Legal Document
Privacy Policy
Last Updated: 01 April 2026 ยท Version 2.1
This policy describes how Equilearn collects, uses, discloses, and protects personal data in accordance with Malaysia's Personal Data Protection Act 2010 (PDPA 2010).
1. Who We Are
Equilearn is a financial education provider operating in Malaysia. Our registered address is 33 Jalan Bukit Bintang, 55100 Kuala Lumpur. We provide structured educational programs for professionals and families on topics including financial statement literacy, behavioral finance, and household financial planning.
For the purposes of the Personal Data Protection Act 2010 (PDPA 2010), Equilearn is the data user responsible for your personal data collected through this website and through our program enrolment processes.
2. Personal Data We Collect
We collect personal data in the following ways: directly from you when you use our contact form, enquire about a program, enrol in a program, or communicate with us by email or telephone; and automatically when you browse this website through standard server logs and analytics tools.
Data collected directly
- Full name
- Email address
- Phone number (where provided)
- Organisation or employer name (where provided)
- Program enrolment information and payment records
- Communications and correspondence with our team
- Feedback, survey responses, and testimonials (where you choose to provide them)
Data collected automatically
- IP address and approximate geographic location
- Browser type, operating system, and device type
- Pages visited, referring URL, and time spent on pages
- Cookie identifiers (see Section 8 for details)
We do not collect sensitive personal data as defined under PDPA 2010 (such as race, religion, health information, or biometric data) in the ordinary course of our activities.
3. Lawful Basis for Processing
Under PDPA 2010, we process your personal data on the following bases:
- Consent: Where you have provided explicit consent, such as when submitting our contact form or subscribing to program updates.
- Contract performance: Where processing is necessary to fulfill a program enrolment agreement you have entered with us.
- Legal obligation: Where processing is required to comply with applicable Malaysian law, including financial record-keeping obligations.
- Legitimate interests: Where we have a legitimate interest that is not overridden by your rights, such as improving our programs and website, or communicating with past participants about related educational offerings.
4. How We Use Your Personal Data
We use personal data we collect for the following purposes:
- Responding to enquiries submitted through our contact form or by telephone
- Processing program enrolments, issuing payment receipts, and administering attendance
- Communicating program schedules, materials, and updates to enrolled participants
- Notifying you of upcoming programs or cohort availability where you have consented to receive such communications
- Submitting claims or participant records to the Human Resources Development Corporation (HRD Corp) where applicable
- Improving our website and program content based on aggregated usage data
- Complying with our legal and regulatory obligations
We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects.
5. Disclosure of Personal Data
We do not sell, rent, or trade your personal data to third parties. We may share your data in the following limited circumstances:
- Service providers: We share data with third-party services that assist in operating our website and delivering our programs, including email service providers, payment processors, and website analytics platforms. These parties are contractually bound to process data only on our instructions.
- HRD Corp: Where an employer is claiming training funding through the Human Resources Development Corporation, we may share relevant participant enrolment data as required by that scheme.
- Legal requirements: We may disclose personal data if required to do so by Malaysian law, court order, or lawful request by a government authority.
- Business transfers: If Equilearn undergoes a merger, acquisition, or transfer of assets, your data may be transferred as part of that transaction, subject to equivalent data protection commitments.
Where we transfer data to third parties, we take reasonable steps to ensure that appropriate data protection safeguards are in place.
6. Retention of Personal Data
We retain personal data only for as long as necessary for the purposes described in this policy, or as required by applicable law. Our general retention schedule is as follows:
- Contact form enquiries: 24 months from the date of submission
- Program enrolment records and correspondence: 7 years from the final program date, as required for financial record-keeping under Malaysian law
- Marketing communications preferences: Until you withdraw consent or unsubscribe
- Website analytics data: 26 months in aggregated or pseudonymised form
When personal data is no longer required, we securely delete or anonymise it.
7. Your Rights Under PDPA 2010
Under the Personal Data Protection Act 2010, you have the following rights in relation to your personal data held by Equilearn:
Right of access
You may request a copy of the personal data we hold about you. We will respond to such requests within 21 days of receiving them.
Right of correction
You may request that we correct inaccurate or incomplete personal data. We will process such requests promptly and notify you of any correction made or declined.
Right to withdraw consent
Where we process your data on the basis of consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.
Right to limit processing
You may request that we limit the way we process your data in certain circumstances, for example where you contest the accuracy of data we hold.
To exercise any of these rights, please contact us using the details in Section 12. We may need to verify your identity before processing your request. We do not charge a fee for access requests unless they are manifestly unfounded or excessive.
9. Security of Personal Data
We implement appropriate technical and organisational measures to protect your personal data from unauthorised access, accidental loss, destruction, or disclosure. These measures include secure HTTPS transmission, restricted access to personal data within our organisation, and regular review of our data handling practices.
While we take reasonable precautions, no method of transmission over the internet or electronic storage is completely secure. We encourage you to contact us promptly if you have reason to believe that your interaction with us has been compromised.
10. Children
Our programs are designed for adults and our website is not directed at individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe a child has provided us with personal data without appropriate parental consent, please contact us and we will take appropriate steps to remove the data.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the services we offer. When we make material changes, we will update the "Last Updated" date at the top of this page. Where we are required by law to notify you of changes, we will do so directly.
We encourage you to review this policy periodically to stay informed about how we handle your personal data.
12. Contact Us
If you have questions about this Privacy Policy, wish to exercise your rights under PDPA 2010, or wish to raise a concern about how we handle your personal data, please contact us using the following details:
Equilearn โ Data Privacy Enquiries
Address: 33 Jalan Bukit Bintang, 55100 Kuala Lumpur, Malaysia
Telephone: +60 3-2743 8196
Email: [email protected]
Business hours: Monday to Friday, 9:00 AM โ 6:00 PM
If you are not satisfied with our response to your enquiry or complaint, you may refer the matter to the Department of Personal Data Protection Malaysia (Jabatan Perlindungan Data Peribadi), which is the regulatory authority responsible for PDPA 2010 enforcement.