Privacy Policy
Last updated: 10 April 2025 · Orsten, Suite 12-7, Plaza Sentral, Kuala Lumpur
1. Introduction
Orsten ("we", "us", "our") is committed to handling personal data responsibly. This Privacy Policy describes what personal data we collect when you interact with this website or engage our services, how we use it, and the rights you have in relation to it. It applies to all information collected through this website and through direct communications with us.
This policy is governed by the Personal Data Protection Act 2010 (PDPA) of Malaysia. If you have questions about how we handle your information, contact us at [email protected].
2. Data We Collect
We collect personal data in the following circumstances:
- Enquiry form: Name, email address, and optionally telephone number and a message you choose to include.
- Direct email or telephone contact: Contact details and the content of any communication you initiate with us.
- Cookies and site analytics: Technical information about your visit such as pages viewed, browser type, and referring URL. See Section 5 and our Cookie Policy for detail.
- Service delivery: For workshop and programme engagements, we may collect organisational context you share during scoping discussions.
We do not collect sensitive personal data such as identification numbers, financial account details, or health information.
3. How We Use Your Data
We use personal data for the following purposes:
- Responding to enquiries and providing information about our catalogue
- Delivering services you have purchased, including sending documents and scheduling sessions
- Issuing invoices and processing payments
- Sending update notifications for the Information Pack to registered recipients within the six-month update window
- Improving our website content and understanding how visitors use the site (analytics)
- Complying with legal obligations applicable under Malaysian law
We do not use your data for unsolicited marketing. We do not sell or rent personal data to third parties.
4. Legal Basis for Processing
Under the Personal Data Protection Act 2010, we process personal data on the following bases:
- Consent: Where you have given consent by submitting an enquiry form or communicating with us directly.
- Contract performance: Where processing is necessary to deliver a service you have engaged.
- Legitimate interests: For site analytics and improvements, subject to your right to object.
- Legal obligation: Where we are required to process data to comply with applicable Malaysian law.
5. Cookies
This website uses cookies to understand how visitors interact with the site and to remember cookie consent preferences. We use essential cookies (necessary for the site to function) and optional analytics and preference cookies, which we only activate if you provide consent. You can manage your cookie preferences at any time via our Cookie Policy page.
6. Data Retention
We retain personal data only as long as necessary for the purpose for which it was collected:
- Enquiry records: up to 12 months from the date of enquiry unless a service engagement follows
- Client records from service engagements: up to 3 years from the date of the last transaction
- Invoice and payment records: 7 years, as required under Malaysian accounting and tax obligations
- Analytics data: retained in aggregated, anonymised form
7. Data Protection Measures
We take reasonable technical and organisational steps to protect personal data against unauthorised access, disclosure, or loss. These include:
- Encrypted data transmission via HTTPS for all website interactions
- Access controls limiting who within Orsten can access personal data
- Storage on servers with appropriate security configurations
- A process for identifying and notifying data subjects in the event of a material breach, in line with PDPA requirements
8. Third Parties
We may share data with the following categories of third parties, limited to what is necessary for the stated purpose:
- Payment processors: To process bank transfer instructions and issue receipts
- Email service providers: To send confirmation emails and document deliveries
- Analytics providers: To analyse aggregated website usage (data shared does not identify individuals)
We do not share personal data with any other third parties without your express consent.
9. Third-Party Links
This website may include links to external websites. Orsten is not responsible for the privacy practices of those sites and encourages you to read their privacy policies before providing any personal data to them.
10. Your Rights
Under the Personal Data Protection Act 2010 (Malaysia), you have the following rights in relation to your personal data:
- Right of access: You may request a copy of the personal data we hold about you.
- Right of correction: You may request that we correct inaccurate or incomplete data.
- Right to withdraw consent: Where processing is based on your consent, you may withdraw it at any time. This does not affect the lawfulness of processing before withdrawal.
- Right to limit processing: In certain circumstances, you may request that we limit how we use your data.
To exercise any of these rights, contact us at [email protected]. We will respond within 21 days.
11. Children's Privacy
Our services are directed at organisations and individuals engaged in commercial activities. We do not knowingly collect personal data from individuals under the age of 18. If you believe a minor has submitted personal data to us, contact us at the address below and we will take appropriate action.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. The updated policy will be published on this page with a revised "last updated" date. Continued use of this website after a policy update constitutes acceptance of the revised terms.
13. Contact
For any questions, data access requests, or concerns about how we handle your personal data, contact us:
- Email: [email protected]
- Address: Orsten, Suite 12-7, Plaza Sentral, Jalan Stesen Sentral 5, 50470 Kuala Lumpur, Malaysia
- Phone: +60 3 2298 4516
If you are not satisfied with our response, you may lodge a complaint with the Department of Personal Data Protection (Jabatan Perlindungan Data Peribadi) of Malaysia.