Data handled with practical safeguards and clear retention rules

General privacy statement

AgentHubRumah collects and processes personal data necessary to provide legal and advisory services to real estate professionals. We limit collection to data required for service delivery, client communications, compliance, and improvement of our advisory materials. This policy explains what data we collect, why we collect it, how long we retain it, and the choices available to users.

Effective date 08-04-2026
Data controller AgentHubRumah (Business ID 928759711152)
Postal address Jalan Kin Mee, Taman Kin Mee, 31400 Ipoh, Perak, Malaysia
01

Definitions

This section explains key terms used in the policy to make the details easier to apply in concrete situations.

Personal data means any information relating to an identifiable person, such as name, contact details, NRIC or passport number when provided for identity verification, and transactional records relevant to advisory services.
Processing covers any operation performed on personal data, including collection, storage, use, disclosure, and deletion.
User refers to any visitor, client, or agent who interacts with AgentHubRumah services or submits personal data for advisory, document review, or compliance purposes.
Service means legal and advisory products, templates, audits, and consultations provided by AgentHubRumah to real estate professionals and agencies.
Cookies are small text files placed on devices to enable functionality and analytics. They help deliver a more consistent and useful service.
02

Data collection and sources

We collect data to provide services, manage engagements, comply with legal obligations, and improve our offerings. Collection is limited to what is necessary for those purposes.

03

Information you provide

Data you may provide when engaging our services or using the site includes the following categories:

  • Contact details: name, email address, phone number provided for scheduling or correspondence.
  • Business information: agency name, business registration number, role within the agency, and address.
  • Transactional data: records of appointments, invoices, payment confirmation, and service agreements.
  • Case materials: documents and files you submit for review, such as contracts, title documents, and correspondence relevant to an advisory matter.
  • Feedback and communications: messages platform with our advisors and notes from consultations.
  • Optional profile data: preferences and non-sensitive professional details you choose to provide to improve service delivery.
04

Information collected automatically

We also collect certain information automatically when you visit our website or use online tools.

  • Device and browser information: device type, operating system, browser version.
  • Usage data: pages visited, time spent, navigation paths, and feature interactions for service improvement.
  • Log data: IP address, access times, and error reports used for diagnostics and security monitoring.
  • Analytics identifiers: anonymous identifiers used by analytics tools to measure site performance and feature uptake.
  • Location data: coarse location derived from IP address to support regional compliance and content localization.
  • Cookie data: values stored in cookies where you have given consent or where cookies are strictly necessary.
05

Third-party sources

We may receive data about you from trusted third parties to facilitate services or improve accuracy of records.

  • Payment processors for invoice settlement and transaction records.
  • Public registers and land offices when verification of titles or encumbrances is required for advisory work.
  • Professional partners engaged for specific services, such as document translation or specialized contribute.
06

Purposes of processing

We process data for specific business and regulatory purposes. Each purpose is tied to the minimal data needed to achieve it.

  • To provide legal reviews, templates, and advisory services requested by clients.
  • To manage client relationships: scheduling, invoicing, and follow-up communications.
  • To comply with legal obligations, including tax, anti-funds laundering checks, and regulatory reporting where applicable.
  • To operate, maintain, and improve website features and content relevant to real estate professionals.
  • To detect and prevent fraud, abuse, and security incidents affecting our services or clients.
  • To personalise communications and provide relevant case studies or service suggestions based on professional interest.
  • To retain records necessary for dispute resolution or to demonstrate compliance in regulatory reviews.
  • To collect aggregated insights used internally to refine checklists, templates, and audit protocols.
07

Legal basis for processing

Where applicable, we rely on a lawful basis to process personal data. For service-related processing we use contractual necessity and legitimate interest; for certain compliance tasks we rely on legal obligations.

  • Contractual necessity: processing required to perform the services you have requested, such as contract review or advisory work.
  • Legal compliance: processing necessary to comply with statutory obligations, for example tax or anti-funds laundering requirements.
  • Legitimate interests: limited processing to operate and improve the service, secure systems, and prevent fraud, balanced against user rights.
  • Consent: used only where you have explicitly agreed to optional uses such as marketing communications or non-essential cookies.
08

Cookies and tracking

Cookies and similar technologies are used to provide core site functionality and obtain analytics. We explain categories and how you can manage them.

Types include strictly necessary cookies for session management, analytics cookies for site improvement, and optional cookies used for personalization and marketing where consent is obtained.

Categories: necessary, performance/analytics, and functional/marketing. Necessary cookies are required for basic operation and cannot be disabled via the site interface.

You can manage cookie preferences through the cookie banner and via your browser settings. Disabling certain cookies may reduce site functionality.

Full cookie policy and preference centre

09

How we share data

We limit disclosure of personal data to parties that have a specific role in service delivery or legal compliance. Where we share data, we require appropriate protections.

  • Service providers involved in payments, hosting, and analytics under contract to process data on our instructions.
  • Professional advisers and third-party partners engaged for a specific client matter, only with the client’s instruction or where necessary for service delivery.
  • Government, regulators, or law enforcement when required by Malaysian law or a valid legal process.
  • Successors or purchasers in the event of a business transfer, subject to protections and notice to affected users where legally required.
  • Public registries and land authorities when verification of property records is necessary for advisory work.
  • Aggregated and anonymised information that does not identify individuals and is used to improve services.
10

International transfers

Some service providers may process data outside Malaysia. When transfers occur, we seek contractual assurances or other safeguards in line with applicable law to protect the data.

Safeguards include standard contractual terms with processors, security assessments, and limited data transfer only where necessary for the service.

11

Data retention

Retention periods are tied to the purpose of processing, regulatory requirements, and the need to resolve disputes.

Client account data is retained for the duration of the business relationship and archived for seven years thereafter to meet tax and regulatory recordkeeping expectations in Malaysia.

Communications and case-specific files are retained for the period necessary to manage the matter and for up to seven years after case closure unless a longer period is required by law.

System logs and diagnostic records are retained for up to two years for security monitoring and technical troubleshooting, unless a longer retention is required by law.

When retention periods expire we securely delete or anonymise personal data. Clients can request earlier deletion where it does not conflict with legal obligations or the performance of contracted services.

12

Security measures

We apply administrative, technical, and organisational measures proportionate to the sensitivity of the data. Controls include access restrictions, encrypted storage for sensitive documents, secure backups, and regular security reviews aligned with practical risk assessments.

  • Access control: role-based access and multifactor authentication for privileged accounts.
  • Encryption: encrypted storage and transport for sensitive client documents and communications.
  • Monitoring and incident response: logging, routine audits, and an incident response plan to address security events.
13

Your rights

You have rights to access and control personal data we hold about you, subject to applicable legal limitations and the need to preserve records for regulatory compliance.

  • Right to access: request a copy of personal data we hold about you.
  • Right to rectification: request correction of inaccurate or incomplete data.
  • Right to erasure: request deletion where data is no longer necessary and deletion does not conflict with legal obligations.
  • Right to object and to restrict processing: raise objections or request restriction where legitimate interests are the basis for processing.
  • Right to restriction of processing — request limits on how we use specific personal data when accuracy is contested or processing is unlawful but you oppose deletion.
  • Right to data portability — request a machine-readable copy of data you provided to AgentHubRumah for transfer to another service where technically feasible.
  • Right to object — object to direct marketing communications and to processing based on legitimate interests; we will review objections and adjust processing or document the lawful basis for retention.
  • Right to withdraw consent — where processing is based on consent for newsletters or marketing, you may withdraw consent at any time; withdrawal affects future processing but does not make prior processing unlawful.
14

Regulatory frameworks and international considerations

Although AgentHubRumah is based in Malaysia and primarily serves Malaysian real estate professionals, we recognize data protection standards that apply in other jurisdictions. When personal data of European Union residents is processed, we act in accordance with applicable provisions of the EU General Data Protection Regulation (GDPR) to the extent required by law and where we determine GDPR applies.

GDPR rules may apply to processing of personal data carried out by AgentHubRumah if you are located in the European Economic Area or if our processing relates to offering services to data subjects in the EEA. Applicability is assessed case-by-case; if you believe GDPR applies to your data, contact our data team with details of the processing and your jurisdiction.

  • Lawful basis: We document the lawful basis for each processing activity (consent, contract performance, legal obligation, vital interests, public task, or legitimate interests) and provide this information on request.
  • Data minimisation: We collect only the personal data necessary for the specified purpose, such as property transaction records, agent credentials, and communications relevant to advisory services.
  • Accuracy and retention: We keep records accurate for transactional purposes and retain data for as long as needed to comply with contractual, legal, or regulatory obligations, using retention schedules appropriate to the category of data.
  • Security measures: Technical and organisational measures, such as access controls and encrypted backups, are used to protect personal data. Where transfers outside the EEA are necessary, we rely on mechanisms that provide adequate safeguards.

If you are in the EEA and you consider our processing of your personal data to breach applicable data protection law, you may file a complaint with the supervisory authority in your member state. You can also contact AgentHubRumah first to attempt resolution by emailing [email protected] or writing to our address.

15

How to exercise your privacy rights

To exercise any privacy right (access, correction, deletion, portability, restriction, objection, withdraw consent), provide a description of the request and a copy of an identity document. For agents and clients we may ask for additional context such as transaction reference numbers or account details to locate records promptly.

[email protected]

We aim to acknowledge requests within 7 days and to respond substantively within 30 days. Complex requests or those requiring verification may take up to 60 days; we will notify you if an extension is necessary and explain the reasons.

16

Marketing communications

AgentHubRumah uses email and SMS for service updates, newsletters, and event invitations targeted to real estate professionals. Communications are tailored using your stated preferences and interaction history. Marketing data includes email address, consent status, and engagement metrics.

You can unsubscribe from marketing emails via the link in every message or by contacting [email protected]. Unsubscription is processed within a few business days; transactional messages related to active services or cases will continue where necessary for contract performance.

17

Children and minors

AgentHubRumah does not intentionally collect personal data of children under 16 for service sign-ups. If we become aware that data from a child has been collected without appropriate consent, we will take steps to remove the data. If you believe a child’s data is held by us, contact [email protected].

18

Links to third parties

Our site and communications may include links to third-party sites such as industry partners, government registries, or payment providers. These sites have their own privacy practices. We recommend reviewing third-party privacy policies before submitting personal data; AgentHubRumah is not responsible for external practices.

19

Updates to this policy

We review and update this privacy policy to reflect evolving services, legal requirements, and practical cases from our work with realtors. Significant changes will be posted on AgentHubRumah.club with an updated effective date. For material changes affecting your rights, we will make reasonable efforts to notify affected users.