Privacy Policy
Last updated: 10 May 2025
Mutiara ("we", "us", "our") is a legal practice registered and operating in Malaysia. This Privacy Policy explains how we collect, use, and safeguard personal data in connection with the services offered through our website at mutiara.biz and through direct client engagements. We take our obligations under Malaysia's Personal Data Protection Act 2010 (PDPA) seriously, and we handle all personal information with the care that sensitive legal matters demand.
If you have any questions about this policy, you may contact us at [email protected].
1. Personal Data We Collect
We may collect the following categories of personal data:
- Contact details — full name, email address, phone number, and mailing address
- Identification information — MyKad number or passport number, where required for legal proceedings
- Financial and asset information — property ownership, bank accounts, and other estate-related details shared during an engagement
- Family and beneficiary information — names and relationships of family members relevant to estate planning or administration
- Website usage data — IP address, browser type, pages visited, and session duration, collected via cookies and analytics tools
Data is collected when you submit an enquiry form on our website, correspond with us by email or phone, or enter into a client engagement agreement.
Legal basis for processing: We process personal data on the basis of (a) your consent, (b) the performance of a contract or pre-contractual steps at your request, (c) compliance with a legal obligation, and (d) our legitimate interests in operating a professional law practice.
Retention: Enquiry data is retained for 12 months. Client engagement data is retained for 7 years from the close of the engagement, consistent with Malaysian legal professional obligations.
2. How We Use Your Data
Personal data collected is used for the following purposes:
- Responding to enquiries and scheduling consultations
- Delivering legal services as agreed in your engagement
- Preparing documents and liaising with Malaysian authorities on your behalf
- Maintaining records required by professional and regulatory obligations
- Improving our website based on aggregated usage analytics
- Sending service-related communications (not marketing, unless you have opted in)
We do not sell personal data to third parties. We do not use your data for automated decision-making or profiling.
3. Data Sharing
We may share personal data with:
- Malaysian government authorities — including the High Court, land offices, and Amanah Raya Berhad, where required to administer an estate
- Financial institutions — when liasing on your behalf during an estate engagement
- IT and hosting providers — who process data on our behalf under appropriate data processing agreements
- Professional advisors — including accountants and valuers, only where relevant and with your knowledge
All third-party recipients are required to handle data in accordance with applicable Malaysian law and their own professional obligations.
4. How We Protect Your Data
We maintain reasonable and appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, or destruction. These include:
- Encrypted transmission of data submitted via our website (HTTPS)
- Access controls limiting data access to authorised staff only
- Secure document storage for physical client files
- Regular review of our information security procedures
In the event of a data breach that may affect your rights, we will notify you as required under the PDPA and inform the relevant authorities where required by law.
5. Cookies
Our website uses cookies to support basic functionality and to understand how visitors use the site. These include essential cookies (required for the site to function), analytics cookies (to improve the website), and preference cookies (to remember your settings). You may manage your cookie preferences at any time via our Cookie Policy page.
6. Your Rights Under Malaysian Law
Under Malaysia's Personal Data Protection Act 2010, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate or incomplete data
- Withdraw consent to data processing at any time (subject to legal obligations)
- Limit the processing of your data in certain circumstances
- Lodge a complaint with the Department of Personal Data Protection (JPDP) if you believe your rights have been breached
To exercise any of these rights, please contact us at [email protected]. We will respond within 21 days. We may ask you to verify your identity before processing a request.
7. Third-Party Links
Our website may contain links to third-party websites. We are not responsible for the privacy practices of those sites and encourage you to review their policies independently. Visiting a linked site does not imply any endorsement by Mutiara.
8. Children's Privacy
Our services are intended for individuals aged 18 and above. We do not knowingly collect personal data from minors. If you believe we have inadvertently received data from someone under 18, please contact us promptly so we can take appropriate steps.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, the updated date at the top of this page will reflect the change. We encourage you to review this policy periodically. Continued use of our website after changes are posted constitutes acceptance of the updated policy.
10. Contact for Data Matters
For any questions, requests, or concerns regarding this Privacy Policy or the handling of your personal data, please contact:
Mutiara
No. 33, Jalan Telawi 5, Bangsar Baru, 59100 Kuala Lumpur, Malaysia
Email: [email protected]
Phone: +60 3-2269 7148