Legal
Privacy Policy
Last updated: 15 May 2026
Cendana ("we", "us", "our") is committed to handling your personal information with care and transparency. This policy explains what we collect, why we collect it, and how we protect it. It applies to information gathered through our website at cendanamy.sbs and through our consulting engagement process.
We operate under the Personal Data Protection Act 2010 (PDPA) of Malaysia. If you have questions about this policy, you can contact us at [email protected].
1. What information we collect
We collect only the information needed to communicate with you and deliver our consulting services. This includes:
- Contact details: your name, email address, and phone number, provided when you complete our contact form or enquiry questionnaire.
- Business information: details about your business that you share during consultations, including operational and financial information relevant to the engagement.
- Website usage data: anonymised data on how visitors interact with our website, collected via analytics cookies (where consent has been given).
Legal basis: We process your data on the basis of your consent (for website enquiries and marketing), contractual necessity (for delivering engagement services), and legitimate interest (for improving our practice and communicating with current clients).
Retention: Contact enquiry data is held for 12 months. Client engagement data is retained for 5 years following the end of the engagement, as required for professional advisory record-keeping.
2. How we use your information
- To respond to your enquiry and discuss whether our services fit your situation
- To deliver the consulting engagement you have engaged us for
- To send administrative communications related to your engagement (session reminders, document delivery)
- To improve our website based on aggregated, anonymised usage data
- To comply with applicable legal and professional obligations
We do not sell, rent, or share your personal information with third parties for marketing purposes. We do not send unsolicited marketing communications.
3. How we protect your information
We take reasonable steps to protect personal information from unauthorised access, disclosure, or loss. These measures include:
- Encrypted transmission of website data via HTTPS
- Password-protected document storage for engagement materials
- Restricted internal access — only the advisor assigned to your engagement holds your files
- Secure deletion of data at the end of the retention period
In the event of a data breach that is likely to affect your rights, we will notify you within 72 hours of becoming aware of it, where this is practically possible.
4. Cookies
Our website uses cookies to function properly and to understand how it is being used. Essential cookies are always active. Analytics and preference cookies are only placed with your consent. You can manage your cookie preferences at any time via our Cookie Policy page.
5. Your rights
Under the Personal Data Protection Act 2010 (Malaysia), you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate or incomplete data
- Withdraw consent for data processing at any time (where processing is based on consent)
- Request that we limit how we use your data in certain circumstances
- Receive your data in a portable format, where technically practicable
To exercise any of these rights, contact us at [email protected]. We will respond within 21 days. If you believe your rights have not been respected, you may lodge a complaint with the Department of Personal Data Protection Malaysia (pdp.gov.my).
6. Third-party links
Our website may contain links to external sites. We are not responsible for the privacy practices of those sites and recommend you review their policies separately.
7. Children's privacy
Our services are intended for business owners and are not directed at individuals under 18 years of age. We do not knowingly collect personal data from minors. If we become aware that we have done so, we will delete it promptly.
8. Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top of this page will reflect any changes. Significant changes will be communicated directly to active clients. Continued use of our website or services after changes take effect constitutes acceptance of the updated policy.
9. Contact for data enquiries
Cendana (Data Controller)
Level 7, Wisma Central, Jalan Ampang, 50450 Kuala Lumpur, Malaysia