1. Introduction
Finloom ("we", "our", "us") is committed to protecting the personal data of every individual who interacts with our services, website, and programs. This Privacy Policy explains how we collect, use, store, and protect your personal data in compliance with the Personal Data Protection Act 2010 (PDPA) of Malaysia and other applicable legislation.
By using our website at finloomx.live or enrolling in any of our programs, you acknowledge that you have read and understood this policy. If you do not agree with any part of this policy, please refrain from submitting your personal data to us.
2. Data Controller
The data controller responsible for your personal data is:
Finloom
17 Jalan Raja Chulan, 50200 Kuala Lumpur, Malaysia
Tel: +60 3-2638 4719
Email: [email protected]
3. Data We Collect
We collect personal data only to the extent necessary for the purposes described in this policy. The categories of data we may collect include:
3.1 Data you provide directly
- Full name and preferred name
- Email address and telephone number
- Age or date of birth (for age-restricted programs such as the Youth Financial Literacy Program)
- Occupation or business type (where relevant to program eligibility)
- Correspondence, enquiries, and form submissions
- Payment and billing information (processed securely via our payment provider)
3.2 Data collected automatically
- IP address and browser type
- Pages visited and time spent on the website
- Referring URL and device type
- Cookie identifiers (see Section 10)
4. Purpose of Processing
We process your personal data for the following purposes:
- To respond to enquiries and provide information about our programs
- To process enrolment and manage your participation in a program
- To send program-related communications, schedules, and materials
- To process payments and issue receipts
- To improve our programs based on participant feedback
- To comply with legal and regulatory obligations
- To send occasional updates about new programs or changes โ you may opt out at any time
We do not use your data for automated decision-making or profiling that produces legal effects on you.
5. Legal Basis for Processing
Under the PDPA 2010, we process your personal data on the following bases:
- Consent โ where you have provided your personal data through our contact form or enrolment process
- Contractual necessity โ where processing is required to fulfil a program enrolment agreement
- Legal obligation โ where we are required by law to retain or disclose data
- Legitimate interest โ for website analytics and service improvement, balanced against your privacy interests
6. Disclosure of Personal Data
We do not sell, trade, or rent your personal data to third parties. We may share your data only in the following limited circumstances:
- Service providers โ trusted third parties who assist with payment processing, email delivery, or website hosting, operating under data processing agreements
- Legal requirements โ where required by law, court order, or regulatory authority in Malaysia
- Business transfers โ in the event of a merger or acquisition, with appropriate safeguards
Any third-party service providers engaged by Finloom are contractually required to handle your data securely and only for the purposes we specify.
7. Data Retention
We retain your personal data only for as long as is reasonably necessary to fulfil the purposes for which it was collected:
- Enquiry and contact form data: up to 12 months from date of submission
- Enrolment and participant records: up to 7 years for legal and financial compliance
- Payment records: as required under Malaysian tax and accounting regulations
- Website analytics data: 26 months (Google Analytics default, pseudonymised)
After the applicable retention period, data is securely deleted or anonymised.
8. Security Measures
We implement reasonable and appropriate technical and organisational security measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. These include:
- HTTPS encryption for all website communications
- Access controls limiting data access to authorised personnel
- Secure storage of participant records
- Regular review of our data handling practices
While we take these precautions, no internet transmission is completely secure. We encourage you to take care when submitting sensitive information online.
9. Your Rights Under the PDPA 2010
As a data subject under Malaysian law, you have the following rights:
- Right of access โ to request a copy of the personal data we hold about you
- Right to correction โ to request that inaccurate or incomplete data be corrected
- Right to withdraw consent โ to withdraw consent for marketing or non-essential communications at any time
- Right to limit processing โ to request restriction of processing in certain circumstances
To exercise any of these rights, please contact us at [email protected] or call +60 3-2638 4719. We will respond within 21 days. There is no fee for reasonable access requests.
11. Minors
Our website is intended for adults and individuals aged 17 and above. Participants under the age of 18 enrolling in the Youth Financial Literacy Program should do so with the knowledge and consent of a parent or guardian. We do not knowingly collect personal data from children under 13. If you believe a child has submitted personal data to us without appropriate consent, please contact us promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. Where changes are material, we will provide reasonable notice on our website. The date at the top of this page indicates when the policy was last revised. Continued use of our website or services after any update constitutes acceptance of the revised policy.
13. Contact Us
If you have any questions, concerns, or complaints regarding this Privacy Policy or how we handle your personal data, please contact us:
Finloom โ Data Enquiries
17 Jalan Raja Chulan, 50200 Kuala Lumpur
Tel: +60 3-2638 4719
Email: [email protected]
You also have the right to lodge a complaint with the Personal Data Protection Commissioner of Malaysia if you believe your data rights have been infringed.