Privacy Policy
Last Updated: 12 May 2025 · Effective: 12 May 2025
Quillaja ("we", "us", "our") is committed to handling personal data responsibly. This Privacy Policy explains what personal data we collect from visitors to our website and clients engaging our services, how we use it, and the rights you have in relation to it. Our practices are aligned with the requirements of Malaysia's Personal Data Protection Act 2010 (PDPA).
1. Data Controller
The data controller for personal data collected through this website and in relation to our services is Quillaja, located at No. 18-1, Jalan PJU 1/3B, SunwayMas Commercial Centre, 47301 Petaling Jaya, Selangor, Malaysia. For data-related enquiries, contact us at [email protected].
2. Personal Data We Collect
We collect personal data in the following ways:
- Contact forms: When you submit an enquiry through our website, we collect your name, email address, and optionally your phone number and message content.
- Service engagements: When you become a client, we may collect additional business contact information and the survey or form response data you share with us for the purpose of the engagement.
- Cookies and analytics: We use cookies to understand how the website is used. See Section 7 and our Cookie Policy for details.
We do not collect sensitive personal data (as defined under the PDPA) through our website or standard service engagements. If survey response data shared with us for an engagement contains sensitive personal data, this is handled under the terms agreed in the service scope.
3. Legal Basis for Processing
We process personal data on the following bases:
- Consent: For website enquiries and cookie preferences.
- Contract: When processing data necessary to deliver the service you have engaged.
- Legitimate interest: For internal record-keeping and service improvement, where this does not override your rights.
- Legal obligation: Where required by Malaysian law.
4. How We Use Personal Data
- To respond to website enquiries and provide information about our services.
- To deliver services you have engaged, including processing survey response data as described in the service scope.
- To communicate project updates, invoice information, and service-related correspondence.
- To maintain records of completed engagements for internal reference.
- To improve our website using anonymised analytics data.
We do not use your personal data for direct marketing communications without your explicit consent. We do not sell personal data to any third party.
5. Data Sharing
We do not share personal data with third parties except in the following limited circumstances:
- Service providers: We may use third-party tools for email delivery or analytics. These providers process data only on our behalf and under appropriate data processing terms.
- Legal requirements: Where required to comply with applicable Malaysian law or a valid legal process.
Survey response data shared with us for a client engagement is not shared with any third party and is not retained beyond the project period unless explicitly agreed otherwise in writing.
6. Data Retention
- Website enquiry data is retained for up to 12 months from the date of submission.
- Client engagement data (contact information and project correspondence) is retained for up to 3 years following the close of the engagement for record-keeping purposes.
- Survey response data shared for a service engagement is deleted within 30 days of the engagement close-out, unless a different period is agreed in the service scope.
- Cookie data follows the retention periods set out in our Cookie Policy.
7. Cookies
Our website uses cookies to track visits and understand usage patterns. We use essential cookies (required for the site to function) and optional analytics and preference cookies (used with your consent). Full details on the types of cookies used, their purpose, and how to manage them are available in our Cookie Policy.
8. Data Protection Measures
We take reasonable technical and organisational steps to protect personal data against unauthorised access, loss, or disclosure. These include:
- Use of secure communication channels (HTTPS) for data transmission.
- Access controls limiting data access to team members who require it for their work.
- Prompt deletion of survey response data at the end of the project period.
- Accepting anonymised data from clients where possible, reducing the personal data involved in engagements.
In the event of a personal data breach that is likely to result in risk to individuals, we will notify affected parties and, where required under applicable law, the relevant authority, within a reasonable timeframe.
9. Your Rights Under the PDPA
Under Malaysia's Personal Data Protection Act 2010, you have the following rights in relation to personal data we hold about you:
- Right of access: To request a copy of the personal data we hold about you.
- Right of correction: To request correction of inaccurate or incomplete personal data.
- Right to withdraw consent: To withdraw consent to processing where consent is the basis for processing.
- Right to limit processing: To request that we stop using your data for certain purposes.
To exercise any of these rights, contact us at [email protected]. We will respond within 21 days. In the event you are not satisfied with our response, you may contact the Department of Personal Data Protection Malaysia (JPDP) as the relevant supervisory authority.
10. Third-Party Links
Our website may contain links to external websites. We are not responsible for the privacy practices of those sites and encourage you to review their privacy policies independently.
11. Children's Privacy
Our services are directed at organisations and professionals. We do not knowingly collect personal data from individuals under 18 years of age. If you believe a minor has submitted data through our website, contact us at [email protected] and we will delete the data promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last Updated" date at the top of the page. Continued use of our website or services after changes take effect constitutes acceptance of the updated policy. We recommend checking this page periodically.
13. Contact Us
For any questions about this Privacy Policy or how we handle your personal data:
Quillaja
No. 18-1, Jalan PJU 1/3B, SunwayMas Commercial Centre
47301 Petaling Jaya, Selangor, Malaysia
Email: [email protected]
Phone: +60 3-7805 4419