Legal
Privacy Policy
Last Updated: 10 April 2025
Pensarae ("we", "us", or "our") is committed to handling personal data with care and in accordance with applicable law. This policy explains what personal data we collect, why we collect it, how we use it, and the rights available to those whose data we hold. It applies to individuals who contact us, use our website at pensa.website, or engage our services.
If you have questions about this policy or the way we handle your data, please contact us at [email protected].
1. Who we are
Pensarae is a legal advisory practice operating from 19 Jalan Burmah, 10050 George Town, Penang, Malaysia. We are the data controller in relation to the personal data described in this policy. We are subject to the Personal Data Protection Act 2010 (PDPA) of Malaysia.
2. Personal data we collect
We collect personal data in the following ways:
- Through enquiry forms submitted on our website (name, email address, telephone number, and any information provided in the message field).
- Through direct communication by email or telephone.
- In the course of providing legal advisory services, including documents and records you provide to us.
- Automatically, through website cookies and analytics tools, where you have consented to their use (see Section 8 below).
3. How we use personal data
We use personal data for the following purposes:
- To respond to enquiries and assess whether we are placed to assist you.
- To provide legal advisory services where an engagement is formalised.
- To comply with our professional obligations as legal practitioners.
- To communicate with you regarding your matter and any developments in it.
- To maintain records of our work in accordance with applicable professional and regulatory requirements.
- To improve the operation and content of our website, where analytics consent has been given.
The legal bases on which we process data include: performance of a contract (or steps taken at your request prior to a contract); compliance with a legal obligation; and, where applicable, your consent (for example, in relation to non-essential cookies).
4. Data retention
Data collected through website enquiry forms that do not proceed to a formal engagement is retained for up to twelve months, after which it is deleted. Data relating to formal engagements is retained for seven years following the conclusion of the engagement, in accordance with professional record-keeping obligations. Analytics data, where collected, is subject to the retention policies of the analytics provider.
5. Data sharing
We do not sell personal data. We share personal data with third parties only in the following circumstances:
- Where required to carry out your matter — for example, submitting documents to an administering body on your behalf, always with your prior knowledge and agreement.
- Where required by law or by our professional obligations.
- With service providers who operate our website infrastructure, under contractual obligations not to use the data for other purposes.
6. Data protection measures
Client documents and records are stored on password-protected systems with access restricted to members of the practice directly involved in the relevant matter. Electronic communications involving sensitive personal data are conducted over secure channels. We conduct periodic reviews of our data handling procedures.
7. Cookies
Our website uses cookies. Essential cookies are necessary for the website to function. We also use analytics cookies to understand how the website is used, subject to your consent. A full explanation of the cookies used is available in our Cookie Policy.
8. Your rights
Under the PDPA 2010 and applicable data protection principles, you have the following rights in relation to personal data we hold about you:
- Access: You may request a copy of personal data we hold about you.
- Correction: You may request that inaccurate or incomplete data be corrected.
- Withdrawal of consent: Where processing is based on consent, you may withdraw it at any time. Withdrawal does not affect processing that took place before withdrawal.
- Objection to processing: You may, in certain circumstances, object to processing of your personal data.
- Erasure: You may, in certain circumstances, request deletion of personal data we hold.
To exercise any of these rights, please contact us at [email protected]. We will respond within thirty days.
9. Third-party links
Our website may contain links to external websites. We are not responsible for the privacy practices of those sites and this policy does not apply to them. We encourage you to review the privacy policy of any external site you visit.
10. Children's privacy
Our services are intended for adults aged eighteen years and over. We do not knowingly collect personal data from individuals under eighteen. If we become aware that data from a minor has been submitted to us, we will delete it promptly.
11. Changes to this policy
We may update this policy from time to time to reflect changes in our practices or applicable law. The date at the top of the policy reflects the most recent revision. Continued use of our website following an update constitutes acceptance of the revised policy.
12. Contact
For questions about this policy or our data handling practices, please write to us at:
Pensarae, 19 Jalan Burmah, 10050 George Town, Penang, Malaysia
Email: [email protected]
Telephone: +60 4-227 8149