Legal Document
Privacy Policy
Last Updated: 18 March 2026 · Effective Date: 18 March 2026
1. Introduction
Mandare ("we", "our", "us") respects the privacy of every person who engages with our services or visits our website. This Privacy Policy explains how we collect, use, store, and protect your personal information in accordance with the Personal Data Protection Act 2010 (PDPA) of Malaysia.
This policy applies to all personal data processed in connection with our legal advisory services and the use of our website at https://mandarex.pro.
If you have questions regarding this policy or how your data is handled, please contact us at [email protected].
2. Data Collection
What We Collect
- Identity Data: Full name, designation, and company name (where applicable)
- Contact Data: Email address and telephone number
- Enquiry Data: Details submitted through our contact form or via email
- Technical Data: IP address, browser type, operating system, and pages visited (via analytics tools)
- Cookie Data: Preferences and session identifiers (see Section 5)
How We Collect It
We collect personal data through:
- Enquiry and contact forms on our website
- Direct email, phone, or in-person communications
- Automated technologies such as cookies and server logs
Legal basis for processing: We process your data on the basis of consent (where given), contractual necessity (to provide legal advisory services), and legitimate interest (to improve our website and services). Retention periods are typically 7 years for engagement records, consistent with Malaysian legal practice requirements, and up to 2 years for enquiry data.
3. Data Usage
We use the personal data we collect for the following purposes:
To assess your legal advisory needs, prepare engagement materials, and communicate throughout the advisory process.
To respond to enquiries, send appointment confirmations, and provide relevant updates on your matter.
To understand how visitors use our website, identify areas for improvement, and maintain technical performance.
To fulfil obligations under Malaysian law, including record-keeping requirements applicable to legal service providers.
We do not sell, rent, or trade your personal data to third parties for marketing purposes. Where we share data with service providers (e.g., cloud hosting, analytics platforms), we do so under data processing agreements that restrict further use.
4. Data Protection Measures
We apply reasonable technical and organisational safeguards to protect personal data against unauthorised access, loss, or disclosure:
Encryption
Data transmitted through our website is protected using TLS/SSL encryption.
Access Controls
Access to personal data is restricted to authorised personnel on a need-to-know basis.
Secure Storage
Client records are stored on secured systems with regular backup and integrity checks.
Breach Notification
In the event of a data breach affecting your rights, we will notify affected individuals as required by applicable law.
6. Your Rights
Under the Personal Data Protection Act 2010 (Malaysia), you have the following rights with respect to your personal data:
To exercise any of these rights, please contact us at [email protected]. We aim to respond within 21 days. If you are not satisfied with our response, you may lodge a complaint with the Department of Personal Data Protection Malaysia (JPDP).
7. Third-Party Links
Our website may contain links to external sites, government portals (such as JAKIM or MCMC), or other resources. We do not control these external platforms and are not responsible for their privacy practices. We encourage you to review the privacy policies of any external sites you visit.
8. Children's Privacy
Our services are intended for individuals aged 18 and above. We do not knowingly collect personal data from persons under the age of 18. If you believe we have inadvertently collected such data, please contact us so we can take appropriate action.
9. Policy Changes
We may update this Privacy Policy from time to time to reflect changes in our practices, services, or applicable laws. When we do, we will revise the "Last Updated" date at the top of this page.
Where changes are material, we will take reasonable steps to notify you, such as posting a notice on our website. Continued use of our website or services after the effective date of any changes constitutes acceptance of the revised policy.
10. Contact Us
If you have questions, concerns, or requests related to this Privacy Policy or your personal data, please reach out to us: