Legal
Privacy notice
Last updated 12 August 2026
CloudFabric Path Advisory (“we”) is a Kuala Lumpur practice. This notice explains how we handle personal data on this website and, at a high level, during a treasury application review. Engagement letters and a separate evidence protocol apply once fieldwork starts.
Who we are
Practice address: METROPOINT 63, 65, 67 & 69, Kuala Lumpur, Wilayah Persekutuan, 50100, Malaysia. Telephone +60 03-26916022. Email engagements@cloudfabricpath.digital. We process personal data in connection with professional services and the operation of this site, in line with the Personal Data Protection Act 2010 as applicable to our activities.
What we collect from the website
If you use the enquiry form, we receive the name, organisation, email, optional phone number, application name, and message you type. The form is acknowledged by a static response file; treat it as an unencrypted public form. Server logs of a typical host may include IP address, browser type, and pages requested. We do not run advertising pixels on this site.
Cookies
A single preference can be stored on your device so the cookie banner does not reappear every visit. Rejecting that storage does not block reading, navigation, or sending an enquiry. See the cookie notice.
What we collect during an engagement
A review of a treasury application typically involves names and logins of operators, approvers, and IT support; email addresses for scheduling; and system extracts that may include user IDs. We ask clients to minimise personal data in samples (for example, masking beneficiary names where the path can still be tested). We do not seek customer-bank retail data. Payment-file samples should be limited to what the letter allows.
Why we use the data
Website enquiries: to reply, to judge whether we can take the work, and to prepare a letter of engagement. Contracted work: to perform the review, keep working papers, invoice, and meet professional record-keeping. We do not sell contact lists or use enquiry details for unrelated marketing lists.
Who we share with
We do not publish enquiry contents. During an engagement we may speak with your internal audit, IT, or bank-relationship contacts because you asked us to. Hosting and email providers process data as processors to keep the site and inbox running. We do not place your treasury extracts on this public website.
Retention
Unsuccessful enquiries are kept only as long as needed to complete the correspondence, then deleted from active mailboxes on a routine clear-down, unless a legal hold applies. Engagement working papers are retained for the period stated in the letter, typically several years after the report date, then destroyed or returned as agreed.
Transfers
The practice is in Malaysia. If a group treasurer sits outside Malaysia and emails us, that correspondence necessarily crosses a border. We do not use the site as a cross-border data room.
Your choices
You may ask what personal data we hold about you from a website enquiry, ask us to correct it, or ask us to delete an enquiry that did not become an engagement. Rights during a live audit may be limited where the data is part of a client’s control evidence. Write to engagements@cloudfabricpath.digital.
Security
The public form is not the channel for production payment files. Once engaged, we agree how extracts move (typically a client-controlled share or an encrypted drop you nominate). Lost devices and mailbox access are controlled inside the practice; we will tell the client if an incident affects their data.