Legal
Privacy Policy
Last Updated: 12 May 2025
Embun ("we", "us", "our") is committed to protecting the personal data of everyone who visits our website or engages with our advisory services. This Privacy Policy explains how we collect, use, store, and protect your data, and outlines your rights under Malaysian data protection law, principally the Personal Data Protection Act 2010 (PDPA).
If you have questions about this policy, please contact us at [email protected].
1. Who We Are
The data controller for personal data processed in connection with Embun's website and services is:
- Business name: Embun
- Address: No. 47, Jalan Macalister, 10400 George Town, Pulau Pinang, Malaysia
- Email: [email protected]
- Phone: +60 4 229 7360
2. Personal Data We Collect
Data you provide directly
When you contact us through the website enquiry form or by email, we may collect:
- Your name
- Your email address
- Your phone number (if you provide it)
- The content of your message, including details about your business
Data collected automatically
When you visit the website, certain technical data may be collected through cookies and analytics tools, including:
- Your IP address and general location
- Browser type and device information
- Pages visited and time spent on the site
- Referring URL
Please refer to our Cookie Policy for full details of cookies used on this website.
3. How We Use Your Personal Data
We use personal data for the following purposes:
- Responding to enquiries: To reply to messages you send us and determine whether our services may be suitable for your situation.
- Delivering advisory services: To fulfil our obligations under any programme agreement, including scheduling sessions, sharing documents, and maintaining client records.
- Improving our website: Using aggregated, anonymised analytics data to understand how visitors use the site.
- Legal compliance: To meet any obligations under Malaysian law where applicable.
Legal basis for processing
Under the PDPA 2010, we process personal data on the following grounds:
- Your consent, provided when you submit the contact form or agree to cookies.
- Contractual necessity, when we need to process data to deliver an agreed programme.
- Legitimate interest, for basic website analytics that help us maintain a functional and informative site.
Data retention
Enquiry data from the contact form is retained for up to 12 months from the date of last contact if no programme begins. Client session records and written documents are retained for 3 years from the end of the engagement, after which they are securely deleted unless otherwise required by law.
4. How We Protect Your Data
We take reasonable technical and organisational measures to protect personal data from unauthorised access, disclosure, or loss. These measures include:
- HTTPS encryption for all website traffic
- Access to client records limited to named team members directly involved in the engagement
- Password-protected storage for written client documents
- Secure deletion of data upon the end of the retention period
In the event of a data breach that may affect your rights, we will notify you and, where required, the relevant Malaysian authorities in accordance with PDPA obligations.
5. Data Sharing
We do not sell or share personal data with third parties for marketing purposes. Personal data may be shared in the following limited circumstances:
- Service providers: We may use third-party tools for email communication and website analytics (such as Google Analytics). These providers process data on our behalf under contractual agreements.
- Legal requirements: Where disclosure is required by Malaysian law, court order, or regulatory authority.
6. Cookies
This website uses cookies for essential functionality, analytics, and user preference storage. You can manage cookie preferences at any time via our Cookie Policy page.
7. Your Rights
Under the PDPA 2010, you have the following rights in relation to your personal data:
- Right of access: You may request a copy of the personal data we hold about you.
- Right of correction: You may request that inaccurate or incomplete data be corrected.
- Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
- Right to cease processing: You may request that we stop processing your data for certain purposes, subject to any overriding legitimate or legal grounds.
To exercise any of these rights, please contact us at [email protected]. We aim to respond within 21 days.
If you have a concern about how we handle your data, you may also contact the Department of Personal Data Protection Malaysia (JPDP) at pdp.gov.my.
8. Third-Party Links
This website may contain links to external websites. We are not responsible for the privacy practices of those sites and encourage you to review their privacy policies directly.
9. Children
Our services are intended for business owners and are not directed at anyone under the age of 18. We do not knowingly collect data from minors. If you believe we have inadvertently collected such data, please contact us and we will delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last Updated" date at the top of this page. If changes are material, we will endeavour to notify active clients by email. Continued use of this website after changes constitutes acceptance of the updated policy.
11. Contact
For privacy-related enquiries, please write to us at [email protected] or by post to:
Embun
No. 47, Jalan Macalister
10400 George Town
Pulau Pinang, Malaysia