Last Updated: 28 March 2026
Privacy Policy
Bestari Hub values the trust you place in us when you share your personal information. This policy explains clearly what data we collect, why we collect it, how it is used, and what rights you have under Malaysian law — specifically the Personal Data Protection Act 2010 (PDPA).
1. Who We Are
Bestari Hub is a financial education centre based in George Town, Penang, Malaysia. We operate as a data user under the PDPA. For data-related enquiries, contact us at:
- Email: [email protected]
- Address: 2 Jalan Transfer, 10050 George Town, Penang, Malaysia
- Phone: +60 4-928 4713
2. Data We Collect
We collect personal data when you interact with our website, contact us, or enrol in our programmes. This may include:
- Full name and contact number
- Email address
- General enquiry or message content
- Programme preferences or service interests
- Technical data such as browser type, IP address, and pages visited (via cookies)
We do not collect sensitive financial data such as bank account numbers or IC numbers through our website forms.
3. How We Collect Data
- Enquiry forms on our website when you reach out to us
- Cookies and analytics tools that track how visitors use our site
- Direct communication via email, phone, or in-person consultation
- Programme enrolment when you register for a course or session
4. Legal Basis for Processing
Under the PDPA 2010, we process your data on the following grounds:
- Consent — when you submit a form or agree to cookies
- Contractual necessity — to deliver the programmes you have enrolled in
- Legitimate interest — to improve our services and communicate relevant educational content
- Legal obligation — where required by Malaysian law
5. How We Use Your Data
- Responding to your enquiries and service requests
- Delivering and administering programmes you enrol in
- Sending relevant updates, session reminders, or educational materials
- Improving our website and understanding how it is used
- Complying with regulatory or legal obligations
We do not sell, rent, or trade your personal data to third parties for marketing purposes.
6. Data Sharing
We may share your data with trusted third parties only where necessary:
- Email and scheduling platforms used to send correspondence or confirmations
- Analytics providers (e.g. Google Analytics) for website performance insights
- Payment processors when you complete a programme purchase
- Legal authorities if required by Malaysian law or court order
All third parties we work with are required to handle your data responsibly and in line with applicable data protection standards.
7. Data Retention
We retain personal data only as long as necessary for the purposes it was collected:
- Enquiry records: up to 12 months unless a programme relationship continues
- Programme participant records: up to 5 years for educational and audit purposes
- Cookie data: as defined in our Cookie Policy
After the retention period, data is securely deleted or anonymised.
8. Data Security
We take reasonable steps to protect your personal data from unauthorised access, disclosure, or misuse:
- Secure encrypted connections (HTTPS) on our website
- Access to personal data restricted to authorised staff only
- Regular review of data handling practices
- Prompt notification procedures in the event of a data breach
No method of transmission over the internet is entirely without risk. We do our best to use appropriate safeguards.
9. Cookies
Our website uses cookies to improve your browsing experience and understand how visitors use our site. For full details on the types of cookies we use and how to manage them, please read our Cookie Policy.
10. Your Rights Under the PDPA
As a data subject under the Personal Data Protection Act 2010, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate or incomplete data
- Withdraw your consent to processing at any time
- Request that we stop processing your data for direct marketing purposes
- Enquire about our data protection practices
To exercise any of these rights, please contact us at [email protected]. We aim to respond within 21 days.
11. Third-Party Links
Our website may contain links to external websites. Bestari Hub is not responsible for the privacy practices of those sites. We encourage you to read the privacy policies of any website you visit independently of us.
12. Children's Privacy
Our services are intended for adults aged 18 and above. We do not knowingly collect personal data from individuals under 18. If you believe a minor has submitted data to us, please contact us so we may remove it promptly.
13. Supervisory Authority
If you have concerns about how your data is being handled, you may contact the Department of Personal Data Protection Malaysia (JPDP):
- Website: www.pdp.gov.my
- Address: Aras 1-3, Kompleks C, Pusat Pentadbiran Kerajaan Persekutuan, 62530 Putrajaya
14. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with a revised "Last Updated" date. Continued use of our website after changes are posted constitutes acceptance of the updated policy. We encourage you to review this page periodically.
15. Contact Us
For any questions, requests, or concerns about this Privacy Policy or your personal data:
- Email: [email protected]
- Phone: +60 4-928 4713
- Address: 2 Jalan Transfer, 10050 George Town, Penang, Malaysia