Legal
Privacy Policy
Last updated: 15 April 2025 ยท Effective: 15 April 2025
1. Introduction
Kortessa ("we", "us", "our") is committed to handling personal information with care and in accordance with applicable Malaysian data protection law, including the Personal Data Protection Act 2010 (PDPA). This Privacy Policy explains how we collect, use, store, and protect personal data when you interact with our website or engage our interior design services.
If you have any questions about this policy or how we handle your data, please contact us at [email protected].
2. Data We Collect
We may collect the following categories of personal data:
- Name and contact details (email address, phone number) provided through our enquiry form
- Address or location details relating to a unit you wish to discuss with us
- Message content you submit through our contact form
- Technical data collected automatically when you visit our website (IP address, browser type, pages viewed, via cookies or analytics tools)
We do not collect sensitive personal data (such as financial account details, identification numbers, or health-related information) through our website.
3. How We Collect Data
- Directly from you when you complete our contact or enquiry form
- Through cookies and analytics tools when you browse our website
- Through email or telephone communication when you contact us directly
4. Legal Basis for Processing
Under the PDPA and applicable data protection principles, we process your personal data on the following bases:
- Consent: Where you have submitted a form or communicated with us, you have provided consent for us to process your data in connection with your enquiry.
- Legitimate interest: We may process certain data to operate and improve our website and communications.
- Contractual necessity: When you engage our services, processing your data is necessary to deliver those services.
5. How We Use Your Data
- To respond to enquiries and provide information about our services
- To deliver the interior design services you have engaged us for
- To communicate service-related information during an engagement
- To comply with legal obligations
- To improve our website based on anonymised usage data
We do not use your personal data for automated decision-making or profiling. We do not sell your data to third parties.
6. Data Sharing
We may share your data in limited circumstances:
- With suppliers or contractors who assist in delivering a service you have engaged, only to the extent necessary and subject to confidentiality obligations
- With analytics service providers (such as Google Analytics) in anonymised or aggregated form
- Where required by Malaysian law or by order of a competent authority
We do not share personal information about you or your unit with third parties for marketing purposes.
7. Data Retention
We retain personal data for as long as necessary to fulfil the purposes for which it was collected:
- Enquiry data not resulting in an engagement: up to 12 months
- Client data relating to a completed engagement: up to 5 years for legal and record-keeping purposes
- Website analytics data: as configured in the relevant analytics tool, typically 14โ26 months
8. Data Protection Measures
We take reasonable steps to protect personal data from unauthorised access, loss, or misuse. These include:
- Secure access controls on systems containing personal data
- Use of HTTPS for data transmission on our website
- Limiting access to personal data to staff who need it to carry out their duties
- Procedures for responding to suspected data breaches in accordance with PDPA requirements
9. Cookies
Our website uses cookies to support basic functionality and, where you consent, for analytics purposes. For full details of the cookies we use and how to manage your preferences, please see our Cookie Policy.
10. Your Rights
Under the Malaysian PDPA, you have the following rights in relation to personal data we hold about you:
- The right to access personal data we hold about you
- The right to correct inaccurate or incomplete data
- The right to withdraw consent to processing at any time (where processing is based on consent)
- The right to request that we cease processing your data for direct marketing purposes
- The right to enquire about the types of data held and the purposes for which it is processed
To exercise any of these rights, please contact us at [email protected]. We will respond within a reasonable timeframe and in accordance with applicable law.
11. Third-Party Links
Our website may contain links to third-party websites (such as listing platforms or supplier sites). We are not responsible for the privacy practices of those sites and encourage you to read their own privacy policies.
12. Children's Privacy
Our services are directed at adults aged 18 and over. We do not knowingly collect personal data from persons under 18. If you believe we have inadvertently collected such data, please contact us and we will delete it promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated effective date. Continued use of our website or services after changes are posted constitutes acceptance of the revised policy.
14. Contact
For any questions about this policy or to exercise your rights:
- Email: [email protected]
- Address: Jalan Tunku Abdul Rahman, Chow Kit, 50100 Kuala Lumpur, Malaysia