Legal
Privacy Policy
Last Updated: 12 May 2025
Budi Pakar ("we", "us", "our") is committed to handling your personal data with care. This policy explains what information we collect when you engage with our website or services, how we use it, and your rights in relation to it. It applies to all individuals who contact us, visit our website, or enter into an advisory arrangement with us.
This policy is prepared in accordance with the Personal Data Protection Act 2010 (PDPA) of Malaysia, which governs how personal data may be collected, used, and disclosed by data processors and data users in Malaysia.
1. Data We Collect
When you contact us or engage our services, we may collect the following personal data:
- Your name and preferred form of address
- Your email address and telephone number
- The name and nature of your business (where relevant to the advisory engagement)
- The content of messages you send us via contact forms or email
- Scheduling information (meeting times and preferences)
- Technical data collected automatically when you visit our website, including your IP address, browser type, and pages visited
We do not collect sensitive personal data (as defined under the PDPA) unless you voluntarily share it with us and it is relevant to your engagement.
Data is collected through our website contact form, direct email correspondence, telephone calls, and in-person sessions at our Jalan Raja Chulan office.
2. How We Use Your Data
We use your personal data for the following purposes:
- To respond to your enquiries and arrange introductory conversations
- To conduct and document advisory sessions
- To send written recap notes and engagement summaries
- To schedule and manage ongoing advisory arrangements
- To maintain records necessary for the conduct of our professional practice
- To comply with legal and regulatory obligations applicable to our business in Malaysia
- To improve the quality and delivery of our services based on aggregated, anonymised feedback
We do not use your data for automated decision-making or profiling. We do not send unsolicited marketing communications. If you have engaged with us in the past and we believe you may be interested in hearing from us, we will contact you only where this is a reasonable expectation of the ongoing relationship.
3. Legal Basis for Processing
We process your personal data on the following bases under the PDPA:
- Consent: Where you have actively contacted us or submitted a form on our website
- Contractual necessity: Where processing is required to deliver advisory services you have engaged
- Legitimate interests: Where we maintain records necessary to conduct our practice responsibly and professionally
- Legal compliance: Where we are required to retain or disclose data to meet legal obligations
4. Data Retention
We retain personal data for as long as is necessary for the purpose for which it was collected:
- Enquiries that do not proceed to an engagement: up to 12 months
- Active client records: for the duration of the engagement plus 5 years
- Financial records: as required by Malaysian law (minimum 7 years)
- Website analytics data: no more than 26 months in aggregated form
When data is no longer required, it is securely deleted or anonymised.
5. Data Sharing and Third Parties
We do not sell, rent, or trade your personal data. We may share data with third parties only in the following limited circumstances:
- With service providers who support our operations (e.g., secure email and scheduling tools), under appropriate data processing agreements
- Where required by law, court order, or regulatory authority in Malaysia
- Where you have given explicit consent for a specific sharing purpose
Where we use third-party tools (such as video conferencing providers for remote sessions), we select services with appropriate data protection standards. We do not control the privacy practices of external platforms you may use independently.
6. Data Security
We take reasonable technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration, or loss. These measures include:
- Encrypted storage and transmission of client files
- Access controls limiting data to authorised personnel only
- Regular review of our data handling practices
- Secure disposal of physical and digital records when no longer required
In the event of a data breach that poses a risk to your rights, we will notify you and, where required, the relevant authority within a reasonable timeframe.
7. Cookies
Our website uses cookies to function and to understand how visitors interact with our pages. Essential cookies are required for the site to operate. Optional cookies (analytics and preference) are only set with your consent.
You can manage your cookie preferences at any time via our Cookie Policy page.
8. Your Rights Under Malaysian Law
Under the Personal Data Protection Act 2010, you have the following rights in relation to the personal data we hold about you:
- Right of access: You may request a copy of the personal data we hold about you
- Right of correction: You may request that inaccurate or incomplete data be corrected
- Right to withdraw consent: You may withdraw consent at any time, where processing is based on consent
- Right to limit processing: You may request that we limit how we use your data in certain circumstances
- Right to enquire: You may ask questions about how your data is used or stored
To exercise any of these rights, please contact us at [email protected]. We will respond within 21 days. There is no charge for a reasonable access request.
If you are not satisfied with our response, you may contact the Personal Data Protection Commissioner of Malaysia, the supervisory authority under the PDPA.
9. Links to External Websites
Our website may contain links to third-party websites. We are not responsible for the privacy practices of those sites and encourage you to read their privacy policies before sharing any personal information. The inclusion of a link does not constitute our endorsement of the site.
10. Children
Our services are intended for business owners and individuals aged 18 or over. We do not knowingly collect personal data from individuals under the age of 18. If you believe we have inadvertently collected such data, please contact us immediately and we will delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. When we do, we will update the "Last Updated" date at the top of this page. Where changes are material, we will notify existing clients directly. Continued use of our website or services after any changes constitutes acceptance of the updated policy.
12. Contact for Privacy Matters
If you have questions about this policy or wish to exercise any of your data rights, please contact us at:
Budi Pakar
26, Jalan Raja Chulan, 50200 Kuala Lumpur, Malaysia
Email: [email protected]
Phone: +60 19-635 4827