LEGAL
Privacy Policy
Last Updated: 15 January 2026
1. Introduction
Mistborne ("we", "us", "our") operates from 3 Jalan Marina, 79100 Iskandar Puteri, Johor, Malaysia. We are committed to protecting the personal data of anyone who contacts us, makes a booking, or uses our website at miistboory.pro.
This Privacy Policy describes what personal data we collect, how we use it, and the rights you have under Malaysia's Personal Data Protection Act 2010 (PDPA). By contacting us or submitting a booking enquiry, you acknowledge the practices described here.
For questions or data-related requests, write to: [email protected]
2. Data We Collect
We collect personal data only when you provide it to us — through the website contact form, by email, or by telephone. The categories of data we may collect include:
- Name and contact details (email address, phone number)
- Enquiry content — tour preferences, dates, group size
- Dietary and accessibility requirements relevant to tour participation
- Technical data automatically collected by the website — IP address, browser type, pages visited, time of visit
We do not collect payment card details through this website. Any payments are processed separately through channels we will communicate to you directly.
3. Legal Basis for Processing
Under the PDPA, we process your personal data on the following bases:
- Consent: When you submit the website contact form
- Contractual necessity: To communicate about and fulfil a tour booking
- Legitimate interest: To maintain records relevant to safety and operational planning
4. How We Use Your Data
- To respond to enquiries and confirm tour bookings
- To coordinate tour-related logistics — catering, departure timing, crew preparation
- To send operational updates relevant to your booking
- To maintain internal records for safety and insurance purposes
- To understand how visitors use our website and improve it over time
We do not use your data for unsolicited marketing. We will not contact you with promotional material unless you have specifically asked us to.
5. Data Sharing
We do not sell your personal data. We may share it in limited circumstances:
- Catering supplier: Dietary requirements shared with our Johor Bahru catering partner where relevant to your tour
- Analytics provider: Aggregated, anonymised data shared with website analytics tools
- Legal obligation: Where required by Malaysian law or in connection with a legal proceeding
6. Data Retention
We retain personal data for as long as is necessary for the purpose it was collected:
- Enquiries that do not result in a booking: deleted within 12 months
- Completed tour bookings: retained for 3 years for insurance and safety records
- Website analytics: aggregate data retained for up to 26 months
7. Data Protection Measures
We take reasonable steps to protect your data:
- The website is served over HTTPS (encrypted connection)
- Internal records are stored on access-controlled systems
- Staff with access to booking data are instructed on confidentiality obligations
- We review our data handling practices periodically
8. Cookies
Our website uses cookies to enable basic site functionality and understand how visitors use the site. For full details on the types of cookies used and how to manage your preferences, see our Cookie Policy.
9. Your Rights
Under the PDPA, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Withdraw consent to data processing
- Request deletion of data we are not required by law to retain
- Object to processing based on legitimate interest
To exercise any of these rights, write to [email protected]. We will respond within 21 days.
10. Third-Party Links
Our website may contain links to external sites. We are not responsible for the privacy practices of those sites and encourage you to review their policies independently.
11. Children
Our website is not directed at individuals under 18 years of age. We do not knowingly collect personal data from minors. Booking enquiries on behalf of a group that includes minors should be made by an adult.
12. Updates to This Policy
We may update this policy from time to time. Material changes will be noted with a revised "Last Updated" date at the top of this page. Continued use of the website following any change constitutes acceptance of the revised policy.
13. Contact for Data Enquiries
For any questions about this policy or about how we handle your personal data:
Mistborne
3 Jalan Marina, 79100 Iskandar Puteri, Johor, Malaysia
Email: [email protected]