Privacy Policy
Last Updated: 15 April 2025 | Effective: 15 April 2025
Lestari Counsel Sdn Bhd ("Lestari Counsel", "we", "us", or "our"), registered in Malaysia, is committed to handling personal data with care and transparency. This Privacy Policy explains what data we collect from visitors to our website and from individuals who engage with our advisory services, how we use that data, and what rights you hold under Malaysian law.
This policy applies to the website at https://lestari-counsel.info and to all personal data collected in the course of our advisory engagements. If you have questions that this document does not address, please write to us at [email protected].
1. Who We Are
Lestari Counsel is the data controller for personal data collected through this website. Our registered office is at 41 Persiaran Tropicana, Tropicana Golf Resort, 47410 Petaling Jaya, Selangor, Malaysia.
2. What Personal Data We Collect
We collect personal data through two principal means:
Via the website enquiry form
- Full name (required)
- Email address (required)
- Telephone number (optional)
- Enquiry message content (optional)
Via analytics and cookies
- Browser type and version
- Pages visited and time on site
- Referring URL
- Approximate geographic location (country/region level only)
We do not collect sensitive personal data such as identification numbers, financial account details, or health information through this website.
3. Legal Basis for Processing
We process personal data under the Personal Data Protection Act 2010 (Malaysia) ("PDPA 2010") on the following bases:
- Consent — where you submit the enquiry form or accept analytical cookies, you consent to the processing described in this policy.
- Legitimate interests — we process analytical data to understand how our website is used and to improve it. We balance this against your privacy rights.
- Contractual performance — where you engage us for advisory services, we process personal data to deliver those services under the terms agreed.
4. How We Use Personal Data
- To respond to enquiries submitted through the contact form
- To deliver advisory services where an engagement is agreed
- To maintain a record of professional communications for our own reference
- To understand aggregate website usage patterns (no individual-level behavioural profiling)
- To comply with legal obligations applicable to our practice in Malaysia
We do not sell personal data to third parties. We do not use personal data for unsolicited direct marketing without your explicit consent.
5. Data Sharing
We share personal data only in the following limited circumstances:
- Service providers — we use a small number of trusted service providers for website hosting and analytics (including Google Analytics, where consented). These providers are bound by contractual obligations consistent with applicable data protection law.
- Legal requirements — we may disclose data where required by Malaysian law or by a lawful order from a court or regulatory authority.
- Professional advisors — our lawyers and accountants may access engagement-related data as necessary for their advisory function, under confidentiality obligations.
6. Data Retention
Enquiry data from the website contact form is retained for a maximum of twelve months from the date of submission, unless the enquiry leads to a professional engagement, in which case the data is retained for seven years from the conclusion of that engagement in accordance with standard professional record-keeping practice.
Analytics data is retained in aggregated, anonymised form only. No individual-level analytics data is retained beyond the session.
7. Cookies
We use a small number of cookies on this website. Essential cookies are required for the site to function and cannot be declined. Optional analytics cookies are activated only with your consent, which you may give or withhold via the cookie banner that appears on your first visit. For full details, please see our Cookie Policy.
8. Data Protection Measures
We apply the following measures to protect personal data in our custody:
- Website served over HTTPS with current TLS encryption
- Access to personal data restricted to staff with a legitimate need
- Engagement documents held on password-protected systems with access logging
- In the event of a data breach affecting your personal data, we will notify you and, where applicable, the relevant regulatory authority in accordance with the PDPA 2010
9. Your Rights Under Malaysian Law
Under the Personal Data Protection Act 2010 (Malaysia), you have the following rights in relation to personal data we hold about you:
- Right of access — you may request a copy of the personal data we hold about you.
- Right of correction — you may request that inaccurate or incomplete data be corrected.
- Right to withdraw consent — where processing is based on your consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing prior to the withdrawal.
- Right to prevent processing — you may request that we cease processing your data for purposes that cause or are likely to cause damage or distress.
- Right to request destruction — where your data is no longer necessary for the purpose for which it was collected, you may request that it be destroyed.
To exercise any of these rights, please write to us at [email protected]. We will respond within thirty days.
If you are not satisfied with our response, you may lodge a complaint with the Department of Personal Data Protection Malaysia (JPDP).
10. Third-Party Links
Our website may contain links to external websites. Lestari Counsel is not responsible for the privacy practices of those websites. We recommend that you review the privacy policy of any external site before submitting personal data to it.
11. Children
Our services are directed at business professionals and organisational clients. We do not knowingly collect personal data from individuals under the age of eighteen. If we become aware that such data has been collected, we will delete it promptly.
12. International Transfers
Personal data submitted through this website may be processed by service providers operating outside Malaysia, including in jurisdictions within the European Economic Area and in the United States. Where we transfer personal data internationally, we ensure that appropriate safeguards are in place consistent with the PDPA 2010.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be noted by updating the "Last Updated" date at the top of this document. Where changes are significant, we will place a notice on the website homepage for a reasonable period.
14. Contact for Data Enquiries
For any questions or requests relating to this Privacy Policy or to the personal data we hold:
- Email: [email protected]
- Post: Lestari Counsel Sdn Bhd, 41 Persiaran Tropicana, Tropicana Golf Resort, 47410 Petaling Jaya, Selangor, Malaysia
- Telephone: +60 3 8329 4751