Legal

Privacy Policy

How Kemuncak Advisory collects, uses, and safeguards the personal information of those who engage with our practice.

Last revised: 1 January 2025  ·  Kemuncak Advisory, Kuala Lumpur

Kemuncak Advisory ("we", "our", or "the practice") is committed to handling personal information with the same discretion and care we bring to client engagements. This policy explains our practices in plain terms.

This policy applies to information collected through our website at kemuncak-advisory.info, through our engagement intake process, and through correspondence with our practice. It should be read alongside our Terms and Conditions and Cookie Policy.

01

Who We Are

Kemuncak Advisory is a technology vendor selection consultancy registered and operating in Malaysia. Our registered business address is Plaza Mont Kiara, 2 Jalan Kiara, 50480 Kuala Lumpur. We act as the data controller for personal information we collect in connection with our services and website.

Any queries regarding this policy or your personal information may be directed to us at [email protected] or by post to our Kuala Lumpur address above.

02

Information We Collect

Information you provide directly

  • Your name, job title, and organisation, when you complete our contact form or correspond with us by email or telephone.
  • Contact details including email address and telephone number.
  • Information about your organisation's technology procurement needs, which you share during an engagement or initial consultation.
  • Any correspondence, notes, or documents you share with us in the course of an engagement.

Information collected automatically

  • Standard server log data including IP address, browser type, referring URL, and pages visited, collected when you access our website.
  • Cookie and similar tracking data, as described in our Cookie Policy.
  • Aggregate analytics data about website use, which we review periodically to improve our site.
03

How We Use Your Information

We use the information we collect for the following purposes:

  • To respond to enquiries you submit through our website or by other means.
  • To deliver advisory services under a confirmed engagement, including preparing written deliverables, conducting evaluation sessions, and corresponding during the project.
  • To fulfil our invoicing and record-keeping obligations.
  • To improve the content and usability of our website, using aggregated and anonymised data only.
  • To send occasional practice updates where you have given consent and where you may withdraw that consent at any time.
  • To comply with legal obligations applicable to our practice in Malaysia.

We do not use personal information for automated profiling or decision-making that produces legal or similarly significant effects.

04

Legal Basis for Processing

We process personal information on the following legal bases under Malaysia's Personal Data Protection Act 2010 (PDPA) and applicable data protection principles:

  • Consent — where you have expressly agreed to our collection and use of your information, including by submitting our contact form.
  • Contractual necessity — where processing is required to fulfil an advisory engagement you have engaged us to perform.
  • Legitimate interests — where we have a genuine business interest in processing the information and that interest is not outweighed by your rights, such as maintaining our records and improving our website.
  • Legal obligation — where we are required by law to retain or disclose certain records.
05

Sharing Your Information

We treat the information shared with us as confidential. We do not sell, rent, or trade personal information with third parties.

We may share information with third parties only in the following limited circumstances:

  • Service providers — including our website host, email service, and accounting software, who process data on our behalf under appropriate agreements.
  • Legal requirements — where we are required to disclose information by law, court order, or regulatory authority.
  • With your consent — in any other case where you have given express permission.

We do not share client information with candidate vendors during an evaluation engagement without the client's explicit instruction.

06

Data Retention

We retain personal information only for as long as is necessary for the purposes set out in this policy, or as required by law.

  • Enquiry records are held for twelve months from the date of the enquiry, unless the enquiry leads to an engagement.
  • Engagement records, including correspondence and deliverables, are retained for seven years following the close of the engagement, in line with Malaysian business record-keeping requirements.
  • Website analytics data is held in aggregated and anonymised form, and is not tied to individual identities after ninety days.
07

Your Rights

Under the Personal Data Protection Act 2010 and applicable privacy principles, you have the following rights in relation to your personal information:

  • Access — to request a copy of the personal information we hold about you.
  • Correction — to request that inaccurate or incomplete information be corrected.
  • Withdrawal of consent — to withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing prior to withdrawal.
  • Limitation — to request that we restrict processing of your information in certain circumstances.
  • Objection — to object to processing based on legitimate interests, in circumstances where your particular situation warrants it.

To exercise any of these rights, please write to us at [email protected]. We will respond within thirty days. We may need to verify your identity before processing your request.

08

Security

We take reasonable technical and organisational measures to protect personal information against unauthorised access, loss, or disclosure. These include encrypted transmission for online communications, access controls limiting who within our practice may access personal data, and secure storage arrangements.

No transmission over the internet can be warranted as entirely secure. If you have concerns about a specific transmission, you may contact us by telephone instead.

09

Third-Party Links

Our website may contain links to third-party websites. We are not responsible for the privacy practices of those websites and encourage you to review their policies independently.

10

Changes to This Policy

We may update this policy from time to time to reflect changes in our practice, applicable law, or the services we provide. The revised date at the top of this page will reflect any material changes.

We encourage you to review this policy periodically. Continued use of our website or services after an update constitutes acceptance of the revised policy.

Questions about this policy

Reach our practice directly

If you have any questions about how we handle your personal information, or wish to exercise any of your rights, we welcome a direct conversation.