Privacy Policy
Last Updated: 14 April 2025 · Effective: 14 April 2025
Cendana Masa ("we", "us", "our") is committed to handling personal information with care and transparency. This policy describes what data we collect when you use our website or contact us about watch services, how we use it, and what rights you have under Malaysian law — including the Personal Data Protection Act 2010 (PDPA).
If you have questions about this policy, contact us at [email protected].
1. Information We Collect
We collect personal information only when you provide it directly to us — through our contact form, by email, or when you bring a watch to the atelier for intake. We do not collect data passively beyond standard website analytics.
Information you provide
- Full name
- Email address
- Phone number (optional)
- Details about your timepiece and service enquiry
- Service intake records (created when you drop off a watch)
Information collected automatically
- Pages visited and time spent on our website (via analytics cookies, where consent is given)
- Browser type and device information
- IP address (anonymised where possible)
Legal basis: Processing is based on your consent (for analytics cookies), our legitimate interest in responding to service enquiries (for contact form data), and the performance of a service agreement (for intake records).
Retention: Enquiry data is retained for 24 months. Service intake records are retained for 5 years for warranty and reference purposes. Analytics data is retained for 14 months.
2. How We Use Your Information
- To respond to your service enquiry and advise on appropriate service pathways
- To create and maintain intake records for watches in our care
- To contact you about progress, findings, and decisions during a service
- To send you the completed service documentation when your watch is ready
- To improve our website and understand how visitors engage with it (analytics, where consent is given)
- To comply with applicable Malaysian legal obligations
We do not use your personal information for unsolicited marketing. We do not share, sell, or rent your data to third parties for their own marketing purposes.
3. Data Sharing
We do not sell or trade your personal data. We may share data only in the following limited circumstances:
- Service providers: Third parties who assist us in operating the website (e.g., hosting, analytics). These parties process data only on our instructions and are bound by appropriate data processing agreements.
- Parts suppliers: Where your watch requires specific components, we may share the watch reference (not your personal details) with parts suppliers to facilitate sourcing.
- Legal obligations: Where required to comply with a legal obligation, court order, or Malaysian regulatory requirement.
4. Data Protection Measures
- Our website is served over HTTPS with TLS encryption
- Access to personal data within our organisation is restricted to personnel who require it for service delivery
- Physical intake records are stored securely at our atelier premises
- We review our data handling practices periodically and update them as appropriate
- In the event of a data breach that may affect your rights, we will notify affected individuals and the relevant Malaysian authority as required under the PDPA
5. Cookies
Our website uses cookies to function and, where you consent, to analyse how it is used. We use:
- Essential cookies: Required for basic site functionality. Always active.
- Analytics cookies: Used to understand page visits and user behaviour. Active only with your consent.
- Preference cookies: Used to remember your cookie choices. Active only with your consent.
For full details and to manage your preferences, see our Cookie Policy.
6. Your Rights Under the PDPA (Malaysia)
Under Malaysia's Personal Data Protection Act 2010, you have the following rights in relation to your personal data:
- Right of access: You may request a copy of the personal data we hold about you.
- Right of correction: You may request that inaccurate or incomplete data be corrected.
- Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time. This does not affect the lawfulness of processing before withdrawal.
- Right to limit processing: You may request that we cease or limit processing of your data in certain circumstances.
- Right to file a complaint: You may lodge a complaint with the Department of Personal Data Protection Malaysia (JPDP) if you believe your data has been handled unlawfully.
To exercise any of these rights, contact us at [email protected]. We will respond within 21 days.
7. Third-Party Links
Our website may contain links to external websites. We are not responsible for the privacy practices or content of those sites. We encourage you to review the privacy policies of any external sites you visit.
8. Children's Privacy
Our services are intended for individuals aged 18 and above. We do not knowingly collect personal data from minors. If you believe a minor has submitted data to us, please contact us and we will delete it promptly.
9. Changes to This Policy
We may update this policy from time to time to reflect changes in our practices or applicable law. Updates will be published on this page with a revised "Last Updated" date. We encourage you to review this policy periodically.
10. Data Controller Contact
For all data-related enquiries, including access requests or concerns:
Cendana Masa
18 Jalan Hujan Rahmat, Overseas Union Garden, 58200 Kuala Lumpur, Malaysia
Email: [email protected]
Phone: +60 3 7980 4631