Cahaya

Legal & Transparency

Privacy Policy

At Cahaya, we handle personal information with the same care and discretion we bring to every legal matter. This policy explains what we collect, why we collect it, and how it is protected.

Last updated: 15 April 2025  ·  Effective: 15 April 2025

1. Introduction

Cahaya ("we", "us", or "our") is a legal services practice operating from George Town, Penang, Malaysia. We are committed to handling your personal information responsibly and in accordance with Malaysia's Personal Data Protection Act 2010 (PDPA).

This Privacy Policy describes the nature of information we may collect when you visit our website at cahaya.world, submit an enquiry, or engage our services. By using our website or contacting us, you acknowledge the practices described here.

If you have questions about this policy or how your data is handled, please contact us at [email protected].


2. Data We Collect

We may collect the following categories of personal information:

Information you provide directly

  • Full name, when provided via our contact form or in correspondence
  • Email address, for responding to your enquiry
  • Phone number, if provided to facilitate a call-back
  • Details shared in your message, relating to your legal matter

Information collected automatically

  • Browser type, operating system, and device type
  • Pages visited, time spent, and navigation patterns
  • Referring website or search query that brought you here
  • IP address (stored for security and analytics purposes)
  • Cookie data, as described in Section 5

Legal basis for processing

  • Consent — when you submit our contact form or accept cookies
  • Legitimate interest — to improve our website and respond to general enquiries
  • Contractual necessity — when you engage our legal services
  • Legal obligation — where required by Malaysian law

Data retention: Contact form submissions are retained for up to 3 years. Analytics data is retained for up to 26 months. Correspondence related to engaged services is retained for 7 years in accordance with Malaysian legal requirements.


3. How We Use Your Data

Personal information collected is used for the following purposes:

  • Responding to enquiries you have submitted through our contact form
  • Delivering legal services you have engaged us to provide
  • Communicating relevant updates about your matter where applicable
  • Improving our website through aggregated, anonymised analytics data
  • Complying with legal, regulatory, and professional obligations applicable to legal practitioners in Malaysia

We do not use your personal information for unsolicited marketing. If you receive any communication from us, it is directly related to an enquiry you initiated or a service we are providing to you.

Data sharing

We do not sell, rent, or trade your personal data. We may share information with trusted service providers who assist in operating our website (for example, web hosting or analytics providers), under strict confidentiality obligations. In limited circumstances, we may disclose information where required by law, court order, or professional regulatory obligations.


4. How We Protect Your Data

We take reasonable and appropriate technical and organisational measures to protect personal information against unauthorised access, alteration, disclosure, or destruction.

  • Data is transmitted using SSL/TLS encryption where applicable
  • Access to personal data is restricted to authorised personnel only
  • We maintain internal policies governing how client information is stored and accessed
  • Our service providers are selected with data security in mind and bound by confidentiality agreements
  • In the event of a data breach affecting your personal information, we will notify you as required under the PDPA

No transmission over the internet can be considered completely secure. While we take every reasonable precaution, we cannot provide an absolute assurance regarding online data security.


5. Cookies

We use cookies and similar technologies to support website functionality, understand how visitors use our site, and remember your preferences. You can control cookie usage at any time through your browser settings or via our Cookie Policy page, which includes detailed information and preference controls.

We use three broad categories of cookies: essential (required for the site to function), analytics (to understand site usage), and preference (to remember settings). Marketing cookies may also be present where applicable. Disabling optional cookies will not prevent you from using the core features of this website.


6. Your Rights

Under Malaysia's Personal Data Protection Act 2010, you have certain rights regarding the personal information we hold about you. These include:

Right to Access

You may request a copy of the personal information we hold about you.

Right to Rectification

You may request corrections to inaccurate or incomplete information.

Right to Erasure

You may ask us to delete data we no longer have a lawful reason to hold.

Right to Object

You may object to processing of your data for specific purposes.

Right to Withdraw Consent

Where processing relies on consent, you may withdraw it at any time.

Right to Data Portability

You may request your data in a structured, commonly used format.

To exercise any of these rights, please contact us at [email protected]. We will respond within 21 days in accordance with the PDPA. If you are unsatisfied with our response, you may lodge a complaint with Malaysia's Department of Personal Data Protection (JPDP).


7. Third-Party Links

Our website may contain links to external websites for your reference. Once you leave our site, we have no control over how those sites handle your information. We encourage you to review the privacy policies of any external websites you visit. Cahaya is not responsible for the content or privacy practices of third-party sites.


8. Children's Privacy

Our services are intended for adults aged 18 and above. We do not knowingly collect personal information from individuals under the age of 18. If we become aware that we have inadvertently collected information from a minor, we will take steps to delete it promptly. If you believe a minor has submitted information to us, please contact us at [email protected].


9. Policy Changes

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. When changes are made, we will update the "Last updated" date at the top of this page.

We encourage you to review this page periodically. Continued use of our website after any changes constitutes your acknowledgement of the revised policy. Where changes are material, we will take reasonable steps to bring them to your attention.


10. Contact Us

If you have any questions, concerns, or requests relating to this Privacy Policy or our data practices, please reach out:

Cahaya

Level 13, Menara Northam, Jalan Sultan Ahmad Shah, 10050 George Town, Penang

[email protected]

+60 4-241 7836