1. Introduction
Restu ("we", "us", "our") is a pension protection legal services firm operating from Johor Bahru, Malaysia. We are committed to protecting the personal information of every individual who reaches out to us, whether by phone, email, or our website.
This Privacy Policy describes how we collect, use, disclose, and safeguard your personal data in accordance with the Personal Data Protection Act 2010 (PDPA) of Malaysia. By engaging with our website or services, you acknowledge the practices described here.
If you have questions at any point, please contact us at [email protected].
2. Personal Data We Collect
We collect personal data only to the extent necessary to understand your situation and deliver our services thoughtfully.
Information you provide directly
- Full name and preferred form of address
- Contact details: email address, phone number, mailing address
- Information relating to your pension or EPF/KWSP matter (shared at your discretion)
- Details of any related parties, such as dependants or next of kin, where relevant to a Family Retirement Care Engagement
Information collected automatically
- IP address, browser type, and operating system
- Pages visited, time spent, and referring pages
- Cookie identifiers (see Section 5)
Legal basis for processing
- Consent — where you have explicitly agreed (e.g. contact form submission)
- Legitimate interest — for website security, fraud prevention, and improving our service
- Contractual necessity — to deliver the service you have engaged us for
- Legal obligation — where required by Malaysian law
Data retention
Client engagement records are retained for seven (7) years from the conclusion of a matter, in compliance with Malaysian legal record-keeping norms. Contact enquiries not leading to a formal engagement are retained for up to twelve (12) months, then securely deleted. Website analytics data is retained for up to 26 months.
3. How We Use Your Data
Service delivery
- Responding to your enquiry and scheduling consultations
- Reviewing pension, EPF/KWSP, or survivor pension documentation
- Preparing correspondence on your behalf with relevant authorities (EPF, JPA, PERKESO)
- Providing updates on the progress of your matter
Operations and compliance
- Maintaining records as required by Malaysian law
- Detecting and preventing fraud or misuse
- Improving the quality and accessibility of our website
Communications
- Sending service updates and relevant correspondence relating to your engagement
- Occasional newsletters or information on pension matters — only where you have opted in
Data sharing
We do not sell, trade, or rent your personal information. We may share data only in the following limited circumstances:
- With relevant Malaysian government authorities (EPF/KWSP, JPA, Jabatan Perkhidmatan Awam) strictly as required to advance your matter
- With trusted service providers operating on our behalf (e.g. secure cloud storage), who are bound by confidentiality obligations
- Where required by law, court order, or regulatory authority
4. Data Protection Measures
Technical safeguards
- SSL/TLS encryption for all data transmitted to and from our website
- Encrypted storage for all digital client records
- Password-protected access with role-based permissions for staff
- Regular software updates and security patching
Organisational safeguards
- Access to personal data limited to staff who require it for their role
- Confidentiality obligations in all staff and contractor agreements
- Regular internal reviews of data handling practices
Breach notification
In the unlikely event of a data breach that affects your personal information, we will notify you and the relevant Malaysian authority as required under the PDPA, with reasonable promptness and with clear guidance on any steps you may wish to take.
6. Your Rights
Under the Malaysian Personal Data Protection Act 2010, you have the following rights in relation to your personal data:
Access and correction
- Right to access — request a copy of the personal data we hold about you
- Right to rectification — request that inaccurate or incomplete data be corrected
Control and erasure
- Right to withdraw consent — you may withdraw consent at any time; this does not affect the lawfulness of processing before withdrawal
- Right to erasure — request deletion of your personal data where there is no longer a lawful basis for us to retain it
- Right to restrict processing — request that we limit how we use your data in certain circumstances
Portability and objection
- Right to data portability — receive your data in a structured, commonly used format
- Right to object — object to processing based on legitimate interest
How to exercise your rights
To make any request, please contact us at [email protected] or in writing to our office address. We will respond within 21 calendar days. If you remain unsatisfied, you may lodge a complaint with the Department of Personal Data Protection Malaysia (JPDP).
7. Third-Party Links
Our website may contain links to external resources, government portals (such as the EPF website or MyGov), or other informational pages. These links are provided for your convenience. Restu has no control over the content or privacy practices of external websites and is not responsible for them. We encourage you to review the privacy policies of any site you visit.
8. Children's Privacy
Our services are intended for individuals aged 18 and above. We do not knowingly collect personal data from anyone under this age. If you believe a minor has submitted personal information to us, please contact us at [email protected] and we will take prompt steps to remove such data.
In the context of survivor pension documentation under a Family Retirement Care Engagement, information about dependants may be shared. In those cases, we handle such data strictly as required to process the engagement, with the same level of care as all other personal information.
9. Policy Updates
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. When we do, we will revise the "Last Updated" date at the top of this page. For material changes, we may also provide a more prominent notice on our website or contact existing clients directly.
Continued use of our website after any changes constitutes your acknowledgement of the revised policy.
10. Contact Information
If you have any questions, concerns, or requests relating to your personal data, please reach us through any of the following:
Data Enquiries
[email protected]Telephone
+60 7-331 8264Office Address
No. 12, Jalan Molek 1/29, Taman Molek,81100 Johor Bahru, Johor, Malaysia