Skip to content

LABÉAU Legal

Privacy Policy

How TEN BINARY SDN. BHD. collects, uses, shares and protects your personal data when you use LABÉAU.

Version 1.0Effective 1 August 2026Last updated 27 July 2026

In short

  • We collect the details you give us, the records your salon keeps about your membership and treatments, and technical data from your device.
  • Health and treatment information is sensitive personal data — we handle it only with your explicit consent and only to provide the service.
  • Your data is hosted on Amazon Web Services in Singapore. We never sell your personal data.
  • You can request access, correction, deletion, portability or withdrawal of consent at any time — see section 11.
  • This summary is for convenience only. The full policy below governs.

1. Introduction and scope

This Privacy Policy explains how TEN BINARY SDN. BHD. (Business Registration No. 202001034172 (1390493-P)) ("LABÉAU", "we", "us", "our") handles personal data in connection with the LABÉAU member mobile application, the websites at labeaupos.com and its subdomains, and the LABÉAU merchant management system (together, the "Platform").

It is issued in accordance with the Personal Data Protection Act 2010 of Malaysia, as amended by the Personal Data Protection (Amendment) Act 2024 ("PDPA"), and applies to individuals in Malaysia and, where relevant, to individuals in Singapore and elsewhere who use the Platform.

Please read this policy together with our Terms of Use. If you do not agree with this policy, do not use the Platform.

2. Who is responsible for your data — an important distinction

Two different organisations may be responsible for different parts of your data: LABÉAU, and the salon, spa or clinic ("Merchant") you visit. Knowing which one holds what determines who you should approach to exercise your rights.

DataWho controls itOur role
Your LABÉAU member account — the profile you create in the app: name, email, phone, date of birth, gender, address, emergency contact, profile photo, notes, login credentialsLABÉAUWe are the data controller. We decide why and how this data is processed.
Your membership record at a salon — treatment and consultation records, appointment history, purchases, invoices, points, credit and package balances, member photos, internal labels and remarksThe MerchantWe are a data processor acting on that Merchant's documented instructions. The Merchant decides what is collected and retained.
Technical and usage data — device identifiers, push tokens, diagnostic and security logsLABÉAUWe are the data controller, for operating and securing the Platform.

Where we act as a processor, we handle the data only as instructed by the Merchant and as required by law, and we apply the security measures described in section 10. For any request about records held by a Merchant, please contact that Merchant directly; if you contact us, we will forward your request to the Merchant and assist them in responding.

3. What personal data we collect

3.1 Data you give us

CategoryExamples
IdentityFirst and last name, date of birth, gender, profile photograph
ContactMobile number and dialling code, email address, residential address, city, state, postcode, country
Emergency contactName and phone number of the person you nominate
Account credentialsPassword (stored only as a salted cryptographic hash — never in readable form), and where you sign in with Google or Facebook, the identifier that provider returns
PreferencesLanguage, notification and marketing preferences, free-text notes you add to your profile

3.2 Data your Merchant records about you

CategoryExamples
Membership identityIdentity document number (NRIC or passport) and identity type, tax identification number (TIN) where required for e-invoicing, marital status, occupation
Commercial recordsAppointments, services and products purchased, invoices and receipts, amounts paid and outstanding, payment method recorded by staff, total spending, last visit date
Loyalty recordsPoints balance and history, credit, service-credit and product-credit balances and history, prepaid packages and remaining sessions, vouchers, membership tier
Service recordsConsultation forms, treatment notes, staff remarks, internal labels, referral source, and photographs of you taken for treatment records (for example before-and-after images)

3.3 Data collected automatically

CategoryExamples
Device and appDevice type, operating system and version, app version, platform (iOS/Android), language and time zone
Push notification tokenAn identifier issued by Apple, Google Firebase Cloud Messaging or Expo so we can deliver notifications to your device
Approximate locationOnly if you grant permission, and only while the app is in the foreground, to sort salons by distance from you. It is used on your device for that purpose and is not stored as a location history.
Security and diagnostic logsSign-in events, IP address, timestamps, error and crash information

We do not collect your card number, CVV or bank credentials. Payments are made directly to the Merchant and the Platform records only the transaction details the Merchant enters, such as the amount and the payment method name.

Where you enable fingerprint or facial authentication, that verification is performed entirely by your device's secure hardware. Your biometric templates are never transmitted to us and we never store them.

4. Sensitive personal data

Some information collected in consultation forms is "sensitive personal data" under the PDPA — in particular information about your physical or mental health. Under section 40 of the PDPA it may only be processed with your explicit consent, or where another statutory ground applies.

Depending on the treatment, a Merchant may record health-related information such as skin sensitivity and allergies, pregnancy or breastfeeding status, previous surgery or aesthetic procedures including botox and fillers, vision and eye conditions, posture and body assessments, sleep and lifestyle factors, and photographs of the treated area.

  • This information is collected by the Merchant for the purpose of assessing your suitability for treatment and delivering it safely.
  • The Merchant must obtain your explicit consent before collecting it, and must tell you the purpose.
  • We process it only as a data processor, to host and display it within the Merchant's system and your app.
  • We do not use health information for marketing, profiling or any purpose beyond providing the Platform.
  • You may withdraw your consent at any time by contacting the Merchant. Withdrawal may mean a treatment can no longer be safely provided to you.

5. Why we use your data, and our lawful basis

PurposeBasis under the PDPA
Create and administer your account; authenticate youNecessary for the performance of a contract with you
Make, confirm, change and remind you of bookingsPerformance of a contract; your consent
Display your membership, balances, packages, invoices and treatment historyPerformance of a contract; processing on the Merchant's instruction
Assess suitability for, and safely deliver, a treatmentYour explicit consent (sensitive personal data)
Send service messages — confirmations, receipts, balance changes, security alertsPerformance of a contract; our legitimate interest in operating the service
Send marketing about offers and promotionsYour consent, which you may withdraw at any time
Secure the Platform, prevent fraud and abuse, investigate incidentsOur legitimate interest in protecting the Platform and its users; compliance with legal obligation
Generate invoices and submit e-invoices to the Inland Revenue Board of Malaysia (LHDN)Compliance with a legal obligation of the Merchant
Maintain accounting, tax and statutory recordsCompliance with a legal obligation
Improve and troubleshoot the Platform using aggregated or de-identified dataOur legitimate interest in improving the service
Respond to lawful requests from regulators, courts and law enforcementCompliance with a legal obligation

We do not sell your personal data, and we do not share it with third parties for their own independent marketing. We do not use your personal data to train machine-learning models.

We do not make decisions producing legal or similarly significant effects about you by automated means. Membership tiers are calculated arithmetically from points recorded by your Merchant and are reviewable by that Merchant.

6. Who we share your data with

RecipientWhat and why
The Merchants you are linked toYour identity, contact, emergency contact, address and booking details, so they can identify you, serve you and maintain their membership records. A Merchant sees only the members linked to that Merchant.
Amazon Web Services, Inc.Cloud hosting, database and file storage in the Asia Pacific (Singapore) region.
Meta Platforms, Inc. / WhatsAppDelivery of WhatsApp Business Platform messages such as appointment reminders, where that channel is used.
Google LLC (Firebase Cloud Messaging) and Expo, Inc.Delivery of push notifications to your device.
Inland Revenue Board of Malaysia (LHDN)E-invoice data required by law, submitted by the Merchant as supplier.
Professional advisers, auditors and insurersWhere reasonably necessary and under a duty of confidence.
Regulators, courts, law enforcementWhere required or permitted by law, or to establish, exercise or defend legal claims.
An acquirerIf we are involved in a merger, acquisition, restructuring or sale of assets, subject to the acquirer being bound to protect your data on terms no less protective than this policy. We will notify you of any such change of control.

Our service providers act as our processors under written terms that restrict them to processing data on our instructions, require appropriate security, and prohibit use for their own purposes.

7. Transfers outside Malaysia

Our production infrastructure — application servers, databases and file storage — is located in the Amazon Web Services Asia Pacific (Singapore) region. Personal data collected in Malaysia is therefore transferred to and stored in Singapore. Some of our service providers may also process limited data in other jurisdictions in order to deliver messages and notifications.

Under section 129 of the PDPA we transfer personal data outside Malaysia only where the receiving jurisdiction has data protection law substantially similar to, or serving the same purposes as, the PDPA, or where another statutory ground applies — including where the transfer is necessary to perform our contract with you, where you have consented, or where we have taken all reasonable steps and exercised all due diligence to ensure the data is not processed inconsistently with the PDPA. We put contractual protections in place with each recipient.

8. How long we keep your data

We keep personal data only for as long as necessary for the purpose it was collected, and then delete or anonymise it. Where we act as processor, the Merchant sets the retention period for its records.

DataRetention
Member account profileFor as long as your account is active, then up to 24 months after closure to handle residual queries and disputes, unless you ask us to delete it sooner
Booking and treatment recordsAs determined by the Merchant, having regard to its professional and legal obligations
Invoices, receipts, tax and accounting recordsAt least 7 years, as required by the Income Tax Act 1967 and related Malaysian legislation
Security and access logsTypically 12 months, or longer where needed to investigate an incident
Push notification tokensUntil the token is replaced, the app is uninstalled, or the device is deregistered
Marketing consent recordsFor as long as needed to evidence your consent or its withdrawal

9. How we protect your data

  • Encryption of data in transit using TLS, and encryption at rest for databases and stored files.
  • Passwords stored only as salted cryptographic hashes; they cannot be read or recovered by our staff.
  • Access to production data restricted to authorised personnel on a least-privilege, need-to-know basis.
  • Tenant separation, so a Merchant can access only the members linked to that Merchant.
  • Time-limited, signed URLs for access to stored images and documents.
  • Optional device-level biometric or passcode locking of the member app, performed entirely on your device.
  • Logging and monitoring of authentication and administrative activity, and regular backups.

No method of transmission or storage is completely secure. While we take the steps required by the Security Principle of the PDPA, we cannot guarantee absolute security, and you are responsible for protecting your password and your device.

Data breach notification

If a personal data breach occurs, we will notify the Personal Data Protection Commissioner as soon as practicable and in any event within 72 hours of becoming aware of it, in accordance with the PDPA. Where the breach causes or is likely to cause significant harm to you, we will notify you without unnecessary delay and in any event within 7 days of notifying the Commissioner, and tell you what happened, what data was involved and what steps to take. Where we act as processor for a Merchant, we will notify that Merchant without undue delay so it can meet its own obligations.

10. Children

The member app is intended for individuals aged 18 and over, and we do not knowingly collect personal data from children under 18 through it. Where a Merchant provides a service to a minor, the Merchant is responsible for obtaining the consent of a parent or guardian in accordance with section 11 of the PDPA. If you believe a child has provided us with personal data, contact us at info@labeaupos.com and we will take steps to delete it.

11. Your rights and how to exercise them

RightWhat it means
AccessAsk whether we hold personal data about you and receive a copy of it.
CorrectionAsk us to correct data that is inaccurate, incomplete, misleading or out of date.
Withdraw consentWithdraw consent you have given, at any time, including for marketing and for sensitive personal data.
Limit processingAsk us to stop or restrict processing likely to cause you substantial and unwarranted damage or distress.
Prevent direct marketingRequire us to stop using your data for direct marketing.
Data portabilityAsk us to transmit your personal data to another data controller, where technically feasible and where the data is in a structured, commonly used format.
DeletionAsk us to delete your account and associated data, subject to records we must retain by law or that a Merchant retains as controller.

To exercise any of these rights, email info@labeaupos.com or write to our Data Protection Officer using the details in section 15. We may ask you to verify your identity before acting. We will respond within 21 days of receiving your request, or tell you within that period if we need longer and why. A reasonable fee may apply to an access request, as permitted by the PDPA.

Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal, and may mean we or a Merchant can no longer provide part or all of the service to you.

If your request concerns records held by a Merchant — treatment notes, balances, invoices — please contact that Merchant, who is the controller of those records. We will help you identify and reach them.

12. Marketing communications

We and the Merchants you are linked to send marketing only where you have consented. Every marketing message includes a way to opt out, and you can also change your preferences in the app or by contacting us. Opting out of marketing does not stop essential service messages such as booking confirmations, receipts and security notices, which are necessary to provide the Platform.

13. Cookies and website analytics

Our websites use strictly necessary cookies and local storage to keep you signed in, remember your language, and maintain security. Where we use analytics to understand aggregate usage, we configure it to minimise personal data and we do not use it to identify you individually. You can control cookies through your browser settings; blocking strictly necessary cookies may prevent parts of the site from working. The member mobile application does not use advertising cookies or third-party ad trackers.

15. Additional information for users in Singapore

If you are in Singapore, the Personal Data Protection Act 2012 (Singapore) may also apply to our handling of your personal data. In that case you have equivalent rights of access and correction, we will notify you and the Personal Data Protection Commission of a notifiable data breach in accordance with that Act, and you may contact our Data Protection Officer using the details below. Our Singapore data protection representative and complaints channel is the same as set out in section 16.

16. Contact us and how to complain

We have appointed a Data Protection Officer who is responsible for overseeing questions about this policy. Please contact them first — we would like the chance to resolve your concern.

Data controllerTEN BINARY SDN. BHD.
Registration No.202001034172 (1390493-P)
Data Protection Officer[NAME OF APPOINTED DPO — to be completed before publication]
Emailinfo@labeaupos.com
WhatsApp+60 11-4041 8665
Registered address[REGISTERED OFFICE ADDRESS — to be completed before publication]

If you are not satisfied with our response, you may lodge a complaint with the Personal Data Protection Commissioner, Department of Personal Data Protection (Jabatan Perlindungan Data Peribadi), Ministry of Digital, Malaysia. Users in Singapore may complain to the Personal Data Protection Commission of Singapore.

17. Changes to this policy

We may update this policy from time to time. Where a change is material — for example a new purpose or a new category of recipient — we will give reasonable advance notice by in-app notice or email, and where the law requires it we will seek your fresh consent. The version number and "last updated" date at the top of this page always identify the current version. Your continued use of the Platform after the effective date constitutes acceptance of the updated policy.

This policy is issued in English. Any translation is provided for convenience only, and in the event of inconsistency the English version prevails.


See also our Terms of Use. Questions about this document can be sent to info@labeaupos.com.

© 2026 TEN BINARY SDN. BHD. · Business Registration No. 202001034172 (1390493-P)