Privacy Policy
Last Updated: 18 May 2025
Thalo Grove ("we", "us", "our") is committed to handling personal data responsibly. This policy explains what information we collect, why we collect it, how we use it, and what rights you have under the Personal Data Protection Act 2010 (PDPA) of Malaysia. It applies to visitors of our website and clients who engage our training services.
For questions about this policy, contact us at [email protected].
1. What Data We Collect
We collect personal data only when you provide it directly or when it arises from your use of our website. The categories we collect include:
- Contact information: name, email address, phone number — submitted through our enquiry form.
- Message content: the text of messages you send via our contact form.
- Technical data: IP address, browser type, device type, pages visited, and session duration — collected automatically through analytics tools if you have consented to analytics cookies.
- Cookie data: your cookie consent preferences, stored in your browser's local storage.
We do not collect sensitive personal data (such as identity card numbers, financial data, or health information) through our website.
2. How We Collect Data
- Directly from you: when you complete and submit our contact form.
- Automatically: through cookies and web analytics tools (only with your consent).
- During service delivery: notes from planning calls or needs reviews, shared by you or your organisation as part of an engagement.
3. Why We Use Your Data
We process personal data for the following purposes:
- Responding to enquiries: to reply to your contact form submission (lawful basis: legitimate interest / performance of a pre-contractual step).
- Providing services: to deliver workshops and learning programmes you have engaged us for (lawful basis: performance of a contract).
- Improving our website: to understand how visitors use our site and identify issues (lawful basis: consent, where analytics cookies are accepted).
- Legal compliance: to meet obligations under Malaysian law, including PDPA 2010 (lawful basis: legal obligation).
We do not use personal data for unsolicited marketing. If you book a service with us and would like to receive occasional updates, we will ask for your explicit agreement separately.
4. Data Sharing
We do not sell or rent personal data. We may share data in the following limited circumstances:
- Service providers: web hosting and analytics providers that process data on our behalf under data processing agreements.
- Legal requirement: if required by Malaysian law, court order, or regulatory authority.
We do not transfer personal data outside Malaysia except where necessary for services you have explicitly requested and with appropriate safeguards in place.
5. Data Retention
- Enquiry form submissions: retained for up to 24 months from the date of submission, then deleted.
- Client engagement records: retained for up to 7 years from the end of the engagement for contractual and legal purposes.
- Analytics data: retained for up to 14 months (standard Google Analytics retention), if you have consented.
- Cookie preference records: stored locally in your browser and cleared when you clear browser data.
6. Data Protection Measures
- Website served over HTTPS with SSL/TLS encryption.
- Access to stored enquiry data is limited to staff directly responsible for responding.
- We do not store payment card details — payments are handled by a third-party payment processor if applicable.
- In the event of a data breach affecting your personal data, we will notify you and the relevant authority in line with PDPA 2010 requirements.
7. Cookies
We use cookies to support site functionality and, where you consent, to collect analytics data. For full details, see our Cookie Policy. You can manage your preferences at any time from that page.
8. Your Rights Under PDPA 2010
As a data subject under the Personal Data Protection Act 2010 (Malaysia), you have the right to:
- Access: request a copy of the personal data we hold about you.
- Correction: request correction of inaccurate or incomplete data.
- Withdrawal of consent: withdraw consent for processing based on consent at any time.
- Restrict processing: request that we limit how we use your data in certain circumstances.
- Erasure: request deletion of data where we have no legal basis to retain it.
To exercise any of these rights, email [email protected]. We will respond within 21 days. Complaints may be directed to the Department of Personal Data Protection Malaysia (pdp.gov.my).
9. Third-Party Links
Our website may link to third-party websites. We are not responsible for their privacy practices. We recommend reviewing the privacy policy of any site you visit.
10. Children's Privacy
Our services are directed at business professionals. We do not knowingly collect personal data from individuals under 18. If you believe a minor has submitted data through our website, please contact us so we can delete it promptly.
11. Changes to This Policy
We may update this policy from time to time. The "Last Updated" date at the top of this page reflects when changes were last made. Continued use of our website after changes constitutes acceptance of the updated policy. For material changes, we will note them clearly on this page.
12. Contact
Data Controller: Thalo Grove
Address: Level 8, Uptown 5, Jalan SS 21/39, 47400 Petaling Jaya, Selangor, Malaysia
Email: [email protected]
Phone: +60 3-7725 4906