Privacy Policy & Personal Data Protection Notice
This Privacy Policy & Personal Data Protection Notice (“Notice”) explains how Mesra Regulatory Consulting Sdn. Bhd. (trading under the trade name “DuoGate”) collects, uses, stores, discloses and protects personal data in accordance with the Personal Data Protection Act 2010 of Malaysia.
We are a Malaysia-based regulatory consulting company providing services for medical devices, in-vitro diagnostics, cosmetics and related healthcare products, including but not limited to regulatory strategy, product registration support, dossier preparation, authorized representative services and/or local registrant support, licensing support and post-market regulatory support.
1. Personal Data We Collect
We may collect personal data from clients, prospective clients, business partners, manufacturers, distributors, suppliers, consultants and website visitors. This may include:
- name, company name, job title and contact details;
- email address, phone number, business address and country;
- information submitted through our website, enquiry forms, email, calls, meetings or events;
- project-related information, regulatory documents and supporting documents;
- billing, payment and transaction information;
- technical website information such as IP address, cookies and website usage data.
For regulatory projects, documents provided to us may occasionally contain personal data of third parties, such as authorized signatories, contact persons, healthcare professionals or other individuals.
2. Source of Personal Data
We may collect personal data directly from you, your organization, clients, manufacturers, distributors, appointed representatives, consultants, publicly available sources, regulatory authority portals, business directories, exhibitions, events, or other parties involved in the regulatory project.
Where you provide personal data relating to another individual, you hereby confirm that you have the authority to do so and that any required notice, consent or other legal basis has been obtained. We shall not be held responsible or liable for any loss, damage, claim or liability arising from or in connection to any breach of confidentiality obligations by you.
3. Purpose of Collection and Use
We may collect and use personal data for the following purposes:
- to respond to enquiries and requests;
- to prepare quotations, proposals and service agreements;
- to provide regulatory consulting and project support services;
- to review, prepare and support regulatory submissions;
- to communicate with clients, authorities, consultants, service providers and business partners;
- to manage billing, payment, accounting and administrative matters;
- to comply with legal, regulatory, tax, audit and business record requirements; and
- to send relevant business updates, regulatory updates or service information, where permitted.
For the avoidance of doubt, the abovementioned list shall be non-exhaustive and may include matters not expressly listed therein.
4. Sensitive Personal Data
Due to the nature of medical device and cosmetic regulatory work and services, client-provided documents may occasionally contain sensitive personal data, including but not limited to health-related information.
Sensitive personal data should only be provided to us where it is necessary for the relevant regulatory purpose and where the party providing the data has obtained all required consents, notices or legal authorizations. We may request that unnecessary sensitive personal data be removed, redacted, anonymized or replaced with non-identifiable information. We shall not be held responsible or liable for any loss, damage, claim or liability arising from or in connection to any breach of confidentiality obligations by you.
5. Disclosure of Personal Data
We may disclose personal data where necessary to:
- our employees, directors, consultants and authorized personnels;
- clients, manufacturers, distributors, importers or appointed local representatives involved in the project;
- regulatory authorities, government agencies, conformity assessment bodies, certification bodies, laboratories or similar parties;
- professional advisers such as lawyers, auditors, accountants and company secretaries;
- IT, cloud storage, email hosting, website hosting and administrative service providers;
- banks, payment processors and financial institutions; and/or
- any party where required or permitted by law.
We hereby undertake that we shall not sell, dispose, disclose and/or release any personal data to unrelated third parties without your prior written consent.
6. Cross-Border Transfer
As our services may involve overseas clients, foreign manufacturers, regional consultants, cloud systems and regulatory authorities in other countries, personal data may be transferred to, stored in or accessed from outside Malaysia.
Where this occurs, we will take reasonable steps to ensure that the personal data is handled securely and used only for the purposes described in this Notice.
7. Security and Retention
We take reasonable steps to protect personal data against any loss, misuse, unauthorized access, disclosure, alteration or destruction.
We retain personal data only for as long as necessary for the purposes stated in this Notice, including but not limited to providing our services, complying with legal or regulatory requirements, maintaining business records, resolving disputes and supporting future regulatory follow-up where applicable.
When personal data is no longer required, we shall take rasonable steps to securely delete, destroy, anonymize or archive the same.
8. Your Rights
Subject to applicable law, you may request access to or correction of your personal data held by us. You may also withdraw your consent or request that we limit the processing of your personal data, subject to applicable legal, contractual and regulatory requirements.
To exercise your rights, please contact us using the contact details below. We may request additional information to verify your identity before processing your request.
9. Consequences of Not Providing Personal Data
Providing personal data is generally voluntary. However, if you do not provide the required information, we may not be able to respond to your enquiry, provide a quotation, enter into an agreement, provide our services, support regulatory submissions, issue invoices or comply with applicable requirements.
10. Cookies
Our website may use cookies or similar technologies to improve website functionality, analyze website traffic and enhance user experience. You may disable cookies through your browser settings, but some website features may not function properly.
11. Updates to This Notice
We may update this Notice from time to time. The latest version will be made available on our website.
12. Contact Us
For any questions, requests or complaints relating to personal data, please contact sales@duogateregulatory.com.