Privacy Policy
How we handle your data
Effective 28 September 2026 · v1.0 · Applies to all Kiralytics users in Malaysia and Singapore
Plain-language summary
- We store your business data so the app works.
- Client names, invoices, time entries, and the logo you upload live in a Postgres database hosted on Neon (Singapore / US-East regions, depending on the branch your account is allocated to). We use this data only to render the app for you.
- We don't sell your data. Ever.
- No third-party ad targeting. No analytics resale. No model training on your data. We charge a subscription fee and that's our business model — not your data.
- Authentication is handled by Neon Auth.
- Your password is hashed and we never see the plaintext. Session cookies are signed and HTTP-only.
- You own your data.
- Export anytime. Delete your account and we erase your records within 30 days, except where tax law requires us to keep financial records for 7 years.
- Two regimes apply.
- Malaysia users have full PDPA 2010 rights. Singapore users additionally benefit from PDPA-SG baseline rights. Both groups can request access, correction, or deletion of their personal data.
Who we are (data controller)
Kiralytics is operated by SP Rekayasa Networks, a company registered in Malaysia. For the purposes of the Personal Data Protection Act 2010 (Malaysia) and the Personal Data Protection Act 2012 (Singapore), SP Rekayasa Networks is the data controller of personal data processed through this service.
Contact our Data Protection Officer at [email protected].
What personal data we collect
We collect personal data in three categories:
- Account data you give us: name, email address, password (hashed, never stored in plaintext), and business settings (business name, address, SSM/UEN registration number if you choose to provide it, logo image).
- Customer data you upload: your clients' names, addresses, emails, phone numbers, and any identification numbers you choose to record against their profile. This is the data of your customers, not ours — you are the data controller for it under PDPA and PDPA-SG.
- Technical data: IP address, browser type, and timestamps of access, used for security and debugging. We retain server access logs for 30 days.
Why we collect it (purposes)
We process your personal data for the following purposes, each tied to a legal basis under PDPA 2010 (which requires one of the listed exceptions in section 6) and PDPA-SG (which uses the concept of "deemed consent" and notification):
- To provide the core invoicing, project tracking, and time management service (performance of a contract).
- To authenticate you and protect your account (our legitimate interest in fraud prevention).
- To send essential service notices (account, billing, security). These are not marketing.
- To comply with tax record-keeping obligations (legal obligation — typically 7 years for financial records in both MY and SG).
- With your separate consent: occasional product updates. You can withdraw this consent at any time.
Where we store and process your data
Application data is stored in a PostgreSQL database hosted on Neon. The production database runs in AWS
ap-southeast-1(Singapore). Preview and development databases may run in other regions for engineering reasons; those contain synthetic or test data only.Authentication is provided by Neon Auth, which is hosted in the same region as your data. Static assets are served from Vercel's edge network.
Who we share it with
We do not sell, rent, or trade personal data. We share personal data only with the following categories of recipient, each operating under a written agreement that imposes data-protection obligations no less protective than those in this policy:
- Infrastructure: Neon (database + auth), Vercel (hosting), Cloudflare (DNS).
- Email delivery: Resend or a comparable transactional email provider, for essential service emails only.
- Payment processors: Stripe (for paid tiers once launched) and Billplz (FPX for Malaysian users). Card details are collected and stored by the processor; we never see full card numbers.
- Analytics: Vercel Analytics (privacy- friendly, no third-party cookies, no cross-site tracking). No Google Analytics or Facebook Pixel.
- Legal: if compelled by a Malaysian or Singaporean court order, regulatory request, or valid subpoena. We will challenge over-broad requests where lawful and notify affected users where permitted.
Cross-border data transfers
While primary data is hosted in Singapore, some sub-processors (Neon's parent infrastructure, Vercel's global edge) may process or store data in other regions including the US. Where we transfer personal data out of Malaysia or Singapore, we rely on the standard contractual clauses imposed by our sub-processor agreements, which impose PDPA-equivalent obligations on the recipient.
Customers in Singapore whose data is processed in the US are protected by the PDPA-SG transfer limitation obligations (Part IV). We assess each sub-processor's data-protection posture before onboarding.
Cookies & tracking
We use only first-party cookies: a session cookie (signed, HTTP-only, secure, strictly necessary for authentication) and a cookie used by Neon Auth for the same purpose. We do not use third-party advertising or analytics cookies.
Vercel Analytics is cookieless and does not track individual users across sites.
How long we keep your data
- Account data: kept while your account is active. Deleted within 30 days of account deletion.
- Customer data you uploaded: kept while your account is active. Deleted within 30 days of account deletion, except as required by tax law.
- Financial records (invoices, payments): retained for 7 years from the date of the transaction, in line with Malaysian and Singapore tax record-keeping requirements (Income Tax Act 1967; Singapore Income Tax Act).
- Server access logs: 30 days, then deleted.
- Backup snapshots: 30 days rolling retention; deleted on rotation.
Your rights — Malaysia PDPA 2010
Under the PDPA 2010, you have the right to:
- Access: request a copy of the personal data we hold about you.
- Correction: request that we correct inaccurate or incomplete personal data.
- Withdraw consent: where we rely on your consent, you may withdraw it at any time without affecting the lawfulness of processing prior to withdrawal.
- Prevent processing likely to cause damage or distress: subject to statutory exceptions.
Exercise these rights by emailing [email protected]. We will respond within 21 days, the maximum period allowed under PDPA 2010.
If you are not satisfied with our response, you may complain to the Jabatan Perlindungan Data Peribadi (JPDP) , the Malaysian data protection regulator (www.pdp.gov.my).
Your rights — Singapore PDPA
Under the PDPA 2012 (Singapore), you have the right to:
- Access: request a copy of your personal data.
- Correction: request correction of inaccurate or incomplete data.
- Withdraw consent: in the same circumstances as under MY PDPA.
- Opt out of marketing communications at any time (we don't currently send any).
Exercise these rights by emailing [email protected]. We will respond within 30 days, the maximum period allowed under PDPA-SG.
If you are not satisfied with our response, you may lodge a complaint with the Personal Data Protection Commission (PDPC) , the Singapore data protection regulator (www.pdpc.gov.sg).
Security measures
We use industry-standard security controls, including:
- TLS 1.2+ for all data in transit.
- AES-256 at-rest encryption at the storage layer (Neon).
- Argon2 / bcrypt-hashed passwords (handled by Neon Auth).
- Application-level AES-256-GCM encryption for payment-provider API credentials.
- Row-level data isolation: every query filters by your user id, derived from your authenticated session.
- Audit logging of authentication events and payment-related actions.
No system is 100% secure. If we discover a breach affecting your personal data, we will notify you and (where required) the relevant regulator within the statutory window (72 hours under PDPA-SG; as soon as practicable under PDPA 2010).
Children's privacy
Kiralytics is a business tool. We do not knowingly collect personal data from anyone under 18. If you believe a child has registered, contact [email protected] and we will close the account.
Changes to this policy
We will update this policy when our practices change. For material changes, we will give you 30 days' notice by email and via an in-app banner. Continued use after the effective date constitutes acceptance. If you do not agree, you may close your account before the effective date.
Contact
Data Protection Officer: [email protected]
Or by post to the address listed on our terms page.