Legal
Privacy Policy
Last updated: 14 April 2025 | Sable Roan, Kuala Lumpur, Malaysia
Sable Roan ("we", "us", "our") is a household documentation and information services business operating from Kuala Lumpur, Malaysia. This Privacy Policy explains what personal data we collect, how we use it, and what choices you have in relation to it. It applies to data collected through our website at sableroan.site and during the course of our engagements with clients.
Our services are administrative and informational. The data we collect is limited to what is needed to deliver those services. We do not collect data beyond that purpose and we do not sell or rent personal information to third parties.
This policy is written to comply with the Personal Data Protection Act 2010 (PDPA) of Malaysia, which is the applicable data protection legislation for our operations.
1. Personal Data We Collect
We collect only the data necessary for enquiries and service delivery. This includes:
- Contact details: name, email address, and phone number (if provided) — collected via the contact form on our website.
- Household information: renewal item details, document types, and scheduling preferences — provided by clients during setup or facilitation sessions.
- Communication records: written summaries of facilitation sessions and correspondence related to your engagement.
- Website usage data: anonymised data collected via cookies and analytics tools (see Section 5).
We do not collect financial account details, government identification numbers, or medical information.
Legal basis for processing
- Contractual necessity: processing needed to deliver the service you have engaged us for.
- Consent: for website cookies and any optional communications you opt into.
- Legitimate interests: for maintaining records of completed engagements.
Retention periods
- Contact enquiries not leading to engagements: deleted within 12 months of enquiry.
- Active engagement records: retained for the duration of the engagement plus 3 years.
- Completed engagement records: retained for 3 years after engagement close, then deleted.
- Website analytics data: retained as per the analytics provider's standard retention settings (typically 14 months).
2. How We Use Your Data
- To respond to enquiries and confirm engagement details.
- To deliver the service you have engaged us for — including preparing trackers, session agendas, summaries, and workbook materials.
- To send you materials related to your engagement (digitally or by post).
- To maintain records of completed engagements for administrative purposes.
- To improve our website using anonymised analytics data.
We do not use your personal data for marketing purposes without your explicit consent. We do not share your data with advertising networks.
3. Data Sharing with Third Parties
We do not sell or rent personal data. Limited sharing occurs only in the following circumstances:
- Service providers: we use a small number of trusted third-party tools for email hosting and website analytics. These providers process data only on our instruction and are subject to data processing agreements.
- Legal obligations: if required to do so by Malaysian law or a valid court order.
No data is transferred outside Malaysia for the primary purpose of our services. Analytics data may be processed by international service providers subject to standard contractual protections.
4. How We Protect Your Data
- Client records are stored on password-protected, access-controlled systems.
- Digital file transfers use encrypted channels where possible.
- Access to personal data within our team is restricted to those who need it for service delivery.
- In the event of a data breach that poses a risk to your rights, we will notify affected individuals promptly and take steps to contain the breach.
5. Cookies
Our website uses cookies to understand how visitors use the site and to remember your cookie preferences. We use the following categories:
- Essential cookies: required for the website to function (always active).
- Analytics cookies: anonymised data on page visits and navigation patterns.
- Preference cookies: remembers your cookie consent choice.
Full details are in our Cookie Policy. You can manage your preferences there at any time.
6. Your Rights Under the PDPA 2010
Under the Personal Data Protection Act 2010 (Malaysia), you have the following rights in relation to your personal data:
- Access: request a copy of the personal data we hold about you.
- Correction: request that inaccurate or incomplete data be corrected.
- Withdrawal of consent: withdraw consent for processing where consent was the legal basis (this may affect service delivery).
- Objection to processing: object to processing based on legitimate interests.
- Deletion: request erasure of data no longer needed for the original purpose, subject to our legal retention obligations.
To exercise any of these rights, write to us at [email protected]. We will respond within 21 calendar days.
If you believe we have not handled your data in accordance with the PDPA, you may contact the Department of Personal Data Protection Malaysia (JPDP) at www.pdp.gov.my.
7. Third-Party Links
Our website may contain links to external websites. We are not responsible for the privacy practices or content of those sites. We encourage you to review the privacy policies of any site you visit through a link on our pages.
8. Children's Privacy
Our services are directed at adults (18 years and over). We do not knowingly collect personal data from individuals under the age of 18. If we become aware that a minor has provided personal data without appropriate consent, we will delete it promptly.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, the "Last updated" date at the top of this page will change. For material changes, we will notify active clients by email. Continued use of our services after a policy update constitutes acceptance of the revised terms.
10. Contact for Data Enquiries
For any questions about this Privacy Policy or how your data is handled:
- Data Controller: Sable Roan
- Address: 9 Persiaran Stonor, 50450 Kuala Lumpur, Malaysia
- Email: [email protected]
- Phone: +60 12-374 6852 (business hours)