Privacy Policy
Last Updated: 12 March 2025 · Tourbillon Nook, Kuala Lumpur, Malaysia
1. Introduction
Tourbillon Nook ("we", "us", "our") is committed to handling your personal data with care and transparency. This Privacy Policy explains what personal information we collect, how we use it, and the rights you hold over your data. It applies to all personal data collected through our website at tourbillonsi.club and during our service interactions.
We operate in compliance with Malaysia's Personal Data Protection Act 2010 (PDPA). By using our website or engaging our services, you agree to the practices described in this policy.
2. Data We Collect
We collect personal data through the contact form on our website and through direct communication. The categories of data we may collect include:
- Your name
- Email address
- Phone number (if provided)
- Any information you choose to share in your message
- Technical data via cookies (see Section 5)
We collect only what is necessary to respond to your enquiry or deliver a service. We do not require you to provide more than your name and email address to make initial contact.
3. Legal Basis for Processing
We process your personal data on the following legal grounds under the PDPA:
- Consent: When you submit a contact form, you provide consent for us to respond to your message.
- Legitimate interest: Maintaining service records, managing enquiries, and communicating service updates.
- Contractual necessity: When you engage us for a service, processing is necessary to fulfil that agreement.
4. How We Use Your Data
- To respond to your service enquiries or questions
- To communicate updates during an active service (e.g. mid-service findings)
- To produce and retain a written service record for your watch
- To improve our website and services through anonymised analytics
- To comply with legal or regulatory obligations
We do not use your personal data for automated decision-making or profiling. We do not sell or rent your data to third parties for marketing purposes.
5. Cookies and Website Data
Our website uses cookies to function properly and to understand how it is used. For full details on the types of cookies we use and how to manage your preferences, please refer to our Cookie Policy.
6. Data Sharing
We do not share your personal data with third parties except in the following limited circumstances:
- With service providers who assist us in operating the website (e.g. hosting and analytics services), under appropriate data processing agreements
- Where required by law or a lawful authority in Malaysia
- With your explicit consent
Any third-party services we use (such as Google Analytics) are governed by their own privacy policies. We encourage you to review those policies independently.
7. Data Retention
We retain personal data only for as long as necessary:
- Enquiry data not resulting in a service: deleted within 6 months
- Service records: retained for 7 years (to support warranty references and insurance documentation)
- Website analytics data: retained in anonymised form for up to 26 months
8. Data Security
We take reasonable technical and organisational measures to protect your personal data from unauthorised access, loss, or disclosure. These measures include encrypted data transmission (HTTPS), restricted access to stored data, and regular review of our security practices.
In the event of a data breach that affects your personal data, we will notify you and the relevant Malaysian authorities as required by law.
9. Your Rights Under PDPA
Under the Personal Data Protection Act 2010, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate or outdated personal data
- Withdraw consent for data processing where consent is the legal basis
- Request deletion of your personal data, subject to legal retention obligations
- Object to processing for purposes of direct marketing
To exercise any of these rights, please contact us at [email protected]. We will respond within 21 days.
10. Third-Party Links
Our website may contain links to third-party sites. We are not responsible for the privacy practices of those sites. We encourage you to review their privacy policies before providing any personal data.
11. Children's Privacy
Our services are directed to individuals aged 18 and above. We do not knowingly collect personal data from persons under the age of 18. If you believe we have inadvertently collected such data, please contact us so we may delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Any material changes will be noted at the top of this page with a revised "Last Updated" date. Continued use of our website after such changes constitutes your acknowledgement of the updated policy.
13. Contact for Privacy Matters
For any questions, requests, or concerns relating to your personal data, please contact us:
- Email: [email protected]
- Address: 67 Jalan Imbi, 55100 Kuala Lumpur, Malaysia
- Phone: +60 3-2381 9456