Legal
Privacy Policy
Last Updated: 15 April 2025 · Effective: 15 April 2025
Nordica Spool ("we", "us", "our") is committed to handling personal data with care and transparency. This policy explains what personal data we collect, why we collect it, how we use it, and what rights you have in relation to it. Our operations are based in Kuala Lumpur, Malaysia, and we operate under the Personal Data Protection Act 2010 (PDPA).
If you have questions about this policy, please contact us at privacy@nordicasas.
1. Data We Collect
We may collect the following personal data:
- Contact information: name, email address, phone number
- Enquiry content: the message you send through our contact form
- Technical data: IP address, browser type, pages visited, time of visit (via analytics tools)
- Cookie preferences: stored locally in your browser
We collect data when you submit a contact form, email us directly, or visit our website. We do not collect sensitive personal data (as defined under PDPA).
2. Legal Basis for Processing
We process your personal data on the following legal bases under the PDPA 2010:
- Consent — when you submit a contact form or accept analytics cookies
- Legitimate interests — to respond to your enquiry and manage our client relationships
- Contract performance — when processing data in connection with an active engagement
3. How We Use Your Data
- To respond to your enquiry or request
- To communicate about a consulting engagement
- To improve our website through aggregated analytics
- To comply with legal obligations
We do not use your data for automated decision-making or profiling. We do not send unsolicited marketing communications.
4. Data Retention
Enquiry data is retained for up to 24 months unless an engagement commences, in which case data relevant to the engagement is retained for 5 years from engagement close. Analytics data is retained for 14 months. You may request deletion at any time.
5. Data Sharing
We do not sell your personal data. We may share data with:
- Our website analytics provider (Google Analytics — anonymised), if you have consented to analytics cookies
- Our email service provider, for the purpose of processing enquiries
- Legal or regulatory authorities, if required by law
Third-party providers are required to handle your data in accordance with applicable data protection law.
6. Security
We take reasonable technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration, or loss. Our website uses HTTPS. Internal documents and engagement notes are stored in access-controlled systems.
7. Cookies
We use cookies to improve your experience on this website and, with your consent, to collect analytics data. For full details, please read our Cookie Policy.
8. Your Rights
Under the PDPA 2010, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Withdraw consent to processing at any time
- Request that we cease processing your data for direct marketing purposes
- Request deletion of your data (subject to legal retention requirements)
To exercise any of these rights, contact us at privacy@nordicasas. We will respond within 21 days.
9. Third-Party Links
Our website may contain links to external sites. We are not responsible for the privacy practices of those sites and encourage you to review their policies separately.
10. Children
Our services are directed to organisations and professionals. We do not knowingly collect personal data from individuals under the age of 18.
11. Changes to This Policy
We may update this policy from time to time. The revised policy will be published on this page with an updated date. Continued use of the website after changes constitutes acceptance of the updated policy.
12. Contact
Data Controller: Nordica Spool
Address: Level 7, Menara Tan & Tan, 207 Jalan Tun Razak, 50400 Kuala Lumpur, Malaysia
Email: privacy@nordicasas