Legal

Privacy Policy

Last updated:

This Privacy Policy explains how IntBooks Sdn Bhd ("IntBooks", "we", "us") collects, uses, discloses, and safeguards your personal data when you visit https://intbooks.my or use the IntBooks ERP application at https://app.intbooks.my. We operate from Kuala Lumpur, Malaysia, and our processing is governed by the Personal Data Protection Act 2010 (PDPA). Where you access the service from the EU/UK, we additionally honour the GDPR rights described below.

1. Data we collect

2. How we use your data

3. Cookies & similar storage

The marketing site at https://intbooks.my currently sets only strictly-necessary cookies (Cloudflare bot mitigation). It runs no analytics, advertising, or cross-site tracking pixels. The ERP app at https://app.intbooks.my sets a Clerk session cookie when you sign in. The full per-cookie disclosure is on our Cookie Policy.

4. Sub-processors

We rely on a small set of sub-processors to deliver IntBooks. The full list — vendor, scope of data, region, and trust-page link — is published at /sub-processors and we notify account admins by email at least 30 days before adding a new sub-processor that processes customer data.

5. Retention

Different record categories have different retention periods, set by Malaysian law and our internal data-minimisation policy.

Record category Retention period Statutory basis
Accounting records (invoices, journals, ledger) 7 years from end of financial year Income Tax Act 1967 §82A; Companies Act 2016 §245
E-invoices submitted to MyInvois 7 years LHDN E-Invoice Guideline §8
Payroll records (EPF/SOCSO/EIS/PCB) 7 years Employees Provident Fund Act 1991 §69
Audit logs (Enterprise plan) 12 months Internal SOC 2 control SC-AT-01
Cloudflare edge request logs (marketing + app) Up to 30 days Cloudflare default retention
Waitlist signups (email, role, industry, revenue, IP, UA) 12 months from submission Internal beta-eligibility window
Services-contact submissions (name, email, phone, company, message) 24 months from submission Sales record & follow-up
Marketing-site chatbot conversations Not persisted server-side; transient processing only Internal data-minimisation policy
Account / authentication metadata Until account deletion + 90 days PDPA §10 (necessity)
Receipt images submitted to AI extraction 90 days then purged from cache Internal data-minimisation policy

You may request export at any time via hello@intbooks.my. Upon account closure we de-identify usage telemetry within 90 days; live business records are retained for the statutory period before secure deletion.

6. Your rights

7. Security

We encrypt data in transit (TLS 1.2+) and at rest (AES-256). Access to production systems is restricted to a small number of named engineers under MFA + audit logging. We disclose qualifying breaches to affected customers within 72 hours of discovery via in-app notice and email to account admins, and — where the breach is significant — notify the Department of Personal Data Protection (JPDP) within the same window in accordance with the PDPA 2024 amendments. Report suspected vulnerabilities to security@intbooks.my.

8. International transfers

Personal data may be transferred between Malaysia, Singapore, and the EU/UK as required to operate the service. Where transfers leave Malaysia we rely on the data exporter consent + adequate-safeguards basis under PDPA §129, and on Standard Contractual Clauses (SCCs) for EU/UK origin data.

9. AI & automated processing

IntBooks uses AI in two distinct surfaces with different providers:

10. Children

IntBooks is a B2B service and is not directed at children under 18. We do not knowingly collect personal data from children. If you believe a child has submitted data to us, please email hello@intbooks.my and we will delete it.

11. Changes to this policy

We will publish material changes here and notify account admins by email at least 30 days before the change takes effect. The "last updated" date above always reflects the current version.

12. Data Protection Officer & contact

We have designated a Data Protection Officer (DPO) as required under the PDPA 2024 amendments. The DPO is the primary point of contact for data-subject requests and JPDP correspondence.