Privacy Policy
Last updated: 12 May 2025 | Effective date: 12 May 2025
This policy explains how Ferromir collects, uses, and looks after personal data provided through our website and services. We aim to keep things straightforward and to respect your choices at every step.
1. Introduction
Ferromir ("we", "us", "our") operates from Level 14, Menara Prestige, No. 1 Jalan Pinang, 50450 Kuala Lumpur, Malaysia. We provide retail pricing analysis and data review services to businesses across Malaysia.
This policy covers personal data collected through our website at ferromi.biz and through direct enquiries to our team. It applies to visitors, prospective clients, and organisations we work with.
We operate in accordance with Malaysia's Personal Data Protection Act 2010 (PDPA) and take reasonable steps to keep information secure and to use it only as described here.
2. Data We Collect
We collect only what is needed to respond to enquiries and deliver our services. This typically includes:
- Contact details — name, email address, and phone number provided through our contact form or by email.
- Business context — information about your retail operation shared voluntarily during discussions about our services.
- Technical data — browser type, device type, pages visited, and approximate location, collected through analytics tools when you visit our website.
- Communications — records of emails or messages exchanged with our team.
Legal basis for processing: We process data where you have given consent (e.g., submitting our contact form), where it is necessary to provide a service you have requested, or where we have a legitimate interest in responding to business enquiries.
Retention: Contact and enquiry data is kept for up to 24 months from last contact, after which it is deleted or anonymised. Data associated with an active service engagement is kept for the duration of that engagement plus 36 months.
3. How We Use Data
We use personal data for the following purposes:
- Responding to enquiries and providing information about our services.
- Delivering services you have engaged us for, including scheduling sessions and sharing outputs.
- Sending service-related communications such as session reminders or follow-up notes.
- Understanding how our website is used so we can improve it.
- Meeting legal obligations, including maintaining records required under Malaysian law.
Marketing: We do not send unsolicited marketing emails. If we share relevant service updates or content, we will give you a straightforward way to stop receiving them at any time.
Data sharing: We do not sell personal data. We may share data with third-party tools we use to operate our website (such as analytics providers) or with professional advisors where legally required. These parties are required to handle data appropriately and only for specified purposes.
4. Data Protection Measures
We take reasonable organisational and technical steps to protect personal data against loss, misuse, or unauthorised access. These include:
- Secure, encrypted transmission of data (HTTPS) across our website.
- Access to personal data limited to team members who need it to carry out their work.
- Regular internal reviews of how data is stored and accessed.
- Prompt assessment and notification in the event of a data breach, in line with PDPA requirements.
No system is fully without risk. If you have concerns about a specific data matter, please reach out directly.
5. Cookies
Our website uses cookies — small files stored in your browser — to help the site function and to understand how visitors use it. We use:
- Essential cookies — required for the site to work properly. These cannot be disabled.
- Analytics cookies — help us understand page visits and how people navigate the site. Optional.
- Preference cookies — remember choices such as cookie consent preferences. Optional.
You can review and manage your cookie preferences on our Cookie Policy page. You can also manage cookies through your browser settings at any time.
6. Your Rights
Under Malaysia's PDPA, you have the right to:
- Access — request a copy of the personal data we hold about you.
- Correction — ask us to correct data that is inaccurate or out of date.
- Withdrawal of consent — where processing is based on your consent, you may withdraw it at any time. This does not affect any processing done before withdrawal.
- Object to processing — in certain circumstances, you may object to how we use your data.
- Complaints — you may raise a concern with Malaysia's Department of Personal Data Protection (JPDP) if you believe your data rights have not been respected.
To exercise any of these rights, please email us at [email protected]. We aim to respond within 21 days.
7. Third-Party Links
Our website may include links to external websites for reference purposes. We are not responsible for the privacy practices or content of those sites. We encourage you to review the privacy policy of any third-party site you visit.
8. Children's Privacy
Our services are directed at retail businesses and their teams. We do not knowingly collect personal data from individuals under 18. If you believe a minor has submitted data through our website, please contact us and we will delete it promptly.
9. Policy Updates
We may update this policy from time to time to reflect changes in our practices or applicable requirements. When we do, we will revise the "Last updated" date at the top of the page.
Continued use of our website after an update means you acknowledge the revised policy. If changes are significant, we will make this clear on the page.
10. Contact
If you have any questions about this policy or how we handle your data, please reach out: