Legal
Privacy Policy
Last updated: 21 March 2025
Setia Chambers is committed to protecting the personal information of everyone who contacts us or uses our website. This policy explains what information we collect, how we use it, and your rights under Malaysian data protection law.
1. Who We Are
The data controller for your personal information is:
Setia Chambers
Unit 22, Ipoh Garden Square, Jalan Lapangan Siber, 31400 Ipoh, Perak, Malaysia
Email: [email protected]
Telephone: +60 5 254 8176
2. What Personal Data We Collect
We collect personal data only when you actively provide it or when it is generated through your use of our website. This may include:
- Identity information: your name, as provided in enquiry forms
- Contact information: email address and telephone number
- Matter-related information: details of your legal matter as shared in correspondence or meetings
- Technical data: IP address, browser type, pages visited (collected via cookies, where consented)
We do not collect sensitive personal data (such as health data or financial account information) through our website forms. If your legal matter involves such data, it is handled under separate solicitor-client confidentiality obligations.
3. How We Collect Your Data
- Enquiry forms submitted on this website
- Direct email or telephone contact with our office
- In-person consultations or meetings
- Cookies and analytics tools on our website (where consented — see Section 7)
4. Legal Basis for Processing
Under the Personal Data Protection Act 2010 (PDPA) of Malaysia, we process your data on the following bases:
- Consent: when you submit an enquiry form or accept optional cookies
- Contractual necessity: when handling data required to provide the legal services you have engaged us for
- Legal obligation: where we are required to retain records under Malaysian legal or professional obligations
- Legitimate interests: for website analytics where this does not override your rights
5. How We Use Your Data
- To respond to your enquiry and arrange an initial consultation
- To deliver the legal services you have engaged us to provide
- To comply with our professional obligations under the Legal Profession Act 1976 and Bar Council rules
- To improve our website based on anonymised usage data (where analytics cookies are enabled)
- To maintain records required by law
We do not use your data for automated decision-making or profiling. We do not send marketing communications without your explicit consent.
6. Data Sharing
We do not sell or share your personal data with third parties for commercial purposes. We may share your data only in these limited circumstances:
- With your consent: for example, with independent medical experts engaged as part of your matter
- Legal requirement: where disclosure is required by a Malaysian court order or by law
- Service providers: IT and hosting providers who process data only on our instruction under contractual obligations
7. Cookies
We use essential cookies required for this website to function, and optional analytics and preference cookies where you have given consent. For full information about the cookies we use and how to manage your preferences, please see our Cookie Policy.
8. Data Retention
We retain your personal data only for as long as necessary for the purpose for which it was collected:
- Enquiries that do not lead to an engagement: up to 12 months
- Active matter files: for the duration of the matter plus 7 years (as required by professional rules)
- Website analytics data (anonymised): up to 26 months
9. Data Security
We maintain appropriate technical and organisational measures to protect your personal data, including encrypted storage, restricted access controls, and regular review of our data handling practices. In the event of a data breach that is likely to affect your rights, we will notify you and the relevant authority in accordance with PDPA requirements.
10. Your Rights Under the PDPA
Under the Personal Data Protection Act 2010, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Withdraw consent where processing is based on consent, without affecting prior processing
- Request deletion of data where there is no legal obligation to retain it
- Limit processing in certain circumstances
- Lodge a complaint with the Department of Personal Data Protection (JPDP) if you believe we have handled your data unlawfully
To exercise any of these rights, contact us at [email protected]. We will respond within 21 days.
11. Third-Party Links
Our website may contain links to external websites. We are not responsible for the privacy practices of those websites and recommend you review their privacy policies separately.
12. Children's Privacy
Our services are intended for adults aged 18 and above. We do not knowingly collect personal data from minors. If you believe a minor has submitted data to us, please contact us so we can remove it promptly.
13. Changes to This Policy
We may update this policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Continued use of our website after any update constitutes acceptance of the revised policy.
14. Contact for Privacy Matters
For any questions about this policy or your personal data, please contact:
Data Privacy Enquiries
Setia Chambers
Unit 22, Ipoh Garden Square, 31400 Ipoh, Perak
Email: [email protected]