General Privacy Statement
This privacy policy explains how StartTopBiz collects, uses, discloses and protects personal data submitted in connection with business formation and related advisory services. We adopt reasonable administrative, physical and technical safeguards appropriate to the sensitivity of data we process. Our approach is to minimise data collection to what is necessary for the provision of the requested services and to keep records only as long as required by law or legitimate business purposes.
Key Definitions
For clarity, we define key terms used throughout this policy. These definitions align with common data protection terminology and are provided to help you understand how we treat different types of information.
Data Collection
We collect data necessary to fulfil our contractual and legal obligations when assisting with business start-up and legal formation. Data collection is limited to what is required to perform the requested services effectively and in compliance with statutory requirements.
Information You Provide
When you engage StartTopBiz, we collect information you voluntarily provide to set up and manage your business entity and to communicate service details.
- Identification and verification data (e.g., national ID, passport number) required for company registration and anti-funds laundering checks.
- Contact information such as full name, business address, email address and telephone number used for correspondence and statutory notifications.
- Business details including proposed company name, business activities, partner and director information, and company resources structure.
- Supporting documentation like proof of address, company constitutive documents, and signed engagement letters necessary for filing with regulatory authorities.
- Payment and billing information required to process invoices and manage fees for formation and ongoing compliance services (we do not store full payment card details on our systems).
- Communications and preferences you provide such as consent for marketing, appointment requests and notes from advisory sessions.
Automatically Collected Data
When you use our website and digital services, we automatically collect technical and usage data to operate the site securely and to improve service delivery.
- Log data including IP address, browser type, operating system, access times and pages viewed for troubleshooting and security monitoring.
- Device identifiers and anonymised usage analytics to evaluate how visitors interact with StartTopBiz resources.
- Session and cookie data used to maintain user sessions, preferences and language settings while navigating our site.
- Referral and campaign parameters that help us understand traffic sources and optimise information materials for entrepreneurs.
- Security-related events such as failed login attempts or suspicious activity records kept to protect accounts and comply with legal requirements.
- Aggregated, non-identifiable statistics created from usage data to monitor service performance and plan enhancements.
Third-Party Sources
We may receive personal data about you from external parties where permitted by law and relevant for service delivery or compliance.
- Government and regulatory bodies (for verification and filing purposes) such as Companies Commission of Malaysia (SSM) when performing incorporation tasks.
- Payment processors and banks to validate and process fee payments related to service provision.
- Third-party service providers engaged for due diligence, background checks, or accounting and bookkeeping services where required.
Purposes of Processing
We process personal data only for specific, explicit and legitimate purposes connected to our services and legal obligations. These purposes are limited to what is necessary.
- To form and register companies and to carry out statutory filings with Malaysian authorities on your behalf.
- To verify identity and perform compliance checks required by Malaysian law, including anti-funds laundering and counter-terrorist funding obligations.
- To provide advisory services, prepare incorporation documents, and manage ongoing corporate compliance tasks.
- To process payments, issue invoices and maintain accurate business records for services rendered.
- To communicate with you about your engagement, respond to enquiries, schedule consultations and deliver requested documentation.
- To maintain security of systems and to detect, prevent and address fraud, misuse or other prohibited activities.
- To perform internal reporting, service improvement analysis and legitimate business administration.
- To comply with legal obligations and cooperate with competent public authorities when lawfully required.
Legal Bases for Processing
Processing is conducted on lawful grounds appropriate to the purpose, including contractual necessity, compliance with legal obligations, and where consent has been provided.
- Performance of a contract: processing necessary to provide the requested company formation and advisory services.
- Legal obligation: processing required to meet statutory filing obligations, tax rules and regulatory checks under Malaysian law.
- Legitimate interests: where processing is necessary for operational needs, security, fraud prevention and business administration, balanced against individual rights.
- Consent: where specific marketing communications or optional services are provided based on your explicit consent, which you may withdraw at any time.
Rights and Compliance (Reference to International Standards)
While StartTopBiz operates in Malaysia, we recognise international data protection principles and provide information on user rights in a manner consistent with common international standards.
- Access: you may request confirmation of whether we process your personal data and obtain copies of that data where applicable.
- Rectification: you may request correction of inaccurate or incomplete personal data we hold about you.
- Erasure: where retention is no longer necessary and no legal grounds require continued storage, you may request deletion of personal data.
- Restriction: you may request restriction of processing where accuracy is contested or processing is unlawful but erasure is not requested.
- Data portability: where processing is based on consent or contract and done by automated means, you may request a structured, machine-readable copy of your data.
- Objection: you may object to processing based on legitimate interests, subject to our right to continue processing for overriding legitimate grounds or legal reasons.
Data Sharing and Disclosure
StartTopBiz does not sell personal data. We share information only where necessary to deliver services, with trusted third parties or when required by law, and we take contractual and technical measures to protect shared data.
- Service providers engaged to perform tasks such as payment processing, background checks, and document storage under written data processing agreements.
- Regulatory authorities and government agencies when required for incorporation filings, tax compliance, or by court order.
- Professional advisers, such as external auditors or legal counsel, where sharing is necessary for provision of services and subject to confidentiality obligations.
- Affiliated entities and subcontractors who support service delivery, with appropriate safeguards and contractual controls.
- Third parties involved in dispute resolution, contribute of suspected misconduct or protection of legal rights, when disclosure is necessary and proportionate.
- Aggregated or anonymised information that does not identify individuals and may be used for reporting and service improvement.
International Data Transfers
Where personal data is processed or stored outside Malaysia, we ensure an adequate level of protection through contractual safeguards, selection of providers with appropriate security practices, and assessment of legal frameworks in recipient jurisdictions.
Safeguards may include standard contractual clauses, data processing agreements, encryption and restricted access controls to ensure continued protection of personal data when transferred internationally.
Data Retention
We retain personal data only as long as necessary for the purpose it was collected, to comply with legal obligations or to resolve disputes. Retention periods reflect statutory requirements for corporate records and anti-funds laundering rules.
Client account records, incorporation documents and statutory registers are retained in accordance with Malaysian legal requirements and typical commercial practice for corporate records.
Communications such as email correspondence and service notes are kept for the period necessary to respond to enquiries and to maintain a record of service interactions, typically for a defined number of years unless longer retention is required by law.
Security logs and system records are retained for a prudent period to support incident contribute and system integrity, after which logs are deleted or anonymised.
When personal data is no longer required we will securely delete, anonymise or otherwise render it irretrievable, subject to any legal obligations to retain specific records longer.
Security of Personal Data
StartTopBiz implements administrative, technical and physical safeguards to protect personal data against unauthorised access, disclosure, alteration and destruction. Security measures are regularly reviewed to reflect changing threats and business needs.
- Access controls and role-based permissions to limit data access to authorised personnel only.
- Encryption in transit and at rest for sensitive information and secure communication channels for client interactions.
- Regular security assessments, patch management, employee training and incident response procedures to detect and address vulnerabilities promptly.
Your Data Rights
You can exercise your data rights by contacting our privacy team. We will respond to verified requests within a reasonable timeframe and in accordance with applicable law.
- Right to access: request a copy of personal data we hold and information about processing activities.
- Right to correction: ask us to correct or update inaccurate or incomplete personal data.
- Right to deletion or restriction: request erasure or limitation of processing where lawful grounds permit.
- Right to object and to withdraw consent: object to processing based on legitimate interests or withdraw consent where processing relies on it.
- Request restriction of processing when accuracy is contested or processing is unlawful but you prefer limited use of your data.
- Object to processing for direct marketing purposes where you no longer wish to receive promotional communications.
- Withdraw consent for processing activities that previously relied on your explicit permission; withdrawal does not affect processing conducted prior to withdrawal.
- File a complaint with the Malaysian Personal Data Protection Department or other competent supervisory authority if you believe your rights were not respected.
How to exercise your privacy rights
To exercise any of the rights outlined above, contact StartTopBiz using the address or email listed below. Please specify the right you wish to exercise and provide sufficient information to identify yourself and the records in question. We will verify identity to protect personal data and may request additional details to fulfill complex requests.
Responses are typically provided within 30 days of receipt. Complex requests that require additional verification or coordination with third parties may take up to 60 days; we will notify you if additional time is needed.
Marketing communications and choices
StartTopBiz may use contact details you provide to send service updates, industry insights, and occasional offers relevant to business formation and compliance in Malaysia. Communications will be based on your preferences and any consents you have provided. We limit marketing content to information that supports starting and operating a business responsibly.
To stop receiving marketing messages, use the unsubscribe link in any email from StartTopBiz or update your communication preferences by contacting our data protection team. Unsubscribe requests are processed promptly and will not affect transactional messages required for service delivery.
Children and minors
StartTopBiz services and content are intended for business users and adults. We do not knowingly collect personal information from individuals under 18. If you believe we have collected information about a minor, contact us with details so we can take appropriate steps to remove the data, subject to verification.
Third-party links and services
Our site may link to third-party websites, tools, or service providers used for payments, analytics, or legal reference. StartTopBiz is not responsible for the privacy practices or content of those third parties. Review third-party privacy policies before sharing personal data with them.
Changes to this privacy statement
We periodically review and update our privacy practices to reflect regulatory changes and operational improvements. Material changes to this privacy statement will be posted on StartTopBiz.info with an updated effective date and, when appropriate, notified to users by email.