1. What this Addendum is and who it's for
This Data Processing Addendum ("DPA") forms part of, and is governed by, the Taokeh Terms of Service ("Terms") between you and us. It applies where, in using the Service, you upload or enter personal data about other people — for example your own customers, suppliers, and employees — that we then store and process on your behalf.
In this DPA:
- "we", "us", "Taokeh" = Enya Venture, a sole proprietorship registered with SSM (Suruhanjaya Syarikat Malaysia), business registration no. 003853053-D (new format 202603132312), registered at Inspirasi Mont Kiara, Jalan Kiara 4, 50480 Kuala Lumpur, Malaysia. Contact: admin@taokeh.my, tel +60 16-773 9678.
- "you", "the Customer" = the subscriber to the Service.
- "the Service" = the Taokeh cloud accounting and ERP software at https://taokeh.my.
You do not need to sign a separate copy. By accepting the Terms and using the Service to process other people's personal data, this DPA applies to you. If your organisation requires a counter-signed copy for its own records, email admin@taokeh.my and we will arrange one.
Applicable data protection law means the Malaysian Personal Data Protection Act 2010 (Act 709) as amended by the Personal Data Protection (Amendment) Act 2024 (Act A1727) ("PDPA"), and any guidance issued by the Personal Data Protection Commissioner / Jabatan Perlindungan Data Peribadi ("JPDP").
2. Roles: who is the controller and who is the processor
The PDPA (as amended in 2024) uses the term data controller (formerly "data user") for the party that decides why and how personal data is processed, and data processor for the party that processes it on the controller's instructions.
| Data |
Role of the Customer |
Role of Taokeh |
| Personal data the Customer enters about its own customers, suppliers, contacts and employees (the "Customer Personal Data") |
Data controller |
Data processor |
| The Customer's own account/identity and billing data (name, email, login, company + SSM details, subscription status) |
— |
Data controller (covered by our Privacy Policy, not this DPA) |
So: for everything you put into the Service about third parties, you are the controller and we are only your processor. We act on your documented instructions and do not decide our own purposes for that data.
Your responsibilities as controller. You confirm that you have a lawful basis under the PDPA to process the Customer Personal Data and to have us process it for you (consent or another lawful basis), that you have given the people concerned the PDPA section 7 notice they are entitled to, and — for sensitive personal data (see Annex 1) — that you have the required explicit consent. We rely on these confirmations.
3. Scope, subject-matter and duration
- Subject-matter: our processing of the Customer Personal Data solely to provide, support, secure and maintain the Service for you.
- Nature and purpose: hosting, storage, computation, transmission, backup, and the specific feature processing you switch on (e.g. invoicing, payroll/statutory calculations, e-invoicing, marketplace sync, storefront orders). Full detail is in Annex 1.
- Duration: for as long as you have an active or read-only workspace, and until the Customer Personal Data is deleted or returned under section 10. (When a prepaid term lapses, the workspace becomes read-only; your data is retained and remains exportable — it is not deleted immediately.)
- Types of data and data subjects: set out in Annex 1, which is the controlling description of the processing.
4. Our obligations as your processor
We will:
- Process only on your documented instructions. We process the Customer Personal Data only to provide the Service and only on your instructions, which are given through your use of the Service, the Terms, this DPA, and any support requests you make. We will tell you if we believe an instruction breaches the PDPA (and may pause that processing), though we are not obliged to give you legal advice.
- Keep our people under confidentiality. Everyone we authorise to access the Customer Personal Data is bound by a duty of confidentiality and is given access only on a need-to-know basis.
- Keep it secure (PDPA Security Principle, s.9). We apply the technical and organisational security measures described in Annex 2 — including tenant isolation enforced by Postgres Row-Level Security, encryption in transit, hashed passwords and optional 2FA, access controls, and audit logging. Under the 2024 amendments the Security Principle applies directly to us as processor, and we accept that responsibility.
- Help you respond to data-subject requests. If a person whose data you control contacts us directly (for access, correction, withdrawal of consent, limiting processing, or data portability), we will not respond on the merits; we will refer them to you and notify you. Taking into account the nature of the processing, we will give you reasonable assistance — through the Service's own export, edit and delete tools, or otherwise — so you can meet your PDPA section 12 and portability obligations.
- Help you with breaches and your other PDPA duties. We will give you reasonable assistance with security, breach handling, any data-protection impact assessment you carry out, and consultation with the Commissioner, taking into account the information available to us.
- Notify you of a personal-data breach. If we become aware of a personal-data breach affecting the Customer Personal Data, we will notify you without undue delay and, in any event, in time to help you meet your own PDPA breach-notification deadlines. Our notice will describe, as far as we know it, the nature of the breach, the data and people likely affected, the likely consequences, and the steps taken or proposed. Reminder of your duty (PDPA 2024, in force 1 June 2025): as controller, you must notify the Commissioner as soon as practicable and within 72 hours of becoming aware of a notifiable breach, and notify affected individuals without unnecessary delay and within 7 days of notifying the Commissioner where the breach is likely to cause significant harm. We will support those timelines; the decision and the notifications remain yours to make.
- Make information available. We will give you the information reasonably necessary to show that we are meeting these obligations (see section 7).
- Return or delete on the end of service (section 10).
5. Sub-processors
You give us general authorisation to engage the sub-processors listed in the Sub-processor Table in section 6 to help deliver the Service.
- We require each sub-processor to be bound by data-protection obligations no less protective than those in this DPA, appropriate to what they do for us.
- We remain responsible to you for a sub-processor's performance of those obligations.
- New or replacement sub-processors: we will update the table in section 6 and give you reasonable advance notice (we give at least 14 days' advance notice by email before the new sub-processor starts processing the Customer Personal Data, except where a faster change is needed for security or continuity).
- Your right to object: if you have reasonable, data-protection grounds to object to a new sub-processor, tell us at admin@taokeh.my within the notice period. We will work with you in good faith to address it. If we can't, you may stop using the affected feature or terminate the part of the Service that needs that sub-processor, as your sole remedy — see the interplay with the Terms in section 9.
The table is the single source of truth for who processes the Customer Personal Data on our behalf. Some sub-processors only ever receive data when you switch on the matching feature or connect your own account — this is flagged in the "When involved" column.
6. Sub-processor Table
This table is the authoritative, current list of Taokeh's sub-processors for the Customer Personal Data. It supersedes any list stated elsewhere. "When involved" tells you whether a sub-processor is always used or only when you turn on a feature / connect your own account.
| Sub-processor |
Purpose |
Location |
When involved |
| Supabase |
Database hosting (Postgres) — primary store for your records |
Singapore (AWS ap-southeast-1) |
Always |
| Render |
Application hosting — runs the Service |
Singapore |
Always |
| Cloudflare |
DNS, CDN, and security / WAF protection |
Global edge (routes to Singapore origin) |
Always |
| Zoho Mail |
Transactional and account email (e.g. notifications, payslip delivery) |
Zoho Corporation data centres (United States) |
Always |
| HitPay |
Payment processing for your Taokeh subscription (MYR, FPX, DuitNow, cards) |
Singapore |
Always (subscription billing) |
| Anthropic |
AI text-helper features (Claude). Only the text you submit to an AI helper is sent; outputs are suggestions you review. Under Anthropic's commercial terms your data is not used to train models |
United States |
Only when you enable AI features (one-time, workspace-level "AI terms" acceptance) |
| LHDN MyInvois |
e-Invoice submission to the tax authority |
Malaysia |
Only when you use e-invoicing |
| Shopee |
Marketplace order / listing / inventory sync |
Regional (Singapore / South-East Asia) |
Only when you connect your own Shopee shop |
| TikTok Shop |
Marketplace order / listing / inventory sync |
Regional (Singapore / South-East Asia) |
Only when you connect your own TikTok Shop |
| Bank Negara Malaysia (BNM) |
Read-only FX reference rates |
Malaysia |
Multi-currency feature — no personal data sent |
Notes:
- BNM is listed for completeness only; we send it no personal data (rates are read-only reference data).
- MyInvois, Shopee and TikTok Shop are, in substance, recipients/processors you direct by choosing to e-invoice or to connect your shop. For data flowing to them through your own connection, you act as controller of that onward flow.
- For any sub-processor located outside Malaysia, the cross-border transfer position in section 8 applies.
7. Audit and information rights
We will make available to you the information reasonably necessary to demonstrate our compliance with this DPA, and will allow for and contribute to audits, as follows:
- First, our documentation. On reasonable written request (no more than once a year, unless required by the Commissioner or after a breach affecting your data), we will provide a summary of our relevant security measures and answer reasonable written questions, subject to confidentiality.
- On-site / deeper audit. If that is not enough to satisfy a specific PDPA requirement, you (or an independent, qualified auditor you appoint who is bound by confidentiality and is not a competitor of ours) may audit our handling of the Customer Personal Data, on at least 30 days' written notice, during business hours, no more than once a year, in a way that does not compromise the security or confidentiality of other customers' data or our systems.
- Costs: each party bears its own costs, except that you bear our reasonable costs for an on-site audit beyond the documentation route, unless the audit reveals our material non-compliance.
This does not give access to other tenants' data, our wider infrastructure beyond what is relevant, or commercially sensitive information unrelated to the Customer Personal Data.
8. International transfer (to Singapore)
The Customer Personal Data is stored and processed in Singapore (Supabase on AWS ap-southeast-1, and Render — Singapore region). This is a cross-border transfer out of Malaysia under the PDPA, and we disclose it to you clearly here.
Under the post-2024 risk-based cross-border regime, this transfer is intended to be lawful on the basis that:
- it is necessary for the performance of the Service (a contract you have entered into), and/or
- the destination provides protection comparable to the PDPA — Singapore's PDPA 2012 is commonly assessed as comparable, and/or
- the recipient is bound by reasonable contractual safeguards.
We apply appropriate contractual safeguards with our Singapore-based processors for this transfer and review them periodically, and we contract our Singapore-based sub-processors on terms requiring appropriate protection. You remain responsible, as controller, for disclosing this Singapore transfer in your own PDPA section 7 notice to your data subjects.
9. Liability and how this fits with the Terms
- This DPA is part of the Terms. Where there is a direct conflict between this DPA and the rest of the Terms on a data-protection matter, this DPA prevails for that matter; on everything else, the Terms govern.
- The limitation of liability and the liability cap in the Terms apply to this DPA, and your and our total combined liability arising out of or related to this DPA and the Terms is subject to that single cap — this DPA does not create a separate or additional cap.
- Your remedy for an unresolved sub-processor objection is limited to the stop-feature / terminate route in section 5.
- Governing law and jurisdiction: Malaysia; the courts of Kuala Lumpur, as stated in the Terms.
10. Return or deletion at the end of service
When the Service ends, or on your written request:
- You can export the Customer Personal Data using the Service's export tools. For at least 30 days after a term lapses or the account closes, your workspace stays read-only and your data remains exportable.
- After that window, and after a reminder to your account email, the data may be scheduled for deletion: we will delete or anonymise the Customer Personal Data from the active database, and purge it from backups in the ordinary backup-rotation cycle, except where we are required to retain certain data by law — for example accounting and tax records kept for 7 years under the Income Tax Act 1967, and seller / e-commerce transaction records kept for at least 3 years under the Consumer Protection (Electronic Trade Transactions) Regulations 2024 (CPETTR 2024). This 7-year retention is Taokeh's own retention, for our own tax and accounting compliance and to defend legal claims; we do not keep these records on your behalf, and it does not relieve you of your own duty to keep your own copies (see Terms §8.4).
- On written request after deletion, we will confirm that deletion has been carried out.
Annex 1 — Details of the processing
Controller: the Customer. Processor: Taokeh (Enya Venture).
Subject-matter and duration: as in sections 3 and 10.
Nature and purpose of processing: hosting, storage, computation, transmission, backup, and feature-specific processing within the Service (general ledger; invoicing/quotes/DO/PO; inventory; banking and reconciliation; payroll with Malaysian statutory calculations — EPF/SOCSO/EIS/PCB/HRDF/Zakat; MyInvois e-invoicing; SST returns; marketplace channels — Shopee, TikTok Shop; hosted storefront; fixed assets; multi-currency; optional AI text helpers), in each case only to provide the Service to the Customer.
Categories of data subjects (as entered by the Customer):
- the Customer's customers / buyers (including storefront buyers);
- the Customer's suppliers / vendors / contacts;
- the Customer's employees.
Categories of personal data:
- Contact / identity PII of customers and suppliers: names, emails, phone numbers, addresses, tax identification numbers (TIN);
- Employee payroll data — SENSITIVE: IC / passport numbers, EPF / SOCSO / EIS numbers, salary, bank account details, tax-residency information;
- Financial records: bank transactions, invoices and other accounting records (which may contain personal data);
- Uploaded documents: SSM certificates, receipts, bill / expense scans (which may contain personal data);
- Storefront orders: buyer name, address and contact details.
Sensitive personal data: the employee payroll data above includes categories the PDPA treats as sensitive / high-sensitivity (national-ID-adjacent identifiers; financial data). The Customer is responsible for the explicit consent required to process these.
Annex 2 — Technical and organisational security measures (TOMs)
These summarise the measures we apply; we may update them as long as protection is not reduced.
- Tenant isolation: every tenant's data is segregated and access-controlled using Postgres Row-Level Security, scoped per tenant on every query through our tenant-scoping layer.
- Encryption in transit: TLS/HTTPS for all access to the Service.
- Access control & authentication: hashed passwords, optional two-factor authentication, role-based access for users within a workspace, and least-privilege internal access.
- Logging & monitoring: server and audit logs of relevant activity.
- Hosting security: application and database hosted with reputable providers in Singapore (Render; Supabase / AWS ap-southeast-1); edge security / WAF via Cloudflare.
- Confidentiality: personnel bound by confidentiality and need-to-know access.
- Backups: regular backups with a defined rotation, supporting recovery and the deletion-on-termination process in section 10.
- Sub-processor diligence: sub-processors engaged under the terms in section 5 and listed in section 6.
Annex 3 — Approved sub-processor list
The approved sub-processor list is the Sub-processor Table in section 6 of this DPA, which is the single source of truth and is kept current there. We do not maintain a separate list elsewhere.
Contact for any question about this DPA, or to request a counter-signed copy: admin@taokeh.my, tel +60 16-773 9678. Data protection enquiries: dpo@taokeh.my. A formal Data Protection Officer will be appointed and named here if and when Taokeh meets the mandatory threshold under the Personal Data Protection (Amendment) Act 2024.