Privacy Policy
Last Updated: 18 February 2025 | Crestholm, 25 Persiaran Gurney, 10250 George Town, Penang, Malaysia
1. Introduction
Crestholm ("we", "our", or "us") is committed to handling personal data with care and transparency. This Privacy Policy explains what information we collect from visitors to our website and from individuals who contact or engage our legal services, how that information is used, and what rights you have in relation to it.
This policy applies to data processed through our website at crestholm and through our client intake and engagement processes. Questions or concerns regarding this policy may be directed to [email protected].
2. Personal Data We Collect
We may collect and process the following categories of personal data:
Information you provide directly
- Name, email address, and phone number submitted via our contact form
- Details of your legal matter shared in correspondence or consultations
- Business information relevant to your IP filing or advisory needs
- Identity documents required for client due diligence
Information collected automatically
- Browser type, device type, and operating system
- Pages visited and time spent on our website
- Referring URL and approximate geographic location (country/region level)
- Cookie-based identifiers where consent has been given (see Section 5)
3. How We Use Your Data
We use personal data for the following purposes:
- Responding to enquiries submitted through our contact form or by email
- Managing client engagements, including filing and correspondence with MyIPO
- Complying with anti-money laundering and client due diligence obligations under Malaysian law
- Improving the functionality and content of our website
- Maintaining records as required by professional conduct obligations
Legal basis for processing
Under Malaysia's Personal Data Protection Act 2010 (PDPA), we process your data on the basis of your consent (for enquiries and optional cookies), performance of a contract (for client engagements), and our legitimate interests (for practice management and security). Where required by law, we process data to comply with legal obligations.
4. Data Retention
We retain personal data for as long as necessary for the purpose for which it was collected, subject to any longer periods required by law or our professional conduct obligations. Specifically:
- Enquiry data (non-clients): up to 12 months from last contact
- Client matter files: 7 years from the close of the matter, or longer if required by applicable law
- Due diligence records: as required under applicable Malaysian anti-money laundering regulations
- Website analytics data: up to 26 months (where analytics cookies are enabled)
5. Cookies and Tracking
Our website uses cookies to support basic functionality and, where you have consented, to gather anonymised analytics. Strictly necessary cookies are used without consent as they are required for the site to operate. Optional analytics and preference cookies are only set where consent has been provided via our cookie consent tool.
You can manage your cookie preferences at any time through our Cookie Policy page.
6. Data Sharing with Third Parties
We do not sell your personal data. We may share data with the following categories of third parties in the course of providing services:
- The Intellectual Property Corporation of Malaysia (MyIPO) in connection with filings and prosecutions
- Professional service providers who assist us with IT systems and document management, under confidentiality obligations
- Regulatory authorities or law enforcement where we are required by law to do so
- Correspondent agents in other jurisdictions where international IP filing is required
All third parties who receive personal data in connection with our services are required to handle it in accordance with applicable data protection obligations.
7. Data Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, or destruction. These include:
- Access controls limiting data access to authorised personnel only
- Encrypted storage and transfer of sensitive client documents
- Regular review of data handling practices and system security
- Staff training on data confidentiality obligations
No data transmission over the internet can be considered entirely without risk. Where you transmit personal data to us by email or contact form, this is done at your own risk, though we take steps to protect it once received.
8. Your Rights Under the PDPA
Under Malaysia's Personal Data Protection Act 2010, you have the following rights in relation to your personal data:
- Right of access — to request a copy of personal data we hold about you
- Right of correction — to request correction of inaccurate or incomplete data
- Right to withdraw consent — where processing is based on your consent, you may withdraw it at any time
- Right to limit processing — to request that we limit processing in certain circumstances
To exercise any of these rights, please contact us at [email protected]. We will respond within 21 days of receiving a valid request.
9. Links to External Sites
Our website may include links to external websites. We are not responsible for the privacy practices of those sites and encourage you to review their privacy policies before submitting any personal information.
10. Children's Privacy
Our services are intended for individuals aged 18 and above. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected information from a person under 18, please contact us and we will take appropriate steps to delete that data.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by updating the "Last Updated" date at the top of this page. Your continued use of our website following any update constitutes your acknowledgement of the revised policy.
12. Contact
For questions about this policy or to exercise your data rights, please contact:
Crestholm
25 Persiaran Gurney, 10250 George Town, Penang, Malaysia