Privacy Policy
Last Updated: 12 May 2025 | Effective Date: 12 May 2025
Cofferly ("we", "us", "our") is committed to protecting the personal information of everyone who interacts with our services and website. This policy explains what data we collect, why we collect it, how we use and protect it, and what rights you have under Malaysian law — specifically the Personal Data Protection Act 2010 (PDPA).
This policy applies to data collected through our website at cofferly.sbs, our contact forms, programme enrolments, and community spaces. If you have any questions, you can reach us at [email protected].
1. What Personal Data We Collect
We collect only the information necessary to provide our education services and respond to enquiries. This may include:
- Contact details: name, email address, phone number (when provided)
- Enrolment information: programme selected, payment details (processed by a third-party provider)
- Usage data: pages visited, browser type, approximate location (via analytics tools)
- Community contributions: posts or reflections shared in our community board (subject to moderation)
Legal basis for processing: consent (for marketing communications and non-essential cookies); contractual necessity (for programme delivery); legitimate interest (for website security and analytics).
Retention period: Contact enquiry data is retained for up to 24 months. Enrolment records are retained for 7 years for accounting purposes. Analytics data is retained for up to 26 months.
2. How We Use Your Data
- Responding to enquiries and booking programme places
- Delivering our workshop, toolkit, and programme services
- Sending confirmation emails and programme-related communications
- Improving our website and content based on anonymised analytics
- Sending occasional updates about new programme dates (only if you have consented)
- Complying with our legal obligations under Malaysian law
We do not sell your personal data to any third party. We do not use your data to build advertising profiles or share it with financial services providers.
3. Data Sharing
We share personal data only in the following limited circumstances:
- Payment processors: to handle programme fees securely (they operate under their own privacy policies)
- Analytics providers: anonymised usage data may be processed by tools such as Google Analytics
- Legal requirements: if required to do so by law or a competent authority in Malaysia
4. Data Protection Measures
- Website served over HTTPS (TLS encryption in transit)
- Access to personal data restricted to staff with a legitimate need
- Passwords and sensitive credentials stored using industry-standard hashing
- In the event of a data breach, affected individuals will be notified as soon as practicable and in accordance with PDPA obligations
5. Cookies
We use cookies for essential site functionality, analytics, and preference storage. You can manage your cookie preferences at any time via our Cookie Policy page. Non-essential cookies are only used with your consent.
6. Your Rights Under PDPA 2010
Under Malaysia's Personal Data Protection Act 2010, you have the following rights:
- Right to access: request a copy of the personal data we hold about you
- Right to correction: request that inaccurate data be corrected or updated
- Right to withdraw consent: withdraw consent for marketing communications at any time
- Right to limit processing: request that we stop using your data for certain purposes
- Right to raise a complaint: you may contact the Department of Personal Data Protection Malaysia (JPDP) if you believe your rights have been infringed
To exercise any of these rights, write to us at [email protected]. We will respond within 21 calendar days.
7. Third-Party Links
Our website may contain links to external sites. We are not responsible for the privacy practices of those sites and encourage you to review their policies separately.
8. Children's Privacy
Our programmes are intended for adults aged 18 and above. We do not knowingly collect personal data from individuals under 18. If you believe a minor has submitted data to us, please contact us and we will remove it promptly.
9. Changes to This Policy
We may update this policy from time to time. When we do, we will update the "Last Updated" date at the top. For material changes, we will notify programme participants by email. Continued use of our services after any update constitutes acceptance of the revised policy.
10. Contact Us
Data Controller: Cofferly
No. 9, Jalan Hang Jebat, 75200 Melaka, Malaysia
Privacy enquiries: [email protected]
Phone: +60 13-447 6820