Malaysia Property Guide

Legal

Privacy Policy

Last updated:

This notice explains what personal data Malaysia Property Guide collects about you, why we collect it, who we share it with and what you can ask us to do about it. It is written to meet the Personal Data Protection Act 2010 of Malaysia (the “PDPA”), which is the law that governs how we handle your data.

Anything below that appears between square brackets is a detail still to be confirmed and published. If you need it before it appears here, ask us and we will tell you.


1. Who we are

Malaysia Property Guide is operated by [COMPANY LEGAL NAME], a company registered in Malaysia under [SSM REGISTRATION NO.], with its registered address at [REGISTERED ADDRESS].

For the purposes of the PDPA we are the data user in respect of the personal data described below. In this notice “we”, “us” and “our” mean [COMPANY LEGAL NAME], and “you” means anyone who joins the waitlist, opens an account, buys the course or books a consultation.

All privacy questions and all requests about your own data go to [PRIVACY CONTACT EMAIL].

2. What this notice covers

It covers the Malaysia Property Guide website and everything you can do on it today:

It does not cover other companies’ websites that we link to, or PayPal’s own pages, which are governed by their own privacy notices.

  • joining the pre-launch waitlist;
  • creating and using a customer account;
  • buying and watching the video course;
  • booking and attending a paid consultation;
  • contacting us by email or WhatsApp.

3. The personal data we collect

We collect only what a given action actually needs. Grouped by what you are doing:

We do NOT collect your payment card number, expiry date or security code. Those are entered on PayPal’s own pages and never reach our servers or our database. What we receive back from PayPal is the amount, the currency, whether the payment succeeded, and PayPal’s reference for it.

We also do not ask for, and do not want, sensitive personal data as the PDPA defines it — your health, political opinions, religious beliefs or any record of an offence. Please do not send it to us.

  • Waitlist — your full name, your email address and your mobile number, exactly the three fields on the form.
  • Customer account — your email address, your name, your mobile number, the language you prefer, and (if you set one) a password, which is stored only as a one-way hash and can never be read back.
  • Signing in and verification — the one-time codes and sign-in links we send you by email or WhatsApp, held as one-way hashes with their expiry, and the IP address that asked for them, kept so we can detect abuse of those endpoints.
  • Purchases — what you bought, the amount and currency, whether it completed, PayPal’s capture reference, the mobile number you gave at checkout, and any discount code you used.
  • Consultations — the session you booked and its time, the time zone and language you booked in, a snapshot of your name, email and phone as they were at the time, anything you typed into the notes field for the consultant, and the meeting link for the call.
  • Watching the course — which lessons you have started and finished, so the site can put you back where you stopped.
  • Technical data — your IP address and browser user-agent as they reach our server in the ordinary course of serving a page. Your IP is also used, in a truncated form covering your network rather than you alone, to sign the video links issued to you so they cannot be pasted into someone else’s browser.

4. Why we collect it, and on what basis

Each purpose below is the reason a particular field exists. We do not collect data “in case it is useful later”.

Our lawful basis is your consent, given when you submit a form that says what it is for, together with the PDPA’s allowance for processing that is necessary to perform a contract you are a party to — which is what applies once you have paid us for a course or a consultation.

  • To tell you when the course opens, and to send you the founding-access offer you asked for by joining the waitlist.
  • To create your account, let you sign in and keep you signed in.
  • To take payment, issue your receipt and give you access to what you paid for.
  • To schedule your consultation, send you the meeting link and let the consultant prepare for the call.
  • To remember your progress through the course.
  • To keep the service secure — rate limiting, abuse detection, and stopping one person’s paid video links being shared with everyone else.
  • To keep the accounting and tax records a business in Malaysia is required to keep.
  • To answer you when you contact us.

5. Consent, and taking it back

Where we rely on your consent — the waitlist and any marketing message — you can withdraw it at any time, and withdrawing is meant to be as easy as giving it was. Email [PRIVACY CONTACT EMAIL] and say so, or use the unsubscribe link in any message we send you.

Withdrawing consent stops us sending you anything further and, for the waitlist, removes your row. It cannot undo processing that already happened, and it does not remove records we are required to keep — a completed purchase remains in our accounts (see section 9).

You can also decline in the first place. The consequence is simply that the thing you declined does not happen: without an email address we cannot tell you the course has launched, and without a name and a payment we cannot give you access to it.

6. How we meet the seven PDPA principles

The PDPA sets out seven principles. This is how each one applies to us in practice:

  • General Principle — we process your personal data only with your consent, or where the PDPA otherwise permits it, and only for the purposes set out in section 4.
  • Notice and Choice Principle — this notice is that notice. It is published in English and Arabic, is linked from the footer of every public page, and is available before you submit anything to us.
  • Disclosure Principle — we disclose your data only to the parties named in section 7 and only for the purposes named there. We do not sell it and we do not rent it out.
  • Security Principle — see section 10.
  • Retention Principle — we keep personal data only as long as the purpose it was collected for lasts, and we delete it after that. See section 9, which gives the actual periods.
  • Data Integrity Principle — we keep your data accurate and up to date so far as we reasonably can. You can correct most of it yourself in your account, and you can ask us to correct the rest.
  • Access Principle — you can ask us for a copy of the personal data we hold about you and ask us to correct it. See section 11.

7. Who we share your data with

We share personal data only with the service providers that make the site work, and only with the part of it they need. Each is bound to use it for our purposes and not their own:

We may also disclose personal data where the law requires it, to a court or regulator, or to establish or defend a legal claim — for example if you dispute a payment with your bank.

Two things worth stating because a reader might assume otherwise. Our video is served from our own server, not from a third-party video platform, so nobody but us sees what you watch. And we do not sell, rent, trade or share your personal data with advertisers, data brokers or anyone else for their own marketing.

  • PayPal — takes your payment, on its own pages, under its own privacy policy. It receives what a payment needs; we receive back only the outcome and its reference.
  • Resayil (api.resayil.io) — the WhatsApp gateway that delivers verification codes and access messages to the mobile number you gave us.
  • [EMAIL DELIVERY PROVIDER] — sends our receipts, sign-in links, verification codes and waitlist announcements to your email address.
  • [HOSTING PROVIDER] — hosts the servers and the database this site and its data run on.
  • Google Fonts — serves the two typefaces the pages are set in. It sets no cookies, but the request itself reveals your IP address and browser to Google. See our Cookie Policy.
  • Our consultants — the consultant taking your session sees your name, contact details and anything you wrote in the notes field, so that they can prepare for and hold the call.

8. Transfers outside Malaysia

Some of the providers in section 7 process data outside Malaysia — PayPal in particular operates internationally, and our email and hosting providers may hold data in other jurisdictions. Most of our customers are themselves outside Malaysia, in the Gulf, so data will in any case cross a border to reach you.

Where we transfer personal data out of Malaysia, we do so on the basis that you have consented to the transfer as part of using a service that plainly requires it, and that the transfer is necessary to perform our contract with you or to take steps you have asked for. We choose providers that offer a level of protection comparable to the PDPA and we pass on only what the provider needs.

9. How long we keep it

The periods below are the ones actually implemented, not aspirations:

Where we are asked to erase your data, we remove your identity and keep the ledger. That means your name, email, mobile, password and the notes you wrote are cleared, while the purchase and booking records — the amounts, currencies and payment references — remain, because they are the record of money that moved and we are required to be able to account for it.

  • Waitlist entries — until the course launches and we have told you, or until you ask us to remove you, whichever is first.
  • Your account and the data in it — for as long as you have an account with us.
  • Verification codes and sign-in links — minutes. They expire on a timer and are useless afterwards.
  • Consultation notes — 24 months after the session, then automatically erased. They matter to the consultant on the day and to nobody afterwards.
  • Payment and booking records — [FINANCIAL RECORD RETENTION PERIOD] years, to meet Malaysian accounting and tax record-keeping requirements and to defend a payment dispute.
  • Server logs — as long as our host retains them, in the ordinary course of running a server.

10. How we protect it

The site is served over HTTPS. Passwords are stored only as one-way hashes and cannot be read back by us or by anyone who obtained the database. Verification codes and sign-in links are likewise stored hashed, expire on a short timer and are single-use. Card details never enter our systems at all.

Access to the administration panel is restricted to our own staff and is password-protected. Paid video is served through short-lived signed links tied to the network you are watching from, so a link copied out of one person’s browser does not work in another’s.

No system is perfectly secure, and we do not claim otherwise. If a breach affecting your personal data occurs, we will act on it and inform you where it is appropriate or required to do so.

11. Your rights, and how to use them

Under the PDPA you have the following rights over your own personal data:

To exercise any of them, email [PRIVACY CONTACT EMAIL] from the address we hold for you, or tell us in the message which address or mobile number your request relates to, so that we can be sure we are answering the right person. We will respond within 21 days, which is the period the PDPA allows. The PDPA permits a data user to charge a prescribed fee for a data access request; we will tell you before we charge you anything, and it is our intention not to.

If you are not satisfied with how we handle your request, you can complain to the Personal Data Protection Commissioner of Malaysia. We would rather you told us first, so that we can put it right.

  • Access — ask us for a copy of the personal data we hold about you.
  • Correction — ask us to correct data that is inaccurate, incomplete or out of date. Your name, email, mobile and language can be changed directly in your account.
  • Withdraw consent — tell us to stop processing data we hold on the basis of your consent, including all marketing.
  • Limit processing — ask us to stop processing your data for direct marketing, or to stop processing that is causing or likely to cause you damage or distress.
  • Erasure — ask us to remove your identity from our records, on the basis described in section 9.

12. Children

This site is for adults buying or considering property, and we do not direct it at children or knowingly collect data from anyone under 18. If you believe a child has given us personal data, tell us at [PRIVACY CONTACT EMAIL] and we will remove it.

13. Cookies

The site sets only the cookies it needs to work — a session, a security token and, if you ask for it, a “remember me”. There are no analytics and no advertising cookies. Our Cookie Policy sets out each one, what it does and how long it lasts.

14. Changes to this notice

We will update this notice when what we do with personal data changes — a new processor, a new purpose, a new retention period. The “last updated” date at the top always tells you which version you are reading. Where a change is significant, we will tell the people it affects rather than relying on you to re-read the page.

15. Contact us

Privacy questions, data access and correction requests, and complaints: [PRIVACY CONTACT EMAIL].

Everything else: [SUPPORT CONTACT EMAIL].

By post: [COMPANY LEGAL NAME], [REGISTERED ADDRESS].