JP Asia Capital Sdn Bhd (Company No. 1106912-P, “we”, “us”) respects your personal data. This policy is prepared under Malaysia’s Personal Data Protection Act 2010 (PDPA), as amended in 2024. It explains what personal data we collect, why we collect it, how we use and protect it, and the rights you have.

1. Scope

This policy applies to:

  • this website, jpasia.co (Chinese and English pages);
  • your contact with us through WhatsApp, phone, email, Facebook, Instagram, Xiaohongshu and similar channels;
  • our business management consultancy, employment law and HR compliance services, and our training courses, including HRDC Claimable courses funded by HRD Corp.

2. Personal data we collect

2.1 Information you give us

  • Enquiries: name, job title, company name, phone and WhatsApp number, email address, and what you tell us about your enquiry.
  • Training registration and HRDC claims: participant name, NRIC or passport number, employer, job title, contact details, attendance records and course evaluations. These are required to submit training grant claims to HRD Corp.
  • Consultancy services: while we work for a client, the client may give us company and employee information, such as employment contracts, staff records, payroll details or disciplinary case files. We process this only as needed for that engagement and keep it confidential under our agreement with the client.
  • Billing: company name, address, tax and invoicing details.

2.2 Information created when you browse

When you visit this website, the web server automatically records basic technical information: IP address, browser and device type, time of visit and pages viewed. We use these records only for security, abuse prevention and fixing technical problems.

This website does not use Google Analytics or any visitor analytics, does not use the Facebook Pixel or advertising trackers, and sets no marketing cookies.

3. Why we use it

We process personal data only to:

  • reply to your enquiries and arrange business diagnoses or meetings;
  • deliver the consultancy, compliance and training services you engage us for;
  • handle course registration, attendance, certificates and HRD Corp grant claims;
  • issue invoices, collect payment and keep accounting and tax records;
  • meet legal and regulatory obligations, or respond to lawful requests from authorities;
  • keep this website secure and running;
  • with your consent, send you information about courses, talks and employment law updates (see section 10).

Giving us personal data is generally voluntary. However, if you do not provide information a service requires (for example, the NRIC number needed for an HRDC claim), we may not be able to provide that service or submit the claim.

4. Who we share it with

We never sell or rent your personal data. We disclose it only where a service requires it or the law requires it, to:

  • HRD Corp, to process training grant claims;
  • appointed trainers and partners, only as needed to run a course or service;
  • service providers: website hosting (DigitalOcean, servers in Singapore), website delivery and security (Cloudflare), business email (Zoho Mail) and messaging (WhatsApp / Meta). They may process data only on our instructions;
  • professional advisers, such as auditors, accountants or lawyers;
  • government and law enforcement agencies, where required by law or court order.

5. Third-party services and cookies

  • Cookies: this website sets no cookies of its own. Our delivery service, Cloudflare, may set one strictly necessary security cookie when it detects suspicious traffic, to identify and block malicious bots. It is not used for tracking or advertising.
  • Google Fonts: some English typefaces are served from Google’s servers, so your browser sends your IP address to Google when loading them. Our Chinese typeface is served from this website.
  • YouTube videos: videos on the Testimonials and Resources pages use YouTube’s privacy-enhanced mode (youtube-nocookie.com). Once you press play, Google / YouTube’s privacy policy applies.
  • External links: we link to Facebook, Instagram, Xiaohongshu, WhatsApp, news websites and others. They have their own privacy policies, and we are not responsible for their practices.

6. Transfers outside Malaysia

This website’s server is located in Singapore, and some service providers (such as Cloudflare, Google and Meta) may process data outside Malaysia. In line with the PDPA, we transfer personal data only where the destination has protection substantially similar to the PDPA, or where we have taken reasonable steps to ensure the data receives equivalent protection.

7. How long we keep it

  • Web server logs: rotated daily and deleted automatically after about 14 days;
  • Enquiry records: for as long as needed to reply and follow up; generally no more than 2 years if you do not become a client;
  • Training and HRDC records: as required for HRD Corp audits;
  • Financial and tax records: at least 7 years, as required by law;
  • Consultancy materials: as set out in the client’s service agreement, then securely deleted or returned.

When a retention period ends, we securely delete or destroy the data.

8. Security

We take reasonable technical and organisational measures to protect personal data from loss, misuse, unauthorised access, modification or disclosure. These include HTTPS encryption across the whole website, access limited to staff who need it, access controls on servers and system accounts, and confidentiality obligations for our partners.

If a personal data breach is likely to cause you significant harm, we will notify the Personal Data Protection Commissioner, and affected individuals where required, as the PDPA requires.

9. Your rights

Under the PDPA, you have the right to:

  • access the personal data we hold about you;
  • correct data that is inaccurate, incomplete or out of date;
  • withdraw consent to our processing at any time (this may affect our ability to continue a service);
  • opt out of direct marketing;
  • data portability: ask us to transmit your data to another party, where technically feasible.

Email [email protected] to make a request. To protect your data, we may need to verify your identity first. We will respond within 21 days of receiving a complete request, and will tell you in advance if a fee permitted by law applies to an access request.

10. Marketing messages

We send information about courses, talks, events and employment law updates by WhatsApp, email or other channels only with your consent. You can reply “unsubscribe” or email us at any time to stop them, and we will act on it promptly.

11. Minors

Our services are for businesses, business owners and working professionals and are not directed at anyone under 18. We do not knowingly collect personal data from minors.

12. Changes to this policy

We may update this policy when the law, our services or this website change, and will update the effective date on this page. For significant changes, we will post a clear notice on the website.

This policy is available in Chinese and English. If there is any inconsistency between them, the English version prevails.

13. Contact us

For questions, requests or complaints about this policy or your personal data, contact:

JP Asia Capital Sdn Bhd (1106912-P)
Personal Data Protection
Unit 41-6, The Boulevard Offices, Mid Valley City, Jalan Syed Putra, 59200 Kuala Lumpur
Email: [email protected]
Phone / WhatsApp: +6019-251 1899

If you believe we have handled your personal data improperly, you may also complain to Malaysia’s Personal Data Protection Department (Jabatan Perlindungan Data Peribadi).

← Back to home