • contractual obligations;
  • legal requirements;
  • tax and accounting requirements;
  • dispute resolution;
  • fraud prevention;
  • security requirements; and
  • legitimate business needs.

When personal data is no longer required, we may delete, anonymise or securely dispose of it, subject to applicable legal requirements.


19. DATA AFTER ACCOUNT CANCELLATION

When a Customer cancels a Subscription, certain personal data may remain in our systems for a reasonable period.

This may include:

  • account information;
  • transaction records;
  • invoices;
  • payment records;
  • support history;
  • security logs; and
  • information required for legal or accounting purposes.

Cancellation of a Subscription does not necessarily result in immediate deletion of all personal data.

Certain information may be retained where required or permitted by law.


20. CUSTOMER REQUEST FOR DATA DELETION

Customers may request deletion of personal data by contacting us.

Where legally and reasonably possible, we will consider requests to delete personal data.

However, deletion may not be possible where information is required for:

  • legal compliance;
  • accounting;
  • tax;
  • fraud prevention;
  • security;
  • dispute resolution;
  • enforcement of contractual rights;
  • regulatory requirements; or
  • other legitimate purposes permitted by law.

21. ACCESS TO PERSONAL DATA

Subject to applicable law, you may request access to personal data that we hold about you.

We may require reasonable verification before processing an access request.

This is intended to protect personal data from unauthorised disclosure.

We may charge a reasonable fee for certain access requests where permitted by applicable law.


22. CORRECTION OF PERSONAL DATA

If you believe that personal data held by us is inaccurate, incomplete or outdated, you may contact us to request correction.

Where appropriate, we will take reasonable steps to correct or update the information.

Customers are responsible for ensuring that information provided to us remains accurate.


23. WITHDRAWAL OF CONSENT

Where processing is based on consent, you may withdraw your consent by contacting us, subject to applicable legal requirements and contractual obligations.

Withdrawal of consent may affect our ability to provide certain features or services.

For example, if certain information is necessary to operate your account, withdrawal of the relevant information may result in the account or feature becoming unavailable.

Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.


24. PERSONAL DATA OF CHILDREN

The Service is intended primarily for businesses and adult users.

We do not knowingly collect personal data directly from children for purposes unrelated to providing the Service.

If you believe that a child has provided personal data to us without appropriate authorisation, please contact us so that we can review and take appropriate action.


25. CUSTOMER RESPONSIBILITY FOR END-USER DATA

If you use the Service to collect, store, manage or process personal data relating to your customers, employees or other individuals, you are responsible for ensuring that:

  • you have a lawful basis for collecting the information;
  • any required notice has been provided;
  • any required consent has been obtained;
  • the information is accurate;
  • the information is collected for appropriate purposes;
  • the information is not used unlawfully; and
  • you comply with applicable privacy and data protection laws.

You should not upload sensitive or unnecessary personal data to the Service.


26. COOKIES AND SIMILAR TECHNOLOGIES

We may use cookies and similar technologies to:

  • maintain login sessions;
  • remember preferences;
  • improve website functionality;
  • improve security;
  • analyse website usage;
  • measure performance;
  • understand how users interact with the Service; and
  • improve user experience.

Cookies may be:

Essential Cookies

Required for core website and account functionality.

Functional Cookies

Used to remember preferences and settings.

Analytics Cookies

Used to understand how users interact with the Service.

Security Cookies

Used to help detect suspicious or malicious activity.

You may be able to control cookies through your browser settings.

Disabling certain cookies may affect the functionality of the Service.


27. ANALYTICS

We may use analytics tools to understand how Customers interact with the Service.

Analytics information may include:

  • pages visited;
  • features used;
  • device information;
  • browser information;
  • approximate location;
  • session duration;
  • interaction events; and
  • technical information.

Where possible, analytics information may be aggregated or anonymised.


28. SECURITY MEASURES

We take reasonable technical and organisational measures to protect personal data against:

  • unauthorised access;
  • accidental loss;
  • misuse;
  • alteration;
  • disclosure;
  • destruction; and
  • other unauthorised processing.

Security measures may include:

  • access controls;
  • authentication;
  • password protection;
  • encrypted communications;
  • server security;
  • monitoring;
  • backups;
  • permission management; and
  • other reasonable technical safeguards.

However, no online system is completely secure.

We cannot guarantee that personal data will never be accessed, disclosed, altered or destroyed due to circumstances beyond our reasonable control.


29. DATA BREACHES AND SECURITY INCIDENTS

If we become aware of a security incident involving personal data, we will assess the incident and take reasonable steps to contain, investigate and address the incident.

Where required by applicable law, we may notify relevant authorities and/or affected individuals.

The nature and timing of any notification will depend on the circumstances and applicable legal requirements.


30. PASSWORDS AND ACCOUNT SECURITY

Customers are responsible for maintaining the confidentiality of their login credentials.

You should:

  • use a strong password;
  • avoid sharing your password;
  • avoid using the same password across multiple services;
  • log out from shared devices; and
  • notify us if you suspect unauthorised access.

We are not responsible for unauthorised access resulting from Customer negligence, compromised credentials or insecure devices outside our reasonable control.


31. LINKS TO OTHER WEBSITES

The Service may contain links to external websites or Third-Party Platforms.

We are not responsible for the privacy practices, security, content or policies of external websites.

Customers should review the privacy policy of any external website before providing personal information.


32. BUSINESS CUSTOMERS AND DATA PROCESSING

Where a business Customer uses the Service to process personal data relating to its own customers, employees or other individuals, the business Customer may determine the purposes for which that information is collected and used.

In such circumstances, the business Customer may be responsible for:

  • providing appropriate privacy notices;
  • obtaining required consent;
  • responding to data subject requests;
  • determining appropriate retention periods;
  • ensuring lawful processing; and
  • complying with applicable data protection obligations.

We may process such information only to provide the Service and in accordance with our contractual relationship with the Customer.


33. NO SALE OF PERSONAL DATA

We do not sell personal data to third parties for their own independent marketing purposes.

We may disclose or share information with service providers where reasonably necessary to operate the Service and provide the functionality requested by Customers.


34. DO NOT TRACK

Some web browsers provide a "Do Not Track" feature.

Because there is currently no universally accepted technical standard for responding to Do Not Track signals, the Service may not respond to such signals in every circumstance.


35. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time.

Changes may be made to reflect:

  • changes in our Service;
  • new features;
  • changes in technology;
  • changes in legal requirements;
  • changes in third-party services; or
  • changes in our data processing practices.

The updated Privacy Policy will be published on our website with a revised "Last Updated" date.

Where required by applicable law, we may provide additional notice regarding material changes.


36. YOUR RIGHTS

Subject to applicable law, you may have rights relating to your personal data, including the right to:

  • request access to personal data;
  • request correction of personal data;
  • request deletion where legally applicable;
  • withdraw consent where processing is based on consent;
  • request information about how personal data is processed; and
  • make a complaint regarding our handling of personal data.

Certain rights may be subject to legal limitations and reasonable verification requirements.


37. COMPLAINTS

If you believe that we have handled your personal data improperly, you may contact us directly so that we can investigate the matter.

We encourage Customers to contact us first so that we can attempt to resolve the issue promptly.

Nothing in this Privacy Policy prevents you from exercising any rights available to you under applicable Malaysian law.


38. CONTACT US

If you have any questions, requests or concerns regarding this Privacy Policy or your personal data, please contact us through the official contact information provided on the PREMO Review System website.

PREMO Review System

Website:
https://review.premostudio.my/

Last Updated: 11 August 2026


39. ACKNOWLEDGEMENT

By using the PREMO Review System, you acknowledge that:

  1. You have read and understood this Privacy Policy.

  2. You understand that personal data may be collected, used, stored and processed for the purposes described above.

  3. You understand that certain Service Providers may process personal data on our behalf.

  4. You understand that certain data may be processed or stored outside Malaysia where necessary to provide the Service.

  5. You understand that payment processing may be handled by third-party payment providers.

  6. You understand that Third-Party Platforms such as Google, Xiaohongshu, Meta, Facebook, Instagram and WhatsApp operate independently and have their own privacy policies.

  7. You understand that if you use the Service to process personal data relating to your own customers, you remain responsible for complying with applicable privacy and data protection requirements relating to those individuals.

  8. You understand that you may contact us regarding access, correction, deletion or other permitted requests relating to your personal data.

  9. You understand that certain personal data may need to be retained after account cancellation for legal, accounting, security, fraud prevention or other legitimate purposes.

  10. You understand that we take reasonable measures to protect personal data but cannot guarantee absolute security of information transmitted or stored online.