Legal

Privacy Notice

How Winner Strategy Group collects, uses, discloses, retains and protects personal data.

Last updated: 8 October 2026

At Winner Strategy Group, we respect the privacy of individuals whose personal data we collect and process, in accordance with the Personal Data Protection Act 2010 (Act 709), as amended by the Personal Data Protection (Amendment) Act 2024, and the guidelines and circulars issued by the Personal Data Protection Commissioner from time to time.

This Privacy Notice explains how we collect, use, disclose, retain and protect personal data when you visit our website, communicate with us, apply for employment, enquire about our services, or otherwise interact with us.

1. Who we are

WS & CO PLT (202206000035 (LLP0033211-LCA) & AF002338) and WS Advisory Sdn. Bhd. (201901004237 (1313564-X)), collectively referred to as “Winner Strategy Group”, “WS Group”, “we”, “us” or “our”, are professional services firms registered in Malaysia.

WS Group provides professional services including audit and assurance, taxation, transfer pricing, advisory, corporate finance, pre-IPO advisory, valuation, risk and governance, sustainability and other professional services.

For the purposes of this Privacy Notice, the relevant WS Group entity responsible for your personal data will depend on the nature of your relationship or engagement with us.

2. Scope of this Privacy Notice

This Privacy Notice applies to personal data collected through:

This Privacy Notice does not replace any specific privacy notice, engagement letter, contractual terms or professional confidentiality obligations that may apply to a particular service or relationship.

Where separate contractual or professional obligations apply, those obligations will continue to apply.

3. Personal data we may collect

Depending on the nature of your interaction with us, we may collect and process personal data including:

Identity and contact information

Business and professional information

Financial, accounting and tax information

Where necessary for our professional services, information may include financial information, accounting records, tax information, banking information, transaction information and other information contained in documents provided to us.

Such documents may also contain personal data relating to employees, customers, suppliers, directors, shareholders or other individuals connected with a client.

Recruitment information

For employment applications, we may collect information contained in your curriculum vitae, application forms, qualifications, employment history, references, interview information and other information reasonably required to assess your application.

Technical and website information

When you use our website, we may collect information such as IP address, browser type, device information, operating system, pages visited, approximate location derived from technical information, access times and other technical information generated through your interaction with the website.

4. How we collect personal data

We may collect personal data directly from you or from other lawful sources, including:

Where appropriate, we may also receive personal data from our clients in connection with the provision of professional services.

5. How we use personal data

We may use personal data for purposes including:

We will not use personal data for purposes that are incompatible with the purposes for which it was collected unless permitted or required by applicable law or otherwise authorised by you.

6. Professional engagements and confidentiality

Information provided to us in connection with an audit, tax, advisory or other professional engagement may be subject to contractual, statutory and professional confidentiality obligations.

This Privacy Notice concerns the processing of personal data. It does not limit or replace any confidentiality obligations applicable to information received in the course of providing professional services.

Where we receive personal data belonging to individuals other than our direct client, we may process that information where reasonably necessary to perform the relevant professional engagement or for another lawful purpose.

7. Disclosure of personal data

We may disclose personal data where reasonably necessary for the purposes described in this Privacy Notice and where permitted or required by applicable law.

Depending on the circumstances, recipients may include:

We do not sell personal data to third parties.

8. Cross-border transfers

Some of our service providers, professional networks, technology systems, cloud platforms or other recipients may be located outside Malaysia.

Where personal data is transferred outside Malaysia, we will take steps required by applicable data protection laws and regulations, including where applicable implementing appropriate safeguards or relying on a permitted basis for the transfer.

Cross-border transfers may occur where necessary for the provision of professional services, operation of our information technology systems, use of cloud services, engagement with professional networks or other legitimate business purposes.

9. Data security

We take reasonable and appropriate measures to protect personal data against unauthorised access, collection, use, disclosure, alteration, loss, misuse or destruction.

Depending on the nature of the information and the circumstances, these measures may include access controls, confidentiality obligations, authentication controls, secure systems, physical security measures, employee awareness and other technical and organisational safeguards.

However, no method of electronic transmission, storage or processing can be guaranteed to be completely secure.

10. Information submitted through the website

General website enquiries, email links, WhatsApp links and similar communication channels should not be treated as secure channels for transmitting highly confidential or sensitive information unless we specifically instruct you to use them for that purpose.

You should avoid submitting unnecessary personal data, passwords, banking credentials, identification documents or highly confidential commercial information through general website enquiry channels.

Where confidential information is required for a professional engagement, we may provide or require the use of designated communication, document exchange or client portal arrangements.

11. Data retention

We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, to comply with applicable legal, regulatory and professional requirements, to establish or defend legal claims, to maintain appropriate business records and for other legitimate purposes.

Different categories of information may be retained for different periods depending on the nature of the information and the purpose for which it is processed.

Professional and engagement records may be retained for periods required by applicable legislation, professional standards, regulatory requirements, contractual obligations and our internal policies.

When personal data is no longer required, we will take reasonable steps to securely delete, destroy or anonymise it, subject to applicable legal and professional requirements.

12. Cookies and website technologies

Our website uses a small number of cookies and similar technologies to operate the website, remember preferences and understand how the website is used.

Analytics. We use Google Analytics, a service provided by Google, to understand how visitors use the website, such as which pages are viewed and how visitors arrive at the website. The information is reported to us in aggregate and is not used to identify individual visitors. Google Analytics cookies are set only if you accept them in the cookie notice. If you decline, these cookies are not set, and Google receives only limited signals without cookies, which cannot be used to recognise you across visits.

Your choice. You can change your choice at any time using the “Cookie settings” link at the bottom of any page. Your choice, and whether you have closed a website announcement, is remembered in your browser.

Third-party services. Our website loads fonts and scripts from third-party providers, which may receive technical information such as your IP address and browser type. Those providers process this information in accordance with their own privacy policies.

You can also control or delete cookies through your browser settings. Disabling certain cookies may affect the functionality of the website.

13. Direct marketing and communications

Where permitted by applicable law, we may send you information about our services, events, publications, insights and other professional updates.

Where consent is required, we will obtain the relevant consent before sending such communications.

You may request that we stop sending marketing communications at any time by contacting us or using the unsubscribe mechanism provided in the relevant communication.

Withdrawal of consent for marketing communications does not necessarily affect communications that are necessary for an existing professional engagement, contractual relationship, legal obligation or other lawful purpose.

14. Recruitment and career applications

If you apply for a position with WS Group, we may process the personal data provided in your application for recruitment, assessment, background checks where appropriate, communication with you and related employment purposes.

We may retain recruitment information for a reasonable period after the recruitment process to deal with recruitment administration, future opportunities, legal requirements and potential disputes.

Where you provide information relating to referees or other individuals, you should ensure that you are authorised to provide that information to us.

15. Your rights

Subject to the Personal Data Protection Act 2010 (Act 709), as amended by the Personal Data Protection (Amendment) Act 2024, and any applicable exemptions, you may have rights in relation to your personal data, including the right to:

Requests may be subject to verification and applicable legal requirements.

We may also be entitled to retain or continue processing certain information where required or permitted by law, professional obligations or legitimate purposes.

16. Data breach and security incidents

We maintain procedures for identifying, assessing, managing and responding to personal data security incidents.

Where a personal data breach occurs, we will take appropriate steps in accordance with applicable laws, regulations and regulatory requirements, including notification to the relevant authorities or affected individuals where required.

17. Third-party websites

Our website may contain links to third-party websites, platforms or services.

Those websites are operated independently from WS Group and may have their own privacy policies and terms of use.

We are not responsible for the privacy practices, security or content of third-party websites.

You should review the relevant third-party privacy notice before providing personal data to them.

18. Changes to this Privacy Notice

We may update this Privacy Notice from time to time to reflect changes in our business, technology, services, applicable laws or regulatory requirements.

The latest version will be published on this website with the relevant effective or updated date.

19. Contact us

If you have questions about this Privacy Notice, wish to exercise your applicable rights, or have a complaint concerning the handling of your personal data, please contact:

Winner Strategy Group
Email: admin@wsco.asia
Website: wsco.asia

Where your enquiry relates specifically to a particular WS Group entity or professional engagement, we may direct your enquiry to the relevant entity or responsible person. You may also lodge a complaint with the Personal Data Protection Commissioner of Malaysia.

20. Governing law

This Privacy Notice is governed by the laws of Malaysia, to the extent applicable.