AUREUS STRATEGIES PE SDN BHD

PRIVACY POLICY

1. Introduction and Scope

(a) This Privacy Policy sets out the practices of the Company in relation to the Processing, retention, and protection of Personal Data in connection with the operation of this Website.

(b) By accessing or using the Website, or by providing any Personal Data to the Company, You acknowledge that You have read and understood this Privacy Policy and consent to the Processing of Your Personal Data in accordance with its terms.

(c) The Company is committed to protecting Personal Data in compliance with the Personal Data Protection Act 2010 of Malaysia (“PDPA”) and applicable regulatory or statutory requirements, and implements reasonable technical, administrative, and organisational measures to safeguard Personal Data against unauthorised or unlawful Processing, loss, or misuse.

(d) This Privacy Policy shall take effect on and from 1 August 2025.

 

2. Definitions and Interpretation

2.1 Definitions

In this Privacy Policy, unless the context otherwise requires, the following expressions shall have the meanings set out below:

Company” means Aureus Strategies PE Sdn Bhd, being the owner and operator of this Website.

Cookies” means small text files or similar technologies placed on User’s device to enable the Website to function, recognise the device, store or retrieve information, analyse usage, and improve performance and security.

Direct Marketing Communication” means the communication by whatever means of any advertising or marketing material which is directed to individuals.

Minor” means an individual under the age of eighteen (18) years.

“Personal Data” has the meaning ascribed to it under the PDPA.

Process”, “Processed” or “Processing”, in relation to Personal Data, means collecting, recording, holding or storing Personal Data, or carrying out any operation or set of operations on Personal Data, including:

  1. the organisation, adaptation or alteration of Personal Data;
  2. the retrieval, consultation or use of Personal Data;
  3. the disclosure of Personal Data by transmission, transfer, dissemination or otherwise making available; or
  4. the alignment, combination, correction, erasure or destruction of Personal Data.

Service Providers” means any third party engaged by the Company to Process Personal Data on its behalf or to provide services related to the operation, maintenance, security, analytics, hosting, administration, or support of the Website or the Company’s business.

Third-Party Websites or Services” means any websites, platforms, services, or content operated or provided by third parties that may be linked to, displayed on, or made available through the Website.

Usage Data” means data collected automatically when a User accesses or uses the Website, including information such as internet protocol (IP) address, browser type, browser version, device identifiers, operating system, pages visited, time and date of access, duration of visits, and other diagnostic data.

User”, “You”, or “Your” means any individual or entity accessing, browsing, or using the Website.

Website” means this website and all webpages, content, information, materials, features, and services made available through it from time to time.

2.2 Interpretation

In this Privacy Policy, unless the context otherwise requires:

  1. headings are inserted for convenience only and shall not affect the interpretation of this Privacy Policy;
  2. words importing the singular include the plural and vice versa;
  3. words importing any gender include all genders;
  4. references to any law or regulation include such law or regulation as amended, re-enacted, or replaced from time to time; and
  5. references to “including” shall be construed as being without limitation.

 

3. Types of Personal Data Collected

The Company may collect the following categories of Your Personal Data, including but not limited to:

(a) Identification and Contact Information

Names, contact details such as email addresses and telephone numbers, professional or corporate details, and other similar identifying information.

(b) Sensitive Personal Data

Sensitive Personal Data as defined under the PDPA, which may be Processed by the Company in accordance with this Privacy Policy.

(c) Technical and Usage Information

Technical data and usage-related information such as internet protocol addresses, browser type and version, device information, pages visited, date and time of access, duration of visits, and other similar technical or diagnostic information.

(d) Third-Party Related Personal Data

Personal Data relating to third parties associated with a User, including directors, shareholders, beneficial owners, representatives, employees, or any other related or connected parties, where such data is provided to the Company by the User.

 

4. Method of Collection

The Company may collect Personal Data through the following methods, including but not limited to:

(a) Direct Collection Through the Website

Personal Data may be collected directly when Users voluntarily provide information to the Company through the Website or via written or electronic communications, including online forms, emails, online messaging platforms, telephone communications, proposals, applications, registrations, or other materials submitted in connection with the Company’s business activities or services.

(b) Automatic Collection

Certain technical and Usage Data may be collected automatically when Users access or use the Website through Cookies or similar technologies.

(c) Collection from Third Parties or Public Sources

Where permitted under applicable law, the Company may collect Personal Data from third parties, related corporations, affiliates, professional advisers, counterparties, regulatory or governmental authorities, or public registries and publicly available sources, for lawful business, compliance, or regulatory purposes.

 

5. Purpose of Collection and Use of Personal Data

The Company collects and uses Personal Data for the following purposes, including but not limited to:

(a) Responding to Enquiries and Communications

To respond to enquiries, requests, or communications submitted by Users, including communications relating to the Company’s business activities, services, or general matters.

(b) Evaluation of Proposals, Investments, and Partnerships

To review, assess, and evaluate investment proposals, business opportunities, partnerships, or participation eligibility, including conducting preliminary assessments and related due diligence processes.

(c) Provision of Information on Services and Activities

To provide Users with updates, notices, announcements, Direct Marketing Communication or general information relating to the Company’s Services, activities, events, or initiatives.

(d) Legal, Regulatory, and Governance Compliance

To comply with applicable laws, regulations, guidelines, orders, and directions, including requirements imposed by regulatory or governmental authorities.

(e) Website Operation and Improvement

To operate, administer, maintain, monitor, and improve the Website, including analysing usage trends and engagement, and enhancing security, performance, functionality, and User experience.

(f) Business Administration and Operations

To support the Company’s internal business operations, including administrative, operational, audit, governance, management, and internal reporting purposes, to the extent permitted by applicable law.

 

6. Disclosure of Personal Data

The Company may disclose Personal Data including but not limited to the following circumstances:

  1. to Service Providers, professional advisers, affiliates, or related entities engaged by or connected with the Company for business, operational, governance, administrative, or compliance purposes, provided that such parties are subject to appropriate confidentiality and data protection obligations;
  2. where such disclosure is required or permitted under applicable law, regulation, guideline, court order, or pursuant to any request or direction of a regulatory, governmental, or law enforcement authority, or where such disclosure is necessary to protect the Company’s legal rights or to comply with its legal or regulatory obligations;
  3. in connection with any merger, acquisition, restructuring, reorganisation, financing, or transfer of all or part of the Company’s business or assets, subject to applicable confidentiality and data protection requirements;
  4. where the Company acts in the reasonable belief that it has in law the right to disclose the Personal Data, or that it would have had the consent of the data subject if the data subject had known of the circumstances of the disclosure;
  5. where the disclosure is justified in the public interest, in circumstances determined in accordance with applicable law;or
  6. where the User has provided consent to such disclosure, in the event that such disclosure is not expressly listed above.

For the avoidance of doubt, the Company does not sell, rent, or trade Personal Data to any third party for commercial gain.

 

7. Cross-Border Transfer of Personal Data

  1. The Company may transfer Personal Data to places outside Malaysia only where such transfer is permitted under section 129 of the PDPA.
  2. Where Personal Data is transferred outside Malaysia, the Company will take reasonable steps to implement appropriate technical, contractual, and organisational safeguards to protect such Personal Data and to ensure a level of protection comparable to that required under the PDPA.
  3. By accessing or using the Website, or by providing any Personal Data to the Company, Users acknowledge and agree that such cross-border transfers may take place where permitted under applicable law and, where required under the PDPA, consent to such transfers.

 

8. Data Retention

  1. The Company will retain Personal Data only for as long as is reasonably necessary for the fulfilment of the purposes for which such Personal Data was Processed.
  2. The Company may retain Usage Data for internal analysis, security, and operational purposes. Usage Data is generally retained for a shorter period, unless longer retention is required to strengthen security, improve functionality, comply with regulatory or audit requirements, or as otherwise required under applicable law.
  3. Where Personal Data and Usage Data are no longer required for the purposes for which they were Processed and retained, the Company will take reasonable steps to destroy or permanently delete such data.

 

9. Data Security Measures

  1. The Company will implement reasonable physical, technical, and organisational security measures, in accordance with section 9 of the PDPA, to protect Personal Data against loss, misuse, unauthorised access, disclosure, alteration, or destruction.
  2. Access to Personal Data is restricted to authorised personnel who require such access for the performance of their duties and who are subject to appropriate confidentiality and data protection obligations.
  3. While the Company takes reasonable steps to protect Personal Data using commercially acceptable security measures, no method of transmission or electronic storage is completely secure, and the Company does not guarantee the absolute security of Personal Data.

 

10. Cookies and Tracking Technologies

  1. The Website may use Cookies and other similar technologies from time to time.
  2. Where used, such technologies may be session-based or persistent and may remain on a User’s device unless removed through browser or device settings.
  3. Users may control or disable Cookies and similar technologies through their browser or device settings. Restricting certain technologies may affect the availability or functionality of some parts of the Website.

 

11. Third-Party Websites

  1. The Website may contain links to Third-Party Websites or Services, which are provided solely for convenience and informational purposes.
  2. The inclusion of any link to Third-Party Websites or Services does not constitute or imply any endorsement, approval, recommendation, or representation by the Company in respect of any content, products, or services made available on or through such Third-Party Websites or Services.
  3. The Company has no control over, and assumes no responsibility for, any Third-Party Websites or Services, including their content, software, plug-ins, tools, systems, services, availability, security, or privacy practices.
  4. Access to and use of any Third-Party Websites or Services, including any third-party software or services used in connection with or embedded on the Website, is entirely at the User’s own risk.
  5. The Company makes no representation or warranty and shall not be responsible or liable, whether directly or indirectly, for any loss or damage arising from or in connection with such access or use.

Users are encouraged to review the privacy policies and practices of any Third-Party Websites or Services before providing any Personal Data to such third parties.

 

12. User Rights

Users have the following rights in relation to their Personal Data held by the Company.

To support the Company’s internal business operations, including administrative, operational, audit, governance, management, and internal reporting purposes, to the extent permitted by applicable law.

(a) Right of Access

Users may request access to their Personal Data held by the Company, subject to any applicable legal, regulatory, or administrative limitations, and to any prescribed fees or procedures permitted under applicable law.

(b) Right to Correction or Update

Users may request the correction or updating of Personal Data that is inaccurate, incomplete, or outdated, and the Company shall take reasonable steps to comply with such request.

(c) Right to Withdraw Consent

Users may withdraw their consent to the Processing of Personal Data at any time by giving notice in writing to the Company. Upon receipt of such notice, the Company shall cease Processing the relevant Personal Data in accordance with section 38 of PDPA.

(d) Direct Marketing Opt-Out

Users may, at any time, opt out of receiving Direct Marketing Communications from the Company.

(e) Submission of Requests

Requests to exercise any of the rights set out above may be submitted by contacting the Company using the contact details provided in this Privacy Policy. The Company may require reasonable verification of identity and sufficient information to locate the relevant Personal Data before processing such requests.

 

13. Minor’s Privacy

  1. The Website is not intended for use by Minor, and the Company does not knowingly collect Personal Data from Minor.
  2. If the Company becomes aware that Personal Data of a Minor has been collected without appropriate authorisation or lawful basis, the Company will take reasonable steps to delete, anonymise, or otherwise cease Processing such Personal Data as soon as practicable, subject to applicable legal or regulatory requirements.

 

14. Amendments to the Privacy Policy

  1. The Company reserves the right, acting reasonably and at its discretion, to revise, amend, or replace this Privacy Policy from time to time, with or without prior notice.
  2. Where, in the Company’s reasonable opinion, any revision, amendment, or replacement is of a substantial nature and materially affects Your access to or use of the Website, the Company shall, where practicable, provide at least seven (7) days’ prior notice of such change by display on the Website or by such other reasonable means as the Company may determine, unless prevented from doing so by circumstances beyond the Company’s reasonable control.
  3. Your continued access to or use of the Website after the effective date of any revision, amendment, or replacement of this Privacy Policy shall constitute Your agreement to and acceptance of the revised Privacy Policy.

 

15. Dispute resolution

If You have any concern, complaint, or dispute arising out of or in connection with this Privacy Policy, You agree to first attempt to resolve such dispute in good faith and informally by contacting the Company using the contact details set out in Clause 17 before commencing any legal proceedings, without prejudice to any statutory rights available to You under applicable law.

 

16. Governing Law and Jurisdiction

This Privacy Policy shall be governed by and construed in accordance with the laws of Malaysia and irrevocably submit to the exclusive jurisdiction of the courts of Malaysia.

 

17. Contact Information

If You have any questions, concerns, or requests relating to this Privacy Policy or the Company’s handling of Personal Data, You may contact the Company using the following details:

Aureus Strategies PE Sdn Bhd (Registration No. 200801010260 (811548-V))

Registered Address: E-3A-02, Blok E, Oasis Ara Damansara, No. 2, Jalan PJU 1A/7A,
47301 Petaling Jaya, Selangor, Malaysia.

Email: inquiry@aureuspe.com

Telephone: +6012-642 7811