Legal
Privacy Policy
Last updated:
This Privacy Policy explains how IntBooks Sdn Bhd ("IntBooks", "we", "us") collects, uses, discloses, and safeguards your personal data when you visit https://intbooks.my or use the IntBooks ERP application at https://app.intbooks.my. We operate from Kuala Lumpur, Malaysia, and our processing is governed by the Personal Data Protection Act 2010 (PDPA). Where you access the service from the EU/UK, we additionally honour the GDPR rights described below.
1. Data we collect
- Account data — name, email, organisation name, role, and authentication identifiers (provided directly or via Clerk SSO).
- Business data — invoices, expenses, journal entries, payroll, inventory, and other accounting records you enter or import.
- Payment data — handled by Stripe and BillPlz; we retain only payment status, plan, and invoice IDs, never card numbers.
- In-app usage telemetry — within the IntBooks ERP at https://app.intbooks.my, we log pages viewed, feature events, error logs, IP and user-agent to operate and improve the service. We do not sell or share this with advertisers.
- Edge request logs — Cloudflare records server-side request metadata (IP, URL, user-agent, response code) for all traffic to https://intbooks.my and https://app.intbooks.my for operational and security purposes (bot mitigation, DDoS, debugging). Retained up to 30 days at the edge.
- Marketing-site cookies — we set no analytics, advertising, or cross-site tracking cookies on https://intbooks.my . The only cookies present are Cloudflare's bot-mitigation cookies. See our Cookie Policy for the full inventory.
- Form submissions — when you submit the waitlist (/coming-soon) or services contact form (/services), we record your email, role, industry, revenue band (waitlist), name, phone, company, message (contact), and IP + user-agent for fraud and rate-limiting. Submissions are delivered via Resend (US).
- Chatbot conversations — messages you send through the marketing-site chatbot are processed by Cloudflare Workers AI (Meta Llama 3.3) to generate a reply. We do not persist conversations server-side; transient processing happens on Cloudflare's global network. Please do not paste personal data, customer details, or financial figures into the chatbot.
2. How we use your data
- To provide the IntBooks ERP service and your contracted features.
- To meet Malaysian regulatory obligations (LHDN MyInvois e-invoicing, SST/GST returns, EPF/SOCSO/EIS/PCB statutory submissions).
- To bill, support, and communicate operationally with you.
- To detect, prevent, and respond to fraud, abuse, and security incidents.
- To improve the product through aggregated, de-identified analytics.
3. Cookies & similar storage
The marketing site at https://intbooks.my currently sets only strictly-necessary cookies (Cloudflare bot mitigation). It runs no analytics, advertising, or cross-site tracking pixels. The ERP app at https://app.intbooks.my sets a Clerk session cookie when you sign in. The full per-cookie disclosure is on our Cookie Policy.
4. Sub-processors
We rely on a small set of sub-processors to deliver IntBooks. The full list — vendor, scope of data, region, and trust-page link — is published at /sub-processors and we notify account admins by email at least 30 days before adding a new sub-processor that processes customer data.
5. Retention
Different record categories have different retention periods, set by Malaysian law and our internal data-minimisation policy.
| Record category | Retention period | Statutory basis |
|---|---|---|
| Accounting records (invoices, journals, ledger) | 7 years from end of financial year | Income Tax Act 1967 §82A; Companies Act 2016 §245 |
| E-invoices submitted to MyInvois | 7 years | LHDN E-Invoice Guideline §8 |
| Payroll records (EPF/SOCSO/EIS/PCB) | 7 years | Employees Provident Fund Act 1991 §69 |
| Audit logs (Enterprise plan) | 12 months | Internal SOC 2 control SC-AT-01 |
| Cloudflare edge request logs (marketing + app) | Up to 30 days | Cloudflare default retention |
| Waitlist signups (email, role, industry, revenue, IP, UA) | 12 months from submission | Internal beta-eligibility window |
| Services-contact submissions (name, email, phone, company, message) | 24 months from submission | Sales record & follow-up |
| Marketing-site chatbot conversations | Not persisted server-side; transient processing only | Internal data-minimisation policy |
| Account / authentication metadata | Until account deletion + 90 days | PDPA §10 (necessity) |
| Receipt images submitted to AI extraction | 90 days then purged from cache | Internal data-minimisation policy |
You may request export at any time via hello@intbooks.my. Upon account closure we de-identify usage telemetry within 90 days; live business records are retained for the statutory period before secure deletion.
6. Your rights
- Access a copy of your personal data.
- Correct data that is inaccurate or incomplete.
- Withdraw consent for any processing done on the basis of consent.
- Lodge a complaint with the Department of Personal Data Protection (JPDP) in Malaysia, or your local supervisory authority in the EU/UK.
- Port your data — we provide CSV/JSON export of every module.
7. Security
We encrypt data in transit (TLS 1.2+) and at rest (AES-256). Access to production systems is restricted to a small number of named engineers under MFA + audit logging. We disclose qualifying breaches to affected customers within 72 hours of discovery via in-app notice and email to account admins, and — where the breach is significant — notify the Department of Personal Data Protection (JPDP) within the same window in accordance with the PDPA 2024 amendments. Report suspected vulnerabilities to security@intbooks.my.
8. International transfers
Personal data may be transferred between Malaysia, Singapore, and the EU/UK as required to operate the service. Where transfers leave Malaysia we rely on the data exporter consent + adequate-safeguards basis under PDPA §129, and on Standard Contractual Clauses (SCCs) for EU/UK origin data.
9. AI & automated processing
IntBooks uses AI in two distinct surfaces with different providers:
- Inside the ERP app at https://app.intbooks.my: receipt extraction, transaction-category suggestions, and the in-app assistant are powered by Anthropic / Claude. Anthropic does not train on your inputs under our enterprise terms.
- On the marketing site at https://intbooks.my : the public chatbot is powered by Cloudflare Workers AI (Meta Llama 3.3-70B). Messages are processed transiently on Cloudflare's global network and are not retained server-side by us. Do not paste personal data, customer details, or financial figures into the marketing chatbot.
- AI outputs are advisory. You remain responsible for reviewing entries before posting to the ledger or filing returns.
- You can opt out of AI features per-organisation under Settings → AI Features; this disables receipt extraction, the in-app assistant, and AI-suggested categorisation. The marketing chatbot can be ignored — it is not invoked unless you click the launcher.
- We do not use solely-automated decisions to produce legal effects on you (PDPA §10A; GDPR Art. 22).
10. Children
IntBooks is a B2B service and is not directed at children under 18. We do not knowingly collect personal data from children. If you believe a child has submitted data to us, please email hello@intbooks.my and we will delete it.
11. Changes to this policy
We will publish material changes here and notify account admins by email at least 30 days before the change takes effect. The "last updated" date above always reflects the current version.
12. Data Protection Officer & contact
We have designated a Data Protection Officer (DPO) as required under the PDPA 2024 amendments. The DPO is the primary point of contact for data-subject requests and JPDP correspondence.
- Data protection enquiries & DPO: dpo@intbooks.my
- General enquiries: hello@intbooks.my
- Security disclosures: security@intbooks.my
- Postal: IntBooks Sdn Bhd, Kuala Lumpur, Federal Territory, Malaysia.