Legal Document
Privacy Policy
Last Updated: 10 April 2025 · Hikmah Legal, Kuala Lumpur
1. Introduction
Hikmah Legal ("we", "us", "our") is committed to protecting the personal data of individuals who contact us, engage our services, or visit our website at hikmahle.live. This Privacy Policy explains how we collect, use, disclose, and safeguard personal data in accordance with the Personal Data Protection Act 2010 (Malaysia) ("PDPA") and applicable legal professional obligations.
If you have questions about this policy or the handling of your personal data, please contact us at [email protected].
2. Data We Collect
Information you provide directly
When you submit an enquiry through our website, engage our services, or correspond with us by email or telephone, we may collect:
- Full name and contact details (email address, telephone number)
- Employment information relevant to your matter (employer name, role, dates)
- Details of the legal matter you are seeking advice on
- Documents you share in connection with a matter (contracts, correspondence, records)
- Billing and payment information where applicable
Information collected automatically
When you visit our website, we may collect technical information including your IP address, browser type, pages visited, and time spent. This is collected through cookies and similar technologies. Please see our Cookie Policy for details.
3. How We Use Your Data
We use personal data for the following purposes:
- Providing legal services: To assess your matter, prepare advice, represent you, and manage the engagement.
- Communication: To respond to your enquiries, send updates on your matter, and provide administrative notices.
- Compliance: To meet our obligations under the Legal Profession Act 1976, the PDPA 2010, and applicable rules of professional conduct.
- Conflict checking: To check for conflicts of interest before accepting engagements.
- Website improvement: To understand how visitors use our site and improve its content and functionality.
We do not use your personal data for marketing purposes without your explicit consent and we do not sell personal data to third parties.
4. Legal Basis for Processing
Under the PDPA 2010, we process personal data on the following bases:
- Consent: When you submit an enquiry or engage our services, you consent to the processing of your data as described in this policy.
- Contract: Processing is necessary to perform a legal services engagement you have entered into with us.
- Legal obligation: We may be required to process and retain data to comply with professional conduct rules, anti-money laundering requirements, or court orders.
- Legitimate interests: For security, conflict checking, and improving our service delivery.
5. Data Retention
We retain client files and related correspondence for a minimum of seven years following the conclusion of an engagement, in accordance with the Limitation Act 1953 and professional conduct requirements. Enquiry records that do not result in an engagement are retained for 12 months. Website usage data collected via analytics is retained for 26 months.
6. Sharing of Personal Data
We do not share personal data with third parties except in the following circumstances:
- With your explicit consent — for example, when sharing correspondence with an opposing party as part of negotiation.
- With professional service providers — such as secure document management platforms or accounting software — bound by confidentiality obligations and PDPA compliance.
- As required by law — including disclosure to courts, regulatory bodies, or law enforcement where legally compelled.
- To protect rights — where disclosure is necessary to protect the safety or legal rights of our firm, clients, or third parties.
7. Data Security
We implement reasonable technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, or destruction. These measures include:
- Encrypted storage of digital files and communications
- Access controls limiting file access to the assigned engagement team
- Secure physical document handling and storage at our Kuala Lumpur office
- Confidentiality obligations for all personnel who handle client information
In the event of a data breach that is likely to result in harm to individuals, we will notify affected parties and, where required, the relevant authorities, in accordance with applicable law.
8. Cookies
Our website uses cookies to understand how visitors use the site and to maintain basic functionality. You can control cookie preferences at any time through our Cookie Policy page. Disabling non-essential cookies does not affect your ability to submit an enquiry or access content on the site.
9. Your Rights
Under the PDPA 2010, you have the following rights in relation to your personal data held by us:
- Right to access: You may request a copy of the personal data we hold about you.
- Right to correction: You may request correction of inaccurate or incomplete personal data.
- Right to withdraw consent: Where processing is based on consent, you may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
- Right to limit processing: In certain circumstances, you may request that we restrict how we use your data.
To exercise any of these rights, please contact us at [email protected]. We will respond within 21 days.
If you are not satisfied with how we handle your request, you may lodge a complaint with the Personal Data Protection Department Malaysia (pdp.gov.my).
10. Third-Party Links
Our website may contain links to external websites. We are not responsible for the privacy practices of those sites, and this policy does not apply to them. We encourage you to review the privacy policies of any external sites you visit.
11. Children's Privacy
Our services are intended for persons aged 18 and above. We do not knowingly collect personal data from individuals under 18. If you believe we have inadvertently collected such data, please contact us and we will take appropriate steps to remove it.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be indicated by an updated "Last Updated" date at the top of this page. Continued use of our website or services following a change constitutes acceptance of the revised policy.
13. Contact Us
For any questions, requests, or concerns relating to this Privacy Policy or the handling of your personal data, please contact:
Hikmah Legal
Level 8, Wisma Antara, Jalan Ampang
50450 Kuala Lumpur, Malaysia
Email: [email protected]
Telephone: +60 3-8923 7146