Inseller — Data Deletion & Data-Subject Rights Policy

Last updated: 23 June 2026 · MFD Holdings Sdn Bhd

This page tells you how to delete your Inseller account and data, how to exercise your rights under Malaysia's personal data law, and how an end-customer of a merchant can ask for their data to be removed. It also serves as Inseller's official data-deletion instructions URL referenced to our connected partners (TikTok, Meta/Facebook, Shopee). If you arrived here from one of those platforms, the relevant instructions are in Section 8 (Connected Platforms) and Section 10 (End-Customers of a Merchant).

This Policy supersedes the prior "Data Deletion Instructions" page previously published at this URL. It forms part of, and should be read together with, the Inseller Terms of Service and the Inseller Privacy Policy (and, where a merchant has entered into one with us, the Inseller Data Processing Addendum). Capitalised terms used but not defined here have the meaning given in the Terms of Service or Privacy Policy.


1. Who We Are and Scope

1.1. Provider. "Inseller" (the "Service", at https://inseller.my) is operated by MFD Holdings Sdn Bhd (Company No. 201901014519 (1323847-H)), a company incorporated in Malaysia ("Inseller", "we", "us", "our"). Registered office: [insert SSM-registered office address, Muar, Johor, Malaysia]. (Note for finalisation: verify both registration numbers and the full registered-office address against the SSM record with the company secretary.)

1.2. What Inseller is. Inseller is a business-to-business (B2B), multi-tenant software-as-a-service (SaaS) platform — a business operating system for e-commerce teams. It helps merchants run their operations, including order and financial analytics, financial reporting, inventory operations, fulfilment workflows, customer and CRM workflows, marketing and creator-collaboration analytics, customer-support/messaging workflows, and business-intelligence tools. To do this, Inseller both reads data from and, where the Customer authorises, writes data to Connected Platforms on the Customer's behalf, and it processes end-customer (buyer) personal data operationally on the Customer's behalf. Each merchant customer (a "Customer") operates within a tenant-isolated "Workspace" accessed by the Customer's "Authorised Users".

1.3. What this Policy covers. This Policy explains:

  • how a Customer or Authorised User requests deletion of their Inseller account and Workspace data (self-service and by email);
  • what data is deleted versus what may be lawfully retained, and for how long;
  • how disconnecting a Connected Platform stops further data pulls (and write-backs) and revokes access tokens;
  • the data-subject rights available under the Personal Data Protection Act 2010 (as amended), and the additional rights Inseller offers as a matter of policy, and how to exercise them; and
  • how an end-customer of a merchant can request deletion of personal data that the merchant collected and that Inseller processes on the merchant's behalf.

1.4. Defined terms used in this Policy.

  • "Connected Platforms" means the third-party marketplaces, ad networks, analytics, storefront, and messaging services a Customer connects to its Workspace via OAuth or API authorisation. These currently include Shopee, TikTok Shop, TikTok Ads, Facebook/Meta, Shopify, and Google Analytics 4, and may change over time as new integrations are added. For the specific purpose of the data-deletion instructions URL we provide to TikTok, Meta/Facebook, and Shopee, the named platforms are those three; this Policy applies equally to any other integration a Customer enables.
  • "Connector Layer" means Inseller's internal data and connector systems that retrieve, normalise, store, and (where authorised) write back data to Connected Platforms on the Customer's behalf.
  • "Connected Platform Data" means data retrieved from, or written to, Connected Platforms, including orders, fees, costs, ad spend, inventory, fulfilment, and settlement data, and the Customer's end-customers' personal data (for example, buyer names, contact details, shipping addresses, and support-conversation content) processed on the Customer's behalf.
  • "Computed Metrics" means unified profit, margin, ROAS, and similar figures generated by the Service. Computed Metrics are derived outputs and may be estimates; the authoritative source of record for any transaction remains the relevant Connected Platform or the Customer's own systems.

2. Our Dual Role Under the PDPA (Important — Read First)

2.1. Malaysia's Personal Data Protection Act 2010, including amendments introduced by the Personal Data Protection (Amendment) Act 2024 (collectively, the "PDPA"), governs the processing of personal data in commercial transactions in Malaysia. Under the PDPA the relevant terms are "data user" (broadly equivalent to a "data controller" under other regimes) and "data processor" (on whom the 2024 amendment now imposes direct statutory obligations). In this Policy we use "data user / controller" and "data processor". Inseller plays two distinct roles under the PDPA, and which role applies determines who you should contact and who is responsible for a deletion or rights request.

2.2. Inseller as data user / controller. For personal data relating to our own account holders and Authorised Users — for example, the name, work email, login credentials, billing contact, and usage/account records of the people who sign up for and administer a Workspace — Inseller is the data user / controller. For this data, Inseller is responsible for deletion and data-subject rights requests, and you may exercise your rights directly with us (see Sections 3, 4, 6, 7 and 9).

2.3. Inseller as data processor (on the Customer's behalf). For Connected Platform Data — in particular the personal data of a Customer's end-customers (buyers) processed via Connected Platforms — Inseller acts as a data processor processing that data on behalf of, and on the documented instructions of, the Customer. For this data, the Customer is the data user / controller and is the party with the primary, direct obligation to handle data-subject requests. Inseller will assist the Customer as processor (see Section 10), and, as a data processor under the 2024 amendment, will also comply with its own direct statutory obligations (including security and breach-assistance duties).

2.4. Why this distinction matters. If you are an end-customer (buyer) of a merchant who shopped on Shopee, TikTok Shop, or another marketplace, the merchant — not Inseller — is the data user / controller of your data. Your deletion request is routed through the merchant, and Inseller acts only on the merchant's instructions (Section 10). If you are an Inseller account holder or Authorised User, you can request deletion directly from us (Sections 3–4).


3. Deleting Your Inseller Account and Workspace Data

This Section applies to Customers and Authorised Users (Inseller account holders). For the data of a merchant's end-customers, see Section 10.

3.1. Self-Service Deletion

3.1.1. Remove an Authorised User. A Workspace owner or administrator can remove an Authorised User at any time from the Workspace's user-management settings. Removing a user revokes that person's access to the Workspace; it does not, by itself, delete the Workspace or its data.

3.1.2. Close a Workspace / delete the account. A Workspace owner (or an administrator with the necessary permission) may request closure and deletion of the entire Workspace from the account settings, where the in-product option is available, or — if the in-product control is not available for your plan or role — by emailing us per Section 3.2. Closing a Workspace begins the deletion process described in Sections 4 and 5.

3.1.3. Export first. Deletion is irreversible. Before deleting, we recommend you export the data you wish to keep. Authorised Users with the appropriate permission can export Workspace data (such as orders and financial reports) using the in-product export tools. After deletion, we are not able to recover data on your behalf.

3.2. Deletion by Email

3.2.1. If you cannot or prefer not to use self-service, email hello@inseller.my with the subject line "Account & Data Deletion Request". To help us locate the correct records and verify you are entitled to make the request, please include:

  • the email address associated with your Inseller account;
  • the Workspace name (or workspace identifier) you want deleted, if applicable; and
  • whether you are requesting closure of an entire Workspace (only a Workspace owner/administrator can do this) or removal of your own individual user record.

3.2.2. Identity verification. Before acting, we will take reasonable steps to verify the requester's identity and authority. For a request to delete an entire Workspace, we will confirm that the requester is an authorised owner or administrator of that Workspace. We may decline or pause a request where we cannot verify identity or authority, or where acting would prejudice the rights of the Customer (for example, a single Authorised User cannot unilaterally delete a Workspace that belongs to the Customer).

3.3. Effect of Deletion

3.3.1. Once a deletion request is verified and processed, the affected account or Workspace becomes inaccessible, and we delete or irreversibly anonymise the associated personal data, subject to the retention exceptions in Section 5. Computed Metrics derived from deleted data are deleted or are no longer regenerable for that Workspace.

3.3.2. Effect on subscription and billing. Closing a Workspace also terminates the associated subscription and stops future billing for that Workspace. Consistent with the Inseller Terms of Service, fees already paid are non-refundable except where required by law or expressly agreed in writing, and any outstanding fees owed up to the date of closure remain payable. Billing and tax records are retained as described in Section 5.2.


4. What We Delete

Subject to the retention exceptions in Section 5, upon verified deletion of an account or Workspace we delete or irreversibly anonymise:

4.1. Account and identity data of Authorised Users (names, work emails, login credentials, profile and preference settings) held by Inseller as data user / controller.

4.2. Workspace configuration and content (Workspace settings, roles and permissions, saved views, internal notes, and uploaded files).

4.3. Connected Platform Data stored in the Connector Layer for that Workspace — including orders, fees, costs, ad spend, inventory, fulfilment, settlement data, and end-customer personal data (buyer names, contact details, addresses, support-conversation content) processed on the Customer's behalf — except where the Customer (as data user / controller) instructs us otherwise or where a retention exception in Section 5 applies.

4.4. Computed Metrics generated for the Workspace.

4.5. Stored OAuth/API credentials and access tokens for that Workspace's Connected Platforms, which we delete or revoke as described in Section 8.

4.6. We also instruct our infrastructure providers and sub-processors (see Section 11) to delete the relevant data in accordance with our agreements with them and their standard deletion cycles, including the routine purge of backups (see Section 5.4).


5. What We Retain, Why, and For How Long (Retention Exceptions)

5.1. We do not retain personal data longer than necessary for the purposes for which it was processed. However, certain data may be lawfully retained after a deletion request where we have a legal obligation or a legitimate business need. We retain the minimum data required for the specific purpose, restrict access to it, and delete or anonymise it once the purpose is fulfilled.

5.2. Retention categories and periods. The periods below are targets and may vary where a longer period is required by law or by an ongoing matter (see 5.3). (Note for finalisation: confirm the security/audit-log period against actual logging retention, and the backup period against the actual Supabase backup / point-in-time-recovery window, before publishing; if a figure cannot be verified, replace it with "our standard rotation cycle" and remove the hard number.)

CategoryWhat is retainedReasonTarget retention period
Billing, tax & accounting recordsInvoices, payment records, subscription and transaction records (via our billing/payment processor)Compliance with Malaysian tax law and companies/accounting law (including the Income Tax Act 1967 and Companies Act 2016); financial auditUp to 7 years from the relevant financial year, or as required by applicable law
Security & audit logsAuthentication, access, and administrative-action logs (minimised; direct identifiers reduced where possible)Security monitoring, fraud and abuse prevention, incident investigation, demonstrating complianceUp to 24 months (target, subject to verification), or longer if needed for an active investigation
Legal hold / dispute recordsRecords relevant to a claim, dispute, complaint, regulatory request, or legal proceedingEstablishing, exercising, or defending legal claims; complying with lawful requestsFor the duration of the matter plus any applicable limitation period
Suppression / do-not-contact recordsMinimal identifiers needed to honour an opt-out or deletion requestTo ensure we do not re-process data we were asked to stop processingFor as long as needed to honour the request
BackupsEncrypted system backups that may temporarily contain deleted dataDisaster recovery and data integrityPurged on our standard backup-rotation cycle (target, subject to verification: within 90 days); deleted data is not restored to live systems except as part of a verified disaster-recovery event

5.3. Legal holds. Where data is subject to a legal hold (for example, an ongoing dispute, complaint, audit, or regulatory or law-enforcement request), we will retain the relevant data until the hold is lifted, even if this is longer than the periods above, and will then delete or anonymise it.

5.4. Backups. Deletion from live, production systems takes effect promptly on completion (Section 7). Residual copies in encrypted backups are removed on the next applicable backup-rotation cycle (target, subject to verification: within 90 days). During this window, backed-up data is retained only for disaster recovery and is not used for any other purpose.

5.5. Anonymisation and aggregate data. We may retain data that has been irreversibly anonymised or aggregated so that it no longer identifies any individual (for example, anonymous benchmarking or service-improvement statistics). Anonymised data is no longer personal data and is not subject to deletion under this Policy.

5.6. Connected Platform Data — controller instructions. Because Connected Platform Data is processed on the Customer's behalf (Section 2.3), our handling of that data on Workspace deletion follows the Customer's documented instructions and the Customer's own retention obligations, subject to the legal exceptions above.


6. Your Rights

6.1. Statutory PDPA rights (in force). Where Inseller is the data user / controller for your personal data (Section 2.2), you may exercise the following rights under the PDPA as currently in force, subject to the conditions and exceptions in the PDPA:

  • Right of access — to request confirmation of whether we process personal data about you, and a copy of that data.
  • Right to correction — to request correction of personal data that is inaccurate, incomplete, misleading, or out of date.
  • Right to withdraw consent — to withdraw any consent you previously gave for processing that relies on consent. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal, and may mean we can no longer provide part or all of the Service to you.
  • Right to prevent processing likely to cause damage or distress — to require us, by written notice, to cease (or not begin) processing your personal data where that processing is likely to cause substantial, unwarranted damage or distress to you or another person, in accordance with the PDPA.
  • Right to prevent processing for direct marketing — to require us to cease (or not begin) processing your personal data for direct-marketing purposes.

6.2. Data portability (not yet in force). The Personal Data Protection (Amendment) Act 2024 introduces a right to data portability; this right will apply only once the relevant subsidiary regulations and guidelines come into force. Until then, you may export the data you provided to us using the in-product export tools described in Section 3.1.3.

6.3. Additional rights Inseller offers as a matter of policy. Separately from the statutory PDPA rights above, and because the PDPA does not currently contain a standalone general "right to erasure", Inseller offers the following as a policy commitment:

  • Account / data deletion — you may request deletion of your Inseller account and Workspace data as described in Sections 3 and 4. This commitment is subject to the retention exceptions in Section 5.
  • Data export — you may export the data you provided to us using the in-product tools (Section 3.1.3).

6.4. Limits on these rights. Some rights do not apply, or apply only partly, where retention or continued processing is required by law (for example, tax and accounting records), is necessary to establish, exercise, or defend legal claims, or is necessary for security, fraud prevention, or the integrity of the Service. Where we cannot fully act on a request, we will tell you why.

6.5. End-customer (buyer) requests are different. If you are an end-customer of a merchant and your data was processed via a Connected Platform, Inseller is a data processor, not the data user / controller — please see Section 10. We will not, on our own initiative, delete or alter a merchant's Connected Platform Data in response to a request from that merchant's end-customer without the merchant's instruction, except where required by law.


7. How to Exercise Your Rights & Our Turnaround Commitment

7.1. How to submit a request. Where Inseller is the data user / controller of your data, you may exercise any right in Section 6 by:

  • using the relevant self-service controls in your account settings (for example, account deletion, profile correction, data export, or marketing unsubscribe); or
  • emailing hello@inseller.my with a clear subject line (for example, "PDPA Access Request", "Correction Request", or "Account & Data Deletion Request") and enough detail for us to locate your records and identify the right you wish to exercise.

7.2. Fees. The PDPA permits us to charge a prescribed fee for certain requests (such as a data-access request), subject to the limits in the Personal Data Protection (Fees) Regulations. We will tell you of any applicable fee before we act. We may decline requests that are repetitive, or that we are not legally or contractually required to fulfil, and will explain our reasons.

7.3. Identity verification. To protect your data, we will take reasonable steps to verify your identity (and, for requests made on behalf of someone else, the requester's authority) before acting. We may ask for additional information for this purpose; we use it only to process the request.

7.4. Turnaround commitment.

  • We will acknowledge your request within 7 days of receipt.
  • We aim to complete verified, eligible requests within 21 days of successful identity verification, and in any event within the maximum period required under the PDPA for the relevant request type.
  • If a request is complex or we need more time to comply with a legal obligation, we will tell you before the applicable period expires, explain the reason, and give you an updated timeline.

7.5. If we decline. If we refuse a request in whole or in part, we will tell you the reason and inform you of your right to lodge a complaint with the Personal Data Protection Commissioner (Pesuruhjaya Perlindungan Data Peribadi), through the Department of Personal Data Protection (Jabatan Perlindungan Data Peribadi, JPDP), www.pdp.gov.my (the "Commissioner / JPDP").


8. Connected Platforms — Disconnecting, Stopping Data Pulls, and Revoking Tokens

8.1. What disconnecting does. A Customer may disconnect any Connected Platform from its Workspace at any time from the Workspace's integration/connection settings. When you disconnect a Connected Platform:

  • Inseller stops reading from and writing to that platform for your Workspace. The Connector Layer ceases scheduled and on-demand retrieval, and any authorised write-back, for the disconnected integration.
  • We revoke or delete the stored OAuth/API access and refresh tokens for that integration so they can no longer be used to access the platform on your behalf. Where the platform supports programmatic token revocation, we call its revocation endpoint; in all cases we delete the credential from our active systems.
  • No new Connected Platform Data is added to your Workspace from that source after disconnection.

8.2. Data already retrieved. Disconnecting stops future pulls and write-backs but does not by itself delete data already retrieved and stored in your Workspace before disconnection. To delete data already held, use the deletion routes in Section 3 (account/Workspace deletion) or instruct us as the data user / controller of that Connected Platform Data.

8.3. Revoking on the platform side. You may also revoke Inseller's access directly from the Connected Platform's own settings (for example, your Meta/Facebook "Business Integrations" or app settings, your TikTok Shop / TikTok Ads connected-app settings, your Shopee authorised-app settings, your Shopify "Apps" settings, or your Google account "Third-party access" settings). Revoking from the platform side will likewise prevent further access; we recommend doing this in addition to disconnecting within Inseller if you want belt-and-braces assurance.

8.4. Platform-initiated deletion signals. Where a Connected Platform sends Inseller a data-deletion or de-authorisation signal in respect of your account (for example, a platform data-deletion callback), we will process it in accordance with that platform's requirements and this Policy. This page is the data-deletion instructions URL we provide to TikTok, Meta/Facebook, and Shopee for that purpose.


9. Authorised Users vs. Customers (Who Can Do What)

9.1. Customer (data user / controller of its Workspace data). The Customer is the entity that contracts for the Service and controls its Workspace. The Customer (acting through a Workspace owner or administrator) is responsible for managing Authorised Users, disconnecting Connected Platforms, exporting data, and requesting Workspace deletion.

9.2. Authorised User (individual). An Authorised User may exercise rights over their own personal data held by Inseller as data user / controller (for example, correcting their profile or requesting deletion of their individual user record), but cannot unilaterally delete the Customer's Workspace or the Customer's Connected Platform Data.

9.3. Departing staff/vendors. Consistent with the Terms of Service, Workspace owners and administrators are responsible for promptly removing access for staff or vendors who no longer require it.


10. End-Customers of a Merchant (Buyers) — How to Request Deletion

10.1. You are dealing with the merchant, not Inseller, as data user / controller. If you bought from a merchant on Shopee, TikTok Shop, or another marketplace, and that merchant uses Inseller, then the merchant is the data user / controller of your personal data and decides how it is used. Inseller only processes that data on the merchant's behalf as a data processor (Section 2.3).

10.2. Where to send your request. To request access to, correction of, or deletion of your personal data, please contact the merchant you purchased from (and/or the marketplace where you placed your order). The merchant is responsible for receiving and deciding on your request as the data user / controller.

10.3. How Inseller assists. When a merchant (as data user / controller) instructs us to act on a verified end-customer request, Inseller will, as data processor, assist the merchant by deleting, anonymising, correcting, or providing a copy of the relevant end-customer personal data held in the merchant's Workspace, subject to the retention exceptions in Section 5 and the merchant's own legal obligations. We aim to action the merchant's verified instruction without undue delay and, in any event, within the timeframes set out in our Data Processing Addendum (or, absent a DPA, within the turnaround targets in Section 7.4). Merchants can also delete an individual buyer's record from within the active Workspace using the in-product customer-management/export tools while the Workspace remains open.

10.4. If you contact Inseller directly. If an end-customer contacts us directly with a deletion or rights request relating to a merchant's data, we will, where we can reasonably identify the relevant merchant, forward the request to that merchant (the data user / controller) and/or direct you to contact the merchant, and we will assist the merchant in responding. We will not delete or alter a merchant's Connected Platform Data on our own initiative without the merchant's instruction, except where we are required to do so by law.

10.5. Underlying marketplace data. Deleting data held within Inseller does not delete the corresponding records held by the marketplace itself (Shopee, TikTok Shop, Meta, etc.) or by the merchant in other systems. To address those, contact the marketplace and the merchant directly.


11. Sub-Processors and Infrastructure

11.1. To provide the Service, Inseller uses a small number of trusted infrastructure providers and sub-processors. Our current sub-processors include:

  • Supabase — database, authentication, and storage;
  • Vercel — application hosting;
  • Stripe — subscription billing and payment processing;
  • Resend — transactional email; and
  • AI / large-language-model (LLM) providersAnthropic (Claude), Google (Gemini), and OpenAI — used to power in-product AI features. (Note for finalisation: confirm before claiming any zero-data-retention / no-training terms for these providers; only state ZDR where contractually in place.)

11.2. Connected Platforms are not sub-processors. Connected Platforms (Shopee, TikTok Shop, TikTok Ads, Facebook/Meta, Shopify, Google Analytics 4, and any others a Customer enables) are upstream data sources from which we retrieve data, and destinations to which we write data, on the Customer's behalf. They are not sub-processors of Inseller.

11.3. The sub-processor list in 11.1 is non-exhaustive and may change. For the current authoritative sub-processor list, see our published sub-processor list (referenced in the Privacy Policy / Data Processing Addendum). When we delete your data, we also instruct relevant sub-processors to delete the corresponding data in line with our agreements and their deletion cycles (see Section 4.6 and Section 5.4).


12. Cross-Border Data Transfers

12.1. Several of our sub-processors and Connected Platforms store or process personal data outside Malaysia (for example, Supabase, Vercel, Stripe, Resend, the LLM providers, and certain Connected Platforms). The PDPA (as amended by the Personal Data Protection (Amendment) Act 2024) regulates the transfer of personal data outside Malaysia, moving from the previous whitelist approach toward a regime based on adequacy and appropriate safeguards.

12.2. Where we transfer personal data outside Malaysia, we do so on a lawful basis permitted by the PDPA — for example, because the transfer is necessary for the performance of, or steps taken at the Customer's request in connection with, our contract with the Customer; because the Customer has consented; because the recipient is in a place with substantially similar or adequate protection; or under appropriate contractual safeguards (such as data-processing terms) that require the recipient to protect the data to a standard consistent with the PDPA. (Note for finalisation: confirm the specific lawful basis and the location(s) of hosting for each sub-processor with counsel.)


13. Lawful Bases for Processing

13.1. Where Inseller is the data user / controller, we process personal data on one or more of the following bases, as permitted by the PDPA:

  • Performance of a contract — to provide, secure, maintain, and support the Service for account holders and Authorised Users.
  • Compliance with a legal obligation — for example, tax, accounting, and record-keeping requirements.
  • Consent — where we rely on consent (for example, certain marketing communications), which you may withdraw at any time (Section 6.1).
  • Legitimate operational interests permitted under the PDPA — for example, security, fraud prevention, network and information-systems integrity, and service improvement, balanced against your interests and rights.

13.2. Where Inseller is a data processor for a Customer's Connected Platform Data, the lawful basis for processing that data is determined by the Customer as data user / controller; Inseller processes it on the Customer's documented instructions.


14. Data Security and Breach Notification

14.1. We apply administrative, technical, and physical safeguards designed to protect personal data, including tenant isolation between Workspaces, access controls, encryption of data in transit and at rest, and logging.

14.2. Breach notification. Where Inseller is the data user / controller and a personal data breach has occurred that meets the applicable notification threshold, we will notify the Commissioner / JPDP as soon as practicable and, in line with current breach-notification guidance, within 72 hours of becoming aware of the breach, and will notify affected data subjects without undue delay (and, where the breach is likely to cause significant harm, within 7 days), as required by the Personal Data Protection (Amendment) Act 2024 and its breach-notification guidelines. Where Inseller acts as data processor, we will notify the affected Customer (data user / controller) without undue delay so that the Customer can meet its own notification obligations, and will assist the Customer as required. (Note for finalisation: confirm the exact statutory timeframes and thresholds with counsel before publication.)


15. Children's Data

15.1. The Service is a B2B tool and is not directed to children. We do not knowingly collect personal data directly from children through the Service. Because Inseller processes a merchant's end-customer (buyer) data on the merchant's behalf, that data may relate to individuals of any age that the merchant lawfully collected; the merchant, as data user / controller, is responsible for the lawful basis for collecting and using such data.


16. Data Protection Officer & Contact

16.1. In accordance with the Personal Data Protection (Amendment) Act 2024, Inseller is appointing (or has appointed) a Data Protection Officer (DPO) and will notify the DPO's contact details to the Commissioner / JPDP as required. (Note for finalisation: confirm the DPO appointment and registration status before publication; do not assert an appointed/registered DPO until this is in place.) You may contact our DPO and our privacy team for any deletion request, data-subject-rights request, or question about this Policy:

Inseller — MFD Holdings Sdn Bhd Attn: Data Protection Officer Email: hello@inseller.my (subject line: "Data Protection" or "DPO") Website: https://inseller.my Registered office: [insert SSM-registered office address, Muar, Johor, Malaysia]

16.2. You also have the right to lodge a complaint with the Personal Data Protection Commissioner (Pesuruhjaya Perlindungan Data Peribadi), through the Department of Personal Data Protection (Jabatan Perlindungan Data Peribadi, JPDP), www.pdp.gov.my.


17. Governing Law, Cross-References, and Changes

17.1. Governing law and jurisdiction. This Policy is governed by the laws of Malaysia, consistent with the Inseller Terms of Service, and any dispute relating to it is subject to the exclusive jurisdiction of the courts of Malaysia — without prejudice to your statutory rights under the PDPA and your right to complain to the Commissioner / JPDP.

17.2. Related documents. This Policy should be read together with the Inseller Terms of Service, the Inseller Privacy Policy, and (for Customers who have entered into one) the Inseller Data Processing Addendum and sub-processor list. In the event of a conflict between this Policy and a signed Data Processing Addendum regarding the processing of Connected Platform Data, the Data Processing Addendum prevails to the extent of the conflict.

17.3. Supersession and versioning. This Policy supersedes the previous "Data Deletion Instructions" page published at this URL. We will keep prior versions on file and make them available on request. The current version is identified by the "Last updated" date at the top of this Policy.

17.4. Changes to this Policy. We may update this Policy from time to time. If we make material changes, we will give reasonable advance notice — by updating the "Last updated" date above and, where appropriate, notifying Customers by email or in-product — before the change takes effect. Where a change requires your consent under applicable law, we will obtain it. This Policy describes our practices and does not, by itself, waive any rights you have under the PDPA.


© 2026 MFD Holdings Sdn Bhd. All rights reserved.