Legal

Privacy Policy

This policy explains how Tesserae collects, uses and protects information provided to us through this website and during our engagements.

Last updated: 1 June 2025

Who we are

Tesserae is a lean and process improvement consultancy operating from Shah Alam, Selangor, Malaysia. Our registered address is Lot 12, Jalan Utarid U5/16, Seksyen U5, 40150 Shah Alam, Selangor. We can be reached at [email protected] or by telephone on +60 13-485 9620.

For the purposes of applicable data protection law, Tesserae is the data controller in respect of personal information collected through this website and in connection with our services.

Information we collect

We collect information in the following ways:

  • Contact enquiries. When you submit our contact form or send us an email, we collect your name, business name, email address, telephone number (if provided) and the content of your message.
  • Website usage data. We collect standard technical information about how visitors use this website, including pages viewed, time spent and referral sources. This information is collected in aggregate and does not identify you individually.
  • Cookies. We use a small number of cookies to help the website function and to understand how it is used. Please see our Cookie Policy for details.
  • Engagement correspondence. During a consulting engagement, we may collect additional information relevant to the scope of work, including information about your business processes, team structure and operational data. This is governed by any written engagement agreement in place.

We do not knowingly collect personal information from individuals under the age of 18.

How we use your information

We use the information we collect to:

  • respond to your enquiries and communicate with you about our services;
  • prepare and deliver consulting work where an engagement has been agreed;
  • understand how this website is used so we can improve it;
  • comply with our legal and regulatory obligations.

We do not use your information for automated decision-making or profiling. We do not sell your personal information to third parties.

Legal basis for processing

Where applicable Malaysian data protection law requires us to identify a legal basis for processing personal information, we rely on the following:

  • Legitimate interests — for responding to enquiries and understanding website usage, where our interests do not override your rights.
  • Contractual necessity — for information processed in connection with an agreed engagement.
  • Legal obligation — where we are required to process information to comply with law.
  • Consent — where we have asked for and received your consent, such as for non-essential cookies.

Sharing your information

We share personal information only in the following circumstances:

  • Service providers. We use a small number of third-party tools to operate this website and manage communications. These providers process data on our behalf and are contractually required to handle it appropriately.
  • Legal requirements. We may disclose information where required to do so by law, court order or regulatory authority.
  • Business transfers. In the event of a merger, acquisition or sale of assets, personal data may form part of the transferred assets. We would notify affected individuals in advance where practicable.

We do not share your information with any other third parties without your explicit consent.

International transfers

Some of the third-party tools we use may process data outside of Malaysia. Where this occurs, we take reasonable steps to ensure that appropriate safeguards are in place consistent with the Personal Data Protection Act 2010 (Malaysia).

How long we keep your information

We retain personal information only for as long as is reasonably necessary for the purposes described in this policy or as required by law:

  • Contact enquiries that do not lead to an engagement are typically deleted within 12 months.
  • Information relating to completed engagements is retained for up to seven years for business record-keeping purposes.
  • Website usage data is retained in aggregate form and not linked to individuals.

Your rights

Under the Personal Data Protection Act 2010 (Malaysia) and, where applicable, other data protection legislation, you may have the right to:

  • access the personal information we hold about you;
  • request that we correct inaccurate or incomplete information;
  • request that we stop processing your information in certain circumstances;
  • withdraw consent where processing is based on consent.

To exercise any of these rights, please contact us at [email protected]. We will respond within a reasonable time and in accordance with our legal obligations.

Security

We take reasonable technical and organisational steps to protect personal information from unauthorised access, loss or misuse. No method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security.

Links to other websites

This website may contain links to external sites. We are not responsible for the privacy practices of those sites and encourage you to review their privacy policies separately.

Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. Material changes will be communicated through this website.

Contact us

If you have questions about this policy or about how we handle your personal information, please contact us:

  • Email: [email protected]
  • Telephone: +60 13-485 9620
  • Address: Lot 12, Jalan Utarid U5/16, Seksyen U5, 40150 Shah Alam, Selangor, Malaysia
  • Office hours: Monday to Friday, 9 am – 6 pm; Saturday, 9 am – 1 pm