Legal
Privacy Policy
Last Updated: 15 April 2025 · Effective: 15 April 2025
1. Introduction
Sungai Method (referred to as "we", "us", or "our") is committed to handling personal data responsibly and in accordance with the Personal Data Protection Act 2010 (PDPA) of Malaysia. This Privacy Policy explains what personal information we collect, why we collect it, how we use it, and what rights you have in relation to your data.
If you have questions about this policy, please contact us at [email protected] or at our office address: Block C, Phileo Damansara 1, Jalan 16/11, 46350 Petaling Jaya, Selangor.
2. What Data We Collect
When you interact with our website or engage our services, we may collect the following types of personal data:
- Name and contact details (email address, telephone number)
- Business information provided in inquiry or engagement context
- Communication records (messages submitted via our contact form)
- Website usage data collected via cookies and analytics tools (see Section 5)
We do not collect sensitive personal data (such as financial account details or identification documents) through our website.
3. Legal Basis and Purpose of Processing
We process personal data on the following bases:
- Consent: When you submit the contact form, you consent to us using your data to respond to your inquiry.
- Legitimate Interest: To operate our website, maintain business communications, and improve our services.
- Contractual Necessity: To manage and deliver consulting engagements entered into with clients.
Data submitted through our contact form is used solely to respond to inquiries and to determine whether an advisory engagement is appropriate. We do not use inquiry data for marketing without explicit consent.
4. Data Retention
We retain personal data for as long as is necessary to fulfil the purpose for which it was collected, or as required by applicable law:
- Contact form submissions: up to 12 months from the date of submission
- Client engagement data: up to 5 years following completion of the engagement (for professional record purposes)
- Website analytics data: retained per the policies of the analytics provider (typically 14–26 months)
5. Cookies and Analytics
Our website uses cookies to understand how visitors interact with our content. We use analytics cookies (where you have consented) to improve the website experience. No personal data from cookies is sold or shared with advertising networks.
For full details on cookies, please refer to our Cookie Policy.
6. Data Sharing with Third Parties
We do not sell personal data. We may share data with the following third-party service providers in the course of operating our website and services:
- Website hosting and infrastructure providers
- Analytics platforms (where consent is given)
- Email communication tools used to respond to inquiries
All third-party providers are selected with data handling standards in mind and are not authorized to use personal data for their own purposes.
7. Data Protection Measures
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, loss, or misuse. These include:
- Secure transmission via HTTPS
- Access controls limiting who can access personal data internally
- Engagement-level confidentiality agreements for all consulting work
In the event of a data breach that is likely to result in risk to your rights, we will notify affected individuals in accordance with our obligations under the PDPA.
8. Your Rights Under Malaysian Law
Under the Personal Data Protection Act 2010 (Malaysia), you have the following rights:
- Right of access: Request a copy of the personal data we hold about you
- Right to correction: Request correction of inaccurate or incomplete data
- Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time
- Right to limit processing: Request restriction of processing in certain circumstances
To exercise any of these rights, please contact us at [email protected]. We will respond within 21 days.
9. Third-Party Links
Our website may contain links to external websites. We are not responsible for the privacy practices of those sites. We encourage you to review the privacy policies of any third-party sites you visit.
10. Children's Privacy
Our services are directed at business organizations and are not intended for individuals under the age of 18. We do not knowingly collect personal data from minors.
11. Policy Updates
We may update this Privacy Policy from time to time. Where changes are material, we will note the updated date at the top of this page. Continued use of our website following any update constitutes acceptance of the revised policy.
12. Contact for Privacy Inquiries
For any questions or concerns about this Privacy Policy or how your personal data is handled:
Sungai Method
Block C, Phileo Damansara 1, Jalan 16/11
46350 Petaling Jaya, Selangor, Malaysia
Email: [email protected]
Phone: +60 3 7956 4283