Tessera Contact Us

Legal

Privacy Policy

This policy describes how Tessera collects, uses, and protects personal data provided through our website and in the course of our advisory engagements. It is governed by the Personal Data Protection Act 2010 (PDPA) of Malaysia.

Last updated: 14 April 2025

1. Introduction and Data Controller

Tessera ("we", "our", or "the practice") is the data controller responsible for personal data collected through this website (tesseraas.world) and in connection with our advisory services. Our registered place of business is Jalan Sultan Ismail 25, 50250 Kuala Lumpur, Malaysia.

Questions about data handling may be directed to [email protected]. We aim to respond to all enquiries within ten working days.

2. Data We Collect

We collect personal data only where it is necessary for a specific purpose. The categories of data we may collect include:

Contact and enquiry data

Name, email address, phone number, and the content of messages submitted through our contact form. Collected when you initiate contact with us.

Engagement data

Information provided during the course of an advisory engagement, including documents, notes, and records created as part of project delivery. This data is handled under a separate confidentiality agreement.

Website usage data

Technical data collected automatically when you visit our website, including IP address, browser type, pages visited, and approximate geographic location. Collected via analytics tools and server logs.

Cookie data

Data stored in browser cookies to remember consent preferences and enable basic website functionality. See our Cookie Policy for detail.

Legal basis for processing

We process personal data on one or more of the following lawful bases under the PDPA 2010:

  • Consent — where you have provided explicit consent (e.g. cookie acceptance, contact form submission)
  • Contract performance — where processing is necessary to deliver an agreed service
  • Legitimate interests — for website analytics and service improvement, where those interests are not overridden by your rights
  • Legal obligation — where we are required to retain records by law

3. How We Use Your Data

Data collected is used only for the purposes for which it was collected or for compatible purposes clearly stated at the time of collection. Specific uses include:

  • Responding to enquiries and assessing whether an engagement is a suitable fit
  • Delivering advisory services as agreed in a written project brief
  • Issuing invoices and maintaining financial records as required by Malaysian law
  • Improving our website and understanding how visitors use it
  • Communicating service updates where you have consented to receive them

We do not sell, rent, or share personal data with third parties for marketing purposes. Data is not used for automated decision-making that produces legal or similarly significant effects.

Data Retention

Contact and enquiry data is retained for up to 24 months from last contact. Engagement records are retained for seven years from the close of the engagement to comply with legal and professional record-keeping requirements. Website analytics data is retained in aggregated, anonymised form only.

4. Data Sharing and Third Parties

We limit sharing of personal data to what is strictly necessary. Third parties that may receive data include:

Service providers

Web hosting, email delivery, and analytics providers acting as data processors under our instruction. These providers are contractually bound to process data only as directed and to maintain appropriate security standards.

Professional advisors

Accountants or legal advisors where disclosure is necessary for a specific, legitimate purpose and is made under appropriate confidentiality obligations.

Legal requirements

Regulatory authorities or law enforcement where we are legally required to disclose information.

Where data is transferred outside Malaysia, we take steps to ensure an adequate level of protection is in place, consistent with the requirements of the PDPA 2010.

5. Data Protection Measures

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:

  • Encrypted data transmission (TLS) for all website communications
  • Access controls limiting data access to staff with a direct operational need
  • Engagement documents stored in access-controlled environments with version history
  • Regular review of data handling practices and third-party processor agreements

In the event of a personal data breach that is likely to result in a risk to your rights, we will notify affected individuals and, where required, the relevant supervisory authority, as soon as reasonably practicable.

6. Cookies

This website uses cookies for core functionality and to understand visitor behaviour. Cookie categories used include essential session cookies (required for the website to function), and optional analytics cookies (used to understand page visits in aggregate).

You can manage or withdraw cookie consent at any time using the preferences control on our website. For full details, see our Cookie Policy.

7. Your Rights

Under the Personal Data Protection Act 2010 (Malaysia), you have the following rights in relation to personal data we hold about you:

Right of access

Request a copy of personal data we hold about you.

Right of correction

Request correction of inaccurate or incomplete data.

Right to withdraw consent

Withdraw consent to processing at any time where consent is the lawful basis.

Right to limit processing

Request that we cease or limit processing of your data in specific circumstances.

Right to prevent direct marketing

Opt out of any direct marketing communications at any time.

Right to lodge a complaint

Raise a concern with the Department of Personal Data Protection Malaysia (JPDP).

To exercise any of these rights, write to us at [email protected]. We will respond within 21 days. Identity verification may be required before we can fulfil a request.

Our website may contain links to external websites. We are not responsible for the privacy practices of those sites and encourage you to review their privacy policies independently. The presence of a link does not constitute endorsement.

9. Children's Privacy

Our services are directed at business professionals and are not intended for individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected such data, please contact us at [email protected] so that we can take appropriate steps.

10. Policy Updates

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. Material changes will be noted with a revised "Last Updated" date at the top of this page. We recommend reviewing this page periodically. Continued use of our website following any update constitutes acceptance of the revised policy.

11. Contact for Data Enquiries

For questions, requests, or concerns relating to this Privacy Policy or the handling of your personal data, please contact us using the details below.

Data enquiries email

[email protected]

Registered address

Tessera
Jalan Sultan Ismail 25
50250 Kuala Lumpur, Malaysia

Supervisory authority

Department of Personal Data Protection Malaysia (JPDP)
www.pdp.gov.my