
Privacy Policy
We respect your privacy and are committed to protecting your personal data in accordance with Malaysian and international law.
Effective Date: 20 May 2026
This Privacy Policy explains how K. L. Kris Food Industries Sdn. Bhd. (Company Registration No. 199201016660) (“Krisfood”, “we”, “us”, or “our”) collects, uses, discloses, retains, and protects personal data obtained through our website at www.krisfood.com (the “Site”) and through our business operations.
This Policy is established in compliance with the Personal Data Protection Act 2010 (PDPA) of Malaysia, and takes into account applicable international frameworks including the EU General Data Protection Regulation (GDPR), where relevant to our global operations.
Please read this Policy carefully. By using our Site or engaging with us, you acknowledge that you have read and understood this Policy.
1. Data Controller
Krisfood is the data controller responsible for the personal data we collect about you. Our registered address is:
For privacy-related enquiries or to exercise your rights, please contact us using the details above or refer to Section 12 of this Policy.
2. Personal Data We Collect
We collect personal data that you provide to us through our website forms (such as contact, product enquiry, and job application forms), as well as data collected automatically when you visit our Site. Submitting a form is always at your discretion; however, certain fields are required to process your request. The categories of personal data we may collect include:
2.1 Data You Provide Directly
- Contact information: Full name, job title, company name, email address, telephone number, and mailing address — collected via contact forms and enquiry submissions.
- Business information: Company registration details, industry sector, product requirements — collected from potential or existing business partners.
- Career application data: CV/résumé, educational background, employment history, skills, and other information submitted through job applications.
- Communications: The content of messages, queries, or feedback you send to us.
- Product specification access: When you request access to a restricted product specification document, we collect your name, email address, IP address, and browser user-agent to log the request and grant time-limited access.
2.2 Data Collected Automatically
- Usage data: IP address, browser type and version, operating system, referring URLs, pages visited, time and date of visits, and time spent on pages.
- Analytics data: Aggregated and anonymised information about how visitors interact with the Site (via Vercel Analytics / Speed Insights).
- Cookies and similar technologies: See Section 9 for details.
2.3 Sensitive Personal Data
We do not intentionally collect sensitive personal data (such as race, religion, health information, or financial account details) through the Site. Please do not submit such information through our contact forms.
3. How We Use Your Personal Data
We use the personal data we collect for the following purposes:
- Responding to enquiries: To reply to questions, requests for product information, samples, or quotations submitted through the Site. When you submit a form, you consent to us collecting and using your data for the specific purpose of that form.
- Business operations: To manage commercial relationships with existing and prospective clients, distributors, and business partners.
- Recruitment: To evaluate job applications, conduct interviews, and manage the hiring process.
- Site improvement: To analyse usage patterns, diagnose technical issues, and enhance the functionality and user experience of our Site.
- Security: To protect the Site, our systems, and our business from fraud, unauthorised access, or other illegal activities.
- Legal compliance: To comply with applicable laws, regulations, judicial orders, and lawful requests from public authorities.
- Marketing communications: To send you information about our products, services, events, and industry news, where you have given consent or where we have a legitimate interest and applicable law permits.
4. Legal Bases for Processing (PDPA and GDPR)
4.1 Malaysian PDPA 2010
Under the Personal Data Protection Act 2010 (PDPA), we process personal data only for lawful purposes directly related to our business activities, and we apply the following data protection principles:
- General Principle: Personal data is processed only for purposes for which consent was given or as permitted by law.
- Notice & Choice Principle: We notify you of the purposes of data collection and provide you with choices regarding the use of your data.
- Disclosure Principle: Personal data is not disclosed to third parties without your consent, unless required by law.
- Security Principle: We implement appropriate technical and organisational measures to protect your data.
- Retention Principle: We retain personal data only for as long as necessary for the purpose for which it was collected.
- Data Integrity Principle: We take reasonable steps to ensure personal data is accurate, complete, and up to date.
- Access Principle: You have the right to access and correct your personal data held by us.
4.2 GDPR Legal Bases (for EU/EEA Data Subjects)
Where EU/EEA data protection law applies, we process your personal data under one or more of the following legal bases:
- Consent (Art. 6(1)(a)): Where you have given explicit consent, for example for marketing emails.
- Contract (Art. 6(1)(b)): Where processing is necessary to perform a contract or take pre-contractual steps at your request (e.g., processing your product enquiry).
- Legal obligation (Art. 6(1)(c)): Where processing is necessary to comply with applicable law.
- Legitimate interests (Art. 6(1)(f)): Where processing is necessary for our legitimate business interests, such as operating and improving the Site, preventing fraud, and business development, provided these interests are not overridden by your rights and interests.
5. Disclosure of Personal Data
We do not sell, rent, or trade your personal data. We may share your personal data with the following categories of recipients, only as necessary and subject to appropriate safeguards:
- Within our group of companies: Our subsidiaries and affiliates within the K. L. Kris Group, where necessary for internal business operations, administration, and service delivery.
- Service providers: Third-party vendors who assist us in operating the Site and delivering our services (e.g., web hosting via Vercel, email delivery, analytics providers), subject to data processing agreements. These providers act on our instructions and are not permitted to use your data for their own purposes.
- Professional advisors: Lawyers, accountants, auditors, and other advisors where necessary.
- Regulatory and legal authorities: Government agencies, courts, law enforcement, and regulators where required by Malaysian or applicable foreign law.
- Business transactions: In the event of a merger, acquisition, restructuring, or sale of assets, personal data may be transferred as part of that transaction, subject to equivalent data protection obligations.
6. International Transfers of Personal Data
As a global cocoa ingredients supplier, Krisfood operates internationally. Personal data may be transferred to, stored in, or processed in countries outside Malaysia, including countries within the EU/EEA and other jurisdictions.
Where we transfer personal data outside Malaysia, we comply with the requirements of the PDPA 2010 and take steps to ensure an adequate level of protection is in place. For transfers from the EU/EEA, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) approved by the European Commission, or other valid transfer mechanisms under the GDPR.
By providing your personal data to us, you consent to the transfer of your data to Malaysia and to other countries in which we operate, subject to the protections described in this Policy.
7. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required or permitted by law. The criteria we use to determine retention periods include:
- The duration of our business relationship with you or your organisation.
- Legal or contractual requirements (e.g., tax and accounting records under Malaysian law).
- Applicable statutes of limitation for potential legal claims.
- Directions from regulatory authorities.
When personal data is no longer required, we will securely destroy, erase, or anonymise it in accordance with our internal data retention policies.
General and product enquiries: Personal data submitted through our Contact Us or product enquiry forms is retained for up to twenty-four (24) months from the date of last correspondence, after which it is securely deleted or anonymised, unless a longer retention period is required by law or for the purposes of an ongoing commercial relationship.
Career applications: Data from unsuccessful applications is retained for up to twelve (12) months to allow us to consider you for future suitable roles, after which it is securely deleted unless you consent to a longer retention period.
Product specification access requests: The name, email address, IP address, and browser user-agent logged when you request a product specification document are retained for up to twelve (12) months for security and audit purposes, after which they are securely deleted.
8. Your Rights
8.1 Rights Under Malaysian PDPA 2010
Under the PDPA 2010, you have the following rights in respect of your personal data:
- Right of access: To request access to the personal data we hold about you.
- Right of correction: To request that inaccurate, incomplete, misleading, or out-of-date personal data be corrected.
- Right to withdraw consent: To withdraw consent to processing at any time (subject to legal or contractual restrictions).
- Right to prevent processing for marketing: To opt out of receiving direct marketing communications.
8.2 Additional Rights for EU/EEA Data Subjects (GDPR)
If you are located in the EU or EEA, you additionally have the right to:
- Right to erasure (“right to be forgotten”): Request deletion of your personal data where there is no longer a lawful basis for us to retain it.
- Right to restriction of processing: Request that we restrict processing of your data in certain circumstances.
- Right to data portability: Receive your personal data in a structured, machine-readable format and transmit it to another controller.
- Right to object: Object to processing based on legitimate interests or for direct marketing purposes.
- Rights related to automated decision-making: Not to be subject to a decision based solely on automated processing that produces significant effects on you.
- Right to lodge a complaint: Lodge a complaint with your local supervisory authority (e.g., your national Data Protection Authority).
8.3 How to Exercise Your Rights
To exercise any of the above rights, please submit a written request to us at corporate@krisfood.com. We will respond to your request within thirty (30) days, or within the timeframe required by applicable law. We may ask you to verify your identity before processing your request.
9. Cookies and Tracking Technologies
Our Site uses cookies and similar technologies to improve your browsing experience and to analyse Site usage. A cookie is a small text file placed on your device by a web server.
9.1 Types of Cookies We Use
- Strictly necessary cookies: Essential for the Site to function properly (e.g., session management, security). These cannot be disabled.
- Analytics cookies: Help us understand how visitors interact with the Site (via Vercel Analytics). Data collected is aggregated and anonymised where possible.
- Functional cookies: Allow the Site to remember your preferences (e.g., language selection) to provide enhanced functionality.
9.2 Third-Party Cookies
Third-party services embedded in or linked from the Site (such as reCAPTCHA by Google) may set their own cookies. We do not control these cookies and recommend reviewing the relevant third-party privacy policies.
9.3 Managing Cookies
You can configure your browser to refuse all or certain cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, some parts of the Site may become inaccessible or not function properly. For more information about managing cookies, visit www.allaboutcookies.org.
10. Security of Personal Data
We implement appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include:
- Secure HTTPS connections for all data transmission over the Site.
- Access controls limiting personal data to authorised personnel only.
- Use of reputable cloud infrastructure providers with industry-standard security certifications.
- Regular review of our information security practices.
However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your personal data, we cannot guarantee absolute security. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant authorities and affected individuals as required by applicable law.
11. Children's Privacy
Our Site is not directed at children under the age of 18. We do not knowingly collect personal data from children. If you believe we have inadvertently collected personal data from a child, please contact us immediately at corporate@krisfood.com and we will take steps to delete such data.
12. Marketing Communications
We may send you marketing communications regarding our products, services, events, and industry news where you have given us your consent or where we otherwise have a lawful basis to do so under applicable law.
You may opt out of receiving marketing communications at any time by:
- Clicking the unsubscribe link in any marketing email we send you.
- Contacting us directly at corporate@krisfood.com.
Opting out of marketing communications will not affect our ability to send you transactional or service-related messages (e.g., responses to your enquiries).
13. Third-Party Services and Links
Our Site may contain links to third-party websites (including social media platforms such as LinkedIn and Facebook). This Privacy Policy applies only to our Site. We are not responsible for the privacy practices of third-party sites and encourage you to review their respective privacy policies before providing any personal data.
Google reCAPTCHA: Our public-facing forms are protected by Google reCAPTCHA. reCAPTCHA collects hardware and software information, including device and application data, and sends it to Google for analysis. Use of reCAPTCHA is subject to Google's Privacy Policy and Terms of Service.
WhatsApp: Our website includes a link to contact us via WhatsApp. If you choose to contact us through WhatsApp, any data you share will be processed by Meta Platforms, Inc. in accordance with WhatsApp's Privacy Policy. We have no control over how WhatsApp processes your data.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. We will post the updated Policy on this page with a revised “Effective Date”. We encourage you to review this Policy periodically.
For material changes, where required by applicable law, we will provide additional notice (such as a prominent notice on the Site or direct communication).
15. Governing Law
This Privacy Policy is governed by and construed in accordance with the laws of Malaysia, including the Personal Data Protection Act 2010. Disputes arising from this Policy shall be subject to the jurisdiction of the Malaysian courts.
For EU/EEA data subjects, this Policy is also subject to the General Data Protection Regulation (GDPR) and relevant national implementing legislation where applicable.
16. Contact and Complaints
For any questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact our data protection contact point:
If you are located in Malaysia and you believe we have not adequately addressed your concerns, you have the right to lodge a complaint with the Department of Personal Data Protection (Jabatan Perlindungan Data Peribadi, JPDP), Malaysia.
If you are located in the EU/EEA, you have the right to lodge a complaint with your national Data Protection Authority.