Privacy Policy
Last Updated: 10 May 2025 · Selasih Group, 22 Jalan Bukit Mertajam, 14000 Bukit Mertajam, Penang, Malaysia
1. Introduction
Selasih Group ("we", "our", "us") takes the handling of personal data seriously. This policy sets out how we collect, use, store and protect information about individuals who engage with our website or who enter into an advisory engagement with us.
This policy is prepared in accordance with Malaysia's Personal Data Protection Act 2010 (PDPA). By using our website or submitting an enquiry, you confirm that you have read and understood this policy.
For questions about this policy or about how your data is handled, please write to [email protected].
2. Data We Collect
We collect only the personal data that is necessary for the purpose for which it is collected. This typically includes:
- Contact information: name, email address, telephone number — provided voluntarily via the enquiry form on our website.
- Organisational context: information about your organisation's size, sector and current technology situation, which you choose to share when making an enquiry or entering an engagement.
- Website usage data: browser type, pages visited, time on site — collected via analytics cookies, if consent has been given.
- Communications: records of email and other written exchanges related to an engagement.
We do not collect sensitive personal data as defined under the PDPA (such as health, financial, political or religious information) in the ordinary course of our advisory work.
3. Legal Basis for Processing
Under the PDPA 2010, we process personal data on the following bases:
- Consent: for analytics cookies and marketing communications, where you have opted in.
- Contractual necessity: to fulfil an advisory engagement you have entered into with us.
- Legitimate interest: to respond to enquiries and to maintain records of our advisory work where there is a legitimate purpose for doing so.
- Legal obligation: where we are required to retain or disclose data by Malaysian law.
4. How We Use Your Data
Personal data collected is used for the following purposes:
- Responding to enquiries submitted via our website or by email.
- Conducting advisory engagements and delivering written outputs.
- Maintaining an engagement record for quality and continuity purposes.
- Sending service-related communications (not marketing unless specifically consented to).
- Improving our website and understanding how it is used (where analytics consent has been given).
We do not sell, rent or share personal data with third parties for commercial purposes. We do not send marketing communications without explicit consent.
5. Data Retention
We retain personal data only for as long as is necessary for the purposes described above:
- Enquiry records: 12 months from last contact, unless an engagement commences.
- Engagement records: 5 years from the conclusion of the engagement, for professional accountability purposes.
- Website analytics data: 26 months in aggregated form.
- Email correspondence: retained for the duration of the engagement plus 2 years.
After the applicable retention period, personal data is securely deleted or anonymised.
6. Data Protection Measures
We take reasonable technical and organisational measures to protect personal data from unauthorised access, loss, or misuse. These include:
- Encrypted email communications where sensitive information is exchanged.
- Password-protected storage for engagement documentation.
- Access limited to practitioners directly involved in the relevant engagement.
- Regular review of data handling practices.
In the event of a data breach that poses a risk to affected individuals, we will notify the relevant parties and, where required by law, the relevant authority, within a reasonable timeframe.
7. Cookies
Our website uses cookies to understand how it is used and, where consent has been given, to support analytics. Cookies that are not strictly necessary for site operation are only placed after you have given consent via the cookie notice displayed on your first visit.
Full details of the cookies we use, their purpose and duration, and instructions for managing them, are set out in our Cookie Policy.
8. Your Rights Under the PDPA 2010
Under Malaysia's Personal Data Protection Act 2010, you have the following rights in respect of your personal data:
- Right of access: to request a copy of the personal data we hold about you.
- Right of correction: to request that inaccurate or incomplete personal data be corrected.
- Right to limit processing: to request that we stop or limit our processing of your personal data in certain circumstances.
- Right to withdraw consent: where processing is based on consent, to withdraw that consent at any time (without affecting the lawfulness of prior processing).
- Right to prevent processing for direct marketing: to opt out of any marketing communications.
To exercise any of these rights, please write to [email protected]. We will respond within 21 days.
If you are not satisfied with our response, you may lodge a complaint with the Department of Personal Data Protection Malaysia (JPDP), which is the supervisory authority under the PDPA 2010.
9. Third-Party Links
Our website may contain links to third-party sites. We are not responsible for the privacy practices or content of those sites. We encourage you to review the privacy policies of any external site you visit.
10. Children's Privacy
Our services are directed at organisations and their professional representatives. We do not knowingly collect personal data from individuals under the age of 18. If you believe we have inadvertently collected data from a minor, please contact us at [email protected] and we will promptly delete it.
11. Changes to This Policy
We may update this policy from time to time to reflect changes in our practices or in applicable law. Updated versions will be posted on this page with a revised "Last Updated" date. Continued use of our website following the posting of changes constitutes your acknowledgement of those changes.
12. Contact
Data Controller: Selasih Group
22 Jalan Bukit Mertajam, 14000 Bukit Mertajam, Penang, Malaysia
Email: [email protected]
Telephone: +60 4 538 9217