Section 01
Introduction
Warisan Advocate ("we", "our", "the firm") is committed to handling personal information with care and discretion. This Privacy Policy explains what personal data we collect, the purposes for which it is held, and the rights available to individuals under the Personal Data Protection Act 2010 (PDPA) of Malaysia.
This policy applies to personal information submitted through our website, provided during an initial consultation, or shared in the course of instructing us on a pension matter. It does not extend to information processed solely in our capacity as legal advisers under a separate engagement agreement, which is governed by our professional obligations.
For questions about this policy, write to us at [email protected] or refer to the contact details at the foot of this document.
Section 02
Data We Collect
Information you provide directly
- Full name and contact details (email address, telephone number)
- Information you share when describing your pension matter through our contact form or in correspondence
- Details relating to public service records, pension entitlements, or family circumstances — only where you choose to share these in advance of a consultation
Information collected automatically
- Browser type, device type, and approximate geographic location (country/region level)
- Pages visited, duration of visit, and referral source — via analytics cookies where you have consented
- IP address, retained only for security logging purposes
Legal basis for processing
We process personal data on the following grounds under Malaysian law:
- Consent — for website analytics and marketing communications, which you may withdraw at any time
- Contractual necessity — to carry out the services you have engaged us to provide
- Legitimate interests — for the security and improvement of our website, where those interests are not overridden by your rights
Retention periods
- Contact form submissions where no engagement follows: 12 months from the date of submission
- Client matter files and related correspondence: 7 years following the close of the matter, in line with our professional obligations
- Website analytics data: 26 months from collection, in accordance with standard analytics practice
Section 03
How We Use Your Data
Personal information submitted through this website is used only for purposes connected with the delivery of our legal services or the operation of this website. We do not sell personal data to third parties, and we do not use it for purposes unrelated to your matter or your enquiry.
Specifically, we use personal data to:
- Respond to your enquiry and, where instructed, to carry out the legal work described
- Schedule and conduct consultations at a time and place suitable for you
- Communicate updates on your matter and any relevant regulatory or procedural changes
- Maintain the security and integrity of our website and systems
- Understand how our website is used, so that we can improve the information provided
Third-party sharing: We may share information with the Department of Public Service (Jabatan Perkhidmatan Awam), the Employees' Provident Fund, or other relevant Malaysian authorities where this is required to carry out the work you have instructed us on. We do not share personal data with advertising networks, data brokers, or unrelated commercial parties.
Marketing communications: We do not send unsolicited marketing messages. If you have provided your contact details and have not objected, we may occasionally send you information about services relevant to pension matters in Malaysia. You may opt out of these at any time by writing to [email protected].
Section 04
Data Protection Measures
We take reasonable steps to protect personal information from unauthorised access, misuse, or disclosure. These include:
- SSL/TLS encryption for all data transmitted through this website
- Restricted access to client data, limited to personnel who have a professional reason to handle it
- Secure storage on servers located within Malaysia or in jurisdictions with equivalent protections
- Regular review of access logs and monitoring for unusual activity
In the event of a breach: Should a data security incident occur that affects your personal information, we will notify you as promptly as reasonably possible, explain what occurred, and set out the steps being taken. Where required under Malaysian law, we will also notify the relevant authority.
No method of transmission or storage is entirely without risk. We do not represent that information submitted through this website is held under conditions of absolute security.
Section 05
Cookies
This website uses cookies — small data files stored on your device — to operate correctly and, where you have given consent, to help us understand how visitors use the site. The types we use are:
- Essential cookies — required for basic functions such as session management. These cannot be disabled.
- Analytics cookies — used, with your consent, to measure page views and navigation patterns.
- Preference cookies — used to remember choices you have made, such as your cookie consent preferences.
For full details and to manage your cookie settings, please visit our Cookie Policy.
Section 06
Your Rights
Under the Personal Data Protection Act 2010, you have the following rights in relation to personal data we hold about you:
Access — to request a copy of the personal data we hold about you
Correction — to ask us to correct information that is inaccurate or incomplete
Withdrawal of consent — to withdraw any consent you have given for processing, where consent is the legal basis
Objection — to object to processing based on legitimate interests, in certain circumstances
Complaint — to lodge a complaint with the Department of Personal Data Protection Malaysia (JPDP) if you believe your rights have not been respected
To exercise any of these rights, write to [email protected]. We will respond within 21 days of receiving a clear and verifiable request. There is no charge for reasonable requests.
Section 07
Third-Party Links
This website may include links to external websites — for example, to government portals, the Malaysian Bar Council, or regulatory authorities — that are not operated by Warisan Advocate. These links are provided for reference only.
We have no control over the content or privacy practices of external sites. We encourage you to read the privacy notices of any site you visit. We are not responsible for how personal information is handled by third-party operators.
Section 08
Children's Privacy
Our services are directed at adults, and we do not knowingly collect personal information from persons under the age of 18 through this website. If you believe a minor has submitted personal information to us, please contact us at [email protected] and we will take appropriate steps to remove it.
In the context of survivor pension matters involving minor dependants, personal information relating to children is handled only to the extent strictly necessary to process a legitimate claim, and always with the consent of the responsible adult.
Section 09
Policy Changes
We may update this policy from time to time to reflect changes in our practices, our services, or applicable law. When we do, the revised version will be published on this page with an updated "Last Updated" date.
We will not make changes that materially reduce your rights without providing reasonable notice. If you have an ongoing matter with us, we will notify you directly of any significant changes.
Section 10
Contact Information
For data protection enquiries, corrections, access requests, or complaints, please reach us through any of the following:
DATA ENQUIRIES
[email protected]TELEPHONE
+60 3-8841 6275OFFICE ADDRESS
Block C, Level 3, Presint 3, Jalan P3
62100 Putrajaya, Federal Territory of Putrajaya
SUPERVISORY AUTHORITY
Jabatan Perlindungan Data Peribadi (JPDP)
Department of Personal Data Protection Malaysia