Legal
Privacy Policy
Cindermark is committed to handling your personal data responsibly and transparently. This policy describes what information we collect, how we use it, and the choices available to you. It applies to all interactions with our website and advisory services.
Last updated: 8 May 2025
Jurisdiction: Malaysia — Personal Data Protection Act 2010 (PDPA)
Contents
1. What Data We Collect
We collect personal data only when you provide it voluntarily or when it is generated through your use of this website. The categories of data we may collect include:
- Contact details — your name, email address, and phone number when submitted via our contact form.
- Enquiry content — the text of messages you send to us through the website.
- Usage data — pages visited, time on site, referring source, and browser type, collected automatically via analytics tools where you have consented.
- Cookie data — preference and consent records stored locally in your browser.
We do not collect sensitive personal data (such as financial records, health data, or identity document numbers) through this website.
Legal basis for processing (PDPA 2010)
- Consent — where you have given clear consent for optional cookies or communications.
- Contractual necessity — where processing is required to respond to your service enquiry.
- Legitimate interests — for website security, fraud prevention, and service improvement.
- Legal obligation — where required by Malaysian law or regulatory authority.
We retain contact enquiry data for up to 24 months from the date of receipt, unless a longer period is required for an ongoing engagement. Analytics data is retained in line with the relevant third-party service settings (typically up to 26 months).
2. How We Use Your Data
Data you provide through this website is used for the following purposes:
- Responding to your enquiries and following up on service requests.
- Scheduling advisory sessions where applicable.
- Sending information about our services where you have requested it.
- Maintaining records of communications for continuity and quality.
- Understanding how visitors use our website to improve content and structure.
- Meeting our obligations under Malaysian law.
We do not use your data for automated decision-making or profiling in ways that have a significant effect on you.
If you have given consent to receive communications, you may withdraw that consent at any time by contacting us at [email protected].
3. How We Protect Your Data
We take reasonable technical and organisational precautions to protect personal data from loss, misuse, or unauthorised access. These include:
- HTTPS encryption for all data transmitted via this website.
- Restricted access to stored enquiry data — only accessible to authorised personnel.
- Use of reputable third-party services with their own security and compliance standards.
- Regular review of our data handling practices.
In the event of a data breach that is likely to affect your rights or interests, we will notify you and the relevant authority as required under applicable Malaysian data protection requirements.
4. Cookies
This website uses cookies to support its functionality and, where you have consented, to understand site usage. The main categories of cookies we use are:
- Essential — required for the site to operate; cannot be turned off.
- Analytics — help us understand how pages are used; only active with your consent.
- Marketing — used for ad-related tracking; only active with your consent.
- Preferences — remember your settings between visits; only active with your consent.
For full details and to manage your cookie choices, see our Cookie Policy.
5. Data Sharing and Third Parties
We do not sell or rent personal data to third parties. We may share data in the following limited circumstances:
- Service providers — analytics and email tools that process data on our behalf, under contractual data processing agreements.
- Legal requirements — where we are required by law, court order, or regulatory authority to disclose information.
- Business succession — if our business is transferred or restructured, data may be transferred as part of that process, subject to the same protections.
Third-party services currently in use on this site include Google Analytics and Google Ads. Each operates under its own privacy and data processing terms.
We do not transfer personal data outside Malaysia other than to reputable international service providers (such as Google), whose data handling meets equivalent protection standards.
6. Your Rights
Under the Personal Data Protection Act 2010 (Malaysia), you have certain rights in relation to your personal data held by us:
Access
You may request a copy of the personal data we hold about you.
Correction
You may ask us to correct any inaccurate or incomplete data.
Withdraw Consent
Where processing is based on consent, you may withdraw it at any time.
Objection
You may object to processing carried out on the basis of our legitimate interests.
Erasure
You may request deletion of your data where there is no lawful basis to retain it.
Complaint
You may file a complaint with the Department of Personal Data Protection (JPDP) Malaysia.
To exercise any of these rights, contact us in writing at [email protected]. We will respond within 21 days of receiving your request.
7. Third-Party Links
Our website may contain links to external sites. We are not responsible for the privacy practices of those sites and encourage you to review their policies before providing any personal data. This policy applies only to information collected through our website.
8. Children's Privacy
Our services are directed at business professionals and organisations. We do not knowingly collect personal data from individuals under the age of 18. If we become aware that data from a minor has been submitted, we will delete it promptly. If you believe a minor has provided data to us, please contact us so we can address it.
9. Policy Updates
We may update this policy from time to time to reflect changes in how we operate or changes in applicable law. When we do, we will update the "Last updated" date at the top of this page. We encourage you to review this page periodically. Continued use of our website after changes are posted constitutes acceptance of the updated policy.
10. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, please reach out to us:
Data Controller: Cindermark
Suite 12-3, Menara Mudajaya, Mutiara Damansara, 47810 Petaling Jaya, Selangor, Malaysia
For complaints that remain unresolved, you may contact the Department of Personal Data Protection (Jabatan Perlindungan Data Peribadi — JPDP) of Malaysia.