Privacy Policy
Last updated: 15 April 2025
1. Introduction
Hearthroot ("we", "us", "our") is committed to handling your personal data responsibly and in accordance with the Personal Data Protection Act 2010 (PDPA) of Malaysia. This policy explains what data we collect, why we collect it, how we use it, and what rights you have in relation to it.
This policy applies to all personal data you provide to us when enquiring about or enrolling in our courses, visiting our website, or corresponding with us by phone or email. If you have any questions about this policy, please contact us at [email protected].
2. Data We Collect
We collect only the information we need to administer our courses and respond to your enquiries. This may include:
- Your name and contact details (phone number, email address)
- The course or courses you are interested in
- Your general location (town or district) for scheduling purposes
- Any information you provide voluntarily in messages or conversations
We do not collect your financial account details, identification documents, or any documents you work with during course sessions. Those documents remain in your possession at all times.
We collect this data when you submit an enquiry form on this website, send us an email, or call our office.
3. How We Use Your Data
We use your personal data for the following purposes:
- To respond to your enquiry and provide information about upcoming intakes
- To confirm enrolment and communicate course details (venue, session dates, what to bring)
- To issue receipts and maintain basic enrolment records as required
- To send follow-up communications where included as part of a course programme
We do not use your data for profiling, automated decision-making, or targeted advertising. We do not sell or share your personal data with third parties for marketing purposes.
Legal basis for processing: Your consent, given when you submit an enquiry, and the performance of the education contract where you enrol.
4. Data Retention
We retain basic enrolment records (name, contact details, course attended, date) for up to five years for administrative purposes. Enquiry messages from people who do not ultimately enrol are deleted within twelve months. You may request earlier deletion at any time (see Section 7).
5. Data Protection
We take reasonable technical and organisational steps to protect your personal data from unauthorised access, loss, or disclosure. Our contact data is stored in password-protected systems accessible only to the Hearthroot administrative team. We do not store payment card information — course fees are collected by bank transfer or cash only.
In the event of a data breach that is likely to affect your rights and interests, we will notify you and the relevant authorities as required under Malaysian law.
6. Cookies and Website Analytics
Our website may use cookies to understand how visitors use it. We do not use cookies for advertising purposes. Please see our Cookie Policy for full details on the types of cookies used and how to manage your preferences.
7. Your Rights Under the PDPA
Under the Personal Data Protection Act 2010, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete personal data
- Withdraw your consent to the processing of your personal data (where processing is based on consent)
- Request that we stop processing your data for purposes other than those strictly necessary
To exercise any of these rights, please contact us at [email protected] or by post to our Ipoh address. We will respond within fourteen working days. You also have the right to lodge a complaint with the Department of Personal Data Protection Malaysia if you believe your data has been handled unlawfully.
8. Third-Party Services
This website may link to external pages (for example, government or regulatory sites). We are not responsible for the privacy practices of those sites. If you contact us via email, your message passes through your own email provider's servers — we have no control over how that provider handles data in transit.
If we use any analytics tool on this website, data processed by that tool is subject to the third-party provider's own privacy policy, which will be referenced in our Cookie Policy.
9. Children's Privacy
Our courses are designed for adults aged 40 and above. We do not knowingly collect data from anyone under the age of 18. If you believe a minor has submitted information to us, please contact us so we can delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of the page. Significant changes will be communicated to enrolled participants by email. Continued use of our services after changes take effect constitutes acceptance of the revised policy.
11. Contact
For data protection enquiries:
- Email: [email protected]
- Address: Hearthroot, 5 Jalan Stesen, 30000 Ipoh, Perak, Malaysia
- Phone: +60 5-242 7836