Legal
Privacy Policy
Last Updated: 12 May 2025 · Saltmarrow, 22 Jalan Padungan, 93100 Kuching, Sarawak, Malaysia
1. Introduction
Saltmarrow ("we", "us", "our") is committed to protecting the personal data of individuals who interact with our website and register for our educational programmes. This policy explains what personal data we collect, why we collect it, how it is used, and how it is protected. It applies to all personal data processed in connection with our website at saltmarrow.sbs and our programme registration processes.
This policy is prepared in compliance with the Personal Data Protection Act 2010 (PDPA), Malaysia. If you have questions about this policy or your personal data, please write to [email protected].
2. Data We Collect
We collect the following categories of personal data:
- Contact information: Full name, email address, and phone number submitted via the enquiry form on our website.
- Programme registration data: Name, email, phone number, and programme selection submitted when registering for a programme.
- Communications data: Content of emails or written messages sent to us.
- Website usage data: IP address, browser type, pages visited, and session duration, collected via analytics cookies (where consent is given).
We do not collect sensitive personal data such as financial account details, identification numbers, or health information.
Data retention: Enquiry data is retained for 12 months. Programme participant data is retained for 36 months following programme completion. Website analytics data is retained for 14 months.
3. How We Use Your Data
Personal data collected is used for the following purposes:
- Responding to enquiries submitted via the website contact form
- Processing programme enrolments and sending programme-related communications
- Sending confirmation, scheduling, and logistical information about programmes you have registered for
- Sending post-programme feedback requests (one contact, opt-out available)
- Improving our website and programme content based on anonymous usage patterns
- Complying with applicable Malaysian law
We do not use personal data for automated decision-making or profiling. We do not sell personal data.
Legal basis: Processing is carried out on the basis of consent (website enquiries), contractual necessity (programme delivery), and legitimate interests (service improvement and communication).
4. Data Sharing
We do not share personal data with third parties for commercial purposes. Limited sharing occurs only in the following circumstances:
- Payment processing: If payment is processed via a third-party gateway, your payment details are handled directly by that provider and are not stored by Saltmarrow.
- Analytics providers: Anonymised and aggregated usage data may be shared with analytics providers (where you have consented to analytics cookies). No personally identifiable information is shared in this context.
- Legal compliance: We may disclose data where required by Malaysian law or a valid court order.
5. Data Protection Measures
We apply appropriate technical and organisational measures to protect personal data, including:
- TLS encryption for data transmitted via our website
- Access controls limiting staff access to personal data on a need-to-know basis
- Secure storage of programme registration records
- Periodic review of data handling practices
In the event of a data breach affecting your personal data, we will notify you in accordance with applicable Malaysian PDPA requirements.
6. Cookies
Our website uses cookies. Essential cookies are required for basic site functionality and cannot be disabled. Optional cookies (analytics) are only placed with your consent via the cookie banner. Please refer to our Cookie Policy for full details and preference management.
7. Your Rights Under the PDPA (Malaysia)
Under the Personal Data Protection Act 2010, you have the following rights with respect to your personal data held by Saltmarrow:
- Right to access: Request a copy of the personal data we hold about you.
- Right to correction: Request correction of inaccurate or incomplete personal data.
- Right to withdraw consent: Withdraw consent for processing at any time, where processing is based on consent.
- Right to limit processing: Request that we limit the use of your personal data in certain circumstances.
- Right to complain: Lodge a complaint with the Personal Data Protection Commissioner of Malaysia if you believe your data has been processed in violation of the PDPA.
To exercise any of these rights, please contact us at [email protected]. We will respond within 21 days.
8. Third-Party Links
Our website may contain links to external websites such as DOSM or Bank Negara Malaysia for reference purposes. We are not responsible for the privacy practices of these external sites and recommend you review their respective privacy policies.
9. Children's Privacy
Our programmes and website are directed at adults aged 18 and above. We do not knowingly collect personal data from individuals under 18 years of age. If we become aware that personal data from a minor has been submitted, we will delete it promptly.
10. Changes to This Policy
We may update this policy from time to time. The date at the top of this page indicates when it was last revised. Material changes will be communicated via a notice on our website or by email to registered participants.
11. Contact
For privacy-related enquiries, please contact our data controller:
Saltmarrow
22 Jalan Padungan, 93100 Kuching, Sarawak, Malaysia
Email: [email protected]
Phone: +60 82 246 7935