LEGAL
Privacy Policy
Last updated: April 2026 | Effective date: April 2026
This Privacy Policy describes how Patrimona ("we", "us", "our"), located at 30 Jalan Gaya, 88000 Kota Kinabalu, Sabah, collects, uses, stores, and protects your personal data. It applies to visitors to our website at patrimon.pro and to individuals who enquire about or enrol in our programs. We are committed to handling your personal data in accordance with Malaysia's Personal Data Protection Act 2010 (PDPA).
Contents
1. Data Controller
Patrimona is the data controller for personal data collected through this website and through our program enrolment process. Our registered address is 30 Jalan Gaya, 88000 Kota Kinabalu, Sabah, Malaysia. For all data protection enquiries, please contact us at [email protected] or by telephone at +60 88-7261 5843.
2. Personal Data We Collect
Depending on how you interact with us, we may collect the following categories of personal data:
- Identity data: full name, preferred name
- Contact data: email address, telephone number, postal address
- Enquiry and communication data: the content of messages you send to us, including through the website contact form
- Enrolment data: program preferences, attendance records, cohort assignment
- Feedback data: post-program survey responses (which may be submitted anonymously at your discretion)
- Technical data: IP address, browser type, device type, pages visited, referring URL — collected automatically via analytics tools when you visit this website
- Payment data: transaction records and payment confirmation details (payment card data is processed by our payment provider and not stored by us directly)
We do not collect sensitive personal data (such as identification card numbers, health information, or financial account details) unless explicitly required for a specific purpose and only with your clear consent.
3. How We Collect Personal Data
We collect personal data through the following means:
- The enquiry and contact form on our website
- Direct communication via email, telephone, or messaging applications
- Program enrolment and registration processes
- Post-program feedback surveys
- Cookies and analytics tools operating on our website (see Section 10)
4. Purposes of Processing
We use your personal data for the following purposes:
- To respond to your enquiries and provide information about our programs
- To process enrolments and administer program participation
- To communicate relevant information about cohort schedules, materials, and program updates
- To maintain records for HRD Corp compliance and training documentation where applicable
- To improve our website and services based on aggregated usage data
- To send occasional communications about upcoming programs, if you have provided consent to receive these
- To comply with applicable legal and regulatory obligations
We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects.
5. Legal Basis for Processing
Under Malaysia's PDPA 2010, we process your personal data based on the following grounds:
- Consent: where you have given clear agreement, such as submitting the contact form or opting in to communications
- Contractual necessity: where processing is required to carry out your program enrolment or respond to a pre-contractual enquiry
- Legal obligation: where we must retain or provide data to comply with applicable Malaysian law
- Legitimate interests: where we have a genuine operational reason to process data and it does not override your rights — for example, maintaining records for training quality and safety purposes
6. Disclosure to Third Parties
We do not sell or rent your personal data to third parties. We may share your data only in the following circumstances:
- Service providers: third-party tools used to operate our website (e.g. analytics providers, email delivery services) who are contractually bound to handle data securely and not use it for their own purposes
- HRD Corp: where required for HRDF-claimable training documentation and only the minimum necessary information
- Legal requirements: if required by applicable law, court order, or government authority
Any third parties with whom we share data are required to maintain appropriate security measures and are prohibited from using your data for any purpose beyond what we have specified.
7. Data Retention
We retain personal data for no longer than is necessary for the purposes for which it was collected, subject to any legal or regulatory requirements:
- Enquiry and contact data: up to 12 months from the date of last contact if no enrolment results
- Enrolment and program records: up to 7 years from the end of the program for compliance and quality assurance purposes
- Marketing consent records: retained until consent is withdrawn
- Website analytics data: according to the retention settings of the analytics provider, typically 14 months
When personal data is no longer required, it is securely deleted or anonymised.
8. Data Security
We take reasonable and appropriate technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. These measures include access controls, secure storage, and regular review of our data handling practices.
While we take these precautions, no method of data transmission or storage can be considered entirely secure. If you have concerns about the security of information you have shared with us, please contact us directly.
9. Your Rights
Under Malaysia's PDPA 2010, you have the following rights in relation to your personal data:
- Right of access: to request a copy of the personal data we hold about you
- Right to correction: to request correction of inaccurate or incomplete personal data
- Right to withdraw consent: where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of processing prior to withdrawal
- Right to limit processing: to request that we limit how we use your data in certain circumstances
To exercise any of these rights, please contact us at [email protected]. We will respond within a reasonable timeframe and no later than 21 days from the date of your request. We may request verification of your identity before processing certain requests.
11. Minors
Our programs and website are directed at adults aged 18 and above. We do not knowingly collect personal data from individuals under the age of 18. If you believe a minor has provided personal data to us, please contact us promptly and we will take steps to remove the information.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or applicable law. The date of the most recent update is shown at the top of this page. We encourage you to review this policy periodically. For significant changes, we will provide a notice where practicable.
Continued use of our website or services after changes are posted constitutes your acknowledgement of the updated policy.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your personal data, please contact us:
- By email: [email protected]
- By telephone: +60 88-7261 5843
- By post: Patrimona, 30 Jalan Gaya, 88000 Kota Kinabalu, Sabah, Malaysia
We take privacy concerns seriously and will respond to your enquiry as promptly as possible.