Legal
Privacy Policy
Last Updated: 10 April 2025 | Effective: 10 April 2025
Horolium, registered at 27 Jalan Tun Sambanthan, 50470 Kuala Lumpur, Malaysia, takes the handling of personal data seriously. This policy explains what information we collect, why we collect it, how we protect it, and your rights under the Personal Data Protection Act 2010 (Malaysia).
Questions about this policy should be directed to [email protected].
1. Data We Collect
When you use the contact form on this website, we collect the information you submit: typically your name, email address, telephone number, and a description of the service you are enquiring about. We do not collect more than is necessary for the purpose.
If you visit the site without submitting a form, we may collect limited technical data through cookies and analytics tools — such as your browser type, device category, and the pages you viewed. This data is not linked to your identity unless you later submit a form.
We do not collect payment information through this website. Payment details, if applicable, are handled separately at the workshop and are not stored electronically.
2. Why We Collect Personal Data
- Service correspondence: To respond to your enquiry, discuss the service required, and coordinate intake and return of your watch.
- Service records: To maintain an accurate record of watches received, work completed, and condition notes issued. These records form part of the service receipt issued to each client.
- Website improvement: Aggregated analytics data (not personally identifiable) helps us understand how visitors use the site and where improvements can be made.
- Legal compliance: Where required by Malaysian law, we may retain records for accounting, tax, or regulatory purposes.
The legal basis for processing your data is consent (for optional cookies and marketing communications) and legitimate interest (for service correspondence and record-keeping where you have chosen to engage with us).
3. How Long We Keep Data
Contact form enquiries that do not result in a service are retained for up to 12 months, then deleted.
Service records — including intake receipts, condition notes, and correspondence related to completed work — are retained for up to 7 years in accordance with Malaysian accounting and tax requirements.
Analytics data is retained in aggregated, anonymised form and not subject to a fixed deletion period.
4. Data Sharing
We do not sell, rent, or trade your personal data.
We may share data with third-party service providers who assist in operating this website — for example, analytics platforms or email service providers. These parties are contractually restricted to using your data only for the purpose of providing services to us and are required to handle it in accordance with applicable data protection law.
We may disclose data if required by a Malaysian court order or regulatory authority.
5. Data Protection Measures
- This website uses HTTPS encryption. Data submitted through forms is transmitted over an encrypted connection.
- Access to service records stored in our internal systems is restricted to workshop staff on a need-to-know basis.
- In the event of a data breach affecting your personal information, we will notify affected individuals and, where required, the relevant Malaysian authority, within a reasonable period of becoming aware of the breach.
6. Cookies
This website uses cookies to manage your preferences and, with your consent, to collect anonymised usage data. A full description of the cookies we use, including their purpose and duration, is available in our Cookie Policy. You can manage your cookie preferences at any time from that page.
7. Your Rights Under PDPA 2010
Under Malaysia's Personal Data Protection Act 2010, you have the following rights in relation to personal data we hold about you:
- Right of access: You may request a copy of the personal data we hold about you.
- Right of correction: You may ask us to correct inaccurate or incomplete data.
- Right to withdraw consent: Where processing is based on your consent, you may withdraw it at any time. This does not affect processing that occurred while consent was active.
- Right to stop processing for direct marketing: You may ask us to stop using your data for direct marketing at any time.
To exercise any of these rights, write to us at [email protected]. We will respond within 21 days.
8. Changes to This Policy
We may update this policy from time to time. When we do, the "Last Updated" date at the top of the page will change. If changes are material, we will make a reasonable effort to notify active clients. Continued use of the website after changes are posted constitutes acceptance of the revised policy.
Data Enquiries