Legal
Privacy Policy
Last Updated: 28 April 2025
1. Introduction
Auroral ("we", "us", "our") is committed to protecting the personal data of individuals who interact with our website and programmes. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and your rights in relation to it. It applies to all information collected through this website and through our programme enrolment process.
This policy is governed by Malaysia's Personal Data Protection Act 2010 (PDPA). By using our website or enquiring about our programmes, you acknowledge that you have read and understood this policy.
If you have questions about this policy, contact us at: [email protected]
2. Data We Collect
We may collect the following categories of personal data:
- Name and contact information (email address, phone number) when you submit an enquiry form
- Programme preferences and questions you include in your message
- Technical data such as IP address, browser type, and pages visited (via analytics cookies, if consented)
- Correspondence records if you contact us by email or phone
We do not collect sensitive personal data, financial account details, or identification documents through this website.
3. How We Collect Data
Data is collected when you:
- Submit the enquiry form on our website
- Contact us directly by phone or email
- Enrol in a programme and provide registration details
- Browse our website (technical/analytics data, subject to cookie consent)
4. Legal Basis for Processing
We process personal data on the following legal bases under the PDPA:
- Consent — where you have provided explicit consent, such as cookie consent or enquiry submission
- Contractual necessity — where processing is required to fulfil a programme enrolment
- Legitimate interests — for programme administration and service communication
5. How We Use Your Data
Personal data collected is used for the following purposes:
- Responding to enquiries and providing information about our programmes
- Processing programme enrolments and sending confirmation details
- Communicating about session schedules, materials, and programme updates
- Improving our website and programme delivery based on aggregated usage data
- Complying with applicable legal obligations
We do not use your personal data for marketing purposes without explicit consent, and we do not sell personal data to third parties.
6. Data Retention
We retain personal data for the following periods:
- Enquiry data (unmatched to enrolment): up to 12 months from date of enquiry
- Enrolment records: up to 3 years from programme completion
- Financial records: up to 7 years as required under Malaysian tax and accounting law
- Analytics data: retained in aggregated, anonymised form
After these periods, data is securely deleted or anonymised.
7. Data Sharing
We do not share your personal data with third parties except in the following limited circumstances:
- Service providers who assist with website hosting or email communication, under data processing agreements
- Where required by law or by a competent authority
We do not share personal data with financial institutions, advertising networks, or unrelated third parties.
8. Data Protection Measures
We take reasonable technical and organisational measures to protect your personal data against unauthorised access, disclosure, or loss. These include:
- Secure HTTPS transmission for all website data
- Access controls limiting staff access to personal data on a need-to-know basis
- Regular review of data handling practices
In the event of a data breach that affects your rights, we will notify affected individuals and the relevant authority as required under the PDPA.
9. Cookies
Our website uses cookies. For detailed information on the cookies we use and how to manage your preferences, please read our Cookie Policy.
10. Your Rights
Under Malaysia's Personal Data Protection Act 2010, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete personal data
- Withdraw consent for data processing where consent is the legal basis
- Request erasure of personal data where there is no lawful reason for continued processing
- Object to processing where processing is based on legitimate interests
- Lodge a complaint with the Personal Data Protection Commissioner Malaysia
To exercise any of these rights, contact us at [email protected]. We will respond within 21 days.
11. Third-Party Links
Our website may contain links to external websites. We are not responsible for the privacy practices of those sites and recommend reviewing their privacy policies independently.
12. Children's Privacy
Our programmes are designed for adults aged 18 and over. We do not knowingly collect personal data from individuals under 18. If we become aware that a minor has submitted personal data through our website, we will delete it promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Any material changes will be reflected in the "Last Updated" date at the top of this page. Continued use of our website following an update constitutes acceptance of the revised policy.
14. Contact
Data controller: Auroral
Address: Jalan Bangsar 76, 59000 Kuala Lumpur, Malaysia
Email: [email protected]
Phone: +60 3 2274 8693