Legal
Privacy Policy
Last Updated: 22 April 2025 · Effective: 22 April 2025
1. Introduction
Cermat ("we", "us", "our") is committed to protecting the personal data of individuals who interact with us through our website and attendance at our programmes. This Privacy Policy explains what data we collect, how we use it, and the rights available to you under Malaysian law.
Cermat is registered and operating in Malaysia. Our programmes are financial education and information services — we do not provide regulated financial advice. This policy applies to all personal data processed through our website at cermati.biz and through our programme enrolment and enquiry processes.
For questions about this policy, contact us at [email protected].
2. Data We Collect
We collect only the personal data necessary to respond to enquiries and manage programme enrolments. This includes:
- Name and email address — provided when submitting our contact form or enquiring about a programme. Required for responding to your enquiry.
- Phone number — provided optionally when submitting a contact form. Used only to follow up on your enquiry if you prefer telephone contact.
- Message content — any information you choose to include in your enquiry message.
- Cookie and analytics data — technical data collected automatically when you visit our website (see Section 5).
Important: Cermat does not collect, store, or process any personal financial information from participants. Our programmes work with general category patterns — not individual financial data. No participant is asked to disclose specific financial figures.
Legal Basis for Processing
- Contact form data — processed on the basis of your consent (submitting the form)
- Programme enrolment data — processed for the performance of a contract or pre-contractual steps
- Analytics data — processed on the basis of your consent via our cookie notice
Data Retention
Enquiry data is retained for up to 12 months after the enquiry is resolved, unless an enrolment contract results — in which case data is retained for 3 years from the end of the programme. Analytics data is retained for 26 months. You may request earlier deletion at any time.
3. How We Use Your Data
- Responding to your enquiries about our programmes
- Managing programme enrolments and sending session details
- Sending confirmation and administrative communications related to your programme
- Improving our website and understanding how visitors use it (analytics, with consent)
- Complying with applicable legal and regulatory requirements
Marketing Communications
We do not send marketing emails without your explicit consent. If you have given consent and wish to withdraw it, email [email protected] at any time.
Third-Party Sharing
We do not sell personal data. Data may be shared with service providers who assist our operations (such as email and web hosting), under contractual terms that require them to protect your data. We do not share data with advertisers or unrelated third parties.
4. Data Protection Measures
- HTTPS encryption for all data transmitted through our website
- Access to personal data is limited to staff with a direct operational need
- Data stored on secured, access-controlled servers
- Regular reviews of our data handling practices
- In the event of a data breach involving your personal data, we will notify you and relevant authorities as required under Malaysian law within a reasonable timeframe
5. Cookies
Our website uses cookies to support its operation and, with your consent, to understand how visitors use the site. Essential cookies are necessary for the website to function and cannot be disabled. Optional analytics and preference cookies are only set with your consent.
For full details of the cookies we use and how to manage your preferences, see our Cookie Policy.
6. Your Rights
Under Malaysia's Personal Data Protection Act 2010 (PDPA), you have the following rights regarding your personal data:
- Right of access — request a copy of the personal data we hold about you
- Right to correction — request that inaccurate or incomplete data be corrected
- Right to withdraw consent — withdraw consent for processing at any time (this will not affect lawfulness of processing before withdrawal)
- Right to prevent processing — request that we stop processing your data for direct marketing or other purposes
To exercise any of these rights, contact us at [email protected]. We will respond within 21 days. If you are dissatisfied with our response, you may lodge a complaint with Malaysia's Department of Personal Data Protection (JPDP).
7. Third-Party Links
Our website may contain links to third-party sites. We are not responsible for the privacy practices of those sites and recommend reviewing their privacy policies before providing any personal data to them.
8. Children's Privacy
Cermat's programmes are designed for adults aged 18 and above. We do not knowingly collect personal data from individuals under 18. If we become aware that personal data from a minor has been submitted, we will delete it promptly.
9. Policy Updates
We may update this policy from time to time. When material changes are made, we will update the "Last Updated" date at the top of this page. Continued use of our website following an update constitutes acceptance of the revised policy.
10. Contact Us
For data protection enquiries, corrections, or to exercise your rights under the PDPA:
Level 10, Menara Southpoint, Mid Valley City, 59200 Kuala Lumpur, Malaysia