3V POS — PRIVACY POLICY AND PERSONAL DATA PROTECTION NOTICE

Issued by: THREE V ANALYTICS (Registration No. 202603168152 (003864392-D))

Effective Date: 01 August 2026 Version: 1.0 Last updated: 01 August 2026

This Notice is issued in accordance with section 7 of the Personal Data Protection Act 2010 (Act 709) of Malaysia, as amended by the Personal Data Protection (Amendment) Act 2024 ("PDPA"). It is available in English and Bahasa Malaysia. In the event of any inconsistency between the two versions, the [English] version shall prevail.

1. WHO WE ARE AND WHAT THIS NOTICE COVERS

1.1 Three V Analytics ("3V", "we", "us", "our") operates 3V POS, a cloud-based point-of-sale platform for food and beverage, hawker and micro-merchant businesses (the "Service"). ‍

1.2 This Notice explains how we collect, use, disclose, store and protect personal data in connection with the Service, our website, our sales and support channels, and our dealings with merchants, their staff, end-customers, agents and business contacts.

1.3 Please read this Notice carefully. By using the Service or providing personal data to us, you acknowledge that you have read and understood it. Where we rely on consent, we will obtain it separately and you may withdraw it as described in Clause 9.

2. OUR TWO ROLES — PLEASE NOTE THE DIFFERENCE

This is the most important part of this Notice for end-customers. We hold two different roles depending on whose data is involved.

(a) 3V is the data controller — meaning we decide the purposes and means of processing — in respect of:

•      merchant registration and account data, subscription billing, support correspondence, account administration and platform security logs; and

•      our website visitors, enquiry and contact form submissions, marketing contacts, prospective merchants, and our agents and resellers.

(b) The merchant is the data controller, and 3V is only the data processor — meaning we process strictly on the merchant's instructions — in respect of:

•      orders, receipts, transaction records and QR self-ordering entries;

•      end-customer contact details collected by the merchant through the Service; and

•      staff and outlet-user records entered into the Service by the merchant.

2.1 Where we act as data processor, we process personal data only on the merchant's documented instructions and in accordance with the Data Processing Addendum (Schedule 1 to the 3V POS Terms of Use).

‍2.2 If you are an end-customer of a restaurant, café or stall that uses 3V POS, that merchant — not 3V — decides what data is collected from you and why. Please direct your questions, access requests and complaints about that data to the merchant in the first instance. We will assist the merchant in responding to you.

3. PERSONAL DATA WE COLLECT

3.1 Merchant account data (we are controller)

•      Business name, SSM registration number, business address, outlet addresses

•      Name, job title, email address, mobile number and identification details of the account owner, directors and authorised administrators

•      Login credentials, authentication tokens and access logs

•      Bank account details or e-mandate details for subscription billing, and payment records

•      Tax status information (for example SST registration number, TIN)

•      Support tickets, correspondence, call and chat records, feedback and survey responses

3.2 Staff and outlet-user data (merchant is controller; we process)

•      Names or display names, staff codes, roles and permissions, PINs

•      Shift, clock-in/out and activity logs within the Service

‍ ‍

3.3 End-customer data (merchant is controller; we process)

•      Order and transaction records, items ordered, amounts, discounts, vouchers, payment method and receipt data

•      Table or queue number and QR self-ordering session data

•      Where the merchant chooses to collect it: name, mobile number, email address and delivery or pickup details

3.4 Website, marketing and prospect data (we are controller)

•      Name, business name, email address, phone number, enquiry content

•      Marketing preferences and engagement data

•      Agent and reseller contact and commission-related details

3.5 Technical and device data (we are controller)

•      Device model, operating system, app version, device and installation identifiers

•      IP address, log data, timestamps, crash reports, diagnostic and performance data

•      In-app usage and feature interaction data

3.6 Sensitive personal data

We do not intentionally collect sensitive personal data (as defined in the PDPA, including health, biometric, religious, political and criminal-record data). Merchants are contractually prohibited from entering sensitive personal data into free-text fields without our prior written agreement. If your device uses fingerprint or face unlock for the App, that biometric verification is performed by your device operating system and the biometric data is never transmitted to or stored by us.

3.7 Payment card data

We do not collect, process or store full payment card numbers, expiry dates or CVV/CVC codes. Card payments are handled by licensed third-party payment providers under their own terms and security standards.

3.8 Children

The Service is intended for business use by persons aged 18 and above. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without the consent of a parent or guardian, we will delete it.

4. HOW WE COLLECT PERSONAL DATA

We collect personal data: (a) directly from you, when you register, subscribe, contact us, attend a demonstration, or use the Service; (b) automatically, when you or your staff use the App, the dashboard or our website; (c) from merchants, where the merchant enters data about staff or end-customers into the Service; (d) from our authorised agents and resellers, who introduce merchants to us; (e) from third parties such as payment gateways, app stores, credit reference or verification sources, and publicly available registers (for example SSM records); and (f) from cookies and similar technologies on our website (Clause 11).

It is obligatory for you to supply the data marked as mandatory at registration, billing and verification stages. If you do not supply it, we may be unable to create your account, provide the Service, process payments, or provide support.

5. PURPOSES OF PROCESSING

We process personal data for the following purposes:

Providing the Service (a) creating, authenticating and administering accounts, devices and user roles; (b) processing and synchronising orders, transactions, receipts, menus, inventory and reports; (c) enabling QR self-ordering, kitchen display and related features; (d) providing customer support, training, onboarding and troubleshooting.

Commercial administration (e) billing, invoicing, collecting subscription fees, managing mandates and recovering debts; (f) verifying identity, business registration and eligibility; (g) administering agent and reseller relationships and commissions.

Security, integrity and legal compliance (h) monitoring, detecting, investigating and preventing fraud, abuse, unauthorised access and security incidents; (i) maintaining audit logs and enforcing our Terms of Use; (j) complying with legal, tax, accounting, regulatory and law enforcement obligations, and establishing, exercising or defending legal claims.

Improvement and analytics (k) analysing usage to maintain, debug, improve and develop the Service; (l) producing aggregated and anonymised statistics and benchmarks that do not identify any individual.

Communications and marketing (m) sending service, security, billing and administrative notices (these are not marketing and you cannot opt out of them while you hold an account); (n) with your consent, sending product updates, offers, newsletters and event invitations.

5.1 Lawful basis

We process personal data on the basis of: your consent; the necessity of processing for the performance of a contract to which you are a party or in order to take steps at your request prior to entering into a contract; compliance with a legal obligation; and, where applicable, our legitimate interests in operating, securing and improving the Service, provided these are not overridden by your interests.

5.2 Automated decision-making

We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. Automated rules may be used for fraud and abuse detection and to flag accounts for human review.

6. DISCLOSURE OF PERSONAL DATA

We may disclose personal data to the following classes of parties, in each case only to the extent necessary:

(a) Cloud hosting, database and infrastructure providers who host and back up the platform; (b) Payment gateways, acquirers, e-wallet operators and banks, for subscription collection and (where the merchant enables it) transaction processing; (c) Communications providers, for email, SMS, WhatsApp and push notifications; (d) Analytics, crash-reporting and error-monitoring providers; (e) Our authorised agents, resellers and implementation partners, in respect of merchants they introduce or support, subject to confidentiality obligations; (f) Professional advisers — auditors, accountants, lawyers, insurers and consultants; (g) Regulators, government agencies, law enforcement and courts, where required or permitted by law, including the Royal Malaysian Customs Department, the Inland Revenue Board and the Personal Data Protection Commissioner; (h) Debt collection agencies, in respect of overdue accounts; (i) An acquirer or successor, in connection with a merger, acquisition, restructuring, financing or sale of assets, subject to confidentiality; (j) Our related corporations, for the purposes set out in this Notice; (k) The relevant merchant, in respect of that merchant's own data; and (l) Any other party with your consent or at your direction.

We do not sell personal data, and we do not disclose personal data for third-party marketing purposes.

7. CROSS-BORDER TRANSFER

7.1 Personal data may be transferred to, stored in, or accessed from locations outside Malaysia by our hosting providers and sub-processors.

7.2 Any such transfer is carried out in accordance with section 129 of the PDPA and the Personal Data Protection Commissioner's Guidelines for Cross Border Personal Data Transfer, on the basis that: (a) the receiving jurisdiction has laws substantially similar to, or that serve the same purposes as, the PDPA; or (b) appropriate legally binding safeguards (including contractual clauses imposing PDPA-equivalent protections) are in place and a transfer impact assessment has been conducted; or (c) another lawful ground under section 129 applies, including your consent or the necessity of the transfer for the performance of a contract.

7.3 Details of our current hosting locations and sub-processors are available on request from [privacy email].

8. SECURITY AND RETENTION

8.1 Security. We take practical steps to protect personal data from loss, misuse, modification, unauthorised or accidental access, disclosure, alteration or destruction, in accordance with the Security Principle under the PDPA. These include encryption in transit and at rest, tenant-level data segregation, role-based access control and least-privilege administration, multi-factor authentication for administrative access, logging and monitoring, routine backups, patching and vulnerability management, personnel confidentiality undertakings and training, and contractual security obligations on our data processors.

8.2 No absolute guarantee. No method of transmission or storage is completely secure. You are responsible for keeping your credentials, PINs and devices secure and for notifying us promptly of any suspected compromise.

8.3 Data breach. Where a personal data breach occurs and it causes or is likely to cause significant harm to affected individuals, or is of significant scale, we will notify the Personal Data Protection Commissioner within seventy-two (72) hours of becoming aware, and will notify affected individuals without unnecessary delay, in accordance with section 12B of the PDPA and the Guideline on Data Breach Notification. Where we act as a data processor, we will notify the relevant merchant (as data controller) without undue delay so that the merchant can meet its own obligations.

8.4 Retention. We retain personal data only for as long as necessary to fulfil the purposes in Clause 5, and thereafter as required to comply with legal, tax, accounting or regulatory obligations, or to establish, exercise or defend legal claims. Indicative periods:

•      Active merchant account and transaction data — for the duration of the subscription.

•      Merchant data after termination — available for export for 30 days, then deleted from active systems and removed from backups within our backup rotation cycle.

•      Invoices, receipts and accounting records — 7 years from the end of the relevant financial year, as required under the Income Tax Act 1967.

•      Support and correspondence records — [3] years from last contact.

•      Security, audit and access logs — [12 to 24] months.

•      Marketing contacts — until consent is withdrawn, or after [24] months of inactivity.

When retention is no longer required, personal data is securely deleted or irreversibly anonymised.

9. YOUR RIGHTS

Subject to the exceptions and conditions in the PDPA, you have the right to:

(a) Access — request a copy of the personal data we hold about you; (b) Correct — request correction of inaccurate, incomplete, misleading or out-of-date data; (c) Withdraw consent — withdraw consent to processing at any time, including for marketing; (d) Limit processing — request that we limit processing for specified purposes; (e) Prevent processing likely to cause damage or distress; (f) Prevent processing for direct marketing; and (g) Data portability — request transmission of your personal data to another data controller, where technically feasible and permitted under the PDPA and applicable guidelines.

How to exercise your rights. Send a written request to [privacy email] or to the address in Clause 13, together with proof of identity and sufficient detail to locate the data. We will respond within twenty-one (21) days of receipt of a valid request, or notify you within that period if more time is required. A prescribed fee may apply to data access and correction requests as permitted under the PDPA.

Consequences of withdrawal. If you withdraw consent necessary for us to provide the Service, we may be unable to continue providing it, and your subscription may be suspended or terminated. Withdrawal does not affect the lawfulness of processing before withdrawal, nor our right to retain data where required by law.

End-customers and staff of merchants. Requests relating to data controlled by a merchant should be sent to that merchant. If you send such a request to us, we will forward it to the relevant merchant where we can identify them, and support the merchant in responding.

10. MARKETING

10.1 We will only send you marketing communications where you have consented, or where permitted by law in respect of similar services to those you already receive from us.

10.2 You may opt out at any time by clicking "unsubscribe" in any marketing email, replying "STOP" to a marketing message, adjusting your in-app preferences, or writing to [privacy email]. Opting out of marketing does not stop service, billing, security and administrative messages.

11. COOKIES AND SIMILAR TECHNOLOGIES

11.1 Our website and web dashboard use cookies and similar technologies for: strictly necessary purposes (session management, authentication, security, load balancing); preferences; and analytics and performance measurement.

11.2 You may control non-essential cookies through our cookie banner (where displayed) or your browser settings. Disabling strictly necessary cookies may prevent the dashboard from functioning.

11.3 The mobile App does not use browser cookies but does use device identifiers and local storage for authentication, offline operation and diagnostics.

12. CHANGES TO THIS NOTICE

12.1 We may update this Notice from time to time. The current version is always available at [privacy policy URL], with the "Last updated" date shown at the top.

12.2 Where a change materially affects how we use your personal data, we will notify you by email or in-app notice before it takes effect and, where required by law, obtain your consent.

13. CONTACT US AND COMPLAINTS

Data Protection Contact

THREE V ANALYTICS (Registration No.: 202603168152 (003864392-D))

Email: team@3vanalytics.com

Phone Number: (+60) 17-465 0432

Address: No.1, Education Boulevard Batu Kawan Industrial Park, 14110 Batu Kawan, Pulau Pinang, Malaysia.