Key definitions
This section explains terms used throughout this policy to help you understand how we treat personal information in the context of property transaction advisory services.
SoraTestate operates dedicated buyer advisory services for property transactions in Malaysia. We collect and process personal data only as necessary to deliver advisory, due diligence and transaction coordination services. Our approach follows legal requirements and industry best practices to protect client information, maintain professional confidentiality and ensure data is handled responsibly during engagement, transaction and required retention periods.
This section explains terms used throughout this policy to help you understand how we treat personal information in the context of property transaction advisory services.
We collect data to evaluate property eligibility, perform due diligence, facilitate communications and coordinate with transaction counterparties. Collection is limited to information necessary for those tasks.
Directly provided data typically comes from engagements, forms, emails and documents you supply to enable advisory and transaction activities.
We also gather technical and behavioural data automatically when you use our website or engage with our online services to operate securely and improve service delivery.
In some cases we receive data about you from trusted third parties to complete a transaction or validate information provided by a client.
We process personal data for specific, documented purposes necessary to provide advisory services and comply with legal obligations relevant to property transactions in Malaysia.
We rely on a combination of lawful bases to process personal data. The applicable basis depends on the specific activity and the relationship with the individual.
SoraTestate uses cookies and similar technologies to enable site functionality, measure performance and provide a secure user experience. You can manage cookie preferences through your browser settings or our cookie banner.
We use session cookies for site operation, persistent cookies for preferences, and analytics cookies to understand site usage. No intrusive profiling cookies are used without consent.
Categories include strictly necessary, performance/analytics and functional cookies used to maintain sessions and collect aggregated usage data.
You may disable or delete cookies via your browser, but certain site features may be affected. For site-specific settings use the cookie preference tool presented on your first visit.
Full cookie details and management
We share personal data only as required to carry out transaction services or to comply with law. Third-party recipients are selected for reliability and confidentiality safeguards.
When necessary to provide services, personal data may be transferred to jurisdictions outside Malaysia. Transfers take place only where appropriate safeguards are in place to ensure adequate protection of personal data.
Safeguards include contractual data processing agreements, data access limitations and assessment of recipient security measures. Transfers are limited to jurisdictions with adequate protections or to providers who commit to equivalent safeguards.
We retain personal data only as long as necessary to deliver services, comply with legal obligations and meet legitimate business needs.
Client account records and key transaction documents are retained for a period consistent with regulatory requirements and professional recordkeeping standards, typically several years after completion.
Communications and advisory notes are retained for operational reasons and dispute resolution; retention periods reflect the nature of the engagement and applicable law.
System logs and access records are retained for security monitoring and compliance purposes for a limited period.
When retention periods expire or upon verified request where permitted, personal data will be securely deleted or anonymised in accordance with our deletion procedures.
SoraTestate implements administrative, technical and physical controls to protect personal data against unauthorised access, disclosure, alteration or destruction. Security measures are reviewed periodically to align with evolving risks and industry practices.
Subject to applicable law, individuals may exercise rights related to their personal data. Requests will be processed in line with verification requirements and legal constraints.
SoraTestate, operating from Malaysia, recognizes EU data protection principles and, where SoraTestate processes personal data of individuals in the EEA, will apply GDPR-aligned protections to those processing activities as appropriate and required by law.
GDPR-related rights and obligations described here apply to personal data of individuals located in the European Economic Area when SoraTestate is the data controller or otherwise processes such data in a context that triggers GDPR application. This does not supersede local legal requirements in Malaysia but reflects our approach to cross-border data handling for EEA individuals.
If you believe SoraTestate has not addressed your GDPR-related concern satisfactorily, you may lodge a complaint with the appropriate supervisory authority in your EEA member state after first contacting our data protection contact detailed below to seek resolution.
To make a request to access, correct, delete, or restrict your personal data, contact our Data Protection Officer in writing with sufficient details to locate the information and a copy of a government-issued ID for identity verification. Provide the nature of your request and any relevant timeframes. Our office details are listed below.
SoraTestate aims to respond to verifiable requests within 30 days. For complex or multiple requests we may require a reasonable extension, not exceeding an additional 60 days, and will inform you of any extension and the reasons for it.
We use personal data to send relevant information about services, events, and updates about SoraTestate only when we have a lawful basis to do so. Marketing may be based on consent or legitimate interest, depending on the channel and context.
You may opt out of marketing communications at any time by following the unsubscribe link in emails, adjusting your account preferences, or contacting our office. Opt-out requests will be processed promptly and in accordance with applicable law.
SoraTestate does not knowingly collect personal data from individuals under 18 without verifiable parental or guardian consent. If we become aware that we have collected personal data of a child under 18 without appropriate consent, we will take steps to remove the data as required by law.
Our website and communications may include links to third-party sites or services. SoraTestate is not responsible for the privacy practices or content of those third parties. We recommend reviewing the privacy policies of any external sites you visit.
SoraTestate may update this privacy policy to reflect changes in our practices or legal obligations. The policy was last updated on 19-02-2026. Material changes will be communicated through the website or other direct channels where appropriate.
Contact SoraTestate: SoraTestate, 23, Jalan Wau A 11/A, Seksyen 11, 40100 Shah Alam, Selangor, Malaysia. Business ID: 018848818026. Phone: +60125258100. Email: [email protected]. For data protection enquiries, please include 'Data Protection' in the subject line and provide sufficient details to identify your request.
+60125258100
23, Jalan Wau A 11/A, Seksyen 11, 40100 Shah Alam, Selangor, Malaysia