Privacy Policy

Last Updated: January 15, 2026

Effective Date: January 15, 2026

1. Introduction

Nimbara operates corporate accommodation services in Malaysia. This Privacy Policy explains how we collect, use, store, and protect personal data from individuals who inquire about, book, or occupy our properties. We are committed to protecting your privacy and handling your data in accordance with Malaysia's Personal Data Protection Act 2010 (PDPA).

By using our services or providing us with your personal data, you consent to the collection and use of information in accordance with this policy. If you have questions about how we handle your data, please contact us at [email protected].

2. Data We Collect

We collect personal data necessary to provide accommodation services and maintain our business operations. The types of data we collect include:

Contact Information

Full name, email address, phone number, and business affiliation. This data is collected when you submit an inquiry form, book a property, or communicate with our team.

Booking and Tenancy Data

Property preferences, arrival and departure dates, number of occupants, corporate billing information, and payment details. We collect this through booking forms, lease agreements, and billing processes.

Identification Documents

Passport copies, visa documentation, or Malaysian IC numbers as required for lease agreements and local registration compliance. These documents are collected during the booking confirmation process.

Usage and Technical Data

IP address, browser type, device information, and website interaction data collected through cookies and similar technologies. We use Google Analytics to understand how visitors interact with our website.

3. How We Use Your Data

We process personal data for specific, legitimate business purposes:

Service Delivery

Processing bookings, preparing properties, coordinating move-in logistics, providing relocation concierge services, and handling maintenance requests. This processing is necessary for contract performance.

Communication

Responding to inquiries, sending booking confirmations, providing property information, and addressing service issues. We communicate primarily via email and phone as provided by you.

Billing and Payments

Generating invoices, processing payments, maintaining financial records, and fulfilling tax obligations. Payment processing may involve third-party providers who handle credit card information securely.

Legal Compliance

Meeting requirements under Malaysian rental regulations, tax laws, and the Personal Data Protection Act 2010. This includes maintaining records for specified retention periods and cooperating with lawful requests from authorities.

4. Legal Basis for Processing

Under the PDPA, we process your personal data based on:

Consent: You provide explicit consent when submitting forms or agreeing to our terms. You may withdraw consent at any time, though this may affect our ability to provide services.

Contract Performance: Processing is necessary to fulfill our accommodation agreement with you, including property preparation, service delivery, and billing.

Legal Obligation: We must process certain data to comply with Malaysian tax laws, rental regulations, and the PDPA itself.

5. Data Sharing and Disclosure

We share personal data only when necessary for service delivery or legal compliance:

Property Owners and Building Management

We share tenant names and contact information with property owners and building management companies for lease administration, security registration, and maintenance coordination.

Service Providers

Payment processors, cleaning services, maintenance contractors, and internet providers receive limited data necessary to perform their specific functions. We require these providers to protect your data and use it only for the stated purpose.

Government Authorities

We disclose data to Malaysian tax authorities, immigration departments, or other government bodies when legally required. This includes tenancy registration and tax reporting obligations.

6. Data Security

We implement administrative, technical, and physical safeguards to protect personal data:

Access Controls: Personal data is accessible only to authorized staff members who require it for their job functions. Access is logged and reviewed periodically.

Encryption: Data transmitted over the internet is encrypted using SSL/TLS protocols. Stored data containing sensitive information (identification documents, payment details) is encrypted at rest.

Secure Storage: Physical documents are stored in locked cabinets with restricted access. Digital files are maintained on secure servers with regular backups and access logs.

Incident Response: We maintain procedures for detecting, reporting, and responding to data breaches. In the event of a breach affecting your data, we will notify you and relevant authorities as required by law.

7. Data Retention

We retain personal data for specific periods based on business needs and legal requirements:

Active Tenancies: Data is maintained throughout the lease period plus 90 days for final billing and property handover processes.

Financial Records: Billing and payment data is retained for 7 years to comply with Malaysian tax law requirements.

Inquiry Data: Contact information from inquiries that do not result in bookings is retained for 2 years, then deleted unless you have consented to marketing communications.

Lease Agreements: Executed lease documents including identification copies are retained for 7 years after lease termination for legal compliance and potential dispute resolution.

8. Cookies and Tracking

Our website uses cookies and similar technologies. For detailed information about the cookies we use and your choices, please see our Cookie Policy.

We use Google Analytics to understand website traffic patterns and improve user experience. This involves collecting anonymous usage data. You can opt out of Google Analytics through browser settings or Google's opt-out tools.

9. Your Rights

Under Malaysia's PDPA, you have specific rights regarding your personal data:

Right to Access

You may request a copy of the personal data we hold about you. We will provide this within 21 days of your request.

Right to Correction

If your personal data is inaccurate or incomplete, you may request that we correct or complete it. We will update records within 14 days.

Right to Withdraw Consent

Where processing is based on consent, you may withdraw that consent at any time. This does not affect the lawfulness of processing before withdrawal.

Right to Limit Processing

You may request that we limit how we use your data, though this may affect our ability to provide services.

To exercise these rights, contact us at [email protected]. We may require identity verification before processing requests.

10. Children's Privacy

Our services are intended for adults 18 years and older. We do not knowingly collect personal data from individuals under 18 without parental consent. If you believe we have inadvertently collected data from a minor, please contact us immediately.

11. Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. Material changes will be communicated via email to active clients or through a prominent notice on our website. The "Last Updated" date at the top indicates when the policy was most recently revised.

12. Contact Information

For questions about this Privacy Policy or how we handle your personal data, please contact:

Nimbara

7 Jalan Ampang Hilir

55000 Kuala Lumpur, Malaysia

Email: [email protected]

Phone: +60 3-4267 8135

13. Supervisory Authority

If you believe we have not handled your personal data appropriately, you have the right to lodge a complaint with the Personal Data Protection Commissioner of Malaysia. Contact details are available at www.pdp.gov.my.