P
Pulau Strategy
Contact Us

Legal & Privacy

Privacy Policy

Pulau Strategy is committed to handling your personal information with care. This policy explains what data we collect, how it is used, and the choices you have.

Last Updated:

1.Introduction

Pulau Strategy ("we", "us", "our") operates a business advisory practice providing trade, operations, and coastal industry consulting services across Malaysia. This Privacy Policy describes how we collect, use, disclose, and safeguard personal information obtained through our website at pulaustr.site and through our client engagement processes.

By accessing our website or submitting an enquiry, you acknowledge that you have read and understood this policy. If you have questions, you may contact us at any time at [email protected].

This policy is governed by Malaysian law, including the Personal Data Protection Act 2010 (PDPA), which establishes principles for the lawful processing of personal data by commercial entities in Malaysia.

2.Data Collection

We may collect the following categories of personal information:

  • Contact details — name, email address, phone number provided via our enquiry form or direct correspondence.
  • Engagement information — details of your business, industry, and the nature of your advisory interest.
  • Technical data — IP address, browser type, pages visited, and time spent on our site, collected through analytics cookies with your consent.
  • Communications — records of emails, calls, or other correspondence related to a service enquiry or engagement.

We collect data through:

  • Our website contact form
  • Direct email or telephone communication
  • Analytics tools (where consent is given)

Legal Basis for Processing

  • Consent — where you have submitted an enquiry or agreed to cookie use.
  • Legitimate interest — responding to your enquiry and improving our advisory services.
  • Contractual necessity — where a formal engagement is in place.

Data Retention

Enquiry records are retained for up to 24 months from last contact. Client engagement records are retained for 7 years in line with Malaysian statutory requirements. Analytics data is retained per platform defaults (typically up to 26 months).

3.How We Use Your Data

We use personal data for the following purposes:

  • Responding to your enquiry and scheduling any initial consultation
  • Delivering advisory services where a formal engagement exists
  • Communicating relevant updates about our services, where you have opted in
  • Understanding site usage to improve content and functionality
  • Meeting legal or regulatory obligations

Data Sharing

We do not sell personal data. We may share data with:

  • Analytics providers (e.g. Google Analytics) — under data processing agreements
  • Advertising platforms (e.g. Meta, Microsoft) — where marketing cookies are consented to
  • Professional advisors and auditors — under confidentiality obligations
  • Regulatory bodies — where required by Malaysian law

Any third party receiving data from us is required to handle it lawfully and in accordance with our instructions.

4.Data Protection Measures

  • All data transmitted through our website is encrypted using HTTPS/TLS.
  • Access to personal data is limited to staff with a direct need and is subject to confidentiality obligations.
  • Our systems are reviewed periodically for security vulnerabilities.
  • In the event of a data breach that may affect your rights, we will notify affected individuals and the relevant authority in a timely manner as required by applicable law.
  • We do not store financial or payment details on our servers.

5.Cookies

We use cookies to support website functionality, understand visitor behaviour, and — where you consent — deliver relevant advertising. Cookie categories include essential, analytics, marketing, and preference cookies.

For full details and to manage your preferences, please visit our Cookie Policy.

6.Your Rights

Under the Personal Data Protection Act 2010 and related frameworks, you have the right to:

Access

Request a copy of the personal data we hold about you.

Rectification

Ask us to correct inaccurate or incomplete data.

Erasure

Request deletion of data no longer necessary for the purposes collected.

Object

Object to processing based on legitimate interest, including direct marketing.

Portability

Request your data in a structured, machine-readable format.

Withdraw Consent

Withdraw consent at any time where processing is consent-based.

To exercise any of these rights, contact us at [email protected]. We will respond within 21 days in line with PDPA requirements. You also have the right to lodge a complaint with the Personal Data Protection Commissioner of Malaysia.

7.Third-Party Links

Our website may contain links to external websites and resources. These are provided for informational purposes only. We have no control over the content or privacy practices of third-party sites and encourage you to review their respective policies before sharing any personal information.

8.Children's Privacy

Our advisory services are directed at business operators and professionals. We do not knowingly collect personal information from individuals under the age of 18. If we become aware that data has been collected from a minor without appropriate consent, we will take prompt steps to remove it.

9.Policy Updates

We may revise this Privacy Policy from time to time. When material changes are made, we will update the "Last Updated" date at the top of this page. We encourage you to review the policy periodically. Continued use of our website following any change constitutes acceptance of the updated terms.

10.Contact Us

For questions, data access requests, or to raise a privacy concern, please contact us directly. We aim to respond within 21 working days.

Address

Level 22, Menara Standard Chartered,
Jalan Sultan Ismail, 50250 Kuala Lumpur