Privacy Policy
Last Updated: 28 March 2026 | Effective Date: 1 April 2026
Corthane is committed to handling personal information with care and transparency. This policy explains what data we collect, how it is used, how long we keep it, and the rights you hold under Malaysian law — principally the Personal Data Protection Act 2010 (PDPA). If you have questions at any point, please reach us at [email protected].
1. Data Controller
The data controller responsible for personal information collected through this website and our services is:
Corthane
52 Jalan Wong Ah Fook, 80000 Johor Bahru, Johor, Malaysia
Tel: +60 7-3384 9216
Email: [email protected]
2. Data We Collect
We collect personal data through several channels, and only what is reasonably necessary for the purposes described in this policy.
Information You Provide Directly
- Contact details: full name, email address, phone number submitted via our enquiry form
- Enquiry content: the substance of messages you send us
- Business information: company name, registration details, and matter-related documents you share during engagement
Information Collected Automatically
- Technical data: IP address, browser type, device information, referring URLs
- Usage data: pages visited, time on site, interaction patterns — collected via cookies and analytics tools
3. Legal Basis for Processing
Under the PDPA 2010, we process personal data on the following bases:
Contractual Necessity
Processing required to deliver the legal services you have engaged us to provide.
Consent
Where you have provided explicit consent, such as for optional analytics or marketing communications.
Legitimate Interest
For internal operations such as website security, fraud prevention, and improving service quality.
Legal Obligation
Where retention or disclosure is required under Malaysian law, including Bar Council regulations.
4. How We Use Your Data
- Responding to enquiries submitted through our contact form
- Delivering contracted legal services including document drafting, compliance reviews, and litigation support
- Sending matter-related correspondence and updates relevant to your engagement
- Maintaining accurate billing and administrative records
- Analysing website usage to improve content and functionality (analytics cookies, where consented)
- Complying with professional obligations under Malaysian Bar regulations and applicable statutes
We do not use your personal data for automated decision-making that produces legal or similarly significant effects.
5. Sharing & Disclosure
We do not sell personal information. Data may be shared in the following limited circumstances:
6. Retention Periods
We retain personal data for as long as necessary for the purpose it was collected, or as required by law.
| Data Category | Retention Period | Basis |
|---|---|---|
| Client matter files | 7 years from matter closure | Legal obligation / limitation periods |
| Billing and financial records | 7 years | Malaysian tax and company law |
| Enquiry form submissions (non-clients) | 12 months | Legitimate interest |
| Website analytics data | 14 months | Consent (where applicable) |
| Cookie consent records | 12 months | Legal compliance |
7. Security Measures
We implement reasonable technical and organisational safeguards to protect personal data from unauthorised access, loss, or disclosure.
TLS Encryption — all data in transit is transmitted over secure, encrypted connections.
Secure Storage — client files are held on access-controlled servers with regular backup routines.
Access Controls — only personnel who require access to a matter are authorised to view related data.
Breach Response — in the event of a data breach affecting your information, we will notify you and the relevant authority within the timeframes prescribed by law.
9. Your Rights
As a data subject under the PDPA 2010 and applicable Malaysian law, you have the following rights:
Right of Access
You may request a copy of the personal data we hold about you, along with information on how it is processed.
Right to Correction
Where information is inaccurate or incomplete, you may request that it be corrected.
Right to Withdraw Consent
Where processing is based on consent, you may withdraw that consent at any time. This does not affect the lawfulness of processing carried out before withdrawal.
Right to Object
You may object to processing carried out on the basis of legitimate interest, including any direct communications you did not explicitly request.
Right to Complain
If you believe your personal data has been handled in a manner inconsistent with applicable law, you may lodge a complaint with the Personal Data Protection Commissioner of Malaysia.
To exercise any of these rights, write to us at [email protected]. We aim to respond within 21 days.
10. Third-Party Links
Our website may contain links to external websites or resources. Corthane is not responsible for the privacy practices of third-party sites, and this policy does not apply to them. We encourage you to review the privacy notices of any external site you visit.
11. Children's Privacy
Our services are intended for individuals aged 18 and above. We do not knowingly collect personal information from minors. If you believe a person under 18 has submitted information through our website, please contact us at [email protected] and we will take appropriate steps to remove such data.
12. Policy Updates
We may revise this policy from time to time as our services evolve or as legal requirements change. When material changes are made, we will update the "Last Updated" date at the top of this page. Continued use of our website following any revision constitutes acknowledgement of the updated terms. Where changes are particularly significant, we may also provide notice through other appropriate channels.
13. Contact Us
For any privacy-related queries, data subject requests, or concerns about how Corthane handles personal information, please do not hesitate to reach us: