Legal & Compliance
Privacy Policy
Last Updated: | Effective Date:
tabulaxxes is committed to handling personal information with care and in accordance with Malaysian law. This Privacy Policy explains what information we collect, how we use it, and the choices available to you. It applies to all individuals who interact with our firm — whether through our website, by telephone, or in the course of receiving our legal services.
If you have any questions about this policy, please write to us at [email protected].
01 — Data Controller
tabulaxxes operates as the data controller in respect of personal data collected through this website and in the course of its legal practice. Our registered address is Lot 4, Level 7, Plaza Sentral, Jalan Stesen Sentral 5, 50470 Kuala Lumpur.
tabulaxxes's legal services are subject to the Personal Data Protection Act 2010 (Malaysia) ("PDPA"). Where our work involves cross-border data flows, we take steps to ensure that data is protected to a standard consistent with Malaysian requirements.
02 — Data We Collect
We collect personal data in the following ways:
Contact and Enquiry Data
When you submit a contact form, telephone us, or write to us by email, we collect your name, email address, telephone number, and the content of your message. This information is used to respond to your enquiry and to assess whether our services may assist you.
Client Matter Data
In providing legal services, we collect personal and financial information necessary to carry out the engagement — including identity documents, financial statements, transaction details, and correspondence with third parties such as financial institutions. Collection of this data is required to perform the services you have engaged us for and to comply with our professional and regulatory obligations.
Website Usage Data
We use analytics tools to understand how visitors interact with our website. This may include pages viewed, session duration, device type, and approximate location. This data is collected in aggregate and is generally not linked to identifiable individuals.
Legal Bases for Processing
- Performance of a contract or steps preparatory to a contract
- Compliance with a legal or regulatory obligation
- Consent, where obtained
- Legitimate interests of our practice, where not overridden by your rights
03 — How We Use Your Data
- To respond to your enquiries and provide the legal services you have requested or are considering engaging.
- To prepare, review, and advise on finance documents, security arrangements, and regulatory submissions in connection with your matter.
- To comply with obligations under the Legal Profession Act 1976, the Anti-Money Laundering, Anti-Terrorism Financing and Proceeds of Unlawful Activities Act 2001, and other applicable Malaysian statutes.
- To maintain client records and conflict checks in accordance with professional practice standards.
- To send periodic written briefings on legal developments where you have consented to receiving such updates. You may withdraw this consent at any time.
- To improve and maintain our website through aggregate usage analytics.
04 — Data Sharing
We do not sell personal data. We share data only in the following circumstances:
Other Parties in Your Transaction
In the course of a financing transaction, we share relevant information with counterparties, financial institutions, and their advisers, as required to complete the engagement.
Regulatory and Legal Authorities
We disclose data to regulators, courts, and law enforcement where required by law or under a legal obligation binding on the firm.
Service Providers
We engage certain third-party providers — including secure document management platforms and analytics services — who process data on our behalf under appropriate contractual safeguards.
05 — Data Retention
| Category | Retention Period |
|---|---|
| Client matter files | 7 years from close of matter |
| Enquiries not leading to an engagement | 12 months |
| Website analytics data | 26 months (aggregate) |
| Cookie consent records | 12 months |
| Anti-money laundering records | 6 years from transaction date (statutory minimum) |
06 — Data Protection Measures
We take reasonable technical and organisational measures to protect personal data against accidental loss, alteration, disclosure, or unauthorised access. These measures include:
- Encrypted communication channels for client correspondence and document exchange.
- Access controls restricting data to personnel who require it for their role in your matter.
- Secure destruction of paper and digital records at the end of their retention period.
- Periodic review of our data handling practices.
In the event of a personal data breach that is likely to affect your rights, we will notify you without undue delay in accordance with our obligations under the PDPA.
07 — Cookies
Our website uses cookies to record your consent preferences and to support basic site functionality. We also use optional analytics cookies to understand how the site is used. You may manage your cookie preferences at any time through our Cookie Policy page. Essential cookies cannot be disabled as they are required for the site to function.
08 — Your Rights
Under the Personal Data Protection Act 2010 and applicable Malaysian law, you have the following rights in respect of personal data we hold about you:
Right of Access
Request a copy of the personal data we hold about you.
Right of Correction
Request correction of inaccurate or incomplete data.
Right to Withdraw Consent
Withdraw consent for processing based on consent at any time, without affecting the lawfulness of prior processing.
Right to Limit Processing
Request that we restrict how we use your data in certain circumstances.
Right to Opt Out of Direct Marketing
Instruct us not to process your data for direct marketing purposes.
Right to Lodge a Complaint
Lodge a complaint with the Personal Data Protection Commissioner of Malaysia.
To exercise any of these rights, please write to us at [email protected]. We aim to respond within 21 days. We may need to verify your identity before processing certain requests.
09 — Third-Party Links
Our website may contain links to external resources, including regulatory publications and legal databases. tabulaxxes is not responsible for the privacy practices of third-party websites and recommends that you review their privacy policies separately before submitting any personal information.
10 — Minors
Our services are directed to adults. We do not knowingly collect personal data from individuals under the age of 18. If you believe a minor has submitted personal data to us, please contact us and we will take appropriate steps to remove that data.
11 — Policy Updates
We may update this policy from time to time to reflect changes in our practices or in applicable law. Where the changes are material, we will place a clear notice on our website. The date at the top of this document indicates when the policy was last revised. Continued use of our website after an update constitutes acceptance of the revised policy.
12 — Contact for Privacy Matters
For questions about this policy, to exercise your rights, or to raise a concern about how we handle your data, please contact us:
Lot 4, Level 7, Plaza Sentral, Jalan Stesen Sentral 5, 50470 Kuala Lumpur
For complaints that remain unresolved, you may contact the Personal Data Protection Commissioner of Malaysia: www.pdp.gov.my