Privacy

Privacy notice

How Merensa Advisory Limited handles the personal information you choose to share with us, and the rights you hold over it under Malaysian law.

Last updated 11 August 2026

Who we are

Merensa Advisory Limited (“Merensa”, “we”, “us”) is a company incorporated in the Federal Territory of Labuan, Malaysia. We provide strategic advisory services, and we are the data controller for the personal information described in this notice.

This notice applies to our website and to inquiries made through it. It is written to meet the notice requirements of the Malaysian Personal Data Protection Act 2010, as amended by the Personal Data Protection (Amendment) Act 2024.

What information we collect

In short: what you give us through the contact form, and standard technical data your browser sends.

Information you provide

  • Your name.
  • Your organization.
  • Your email address, and your telephone number if you ask us to call.
  • The substance of your inquiry, in whatever detail you choose to give it.

We do not purchase contact data, and we do not assemble marketing profiles. We ask for no sensitive personal data as that term is defined in section 4 of the Act, and we would ask you not to send any through a web form. If a matter is sensitive, a conversation is the safer place for it.

Information collected automatically

Our hosting and analytics providers record ordinary technical data when you visit: IP address, browser and device type, operating system, referring page, and which pages you read. IP address gives an approximate region, not a precise location. This data supports the security and operation of the site and our understanding of which pages are read.

How we use it

We use your information to reply to you, to consider and conduct an engagement you ask us to undertake, to keep the records our professional and statutory obligations require, and to keep the site secure and working.

An inquiry is not added to a mailing list, and we send no marketing email. Should that ever change, we would ask your consent first and honor its withdrawal at any time.

Our lawful basis

We process personal data in accordance with the seven Personal Data Protection Principles set out in the Act: the General, Notice and Choice, Disclosure, Security, Retention, Data Integrity and Access Principles.

  • Consent. You give us your details voluntarily when you submit the contact form, having read this notice. You may withdraw that consent at any time.
  • Performance of a contract. Where processing is necessary to take steps at your request before an engagement, or to perform one already agreed.
  • Legal obligation. Where the law, a regulator, or a court requires it of us.
  • Legitimate interests. For the security of our systems and the administration of our own business, weighed each time against your interests and rights.

When we disclose it

Access is restricted to the Merensa specialists engaged on your matter. Beyond them, we disclose personal data only in these circumstances:

  • Service providers. Hosting, email, and analytics providers acting on our written instructions under data processing terms, and only to the extent their service requires.
  • Professional advisers. Our own counsel, auditors and insurers, under a duty of confidence.
  • Legal requirement. Where compelled by law or an order of a competent authority.
  • Corporate transaction. In connection with a merger, financing or transfer of our business, in which case the recipient is bound by this notice.

We do not sell, rent, or trade personal data, and we do not share it with third parties for their own marketing.

Transfers outside Malaysia

Our hosting and email infrastructure sits outside Malaysia, and our people work across several jurisdictions. Personal data may therefore be transferred to and stored in another country.

Section 129 of the Act, read with the Commissioner’s cross-border transfer guidelines, permits such transfers where the destination has data protection law substantially similar to the Act or affords an adequate level of protection, or where a recognized exception applies. We assess each destination on that basis before data moves, and we bind our providers by contract to standards no lower than those in this notice.

How long we keep it

Under the Retention Principle we keep personal data no longer than the purpose requires. In practice, an inquiry that does not become an engagement is destroyed twelve months after our last exchange. Engagement records are kept for seven years from the close of the matter, the period our professional, tax and statutory obligations require.

When a retention period ends, data is deleted or anonymized. Where a copy persists in a backup archive, it is isolated from further processing until the archive itself expires.

Security, and what happens after a breach

We apply organizational and technical measures proportionate to the sensitivity of what boards tell us: encrypted transport and storage, access confined to those engaged on the matter, and periodic review of the providers we rely on. No transmission over the internet can be guaranteed secure, and material you send us travels at your own risk.

Where a personal data breach occurs, section 12B of the Act requires us to notify the Personal Data Protection Commissioner as soon as practicable, and in any event within 72 hours of becoming aware of it. Where the breach is likely to cause significant harm, we notify the individuals affected without unnecessary delay, and tell them plainly what happened and what to do about it.

Cookies and analytics

This site sets a small number of cookies. Strictly necessary cookies keep the site working and secure; they cannot be switched off. Analytics cookies measure, in aggregate, which pages are read, and run only with your consent. Preference cookies remember choices you make, including your cookie choice itself.

Nothing here follows you onto other sites, and we run no advertising trackers. You can change your choice at any time through in the footer, or refuse cookies in your browser. Blocking the strictly necessary ones will affect how the site works.

Your rights

Under the Act you hold the following rights over the personal data we keep about you:

  • Access. To be told whether we hold data about you and to receive a copy of it.
  • Correction. To have data that is inaccurate, incomplete or out of date put right.
  • Withdrawal of consent. To withdraw consent to processing, without affecting what was lawful before.
  • To prevent processing. To require us to stop processing likely to cause you damage or distress, and to stop processing for direct marketing.
  • Portability. Under section 43A, to ask that your data be transmitted directly to another data controller, so far as it is technically feasible and formats allow.

Make any of these requests through the contact page. We may ask for enough information to satisfy ourselves that the request is yours. We reply within 21 days where the Act sets that period, and otherwise within 30 days. A fee applies only where the Act permits one, and we tell you before it is incurred.

If our answer does not satisfy you, tell us first and we will look again. You may then complain to the Personal Data Protection Commissioner, Jabatan Perlindungan Data Peribadi, Putrajaya — pdp.gov.my.

If you are outside Malaysia

Malaysian law governs this notice. Where the law of your own jurisdiction gives you further rights, we honor them.

  • European Economic Area and United Kingdom. Rights of access, rectification, erasure, restriction, portability and objection under the GDPR and UK GDPR, and the right to complain to your national supervisory authority.
  • Australia. Rights of access and correction under the Privacy Act 1988, and the right to complain to the Office of the Australian Information Commissioner.
  • Singapore. Rights of access, correction and consent withdrawal under the Personal Data Protection Act 2012, and the right to complain to the Personal Data Protection Commission.

In every case, start with the contact page. We would rather resolve it directly.

Children

Our services are directed to organizations and the people who lead them. We do not knowingly collect personal data from anyone under 18. If we learn that we hold such data, we delete it. If you believe a child has sent us information, tell us through the contact page.

Changes to this notice

We revise this notice as the law and our practices change. The date at the head of the page marks the current version. Where a change is material, we post a notice on the site before it takes effect.

How to reach us

Questions about this notice, and every request made under it, go through the contact page. Mark the message for the attention of our Data Protection Officer so that it reaches them directly.