Privacy Policy
Last updated:
1. INTRODUCTION
1.1 Edmates International ("Edmates", "Company", "we", "us", "our") is committed to protecting and respecting your privacy. This Privacy Policy ("Policy") describes how we collect, use, disclose, retain, and safeguard Personal Data when you access or use our website located at www.edmates.com (the "Website") and our education consultancy services (collectively, the "Services").
1.2 This Policy is issued in compliance with the Malaysia Personal Data Protection Act 2010 ("PDPA") and other applicable data protection laws and regulations. We are committed to ensuring that Personal Data processed by us is handled in accordance with the principles set forth in the PDPA.
1.3 By accessing, browsing, or otherwise using the Website or Services, you acknowledge that you have read, understood, and agree to the collection, use, and disclosure of your Personal Data as described in this Policy. If you do not agree with the practices described herein, you must discontinue use of our Services immediately.
1.4 This Policy should be read in conjunction with our Terms of Service, Cookies Policy, and Disclaimer, which are incorporated herein by reference.
2. DEFINITIONS
For the purposes of this Policy, the following definitions shall apply:
"Data Controller" means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data. For the purposes of this Policy, Edmates International is the Data Controller.
"Data Processor" means a natural or legal person, public authority, agency, or other body which processes Personal Data on behalf of the Data Controller.
"Data Subject" means any identified or identifiable natural person whose Personal Data is processed by the Company. In the context of this Policy, you are the Data Subject.
"Personal Data" means any information which relates directly or indirectly to a Data Subject, who is identified or identifiable from that information or from that and other information in the possession of the Data Controller, including any sensitive personal data and expression of opinion about the Data Subject.
"Processing" means any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, or destruction.
"Sensitive Personal Data" means any Personal Data consisting of information as to the physical or mental health or condition of a Data Subject, political opinions, religious beliefs, the commission or alleged commission of any offence, or any other personal data as determined by applicable law.
"Third Party" means any natural or legal person, public authority, agency, or body other than the Data Subject, Data Controller, Data Processor, or persons who are authorised to process Personal Data under the direct authority of the Data Controller or Data Processor.
3. DATA CONTROLLER INFORMATION
3.1 Edmates International is the Data Controller responsible for your Personal Data collected through the Website and Services.
3.2 For all enquiries, requests, or complaints relating to this Policy or the processing of your Personal Data, please contact us at:
Edmates International
Email: hello@edmates.com
Website: www.edmates.com
4. CATEGORIES OF PERSONAL DATA WE COLLECT
4.1 We collect various categories of Personal Data depending on your interactions with us and the Services you utilise. The categories of Personal Data we may collect include:
4.2 Identity Data
This includes your full legal name, title, date of birth, gender, nationality, country of birth, passport number, national identification number, photographs, and copies of identification documents.
4.3 Contact Data
This includes your residential address, correspondence address, email address, telephone numbers (mobile and landline), emergency contact details, and social media identifiers.
4.4 Academic and Professional Data
This includes educational qualifications, academic transcripts, certificates, standardised test scores (such as IELTS, TOEFL, SAT, GRE, GMAT), professional qualifications, employment history, curriculum vitae, personal statements, letters of recommendation, and extracurricular activities.
4.5 Financial Data
This includes bank account details, payment card information, transaction history, financial statements, sponsorship information, and scholarship details.
4.6 Immigration Data
This includes visa application information, immigration status, travel history, visa approval letters, student pass details, and related documentation.
4.7 Technical Data
This includes Internet Protocol (IP) address, browser type and version, device identifiers, operating system and platform, time zone setting and location, browser plug-in types and versions, and other technology on the devices you use to access the Website.
4.8 Usage Data
This includes information about how you use our Website and Services, including the pages you visit, the time and date of your visit, the time spent on each page, clickstream data, and other diagnostic data.
4.9 Communication Data
This includes your correspondence with us via email, telephone, chat, or other means, your preferences in receiving communications from us, and your communication preferences.
4.10 Health Data
Where required for visa applications or university admissions, this may include medical examination results, vaccination records, health declarations, and information relating to any disabilities or special needs requiring accommodation.
5. HOW WE COLLECT PERSONAL DATA
5.1 We collect Personal Data through the following means:
(a) Direct Interactions: When you provide information directly to us by completing forms on our Website, corresponding with us by email, telephone, or otherwise, registering for our Services, subscribing to our newsletters, requesting information or marketing materials, or providing feedback or completing surveys.
(b) Automated Technologies: As you interact with our Website, we may automatically collect Technical Data and Usage Data through cookies, server logs, and other similar technologies. Please refer to our Cookies Policy for further details.
(c) Third Parties and Publicly Available Sources: We may receive Personal Data about you from various third parties, including: (i) Educational Institutions to which you have applied or been admitted; (ii) referees who provide letters of recommendation; (iii) visa and immigration authorities; (iv) payment service providers; (v) analytics providers; (vi) advertising networks; and (vii) publicly available sources such as social media platforms.
(d) Parents or Legal Guardians: Where applicable, we may collect Personal Data from parents or legal guardians acting on behalf of minor applicants.
6. PURPOSES FOR WHICH WE PROCESS PERSONAL DATA
6.1 We process your Personal Data for the following purposes:
6.2 Service Provision
To provide our education consultancy Services, including: (a) assessing your eligibility for programmes at Educational Institutions; (b) advising on university and programme selection; (c) preparing and submitting applications on your behalf; (d) facilitating communication between you and Educational Institutions; (e) assisting with visa and student pass applications; (f) arranging accommodation and airport reception services; and (g) providing pre-departure orientation and ongoing support.
6.3 Contractual Obligations
To perform our contractual obligations to you, including processing your registration, managing your account, processing payments, and communicating with you regarding our Services.
6.4 Legal and Regulatory Compliance
To comply with applicable laws, regulations, and legal processes, including responding to requests from public and government authorities, complying with court orders, and meeting our legal and regulatory obligations.
6.5 Legitimate Business Interests
To pursue our legitimate business interests, including: (a) improving and developing our Services; (b) understanding how users interact with our Website; (c) conducting analytics and market research; (d) ensuring the security and integrity of our systems; (e) preventing fraud and other harmful activities; (f) protecting our legal rights and interests; and (g) managing our business operations.
6.6 Marketing and Communications
Where you have provided your consent or where otherwise permitted by law, to send you marketing communications, newsletters, promotional materials, and information about our Services, Educational Institutions, scholarships, and other opportunities that may be of interest to you.
6.7 Third-Party Disclosure
To share your Personal Data with Educational Institutions, visa authorities, accommodation providers, and other third parties as necessary for the provision of Services and as described in Section 8 of this Policy.
7. LEGAL BASIS FOR PROCESSING
7.1 Under the PDPA and other applicable data protection laws, we must have a lawful basis for processing your Personal Data. We rely on the following legal bases:
(a) Consent: Where you have given your explicit consent to the processing of your Personal Data for one or more specific purposes. You have the right to withdraw your consent at any time by contacting us at hello@edmates.com.
(b) Contractual Necessity: Where processing is necessary for the performance of a contract to which you are a party, or to take steps at your request prior to entering into a contract.
(c) Legal Obligation: Where processing is necessary for compliance with a legal obligation to which we are subject.
(d) Legitimate Interests: Where processing is necessary for the purposes of our legitimate interests or those of a third party, except where such interests are overridden by your fundamental rights and freedoms.
(e) Vital Interests: In limited circumstances, where processing is necessary to protect your vital interests or those of another person.
7.2 With respect to Sensitive Personal Data, we will only process such data where: (a) you have given your explicit consent; (b) processing is necessary for the establishment, exercise, or defence of legal claims; (c) processing is necessary for reasons of substantial public interest; or (d) processing is otherwise permitted by applicable law.
8. DISCLOSURE OF PERSONAL DATA
8.1 We may disclose your Personal Data to the following categories of recipients:
(a) Educational Institutions: Universities, colleges, and other academic institutions in Malaysia and elsewhere for the purpose of processing your applications, enrolment, and related academic matters.
(b) Government and Regulatory Authorities: Immigration departments, visa authorities, education ministries, and other governmental bodies as required for visa applications, student pass issuance, and regulatory compliance.
(c) Service Providers: Third-party service providers who perform services on our behalf, including payment processors, IT service providers, cloud hosting providers, customer relationship management providers, and analytics providers.
(d) Accommodation Providers: Student housing providers, hostels, and other accommodation services for the purpose of arranging your accommodation.
(e) Insurance Providers: Health and travel insurance companies as required for student insurance arrangements.
(f) Professional Advisors: Lawyers, accountants, auditors, and other professional advisors as necessary for the conduct of our business.
(g) Business Transferees: In the event of a merger, acquisition, reorganisation, sale of assets, or bankruptcy, your Personal Data may be transferred to the acquiring entity or successor.
(h) Law Enforcement: Law enforcement agencies, courts, regulators, and other governmental authorities where we are required to do so by law or to protect our legal rights.
8.2 We require all third parties to whom we disclose Personal Data to respect the security of your Personal Data and to treat it in accordance with applicable law. We do not permit third-party service providers to use your Personal Data for their own purposes and only permit them to process your Personal Data for specified purposes and in accordance with our instructions.
9. INTERNATIONAL DATA TRANSFERS
9.1 Given the nature of our Services, your Personal Data may be transferred to, stored, and processed in countries outside Malaysia, including countries where Educational Institutions to which you apply are located, and countries where our service providers operate.
9.2 When we transfer your Personal Data outside Malaysia, we will ensure that appropriate safeguards are in place to protect your Personal Data in accordance with the PDPA and other applicable data protection laws. Such safeguards may include: (a) transferring data to countries that have been recognised as providing an adequate level of data protection; (b) implementing standard contractual clauses approved by the relevant authorities; (c) obtaining your explicit consent to the transfer; or (d) where the transfer is necessary for the performance of a contract with you or in your interest.
9.3 By providing your Personal Data to us and using our Services, you acknowledge and consent to the transfer of your Personal Data outside Malaysia for the purposes described in this Policy.
10. DATA RETENTION
10.1 We will retain your Personal Data only for as long as reasonably necessary to fulfil the purposes for which it was collected, including to satisfy any legal, regulatory, tax, accounting, or reporting requirements.
10.2 In determining the appropriate retention period for Personal Data, we consider the amount, nature, and sensitivity of the Personal Data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process your Personal Data, whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting, or other requirements.
10.3 As a general guideline: (a) application records and supporting documentation will be retained for a minimum of seven (7) years following the completion of your application or the termination of our engagement; (b) financial and transaction records will be retained for the period required by applicable tax and accounting laws; (c) communication records will be retained for a period of three (3) years from the date of the communication; and (d) Technical Data and Usage Data will be retained for a period of two (2) years.
10.4 Upon expiration of the applicable retention period, we will securely delete or anonymise your Personal Data in accordance with our data retention policies and applicable law.
11. DATA SECURITY
11.1 We have implemented appropriate technical and organisational measures designed to protect your Personal Data against unauthorised access, alteration, disclosure, or destruction. These measures include:
(a) Encryption of Personal Data in transit and at rest;
(b) Implementation of access controls and authentication mechanisms;
(c) Regular security assessments and vulnerability testing;
(d) Employee training on data protection and security practices;
(e) Physical security measures at our premises;
(f) Secure disposal of Personal Data when no longer required; and
(g) Incident response procedures for data breaches.
11.2 Notwithstanding the foregoing, no method of transmission over the Internet or method of electronic storage is completely secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security.
11.3 You are responsible for maintaining the confidentiality of any passwords or account credentials used to access our Services. You agree to notify us immediately of any unauthorised use of your account or any other breach of security.
11.4 In the event of a Personal Data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority in accordance with applicable law.
12. YOUR RIGHTS AS A DATA SUBJECT
12.1 Subject to applicable law, you have the following rights in relation to your Personal Data:
(a) Right of Access: You have the right to request access to your Personal Data held by us and to obtain a copy of such data, subject to certain exceptions.
(b) Right to Rectification: You have the right to request the correction of inaccurate or incomplete Personal Data.
(c) Right to Erasure: In certain circumstances, you have the right to request the deletion or removal of your Personal Data where there is no compelling reason for its continued processing.
(d) Right to Restrict Processing: In certain circumstances, you have the right to request the restriction of processing of your Personal Data.
(e) Right to Data Portability: Where technically feasible and where processing is based on consent or contract, you have the right to receive your Personal Data in a structured, commonly used, and machine-readable format.
(f) Right to Object: You have the right to object to processing of your Personal Data based on legitimate interests or for direct marketing purposes.
(g) Right to Withdraw Consent: Where processing is based on consent, you have the right to withdraw your consent at any time. Withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.
(h) Right to Lodge a Complaint: You have the right to lodge a complaint with the Personal Data Protection Commissioner or other relevant supervisory authority if you believe that your rights have been violated.
12.2 To exercise any of your rights, please submit a written request to hello@edmates.com. We may require you to verify your identity before processing your request. We will respond to your request within the timeframe prescribed by applicable law.
12.3 Please note that certain rights may be limited under applicable law. We may decline to process requests that are unreasonably repetitive, require disproportionate technical effort, jeopardise the privacy of others, or are otherwise impractical.
13. CHILDREN'S PRIVACY
13.1 Our Services are not directed at children under the age of eighteen (18). We do not knowingly collect Personal Data from children under eighteen (18) without the consent of a parent or legal guardian.
13.2 Where we provide Services to applicants who are minors, we require that a parent or legal guardian consent to the collection, use, and disclosure of the minor's Personal Data on their behalf. The parent or legal guardian shall be responsible for ensuring the accuracy of the information provided and for exercising data subject rights on behalf of the minor.
13.3 If we become aware that we have collected Personal Data from a child under eighteen (18) without appropriate consent, we will take steps to delete such information promptly. If you believe that we may have collected information from a child without appropriate consent, please contact us at hello@edmates.com.
14. MARKETING COMMUNICATIONS
14.1 Where you have provided your consent or where otherwise permitted by law, we may send you marketing communications regarding our Services, Educational Institutions, scholarships, events, and other information that may be of interest to you.
14.2 You may opt out of receiving marketing communications at any time by: (a) clicking the "unsubscribe" link in any marketing email; (b) contacting us at hello@edmates.com; or (c) adjusting your communication preferences in your account settings, where applicable.
14.3 Please note that even if you opt out of marketing communications, we may still send you non-promotional communications, such as those relating to your account, your use of the Services, or any ongoing application or engagement.
15. COOKIES AND TRACKING TECHNOLOGIES
15.1 We use cookies and similar tracking technologies to collect and use Technical Data and Usage Data about you. Cookies are small data files stored on your device that help us improve our Website and your experience, analyse which pages are useful and which are not, and deliver relevant advertising.
15.2 For detailed information about the cookies we use, the purposes for which we use them, and how you can manage your cookie preferences, please refer to our Cookies Policy.
16. THIRD-PARTY WEBSITES AND SERVICES
16.1 Our Website may contain links to third-party websites, applications, or services that are not operated by us. If you click on a third-party link, you will be directed to that third party's site. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party websites or services.
16.2 We strongly advise you to review the privacy policy of every site you visit. This Policy applies only to our Website and Services and does not apply to any third-party websites or services.
17. CHANGES TO THIS PRIVACY POLICY
17.1 We reserve the right to update or modify this Policy at any time. Any changes will be effective immediately upon posting of the revised Policy on the Website. The "Effective Date" at the top of this Policy indicates when this Policy was last revised.
17.2 We will notify you of any material changes by: (a) posting a notice on our Website; (b) sending an email to the address associated with your account, where applicable; or (c) other means as we deem appropriate. Your continued use of the Services following the posting of any changes constitutes your acceptance of such changes.
17.3 We encourage you to review this Policy periodically for any updates or changes.
18. GOVERNING LAW
18.1 This Policy shall be governed by and construed in accordance with the laws of Malaysia, including the Personal Data Protection Act 2010.
18.2 Any dispute arising out of or in connection with this Policy shall be subject to the exclusive jurisdiction of the courts of Malaysia.
19. CONTACT US
19.1 If you have any questions, concerns, or complaints regarding this Policy or our data protection practices, or if you wish to exercise any of your rights as a Data Subject, please contact us at:
Edmates International
Website: www.edmates.com
Email: hello@edmates.com
19.2 We will endeavour to respond to all enquiries and complaints within the timeframe prescribed by applicable law.
By using our Services, you acknowledge that you have read and understood this Privacy Policy and consent to the collection, use, and disclosure of your Personal Data as described herein.