Privacy Policy
Last Updated: 14 April 2025 · Effective: 14 April 2025
1. Introduction
Pebblehearth ("we", "us", "our") is committed to handling personal data responsibly and in accordance with Malaysia's Personal Data Protection Act 2010 (PDPA). This policy describes how we collect, use, store, and protect personal information provided through this website and in the course of delivering our services.
If you have questions about how your data is handled, contact us at [email protected].
2. Data We Collect
Information you provide directly
- Full name (required for service enquiries)
- Email address (required for service enquiries)
- Phone number (optional, provided at your discretion)
- Message content submitted through the contact form
Information collected automatically
- Cookie consent preferences stored in your browser's local storage
- Analytics data if you have consented to analytics cookies (pages visited, session duration)
- Technical data such as browser type and approximate location (at country/region level only)
Information collected during service delivery
During on-site visits, our practitioners take handwritten notes. For the Heirloom Storage Survey, photographs of storage locations are taken. For the Multigenerational Memory Project, audio recordings of conversations are made. All of this is conducted with your explicit consent and is governed by separate service-specific arrangements confirmed at booking.
3. Legal Basis for Processing
- Consent: Processing of contact form submissions is based on your voluntary submission. Cookie-based analytics are based on your explicit cookie consent.
- Contract performance: Once a service is booked, processing of your information is necessary to deliver that service.
- Legitimate interest: We may retain records of completed engagements for a period of two years for administrative and quality assurance purposes.
4. How We Use Your Data
- Responding to enquiries submitted through the contact form
- Scheduling and administering service visits
- Delivering written outputs to you following each engagement
- Communicating about your booking or project
- Improving the functionality of this website (if analytics consent is given)
We do not use your personal data for direct marketing without your explicit consent. We do not sell, rent, or share personal data with third parties for commercial purposes.
5. Data Retention
- Contact form enquiries: retained for up to 12 months, or until the enquiry is resolved
- Booking records and service correspondence: retained for 2 years following completion
- Heirloom survey photographs: deleted within 30 days of the family accepting the final written output
- Memory Project audio recordings: transferred to the family and deleted from our systems within 30 days of project completion
- Cookie consent records: retained in your browser's local storage under your control
6. Data Protection Measures
- Website communications are encrypted in transit using TLS
- Service-related files are stored on access-controlled systems with limited internal access
- Handwritten on-site notes are stored securely and not digitised externally
- In the event of a data breach affecting your personal information, we will notify you within a reasonable period as required under applicable law
7. Cookies
We use essential cookies to support basic site functionality, and optional cookies for analytics and preference storage. You can manage your cookie preferences at any time through our Cookie Policy page.
8. Your Rights
Under the Malaysian Personal Data Protection Act 2010, you have the following rights regarding your personal data:
- Right to access the personal data we hold about you
- Right to correct inaccurate or incomplete personal data
- Right to withdraw consent for data processing at any time
- Right to request erasure of personal data we no longer need to retain
- Right to limit how your data is processed in certain circumstances
To exercise any of these rights, contact us at [email protected]. We will respond within 21 days.
9. Third-Party Links
This website may contain links to external websites. We are not responsible for the privacy practices of those sites and encourage you to review their policies independently.
10. Children's Privacy
Our services are directed at adults (18 years and above). We do not knowingly collect personal data from individuals under 18. If you believe a minor has submitted information through this site, please contact us at [email protected] and we will delete it.
11. Supervisory Authority
If you are a Malaysian resident and believe your personal data rights have not been respected, you may lodge a complaint with the Department of Personal Data Protection Malaysia (JPDP) at www.pdp.gov.my.
12. Policy Updates
We may update this policy from time to time to reflect changes in our practices or legal requirements. When we do, the "Last Updated" date at the top of this page will change. Continued use of this website following any update constitutes your acceptance of the revised policy.
13. Contact
Data Controller: Pebblehearth
14 Jalan SS 2/61, 47300 Petaling Jaya, Selangor, Malaysia
Email: [email protected]
Phone: +60 19-783 4106