Legal
Privacy Policy
Last Updated: 30 January 2026
1. Introduction
fermatat ("we", "us", "our") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, and protect personal data when you use our website, engage our legal services, or communicate with us. This policy applies to all personal data processed by fermatat in connection with our legal practice based at 47 Persiaran Stonor, 50450 Kuala Lumpur, Malaysia.
For any questions about this policy or how we handle your data, please contact us at [email protected].
2. Data We Collect
We may collect and process the following categories of personal data:
Contact Information: Your name, email address, telephone number, and postal address when you submit a contact form, send us an enquiry, or engage our services.
Service-Related Information: Details relevant to the legal matter you engage us for, such as employment details, business registration information, intellectual property details, or regulatory documentation.
Technical Data: Information collected automatically when you visit our website, including IP address, browser type, pages visited, and time spent on pages, gathered through cookies and analytics tools.
Communication Records: Records of correspondence between you and our team, including emails, phone call notes, and meeting notes relevant to your engagement.
3. How We Collect Data
We collect personal data through the following means: directly from you when you fill in forms on our website, send us correspondence, or provide information during the course of an engagement; automatically through cookies and similar technologies when you browse our website; and from third parties such as government agencies or regulatory bodies when processing your legal matter with your consent.
4. Legal Basis for Processing
Under Malaysia's Personal Data Protection Act 2010 (PDPA), we process your personal data on the following bases:
Consent: Where you have given us clear consent to process your personal data for specific purposes, such as marketing communications.
Contractual Necessity: Where processing is necessary for the performance of a contract between you and fermatat, or to take steps at your request prior to entering into a contract.
Legal Obligation: Where processing is necessary for compliance with a legal obligation to which we are subject, including regulatory reporting requirements.
Legitimate Interest: Where processing is necessary for our legitimate interests, provided these are not overridden by your rights and interests.
5. How We Use Your Data
We use personal data we collect for the following purposes: to provide legal services you have engaged us for, including immigration advisory, intellectual property registration, and regulatory compliance consultation; to communicate with you about your matter and respond to your enquiries; to manage our internal business operations, including record-keeping and quality assurance; to comply with our legal and regulatory obligations as a law practice registered with the Malaysian Bar Council; and to improve our website and services based on how visitors use our site.
6. Data Sharing
We may share your personal data with the following parties, only to the extent necessary for the purposes described in this policy:
Government Agencies: Such as the Immigration Department of Malaysia, MyIPO, Bank Negara Malaysia, MCMC, MDEC, or MIDA, where required for the processing of your legal matter.
Service Providers: Third-party providers who assist us with website hosting, analytics, and administrative functions, bound by data processing agreements.
Professional Advisors: External counsel or specialists where required for your matter, with your prior knowledge.
We do not sell, rent, or trade your personal data to third parties for marketing purposes.
7. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected: engagement-related data is retained for seven years after the conclusion of a matter, in line with professional obligations; contact form data is retained for twelve months from the date of submission if no engagement follows; website analytics data is retained for twenty-four months. After the retention period, data is securely deleted or anonymised.
8. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include encrypted communications for sensitive data transmission, access controls limiting data access to authorised personnel only, regular security reviews of our systems and processes, and secure physical storage for paper records at our office premises.
9. Cookies
Our website uses cookies to improve functionality and analyse usage patterns. For full details about the cookies we use and how to manage your preferences, please refer to our Cookie Policy.
10. Your Rights
Under the PDPA 2010, you have the following rights regarding your personal data:
Right of Access: You may request access to the personal data we hold about you.
Right to Correction: You may request that we correct any inaccurate or incomplete personal data.
Right to Withdraw Consent: Where processing is based on consent, you may withdraw that consent at any time.
Right to Prevent Processing: You may request that we stop processing your personal data in certain circumstances.
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within a reasonable timeframe.
11. Third-Party Links
Our website may contain links to third-party websites. We are not responsible for the privacy practices of those websites and encourage you to read their privacy policies before providing any personal data.
12. Children's Privacy
Our services are not directed at individuals under the age of 18. We do not knowingly collect personal data from minors. If we become aware that we have inadvertently collected data from a minor, we will take steps to delete it promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable legislation. Any updates will be posted on this page with a revised "Last Updated" date. We encourage you to review this page periodically.
14. Contact Information
Data Controller: fermatat
Address: 47 Persiaran Stonor, 50450 Kuala Lumpur, Malaysia
Email: [email protected]
Phone: +60 3-2171 4938
If you are unsatisfied with our handling of your data, you have the right to lodge a complaint with the Department of Personal Data Protection (JPDP) Malaysia.