This Privacy Policy explains how FT IDEAS ENTERPRISE collects, uses, discloses, transfers, retains and protects your personal data when you visit https://farhanterubos.com, subscribe to our newsletter, download our free resources, create an account, or purchase any of our products.
This Policy is issued as a written notice under section 7 of the Personal Data Protection Act 2010 (Act 709) of Malaysia, as amended by the Personal Data Protection (Amendment) Act 2024, and constitutes our privacy notice for the purposes of Articles 13 and 14 of the UK General Data Protection Regulation and Regulation (EU) 2016/679 (EU GDPR) where those instruments apply to you.
1. Who we are
The data controller (referred to in the Personal Data Protection Act 2010 as the “data user” or, following the 2024 amendments, the “data controller”) responsible for your personal data is:
| Item | Details |
|---|---|
| Registered business name | FT IDEAS ENTERPRISE |
| Business registration number | SSM No. 201703313130 (002706763-U) |
| Business form | Sole proprietorship registered in Malaysia |
| Registered business address | A-6-7, Idaman Sutera Condominium, Jalan Meranti, 53100 Kuala Lumpur, Wilayah Persekutuan Kuala Lumpur, Malaysia |
| Website | https://farhanterubos.com |
| Email (including privacy and data protection enquiries) | [email protected] |
| Telephone | +60 17-719 4960 |
| Trading names covered by this Policy | Farhan Terubos, HIS™, FT IDEAS |
In this Policy, “we”, “us” and “our” mean FT IDEAS ENTERPRISE. “You” and “your” mean the individual whose personal data we process. “Site” means https://farhanterubos.com and any subdomain of it. “Services” means the Site together with our newsletters, free resources, podcast, online courses, membership area and any other product or service we make available.
1.1 Data protection contact
All privacy enquiries, data subject requests and complaints should be directed to [email protected] with the subject line “Data Protection Request”. We do not currently meet the thresholds requiring the mandatory appointment of a Data Protection Officer under the Personal Data Protection (Amendment) Act 2024 and the Commissioner’s Guidelines on the Appointment of Data Protection Officer. If that changes, we will appoint a Data Protection Officer, notify the Commissioner within twenty-one (21) days as required, and update this Policy.
2. Scope of this Policy
This Policy applies to personal data we process in the course of commercial transactions and related activities, including where you:
- visit or browse the Site;
- subscribe to the HIS™ Newsletter or download a free resource such as the ebook SYSTEMS, NOT CERTIFICATES;
- register for or log in to an account or membership area;
- purchase, access or use any paid product, including our online course;
- contact us by email, contact form, telephone or social media;
- listen to the HIS™ Podcast through a player embedded on the Site; or
- click a link we have published, including a shortened or tracked link.
This Policy does not apply to third-party websites, platforms or applications that we link to. Those operators have their own privacy policies and we are not responsible for them. See Section 18.
3. Legal framework
We process personal data in accordance with:
- the Personal Data Protection Act 2010 (Act 709) of Malaysia, as amended by the Personal Data Protection (Amendment) Act 2024 (Act A1719), together with its subsidiary legislation, standards, codes of practice and the Commissioner’s published guidelines (collectively, the “PDPA”);
- the Electronic Commerce Act 2006 (Act 658);
- the Consumer Protection Act 1999 (Act 599) and the Consumer Protection (Electronic Trade Transaction) Regulations 2024;
- the Communications and Multimedia Act 1998 (Act 588); and
- where and to the extent applicable to you as a visitor located in the United Kingdom or the European Economic Area, the UK GDPR and the EU GDPR, together with the applicable national implementing legislation and the ePrivacy Directive 2002/58/EC as implemented locally.
Malaysian law is the primary regime governing this Policy. The UK and EU provisions are applied as an additional layer of protection for individuals located in those territories, and are set out separately in Section 14.
4. The personal data we collect
We collect only the personal data we actually need. The table below sets out what we collect, at which point, and whether providing it is obligatory.
| Touchpoint | Personal data collected | Obligatory? |
|---|---|---|
| Browsing the Site | IP address; approximate location derived from IP address; browser type and version; operating system; device type; referring URL; pages viewed; date, time and duration of visit; cookie and similar identifiers. | Automatic. Non-essential collection is subject to your consent (see Section 8 and our Cookie Policy). |
| Newsletter and free ebook opt-in | Name (or the name you choose to give); email address; date and time of subscription; IP address at the point of subscription (as proof of consent); subsequent email open and click activity. | Yes. Without an email address we cannot deliver the newsletter or the ebook. |
| Account registration | Name; username; email address; encrypted password; account creation date; login timestamps; IP address; membership level and access entitlements. | Yes. Without these we cannot create or secure your account. |
| Checkout and purchase | Billing name; billing address (including country, state and postcode); email address; telephone number; order details; order date; transaction reference; payment status; the last four digits and card type or payment method as reported back to us by the payment processor. | Yes. Without these we cannot process a payment, issue a receipt or meet our tax record-keeping obligations. |
| Contact form and email correspondence | Name; email address; the content of your message and any attachments; correspondence history. | Yes, to the extent needed to answer you. |
| Testimonials and user-submitted content | Name or display name; the content you submit; any images you choose to include; the context in which it was submitted. | No. Entirely voluntary. |
| Clicking a shortened or tracked link we publish | IP address; device and browser information; click timestamp; referring source; advertising and analytics identifiers set by the link-shortening service and any advertising pixels it carries. | Subject to consent where required. |
4.1 Data we do not collect
We do not collect, and we ask you not to send us:
- Sensitive personal data as defined in section 2 of the PDPA, meaning personal data consisting of information as to your physical or mental health or condition, political opinions, religious beliefs or other beliefs of a similar nature, the commission or alleged commission of any offence, or any other personal data as the Minister may determine by order published in the Gazette. Where UK or EU GDPR applies, this also means the special categories of personal data in Article 9 and criminal offence data in Article 10;
- your identity card (MyKad), passport or other government identification number;
- your date of birth;
- your employer’s name, your job title, your salary or your income;
- full payment card numbers, card verification values or bank account credentials; and
- biometric data.
If you send us sensitive personal data unprompted, we will delete it as soon as reasonably practicable unless we are required to retain it by law. Please do not include such information in a contact form or support email.
4.2 Physical address
We do not routinely collect your physical address. We may collect a billing address where a payment processor requires it for fraud screening or tax purposes, and we will collect a delivery address if and when we begin to sell physical goods such as a printed book. If we begin to collect delivery addresses, we will update this Policy before doing so.
4.3 AI tools
Our content teaches the use of third-party artificial intelligence tools. We do not operate an AI chatbot on the Site, we do not record, transcribe or store any prompt or conversation you have with any AI tool, and we do not submit your personal data to any AI model provider for training. Any interaction you have with a third-party AI tool is governed by that provider’s own terms and privacy policy, not by ours.
4.4 Recordings
We do not currently run webinars, live calls or any other activity in which we record your voice or image. If we introduce them, we will tell you before any recording begins and obtain your consent where required.
5. How we collect your personal data
We collect personal data:
- directly from you, when you fill in a form, subscribe, register, purchase or contact us;
- automatically, through cookies, server logs, analytics tags and tracked links, as described in our Cookie Policy;
- from our service providers, such as a payment processor confirming that a transaction has succeeded or failed; and
- from publicly available sources, only where you have chosen to interact with us publicly, for example by commenting on or tagging one of our social media posts.
6. Why we process your personal data, and on what legal basis
Under the PDPA, we may only process personal data with your consent or where one of the grounds in section 6(2) of the PDPA applies. Where the UK or EU GDPR applies, we must additionally identify a lawful basis under Article 6. The table below sets out both.
| Purpose | Data used | PDPA basis | GDPR Art. 6 basis (UK/EEA only) |
|---|---|---|---|
| Delivering the free ebook and the HIS™ Newsletter | Name; email; engagement data | Your consent (s.6(1)(a)) | Consent — Art. 6(1)(a) |
| Creating and administering your account, and giving you access to products you have bought | Account data; entitlement data | Necessary for the performance of a contract with you (s.6(2)(b)) | Contract — Art. 6(1)(b) |
| Taking payment, issuing receipts and preventing payment fraud | Billing and transaction data | Necessary for the performance of a contract, and compliance with legal obligations (s.6(2)(b), s.6(2)(a)) | Contract — Art. 6(1)(b); Legal obligation — Art. 6(1)(c); Legitimate interests — Art. 6(1)(f) |
| Answering your enquiries and providing support | Contact data; correspondence | Necessary for the performance of a contract or at your request before entering into one (s.6(2)(b)) | Contract — Art. 6(1)(b); Legitimate interests — Art. 6(1)(f) |
| Keeping accounting, tax and business records | Transaction data | Compliance with legal obligations (s.6(2)(a)), including the Income Tax Act 1967 | Legal obligation — Art. 6(1)(c) |
| Securing the Site, detecting abuse and enforcing our Terms of Service and Acceptable Use Policy | Log data; account data; access data | Our legitimate interests in protecting our business and our lawful rights (s.6(2)(f)) | Legitimate interests — Art. 6(1)(f) |
| Measuring how the Site is used so we can improve it | Analytics and cookie data | Your consent (s.6(1)(a)) | Consent — Art. 6(1)(a) |
| Marketing and advertising measurement through tracked links and advertising pixels | Click, device and advertising identifiers | Your consent (s.6(1)(a)) | Consent — Art. 6(1)(a) |
| Publishing a testimonial you have given us | Name or display name; the content you submitted | Your consent (s.6(1)(a)) | Consent — Art. 6(1)(a) |
| Establishing, exercising or defending legal claims | Any relevant data | Necessary for legal proceedings or obtaining legal advice (s.6(2)(c) and s.39) | Legitimate interests — Art. 6(1)(f); Legal claims — Art. 9(2)(f) where relevant |
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal, and it does not affect processing carried out on a different basis. See Section 12.
Where we rely on legitimate interests, we have carried out a balancing exercise and concluded that our interest does not override your rights and freedoms. You may ask us for a summary of that assessment at any time.
7. What happens if you do not provide personal data
Section 7(2) of the PDPA requires us to tell you the consequences of not supplying personal data. In summary:
- If you do not give us an email address, we cannot send you the free ebook or the newsletter.
- If you do not complete account registration, we cannot give you access to any paid product.
- If you do not provide billing details, we cannot take payment and no contract will be formed.
- If you refuse strictly necessary cookies, core parts of the Site — including login and checkout — will not work.
- If you refuse non-essential cookies, the Site will still work normally. Only measurement and advertising features are affected.
8. Cookies and similar technologies
We use cookies, pixels, tags, local storage and similar technologies. Strictly necessary cookies are set without consent because the Site cannot function without them. All other categories are set only where you have given consent, where consent is required.
Full details — including the categories we use, the third parties involved, storage durations and how to withdraw consent — are set out in our separate Cookie Policy, which forms part of this Policy.
We honour the Global Privacy Control (GPC) signal and browser “Do Not Track” preferences where our systems are able to detect them, and we treat a GPC signal as a valid withdrawal of consent to non-essential cookies and to any sale or sharing of personal data for cross-context behavioural advertising.
9. Who we share your personal data with
We disclose personal data only where it is necessary for the purposes set out in Section 6. The following table names every category of recipient and the actual service involved.
| Recipient | Role | What they receive | Where processed |
|---|---|---|---|
| Hostinger International Ltd | Website hosting and server infrastructure for the Site, including the database in which account, subscriber and order records are stored | All data submitted to or generated by the Site | Data centre located in Malaysia. Support and administration may be provided from Lithuania and other locations. |
| WordPress and WooCommerce (self-hosted software running on our own hosting) | Website and e-commerce platform | Account, order and content data | Malaysia (on our host) |
| MailPoet (Automattic Inc.) | Newsletter and email marketing plugin. Subscriber records are stored in our own database on our host; where we use the MailPoet Sending Service to deliver messages, delivery is routed through Automattic’s infrastructure | Name; email; engagement data | Malaysia (list storage); United States and other locations (sending service, where used) |
| Ultimate Membership Pro (self-hosted plugin) | Membership, account and access control | Account and entitlement data | Malaysia (on our host) |
| Stripe, Inc. / Stripe Payments Malaysia Sdn. Bhd. | Payment processing | Billing name; email; billing address; amount; card data collected directly by Stripe (we never receive full card numbers) | United States, Ireland, Singapore and other Stripe locations |
| PayPal (Europe) S.à r.l. et Cie, S.C.A. / PayPal Pte. Ltd. | Payment processing | Name; email; transaction data | United States, Luxembourg, Singapore |
| Billplz Sdn. Bhd. | Malaysian payment gateway (FPX / online banking) | Name; email; transaction data | Malaysia |
| Razorpay | Payment processing | Name; email; transaction data | India and other Razorpay locations |
| Google LLC — Google Analytics 4 | Website analytics and measurement | Cookie identifiers; truncated IP address; page and event data | United States and Google regional data centres |
| Switchy | Link shortening, click tracking and the deployment of advertising pixels (including Meta, TikTok, Google and Pinterest pixels) on links we publish | IP address; device and browser data; click data; advertising identifiers | United States and European Union |
| Meta Platforms, TikTok, Google and Pinterest | Advertising measurement and audience building, through pixels carried on our shortened links | Advertising identifiers; click and conversion events | United States and other global locations |
| Google LLC — Gmail / Google Workspace | Business email used to answer support enquiries sent to our support address | Your name, email address and the content of your correspondence | United States and Google regional data centres |
| Beagle Security | Automated security testing of the Site | Technical and log data; no marketing or subscriber data | India / United States |
| Professional advisers, auditors and insurers | Legal, accounting and tax advice | Only what is strictly necessary | Malaysia |
| Regulators, law enforcement and courts | Where we are legally compelled, or where disclosure is necessary to establish, exercise or defend legal claims | Only what is strictly necessary | Malaysia and, where relevant, other jurisdictions |
Where a recipient acts as a data processor on our behalf, we require it by contract to process personal data only on our documented instructions, to keep it confidential, to apply appropriate technical and organisational security measures, and to assist us with data subject requests and breach notification.
10. Transfers of personal data outside Malaysia
Our primary storage — the Site database, subscriber list, account records and order records — is located in a data centre in Malaysia.
However, several of the service providers named in Section 9 process personal data outside Malaysia. Section 129 of the PDPA, as amended with effect from 1 April 2025, no longer relies on a Minister-gazetted “whitelist” of approved destinations. Instead, a data controller may transfer personal data outside Malaysia where one of the statutory conditions is met.
We rely on the following conditions in section 129 of the PDPA:
- the destination has in force a law that is substantially similar to the PDPA, or that serves the same purposes, or ensures an adequate level of protection at least equivalent to that afforded by the PDPA;
- you have given your consent to the transfer;
- the transfer is necessary for the performance of a contract between you and us, or for the conclusion or performance of a contract between us and a third party which is entered into at your request or is in your interests; or
- we have taken all reasonable precautions and exercised all due diligence to ensure that the personal data will not be processed in a manner that would, if it took place in Malaysia, contravene the PDPA.
Where the UK or EU GDPR applies to a transfer, we rely on the European Commission’s Standard Contractual Clauses (or the UK International Data Transfer Agreement / UK Addendum), or on an applicable adequacy decision, and we carry out a transfer risk assessment where required.
You may request a copy of the safeguards applying to a specific transfer by writing to [email protected].
11. How long we keep your personal data
We keep personal data only for as long as it is necessary for the purpose for which it was collected, and then we delete or irreversibly anonymise it. Our retention periods are:
| Category | Retention period | Reason |
|---|---|---|
| Newsletter subscriber records | Until you unsubscribe, or after 24 months of continuous inactivity (no opens and no clicks), whichever is earlier | Consent-based processing must not continue indefinitely |
| Unsubscribe / suppression record | Retained indefinitely, in minimised form (a hashed or plain email address only) | We are required to honour your opt-out. We cannot do that if we delete the record of it. |
| Account data | For the duration of your account. On deletion, removed from live systems within 30 days and purged from encrypted backups within a further 90 days | No longer necessary once the account ends |
| Purchase, invoice and accounting records | 7 years from the end of the relevant year of assessment | Required by section 82 and section 82A of the Income Tax Act 1967, and by the Sales Tax Act 2018 / Service Tax Act 2018 where applicable |
| Course access and entitlement records for lifetime-access products | For as long as the product is offered, plus 7 years | Necessary to honour the licence you bought and to evidence it |
| Support correspondence | 24 months from the last message in the thread | Service quality and dispute handling |
| Server, security and access logs | 12 months | Security monitoring and incident investigation |
| Analytics data | In accordance with the retention setting configured in Google Analytics 4, currently 14 months | Measurement |
| Consent records (cookie and marketing consent) | 3 years from the date consent was given or withdrawn | To evidence compliance |
| Records relating to an actual or threatened legal claim | Until the claim is finally resolved plus the applicable limitation period, being 6 years under the Limitation Act 1953 | Establishing, exercising or defending legal claims |
12. Your rights
You have the following rights in relation to your personal data.
12.1 Rights under the Malaysian PDPA
| Right | What it means | Statutory source |
|---|---|---|
| Right of access | To be informed whether we process your personal data, and to be supplied with a copy of it | PDPA s.30 |
| Right to correct | To require us to correct personal data that is inaccurate, incomplete, misleading or not up to date | PDPA s.34 |
| Right to withdraw consent | To withdraw, by written notice, any consent you have given to the processing of your personal data | PDPA s.38 |
| Right to prevent processing likely to cause damage or distress | To require us, by written notice, to stop or not begin processing that is causing or likely to cause substantial damage or distress to you or another person | PDPA s.42 |
| Right to prevent processing for direct marketing | To require us, at any time and free of charge, to stop or not begin processing your personal data for purposes of direct marketing | PDPA s.43 |
| Right to data portability | To request that your personal data be transmitted directly to another data controller, where technically feasible and where the data formats are compatible | PDPA s.43A (in force from 2025) |
| Right to be notified of a data breach | To be notified without unnecessary delay where a personal data breach has caused or is likely to cause significant harm to you | PDPA s.12B |
We will respond to a data access or correction request within twenty-one (21) days of receiving it, as required by section 31 and section 36 of the PDPA. Where we cannot comply within that period, we will tell you and give reasons, and we will comply as soon as practicable and in any event within fourteen (14) days after the expiry of the initial period.
A fee may be prescribed for a data access request under section 30(2) of the PDPA. In practice, we do not charge a fee for a first request in any twelve-month period. We reserve the right to charge a reasonable, cost-based fee for manifestly unfounded, excessive or repetitive requests, and we will always tell you the amount before proceeding.
12.2 Additional rights if you are in the United Kingdom or the European Economic Area
If the UK GDPR or the EU GDPR applies to our processing of your personal data, you also have:
- the right of access, including to a copy of your personal data (Article 15);
- the right to rectification (Article 16);
- the right to erasure, sometimes called the right to be forgotten (Article 17);
- the right to restriction of processing (Article 18);
- the right to data portability in a structured, commonly used, machine-readable format (Article 20);
- the right to object to processing based on legitimate interests, and an absolute right to object to processing for direct marketing purposes (Article 21); and
- the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you (Article 22). We do not carry out such processing.
We will respond to a GDPR request within one (1) month, extendable by up to two further months for complex or numerous requests, in which case we will tell you within the first month and explain why.
12.3 How to exercise your rights
Send a written request to [email protected] with the subject line “Data Protection Request”. Please tell us:
- which right you wish to exercise;
- the email address or account username associated with your personal data; and
- enough detail for us to identify what you are asking for.
We may ask you for information to verify your identity before we act. This is a security measure, not an obstacle: we will not disclose personal data to someone who is not entitled to receive it. We will not ask you for a copy of your identity card, passport or any other government identification document.
If you have an account, you may also delete it yourself from within your account settings. Deleting your account has the effects described in Section 11.
You can unsubscribe from marketing email at any time using the unsubscribe link at the foot of every message, or by emailing us. We action unsubscribes immediately and in any event within ten (10) business days.
13. Security of your personal data
We take practical steps to protect personal data from loss, misuse, modification, unauthorised or accidental access, disclosure, alteration or destruction, as required by the Security Principle in section 9 of the PDPA and by Article 32 of the UK and EU GDPR. Our measures include:
- encryption of data in transit using TLS across the whole Site;
- hashed and salted storage of account passwords — we cannot see your password;
- outsourcing all card processing to PCI-DSS compliant payment processors, so that full card numbers never touch our systems;
- role-based access control and the principle of least privilege for administrative accounts;
- multi-factor authentication on administrative and email accounts;
- regular software, plugin and platform updates;
- periodic automated security testing of the Site; and
- encrypted, access-controlled backups.
No method of transmission over the internet and no method of electronic storage is completely secure. While we apply appropriate safeguards, we cannot guarantee absolute security. You are responsible for keeping your account password confidential and for not sharing your login credentials, as required by our Terms of Service and Acceptable Use Policy.
13.1 Personal data breaches
If a personal data breach occurs, we will:
- assess without undue delay whether the breach causes or is likely to cause significant harm to any affected individual;
- notify the Personal Data Protection Commissioner within seventy-two (72) hours of becoming aware of the breach where notification is required under section 12B of the PDPA and the Commissioner’s Guidelines on Data Breach Notification;
- notify affected individuals without unnecessary delay where the breach is likely to cause significant harm to them;
- where the UK or EU GDPR applies, notify the relevant supervisory authority within 72 hours under Article 33, and notify affected individuals under Article 34 where the breach is likely to result in a high risk to their rights and freedoms; and
- maintain an internal record of every breach, whether or not it is notifiable.
14. Additional information for UK and EEA visitors
If you are located in the United Kingdom or the European Economic Area, the following additional information applies.
- Controller. We are the controller of your personal data. We have not appointed an Article 27 representative in the UK or the EU, on the basis that our processing of UK and EEA personal data is occasional, does not involve large-scale processing of special category data, and is unlikely to result in a risk to the rights and freedoms of individuals. We keep this assessment under review.
- Lawful bases. These are set out in the final column of the table in Section 6.
- International transfers. See Section 10.
- Automated decision-making. We do not carry out automated decision-making producing legal or similarly significant effects, and we do not carry out profiling for those purposes.
- Complaints. See Section 17.
15. Children
Our Services are intended for adults. You must be at least eighteen (18) years of age to create an account, subscribe or make a purchase, consistent with the Age of Majority Act 1971 and section 11 of the Contracts Act 1950.
We do not knowingly collect personal data from anyone under the age of 18, and we do not market to children. If you believe that a person under 18 has provided us with personal data, please contact us and we will delete it without undue delay.
Where the UK or EU GDPR applies, we do not knowingly offer information society services directly to a child within the meaning of Article 8.
16. Marketing communications
We will send you marketing email only where you have opted in, and only about our own products, content and services. We will not pass your email address to a third party for that party’s own marketing.
Every marketing email contains a one-click unsubscribe link. You may also object at any time by emailing us. Once you unsubscribe, we will continue to send you transactional messages where necessary — for example a purchase receipt, an access credential, a security notice or a material change to these policies. You cannot unsubscribe from transactional messages while you hold an account or a live purchase with us.
17. Complaints
If you are unhappy with how we have handled your personal data, please tell us first at [email protected]. We take complaints seriously and we will respond substantively within twenty-one (21) days.
If you remain dissatisfied, you may complain to the relevant supervisory authority:
| If you are in… | Authority | Contact |
|---|---|---|
| Malaysia | Jabatan Perlindungan Data Peribadi (Personal Data Protection Department), Ministry of Digital | www.pdp.gov.my |
| United Kingdom | Information Commissioner’s Office (ICO) | www.ico.org.uk |
| European Economic Area | The supervisory authority of the Member State of your habitual residence, place of work, or the place of the alleged infringement | edpb.europa.eu (list of national authorities) |
Complaining to us does not remove your right to complain to a supervisory authority, and complaining to a supervisory authority does not remove any other legal remedy available to you.
18. Third-party links, embedded content and affiliate links
The Site contains links to third-party websites, tools and platforms, and embeds third-party content such as podcast players and video players. Following such a link or interacting with embedded content may allow that third party to collect personal data about you, including through its own cookies. We do not control those third parties and this Policy does not apply to them. Read their privacy policies.
Some of our outbound links are affiliate links. If you click one and go on to buy, we may receive a commission from the provider at no additional cost to you. Where an affiliate link is used, we disclose it. Clicking an affiliate link shares click, device and referral data with the affiliate network and the merchant.
19. Changes to this Policy
We review this Policy at least annually, and whenever we introduce a new product, a new processor or a materially new processing activity.
If we make a material change, we will update the version number and effective date at the top of this document, publish the revised Policy on the Site, and — where the change materially affects how we use personal data you have already given us — notify subscribers and account holders by email at least fourteen (14) days before the change takes effect. Where a change requires your fresh consent under the PDPA or the GDPR, we will ask for it and will not rely on silence.
19.1 Version history
| Version | Date | Summary of changes |
|---|---|---|
| 1.0 | 2 August 2026 | First issue. Replaces the previous Privacy Policy published on farhanterubos.com. |
20. Language
Section 7(3) of the PDPA requires a written notice given under section 7 to be issued in both the national language (Bahasa Melayu) and the English language. A Bahasa Melayu version of this Policy is published alongside this English version at the same location on the Site.
In the event of any inconsistency between the two versions, the English version prevails for the purposes of interpretation, save where Malaysian law requires otherwise.
21. How to contact us
| Business name | FT IDEAS ENTERPRISE |
| Registration number | SSM No. 201703313130 (002706763-U) |
| Address | A-6-7, Idaman Sutera Condominium, Jalan Meranti, 53100 Kuala Lumpur, Wilayah Persekutuan Kuala Lumpur, Malaysia |
| [email protected] | |
| Telephone | +60 17-719 4960 |
| Website | https://farhanterubos.com |
© FT IDEAS ENTERPRISE. All rights reserved. This Privacy Policy should be read together with our Cookie Policy, Terms of Service, Acceptable Use Policy and Return Policy, each of which is published at https://farhanterubos.com.
