Legal
Privacy Policy
This policy describes how Tessera collects, uses, and protects personal data provided through our website and in the course of our advisory engagements. It is governed by the Personal Data Protection Act 2010 (PDPA) of Malaysia.
Last updated: 14 April 2025
1. Introduction and Data Controller
Tessera ("we", "our", or "the practice") is the data controller responsible for personal data collected through this website (tesseraas.world) and in connection with our advisory services. Our registered place of business is Jalan Sultan Ismail 25, 50250 Kuala Lumpur, Malaysia.
Questions about data handling may be directed to [email protected]. We aim to respond to all enquiries within ten working days.
2. Data We Collect
We collect personal data only where it is necessary for a specific purpose. The categories of data we may collect include:
Contact and enquiry data
Name, email address, phone number, and the content of messages submitted through our contact form. Collected when you initiate contact with us.
Engagement data
Information provided during the course of an advisory engagement, including documents, notes, and records created as part of project delivery. This data is handled under a separate confidentiality agreement.
Website usage data
Technical data collected automatically when you visit our website, including IP address, browser type, pages visited, and approximate geographic location. Collected via analytics tools and server logs.
Cookie data
Data stored in browser cookies to remember consent preferences and enable basic website functionality. See our Cookie Policy for detail.
Legal basis for processing
We process personal data on one or more of the following lawful bases under the PDPA 2010:
- Consent — where you have provided explicit consent (e.g. cookie acceptance, contact form submission)
- Contract performance — where processing is necessary to deliver an agreed service
- Legitimate interests — for website analytics and service improvement, where those interests are not overridden by your rights
- Legal obligation — where we are required to retain records by law
3. How We Use Your Data
Data collected is used only for the purposes for which it was collected or for compatible purposes clearly stated at the time of collection. Specific uses include:
- Responding to enquiries and assessing whether an engagement is a suitable fit
- Delivering advisory services as agreed in a written project brief
- Issuing invoices and maintaining financial records as required by Malaysian law
- Improving our website and understanding how visitors use it
- Communicating service updates where you have consented to receive them
We do not sell, rent, or share personal data with third parties for marketing purposes. Data is not used for automated decision-making that produces legal or similarly significant effects.
Data Retention
Contact and enquiry data is retained for up to 24 months from last contact. Engagement records are retained for seven years from the close of the engagement to comply with legal and professional record-keeping requirements. Website analytics data is retained in aggregated, anonymised form only.
4. Data Sharing and Third Parties
We limit sharing of personal data to what is strictly necessary. Third parties that may receive data include:
Service providers
Web hosting, email delivery, and analytics providers acting as data processors under our instruction. These providers are contractually bound to process data only as directed and to maintain appropriate security standards.
Professional advisors
Accountants or legal advisors where disclosure is necessary for a specific, legitimate purpose and is made under appropriate confidentiality obligations.
Legal requirements
Regulatory authorities or law enforcement where we are legally required to disclose information.
Where data is transferred outside Malaysia, we take steps to ensure an adequate level of protection is in place, consistent with the requirements of the PDPA 2010.
5. Data Protection Measures
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:
- Encrypted data transmission (TLS) for all website communications
- Access controls limiting data access to staff with a direct operational need
- Engagement documents stored in access-controlled environments with version history
- Regular review of data handling practices and third-party processor agreements
In the event of a personal data breach that is likely to result in a risk to your rights, we will notify affected individuals and, where required, the relevant supervisory authority, as soon as reasonably practicable.
6. Cookies
This website uses cookies for core functionality and to understand visitor behaviour. Cookie categories used include essential session cookies (required for the website to function), and optional analytics cookies (used to understand page visits in aggregate).
You can manage or withdraw cookie consent at any time using the preferences control on our website. For full details, see our Cookie Policy.
7. Your Rights
Under the Personal Data Protection Act 2010 (Malaysia), you have the following rights in relation to personal data we hold about you:
Right of access
Request a copy of personal data we hold about you.
Right of correction
Request correction of inaccurate or incomplete data.
Right to withdraw consent
Withdraw consent to processing at any time where consent is the lawful basis.
Right to limit processing
Request that we cease or limit processing of your data in specific circumstances.
Right to prevent direct marketing
Opt out of any direct marketing communications at any time.
Right to lodge a complaint
Raise a concern with the Department of Personal Data Protection Malaysia (JPDP).
To exercise any of these rights, write to us at [email protected]. We will respond within 21 days. Identity verification may be required before we can fulfil a request.
8. Third-Party Links
Our website may contain links to external websites. We are not responsible for the privacy practices of those sites and encourage you to review their privacy policies independently. The presence of a link does not constitute endorsement.
9. Children's Privacy
Our services are directed at business professionals and are not intended for individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected such data, please contact us at [email protected] so that we can take appropriate steps.
10. Policy Updates
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. Material changes will be noted with a revised "Last Updated" date at the top of this page. We recommend reviewing this page periodically. Continued use of our website following any update constitutes acceptance of the revised policy.
11. Contact for Data Enquiries
For questions, requests, or concerns relating to this Privacy Policy or the handling of your personal data, please contact us using the details below.
Data enquiries email
[email protected]Registered address
TesseraJalan Sultan Ismail 25
50250 Kuala Lumpur, Malaysia
Supervisory authority
Department of Personal Data Protection Malaysia (JPDP)
www.pdp.gov.my