Legal
Privacy Policy
Last Updated: 21 April 2025 · Effective: 21 April 2025
1. Introduction
Tuah Partners ("we", "us", "our") is a business advisory practice registered in Malaysia, with its principal office at 89, Persiaran Gurney, 10250 George Town, Pulau Pinang. We are the data controller for personal data collected through this website and through our advisory engagements.
This Privacy Policy describes how we collect, use, store, and protect personal data in accordance with the Personal Data Protection Act 2010 (PDPA) of Malaysia. We take our obligations under the PDPA seriously and handle personal data with the care that our practice demands of all its work.
For enquiries about this policy or your personal data, contact us at [email protected].
2. Personal Data We Collect
2.1 Data you provide directly
- Full name and contact details (email address, telephone number)
- Organisation name and professional role (where provided)
- Nature of the enquiry or situation described in a contact message
- Correspondence conducted by email or post
2.2 Data collected automatically
- IP address and browser type (for security and site analytics)
- Pages visited and time spent (via analytics cookies, if consent is given)
- Cookie preferences (stored in your browser's local storage)
2.3 Legal basis for processing
- Consent — for optional cookies and marketing communications
- Legitimate interest — for responding to enquiries and maintaining our records
- Contractual necessity — for data required to fulfil an advisory engagement
3. How We Use Personal Data
- To respond to enquiries and assess whether an engagement is appropriate
- To conduct and administer advisory engagements you have entered into with us
- To maintain records of correspondence and engagement materials
- To improve our website and understand how visitors use it (analytics, with consent)
- To comply with our legal and regulatory obligations under Malaysian law
We do not use personal data for unsolicited marketing. We do not sell, rent, or trade personal data to third parties for commercial purposes.
4. Data Sharing
We do not share personal data with third parties except in the following limited circumstances:
- With your consent — for example, where an engagement involves coordinating with your legal or accounting advisers
- Service providers — such as web hosting providers who process data on our behalf and are bound by data processing agreements
- Legal obligation — where disclosure is required by law, court order, or regulatory authority in Malaysia
We do not transfer personal data outside Malaysia except where required by law or with your explicit consent.
5. Data Retention
- Enquiry records — retained for 12 months from the date of last correspondence where no engagement was entered into
- Engagement materials — retained for 7 years from the close of the engagement, in accordance with Malaysian statutory requirements
- Analytics data — retained in aggregated, anonymised form; individual session data not retained beyond 26 months
- Cookie preferences — stored in your browser's local storage and retained until you clear your browser data
6. Data Security
We take reasonable technical and organisational measures to protect personal data from unauthorised access, disclosure, alteration, or destruction. These include:
- HTTPS encryption for all data transmitted via this website
- Access controls limiting personal data to authorised personnel only
- Secure email practices for sensitive correspondence
- No retention of engagement materials on public cloud services without encryption
In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the relevant authorities as required under Malaysian law.
7. Cookies
This website uses cookies. Essential cookies are necessary for the site to function correctly and are set without consent. Optional cookies (analytics and marketing) are set only with your consent, which you can manage at any time via our Cookie Policy page.
8. Your Rights Under the PDPA
Under the Personal Data Protection Act 2010, you have the following rights in relation to your personal data:
- Right of access — to request a copy of the personal data we hold about you
- Right of correction — to request correction of inaccurate or incomplete data
- Right to limit processing — to request that we limit use of your data in certain circumstances
- Right to withdraw consent — where processing is based on consent, you may withdraw it at any time
- Right to make a complaint — you may lodge a complaint with the Department of Personal Data Protection Malaysia (JPDP) if you believe your data has been processed unlawfully
To exercise any of these rights, write to us at [email protected]. We will respond within 21 days.
9. Third-Party Links
This website may contain links to external websites. We are not responsible for the privacy practices of those sites and encourage you to review their privacy policies independently.
10. Children
Our services are directed at business principals and senior professionals. We do not knowingly collect personal data from individuals under 18 years of age. If you believe we have inadvertently collected such data, please contact us at [email protected] and we will delete it promptly.
11. Changes to this Policy
We may update this Privacy Policy from time to time. Material changes will be noted with a revised effective date at the top of this page. Continued use of this website after a policy update constitutes acceptance of the revised terms.
12. Contact
For privacy-related enquiries, write to:
Tuah Partners
89, Persiaran Gurney, 10250 George Town, Pulau Pinang, Malaysia
[email protected]
Tel: +60 4-263 5947