Privacy Policy
This policy describes how Thornfeld collects, uses, and safeguards information when you visit our website or engage with our consulting services. We handle personal information carefully and only to the extent necessary for legitimate business purposes.
1. Who We Are
Thornfeld is a business consulting practice registered and operating in Malaysia. Our registered address is 9 Persiaran Multimedia, 63100 Cyberjaya, Selangor. We provide consulting services in innovation ecosystem design, R&D portfolio guidance, and technology landscape review.
For the purposes of the Personal Data Protection Act 2010 (Malaysia), Thornfeld is the data user in respect of personal information collected through this website and through our service engagements.
2. Information We Collect
We may collect the following categories of personal information:
- Contact information — your name, email address, phone number, and organisation name when you submit an enquiry or contact form on this website.
- Communication content — the content of messages you send to us by email or through the contact form.
- Engagement information — information you share with us during a consulting engagement, which may include organisational data, strategy documents, and personnel details relevant to the scope of work.
- Usage data — technical information about your visit to our website, including your IP address, browser type, referring URL, pages viewed, and session duration, collected through analytics tools.
- Cookie data — see Section 8 for details on cookies and similar technologies.
We do not collect sensitive personal data as defined under the PDPA unless this is explicitly necessary for a specific engagement and consented to in writing.
3. How We Use Your Information
We use personal information for the following purposes:
- To respond to enquiries and communicate with prospective clients.
- To conduct, manage, and deliver consulting engagements.
- To maintain records of our service delivery and communications.
- To send service-related correspondence, including invoices and engagement documentation.
- To understand how our website is used and to improve it over time.
- To comply with legal obligations and enforce our contractual rights.
We do not use personal information for unsolicited marketing communications. We do not sell, rent, or trade personal information to third parties for commercial purposes.
4. Legal Basis for Processing
Under the PDPA 2010, we process personal information on the following grounds:
- Consent — when you submit a contact form or enquiry, you consent to us processing your information in order to respond.
- Contractual necessity — when you engage our services, we process information necessary to perform the agreed scope of work.
- Legitimate interests — for website analytics and operational record-keeping, where these interests do not override your rights.
- Legal obligation — where we are required to retain or disclose information under applicable Malaysian law.
5. Disclosure of Information
We do not share personal information with third parties except in the following circumstances:
- Service providers — we use third-party tools including analytics services (such as Google Analytics) and email hosting. These providers are contractually bound to handle information only as directed by us.
- Legal requirements — where required by a court order, regulatory authority, or applicable law, we may disclose information to the extent legally required.
- Business transfer — in the event of a business sale, merger, or acquisition, personal information may be transferred as part of that transaction, subject to the same protections described in this policy.
We do not transfer personal information outside Malaysia except where required by a service provider operating in another jurisdiction, in which case we take reasonable steps to ensure an adequate level of data protection.
6. Data Retention
We retain personal information for as long as is reasonably necessary for the purpose for which it was collected:
- Enquiry and contact form data is retained for up to 24 months from the date of submission, or until the relevant engagement concludes, whichever is later.
- Engagement documentation and communications are retained for a minimum of 7 years in line with standard business record-keeping practice in Malaysia.
- Website analytics data is subject to the retention policies of the analytics provider used.
When data is no longer required, we take reasonable steps to delete or anonymise it securely.
7. Your Rights
Under the PDPA 2010, you have the right to:
- Request access to personal information we hold about you.
- Request correction of inaccurate personal information.
- Withdraw consent for processing (where consent is the basis), subject to reasonable notice.
- Request that we cease using your information for direct marketing purposes.
To exercise any of these rights, please contact us at [email protected] or by telephone at +60 3-8318 7246. We will respond within a reasonable time and in accordance with applicable law.
Note that some requests may be subject to limitations — for example, where retention is required by law or where disclosure would affect the rights of another individual.
9. Third-Party Links
Our website may contain links to external websites operated by third parties. This privacy policy does not apply to those websites. We are not responsible for the privacy practices of third-party sites and recommend reviewing their policies before submitting any personal information.
10. Security
We take reasonable technical and organisational measures to protect personal information against unauthorised access, loss, or disclosure. Our website uses HTTPS encryption for data in transit. Access to personal data held internally is restricted to individuals who require it for legitimate work purposes.
No system is entirely without risk. If you have reason to believe that your information has been compromised, please contact us promptly.
11. Children
Our website and services are directed at business professionals and organisations, not at individuals under the age of 18. We do not knowingly collect personal information from children. If you believe a child has submitted information to us, please contact us so we can delete it.
12. Changes to This Policy
We may update this privacy policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. We encourage you to review this policy periodically. Continued use of our website after any changes constitutes your acknowledgment of the updated policy.
13. Contact Us
If you have questions about this privacy policy or how your information is handled, please contact us:
- Email: [email protected]
- Phone: +60 3-8318 7246
- Address: 9 Persiaran Multimedia, 63100 Cyberjaya, Selangor, Malaysia
- Hours: Monday–Friday, 9:00 AM – 6:00 PM; Saturday 9:00 AM – 1:00 PM