Taokeh Log in

Privacy Policy

English · Bahasa Malaysia

Effective date: on publication · Version 2026-07-11

Terms of ServicePrivacy PolicyPDPA NoticeAcceptable Use PolicyRefund & Billing PolicyData Processing AddendumCookie Notice

This Privacy Policy (also our Personal Data Protection Notice under section 7 of the Personal Data Protection Act 2010) explains how Taokeh handles personal data. It is written for our customers — Malaysian small and medium businesses — and for the people whose data passes through the Service. We have tried to keep it plain and readable.

It is governed by the Personal Data Protection Act 2010 (Act 709) as amended by the Personal Data Protection (Amendment) Act 2024, the changes of which were phased in during 2025 (including the move from "data user" to "data controller", a mandatory Data Protection Officer, data-breach notification, and a data-portability right). Throughout this notice we use the term "data controller" in line with the 2024 amendments.

1. Who we are, and how to contact us

Taokeh is a cloud accounting and ERP service for Malaysian SMEs (the "Service"). In this notice "Taokeh", "we", "us" and "our" mean the operator of the Service; "you" and "the Customer" mean the business that subscribes to the Service.

The Service is operated by:

  • Enya Venture — a sole proprietorship registered with the Companies Commission of Malaysia (SSM).
  • Business registration no.: 003853053-D (new format 202603132312).
  • Registered address: Inspirasi Mont Kiara, Jalan Kiara 4, 50480 Kuala Lumpur, Malaysia.
  • Email: admin@taokeh.my
  • Telephone: +60 16-773 9678
  • Website: https://taokeh.my

(A separate "Taokeh Sdn Bhd" company is a future plan and does not operate the Service today. If the operating entity changes, we will update this notice — see Section 14, Change of ownership.)

Data Protection Officer (DPO)

For any privacy question, access or correction request, or complaint, contact us. Data protection enquiries: dpo@taokeh.my.

  • By email: dpo@taokeh.my
  • By post: Data Protection enquiries, Enya Venture, Inspirasi Mont Kiara, Jalan Kiara 4, 50480 Kuala Lumpur, Malaysia
  • By telephone: +60 16-773 9678

A formal Data Protection Officer will be appointed and named here if and when Taokeh meets the mandatory threshold under the Personal Data Protection (Amendment) Act 2024. Under the 2024 amendments, appointing a DPO and notifying the Commissioner (the Personal Data Protection Department, JPDP) within 21 days of appointment is mandatory once certain thresholds are met — for example processing the personal data of 20,000 or more data subjects, or sensitive personal data (which includes financial data) of 10,000 or more data subjects. If that threshold is met, we will appoint and notify a DPO within 21 days and name them here.

2. The two roles: what we control vs. what we only process

This is the most important part of this notice, so we put it first.

The Service holds two very different kinds of personal data, and Taokeh plays a different role for each.

Role A — Data Taokeh CONTROLS (we are the data controller)

This is data about you and your team's use of Taokeh itself — the account you open with us, who signs in, your billing status, and how you use the Service. We decide why and how this data is processed, so for this data Taokeh is the data controller. Section 4 covers it.

Role B — Data Taokeh only PROCESSES on your behalf (you are the data controller)

This is the business data you enter into the Service — your own customers, suppliers, employees, payroll, invoices, bank transactions, uploaded documents and storefront orders. You decide why and how that data is used; Taokeh merely stores and processes it on your instructions to run the Service. For this data you are the data controller and Taokeh is the data processor. Section 5 covers it.

What this means in practice:

  • For your business data (Role B), you are responsible for having a lawful basis under the PDPA, for giving your own PDPA section 7 notice to the people whose data you upload (your customers, employees and suppliers), and for obtaining any consent that is required. Taokeh does not decide how that data is used and does not contact those individuals.
  • A separate Data Processing Agreement (DPA) sets out, in contractual detail, how Taokeh handles your business data as your processor. The DPA forms part of your agreement with us.
  • If one of your customers, employees or suppliers asks Taokeh to access, correct or delete their data, we will direct them back to you (the data controller) and, where appropriate, assist you in responding — we will not action it ourselves without your instruction.

3. A quick note: we do not sell your data

We do not sell, rent or trade personal data — neither the account data we control nor the business data you entrust to us. We share data only with the service providers listed in Section 7, only to run the Service, and only as this notice describes.

4. Role A — Personal data Taokeh CONTROLS

4.1 What we collect

(a) Account and identity data (you provide this when you sign up and use the Service):

  • Your name, email address and telephone number.
  • Your password — stored only as a salted hash, never in plain text.
  • Your two-factor authentication (2FA) secrets / recovery details.
  • Your company name, SSM registration number and business address.
  • Your user role and permissions within the workspace.
  • Your billing and subscription status (which plan and add-ons you have, and whether your term is active, lapsed or read-only).

(b) Usage and technical data (collected automatically as you use the Service):

  • Server logs and audit logs (a record of key actions taken in the workspace, for security and accountability).
  • Your IP address, browser type and device information.
  • Session cookies needed to keep you signed in (see Section 9, Cookies).

(c) Payment data:

  • Payments are handled by our payment processor, HitPay (FPX / DuitNow / cards). Taokeh does not store full card numbers, and we do not store your card. We store only your subscription state (plan, add-ons, term dates, paid/unpaid).

4.2 How and why we use it, and our lawful basis under the PDPA

Purpose Why Lawful basis (PDPA 2010, s.6)
Create and run your account; authenticate sign-in; enforce roles To deliver the Service you asked for Necessary for the performance of our contract with you
Take payment; manage your prepaid term, renewals and read-only lapse To bill you and keep your subscription correct Performance of contract
Send service and account emails (security alerts, billing, expiry, important notices) To operate the account safely Performance of contract / our legitimate interest in running the Service
Keep audit and server logs; detect and prevent fraud, abuse and security incidents To protect you, other tenants and the Service Our legitimate interest in security; legal compliance
Provide customer support To help you when you ask Performance of contract
Comply with Malaysian law (tax, accounting, e-commerce record-keeping) We are legally required to Compliance with a legal obligation
Optional marketing updates about Taokeh Only if you opt in Your consent (you can withdraw at any time)

We process this data only for the purposes above or a directly related purpose (PDPA Disclosure Principle, s.8), and we do not collect more than we need (General Principle, s.6).

4.3 Is it obligatory? (PDPA s.7(2))

The account and identity data in Section 4.1(a) is obligatory — we cannot create or run your account, take payment, or secure your sign-in without it. If you do not supply it, you will not be able to register for or use the Service. Optional marketing consent is entirely voluntary and refusing it has no effect on your use of the Service.

5. Role B — Business data Taokeh only PROCESSES on your behalf

When you use the Service, you enter business records. You are the data controller for this data; Taokeh is your data processor and handles it strictly on your instructions to provide the Service. The categories include:

  • Your contacts' personal data — names, emails, phone numbers, addresses and tax identification numbers (TIN) of your customers and vendors.
  • Employee payroll data — this is SENSITIVE personal data (PDPA s.40) and is treated with extra care. It can include IC or passport numbers, EPF / SOCSO / EIS numbers, salary, bank account details and tax-residency information.
  • Financial records — bank transactions, invoices, quotes, delivery orders, purchase orders, the general ledger and related accounting records.
  • Uploaded documents — e.g. SSM certificates, receipts, and bill/expense scans.
  • Storefront buyer orders — the name, address and contact details of people who buy through your hosted storefront.

We process this data only to provide the Service — to store it, display it back to you, run calculations (e.g. payroll statutory figures, SST, e-invoicing), generate your documents, sync your sales channels, and let you export it. We do not use your business data for our own purposes, and we do not use it to train any AI model (see Section 8).

Because you are the data controller for this data, you are responsible for: having a valid lawful basis under the PDPA to hold and upload it; giving your own section 7 notice to the individuals concerned (your customers, employees and suppliers); obtaining explicit consent where the data is sensitive (e.g. employee IC, biometric or financial data under s.40); and keeping it accurate. If any of those individuals contacts us directly, we will refer them to you and assist you as your processor.

The contractual detail of this processor relationship — security, sub-processors, breach handling, audit, and deletion or return of data on termination — is set out in our separate Data Processing Agreement (DPA).

6. Source of the personal data (PDPA s.7(1)(c))

  • Account data (Role A): comes from you directly when you sign up and use the Service, and is generated automatically as you use it (logs, IP, cookies).
  • Business data (Role B): comes from you — you (or your authorised users) enter or upload it, or it flows in from sales channels you connect (Shopee, TikTok Shop) and from your storefront buyers. Taokeh does not buy personal data or acquire it from data brokers.

7. Who we share data with — our sub-processors

We use a small set of trusted service providers (sub-processors) to run the Service. Each is used only for the purpose stated, and only to the extent needed. We require them to protect the data to a standard consistent with the PDPA. This is the class of third parties to whom data is or may be disclosed (PDPA s.7(1)(e)).

Sub-processor Purpose Location
Supabase Database hosting (where your data is stored) Singapore (AWS ap-southeast-1)
Render Application hosting (runs the Service) Singapore
HitPay Payment processing — MYR, FPX, DuitNow, cards Singapore
Anthropic Optional AI text features (see Section 8) United States
Zoho Mail Transactional and account email (e.g. sign-in, billing, alerts) Zoho Corporation data centres (United States)
Cloudflare DNS, content delivery, and security / web-application firewall Global edge network (traffic routed to the Singapore region)
LHDN MyInvois e-Invoice submission — only if you use e-invoicing Malaysia
Shopee / TikTok Shop Marketplace sync — only if you connect your own shop Regional (Singapore / South-East Asia)
Bank Negara Malaysia Read-only foreign-exchange reference rates — no personal data is sent Malaysia

We may also disclose data where we are legally required to (e.g. a court order or a lawful request from an authority), or where necessary to establish, exercise or defend legal rights. We will not disclose your data for any purpose outside this notice without a lawful basis.

Statutory recipients of your payroll data (such as EPF, SOCSO and LHDN) receive that data because you, as the employer and data controller, instruct the Service to generate the relevant statutory files and submissions — not because Taokeh discloses it on its own account.

If we add or change a sub-processor, we will update this list and give at least 14 days' advance notice by email.

8. Cross-border transfer (your data is hosted in Singapore)

Your data is stored and processed in Singapore. Our application runs on Render (Singapore) and our database runs on Supabase / Postgres (AWS ap-southeast-1, Singapore). This means personal data is transferred outside Malaysia, which we disclose to you here as required by the PDPA.

Under the PDPA's cross-border transfer regime (as revised by the 2024 amendments and the Cross-Border Personal Data Transfer Guidelines of 2025), this transfer is supported on the following basis:

  • It is necessary for the performance of our contract with you (the Service is delivered from Singapore-based infrastructure); and
  • Singapore's data-protection law (the PDPA 2012) provides a comparable level of protection; and
  • We put contractual safeguards in place with our Singapore-hosted processors (data-processing terms / standard contractual clauses) so they may not process the data in contravention of the Malaysian PDPA.

We apply appropriate contractual safeguards with our Singapore-based processors for this transfer and review them periodically.

Each tenant's data is isolated from every other tenant's data at the database level using Row-Level Security (see Section 10).

9. AI features (optional, and off by default)

Taokeh offers optional AI helper features (text only) — for example an assistant and a journal-entry drafter. These features are off by default and are gated behind a one-time, workspace-level acceptance of our AI terms. They only operate after that acceptance.

When you use an AI helper:

  • Only the text you submit to that helper is sent to our AI provider, Anthropic (Claude). We do not send your whole database.
  • Outputs are suggestions that a person on your side reviews before they are used. The AI does not make final accounting, tax or legal decisions for you.
  • Under Anthropic's commercial terms, your data is not used to train AI models.

If you never accept the AI terms, no data is sent to the AI provider.

10. Cookies

Taokeh uses only one strictly-necessary cookie — a session / authentication cookie named connect.sid that keeps you signed in and protects your session (e.g. against cross-site request forgery). It is first-party, HttpOnly, SameSite=Lax, marked Secure in production, with a lifetime of about 7 days. We set no advertising or tracking cookies.

We do not use advertising, cross-site tracking, or third-party marketing/analytics cookies. Because the session cookie is strictly necessary to deliver a service you explicitly requested (signing in), we set it without a separate opt-in banner. You can block or delete cookies in your browser settings, but blocking the session cookie will prevent you from logging in. If we ever add non-essential cookies, we will update our notice and obtain your prior consent first.

For full detail, see our separate Cookie Notice.

11. Security (PDPA s.9, Security Principle)

We take practical steps to protect personal data from loss, misuse and unauthorised access, modification or disclosure. These include:

  • Tenant isolation — each customer's data is separated using Postgres Row-Level Security, so one tenant cannot see another's data.
  • Encryption in transit — data is transmitted over encrypted (HTTPS / TLS) connections.
  • Hashed passwords — passwords are stored only as salted hashes, never in readable form.
  • Two-factor authentication (2FA) — available to protect sign-in, with recovery options.
  • Audit logs — key actions in a workspace are logged for accountability and incident investigation.
  • Access controls — role-based permissions limit who can see and do what; our own staff access is limited to what is needed for hosting, support and maintenance.

No system can be guaranteed perfectly secure, but we work to keep these protections current. Our sub-processors are required to maintain equivalent security. Under the 2024 amendments, the Security Principle now also binds data processors directly, and our DPA reflects this.

Data-breach notification

If a personal-data breach occurs, we will follow the PDPA's breach-notification rules: we will notify the Commissioner (JPDP) as soon as practicable and within 72 hours of becoming aware of a notifiable breach, and where the breach is likely to cause significant harm, we will notify affected data subjects within 7 days of notifying the Commissioner. Where Taokeh is acting as your processor (your business data), we will notify you without undue delay so that you, as the controller, can meet your own notification obligations. We keep an internal breach register.

12. How long we keep data (PDPA s.10, Retention Principle)

We keep personal data only for as long as it is needed for the purposes in this notice, then delete or anonymise it.

  • While your subscription is active: we keep your account data and your business data for as long as your workspace is in use.
  • When a term lapses or the account closes: for at least 30 days, your workspace stays read-only and your data remains exportable — it is not deleted immediately. This gives you time to renew or export.
  • Deletion: after that 30-day window, and after a reminder to your account email, the data may be scheduled for deletion. We will delete or anonymise personal data from our active systems within a reasonable period, and purge it from backups on our normal backup-rotation cycle.
  • Legal retention overrides deletion: where Malaysian law requires us (or requires you) to keep certain records for a set period, we keep them for that period even after closure. For example, accounting and tax records are kept for 7 years (Income Tax Act 1967), and seller / e-commerce transaction records are kept for at least 3 years under the Consumer Protection (Electronic Trade Transactions) Regulations 2024. This 7-year retention is Taokeh's own retention, for our own tax and accounting compliance and to defend legal claims; we do not keep these records on your behalf, and it does not relieve you of your own duty to keep your own copies of your records (see Terms §8.4).

You can request a full export of your data at any time while it remains available.

13. Your rights (PDPA Part II)

Under the PDPA you have the following rights in relation to your own personal data that Taokeh controls (Role A):

  • Access — ask for a copy of the personal data we hold about you (s.12).
  • Correction — ask us to correct data that is inaccurate, incomplete, misleading or out of date (s.11–12).
  • Withdraw consent — where we rely on your consent (e.g. marketing), withdraw it at any time, in whole or in part.
  • Limit processing — ask us to limit the processing of your data, including opting out of any direct marketing.
  • Data portability — under the 2024 amendments, ask us to transmit your personal data to another data controller, where this is technically feasible and the formats are compatible.
  • Complain — see Section 18.

How to exercise these rights: email dpo@taokeh.my or write to the address in Section 1. We will respond as soon as practicable and within the period prescribed by the PDPA. A prescribed fee may apply to certain access requests as allowed by law, and there are limited grounds on which we may decline a request (which we will explain if they apply). We keep a log of requests and how we handled them.

If your request concerns business data Taokeh only processes (Role B) — for example you are a customer, employee or supplier of one of our subscribers — please contact that business (the data controller). If you contact us, we will refer you to them and assist them as their processor.

14. Change of ownership

If the Service or Enya Venture's business is sold, merged or reorganised (including any future move to a "Taokeh Sdn Bhd" entity), personal data may be transferred to the successor as part of that transaction. Any successor will remain bound by a privacy standard consistent with this notice, and we will update the operator details here.

15. Children's data

The Service is a business tool and is not directed at children. We do not knowingly collect personal data from children. The personal data of individuals who happen to be minors may appear in your business records (for example a storefront buyer or an employee under 18); where it does, you are the data controller for that data and are responsible for the appropriate lawful basis and consent.

16. Language

This notice is available in English and Bahasa Malaysia, as required by the PDPA (s.7(3)). In the event of any conflict between the two versions, the English version prevails.

17. Changes to this notice

We may update this notice from time to time — for example when we add a feature, change a sub-processor, or to reflect changes in the law. When we make a material change, we will update the effective date above and, where appropriate, notify you (e.g. by email or an in-app notice) before the change takes effect. Please review it periodically.

18. How to complain

If you have a concern about how we handle personal data, please contact us first at dpo@taokeh.my (Section 1) — we would like the chance to put things right.

You also have the right to lodge a complaint with the regulator:

  • the Personal Data Protection Department (Jabatan Perlindungan Data Peribadi, JPDP), Putrajaya — see pdp.gov.my for the current complaint channel.

19. Contact

Enya Venture (operating "Taokeh")
Business reg. no. 003853053-D (202603132312)
Inspirasi Mont Kiara, Jalan Kiara 4, 50480 Kuala Lumpur, Malaysia
Email: admin@taokeh.my · Tel: +60 16-773 9678 · https://taokeh.my
Data protection enquiries: dpo@taokeh.my.

This Privacy Policy doubles as our PDPA section 7 notice. It governs personal data only; how the Service may be used is covered by our Terms of Service, and the processing of your business data on your behalf is covered by our Data Processing Agreement. Governing law: Malaysia.

Terms · Privacy · PDPA Notice · Acceptable Use · Refund & Billing · DPA · Cookies © 2026 Taokeh. Operated by Enya Venture (SSM 003853053-D).
English · Bahasa Malaysia