Privacy Policy
Last Updated: 12 May 2025 | Coterra, No. 19, Jalan Raja Ekram, 30450 Ipoh, Perak, Malaysia
1. Introduction
Coterra ("we", "us", "our") is committed to handling your personal data responsibly and transparently. This Privacy Policy explains what information we collect, how we use it, and your rights in relation to it. It applies to all personal data collected through our website at coterra.sbs, our contact forms, and our membership operations.
We process personal data in accordance with Malaysia's Personal Data Protection Act 2010 (PDPA). If you have any questions about this policy, please contact us at [email protected].
2. Data We Collect
2.1 Information You Provide Directly
- Contact form submissions: name, email address, phone number (optional), and message content.
- Membership enquiries and onboarding: name, email address, phone number, and background information relevant to circle placement.
- Communications: emails, messages, and other correspondence you send us.
2.2 Information Collected Automatically
- Usage data: pages visited, time spent on pages, browser type, and device information.
- Cookies: see Section 6 and our Cookie Policy for details.
- Analytics: aggregated, anonymised data about how visitors use our website, processed through tools such as Google Analytics (where enabled by your cookie preferences).
2.3 Legal Basis for Processing
- Consent: where you have given clear consent, for example via our cookie banner or when submitting our contact form.
- Legitimate interests: for operational purposes such as responding to enquiries, managing memberships, and improving our services.
- Contractual necessity: to fulfil membership obligations once you become a member.
3. How We Use Your Data
- To respond to your enquiries and messages promptly.
- To manage your membership, including onboarding, circle placement, and communications.
- To send you information about upcoming events, new resources, and community updates (you may opt out at any time).
- To improve our website and community experience using aggregated analytics data.
- To comply with legal obligations applicable under Malaysian law.
We do not sell, rent, or trade your personal data to third parties for marketing purposes.
3.1 Third-Party Service Providers
We may share data with trusted service providers who help us operate our website and community, including email hosting providers and analytics platforms. These providers are contractually required to handle data securely and only for the purposes we specify. Providers may include Google Analytics and email delivery services.
4. Data Retention
- Contact form enquiries: retained for 24 months from the date of submission, or for as long as necessary to complete the enquiry.
- Active member records: retained for the duration of membership plus 36 months following expiry or termination.
- Analytics data: retained in aggregated, anonymised form in accordance with Google Analytics default retention settings.
After the applicable retention period, personal data is securely deleted or anonymised.
5. Data Protection Measures
We take reasonable technical and organisational measures to protect your personal data against unauthorised access, loss, or misuse. These include:
- Secure HTTPS connections for all web traffic.
- Restricted access to personal data — only team members who need it to fulfil their roles may access it.
- Regular review of data handling practices and access controls.
- Prompt notification to affected individuals in the event of a data breach, as required under applicable law.
6. Cookies
Our website uses cookies to support basic functionality and, where you consent, to collect analytics data. We do not use cookies for advertising or to track you across other websites.
You can manage your cookie preferences at any time via our Cookie Policy page, which includes toggles for each cookie category.
7. Your Rights
Under Malaysia's Personal Data Protection Act 2010, you have the following rights regarding your personal data:
- Right to access: request a copy of the personal data we hold about you.
- Right to correction: request that inaccurate or incomplete data be corrected.
- Right to withdraw consent: where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
- Right to limit processing: request that we restrict how we use your data in certain circumstances.
- Right to erasure: request deletion of your personal data, subject to our legal obligations and legitimate interests.
To exercise any of these rights, contact us at [email protected]. We will respond within 21 days. We may ask you to verify your identity before processing the request.
If you are dissatisfied with our response, you may lodge a complaint with Malaysia's Department of Personal Data Protection (pdp.gov.my).
8. Third-Party Links
Our website may contain links to external websites operated by third parties. We are not responsible for the privacy practices of those websites and recommend that you review their privacy policies separately before providing any personal data to them.
9. Children's Privacy
Our membership is intended for adults aged 18 and over. We do not knowingly collect personal data from persons under 18. If we become aware that personal data has been submitted by a minor, we will delete it promptly. Please contact us at [email protected] if you believe this has occurred.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. The updated version will be published on this page with a revised "Last Updated" date. We encourage you to review this policy periodically. Continued use of our website or membership services following any update constitutes acceptance of the revised policy.
11. Contact Us
For any questions, requests, or concerns regarding this Privacy Policy or how we handle your personal data, please reach out to us:
- Email: [email protected]
- Address: No. 19, Jalan Raja Ekram, 30450 Ipoh, Perak, Malaysia
- Phone: +60 12-674 8309