VESTIGO and its affiliates are committed to protecting and respecting your privacy.

In general this VESTIGO Privacy Statement (“Privacy Statement”) explains the type of personal data we collect, the people who visits VESTIGO’s website (“Website”), when and why we collect such data, how we intend to use it, the conditions under which we may disclose the data to others, and how we keep it secured and protected. Please read below carefully to understand VESTIGO’s views and practices regarding your personal data and how we will treat it.

WHO WE ARE
VESTIGO is a small marginal fields specialist that delivers rapid monetization of hydrocarbon resources. VESTIGO is a wholly owned subsidiary of PETRONAS Carigali Sdn Bhd and incorporated under the laws of Malaysia with company number 1044120-D, having its place of business in Menara Binjai, Level 13, No. 2 Jalan Binjai, Off Jalan Ampang, 50450, Kuala Lumpur, Malaysia.
INFORMATION GATHERING AND USAGE

We may collect information about you when you are interacting with us through our Website, for example when you contact us for further information, register for job alerts, or take part in any of our online or digital initiatives.
We may collect your personal data which you voluntarily provide to us through our Website such as your name, your contact information (i.e. your address, email address, telephone number), information which is collected from you automatically such as your log-in information, browser type, operating system, and URL information, and other information depending on the purpose of your visit to our Website.
We may use personal data that we obtain from you:
• in respect of personal details and contact information which you have provided to us, to identify you and personalise it to your requirement or interest;
• in respect of information which is collected from you automatically, to ensure that content is presented in the most effective manner wherein data is properly organized in data controller database for you and for your computer, to allow you to participate in interactive features of our Website, when you choose to do so, as well as being part of our efforts to keep our Website safe and secure;
• to obtain information about your preferences, online movements and use of our Website;
• to carry out research and statistical analysis to help improve our content, our products and services and to help us better understand your requirements and interests;
• to process, facilitate, administer and provide information on our products and services, to carry out, manage and maintain your relationship with us, your commercial transactions and dealings with us, or promote products and services of our affiliates which we think may be of interest to you (subject to your consent);
• in other circumstances, such purposes that are necessary or directly related to your relationship with us or where it is permitted under the applicable laws.
When we collect personal data from you through our Website, we will only do so when needed for fulfilment of one of the purposes set out above.
Processing your personal data, and obtaining your consent

Your consent is required for processing your personal data, however you may withdraw your consent at any time, by contacting us by using the contact details below. Notwithstanding the foregoing, withdrawing your consent will not affect the previous data processing as prior consent has been given.
There may be instances where we process your personal data without having obtained your consent when it is required by the law, for our legitimate interests or other lawful grounds. This applies to processing activities which are governed by the applicable laws of certain jurisdictions in which we operate. We do not seek your consent in such cases in order for us to provide you with efficient services (in some cases obtaining consent might not be possible for example, for detection of fraud). Before processing your personal data, your rights as a Data Subject will be taken into account.
Storage of your information
All information you have provided to us is stored on our secure servers. We maintain appropriate administrative, technical and physical safeguards to protect against loss, misuse or unauthorized access, disclosure, alteration or destruction of the personal data you have provided to us in accordance with applicable laws.
Where we have given you (or where you have chosen) a password which enables you to access certain parts of our site, you are responsible for keeping this password confidential. We recommend you not to share your password with anyone for security reasons.

Period for which we store your personal data

We only keep your personal data for as long as we require in order to fulfil the purpose for which it was collected or provided to us (unless a legal obligation requires us to keep it for a longer period).
Transfers of your information

We limit access to personal data we collect to our employees and third-party agents (where your consent is obtained), whom we reasonably believe require your information to address your issues and respond to your requests. Such third parties may include:
• other members of VESTIGO and its affiliates;
• our approved sub-contractors, business partners, suppliers, or other third-party organizations providing administrative, IT or other services to VESTIGO or its affiliates.
• analytics and search engine providers that assist us in the improvement and optimization of our site;
• advertisers and advertising networks that require the data to select and serve relevant adverts to you and others; or
• third parties in connection with the transfer of all or any part of our business or assets.
We will also disclose your personal data to third parties if we are under a duty to disclose or share your personal data in order to comply with any legal obligation, or to protect the rights, property, or safety of VESTIGO and its affiliates or others.
As part of the services offered to you through this Website, the information which you provide to us may in some instances be transferred to countries outside of the European Economic Area (“EEA”). The data protection laws in such countries may not provide the same level of protection for your personal data as provided for under European data protection laws. However, when we transfer your information outside of the EEA in this way, we take steps to ensure that appropriate security measures are taken with the aim of ensuring that your privacy rights continue to be protected as outlined in this Privacy Statement. You can obtain further details about these security measures by contacting us at the contact details set out below.

If we transfer your personal data we will always do so under strict conditions of confidentiality and similar levels of security safeguards.

YOUR RIGHTS UNDER EUROPEAN UNION LAWS, IF APPLICABLE

The General Data Protection Regulation (Regulation EU 2016/679) (“GDPR”) was adopted in the European Union (“EU”) on 27 April 2016 and takes full effect from 25 May 2018.

Occasionally, VESTIGO might receive or collect through our Website the types of personal data described in this Privacy Statement from individuals who are located in the EU or the EEA when accessing our Website. If and to the extent that the GDPR applies to our processing of your personal data as described in this Privacy Statement, please note that you may have the following rights:

• Access. You may contact us at any time in order to request access to the personal data we hold about you. We will confirm whether we are processing your personal data, provide details of the categories of personal data concerned and the reasons for our processing.
• Rectification. If the information we hold appears to be inaccurate we will not use it, and not disclose it to others unless and until the information is verified. You should notify us to correct, adjust or complete your personal data by providing the correct information at any time. To the extent reasonably possible, we will inform parties of your updated or amended personal data for their further actions.

• Restriction. In certain circumstances, it may be possible to require us to limit the way in which we process your personal data (i.e., require us to continue to store your personal data, but not otherwise process it without your consent).

• Erasure. You may ask to have the information on your account deleted or removed. We will try to do so promptly, and, to the extent reasonably possible, we will inform anyone who has received your personal data of your request. However, we must keep track of certain transaction information, for legal compliance purposes, so we may not be able to fully delete your information in certain circumstances.

• Receiving/transferring your personal data. You may also ask us to send you the personal data we hold on you in an electronic, structured and user-friendly format, or you may ask us to send this data to another entity. Please note that if you choose to ask us to send your personal data to you or another party, this may impact our ability to provide the products and services you requested as data portability may be subject to the system’s compatibility between sender and receiver (which may affect the format of the data transferred).
• Object. Save and except for data processing without your consent to pursue our legitimate interests, you may object the processing of your personal data. In particular where we use your personal data to contact you for marketing purposes. Such objection can be raised at any time by notifying us.

• Automated decision-making. You have the right to be informed of any automated decision-making, including profiling, used in connection with your personal data, and we will provide information about such implementation, as well as the significance and consequences of such processing.

• Complaints. If you are located in the EEA and you believe that our processing of your personal data is in breach of data protection law, you have the right to lodge a complaint with the relevant data protection supervisory authority in the country where you are based or any place in the EEA where you believe the infringement has occurred. A list of EU national data protection authorities can be found https://edpb.europa.eu/about-edpb/board/members_en. You may also contact us at any time if you wish to complain about our processing of your personal data.
SECURITY
We limit access to personal data that we collect about you to our employees and third-party agents, who we reasonably believe need to have access to your information to provide you with the information or services you request from us. We have reasonable security measures in place to help protect against the loss, misuse and alteration of the information under our control. While we cannot guarantee that loss, misuse or alteration to the personal data will not occur, we ensure that our systems adhere to market security standard so as to help safeguard against such occurrences.
CHANGES TO YOUR DETAILS OR PREFERENCES

We aim to keep our records as up-to-date and accurate as possible. You can review, change or delete the details supplied to us through our Website by contacting us at the contact details set out below. Depending on your location and the nature of our personal data processing activities, the laws of jurisdictions such as the EU might apply to our processing of your personal data. You may also have the right to ask us not to process your personal data for marketing purposes. To the extent required by such applicable laws, we may inform you (before collecting your data) if we intend to use your data for such purposes or if we intend to disclose your information to any third party for such purposes.

You can exercise your right to prevent such processing by checking certain boxes on the forms we use to collect your data, or by contacting us at the contact details set out below. Please note that if you ask us to delete your data this may impact on our ability to provide the services you request. In addition, we may keep track of certain information for legal compliance purposes, so we may not be able to fully delete it in certain circumstances.

COOKIES AND SIMILAR TECHNOLOGIES

VESTIGO and its affiliates and our third-party providers set and use cookies and similar technologies in order to distinguish you from other users of our Website, to provide a better experience when you browse our Website, and to improve the Website’s performance and usefulness. The use of cookies and similar technologies is standard across websites and applications in which information about your online activities is collected.

A cookie is a small data file that Website place on your hard drive when you visit the Website. A cookie file can contain information such as a user ID that tracks the pages you’ve visited within that site. The cookies on this Website are primarily used to recognize that a user has visited the Website previously and to track user traffic patterns. We do not correlate this information with data about individual users, nor do we share this information or sell it to any third party.

Managing Cookies

If you prefer not to receive cookies through the Website, you can set your browser to warn you before accepting cookies and refuse the cookie when your browser alerts you to its presence. You also can refuse all cookies by turning them off in your browser. For more information about cookies, including how to set your browser to reject cookies, visit www.allaboutcookies.org.

Cookie Expiration

The cookies will remain on your computer after the browser is closed. Until removed, the cookies will become active again when the website is reopened. Cookies can be deleted by you, at any time, and will not collect any information when you are not accessing the website.

LINKS TO THIRD PARTY WEBSITES (IF APPLICABLE)

Our Website may, from time to time, contain links to and from the websites and social media channels of our networks, advertisers and affiliates. If you follow a link to any of these websites or channels, please note that these websites or channels have their own privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any personal data to these websites or channels.

CHANGES TO OUR PRIVACY STATEMENT

Any changes we make to our Privacy Statement in the future will be posted on this page and, where appropriate, we shall notify you by e-mail. Please check our Website or you may contact us to know any updates or changes to our Privacy Statement.

LANGUAGE

In accordance with the requirement of Malaysian data protection and privacy law, this Privacy Statement is issued in both English and Bahasa Malaysia. In the event of any inconsistencies or discrepancies between the English version and the Bahasa Malaysia version, the English version shall prevail.

HOW YOU CAN CONTACT US

Any questions, comments and requests regarding this Privacy Statement are welcomed and should be addressed to:
Legal Department, VESTIGO Petroleum Sdn Bhd

Address: Menara Binjai, Level 13, No. 2 Jalan Binjai, Off Jalan Ampang, 50450, Kuala
Lumpur, Malaysia
Email Address: info@vestigopetroleum.com