Legal
Privacy Policy
Last Updated: 22 April 2025 · Effective: 22 April 2025
1. Introduction
Tenang ("we", "us", "our") is committed to protecting the personal information of everyone who interacts with us — whether that is through our website, by attending one of our programmes, or by making an enquiry. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and your rights regarding that data.
Tenang is based at Level 5, Wisma Mont Kiara, 1 Jalan Kiara, Mont Kiara, 50480 Kuala Lumpur, Malaysia. This policy is governed by and interpreted in accordance with Malaysia's Personal Data Protection Act 2010 (PDPA).
If you have questions about this policy or how your data is handled, contact us at [email protected].
2. Data We Collect
We collect only the personal data that is necessary for the purposes described below. This includes:
- Contact information — name, email address, and telephone number provided via our enquiry form or during programme registration.
- Programme participation data — records of which programmes you have enrolled in or attended, for administrative and communication purposes.
- Correspondence — emails, messages, and other communications you send to us.
- Website usage data — anonymous or aggregated data collected via cookies, including pages visited, time on site, and browser type. This data does not personally identify you unless combined with other information.
We do not collect any financial information (bank details, card numbers), sensitive personal data, or data from minors under 18.
3. How We Collect Data
- Enquiry and contact forms on our website, where you voluntarily provide information.
- Programme registration — information collected when you register for a workshop or programme.
- Direct communication — information provided when you email or call us.
- Cookies and analytics — see our Cookie Policy for full details. We use analytics tools to understand general website usage patterns.
4. Legal Basis for Processing
Under the PDPA and generally accepted data protection principles, we process personal data on the following bases:
- Consent — where you have provided explicit consent, for example by submitting an enquiry form or opting in to communications.
- Contract — where processing is necessary to fulfil a programme booking or service agreement with you.
- Legitimate interests — where processing is necessary for our legitimate business interests, such as responding to general enquiries, provided these interests are not overridden by your rights.
- Legal obligation — where we are required to process data to comply with a legal obligation.
5. How We Use Your Data
- To respond to enquiries and provide information about our programmes.
- To administer programme registrations and communicate logistical information.
- To send occasional updates about upcoming programmes or changes to our offerings — you may opt out at any time.
- To improve our website and services based on aggregated, anonymous usage data.
- To comply with applicable legal and regulatory obligations.
We do not use your data to make automated decisions that affect you, nor do we engage in profiling for marketing purposes.
6. Data Sharing and Third Parties
We do not sell personal data. We may share data with the following categories of third party, only where necessary:
- Service providers — such as email delivery services and website hosting providers, under data processing agreements that require them to handle data securely and only for specified purposes.
- Analytics tools — anonymised or aggregated data shared with analytics providers (such as Google Analytics) for website improvement. No personally identifying data is shared in this context.
- Legal obligations — where we are required by law or a court order to disclose information.
7. Data Retention
- Enquiry data — retained for 24 months from the date of the enquiry, unless a programme booking is made.
- Programme participant data — retained for 5 years from the date of participation, for record-keeping and communication purposes.
- Correspondence — retained for 24 months unless part of an ongoing relationship.
- Analytics data — anonymous and aggregated; retained per the analytics provider's standard retention settings.
On expiry of retention periods, data is securely deleted or anonymised.
8. Data Security
We take reasonable technical and organisational measures to protect personal data against unauthorised access, disclosure, or loss. These include:
- Secure, encrypted connections (HTTPS) on our website.
- Access controls limiting which staff can view personal data.
- Password-protected storage systems for administrative records.
- Regular review of data handling practices.
In the unlikely event of a data breach affecting your personal information, we will notify affected individuals and relevant authorities as required under the PDPA.
9. Cookies
We use cookies on our website to maintain basic site functionality and to understand how visitors use the site. Essential cookies cannot be disabled as they are required for the site to work. Optional analytics and preference cookies can be managed via our Cookie Policy page, where you can adjust your preferences at any time.
10. Your Rights
Under the PDPA, you have the right to:
- Access — request a copy of the personal data we hold about you.
- Correction — request that inaccurate or incomplete data be corrected.
- Withdrawal of consent — withdraw consent to processing at any time (this does not affect the lawfulness of processing before withdrawal).
- Objection — object to processing carried out on the basis of legitimate interests.
- Erasure — request deletion of your data where it is no longer needed for the purposes for which it was collected, subject to legal retention requirements.
To exercise any of these rights, write to us at [email protected]. We will respond within 30 days. Where identity verification is required, we may ask for reasonable supporting information.
If you believe your data has been handled unlawfully, you may lodge a complaint with the Department of Personal Data Protection Malaysia (PDPD) at pdp.gov.my.
11. Third-Party Links
Our website may include links to external websites. We are not responsible for the privacy practices of third-party sites and encourage you to review their privacy policies independently. This policy applies only to data collected via Tenang's own website and services.
12. Children's Privacy
Tenang's programmes are designed for adults aged 18 and above. We do not knowingly collect personal data from individuals under 18. If we become aware that data has been collected from a minor, we will delete it promptly. If you believe this has occurred, please contact us at [email protected].
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last Updated" date at the top of this page. Continued use of our website after changes take effect constitutes acceptance of the revised policy. For significant changes, we will make reasonable efforts to notify affected individuals directly.
14. Contact
For any data protection queries, requests, or concerns:
Tenang
Level 5, Wisma Mont Kiara, 1 Jalan Kiara, Mont Kiara, 50480 Kuala Lumpur
Email: [email protected]
Phone: +60 3-6201 9438