Privacy Policy

Last updated 30 August 2026

This policy explains what personal data the system holds, where it is stored, who can see it, and how long it is kept. It is written for firms who process their clients’ employee data and need to know exactly where that data goes.

1. What we hold

Account data: the names, email addresses and roles of the people you invite into your workspace, plus a hashed password (we never store passwords in readable form).

Client and engagement data you enter: company details, directors and shareholders, financial figures, uploaded documents.

Employee data you enter for payroll: names, identity card numbers, salaries, EPF, SOCSO and tax reference numbers. This is personal data under the Personal Data Protection Act 2010, and you are the data user for it.

Technical records: sign-in attempts, IP addresses and an audit trail of changes. These exist so a firm can answer the question "who changed this figure, and when".

2. Where it is stored

On a server rented and operated for Adsinar Advisory, in a PostgreSQL database. Documents you upload are stored on the same server, not in a third-party service.

Scanned PDFs and photographed receipts are processed by OCR software running on that same server. Your clients’ figures are not sent to any external conversion website or AI service for reading.

3. Who can see it

Each firm’s workspace is isolated. One firm cannot query, list or reach another firm’s records; this is enforced in the database queries themselves, not just hidden in the interface.

Within your workspace, what a person sees depends on the role you gave them. Clients you invite see only the companies they are linked to.

Adsinar Advisory staff may access a workspace for support, and only when needed to diagnose a problem. Such access is recorded.

4. Who we share it with

We do not sell personal data, and we do not share it for advertising.

Payment processing, when you subscribe, is handled by a payment provider that receives only what is needed to take payment. Card details never reach our server.

We disclose data to an authority only where Malaysian law requires it.

5. How long it is kept

While your workspace is active, your data is kept so you can work with it. Deleted records are marked deleted and retained for a limited period so an accidental deletion can be reversed.

Database backups are taken before every system update and rotated, with older backups removed automatically.

Note that Malaysian law imposes its own retention requirements on accounting records. Those obligations are yours, and you should keep your own copies accordingly.

6. Your rights under the PDPA

People whose personal data you hold in the system may ask you to access or correct it. Because you control your workspace, you can act on those requests directly.

For data we hold about you as an account holder — your name, email, sign-in records — write to [email protected] to access, correct or delete it.

7. Security

Passwords are stored hashed with bcrypt. Sessions are signed and expire. Requests that change data carry CSRF protection. Traffic is encrypted in transit.

No system is perfectly secure. If a breach affects your data, we will tell you what happened, what was affected, and what to do.

8. Cookies

The system uses cookies to keep you signed in, to protect against cross-site request forgery, and to remember your language choice. It does not use advertising or cross-site tracking cookies.

Privacy questions or requests: [email protected]