Legal
Privacy Policy
1. Introduction
Fundwise ("we", "us", "our") is committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard personal data you provide to us or that we collect when you use our website, enquire about our programmes, or engage our services. We operate in accordance with Malaysia's Personal Data Protection Act 2010 (PDPA) and its subsidiary regulations.
By accessing our website or engaging with us, you acknowledge that you have read and understood this policy. If you do not agree with any part of it, you should discontinue your use of our website and services.
2. Who We Are
Fundwise is a financial education practice operating in Malaysia. Our registered business address is 23 Jalan Tuanku Abdul Rahman, 50100 Kuala Lumpur, Wilayah Persekutuan. You can contact us regarding data privacy matters at:
- Email: [email protected]
- Phone: +60 3-2698 5341
- Post: 23 Jalan Tuanku Abdul Rahman, 50100 Kuala Lumpur, Wilayah Persekutuan
3. Personal Data We Collect
We may collect the following categories of personal data, depending on how you interact with us:
- Identity data: Your name, as provided in enquiry forms or programme registration.
- Contact data: Email address and telephone number.
- Communication data: The content of messages you send us through our contact form, email, or telephone.
- Programme data: Information you share during our sessions that relates to your financial situation, goals, or circumstances. This data is collected directly by you in the course of our educational services and is handled with strict confidentiality.
- Technical data: IP address, browser type, operating system, referring URLs, and pages visited — collected automatically via server logs and, where consented, analytics cookies.
- Cookie and tracking data: As described in our Cookie Policy.
We do not knowingly collect personal data from individuals under the age of 18. If you believe a minor has submitted data to us, please contact us promptly.
4. How We Collect Personal Data
We collect personal data through the following means:
- Directly from you when you complete our contact or enquiry form.
- When you contact us by telephone or email.
- During intake conversations and programme sessions.
- Automatically when you visit our website, via server logs and cookies (subject to your consent preferences).
- From third-party analytics services, where you have consented to analytics cookies.
5. Purposes and Legal Basis for Processing
We process your personal data for the following purposes:
- Responding to enquiries: To respond to messages submitted via our contact form or by other means.
- Service delivery: To provide and manage our financial education programmes, including scheduling, communications, and follow-up.
- Business administration: Record-keeping, invoicing, and maintaining programme records.
- Website analytics: Where consented, to understand how visitors use our website so we can improve it.
- Marketing communications: Where you have separately consented, to send information about our programmes and updates. You may withdraw this consent at any time.
- Legal compliance: To comply with applicable legal obligations under Malaysian law.
Under the PDPA, we rely on your consent as the primary basis for processing your personal data. In some circumstances, we may process data where it is necessary for the performance of a contract with you, or to comply with a legal obligation.
6. Disclosure of Personal Data
We do not sell, rent, or trade your personal data to third parties. We may share data in the following limited circumstances:
- Service providers: Trusted third parties who assist us in operating our website or delivering services (for example, web hosting providers, email service providers). These parties are contractually required to handle data only as instructed by us and in accordance with applicable law.
- Legal requirements: Where we are required to disclose data by law, court order, or government authority.
- Business transfers: In the event of a merger, acquisition, or sale of our business, personal data may be transferred to the relevant successor entity, subject to equivalent data protection obligations.
Any personal data you share during programme sessions — including details about your financial circumstances — is treated as strictly confidential and is not shared with any third party without your explicit consent, except where legally required.
7. Data Retention
We retain personal data only for as long as is necessary for the purposes for which it was collected, or as required by law. Specifically:
- Enquiry and contact form data is retained for up to 24 months from the date of last contact.
- Programme records are retained for up to 7 years for business and accounting purposes.
- Website analytics data is retained in accordance with the retention settings of the relevant analytics service.
- Marketing consent records are retained until you withdraw consent, and for a reasonable period thereafter for compliance purposes.
When personal data is no longer required, it is securely deleted or anonymised.
8. Your Rights Under the PDPA
Under the Personal Data Protection Act 2010, you have the following rights in relation to your personal data:
- Right to access: You may request confirmation of whether we hold personal data about you and, if so, obtain a copy of that data.
- Right to correction: You may request correction of any personal data we hold that is inaccurate, incomplete, or out of date.
- Right to withdraw consent: Where processing is based on your consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
- Right to limit processing: In certain circumstances, you may request that we limit the purposes for which we process your data.
To exercise any of these rights, please contact us at [email protected] or by telephone at +60 3-2698 5341. We will respond within a reasonable time and in any event within the timeframes required by applicable law. We may need to verify your identity before processing your request.
9. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, alteration, or disclosure. These measures include secure server configurations, access controls, and staff awareness of data handling obligations.
However, no method of data transmission over the internet or method of electronic storage is completely secure. While we take reasonable steps to protect your data, we cannot warrant absolute security. If you have reason to believe that your data has been compromised, please contact us immediately.
10. Cookies
Our website uses cookies and similar tracking technologies. Your consent to non-essential cookies is requested when you first visit our website. For full details on the cookies we use, their purposes, and how to manage your preferences, please refer to our Cookie Policy.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational circumstances. When we make material changes, we will update the "Last updated" date at the top of this page. We encourage you to review this policy periodically. Continued use of our website or services after any update constitutes acceptance of the revised policy.
12. Contact and Complaints
If you have questions about this Privacy Policy, wish to exercise your data rights, or have a complaint about how we have handled your personal data, please contact us:
- Email: [email protected]
- Phone: +60 3-2698 5341
- Post: Fundwise, 23 Jalan Tuanku Abdul Rahman, 50100 Kuala Lumpur, Wilayah Persekutuan
If you are not satisfied with our response, you may refer your complaint to the Department of Personal Data Protection (JPDP), the relevant regulatory authority in Malaysia under the Personal Data Protection Act 2010.