Privacy
Policy.
Manifesto Agency (Registration No. 202603059119 (003829903-D)), a sole proprietorship registered in Malaysia with the Companies Commission of Malaysia (SSM) (“Manifesto”, “we”, “us”, “our”), operates the website at manifestoagency.co and provides public relations, influencer marketing, growth marketing, and AI systems services (together, the “Services”).
This Privacy Policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and the rights you have over it. It applies to visitors to our website, people who contact us or submit our audit form, clients and prospective clients, and the media contacts and creators held in our proprietary platforms.
We are the data controller (referred to as a “data user” under Malaysian law) for the personal data described in this policy.
Our principal law is the Malaysian Personal Data Protection Act 2010, as amended by the Personal Data Protection (Amendment) Act 2024 (together, the “PDPA”). Because we work with clients and contacts worldwide, this policy also explains how we handle personal data of individuals in the European Economic Area (“EEA”) and the United Kingdom under the General Data Protection Regulation (“GDPR” and “UK GDPR”) where those laws apply to us.
1. Who we are and how to contact us
| Controller | Manifesto Agency |
| SSM registration number | 202603059119 (003829903-D) |
| Business form | Sole proprietorship registered under the Registration of Businesses Act 1956 |
| Location | Kuala Lumpur, Wilayah Persekutuan, Malaysia |
| General contact | hello@manifestoagency.co |
| Privacy and data protection contact | privacy@manifestoagency.co |
| Data Protection Officer | Data Protection Officer — privacy@manifestoagency.co |
Our full registered business address is on file with the Companies Commission of Malaysia (SSM) and is available on request, or through the SSM e-Info register using the registration number above. For all privacy matters, privacy@manifestoagency.co is the fastest route to a response.
If you want to exercise any of the rights described in Section 10, or you have a question or complaint about how we handle your personal data, write to privacy@manifestoagency.co. We aim to acknowledge every request within 7 days and to respond substantively within 21 days, and in any event within the periods required by applicable law.
2. The personal data we collect
We collect personal data in four ways: you give it to us, we collect it automatically when you use our website, we receive it from our clients, and we compile it from public and licensed sources for our media and creator platforms.
2.1 Data you give us
Contact and enquiry data. When you use our contact form, our growth audit form, book a discovery call, or email us: your name, email address, company name, job title, phone number where you provide it, and the content of your message or form responses.
Growth audit responses. The audit form collects your stated area of interest, your company’s stage and sector, your objectives, and your contact details, so that we can prepare a tailored snapshot and decide whether we are the right fit.
Client and engagement data. If you become a client or work for one: billing and business contact details, the contents of our correspondence, meeting notes, and any personal data contained in materials you share with us for the purposes of the engagement.
Recruitment data. If you apply to work with us: your CV, work history, portfolio, and any information you choose to include in your application.
Subscription data. If you subscribe to our Journal or any mailing list: your email address and your engagement with the emails we send.
2.2 Data we collect automatically
Server log data. Every time you visit our website, our servers and hosting provider receive: your IP address, the date and time of your visit, the pages you requested, the referring URL, the number of bytes transferred, your browser type and version, your device type, and your operating system.
Usage and analytics data. Subject to your cookie consent, we collect: pages viewed, time on page, scroll depth, clicks, navigation paths, approximate location derived from IP address (country, region, and sometimes city), the search terms or campaign that brought you to us, and whether you are a returning visitor.
Cookies and similar technologies. See our Cookie Policy for the full detail of what we set, why, how long it lasts, and how to change your choices.
2.3 Data we receive from clients
When a client engages us, they may share personal data with us so we can perform the Services — for example, contact details for their team, their customer or community data for analysis, or access to their marketing platforms. In these cases the client is the data controller and we act as a data processor on their behalf, processing that data only on their documented instructions and under a written data processing agreement.
2.4 Data in our proprietary platforms
We operate four proprietary platforms — PR OS, Influencer OS, AI Studio, and AgentOS. Two of these hold personal data about people who are not our clients:
PR OS holds professional contact and coverage data about journalists, editors, and publications: name, publication, role or beat, professional email address, professional social handles, published article history, and publication-level traffic and SEO metrics. This data is compiled from publicly available sources such as publication mastheads, article bylines, public professional profiles, and licensed media databases.
Influencer OS holds professional data about content creators and key opinion leaders: handle and display name, platform, publicly available follower and engagement metrics, content categories, audience geography and demographic estimates as reported by platform APIs and analytics vendors, and authenticity signals derived from public engagement patterns.
We process this data on the basis of our legitimate interest in operating a professional media and creator relations business — a form of processing that is standard and expected in the PR industry, and that is directed at people in their professional capacity, not their private lives. We do not sell this data.
If you are a journalist or creator and you do not want to be in our database, tell us at privacy@manifestoagency.co and we will remove you. We will not ask you to justify the request. See Section 10.
2.5 Sensitive personal data
We do not seek to collect sensitive personal data. Under the PDPA as amended, sensitive personal data includes information about physical or mental health, political opinions, religious beliefs, the commission of offences, and biometric data. Please do not include sensitive personal data in enquiry forms or emails unless we have specifically asked for it.
2.6 Children
Our website and Services are directed at businesses and are not intended for anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact privacy@manifestoagency.co and we will delete it.
3. Why we process your personal data, and our legal basis
Under the PDPA we must process personal data lawfully and tell you why. Under the GDPR we must also identify a legal basis. The table below covers both.
| What we do | Why | PDPA basis | GDPR basis (where applicable) |
|---|---|---|---|
| Serve and secure the website | To deliver a working, secure site and prevent abuse | Necessary for our legitimate business operation; you consent by using the site | Art. 6(1)(f) — legitimate interests |
| Respond to enquiries and audit submissions | To answer you and assess fit | Necessary for steps taken at your request prior to a contract | Art. 6(1)(b) — pre-contractual steps |
| Deliver the Services to clients | To perform our engagement | Performance of a contract | Art. 6(1)(b) — contract |
| Billing, accounting, and tax records | To run a lawful business | Compliance with legal obligations | Art. 6(1)(c) — legal obligation |
| Website analytics and performance measurement | To understand and improve the site | Your consent, given through our cookie banner | Art. 6(1)(a) — consent |
| Email marketing and Journal updates | To send you content you asked for | Your consent, with opt-out in every message | Art. 6(1)(a) — consent |
| Operating PR OS and Influencer OS | To run a professional media and creator relations business | Legitimate business interest, professional-capacity data | Art. 6(1)(f) — legitimate interests |
| Recruitment | To assess applications | Steps prior to entering an employment contract | Art. 6(1)(b) / Art. 6(1)(f) |
| Detecting fraud, abuse, and security incidents | To protect our systems, clients, and users | Legitimate interest and legal obligation | Art. 6(1)(f) / Art. 6(1)(c) |
| Establishing or defending legal claims | To protect our legal position | Legitimate interest, legal obligation | Art. 6(1)(f) |
Where we rely on your consent, you can withdraw it at any time — see Section 10.6. Withdrawing consent does not affect processing carried out before you withdrew it.
Where we rely on legitimate interests, we have assessed that our interest does not override your rights and freedoms. You can object to this processing (Section 10.4), and you can ask us for a summary of our assessment.
4. Automated decision-making and profiling
Our platforms score and rank media outlets and creators to inform our recommendations — for example, Influencer OS scores creator profiles for audience authenticity and fit. These scores inform human decisions; they do not by themselves produce legal or similarly significant effects on any individual. A member of our team reviews and decides on every outreach and engagement recommendation.
We do not make decisions about you based solely on automated processing within the meaning of Article 22 GDPR.
5. Who we share your personal data with
We do not sell your personal data. We share it in the following circumstances only.
5.1 Service providers
We use third-party providers to run our business. Each has access only to the data they need, is bound by contract to process it only on our instructions, and may not use it for their own purposes.
| Provider | Purpose | Location |
|---|---|---|
| Vercel Inc. | Website hosting and delivery | USA / global edge network |
| Google LLC (Google Analytics, Google Tag Manager) | Website analytics and tag management | USA / EU |
| Cal.com (self-hosted) | Discovery-call scheduling on our own subdomain | Self-hosted on Vercel |
| Airtable, Inc. | Lead capture and client / prospect records | USA |
| Sendinblue SAS (Brevo) | Transactional and marketing email, contact management | European Union (France) |
5.2 Clients
Where we act as a processor for a client, we return or disclose personal data to that client as part of delivering the Services.
5.3 Professional advisers
Our lawyers, accountants, auditors, and insurers, where they need the data to advise us.
5.4 Legal and regulatory disclosure
We may disclose personal data where we believe in good faith that disclosure is necessary to:
- comply with a legal obligation, court order, or lawful request from a regulator or law enforcement authority, including the Malaysian Personal Data Protection Commissioner;
- enforce our terms or other agreements;
- investigate or prevent fraud, security incidents, or technical problems;
- protect the rights, property, or safety of Manifesto, our clients, our users, or the public;
- establish, exercise, or defend legal claims.
5.5 Business transfers
If we are involved in a merger, acquisition, restructuring, or sale of assets, personal data may be transferred as part of that transaction. We will notify you before your personal data becomes subject to a materially different privacy policy.
6. International transfers of personal data
We are based in Malaysia and we work worldwide. Your personal data will be transferred to and processed in countries outside your own, including the United States and the European Union, where our service providers operate.
Under the PDPA as amended, we may transfer personal data outside Malaysia where the receiving jurisdiction has laws substantially similar to the PDPA or ensures an adequate level of protection, or where another lawful ground for transfer applies. We assess each transfer before we make it.
Under the GDPR, where we transfer personal data of individuals in the EEA or UK to a country without an adequacy decision, we rely on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum where relevant), together with supplementary technical and organisational measures where our assessment says they are needed.
You have the right to receive a copy of the safeguards we rely on. Request one at privacy@manifestoagency.co.
7. How long we keep personal data
We keep personal data only as long as we need it for the purpose we collected it for, or as long as the law requires.
| Data | Retention period |
|---|---|
| Server log files | 30 days |
| Website analytics data | 14 months from collection |
| Enquiry and audit form submissions that do not become clients | 24 months from last contact |
| Client records and engagement files | 7 years from the end of the engagement |
| Accounting, invoicing, and tax records | 7 years, as required by the Income Tax Act 1967 |
| Marketing and mailing list data | Until you unsubscribe, then a suppression record only |
| Recruitment records — unsuccessful applicants | 12 months from the decision, unless you ask us to keep them longer |
| PR OS and Influencer OS records | While the contact is professionally active and the record is accurate; reviewed at least every 24 months; deleted on request |
| Cookie consent records | 12 months, as evidence of consent |
When a retention period ends we delete the data or irreversibly anonymise it. Where deletion is not immediately possible — for example, in a backup — we isolate the data and delete it on the next backup cycle.
8. How we protect personal data
We apply technical and organisational measures appropriate to the risk, including:
- encryption in transit (TLS) across our website and platforms, and encryption at rest for stored personal data;
- role-based access control, so staff can access only the data their role requires;
- multi-factor authentication on all administrative and platform accounts;
- written data processing agreements with every provider that handles personal data for us;
- confidentiality obligations in every staff and contractor agreement;
- logging and monitoring of access to systems holding personal data;
- periodic review of our security measures and provider arrangements.
No system is perfectly secure. We cannot guarantee absolute security of data transmitted over the internet, and we do not claim to. What we can commit to is that we take security seriously, we review it, and we will tell you when something goes wrong.
9. Data breach notification
Under the PDPA as amended, if a personal data breach occurs that causes or is likely to cause significant harm to affected individuals, we will notify the Personal Data Protection Commissioner and the affected individuals within the timeframes set out in the Act and its subsidiary regulations.
Where the GDPR applies, we will notify the relevant supervisory authority within 72 hours of becoming aware of a breach where it is likely to result in a risk to individuals’ rights and freedoms, and we will notify affected individuals without undue delay where the risk is high.
We maintain an internal breach register and incident response procedure.
10. Your rights
You have the following rights. All of them are exercised by writing to privacy@manifestoagency.co. We will not charge you a fee, and we will not ask you to explain why you are making the request. We may ask you to verify your identity before we act, to make sure we are not disclosing your data to someone else.
10.1 Right of access
You can ask us to confirm whether we hold personal data about you and to give you a copy of it, along with information about how we use it.
10.2 Right to correction
You can ask us to correct personal data that is inaccurate, and to complete data that is incomplete.
10.3 Right to erasure
You can ask us to delete personal data where we no longer need it, where you withdraw consent that was our only basis for holding it, or where you object and we have no overriding legitimate ground to continue. Journalists and creators in PR OS or Influencer OS: this is the right to use, and we will action it without argument.
10.4 Right to object
You can object to processing based on our legitimate interests, and to any processing for direct marketing purposes. If you object to direct marketing, we will stop — there is no balancing test and no exception.
10.5 Right to restrict processing
You can ask us to limit how we use your personal data — for example, while we investigate a correction request.
10.6 Right to withdraw consent
Where we rely on your consent, you can withdraw it at any time. Use the unsubscribe link in any marketing email, change your choices in our cookie settings, or email us.
10.7 Right to data portability
Where we process your personal data by automated means on the basis of consent or a contract, you can ask for a copy in a structured, commonly used, machine-readable format, and ask us to transmit it to another controller where technically feasible. (This right was introduced in Malaysia by the Personal Data Protection (Amendment) Act 2024.)
10.8 Right to limit processing for direct marketing
Under section 43 of the PDPA you may, at any time, require us to cease or not to begin processing your personal data for the purposes of direct marketing.
10.9 Right to complain
If you are not satisfied with how we have handled your personal data or your request, you can complain to a supervisory authority. You can complain to us first, and we would prefer that you did, but you are not required to.
Malaysia — Personal Data Protection Department (Jabatan Perlindungan Data Peribadi), Ministry of Digital, Malaysia. pdp.gov.my
EEA — the supervisory authority in your country of residence, work, or where the alleged infringement took place. A list is maintained at edpb.europa.eu
United Kingdom — Information Commissioner’s Office, ico.org.uk
11. Third-party websites
Our website and Journal contain links to sites we do not operate, including clients’ websites, publications that have covered our work, and social platforms. We are not responsible for the privacy practices of those sites. Clicking a third-party link takes you outside our control, and we encourage you to read the privacy policy of any site you visit.
12. Changes to this policy
We may update this policy to reflect changes in our practices, our technology, or the law. When we do, we will change the “Last updated” date at the top. If the change is material — for example, a new purpose for processing, or a new category of recipient — we will give you notice before it takes effect, by email where we have your address or by a prominent notice on the website.
We encourage you to review this policy periodically.
13. Definitions
Personal data — any information relating to an identified or identifiable individual, whether recorded in a material form or not, that is being processed or is capable of being processed.
Sensitive personal data — personal data consisting of information about an individual’s physical or mental health, political opinions, religious or similar beliefs, the commission or alleged commission of any offence, biometric data, or any other data designated as sensitive by the Minister.
Processing — any operation performed on personal data, including collecting, recording, organising, storing, adapting, retrieving, using, disclosing, transferring, erasing, or destroying it.
Data controller (a “data user” under the PDPA) — the person who, alone or jointly with others, determines the purposes and means of processing personal data. For the data described in this policy, that is Manifesto.
Data processor — a person who processes personal data on behalf of and on the instructions of a data controller.
Data subject — the individual who is the subject of the personal data.
14. Language
This Privacy Policy is published in English, which is the governing version. Where we provide a Bahasa Malaysia translation, the English version shall prevail in the event of any conflict or inconsistency between the two.
Manifesto Agency
Registration No. 202603059119 (003829903-D)
Kuala Lumpur, Malaysia
privacy@manifestoagency.co