Inseller Privacy Policy

Last updated: 23 June 2026 · MFD Holdings Sdn Bhd


1. Introduction and Scope

1.1 This Privacy Policy ("Policy") explains how MFD Holdings Sdn Bhd (Registration No. 201901014519 (1323847-H)), a company incorporated in Malaysia ("Inseller", "we", "us", or "our"), collects, uses, discloses, stores, transfers, retains, and protects personal data in connection with the Inseller software-as-a-service platform and related websites, applications, dashboards, application programming interfaces (APIs), connectors, AI features, and support channels (collectively, the "Service"), accessible at https://inseller.my.

1.2 Inseller is a business-to-business (B2B), multi-tenant commerce-analytics and decision-support platform. Each business customer (a "Customer", "merchant", or "you" where the context refers to the contracting business) is provided with a tenant-isolated environment (a "Workspace") that may be accessed by individuals the Customer authorises ("Authorised Users").

1.3 This Policy is written to comply with the Personal Data Protection Act 2010 of Malaysia, including the amendments introduced by the Personal Data Protection (Amendment) Act 2024 (together, the "PDPA"), and with applicable subsidiary regulations, codes of practice, and guidelines issued under it.

1.4 This Policy forms part of, and should be read together with, the Inseller Terms of Service and any other policy or agreement we reference. Where we publish or enter into a Data Processing Agreement (DPA), Cookie Policy, Acceptable Use Policy, or Sub-processor List, those documents also apply to the extent relevant. In the event of any conflict between this Policy and a signed DPA between you and us, the signed DPA prevails with respect to the processing of personal data that we handle on your behalf.

1.5 Certain terms are defined in Section 3 of this Policy. Any other capitalised term used but not defined in this Policy has the meaning given to it in the Terms of Service.


2. Who We Are and Our Two Roles Under the PDPA

The PDPA distinguishes between a "data user" (the person who processes personal data, or who controls or authorises the processing of personal data, broadly equivalent to a "controller" under other regimes) and a "data processor" (a person who processes personal data solely on behalf of a data user, and not for that person's own purposes). Inseller operates in two distinct roles depending on the category of personal data concerned.

2.1 Inseller as a Data User

For the personal data of our own account holders, Customers, Authorised Users, billing contacts, prospects, website visitors, and support contacts, Inseller is the data user. We determine the purposes and means of processing this data — for example, to create and administer accounts, authenticate users, bill subscriptions, provide support, secure the Service, and communicate with you. Sections 4 to 16 of this Policy describe how we handle personal data in this capacity.

2.2 Inseller as a Data Processor

For the personal data of a Customer's own end-customers (for example, the buyers, recipients, and contacts whose details flow into the Service as part of Connected Platform Data — see Section 3), Inseller acts as a data processor on behalf of the Customer. In this role:

  • the Customer is the data user in respect of its end-customers' personal data;
  • we process that personal data only on the Customer's documented instructions (which include the configuration choices the Customer makes when it connects platforms, sets up its Workspace, and uses the Service), and for the purpose of providing the Service to the Customer;
  • we do not use the Customer's end-customer personal data for our own independent purposes, and we do not sell or rent it; and
  • the Customer remains responsible for its own compliance obligations as a data user, including providing notices to, and (where required) obtaining consent from, its end-customers — see Section 13.

Section 12 (Connected Platform Data) and Section 13 (Customer obligations) describe how we handle personal data in this processor capacity.

2.3 Contact and Data Protection Officer

For all privacy matters, including in respect of either role above, you may contact us at:

Inseller — MFD Holdings Sdn Bhd Data Protection Officer / Privacy Team Email: hello@inseller.my (please mark the subject line "Privacy Inquiry" or, for incidents, "Security Incident") Website: https://inseller.my Registered address: No 6, Jalan Kempas 6, 84200 Bukit Bakri, Muar, Johor, Malaysia

The Personal Data Protection (Amendment) Act 2024 introduced a requirement for certain data users to appoint a Data Protection Officer (DPO). We will determine whether this requirement applies to us under the implementing regulations and, where it does, we will name a specific DPO (person or role) and a registered contact in the finalised version of this Policy. Until then, DPO-related correspondence may be sent to the email address above.


3. Key Definitions

For clarity, the following terms are used throughout this Policy:

  • "Customer" means a business that subscribes to or uses the Service under the Terms of Service and on whose behalf a Workspace is provisioned.
  • "Workspace" means the tenant-isolated environment provisioned for a Customer within the Service.
  • "Authorised User" means an individual whom a Customer authorises to access its Workspace (for example, a Workspace owner, administrator, or member).
  • "Connected Platforms" means the third-party commerce, advertising, messaging, and analytics platforms that a Customer connects to its Workspace via OAuth or API (currently including Shopee, TikTok Shop, TikTok Ads, Facebook / Meta, Shopify, and Google), as updated from time to time. Connected Platforms are sources of data, not sub-processors engaged by us.
  • "Connector Layer" means Inseller's internal data and connector systems used to retrieve, normalise, and store data from Connected Platforms (referred to within the product as "MCP").
  • "Connected Platform Data" means data that we retrieve from Connected Platforms on the Customer's behalf, including orders, fees, costs, ad spend, inventory, settlement data, and derived financial records, and the Customer's end-customers' personal data (for example, buyer names, contact details, and delivery addresses).
  • "Computed Metrics" means unified figures derived by the Service, such as profit, margin, and return on ad spend (ROAS). Computed Metrics are estimates and decision-support outputs; they are not an authoritative system of record.
  • "Personal data", "sensitive personal data", "data user", "data processor", "data subject", and "processing" have the meanings given to them under the PDPA.

4. Categories of Personal Data We Collect

We collect and process the following categories of personal data. Not all categories apply to every individual.

4.1 Account and Identity Data (Inseller as data user)

Information used to create, secure, and administer accounts and Workspaces, including: name, business email address, telephone number, job title or role, Workspace name and membership, role and permission assignments, authentication identifiers, password hashes and multi-factor authentication settings, profile preferences, and language/locale settings.

4.2 Billing and Subscription Data (Inseller as data user)

Information used to manage subscriptions and payments, including: billing contact name and email, billing address and tax details, subscription plan and status, invoices, and transaction and payment-status records. Card and payment-credential details are collected and processed by our payment provider (Stripe) and are not stored on Inseller's own systems. We receive limited, tokenised, or summary payment information from Stripe (for example, the last four digits of a card, card brand, payment outcome, and subscription identifiers).

4.3 Usage, Device, Log, and Cookie Data (Inseller as data user)

Information collected automatically when you access the Service, including: IP address, approximate location derived from IP, device and browser type and settings, operating system, application interactions and feature usage, pages and screens viewed, session and event timestamps, referral information, log files, error and diagnostic reports, security and authentication events, and fraud-prevention signals. Some of this data is collected through cookies and similar technologies — see Section 10.

4.4 Support and Communications Data (Inseller as data user)

Information you provide when you contact us or that is generated through support interactions, including: support tickets and messages, email correspondence, attachments and screenshots you choose to share, feedback, survey responses, and records of communications relating to the Service.

4.5 AI Feature Data (Inseller as data user, on Customer instruction)

Where you use in-product AI features, we process the prompts, queries, and the Service data made available to those features in order to generate responses, summaries, and decision-support outputs. See Section 8.4 for how we handle data shared with AI/LLM providers.

4.6 Connected Platform Data, including end-customer personal data (Inseller as data processor)

Where a Customer connects a Connected Platform, we retrieve Connected Platform Data on the Customer's behalf. This includes commercial data (orders, fees, costs, ad spend, inventory, settlement data, and derived financial records) and may include the personal data of the Customer's end-customers, such as buyer names, usernames or handles, contact details (including phone numbers and email addresses), delivery and billing addresses, order and transaction records, messaging or chat interactions, and related buyer interactions. Where a Customer uses messaging-orchestration features, this may include end-customer phone numbers and message content processed through a messaging provider (see Section 8.1). Inseller processes this end-customer personal data solely as a data processor on the Customer's behalf, as described in Sections 2.2 and 12.

4.7 Sensitive Personal Data

We do not require, and ask that you do not submit through the Service, sensitive personal data (such as information about physical or mental health, religious or other beliefs, political opinions, or the commission of offences) except where strictly necessary and lawful. The PDPA requires explicit consent for the processing of sensitive personal data. Where any sensitive personal data is processed, it will be on the basis of explicit consent or another lawful ground under the PDPA. National identification numbers, financial account numbers, or similar identifiers should only be provided where genuinely required for a service or by law.


5. Sources of Personal Data

We obtain personal data from the following sources:

  • Directly from you — when you register, configure a Workspace, invite or manage Authorised Users, subscribe, contact support, complete forms, or otherwise interact with the Service or our website.
  • Automatically — through your use of the Service, via cookies, log data, and similar technologies (see Sections 4.3 and 10).
  • From your organisation — for example, when a Workspace owner or administrator creates an account for you, assigns you a role, or invites you as an Authorised User.
  • From our payment provider — limited billing and payment-status information from Stripe.
  • From Connected Platforms — Connected Platform Data (including end-customer personal data) retrieved on the Customer's behalf, where a Customer has connected the relevant platform via OAuth/API. We process this data as a data processor.
  • From service providers and sub-processors — for example, security, infrastructure, analytics, and error-monitoring information generated by the providers that help us operate the Service (see Section 8).

6. Purposes of Processing and Legal Basis

We process personal data only where a lawful basis under the PDPA applies. The PDPA operates on a consent-centred model: as a general rule, processing requires the data subject's consent (which may be express or, in the circumstances recognised by the PDPA, deemed), unless one of the limited grounds in section 6(2) of the PDPA applies. Those grounds are that the processing is necessary:

  • for the performance of a contract to which the data subject is a party;
  • for the taking of steps at the data subject's request with a view to entering into a contract;
  • for compliance with a legal obligation to which the data user is subject (other than a contractual obligation);
  • to protect the vital interests of the data subject;
  • for the administration of justice; or
  • for the exercise of any functions conferred on a person by or under any law.

The table below indicates the basis(es) on which we rely for each purpose. Where we rely on consent, you may withdraw that consent as described in Section 9.

#PurposePrimary lawful basis under the PDPA
6.1Creating, administering, authenticating, and securing accounts and Workspaces; managing Authorised Users, roles, and permissionsNecessary for performance of the contract (Terms of Service)
6.2Providing, operating, and maintaining the Service, including retrieving and normalising Connected Platform Data and generating Computed MetricsNecessary for performance of the contract; (for end-customer personal data) processing on the Customer's instructions as data processor
6.3Processing subscriptions, invoices, billing, payments, renewals, and disputes (via Stripe)Necessary for performance of the contract; compliance with a legal obligation (tax/accounting record-keeping)
6.4Providing customer support and responding to enquiriesNecessary for performance of the contract; consent (for support you initiate)
6.5Sending service, security, transactional, and administrative communications (for example, transactional emails via Resend)Necessary for performance of the contract
6.6Securing the Service, monitoring for and preventing fraud, abuse, and unauthorised access, and maintaining audit logsCompliance with a legal obligation; necessary for performance of the contract (to deliver a secure Service); (where applicable) protecting vital interests
6.7Maintaining, troubleshooting, debugging, and improving the Service, including aggregated and de-identified analyticsConsent (where given for non-essential analytics); otherwise carried out on aggregated or de-identified data that does not identify you
6.8Providing in-product AI features that you choose to useNecessary for performance of the contract; consent (where AI features are optional)
6.9Sending marketing or promotional communications about the ServiceConsent / deemed consent at sign-up, withdrawable at any time, with an opt-out always available (see Sections 9.4 and 9.6)
6.10Complying with legal, regulatory, audit, tax, and law-enforcement obligations, and establishing, exercising, or defending legal claimsCompliance with a legal obligation; administration of justice; exercise of functions conferred by law
6.11Effecting a corporate transaction (merger, acquisition, financing, or business transfer)Consent and/or as necessary in connection with the contract, subject to the safeguards in Section 8.3

Where, in respect of any of the above, no statutory ground in section 6(2) applies and the processing is genuinely discretionary (such as non-essential analytics or marketing), we rely on your consent and will obtain it where required by the PDPA. We will not process personal data for a materially new purpose that is incompatible with the purposes above without providing notice and, where required, obtaining consent.


7. Obligatory vs Voluntary Provision

Some personal data is required to provide the Service — for example, account, identity, and billing data. If you do not provide it, we may be unable to create your account, complete your subscription, or make the Service available to you. Other data is voluntary (for example, optional profile details or feedback), and not providing it will not prevent you from using core features. Where we collect data on a Customer's behalf from Connected Platforms, the scope is determined by the platforms the Customer chooses to connect and the permissions it grants.


8. Disclosure, Sharing, and Sub-processors

We do not sell, rent, or trade personal data. We disclose personal data only as described below, and we require our service providers to protect personal data under contractual obligations consistent with the PDPA.

8.1 Service providers and sub-processors

We engage trusted third parties to host, operate, secure, bill, support, monitor, and analyse the Service. The table below lists our principal sub-processors. This list reflects our current principal sub-processors and may change over time; a current, complete sub-processor list is, or will be, made available on request and (where published) via our Sub-processor List.

Sub-processorFunctionNature of data
SupabaseDatabase, authentication, and file storageAccount, identity, usage, support, and Connected Platform Data (including end-customer personal data within the Service)
VercelApplication hosting and deliveryUsage, device, log, and request data
StripeSubscription billing and payment processingBilling and payment data
ResendTransactional and service email deliveryRecipient email address and message content
PostHogProduct analyticsUsage, device, IP address, and user/event identifiers
SentryError and crash monitoringLog, diagnostic, and limited request and user context (which may include personal data present in error context)
Google Analytics (GA4)Website / product analyticsUsage, device, and IP address
respond.ioMessaging and WhatsApp orchestration (where the Customer enables it)End-customer contact data, including phone numbers, and message content (processor-role data handled on the Customer's behalf)
AI / LLM providers (Anthropic, Google, and OpenAI)Powering in-product AI featuresPrompts, queries, and the Service data you make available to those features
Connected Platforms (Shopee, TikTok Shop, TikTok Ads, Facebook / Meta, Shopify, Google)Data sources connected by the Customer via OAuth/APIConnected Platform Data retrieved on the Customer's behalf

We also use operational tools such as Telegram, Slack, and Notion for internal alerting, team communication, and operational record-keeping. Where any personal data flows to these tools, it does so only to operate, monitor, and support the Service, and we limit such flows to what is necessary for those purposes.

Where a signed DPA applies, we will handle changes to sub-processors in accordance with that DPA, including any notification or objection rights.

Note that Connected Platforms are data sources, not sub-processors we engage: the Customer establishes the connection and authorises the data flow. Each Connected Platform processes data under its own terms and privacy policy, over which we have no control.

8.2 Connected Platform Data is processed on the Customer's behalf

Personal data within Connected Platform Data — in particular the Customer's end-customers' personal data — is processed by us as a data processor on the Customer's behalf and disclosed only to the sub-processors above strictly to provide the Service. We do not disclose it for our own purposes.

8.3 Other permitted disclosures

We may also disclose personal data:

  • to comply with the law — to courts, regulators, or law-enforcement and government authorities where required by valid legal process or to establish, exercise, or defend legal claims;
  • to protect rights and safety — where reasonably necessary to protect the rights, property, or safety of Inseller, our Customers, their end-customers, or the public, and to prevent fraud or abuse; and
  • in a corporate transaction — in connection with a merger, acquisition, financing, reorganisation, or sale of assets, subject to the recipient agreeing to protect personal data consistent with this Policy.

8.4 AI / LLM providers

Where you use in-product AI features, relevant prompts and Service data are transmitted to AI/LLM providers (currently Anthropic, Google, and OpenAI) to generate outputs. We engage such providers under terms intended to restrict their use of your data to providing the feature to us (for example, not training general models on your data, where such terms are available). AI outputs (Computed Metrics and AI responses) are decision-support estimates and should not be treated as authoritative records or professional advice.


9. Data Subject Rights

Subject to the conditions and exceptions under the PDPA, you have the following rights in respect of your personal data:

  • 9.1 Right of access — to request confirmation of whether we process your personal data and to be provided with a copy of it.
  • 9.2 Right to correction — to request correction of personal data that is inaccurate, incomplete, misleading, or out of date.
  • 9.3 Right to limit / restrict processing — to require us to limit the processing of your personal data in the circumstances permitted by the PDPA.
  • 9.4 Right to withdraw consent — where processing is based on consent, to withdraw that consent at any time. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal, and may affect our ability to provide certain features.
  • 9.5 Right to prevent processing likely to cause damage or distress — to require us to stop or not begin processing that is likely to cause unwarranted and substantial damage or distress.
  • 9.6 Right to prevent direct marketing — to require us, at any time, to stop processing your personal data for direct marketing. You can opt out of marketing communications via the unsubscribe link in any marketing email or by contacting us.
  • 9.7 Right to data portability — in accordance with the Personal Data Protection (Amendment) Act 2024, to request that your personal data be transmitted, where technically feasible, to another data user.

Exercising your rights. Requests can be made by emailing hello@inseller.my with the subject line "Privacy Inquiry". We may need to verify your identity before acting on a request. We will respond within 21 days as required by the PDPA, or we will notify you within that period if an extension is reasonably required because of the complexity or number of requests. Where the PDPA permits a fee for certain requests (such as data access), we will inform you in advance. If we decline a request, we will explain our reasons to the extent permitted by law and inform you of your right to lodge a complaint with the Personal Data Protection Commissioner (see Section 20).

Requests relating to end-customer (Connected Platform) data. Because we act as a data processor for a Customer's end-customer personal data, requests from a Customer's end-customers should be directed to the relevant Customer (the data user). If we receive such a request directly, we will, where appropriate, refer the individual to the Customer and/or assist the Customer in responding, in accordance with our agreement with that Customer.


10. Cookies and Similar Technologies

We use cookies and similar technologies for essential functionality (such as authentication and security), to remember preferences, and to understand and improve how the Service is used.

  • Essential cookies are necessary for the Service to function (for example, authentication and security) and are always used.
  • Analytics cookies and similar technologies help us understand usage and improve the Service. These are provided through analytics tools including PostHog and Google Analytics (GA4). Where required by law, non-essential analytics cookies are used only with your consent, and you can control cookies through your browser settings and any in-product preference controls.

11. Data Security (PDPA Security Principle)

In accordance with the Security Principle under the PDPA, we take practical steps to protect personal data from loss, misuse, modification, unauthorised or accidental access or disclosure, alteration, or destruction. Our measures include:

  • encryption of personal data in transit and at rest;
  • Workspace-level tenant isolation so that each Customer's data is logically segregated, enforced at the database layer (including row-level security);
  • role-based access controls and the principle of least privilege for Authorised Users and our personnel;
  • private file storage buckets and signed, time-limited access to files;
  • audit logging, authentication monitoring, and fraud-prevention signals;
  • secure software-development practices, dependency scanning, and secret-management controls; and
  • periodic security testing and review of our providers' security posture.

We require our personnel and sub-processors to keep personal data confidential and to apply appropriate safeguards. Authorised Users and Customers also play a role in security and must keep credentials confidential, manage roles and permissions responsibly, and promptly remove access for departed staff or vendors (see the Terms of Service). While we take security seriously, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.


12. Connected Platform Data — How We Handle It as Processor

12.1 When a Customer connects a Connected Platform (for example, Shopee, TikTok Shop, TikTok Ads, Facebook / Meta, Shopify, or Google, as updated from time to time) via OAuth/API, Inseller's Connector Layer retrieves Connected Platform Data on the Customer's behalf and stores it within the Customer's tenant-isolated Workspace.

12.2 Connected Platform Data may include the personal data of the Customer's end-customers (for example, buyer names, contact details including phone numbers, and delivery addresses, and — where messaging features are enabled — message content). Inseller processes this personal data solely as a data processor on the Customer's documented instructions and only to provide the Service, generate Computed Metrics, and support the Customer's operations within the Workspace.

12.3 We do not use the Customer's end-customer personal data for our own purposes, do not sell or rent it, and disclose it only to the sub-processors listed in Section 8 strictly for the purpose of operating the Service, or as required by law.

12.4 The Customer may disconnect a Connected Platform at any time, which will stop further retrieval of new Connected Platform Data from that platform. Treatment of previously retrieved data is addressed in Section 14 (Retention) and any applicable DPA.

12.5 Computed Metrics and derived financial records produced from Connected Platform Data are estimates and decision-support outputs and are not a system of record for the Customer's underlying commercial or personal data.


13. Customer Obligations Regarding Their End-Customers

Because Inseller acts as a data processor for end-customer personal data, the Customer is the data user and is responsible for its own PDPA compliance in respect of its end-customers. In particular, the Customer must:

  • have a valid lawful basis (including, where required, consent or another permitted ground under the PDPA, the Connected Platforms' terms, and applicable law) to collect end-customer personal data and to have it processed by Inseller as a processor;
  • provide its end-customers with the privacy notices required by law, including informing them that their data may be processed by service providers such as Inseller for analytics and operational purposes;
  • ensure that connecting a platform and importing its data into the Workspace does not breach the Connected Platform's terms or any agreement with the end-customer;
  • only grant Workspace and data access to Authorised Users who are permitted to handle such data, and manage roles, permissions, and offboarding responsibly; and
  • respond to its own end-customers' data subject requests as the data user, with our reasonable assistance as set out in any DPA and in Section 9.

The Customer indemnifies Inseller in respect of claims arising from the Customer's failure to meet these obligations, as further set out in the Terms of Service and/or any DPA.


14. Data Retention

14.1 We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to provide the Service, comply with legal, tax, accounting, audit, and regulatory obligations, resolve disputes, and enforce our agreements.

14.2 Account, Workspace, and operational data is generally retained while the relevant Workspace remains active and for a reasonable period afterwards to allow for reactivation, export, billing reconciliation, and dispute resolution.

14.3 Connected Platform Data (including end-customer personal data) is retained on the Customer's behalf for as long as needed to provide the Service, subject to the Customer's instructions and any applicable DPA. On termination, and following any agreed export or grace period, we will delete or anonymise such data in accordance with the DPA (where one applies), our internal retention schedule, and applicable law (except where retention is required by law).

14.4 Billing, tax, security, and audit records may be retained for longer periods where required by law or for legitimate business purposes.

14.5 When personal data is no longer required, we take reasonable steps to delete, irreversibly anonymise, or securely archive it. Specific retention periods can be provided on request and will, where applicable, be set out in a DPA.


15. Cross-Border Data Transfers

15.1 Inseller is based in Malaysia, but some of our sub-processors (including cloud hosting, database, email, payment, analytics, error-monitoring, and AI providers) may store or process personal data on infrastructure located outside Malaysia.

15.2 Where we transfer personal data outside Malaysia, we do so in accordance with the cross-border transfer requirements of the PDPA (including section 129 as amended) and any conditions, whitelists, or prescribed safeguards issued by the Personal Data Protection Commissioner, relying on a permitted basis such as your consent or the necessity of the transfer for the performance of a contract with you.

15.3 You may contact us to ask how a particular transfer is protected and which basis or safeguards apply.


16. Data Breach Notification

In line with the mandatory breach-notification requirements introduced by the Personal Data Protection (Amendment) Act 2024, if we become aware of a personal data breach, we will:

  • promptly assess the nature, scope, and likely risk of the breach and take steps to contain and remediate it;
  • notify the Personal Data Protection Commissioner within the timeframe and in the manner prescribed by the PDPA and its regulations (which the 2024 amendments and their implementing regulations require to be done as soon as practicable and within the prescribed period), where the breach meets the applicable notification threshold; and
  • notify affected data subjects (and/or, where Inseller acts as a data processor, the relevant Customer as data user) where required by law, so that the Customer can in turn notify its end-customers and the Commissioner as required.

Where Inseller acts as a data processor, we will notify the affected Customer without undue delay after becoming aware of a breach affecting that Customer's data, and will reasonably assist the Customer in meeting its own notification obligations.

Please report any suspected security or privacy incident to hello@inseller.my with the subject line "Security Incident".


17. Age and Eligibility

The Service is a B2B tool intended for use by businesses and their authorised personnel, and is not directed to children. Authorised Users and account holders must be at least 18 years of age — the age of majority in Malaysia under the Age of Majority Act 1971 — and have the capacity to enter into a binding contract under Malaysian law. We do not knowingly create accounts for individuals under 18.

Where end-customer data processed on a Customer's behalf may include data relating to minors, the Customer is the data user and is responsible for ensuring it has the appropriate lawful basis (including any required parental or guardian consent) under the PDPA and applicable law. As a data processor, Inseller does not screen end-customer data for age and relies on the Customer's compliance.

If you believe an individual under 18 has registered for an account, or that a child's personal data has been provided to us without appropriate consent, please contact us so that we can take appropriate action.


18. Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices, the Service, our sub-processors, or the law. We will post the updated Policy on this page and revise the "Last updated" date. Where changes are material, we will provide additional notice (for example, by email or in-product notice) where required or appropriate. Your continued use of the Service after the effective date of an updated Policy constitutes acceptance of the changes, to the extent permitted by law.


19. Governing Law

This Policy is governed by and construed in accordance with the laws of Malaysia, and the Personal Data Protection Act 2010 (as amended by the Personal Data Protection (Amendment) Act 2024) applies to our processing of personal data. Any disputes relating to this Policy are subject to the jurisdiction arrangements set out in the Terms of Service.


20. How to Contact Us and the Regulator

If you have any questions, concerns, or requests regarding this Policy or our handling of personal data, please contact:

Inseller — MFD Holdings Sdn Bhd Registration No. 201901014519 (1323847-H) Data Protection Officer / Privacy Team Email: hello@inseller.my Website: https://inseller.my Registered address: No 6, Jalan Kempas 6, 84200 Bukit Bakri, Muar, Johor, Malaysia

For privacy, data access, correction, limitation of processing, withdrawal of consent, portability, DPA, or security-related matters, please mark your email subject line as "Privacy Inquiry" or, for incidents, "Security Incident".

The regulator. The body responsible for the PDPA is the Personal Data Protection Department (Jabatan Perlindungan Data Peribadi / JPDP), headed by the Personal Data Protection Commissioner (Pesuruhjaya Perlindungan Data Peribadi) (in this Policy, the "Commissioner" and the "Department (JPDP)"). You have the right to lodge a complaint with the Department (JPDP) / the Commissioner if you believe your personal data rights under the PDPA have not been respected.


Related documents: This Privacy Policy should be read together with the Inseller Terms of Service and, where published or entered into, any Cookie Policy, Data Processing Agreement (DPA), Sub-processor List, and Acceptable Use Policy.

© 2026 MFD Holdings Sdn Bhd. All rights reserved.