Legal
Privacy Policy
Last updated: 3 April 2026
This policy describes how Thalwyn Consulting Sdn Bhd ("Thalwyn", "we", "our") collects, uses, stores, and protects personal information provided through this website or in connection with our consulting services. We operate in compliance with the Personal Data Protection Act 2010 (Malaysia) (PDPA). We encourage you to read this document carefully.
1. Who We Are
Thalwyn Consulting Sdn Bhd is a business consulting firm registered in Malaysia (SSM No. 201101012345), with our principal office at 5-12 Persiaran Gurney, 10250 George Town, Penang. We provide organizational restructuring, talent strategy, and performance benchmarking services to companies primarily operating in Malaysia.
2. Personal Data We Collect
We may collect the following categories of personal data:
- Contact information — such as your name, business email address, phone number, and company name, when you submit our contact form or communicate with us directly.
- Correspondence records — the content of emails, enquiries, or messages you send us.
- Usage data — pages visited, time spent on site, and referring URLs, collected via analytics tools when you consent to their use.
- Device and browser data — IP address, browser type, operating system, and screen resolution, collected automatically when you access this site.
We do not collect sensitive personal data (as defined under the PDPA) unless explicitly required for a specific engagement and with your prior written agreement.
3. How We Use Your Personal Data
We use the personal data we collect for the following purposes:
- To respond to enquiries submitted through our contact form or by email.
- To assess whether our services may be a suitable fit for your organisation.
- To deliver consulting services under a signed engagement agreement.
- To send service-related communications (such as project updates or invoice notifications).
- To improve the content and functionality of this website, where analytics consent has been granted.
- To comply with applicable legal and regulatory obligations.
We do not use your personal data for unsolicited marketing, nor do we sell or rent personal data to third parties.
4. Legal Basis for Processing
Under the PDPA, we process personal data where:
- You have given your consent (for example, by submitting our contact form or accepting analytics cookies).
- Processing is necessary to fulfil a contract with you or to take steps at your request prior to entering a contract.
- Processing is required to comply with a legal obligation applicable to us.
- Processing serves our legitimate interests, such as improving our services or maintaining records of correspondence, provided those interests are not overridden by your rights.
5. Sharing of Personal Data
We may share your personal data with:
- Service providers — third-party vendors who assist with website hosting, email delivery, or analytics, operating under data processing agreements.
- Professional advisers — lawyers, accountants, or auditors where required for legal or compliance purposes.
- Regulatory authorities — where disclosure is required by law or court order.
We do not transfer personal data outside Malaysia except where necessary and permitted under applicable law, and only where an adequate level of protection is maintained.
6. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes described in this policy, or as required by law. Enquiry records are typically retained for 24 months. Client engagement records are retained for 7 years following the completion of the engagement, in accordance with standard commercial and tax record-keeping requirements. Upon expiry of the applicable retention period, personal data is securely deleted or anonymised.
7. Cookies and Tracking Technologies
This website uses cookies and similar technologies to support basic site functionality and, with your consent, to collect usage analytics. You may manage your cookie preferences at any time via our Cookie Policy page. Please refer to that page for a full description of the cookies we use and how to control them.
8. Your Rights Under the PDPA
Under the Personal Data Protection Act 2010, you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate or incomplete personal data.
- Withdraw consent to processing at any time (without affecting the lawfulness of prior processing).
- Request that we cease processing your personal data for direct marketing purposes.
To exercise any of these rights, please contact us at [email protected]. We will respond to requests within 21 days.
9. Security
We take reasonable technical and organisational steps to protect personal data against unauthorised access, disclosure, alteration, or destruction. These include encrypted data transmission (TLS), access controls, and staff awareness of data handling responsibilities. However, no method of transmission over the internet is entirely without risk, and we cannot guarantee absolute security.
10. Links to Other Websites
This website may contain links to external websites. We are not responsible for the privacy practices or content of those sites. We encourage you to review the privacy policies of any sites you visit.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. The revised version will be published on this page with a new effective date. We recommend checking this page periodically.
12. Contact Us
If you have questions about this policy or wish to exercise your rights, please contact:
- Thalwyn Consulting Sdn Bhd
- 5-12 Persiaran Gurney, 10250 George Town, Penang
- Email: [email protected]
- Phone: +60 4-261 8437