Legal

Privacy Policy

Last updated: 10 March 2026  ·  Effective: 10 March 2026

Gemilang Trade respects the privacy of everyone who interacts with our firm. This Privacy Policy explains how we collect, use, store, and protect personal data provided to us through our website and in the course of advisory engagements. We handle personal information with care and in accordance with the Personal Data Protection Act 2010 (PDPA) of Malaysia.

If you have questions about how your data is handled, please write to us at [email protected].

1. Data We Collect

We may collect and process the following categories of personal data:

  • Identity data — name, designation, company name
  • Contact data — email address, telephone number, business address
  • Enquiry data — the content of messages or queries submitted via our contact form
  • Technical data — IP address, browser type, pages visited, session duration (via analytics cookies, subject to your consent)
  • Preference data — cookie consent settings stored locally on your device

We do not knowingly collect sensitive personal data (such as financial account numbers, identity card numbers, or health information) unless specifically required by an engagement, in which case a separate data handling agreement will be provided.

2. How We Collect Data

  • Contact form — when you submit an enquiry through our website
  • Email and telephone — when you contact us directly
  • Cookies and analytics — when you browse our website (see Section 6)
  • Engagement correspondence — during the course of advisory work

3. Legal Basis for Processing

Under the PDPA, we process personal data on the following bases:

  • Consent — where you have provided express consent, such as when submitting our enquiry form or accepting analytics cookies
  • Contract performance — where processing is necessary to perform services you have requested
  • Legitimate interest — for improving our website and service delivery, balanced against your rights
  • Legal obligation — where we are required by law to retain or disclose certain records

4. How We Use Your Data

4.1 Service Delivery

Personal data collected during enquiries and engagements is used to understand your matter, prepare advisory opinions, and communicate our findings to you or your authorised representatives.

4.2 Communication

We use contact data to respond to enquiries, schedule consultations, and send engagement-related correspondence. We do not send unsolicited marketing communications.

4.3 Website Analytics

Where you consent, we use analytics tools to understand how visitors use our site. This helps us improve content and navigation. Analytics data is aggregated and does not identify you personally.

4.4 Legal and Compliance Obligations

We may be required to retain certain records for prescribed periods under Malaysian law, including professional conduct obligations applicable to legal advisory services.

5. Data Sharing

We do not sell, rent, or trade personal data. We may share data in limited circumstances:

  • Service providers — third-party platforms that support our operations (website hosting, email delivery, analytics), each bound by data processing agreements
  • Regulatory or legal disclosure — where required by law, court order, or competent authority
  • Professional referrals — with your express consent, where your matter requires specialist input from another professional

We do not transfer personal data outside Malaysia except where appropriate safeguards are in place consistent with Section 129 of the PDPA or applicable exemptions.

6. Cookies

Our website uses cookies to support basic functionality and, with your consent, to collect analytics data. The main categories are:

  • Essential cookies — required for the site to work; cannot be disabled
  • Analytics cookies — help us understand site usage patterns (optional)
  • Preference cookies — remember your consent settings (optional)
  • Marketing cookies — not currently in active use on this site (optional)

You can review and update your cookie preferences at any time on our Cookie Policy page.

7. Data Retention

We retain personal data only for as long as reasonably necessary:

  • Enquiry records — up to 12 months if no engagement follows
  • Engagement records — minimum 7 years in line with professional record-keeping standards and Malaysian statutory requirements
  • Analytics data — up to 26 months (aggregated)
  • Cookie consent records — stored locally on your device; cleared when you reset preferences

8. Your Rights

Under the PDPA and applicable data protection principles, you have the right to:

  • Access — request a copy of personal data we hold about you
  • Correction — request correction of inaccurate or incomplete data
  • Withdrawal of consent — withdraw consent at any time without affecting the lawfulness of prior processing
  • Restriction — request that we limit how we use your data in certain circumstances
  • Erasure — request deletion of data where we no longer have a legal basis to retain it
  • Complaint — lodge a complaint with the Personal Data Protection Commissioner of Malaysia if you believe your rights have been infringed

To exercise any of these rights, contact us at [email protected]. We will respond within 21 days.

9. Data Security

We implement reasonable technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. These include:

  • TLS encryption for data transmitted via our website
  • Access controls restricting data to authorised personnel
  • Regular review of data handling practices
  • Secure disposal of records no longer required

No method of electronic transmission or storage is completely secure. In the event of a data breach that is likely to affect your rights, we will notify you and the relevant authority as required by law.

10. Third-Party Links

Our website may contain links to external sites operated by third parties, including government portals and professional bodies. We are not responsible for the privacy practices of those sites and encourage you to review their respective policies.

11. Children's Privacy

Our services are directed to business professionals and organisations. We do not knowingly collect personal data from individuals under 18 years of age. If you believe a minor has submitted data to us, please contact us promptly so we may take appropriate steps.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. The revised version will be published on this page with an updated date. Continued use of our website after any changes constitutes acceptance of the revised policy.

13. Contact

If you have questions, concerns, or requests relating to this Privacy Policy or our handling of your personal data, please contact:

Gemilang Trade — Data Privacy

[email protected]

Level 8, KLIA Office Tower, KL International Airport, 64000 Sepang, Selangor, Malaysia

+60 3-8778 3641