PRIVACY NOTICE

Effective Date: 16 July 2026

This Privacy Notice explains how MyKongsi collects, uses, discloses, stores and protects personal data when you:

  • visit or interact with mykongsi.com and any related MyKongsi webpage, portal or online form (collectively, the "Site");
  • communicate with MyKongsi through email, telephone, WhatsApp or its public social-media channels;
  • make an enquiry, book a consultation or begin onboarding; or
  • order, receive or interact with services offered or arranged through MyKongsi.

This Notice is issued under Malaysia's Personal Data Protection Act 2010, as amended ("PDPA"). It should be read together with the Terms of Use, Customer DD Policy, Refund & Termination Policy, cookie settings and any privacy notice issued by an identified Contracting Entity or Service Provider.

In this Notice, "you" means the individual whose personal data is processed, whether as a website visitor, Customer, director, shareholder, beneficial owner, authorised representative, payor or other connected person.

1. WHO CONTROLS YOUR PERSONAL DATA

MyKongsi Sdn. Bhd. (Company No. 202101039178 / 1439478-A) is the data controller for personal data collected through the Site, MyKongsi's public social-media channels and its customer-facing enquiry, booking and onboarding communications.

The legal entity contracting with the Customer ("Contracting Entity"), an appointed company secretary or another Service Provider may separately control personal data processed for its own contractual, statutory, professional or compliance purposes. The relevant entity and its role will be identified in the applicable quotation, order confirmation, engagement document or separate privacy notice. Where another entity acts as an independent data controller, its own privacy notice and processing practices will also apply.

Where another entity processes personal data solely on MyKongsi's instructions, it acts as a data processor. MyKongsi may use data processors to operate or support the Site, booking facilities, digital forms, eKYC, electronic signing, payments, hosting, analytics, security and communications.

Operators of third-party websites and platforms, including Facebook, Instagram, LinkedIn, WhatsApp and Google, independently control personal data processed through their platforms under their own privacy terms.

2. WHO AND WHAT THIS NOTICE COVERS

This Notice covers personal data relating to:

  • visitors to and users of the Site;
  • persons who interact with MyKongsi's advertisements, social-media pages or online content;
  • enquirers, Customers and account users;
  • directors, shareholders, beneficial owners, authorised persons and payors;
  • representatives and persons whose data is supplied by another person; and
  • persons using booking, eKYC, digital-signing, payment and support channels.

This Notice applies to information about identifiable individuals. Information relating solely to a company or other entity is not personal data unless it also identifies or relates to an individual.

If you provide another person's personal data, you must be authorised to do so and, where required, ensure that the person is informed of this Notice.

3. PERSONAL DATA WE COLLECT

Category Examples
Identity and contact Name, NRIC or passport details, date of birth, nationality, photograph, signature, address, email address and mobile number
Corporate and ownership Companies, appointments, shareholdings, beneficial ownership, authority, statutory records and resolutions
CDD/KYC and risk Identity and address evidence, occupation, business activity, source of funds or wealth, PEP, sanctions, adverse-media, fraud and verification results, and compliance or risk classifications
Financial and transaction Payor, bank or refund details, invoices, payments, government fees and transaction history
Service and communications Forms, instructions, correspondence, call or meeting notes, digital signatures, support requests and complaints
Technical and analytics IP address, device and browser data, account and security logs, cookie identifiers, Google Analytics, referring pages and interactions with the Site
Marketing Channel preferences, consent and opt-out records

We may also process sensitive personal data where relevant, including biometric data used for identity verification and information concerning health, political opinions, religious beliefs, alleged offences or other matters classified as sensitive under the PDPA. Such data will be processed only with the consent or other authority and safeguards where required by law.

Information entered into a form may be recorded when the form is submitted or otherwise transmitted to MyKongsi. This includes information submitted through an upload, eKYC, electronic-signing, booking, payment or support facility.

4. HOW WE COLLECT DATA

We collect personal data:

  • directly from you through enquiries, consultations, website and onboarding forms, uploads, eKYC, digital signing and payments;
  • from an authorised representative or onboarding staff entering information supplied by you;
  • from co-founders, directors, shareholders, beneficial owners, payors and Service Providers;
  • from SSM, government or public records, professional advisers, screening providers, verification databases and other lawful sources;
  • automatically through website logs, cookies and Google Analytics; and
  • from advertising, social-media and communications platforms when you interact with MyKongsi through those platforms.

MyKongsi may rely on personal data supplied by you, an authorised representative or another connected person. You should promptly notify MyKongsi if any supplied information is inaccurate, incomplete or no longer current.

5. PURPOSE OF PROCESSING AND CONSEQUENCES

MyKongsi may process personal data for the following purposes:

  • esponding to enquiries and arranging consultations;
  • creating and managing accounts, onboarding records and Customer relationships;
  • providing or arranging incorporation, company-secretarial, registered-office and related services;
  • performing contracts and taking requested steps before entering into a contract;
  • conducting CDD/KYC, beneficial ownership, sanctions/TFS, PEP, fraud, identity-verification and risk checks;
  • processing payments, invoices, refunds, credits and debt recovery;
  • preparing documents, making statutory filings and carrying out legal, regulatory or professional duties;
  • verifying instructions, authority, identity and account security;
  • operating, securing, maintaining and improving the Site and services;
  • conducting audits, quality assurance, aggregated analytics, complaint handling and dispute management;
  • protecting and enforcing MyKongsi's, the Contracting Entity's, a Service Provider's or another person's legal rights;
  • complying with record-keeping, reporting and other legal or regulatory requirements;
  • facilitating a lawful restructuring, financing, sale or transfer of a business; and
  • sending optional marketing where consent has been given or the communication is otherwise permitted by law.

Personal data will be processed with consent or where the processing is otherwise permitted by the PDPA, including where necessary for a contract, requested pre-contract steps, legal obligations, administration of justice or the exercise of legal functions.

Where information is marked as mandatory, it is required to assess or provide the requested service, verify identity or authority, or satisfy legal, regulatory or professional obligations. If mandatory information is not supplied, MyKongsi, the Contracting Entity or the relevant Service Provider may be unable to proceed and may delay, refuse, suspend or terminate the relevant service.

Information not marked as mandatory is generally voluntary. However, choosing not to provide it may limit certain features, communications or optional services.

6. DISCLOSURES

Personal data may be disclosed to:

  • the Contracting Entity, appointed company secretary and other identified Service Providers or related service entities;
  • SSM, BNM, LHDN, courts, law enforcement agencies, regulators and competent authorities;
  • banks, payment providers, eKYC, digital-signature and booking providers, and IT, hosting, security, analytics and communications providers;
  • lawyers, accountants, auditors, tax agents, insurers, debt-recovery providers and professional advisers;
  • advertising and social-media platforms where you have permitted the relevant cookies, integrations or marketing activity;
  • counterparties, advisers and prospective acquirers involved in a lawful restructuring, financing or business transfer; and
  • other persons authorised by you or permitted or required by law.

A recipient may process personal data as MyKongsi's data processor or as an independent data controller, depending on its role. An independent data controller is responsible for its own processing and may provide a separate privacy notice.

MyKongsi may disclose information without prior notice where disclosure is required or permitted by law, or where notice could prejudice an investigation, regulatory report, fraud-prevention measure or legal right, or amount to unlawful tipping-off.

7. COOKIES, ANALYTICS, SOCIAL MEDIA AND EXTERNAL LINKS

The Site uses essential cookies needed for security, navigation and core functionality. Subject to your cookie preferences, it may also use Google Analytics and other non-essential analytics or advertising technologies.

Where consent is required, non-essential cookies will be activated only after your preferences have been recorded. You can accept, reject or adjust non-essential cookies through the "Cookie Settings" facility on the Site. You may change your preferences at any time, although this will not remove information already lawfully collected.

Information about the categories of cookies used, their purposes and, where available, their duration and providers is available through the Cookie Settings facility.

Interactions through Facebook, Instagram, LinkedIn, WhatsApp and other third-party platforms may also be processed by those platform operators under their own privacy terms. Those operators independently control their processing, and MyKongsi is not responsible for their privacy practices.

The Site may contain links, embedded content or booking, payment and verification facilities operated by third parties. MyKongsi is not responsible for a third party's independent website, security or privacy practices. You should review the applicable third-party privacy terms before submitting personal data.

Do not send sensitive identity or CDD documents through public social-media messaging unless specifically directed to an approved secure channel.

8. DIRECT MARKETING

Marketing by email, WhatsApp or SMS is optional.

Where the Site offers a marketing option, it will be presented as an unticked and optional choice. Refusing marketing does not affect your ability to submit an enquiry, begin onboarding or receive a service.

You may opt out at any time using the unsubscribe or opt-out mechanism provided in the message or by contacting privacy@mykongsi.com.

Withdrawing from marketing does not prevent MyKongsi or a Service Provider from sending service, payment, security, compliance or statutory communications. Withdrawal does not affect marketing communications already sent or other processing lawfully carried out before the withdrawal was received.

9. CROSS-BORDER PROCESSING

Some booking, analytics, cloud, communications, verification, payment, social-media or support providers may process or store personal data outside Malaysia.

The types of recipients and purposes of these transfers are described in Clauses 5 and 6 of this Notice. The countries involved may have personal-data protection laws that differ from those of Malaysia.

Transfers will be made only where permitted under the PDPA, including where:

  • the destination has a law substantially similar to the PDPA or provides an adequate level of protection;
  • you have consented to the transfer after receiving the required information;
  • the transfer is necessary for a contract, requested service, legal proceeding or other condition permitted by the PDPA; or
  • another applicable statutory condition is satisfied.

MyKongsi will apply reasonable contractual, organisational and technical safeguards appropriate to the nature of the data and the risks of the transfer.

10. SECURITY AND PROCESSORS

MyKongsi uses reasonable administrative, physical and technical safeguards appropriate to the nature of the personal data and risk. These may include access controls, authentication, secure transfer and storage, logging, backups, staff confidentiality and provider controls.

Data processors processing personal data on MyKongsi's behalf are required to comply with the Security Principle under the PDPA and applicable contractual and security requirements.

No method of electronic transmission or storage is completely secure. You are responsible for protecting your account credentials, devices and communication channels and for promptly notifying MyKongsi of any suspected unauthorised access or disclosure.

You should use only the secure upload, eKYC or digital-signing channel identified by MyKongsi for identity, ownership, financial or CDD documents.

11. RETENTION

Personal data will be retained only for as long as necessary for the stated purposes and the applicable statutory, AML/CFT/CPF, company-secretarial, accounting, tax, professional, limitation, dispute and enforcement requirements.

Retention periods may differ according to the type of data, the applicable legal or professional requirements, the duration of the Customer relationship, and whether the data is required for an investigation, dispute or legal claim.

Data will then be securely deleted, destroyed or anonymised unless lawful retention continues. Residual copies may remain temporarily in secured backup systems until they are overwritten or deleted through the ordinary backup cycle. Information that has been irreversibly anonymised may be retained because it no longer identifies an individual.

12. DATA BREACHES AND DPO

MyKongsi maintains an incident-response and escalation process. The Personal Data Protection Commissioner and affected data subjects will be notified where required by the PDPA.

Each independent data controller is responsible for assessing and notifying a breach involving processing under its control. Service Providers and data processors may be required to notify MyKongsi of relevant incidents and assist with the investigation and response.

Where the applicable statutory conditions are met, MyKongsi will appoint a Data Protection Officer and notify the Commissioner of the appointment. Appointment of a Data Protection Officer does not remove MyKongsi's or a data processor's obligations under the PDPA. Privacy and DPO-related enquiries may be directed to privacy@mykongsi.com.

13. YOUR RIGHTS

Subject to the PDPA and any applicable exceptions, you may:

  • request access to and correction of personal data;
  • withdraw consent where processing depends on consent;
  • object to direct marketing;
  • request prevention of processing likely to cause unwarranted damage or distress;
  • request data portability where applicable, technically feasible and compatible with the receiving data controller's system; and
  • make a complaint to MyKongsi or the Personal Data Protection Commissioner.

Withdrawing consent does not affect processing already carried out and does not prevent continued processing or retention where permitted or required by law. Withdrawal may affect MyKongsi's or a Service Provider's ability to provide the relevant service.

MyKongsi may require information to verify your identity and authority before acting on a request. A request may be refused, limited or subject to a prescribed fee where permitted by law.

14. CONTACT AND IDENTITY VERIFICATION

Data controller for the Site and MyKongsi's customer-facing channels:

MyKongsi Sdn. Bhd. (Company No. 202101039178 / 1439478-A)

Identity and authority may be verified before a request is fulfilled. MyKongsi may request identification, supporting documents or written authority and may communicate directly with the data subject where another person submits the request.

Complaints may also be submitted to the Personal Data Protection Commissioner through the official channels published at www.pdp.gov.my

15. LANGUAGE, AVAILABILITY AND UPDATES

This Notice is available on the Site in both Bahasa Malaysia and English and is reasonably accessible through the Site footer, relevant online forms and onboarding channels.

MyKongsi may update this Notice from time to time. The updated version will take effect on the effective date stated at the top of the Notice. The date shown at the top indicates when the Notice was last revised.

Material changes will be communicated through the Site, email or another reasonable channel where required. Where MyKongsi proposes to use or disclose personal data for a materially different purpose, it will provide any further notice or choice required by the PDPA before doing so.