Effective date: on publication · Version 2026-07-11
This Privacy Policy (also our Personal Data Protection Notice under section 7 of the Personal Data Protection Act 2010) explains how Taokeh handles personal data. It is written for our customers — Malaysian small and medium businesses — and for the people whose data passes through the Service. We have tried to keep it plain and readable.
It is governed by the Personal Data Protection Act 2010 (Act 709) as amended by the Personal Data Protection (Amendment) Act 2024, the changes of which were phased in during 2025 (including the move from "data user" to "data controller", a mandatory Data Protection Officer, data-breach notification, and a data-portability right). Throughout this notice we use the term "data controller" in line with the 2024 amendments.
Taokeh is a cloud accounting and ERP service for Malaysian SMEs (the "Service"). In this notice "Taokeh", "we", "us" and "our" mean the operator of the Service; "you" and "the Customer" mean the business that subscribes to the Service.
The Service is operated by:
(A separate "Taokeh Sdn Bhd" company is a future plan and does not operate the Service today. If the operating entity changes, we will update this notice — see Section 14, Change of ownership.)
For any privacy question, access or correction request, or complaint, contact us. Data protection enquiries: dpo@taokeh.my.
A formal Data Protection Officer will be appointed and named here if and when Taokeh meets the mandatory threshold under the Personal Data Protection (Amendment) Act 2024. Under the 2024 amendments, appointing a DPO and notifying the Commissioner (the Personal Data Protection Department, JPDP) within 21 days of appointment is mandatory once certain thresholds are met — for example processing the personal data of 20,000 or more data subjects, or sensitive personal data (which includes financial data) of 10,000 or more data subjects. If that threshold is met, we will appoint and notify a DPO within 21 days and name them here.
This is the most important part of this notice, so we put it first.
The Service holds two very different kinds of personal data, and Taokeh plays a different role for each.
This is data about you and your team's use of Taokeh itself — the account you open with us, who signs in, your billing status, and how you use the Service. We decide why and how this data is processed, so for this data Taokeh is the data controller. Section 4 covers it.
This is the business data you enter into the Service — your own customers, suppliers, employees, payroll, invoices, bank transactions, uploaded documents and storefront orders. You decide why and how that data is used; Taokeh merely stores and processes it on your instructions to run the Service. For this data you are the data controller and Taokeh is the data processor. Section 5 covers it.
What this means in practice:
We do not sell, rent or trade personal data — neither the account data we control nor the business data you entrust to us. We share data only with the service providers listed in Section 7, only to run the Service, and only as this notice describes.
(a) Account and identity data (you provide this when you sign up and use the Service):
(b) Usage and technical data (collected automatically as you use the Service):
(c) Payment data:
| Purpose | Why | Lawful basis (PDPA 2010, s.6) |
|---|---|---|
| Create and run your account; authenticate sign-in; enforce roles | To deliver the Service you asked for | Necessary for the performance of our contract with you |
| Take payment; manage your prepaid term, renewals and read-only lapse | To bill you and keep your subscription correct | Performance of contract |
| Send service and account emails (security alerts, billing, expiry, important notices) | To operate the account safely | Performance of contract / our legitimate interest in running the Service |
| Keep audit and server logs; detect and prevent fraud, abuse and security incidents | To protect you, other tenants and the Service | Our legitimate interest in security; legal compliance |
| Provide customer support | To help you when you ask | Performance of contract |
| Comply with Malaysian law (tax, accounting, e-commerce record-keeping) | We are legally required to | Compliance with a legal obligation |
| Optional marketing updates about Taokeh | Only if you opt in | Your consent (you can withdraw at any time) |
We process this data only for the purposes above or a directly related purpose (PDPA Disclosure Principle, s.8), and we do not collect more than we need (General Principle, s.6).
The account and identity data in Section 4.1(a) is obligatory — we cannot create or run your account, take payment, or secure your sign-in without it. If you do not supply it, you will not be able to register for or use the Service. Optional marketing consent is entirely voluntary and refusing it has no effect on your use of the Service.
When you use the Service, you enter business records. You are the data controller for this data; Taokeh is your data processor and handles it strictly on your instructions to provide the Service. The categories include:
We process this data only to provide the Service — to store it, display it back to you, run calculations (e.g. payroll statutory figures, SST, e-invoicing), generate your documents, sync your sales channels, and let you export it. We do not use your business data for our own purposes, and we do not use it to train any AI model (see Section 8).
Because you are the data controller for this data, you are responsible for: having a valid lawful basis under the PDPA to hold and upload it; giving your own section 7 notice to the individuals concerned (your customers, employees and suppliers); obtaining explicit consent where the data is sensitive (e.g. employee IC, biometric or financial data under s.40); and keeping it accurate. If any of those individuals contacts us directly, we will refer them to you and assist you as your processor.
The contractual detail of this processor relationship — security, sub-processors, breach handling, audit, and deletion or return of data on termination — is set out in our separate Data Processing Agreement (DPA).
We use a small set of trusted service providers (sub-processors) to run the Service. Each is used only for the purpose stated, and only to the extent needed. We require them to protect the data to a standard consistent with the PDPA. This is the class of third parties to whom data is or may be disclosed (PDPA s.7(1)(e)).
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database hosting (where your data is stored) | Singapore (AWS ap-southeast-1) |
| Render | Application hosting (runs the Service) | Singapore |
| HitPay | Payment processing — MYR, FPX, DuitNow, cards | Singapore |
| Anthropic | Optional AI text features (see Section 8) | United States |
| Zoho Mail | Transactional and account email (e.g. sign-in, billing, alerts) | Zoho Corporation data centres (United States) |
| Cloudflare | DNS, content delivery, and security / web-application firewall | Global edge network (traffic routed to the Singapore region) |
| LHDN MyInvois | e-Invoice submission — only if you use e-invoicing | Malaysia |
| Shopee / TikTok Shop | Marketplace sync — only if you connect your own shop | Regional (Singapore / South-East Asia) |
| Bank Negara Malaysia | Read-only foreign-exchange reference rates — no personal data is sent | Malaysia |
We may also disclose data where we are legally required to (e.g. a court order or a lawful request from an authority), or where necessary to establish, exercise or defend legal rights. We will not disclose your data for any purpose outside this notice without a lawful basis.
Statutory recipients of your payroll data (such as EPF, SOCSO and LHDN) receive that data because you, as the employer and data controller, instruct the Service to generate the relevant statutory files and submissions — not because Taokeh discloses it on its own account.
If we add or change a sub-processor, we will update this list and give at least 14 days' advance notice by email.
Your data is stored and processed in Singapore. Our application runs on Render (Singapore) and our database runs on Supabase / Postgres (AWS ap-southeast-1, Singapore). This means personal data is transferred outside Malaysia, which we disclose to you here as required by the PDPA.
Under the PDPA's cross-border transfer regime (as revised by the 2024 amendments and the Cross-Border Personal Data Transfer Guidelines of 2025), this transfer is supported on the following basis:
We apply appropriate contractual safeguards with our Singapore-based processors for this transfer and review them periodically.
Each tenant's data is isolated from every other tenant's data at the database level using Row-Level Security (see Section 10).
Taokeh offers optional AI helper features (text only) — for example an assistant and a journal-entry drafter. These features are off by default and are gated behind a one-time, workspace-level acceptance of our AI terms. They only operate after that acceptance.
When you use an AI helper:
If you never accept the AI terms, no data is sent to the AI provider.
Taokeh uses only one strictly-necessary cookie — a session / authentication cookie named connect.sid that keeps you signed in and protects your session (e.g. against cross-site request forgery). It is first-party, HttpOnly, SameSite=Lax, marked Secure in production, with a lifetime of about 7 days. We set no advertising or tracking cookies.
We do not use advertising, cross-site tracking, or third-party marketing/analytics cookies. Because the session cookie is strictly necessary to deliver a service you explicitly requested (signing in), we set it without a separate opt-in banner. You can block or delete cookies in your browser settings, but blocking the session cookie will prevent you from logging in. If we ever add non-essential cookies, we will update our notice and obtain your prior consent first.
For full detail, see our separate Cookie Notice.
We take practical steps to protect personal data from loss, misuse and unauthorised access, modification or disclosure. These include:
No system can be guaranteed perfectly secure, but we work to keep these protections current. Our sub-processors are required to maintain equivalent security. Under the 2024 amendments, the Security Principle now also binds data processors directly, and our DPA reflects this.
If a personal-data breach occurs, we will follow the PDPA's breach-notification rules: we will notify the Commissioner (JPDP) as soon as practicable and within 72 hours of becoming aware of a notifiable breach, and where the breach is likely to cause significant harm, we will notify affected data subjects within 7 days of notifying the Commissioner. Where Taokeh is acting as your processor (your business data), we will notify you without undue delay so that you, as the controller, can meet your own notification obligations. We keep an internal breach register.
We keep personal data only for as long as it is needed for the purposes in this notice, then delete or anonymise it.
You can request a full export of your data at any time while it remains available.
Under the PDPA you have the following rights in relation to your own personal data that Taokeh controls (Role A):
How to exercise these rights: email dpo@taokeh.my or write to the address in Section 1. We will respond as soon as practicable and within the period prescribed by the PDPA. A prescribed fee may apply to certain access requests as allowed by law, and there are limited grounds on which we may decline a request (which we will explain if they apply). We keep a log of requests and how we handled them.
If your request concerns business data Taokeh only processes (Role B) — for example you are a customer, employee or supplier of one of our subscribers — please contact that business (the data controller). If you contact us, we will refer you to them and assist them as their processor.
If the Service or Enya Venture's business is sold, merged or reorganised (including any future move to a "Taokeh Sdn Bhd" entity), personal data may be transferred to the successor as part of that transaction. Any successor will remain bound by a privacy standard consistent with this notice, and we will update the operator details here.
The Service is a business tool and is not directed at children. We do not knowingly collect personal data from children. The personal data of individuals who happen to be minors may appear in your business records (for example a storefront buyer or an employee under 18); where it does, you are the data controller for that data and are responsible for the appropriate lawful basis and consent.
This notice is available in English and Bahasa Malaysia, as required by the PDPA (s.7(3)). In the event of any conflict between the two versions, the English version prevails.
We may update this notice from time to time — for example when we add a feature, change a sub-processor, or to reflect changes in the law. When we make a material change, we will update the effective date above and, where appropriate, notify you (e.g. by email or an in-app notice) before the change takes effect. Please review it periodically.
If you have a concern about how we handle personal data, please contact us first at dpo@taokeh.my (Section 1) — we would like the chance to put things right.
You also have the right to lodge a complaint with the regulator:
Enya Venture (operating "Taokeh")
Business reg. no. 003853053-D (202603132312)
Inspirasi Mont Kiara, Jalan Kiara 4, 50480 Kuala Lumpur, Malaysia
Email: admin@taokeh.my · Tel: +60 16-773 9678 · https://taokeh.my
Data protection enquiries: dpo@taokeh.my.
This Privacy Policy doubles as our PDPA section 7 notice. It governs personal data only; how the Service may be used is covered by our Terms of Service, and the processing of your business data on your behalf is covered by our Data Processing Agreement. Governing law: Malaysia.