profitlyra

Privacy Policy

Last updated: 23 September 2026.

Identity and Role of the Data Controller

profitlyra operates this website as the data controller for personal data collected through corporate finance services. We determine the purposes and means of processing in line with Malaysian data protection requirements.

Scope of the Notice and the People It Covers

This notice applies to visitors, clients and prospective clients engaging with our corporate finance offerings. It covers individuals whose data we process in Malaysia and extends to interactions via our contact form and blog.

Categories of Personal Data and Sources

We collect identification details, contact information, financial records and professional credentials primarily from you directly, as well as from public registries and third-party verification services when required for due diligence.

Purpose-by-Purpose Explanation of Processing and Legal Basis

Data is processed to deliver corporate finance advice under contractual necessity, to comply with anti-money laundering obligations under legal requirements, to improve site functionality on the basis of legitimate interests, and to respond to enquiries with your consent.

Whether Providing Data Is Required and Consequences

Supplying certain data is mandatory to access our services. Failure to provide it may prevent us from completing transactions, performing regulatory checks or responding to your requests.

Cookies and Similar Technologies

We use cookies for essential site operation and analytics. Please refer to our separate Cookie Policy for detailed information on types, purposes and management options, accessible via the site-wide cookie banner.

Processors, Service-Provider Categories and Disclosures

Trusted processors such as cloud hosting providers, payment processors and legal advisors receive data under strict contracts. Disclosures occur only when required by Malaysian law or regulatory bodies.

International Transfers and Safeguards

Where data is transferred outside Malaysia, we apply contractual clauses and ensure recipients maintain comparable protection standards consistent with local regulations.

Specific Retention Periods or Criteria

Personal data is retained for seven years after the end of a client relationship to meet statutory requirements, or shorter periods where no longer necessary for the original purpose.

Security and Data-Minimisation Practices

Appropriate technical measures including encryption and access controls are implemented. We collect only the minimum data needed and regularly review processing activities to limit exposure.

Data-Subject Rights and Exercising Them

You may request access, correction, deletion or restriction of your data. Submit requests via the Contacts page form or by writing to [email protected]. We respond within the timelines prescribed by Malaysian law.

Right to Withdraw Consent and Object to Marketing

Where processing relies on consent you may withdraw it at any time. You can also object to direct marketing by using the unsubscribe options or contacting [email protected].

Right to Complain to the Supervisory Authority

If you are dissatisfied with our response you may lodge a complaint with the Personal Data Protection Commission of Malaysia using the contact details published on their official website.

Children or Age Restrictions

Our services are intended for corporate clients and individuals aged eighteen and above. We do not knowingly collect data from minors.

Automated Decision-Making and Profiling

We do not engage in solely automated decision-making that produces legal effects. Any profiling for risk assessment includes human oversight.

Policy Changes and Effective Date

We review this policy periodically. Changes take effect from the date stated at the top of the page. Continued use of the site after updates constitutes acceptance of the revised terms.