Last updated: January 2026
This Privacy Policy explains how Phoenix Investment Bank (Labuan) Ltd collects, uses, stores, discloses, and protects personal data and non-public information provided through our website, online channels, products, services, enquiries, applications, and ongoing business relationships.
1. Introduction
Phoenix Investment Bank (Labuan) Ltd, referred to in this policy as "Phoenix", "we", "us", or "our", is committed to protecting the confidentiality, integrity, and security of personal data entrusted to us.
By accessing our website, submitting information to Phoenix, or using our online services, you acknowledge that your personal data may be handled in accordance with this Privacy Policy and applicable law.
We may amend this Privacy Policy from time to time. Updated versions become effective when published on this website.
2. Regulatory and Security Framework
This policy applies to personal information about individuals, including clients, prospective clients, business partners, representatives, job applicants, employees, and other persons whose information may be processed by Phoenix.
We process personal data in accordance with applicable Malaysian data protection requirements, including the Personal Data Protection Act 2010 where relevant, Labuan Financial Services Authority requirements, and applicable international privacy and information-security standards.
Phoenix maintains administrative, technical, and physical safeguards designed to protect personal data against unauthorised access, misuse, accidental loss, alteration, or disclosure. Our systems and procedures may be monitored, tested, and reviewed to support operational integrity and detect unlawful activity.
3. Consent
Where consent is required, by submitting information to Phoenix or using our online services, you consent to the collection, processing, storage, use, and disclosure of your personal data for the purposes described in this policy.
If you provide personal data about another individual, you confirm that you have the authority to do so and that the individual has been informed of the matters covered by this policy.
4. Categories of Personal Data Collected
Depending on the relationship, product, service, enquiry, or regulatory requirement, Phoenix may collect and process the following categories of information:
- Identification information, including name, identity document or passport details, nationality, date of birth, photographs, and verification records.
- Contact information, including residential address, mailing address, email address, and telephone number.
- Employment, business, source-of-funds, source-of-wealth, transaction, financial, tax, and account information.
- Information provided through application forms, onboarding documents, correspondence, meetings, calls, or online enquiries.
- Information from credit reporting agencies, financial institutions, government bodies, regulatory authorities, sanctions lists, public registers, and third-party verification providers.
- Technical and usage information, including IP address, browser type, device information, cookies, analytics data, and website interaction records.
If requested information is not provided, is incomplete, or is inaccurate, Phoenix may be unable to process an enquiry, assess an application, provide services, meet regulatory obligations, or maintain a relationship with you.
5. Cookies, Analytics, and Social Plugins
Our website may use cookies and similar technologies to support website functionality, improve site usability, understand site performance, and analyse visitor activity.
You may disable cookies through your browser settings, although doing so may affect certain website functions. Where third-party analytics, advertising features, or social media plugins are used, those providers may receive technical and usage data under their own policies.
For further details, please refer to our Cookie Policy.
6. Purposes for Processing Personal Data
Phoenix may process personal data for legitimate business, contractual, compliance, operational, and regulatory purposes, including:
- Establishing, managing, and maintaining client or business relationships.
- Processing applications, enquiries, mandates, accounts, products, and services.
- Conducting KYC, AML/CFT, sanctions, credit, risk, suitability, due diligence, and underwriting checks.
- Meeting legal, regulatory, audit, tax, reporting, record-keeping, and supervisory obligations.
- Preventing fraud, managing disputes, monitoring security, and protecting Phoenix, clients, counterparties, and markets.
- Providing client support, administration, settlement, reconciliation, transaction processing, and service communications.
- Improving systems, services, products, analytics, governance, and internal controls.
- Sending marketing or informational communications where permitted by law, contract, consent, or legitimate business interest.
7. Disclosure of Personal Data
Phoenix does not sell personal data. We may disclose personal data on a need-to-know basis and where lawful or necessary, including to:
- Phoenix group companies, affiliates, branches, representatives, or related entities in Malaysia or overseas.
- Service providers, agents, administrators, technology vendors, custodians, payment processors, auditors, insurers, lawyers, consultants, and professional advisers.
- Verification providers, credit bureaus, credit reporting agencies, counterparties, correspondent institutions, introducing brokers, and business partners.
- Regulatory authorities, law-enforcement bodies, courts, tax authorities, government agencies, and other parties where disclosure is required or permitted by law.
- Persons authorised by you or acting on your behalf, including advisers, brokers, accountants, solicitors, trustees, representatives, or other appointed parties.
Where information is transferred or accessed outside Malaysia, Phoenix will take reasonable steps to ensure that appropriate confidentiality, security, and data protection safeguards apply.
8. Data Storage and Retention
Personal data may be stored in secure electronic systems, protected physical records, cloud environments, or third-party infrastructure used by Phoenix or its service providers.
We retain personal data for as long as necessary to fulfil the purposes for which it was collected, comply with legal and regulatory retention obligations, resolve disputes, enforce agreements, and support legitimate business needs.
When personal data is no longer required, Phoenix will take reasonable steps to securely destroy, delete, anonymise, or de-identify it, unless continued retention is required or permitted by law.
9. Data Accuracy and Your Obligations
You are responsible for ensuring that information provided to Phoenix is accurate, complete, current, and not misleading. You should notify Phoenix promptly if your personal data changes or if you become aware that any information held by Phoenix is inaccurate.
10. Access, Correction, and Data Rights
Subject to applicable law, you may request access to personal data that Phoenix holds about you, request correction of inaccurate or incomplete data, or make enquiries about how your personal data is processed.
Requests may be subject to identity verification, legal limitations, regulatory restrictions, operational requirements, and reasonable administrative fees where permitted by law.
There may be circumstances where Phoenix cannot provide access or make a requested correction. Where required, we will explain the reason for refusing or limiting a request.
11. Online Security and Password Protection
Where online services, portals, or authenticated channels are provided, access may be protected by user credentials, authentication controls, and security monitoring.
You are responsible for keeping your login credentials confidential and for notifying Phoenix immediately if you suspect unauthorised access, misuse, compromise, or any security incident involving your account or communications with Phoenix.
12. Electronic Communications and Internet Risks
Internet communications may involve security, confidentiality, delivery, interception, malware, and transmission risks. You should consider these risks before sending sensitive information by email, website forms, or other electronic channels.
If you do not wish to transmit information electronically, you may contact Phoenix through alternative official communication channels.
13. Marketing Communications
Phoenix may send service updates, market information, event notices, product information, or other communications where permitted by law, consent, contract, or legitimate business interest.
You may request that we stop sending marketing communications by using the unsubscribe method provided, where available, or by contacting us directly.
14. Intellectual Property and Website Content
All content, trademarks, logos, designs, images, documents, and intellectual property displayed on this website are owned by or licensed to Phoenix unless otherwise stated.
This Privacy Policy does not grant any rights to copy, reproduce, distribute, publish, or commercially exploit Phoenix website content without prior written consent.
15. Relationship with Other Policies
This Privacy Policy should be read together with our Terms & Conditions, Cookie Policy, regulatory notices, product documents, account terms, client agreements, and any other privacy or data-protection notices provided by Phoenix.
16. Contact Information
If you have questions, concerns, requests, or complaints regarding this Privacy Policy or the handling of your personal data, please contact Phoenix Investment Bank (Labuan) Ltd at admin@thephoenixbank.com.
