Privacy Policy
Pulau Strategy is committed to handling your personal information with care. This policy explains what data we collect, how it is used, and the choices you have.
1.Introduction
Pulau Strategy ("we", "us", "our") operates a business advisory practice providing trade, operations, and coastal industry consulting services across Malaysia. This Privacy Policy describes how we collect, use, disclose, and safeguard personal information obtained through our website at pulaustr.site and through our client engagement processes.
By accessing our website or submitting an enquiry, you acknowledge that you have read and understood this policy. If you have questions, you may contact us at any time at [email protected].
This policy is governed by Malaysian law, including the Personal Data Protection Act 2010 (PDPA), which establishes principles for the lawful processing of personal data by commercial entities in Malaysia.
2.Data Collection
We may collect the following categories of personal information:
- Contact details — name, email address, phone number provided via our enquiry form or direct correspondence.
- Engagement information — details of your business, industry, and the nature of your advisory interest.
- Technical data — IP address, browser type, pages visited, and time spent on our site, collected through analytics cookies with your consent.
- Communications — records of emails, calls, or other correspondence related to a service enquiry or engagement.
We collect data through:
- Our website contact form
- Direct email or telephone communication
- Analytics tools (where consent is given)
Legal Basis for Processing
- Consent — where you have submitted an enquiry or agreed to cookie use.
- Legitimate interest — responding to your enquiry and improving our advisory services.
- Contractual necessity — where a formal engagement is in place.
Data Retention
Enquiry records are retained for up to 24 months from last contact. Client engagement records are retained for 7 years in line with Malaysian statutory requirements. Analytics data is retained per platform defaults (typically up to 26 months).
3.How We Use Your Data
We use personal data for the following purposes:
- Responding to your enquiry and scheduling any initial consultation
- Delivering advisory services where a formal engagement exists
- Communicating relevant updates about our services, where you have opted in
- Understanding site usage to improve content and functionality
- Meeting legal or regulatory obligations
Data Sharing
We do not sell personal data. We may share data with:
- Analytics providers (e.g. Google Analytics) — under data processing agreements
- Advertising platforms (e.g. Meta, Microsoft) — where marketing cookies are consented to
- Professional advisors and auditors — under confidentiality obligations
- Regulatory bodies — where required by Malaysian law
Any third party receiving data from us is required to handle it lawfully and in accordance with our instructions.
4.Data Protection Measures
- All data transmitted through our website is encrypted using HTTPS/TLS.
- Access to personal data is limited to staff with a direct need and is subject to confidentiality obligations.
- Our systems are reviewed periodically for security vulnerabilities.
- In the event of a data breach that may affect your rights, we will notify affected individuals and the relevant authority in a timely manner as required by applicable law.
- We do not store financial or payment details on our servers.
6.Your Rights
Under the Personal Data Protection Act 2010 and related frameworks, you have the right to:
Request a copy of the personal data we hold about you.
Ask us to correct inaccurate or incomplete data.
Request deletion of data no longer necessary for the purposes collected.
Object to processing based on legitimate interest, including direct marketing.
Request your data in a structured, machine-readable format.
Withdraw consent at any time where processing is consent-based.
To exercise any of these rights, contact us at [email protected]. We will respond within 21 days in line with PDPA requirements. You also have the right to lodge a complaint with the Personal Data Protection Commissioner of Malaysia.
7.Third-Party Links
Our website may contain links to external websites and resources. These are provided for informational purposes only. We have no control over the content or privacy practices of third-party sites and encourage you to review their respective policies before sharing any personal information.
8.Children's Privacy
Our advisory services are directed at business operators and professionals. We do not knowingly collect personal information from individuals under the age of 18. If we become aware that data has been collected from a minor without appropriate consent, we will take prompt steps to remove it.
9.Policy Updates
We may revise this Privacy Policy from time to time. When material changes are made, we will update the "Last Updated" date at the top of this page. We encourage you to review the policy periodically. Continued use of our website following any change constitutes acceptance of the updated terms.
Contact Us
For questions, data access requests, or to raise a privacy concern, please contact us directly. We aim to respond within 21 working days.
Phone
+60 3 2031 6478Address
Level 22, Menara Standard Chartered,Jalan Sultan Ismail, 50250 Kuala Lumpur