Legal
Privacy Policy
Last Updated: 14 April 2025 · Permata Wira, Kuala Lumpur, Malaysia
Permata Wira ("we", "us", "our") is committed to handling personal data with care and transparency. This Privacy Policy explains what information we collect when you use our website at permataw.site or contact us about our watch servicing, describes how that information is used, and sets out your rights under the Personal Data Protection Act 2010 (PDPA) of Malaysia.
By using our website or submitting a service enquiry, you acknowledge that you have read and understood this policy.
1. Data Controller
The data controller responsible for your personal data is:
- Business name: Permata Wira
- Address: 39 Jalan Bukit Bintang, 55100 Kuala Lumpur, Malaysia
- Email: [email protected]
- Phone: +60 3 2148 7639
2. What Personal Data We Collect
We collect the following categories of personal data:
Information You Provide Directly
- Name (required for service enquiries)
- Email address (required for correspondence)
- Phone number (optional, provided at your discretion)
- Details about your watch and the service you are enquiring about
- Any additional information you include in the message field of our contact form
Information Collected Automatically
- Browser type and version
- Pages visited and time spent on each page
- Referring URL (the page you came from)
- IP address (anonymised where possible)
- Cookie preferences and consent records
3. Legal Basis for Processing
We process your personal data on the following legal grounds under the PDPA 2010:
- Consent: When you submit our contact form or accept cookies, you consent to the processing described in this policy.
- Legitimate interest: We process enquiry data to respond to service requests — a legitimate business interest that does not override your rights.
- Contract performance: If a service agreement is entered into, we process the data necessary to carry out that agreement.
4. How We Use Your Personal Data
Personal data collected through this website is used for the following purposes:
- Responding to service enquiries and arranging intake appointments
- Communicating about the progress of an ongoing service
- Maintaining service records associated with your watch
- Improving the performance and content of our website through anonymised analytics
- Complying with legal obligations applicable in Malaysia
We do not use your personal data for unsolicited marketing communications. If you wish to receive service updates or information from us, this will be agreed with you directly.
5. Data Sharing
We do not sell, rent, or trade your personal data to third parties. We may share data only in the following limited circumstances:
- Service providers: Analytics and hosting providers who process data on our behalf under data processing agreements. These providers are not permitted to use your data for their own purposes.
- Legal requirements: Where disclosure is required by Malaysian law, court order, or a competent regulatory authority.
- Parts sourcing: In the Heritage Service Programme, where period-correct parts are required, we may share the watch reference (not your identity) with specialist suppliers.
6. Data Retention
We retain personal data for as long as is necessary for the purpose for which it was collected:
- Service enquiries that do not proceed to a service agreement: retained for 12 months, then deleted.
- Service records (where a service was completed): retained for 5 years to support warranty-related queries and service history.
- Cookie consent records: retained for 12 months from the date of consent.
- Website analytics data: retained in anonymised form for up to 24 months.
7. Data Protection Measures
We take reasonable technical and organisational steps to protect personal data against unauthorised access, disclosure, alteration, or destruction. These measures include:
- HTTPS encryption for all data transmitted through the website
- Access controls limiting who within the atelier can access client records
- Regular review of third-party service provider security practices
- Prompt assessment and notification procedures in the event of a data breach
In the event of a data breach that is likely to result in a risk to your rights, we will notify the relevant authority and affected individuals as required under applicable law.
8. Cookies
Our website uses cookies to support basic functionality and to understand how the site is used. Cookie types used include essential cookies (required for the site to function) and optional analytics cookies. You may manage your cookie preferences at any time via our Cookie Policy page.
9. Your Rights
Under the Personal Data Protection Act 2010 (Malaysia), you have the following rights in relation to your personal data:
- Right of access: You may request a copy of the personal data we hold about you.
- Right of correction: You may request correction of inaccurate or incomplete data.
- Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time. This does not affect the lawfulness of processing prior to withdrawal.
- Right to limit processing: In certain circumstances, you may request that we restrict how we use your data.
- Right to object: You may object to processing based on legitimate interests where your particular situation warrants it.
To exercise any of these rights, please contact us at [email protected]. We will respond within a reasonable period and in any event within 21 days of receiving your request.
If you are dissatisfied with how we handle your data, you may lodge a complaint with the Department of Personal Data Protection Malaysia (JPDP) at www.pdp.gov.my.
10. Third-Party Links
Our website may contain links to third-party websites, including payment processors or reference resources. We are not responsible for the privacy practices of those sites. We recommend reviewing the privacy policy of any external site before submitting personal data.
11. Children's Privacy
Our services are directed at adults. We do not knowingly collect personal data from individuals under the age of 18. If you believe a minor has submitted personal data through our website, please contact us at [email protected] and we will take steps to delete it promptly.
12. Policy Updates
We may update this Privacy Policy from time to time. The most current version will always be published at this address, with the "Last Updated" date revised accordingly. Continued use of the website following a policy update constitutes acceptance of the revised terms.
13. Contact for Privacy Matters
For any questions about this policy or how your data is handled, please contact:
- Email: [email protected]
- Post: Permata Wira, 39 Jalan Bukit Bintang, 55100 Kuala Lumpur, Malaysia