Privacy Policy
This policy explains how Serasi Group Sdn. Bhd. collects, uses, and protects personal data in accordance with Malaysia's Personal Data Protection Act 2010 (PDPA). We encourage you to read it carefully.
1. Introduction
Serasi Group Sdn. Bhd. ("we", "us", or "our") is a business consulting firm registered in Malaysia, with our principal office at 7, Jalan Teknologi 3/1, Taman Teknologi Malaysia, 57000 Kuala Lumpur. We are committed to protecting the personal data you share with us and handling it with transparency and care. Questions about this policy may be directed to [email protected].
2. Personal Data We Collect
We collect the following categories of personal data when you interact with our website or engage our services:
- Contact information: name, email address, telephone number
- Business information: company name, role, industry sector
- Enquiry content: details you share in contact forms or correspondence
- Technical data: IP address, browser type, pages visited, session duration (via analytics cookies where consent has been given)
We do not collect sensitive personal data such as identification card numbers, financial account details, or health information through our website.
3. How We Collect Personal Data
Personal data is collected through the following means:
- Contact forms on our website
- Email correspondence initiated by you
- Telephone calls where notes are taken with your awareness
- Cookies and website analytics tools (subject to your consent preferences)
4. Legal Basis for Processing
We process your personal data on the following legal bases under the PDPA 2010:
- Consent: where you have provided express consent (e.g. cookie preferences, newsletter sign-up)
- Contractual necessity: where processing is required to fulfil a consulting engagement you have entered into with us
- Legitimate interests: where we have a genuine business reason to process data, balanced against your rights (e.g. responding to an enquiry you submitted)
5. How We Use Your Personal Data
We use the personal data we collect for the following purposes:
- Responding to your enquiries and providing requested information
- Delivering and managing consulting engagements
- Sending service-related communications (invoices, progress updates, deliverables)
- Improving our website and service experience based on aggregated analytics
- Meeting our legal and regulatory obligations in Malaysia
We do not sell, rent, or trade personal data to third parties for marketing purposes.
6. Data Retention
We retain personal data only for as long as necessary to fulfil the purpose for which it was collected:
- Enquiry data (non-clients): up to 12 months from the date of enquiry
- Client engagement data: up to 7 years following engagement completion, in line with Malaysian statutory requirements for business records
- Analytics data: up to 26 months from collection (where consent has been given)
7. Data Sharing
Your personal data may be shared with the following categories of recipients only where strictly necessary:
- Engagement team members: Serasi Group consultants directly involved in your project
- Technology service providers: hosting, email, and analytics platforms operating under data processing agreements
- Regulatory or legal authorities: where required by Malaysian law or court order
We do not transfer personal data outside of Malaysia unless appropriate safeguards are in place.
8. Data Protection Measures
We take reasonable technical and organisational measures to protect personal data against unauthorised access, loss, or misuse. These include:
- Encrypted data transmission (HTTPS) on our website
- Access controls limiting data access to authorised team members
- Secure document handling during consulting engagements, including NDAs with clients
- Regular review of our data handling practices
9. Cookies
Our website uses cookies to support its functionality and, where consent is given, to collect analytics data. We use four categories of cookies: essential (always active), analytics, marketing, and preference. You can manage your cookie preferences at any time via our Cookie Policy page.
10. Your Rights Under the PDPA
As a data subject under Malaysian law, you have the following rights:
- Right of access: to request a copy of the personal data we hold about you
- Right of correction: to request that inaccurate or incomplete data be corrected
- Right to withdraw consent: where processing is based on consent, you may withdraw it at any time
- Right to limit processing: to request that we restrict the use of your data in certain circumstances
To exercise any of these rights, please contact us at [email protected]. We will respond within 21 days in line with PDPA requirements.
11. Third-Party Links
Our website may contain links to third-party websites. We are not responsible for the privacy practices of those sites and recommend reviewing their respective privacy policies before submitting any personal data.
12. Children's Privacy
Our services are intended for business professionals aged 18 and above. We do not knowingly collect personal data from individuals under 18 years of age. If you believe a minor has submitted data to us, please contact us immediately and we will remove it.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When material changes are made, we will update the "Last Updated" date at the top of this page. Continued use of our website following such changes constitutes your acknowledgement of the updated policy.
14. Contact
All privacy-related enquiries should be directed to:
- Email: [email protected]
- Address: Serasi Group Sdn. Bhd., 7, Jalan Teknologi 3/1, Taman Teknologi Malaysia, 57000 Kuala Lumpur, Malaysia
- Phone: +60 3-8946 3718