Legal
Privacy Policy
Last Updated: 10 April 2025 | Effective Date: 10 April 2025
Warisan Advisory takes the protection of your personal information seriously. This policy explains what data we collect, how it is used, and the rights you have in relation to your information. We are committed to handling personal data in a manner that is transparent, lawful, and respectful of the people whose information we hold.
1. Who We Are
Warisan Advisory is a consultancy practice registered in Malaysia, operating from A-3-8, Jalan PJS 8/9, Dataran Mentari, 46150 Petaling Jaya, Selangor. For any privacy-related enquiries, you may contact us at [email protected] or by phone at +60 3 5634 8279.
2. What Personal Data We Collect
We collect personal data in the following circumstances:
- When you submit an enquiry through our contact form (name, email address, phone number, message content)
- When you correspond with us by email or telephone
- When you engage us for consulting services (organisational and professional information)
- Through cookies and website analytics (see Section 5 below)
We do not collect sensitive categories of personal data unless this is explicitly provided by you in the course of an engagement and is directly relevant to the work being undertaken.
3. Legal Basis for Processing
We process your personal data on the following grounds under the Personal Data Protection Act 2010 (PDPA) of Malaysia:
- Consent: Where you have freely given consent, including through cookie acceptance or enquiry form submission
- Contractual necessity: Where processing is necessary for the performance of a contract to which you are party
- Legitimate interests: Where we have a legitimate interest that does not override your rights — for example, in maintaining records of past engagements
- Legal obligation: Where we are required to process data to comply with a legal requirement
4. How We Use Your Personal Data
We use your personal data for the following purposes:
- To respond to enquiries and provide information about our services
- To deliver consulting engagements and associated advisory work
- To maintain records of past and current engagements for professional and legal purposes
- To send follow-up communications where consent has been given
- To improve our website and service offering based on usage data
We do not sell personal data to third parties. We do not use personal data for automated decision-making.
5. Cookies and Website Analytics
Our website uses cookies to understand how visitors interact with the site. For full information about the types of cookies used and how to manage your preferences, please see our Cookie Policy. We use Google Analytics to understand aggregate usage patterns; this does not involve the identification of individual visitors without additional consent.
6. Data Retention
We retain personal data only for as long as is necessary for the purposes for which it was collected:
- Enquiry records: 24 months from date of submission
- Engagement records: 7 years from completion of engagement (for professional and legal compliance purposes)
- Cookie consent records: 12 months from date of consent
After these periods, data is securely deleted or anonymised.
7. Sharing Personal Data
We do not share personal data with third parties except in the following circumstances:
- Service providers who assist in operating our website (such as hosting and analytics services), subject to appropriate data processing agreements
- Where required by law, court order, or competent regulatory authority
- In the event of a restructuring or transfer of our business, subject to the recipient maintaining equivalent standards of protection
8. Data Protection Measures
We take reasonable technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure. These include:
- Secure, encrypted connections (HTTPS) for all data transmission
- Access controls limiting who within Warisan Advisory can access personal data
- Regular review of data practices and security arrangements
- Clear procedures for responding to data breaches, including timely notification where required by law
9. Your Rights
Under the PDPA 2010 and applicable law, you have the following rights in relation to your personal data:
- Right of access: You may request a copy of the personal data we hold about you
- Right to correction: You may ask us to correct inaccurate or incomplete data
- Right to withdraw consent: Where processing is based on consent, you may withdraw that consent at any time
- Right to erasure: In certain circumstances, you may ask us to delete your personal data
- Right to object: You may object to processing based on legitimate interests
To exercise any of these rights, please contact us at [email protected]. We will respond to requests within 21 days.
10. Links to Third-Party Sites
Our website may contain links to external sites. We are not responsible for the privacy practices of those sites. We encourage you to review the privacy policies of any third-party sites you visit.
11. Children's Privacy
Our services are intended for adults and organisations. We do not knowingly collect personal data from individuals under the age of 18. If we become aware that such data has been submitted, we will delete it promptly.
12. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated by updating the "Last Updated" date at the top of this page. We encourage you to review this policy periodically. Continued use of our website after a change has been published constitutes acceptance of the updated policy.
13. Contact for Privacy Matters
For any questions or concerns about this privacy policy or how we handle personal data, please contact:
- Email: [email protected]
- Phone: +60 3 5634 8279
- Post: Warisan Advisory, A-3-8, Jalan PJS 8/9, Dataran Mentari, 46150 Petaling Jaya, Selangor, Malaysia
You also have the right to lodge a complaint with the Personal Data Protection Commissioner of Malaysia if you believe your rights have not been adequately addressed.