Privacy Policy (PDPA)

(EFFECTIVE DATE: May 01, 2019)


We, AiVA Vacation Lifestyle Sdn Bhd (formerly known as AiVA Lifestyle Sdn Bhd (Company number 1336493-V) (including all of its subsidiaries, brands, related and/or associated companies/brands). These entities are collectively referred to as "AiVA", "Travelooker", "we", "us", or "our". At AiVA, we value your trust, respect, and committed to protect your personal data and privacy. This Privacy Policy (collectively, "Policy") explains how we collect, use, share, disclose, and process personal information in accordance with the Personal Data Protection Act 2010 ("Act"), when you visit our websites, mobile sites, mobile applications, our person-to-person interaction, other online or offline activities (collectively, "Platforms"), use or participate in any of the tours, travel, cruise, hotels, events, meetings, attraction, activities, related products and services offered through the Platforms (collectively, "Services"). You are advised to read this Privacy Policy carefully. By visiting AiVA’s Platforms or using our services, you consent to our collection, use, and disclosure of your personal information in accordance with this Privacy Policy. If you do not agree to the terms of the policy, please do not use or access our Platforms or Services. Note: Our privacy policy may change at any time without prior notification. To make sure that you are aware of any changes, kindly review the policy periodically. This Privacy Policy is effective as of the date above.


“Client/Distributor/User” means an individual who (a) has contacted us through any means to find out more about any goods or services we provide, or (b) may, or has, entered into a contract with us for the supply of any goods or services by us; and

“Personal Data” means data, whether true or not, about a client who can be identified: (a) from that data; or (b) from that data and other information to which we have or are likely to have access.

We generally do not collect your personal data unless

It is provided to us voluntarily by you directly or via a third party who has been duly authorised by you to disclose your personal data to us (your “authorized representative”) after (i) you (or your authorised representative) have been notified of the purposes for which the data is collected, and (ii) you (or your authorised representative) have provided written consent to the collection and usage of your personal data for those purposes, or

Collection and use of personal data without consent is permitted or required by other laws. We shall seek your consent before collecting any additional personal data and before using your personal data for a purpose which has not been notified to you (except where permitted or authorised by law);

How We Collect Your Personal Data

We may also collect your personal data from a variety of sources, including, without limitation, 

  • When participate in offline activities organised and/or sponsored by us, such as meetings, events, contests, and client satisfaction surveys;
  • When making a reservation with us;
  • When you visit our website;
  • When you contact us in person;
  • When we contact you in person;
  • When we collect information about you from third parties;
  • When you interact with us via social media such as Facebook, Twitter, and Instagram, etc;
  • Via publicly accessible resources such as directories;
  • Via contractual agreement or arrangement;
  • Via telephone, fax, online chat, and email;
  • Via any Platform owned and managed by AiVA;
  • Via third party distributors, travel agents, travel aggregators, online portals, and alike.

Personal Data We May Collect from You

Based on AiVA nature of business, AiVA may collect from you personal information including but not limited to the following:

  • Name;
  • Verification identification information, such as your identity card number and passport number, nationality, gender, date of birth, marital status;
  • Contact information, such as your home address or correspondence address, email address or telephone number;
  • Visual information, such as your photographs, audios and videos;
  • Employment information, such as your employer, position;
  • Financial information, such as your credit card numbers, debit card numbers or bank account information (including cardholder name, number and expiration date) and information about a payment recipient (such as name, contact information and account information);
  • Dietary requirements;
  • Medical reports/records or information relevant to your travel arrangements;
  • Travel Details, including:
  • o   Flight detail – flight number, arrival and departure time;
  • o   Intended check-in and check-out dates;
  • o   Number of rooms required;
  • o   Pick-up and drop-off dates & time;
  • o   Personal details of all passengers, including name, date of birth, nationality, gender, telephone number, email address and passport number.

The types of personal data collected depend on the purposes of collection. We may “process” your personal data by way of collecting, recording, holding, storing, using, sharing, disclosing and/or deleting it;

When you browse through our Platforms, we may collect information regarding the device, device location, domain and host from which you access the Platform, the Internet Protocol address of the computer or Internet service provider you are using, and anonymous site statistical data. We may also collect information using cookies (see Cookies section below).


We may collect and use your personal data for any or all of the following purposes:

How We Collect Your Personal Data

We may also collect your personal data from a variety of sources, including, without limitation, 

  • Register for a user Account with us;
  • Performing obligations in the course of or in connection with our provision of the goods and/or services requested by you;
  • Process, Manage and Verify your identity in compliance with requirements under anti-money laundering legislation (which may include checking identity against verification sources such as credit bureaus or records maintained by utility or telecommunications companies, and watch lists established by regulatory agencies and similar bodies in local and foreign countries);
  • Administer, improve and personalize your experience on the Platforms;
  • Responding to, handling, and processing queries, requests, applications, complaints, and feedback from you;
  • Resolve disputes, troubleshoot concerns and help promote safe Services;
  • Detect, prevent and protect you and us against error, fraud and other criminal activity;
  • Fulfil and validate your purchases/reservations/bookings/inquiries;
  • Prepare itineraries, invoices and process transactions;
  • Communicate with you about our products and services;
  • Managing your relationship with us, provide customer service and support;
  • Processing payment or credit transactions;
  • Measure consumer interest in our Platforms and Services;
  • Sending your marketing information about our goods or services including notifying you of our marketing events, initiatives and promotions, membership and rewards schemes and other promotions;
  • Complying with any applicable laws, regulations, codes of practice, guidelines, or rules, or to assist in law enforcement and investigations conducted by any governmental and/or regulatory authority;
  • Occasionally send you market research or surveys, internal marketing analysis, client profiling activities, analysis of client patterns and choices, usage and activity trends analysis in relation to the Platform and/or Service and our users’ demographics (on an anonymised basis);
  • Facilitate your participation in, and our administration of, any of our activities including contests, promotions, activities, campaigns, events, meetings and exhibitions or polls;
  • Provide updates and analyze trends and site usage to enhance our marketing and promotional efforts;
  • Improve our content, service and product offerings;
  • For daily operation and administration of services and facilities in relation to the products provided to you;
  • Transfer or assign our rights, interests and obligations under any agreements entered into with us;
  • We may use personal information for other purposes with your consent or as permitted or required by law;
  • Transmitting to any unaffiliated third parties including our third party service providers and agents, and relevant governmental and/or regulatory authorities, whether in your country or abroad, for the aforementioned purposes; and
  • Any other incidental business purposes related to or in connection with the above;
  • For internal administrative and updating purposes, such as auditing, data analysis, record keeping, contact lists, risk management, security, etc; 


We will not sell, rent, transfer or disclose any of your personal data to any third party without your consent. However, we may disclose some of your personal data to the following third parties, as necessary to provide a Service you have requested.

Where such disclosure is required for performing obligations in the course of or in connection with our provision of the goods or services requested by you; or

Our subsidiaries, related and/or associated companies;

Your immediate family members and/or emergency contact person as may be notified to us from time to time;

Successors in title to us;

Our selected third parties (business/marketing partners, sponsors, advertisers) who offer promotions or organise contests, events, activities or campaigns;

Any person under a duty of confidentiality to which has undertaken to keep your personal data confidential which we have engaged to discharge our obligations to you;

Any party in relation to legal proceedings or prospective legal proceedings;

Auditors, consultants, lawyers, accountants or other financial or professional advisers appointed in connection with our business on a strictly confidential basis, appointed by us to provide services to us; any party nominated or appointed by us either solely or jointly with other service providers, who provide services or conduct data processing on our behalf, or for data centralization and/or logistics purposes;

May transfer personal information to service providers (including affiliates acting in this capacity) that perform services on our behalf, for example, call centre, marketing, analytics, information technology and data hosting and processing. Some of these service providers may be located outside of your country, and your personal information may be collected, used, disclosed, stored and processed outside of your country for the purposes described in this Privacy Policy. Personal information will be subject to your local and foreign legal requirements applicable to us, our affiliates and service providers, which may include lawful requirements to disclose personal information to government and national security agencies in certain circumstances;

Storage facility and records management service providers;

Government agencies, law enforcement agencies, courts, tribunals, regulatory/professional bodies, industry regulators, ministries, and/or statutory agencies or bodies, offices or municipality in any country, if required or authorised to do so, to satisfy any applicable law, regulation, order or judgment of a court or tribunal or queries from the relevant authorities;

Our business/marketing partners, third party product and/or service providers, suppliers, vendors, distributors, contractors or agents, on a need to know basis, that provide related products and/or services in connection with our business on our behalf or to assist us with the provision of the Platform and/or Service to you;

The general public when you become a winner in a contest, participate in our events or activities, submit your rating and/or review or other features of the Platform and/or Service that are viewable by the general public without compensation for advertising and publicity purposes;

Any third party (and its advisers/representatives) in connection with any proposed or actual reorganization, merger, sale, consolidation, acquisition, joint venture, assignment, transfer, funding exercise or asset/share sale relating to all or any portion of our business or in the unlikely event of insolvency, bankruptcy or receivership; and/or

Any other person reasonably requiring the same in order for us to operate and maintain our business or carry out the activities set out in the Purposes or as instructed/authorised by you;

We may disclose personal information as necessary to resolve disputes, detect, prevent and protect you and us against error, fraud and other criminal activity, enforce our terms and conditions, collect amounts owed to us, meet legal, regulatory, self-regulatory, insurance, audit, and security requirements, and in other circumstances with your consent or as permitted or required by law;


We generally rely on personal data provided by you (or your authorized representative). In order to ensure that your personal data is current, complete and accurate, please update us if there are changes to your personal data by informing our Data Protection Officer in writing or via email at the contact details provided above.


We are committed to ensuring that your personal data is stored securely. In order to prevent unauthorised access, disclosure or other similar risks, we endeavour, where commercially practicable, to implement appropriate technical, physical, electronic and procedural security measures in accordance with the applicable laws and regulations and industry standard to safeguard against and prevent the unauthorised or unlawful processing of your personal data, and the destruction of, or accidental loss, damage to, alteration of, unauthorised disclosure of or access to your personal data.

We will make reasonable updates to our security measures from time to time and ensure the authorised third parties only use your personal data for the Purposes set out in this Privacy Policy.

The Internet is not a secure medium. However, we will put in place various reasonable security procedures with regard to the Platform and your electronic communications with us. All our employees and data processors, which have access to, and are associated with the processing of your personal data, are obliged to respect the confidentiality of your personal data.

Unfortunately, no data transmission over the Internet or any wireless network can be guaranteed to be 100% secure. While we take commercially practical steps to protect your personal data, we cannot and do not accept responsibility for any unauthorised access, unlawful interceptions or loss of personal data transmitted to or from AiVA, and are not responsible for the actions of any third parties that may receive any such personal data.


You acknowledge that the provision of your personal data to us over the Internet is entirely at your own risk.

You further acknowledge that if you post your rating and/or review on the Platform, your rating and/or review will become public information and will be retained by us even after your account has been terminated. Your email addresses and phone number will not be visible to others through any rating and/or review that you post.

If any part of the Platform links you to other websites, those websites do not operate under this Privacy Policy and we do not accept any responsibility or liability arising from those websites. We suggest you to read and understand those websites’ privacy policy before you provide your personal data to those websites.

We use cookies (an alphanumeric identifier that we transfer to your computer’s or mobile device’s hard drive so that we can recognise your web browser or mobile device, track your visits to the Platform or remember your username and/or password each time log-in) to monitor your use of the Platform. All such demographic data collected through cookies are not personal data and we may use this data in aggregated, statistical and/or anonymised form. You may disable cookies by changing the settings on your web browser or mobile device; although this may mean that certain features on the Platform will not function properly if you set your web browser or mobile device to not accept cookies.

In addition to using cookies and related technologies as described above, we may also permit certain third party companies to help us tailor advertising that we think may be of interest to users and use other data about user activities on our Platform and/or Service (e.g., to allow them to tailor ads on third party services). These companies may deliver ads that might also place cookies and otherwise track user behaviour.

Please note that when you first install our mobile application on your mobile device, we will set up an account associated with that mobile device (“Account”). We will collect and use your personal data, in accordance with this Privacy Policy, whenever you activate our mobile application on that mobile device. This use includes linking your personal data with your Account. Most mobile platforms (iOS, Android, etc) have different permission systems for obtaining your consent. The iOS platform will alert you the first time our mobile application wants permission to access certain types of data and will let you consent (or not consent) to that request. Android devices will notify you of the permissions that our mobile application seeks before you first use the mobile application, and your use constitutes your consent.

The Platform may integrate with social sharing features and other related tools which allow you to share information with your friends or the public, depending on the settings you establish with the social sharing network. The social sharing network’s use of your personal data made available by AiVA is governed by that social sharing network’s privacy policy, not by this Privacy Policy. By connecting your social sharing network account through the Platform, you agree that we may collect your personal data from your social sharing network account only in accordance with your privacy settings you have set up under your social sharing network account and for the Purposes provided under this Privacy Policy.

We may automatically receive record and store location services information from your computer or mobile device when you interact with us. You hereby consent to our use of anonymised location services information collected from you. Where the location services information is personally identifiable, we will give you the options to manage your disclosure of this information. Depending on the functionalities available on your computer or mobile device, you may benefit from advanced options to manage the location services information. A computer or mobile device may report its GPS location at the time you interact with us if the location services settings are enabled. Such information is not identified as personal data, except where we are required to do otherwise under applicable law.

Our collection of your computer or mobile device location information is solely at your discretion. You can enable or disable location services when you use the Platform at any time, through your computer or mobile device settings. Should you use the Platform with location services enabled, you consent to our collection and dissemination of your computer or mobile device location information through the Platform, as specified in this Privacy Policy. Under no circumstances shall we be liable for claims or for any damages therefrom, arising out of your informed decision to allow other users to see your computer or mobile device location information, as specified in this Privacy Policy.


We collect, use, share, disclose, and process personal information with your consent, except as permitted or required by law. By visiting our Platforms, using our Services or providing your information, you consent to the collection, use share, disclose, and process of your personal information as described in this Privacy Policy. We may be required or permitted under statute or regulation to collect, use, share, disclose, and process personal information without your consent, for example to comply with a court order, to comply with local or federal regulations or a legally permitted inquiry by a government agency, or to collect a debt owed to us.

You may withdraw your consent to our collect, use, share, disclose, and process of personal information at any time, subject to contractual and legal restrictions and reasonable notice. Note that if you withdraw your consent to certain uses of your personal information, we may no longer be able to provide our Services.


AiVA's may establish and maintain a file of your personal information for the purposes described above. Your file will be stored on our servers or those of our service providers. If you wish to request access to or correction of your personal information in our custody or control, you may write to the address or email listed below, with attention to the Privacy Officer. Your right to access or correct your personal information is subject to applicable legal restrictions. We may take reasonable steps to verify your identity before granting access or making corrections.

You may at any time, by written notice to AiVA, requesting AiVA at the end of a prescribed period, as is reasonable in the circumstances, to cease or not to begin processing your personal data for the purpose of direct marketing.

If you wish to make inquiries or complaints or have other concerns about our personal information practices, you may write to us at the address below or by emailing us at


In the event of any inconsistencies or discrepancies between the English version and other translated versions of this Privacy Policy, the English version shall prevail.