Privacy Policy

Last updated: 27 September 2026

Privacy Policy / Personal Data Protection Notice

0. Introduction and scope

Mainhome Solution (MM2H) Sdn. Bhd. (Registration No. 202401031238 (1577087-H)) (“we”, “us”, “our”) is an MM2H agent licensed by the Ministry of Tourism, Arts and Culture Malaysia (MOTAC) under the Tourism Industry Act 1992 (licence no. MM2H913). For the personal data described in this notice, we are the data controller under the Personal Data Protection Act 2010, as amended by the Personal Data Protection (Amendment) Act 2024 (“PDPA”).

As required by section 7 of the PDPA, this notice explains what personal data we process, where it comes from, why we process it, whether you must provide it, the classes of third parties we disclose it to, whether it is transferred outside Malaysia, how long we keep it, how we protect it, what rights you have and how to contact us.

This notice applies to:

  • visitors to our website mhmm2h.com; and
  • people who enquire with us or engage us for an MM2H application (principal applicants), and their dependants (spouse, children, parents).

1. What personal data we process

1.1 Website visitors

  • Enquiry form: the name, email address, phone number and message you choose to submit.
  • Spam protection: the enquiry form has a hidden field that helps filter out spam sent by bots. It works on our website server and is not sent to any third party, and we do not keep the value of that field.
  • Language preference: a cookie that remembers the website language you chose.
  • Technical logs: as part of normal operation, our website server, provided by our hosting provider (see section 6), may record server logs such as IP address, browser type and time of visit.

This website does not use Google Analytics, Facebook Pixel or any other advertising or analytics tracking.

Please do not submit passports, medical reports, police clearance certificates, bank statements or similar documents through the website enquiry form. The website is for general enquiries only. We collect such documents only after you engage us, through a channel we tell you about at that time.

The WhatsApp link (wa.me) and WeChat QR code on this website take you to third-party platforms. Conversations with us on those platforms are also governed by the platforms’ own privacy policies.

1.2 MM2H clients (including dependants)

Once you engage us for an MM2H application, we collect the following from the principal applicant and dependants (spouse, children, parents), depending on the case, in order to prepare and submit the application:

  • Identity and family information: name, date of birth, nationality, passport (bio-data and visa pages), photographs, birth certificates, marriage certificate, address and contact details.
  • Financial information: bank statements, payslips, employment letters, proof of income and assets, fixed deposit (FD) documents.
  • Property information (if applicable): sale and purchase agreement and related documents.

Some of this data is required by the authorities administering the MM2H programme (see section 4).

1.3 Sensitive personal data

Under section 4 of the PDPA, information about a person’s physical or mental health or condition, and about the commission or alleged commission of any offence, is sensitive personal data. For MM2H applications we process:

  • health data: medical reports, medical examination results, medical insurance details;
  • data relating to offences: certificate of good conduct / police clearance certificate.

We only process this data with your explicit consent (section 40(1)(a) of the PDPA), or where the law otherwise permits. We do not collect sensitive personal data through the website.

1.4 Personal data of persons under 18

Where an application includes children under 18, we process their personal data (including the sensitive personal data above). Under regulation 3(3) of the Personal Data Protection Regulations 2013, consent must be given by their parent, guardian or person with parental responsibility.

2. Where we get your data

  • From you directly (via the website form, WhatsApp, WeChat, email, phone or in person);
  • From family members or representatives you authorise to provide it;
  • From organisations involved in your application, such as approval results from government agencies, medical reports from clinics, and confirmations from banks or insurers;
  • From our website server logs (technical data described in section 1.1 only).

3. Why we process your data (purposes)

  • To answer your enquiry and explain the MM2H programme and our services;
  • To assess your eligibility and give you a quotation;
  • To prepare, translate, certify and submit your MM2H application, follow up on approval, and arrange later steps such as interviews, medical examinations, fixed deposits, insurance and property purchase;
  • To keep you updated on progress and handle your requests and complaints;
  • To protect the website from spam and abuse;
  • To meet legal, regulatory, accounting, tax and audit obligations, including requirements under the Tourism Industry Act 1992 and MOTAC requirements for licensed agents;
  • To establish, exercise or defend legal rights.

4. Do you have to provide your data?

  • Website enquiries: the fields marked as required on the form must be filled in so that we can reply to you. Other information is optional. If you do not provide the required fields, we will not be able to respond to your enquiry.
  • MM2H applications: documents required by the authorities administering the MM2H programme (including health and criminal record information) are mandatory for the application. If you do not provide them, provide them incompletely, or withdraw consent to their processing, we may be unable to submit or continue your application, and the application may be rejected or delayed.

5. Classes of third parties we disclose your data to

We disclose personal data only as needed for the purposes in section 3, to the following classes of third parties:

  • Government and regulators: MOTAC / One Stop Centre (OSC) MM2H, the Immigration Department of Malaysia, the Ministry of Home Affairs, the Royal Malaysia Police (PDRM), the Inland Revenue Board of Malaysia (LHDN), and any other authority legally entitled to request it;
  • Banks and insurers: licensed banks in Malaysia (e.g. for fixed deposits) and insurance companies;
  • Medical: clinics designated or recognised by MOTAC;
  • Document services: translation and attestation service providers, including Malaysian embassies and consulates abroad and the attestation authorities of the relevant countries;
  • Professional advisers: lawyers, accountants and auditors;
  • Property (if applicable): property developers and their lawyers;
  • Service providers (data processors): providers of website and email hosting and cloud storage, who process data only on our instructions;
  • Communication platforms: WhatsApp and WeChat, when you choose to communicate with us through them. These platforms process your data under their own privacy policies.

Under the PDPA, data processors acting on our behalf must themselves comply with the Security Principle. We require service providers that process personal data on our behalf to protect it and to use it only to provide their services to us.

We do not sell your personal data.

6. Transfers outside Malaysia

Because of the nature of our work, your data may be transferred outside Malaysia. The classes of recipients and the purposes of transfer are:

  • Attestation authorities, and Malaysian embassies or consulates abroad (in your country of residence or origin): attesting your documents for the MM2H application;
  • Website and email hosting provider: a Malaysian hosting provider whose data centres may be located in Malaysia or in nearby countries such as Singapore: storing and transmitting website enquiries and email correspondence;
  • Cloud storage providers, whose servers may be in other countries: storing your file and correspondence;
  • Communication platforms (WhatsApp, WeChat), when you choose to communicate with us through them: communicating about your enquiry or application.

Data protection laws in those places may differ from Malaysia’s. We only transfer data outside Malaysia where section 129 of the PDPA allows it. We rely on the following grounds:

  • Your consent (section 129(3)(a)): when you submit an enquiry and tick the consent box on the enquiry form, you consent to the transfer of your enquiry details as described in this section in order to handle your enquiry (for example, through our email hosting service). When you engage us, we tell you which kinds of overseas recipients may receive your data and why, and ask for your consent;
  • Performing our contract with you, or a contract made at your request or in your interests (section 129(3)(b) and (c)): sending your documents to the attestation authority of your home country, or to a Malaysian embassy or consulate, is necessary to carry out the application you have entrusted to us.

7. Personal data of other people you give us (dependants)

If you give us personal data about another person (for example your spouse, children or parents), please let them know about this notice, and make sure that you have their consent or are entitled to provide it on their behalf. For children under 18, consent is given by their parent or guardian.

8. How we protect your data

In line with section 9 of the PDPA and the Commissioner’s Personal Data Protection Standard 2015, we take reasonable practical measures to protect personal data from loss, misuse, unauthorised access, modification or disclosure. Our website uses an encrypted connection (HTTPS).

No method of sending data electronically is completely free of risk. Please do not send passports or other important documents through public or insecure channels.

9. How long we keep your data

We keep personal data only for as long as needed to fulfil the purposes in section 3, and for any period required by law, regulation, accounting or audit. After that, we delete or destroy it, or make it no longer identifiable (section 10 of the PDPA; item 6 of the Personal Data Protection Standard 2015).

10. Your rights

Within the limits set by the PDPA, you may:

  • Access (section 30): ask whether we hold your data and obtain a copy. We will respond within 21 days of receiving your request; if we cannot, we will tell you in writing before that period ends, with reasons, and complete the request within a further 14 days (section 31). Under the Personal Data Protection (Fees) Regulations 2013, a fee not exceeding the statutory maximum may be charged for an access request.
  • Correct (sections 34 and 35): ask us to correct data that is inaccurate, incomplete, misleading or not up to date. We will act within 21 days of receiving your request; if we cannot, we will tell you in writing before that period ends, with reasons, and complete the correction within a further 14 days.
  • Withdraw consent (section 38): withdraw your consent to processing by written notice. We will then stop processing your data, except where we must keep or use it to comply with a legal obligation (for example statutory record-keeping) or to establish, exercise or defend legal rights. Withdrawal may mean we cannot continue our services (see section 4).
  • Limit processing: you can limit how we process your data by withdrawing consent and by using the rights below.
  • Prevent processing likely to cause damage or distress (section 42): ask us in writing to stop processing that is causing or is likely to cause substantial and unwarranted damage or distress to you or another person; we will reply in writing within 21 days. This right does not apply in some cases, for example where you have consented or the processing is necessary to perform a contract with you.
  • Object to direct marketing (section 43): see section 11.
  • Data portability (section 43A): ask us, by written notice sent electronically, to transmit your personal data to another data controller of your choice, subject to technical feasibility and compatibility of the data format.

Please send your request in writing (by email or post) to the contact in section 14. We will acknowledge receipt. To protect your data, we may ask for your name, passport or identity card number and address, and, if you act for someone else, proof of your authority. Where the law allows, we may refuse part of a request and will explain why.

11. Direct marketing

We do not carry out direct marketing and do not send marketing messages or newsletters. If we decide to do so in future, we will first ask for your separate consent, and you may withdraw it at any time. Under section 43 of the PDPA, you may also ask us in writing at any time not to process your data for direct marketing.

12. Cookies

Cookies are small text files that a website stores in your browser so that it works properly or remembers your settings. This website only uses cookies that are needed for it to work:

Purpose Set by Who it applies to
Remembering the website language you chose (pll_language) This website Visitors who choose a language
Keeping website administrators signed in, and related security checks This website Website administrators only

We do not use advertising, analytics or tracking cookies.

Map and fonts: the map on our website is a static image stored on our website server, and the website’s fonts are also served from our website server, so opening our pages does not connect your browser to third-party map or font services. Only if you click the “Open in Google Maps” link below the map will you go to Google’s website, where the Google Privacy Policy applies.

Managing cookies: you can view, delete or block cookies in your browser settings. If you block these cookies, your language choice may not be remembered. Third-party platforms you visit from this website (such as WhatsApp or WeChat) may set their own cookies under their own policies.

13. Data breaches

Under section 12B of the PDPA and the Commissioner’s Data Breach Notification Guideline:

  • if a personal data breach causes or is likely to cause significant harm, we will notify the Personal Data Protection Commissioner as soon as practicable and no later than 72 hours, counted in the manner set out in the Guideline (generally from when we become aware of, or confirm, the breach);
  • if the breach causes or is likely to cause you significant harm, we will notify you without unnecessary delay and no later than 7 days after notifying the Commissioner, explaining what happened, the likely consequences, what we are doing, and what you can do to protect yourself.

14. Contact us

For questions, requests or complaints about this notice or your personal data, please contact:

  • Contact person: Director (Personal Data Protection), Mainhome Solution (MM2H) Sdn. Bhd.
  • Address: B-15-03, Tower B, Vertical Business Suite, Avenue 3, Bangsar South City, 59200 Kuala Lumpur, W.P. Kuala Lumpur, Malaysia
  • Email: info@mhmm2h.com (please mark the subject “Personal Data”)
  • Phone: 012-3972658

If you are not satisfied with how we handle your concern, you may also complain to the Personal Data Protection Commissioner (Jabatan Perlindungan Data Peribadi, www.pdp.gov.my).

15. Language

This notice is available in English, Bahasa Melayu and Chinese. The Bahasa Melayu and Chinese versions are published on this website alongside this English version. If there is any inconsistency between the versions, the English version prevails.

16. Changes to this notice

We may update this notice because of changes in the law, our business or the website. The updated version will be posted on this page with a new “Last updated” date. For significant changes, we will inform existing clients beforehand. Before using your data for a purpose other than the one it was collected for, we will inform you and, where the law requires, obtain your consent.