CEOS Data Deletion Instructions
You may ask CEOS to delete personal data that is no longer needed and that CEOS is not required or permitted to retain.
Requesting deletion of your CEOS data
These instructions apply to data associated with CEOS websites, the CEOS Community Hub, CEOS Top-Up, CEOS WhatsApp and messaging services, community applications, referrals and support interactions.
Step 1 — Send your request privately
Email admin@ceosfamilysugo.com using the subject Data Deletion Request – CEOS Messaging.
Please include only the information needed to locate your records:
- your full name or CEOS account name;
- the telephone number used to contact CEOS, including country code;
- the CEOS service you used;
- any relevant CEOS account, application or order number; and
- whether you want specific data deleted or want CEOS to review all eligible data connected to you.
Do not send passwords, banking PINs, TACs, OTPs, full payment-card numbers, Meta access tokens, private keys or other credentials.
Deleting a WhatsApp conversation from your device does not automatically delete records held by CEOS. A request must be sent using the process above.
Step 2 — Identity verification
CEOS will acknowledge the request within 7 calendar days and may ask for proportionate information to confirm that you are the data subject or an authorised representative.
Verification may use information already associated with the account or interaction, such as confirmation from the same email address or telephone number, an account or order reference, or another low-risk verification method.
CEOS will never ask for your password, banking PIN, TAC, OTP, full card number or Meta/WhatsApp access token to verify a deletion request.
If CEOS cannot safely verify the requester, the request may be paused or refused to prevent unauthorised deletion. CEOS will explain what additional non-secret information is required where appropriate.
Step 3 — Review and response
CEOS will identify the relevant systems and determine which records:
- can be deleted;
- should be anonymised or de-identified;
- should be restricted from ordinary use; or
- must be retained for legal, accounting, fraud-prevention, security, dispute or audit purposes.
CEOS will complete the request, or provide a status or refusal explanation, within 30 calendar days. An extension will be used only where reasonably necessary for identity verification, technical complexity, legal retention, an active dispute or a legal hold. CEOS will explain the reason for the extension where permitted by law.
Data that may be deleted
Depending on the circumstances, eligible data may include:
- inactive profile and contact information;
- WhatsApp support messages and attachments that are no longer required;
- community application information where there is no continuing lawful need;
- unattached receipt uploads;
- optional preferences and non-essential profile information; and
- other records that have reached the end of their approved retention period.
Data that may need to be retained
CEOS may retain limited information where necessary to:
- comply with accounting, tax, corporate or other legal obligations;
- preserve order, payment, refund and fulfilment history;
- investigate fraud, duplicate receipts, abuse or security incidents;
- establish, exercise or defend legal claims;
- honour an opt-out or prevent repeated contact;
- protect another person’s rights; or
- preserve an active dispute or legal hold.
Where possible, data retained for these purposes will be restricted to the minimum necessary and will not be used for unrelated marketing.
The retention periods described in the CEOS Privacy & Cookie Notice include 7 years for accounting, order and payment-reference records; 2 years after closure for receipt images and support records; 30 days for unattached uploads; and up to 24 months for security and session logs. Records are retained longer only where required by law or necessary for an active dispute or legal hold.
WhatsApp and Meta data
CEOS can act only on data within systems it controls. A verified deletion request will include eligible WhatsApp message content, attachments and related webhook records stored by CEOS.
Meta and WhatsApp independently control information held in their own services. To manage or delete information held directly by Meta or WhatsApp, use the privacy and account controls provided by those services.
Backups and service providers
Deleted data may remain temporarily in protected backups until the normal backup-expiry cycle completes. Backup copies are isolated from ordinary use and will not be restored except for legitimate disaster recovery, security or legal needs. If restored, approved deletion controls should be reapplied where technically feasible.
CEOS will instruct relevant processors to delete or restrict eligible data where required by applicable contracts and law.
Completion notice
After completing the review, CEOS will tell you:
- whether the request was completed;
- which categories of data were deleted, anonymised or restricted;
- whether limited data was retained and the general reason; and
- how to raise a concern if you disagree with the outcome.
CEOS will not include another person’s personal data, protected security details or confidential fraud-control information in the response.
Contact and complaints
Deletion and privacy questions may be sent to:
CEOS Enterprise / HLCEOS HOLDINGS SDN. BHD.
Email: admin@ceosfamilysugo.com
Website: https://www.ceosfamilysugo.com/
Subject to applicable law, you may also complain to Malaysia’s Personal Data Protection Commissioner if you believe your personal data has been handled improperly.
