1. Introduction
Quipu Software Solutions ("Quipu", "we", "us", or "our") operates the Quipu AI Accounting platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our web application and services, in accordance with the Personal Data Protection Act 2010 (PDPA) of Malaysia.
By accessing or using Quipu, you consent to the processing of your personal data as described in this Privacy Policy. If you do not agree, please discontinue use of our services.
2. Information We Collect
2.1 Information You Provide
- Account Information: Name, mobile number, email address, and business details when you register.
- Business Data: Company name, Business Registration No (BRN), Tax Identification No (TIN), SST Registration No, invoices, financial transactions, party details, bank statements, and other accounting data you enter or upload.
- Payment Information: Subscription payment details processed through our payment gateway (FPX, DuitNow, and card networks). We do not store your card or bank account details directly.
- Communications: Messages you send through our contact form, support requests, or feedback.
2.2 Information Collected Automatically
- Usage Data: Pages visited, features used, time spent, and interaction patterns to improve our service.
- Device Information: Browser type, operating system, device type, and screen resolution.
- Log Data: IP address, access times, and referring URLs.
2.3 AI-Processed Data
- Document Scanning: When you use our AI invoice scanning feature, images or PDFs you upload are processed to extract text and financial data. These documents are processed in real-time and are not retained after extraction is complete.
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our accounting and SST compliance services
- Generate SST-02 returns from your transaction data
- Prepare and submit MyInvois e-invoices to LHDN on your behalf
- Process AI-powered invoice scanning and data extraction
- Send important notifications about filing deadlines, compliance alerts, and supplier discrepancies
- Process subscription payments and manage your account
- Respond to your support requests and communications
- Analyse usage patterns to improve our platform (aggregated, non-personal data only)
- Comply with legal obligations under Malaysian tax law and the Personal Data Protection Act 2010
4. Our PDPA Commitments
We process personal data in line with the seven principles of the Personal Data Protection Act 2010:
- General Principle: We process your personal data only with your consent and for lawful purposes connected with our services.
- Notice & Choice Principle: This policy informs you of the data we collect, why we collect it, and your rights over it.
- Disclosure Principle: We do not disclose your personal data for any purpose other than those described here without your consent.
- Security Principle: We apply the technical and organisational safeguards described below to protect your data.
- Retention Principle: We keep your personal data only for as long as necessary to fulfil its purpose or to meet legal obligations.
- Data Integrity Principle: We take reasonable steps to ensure your data is accurate, complete, and up to date.
- Access Principle: You may access and correct your personal data as described in Section 8.
5. Data Isolation & Security
Your business data is protected through multiple layers of security:
- Schema-Level Isolation: Each company's data is stored in a completely separate database schema. Your data is never co-mingled with other tenants.
- Encryption: All data is encrypted in transit (TLS 1.3) and at rest (AES-256 encryption).
- Access Controls: Role-based access control (Owner, Admin, Accountant, Viewer) ensures only authorised personnel access your data.
- Two-Factor Authentication: Optional 2FA adds an extra layer of protection to your account.
- Regular Backups: Daily automated backups with point-in-time recovery capability.
- Audit Trail: Complete logging of all actions for accountability and compliance.
6. Data Location
Your personal and business data is hosted on servers located in the Malaysia region. Where any processing takes place outside Malaysia, we ensure it is carried out under safeguards consistent with the PDPA.
7. Data Sharing & Disclosure
We do not sell, trade, or rent your personal or business data to third parties. We may share data only in these circumstances:
- Payment Processing: Transaction details shared with our payment gateway (supporting FPX, DuitNow, and card networks) for subscription payments, governed by their privacy policy.
- MyInvois Submission: When you choose to issue e-invoices, the relevant invoice data is transmitted to the LHDN MyInvois portal as required by law.
- Legal Compliance: When required by law, regulation, court order, or a governmental or regulatory authority such as LHDN, RMCD, or SSM.
- Service Providers: Cloud hosting and infrastructure providers who process data on our behalf under strict data processing agreements.
8. Your Rights & Data Retention
We retain your data as follows:
- Active Accounts: All data is retained as long as your subscription is active.
- After Cancellation: Business data is retained for 90 days after subscription cancellation, after which it is permanently deleted.
- Financial Records: As required by Malaysian tax law, certain financial records may be retained for up to 7 years.
- Scanned Documents: Processed in real-time and not stored beyond the extraction session.
In accordance with the Personal Data Protection Act 2010, you have the right to:
- Access: Request a copy of your personal data we hold. We aim to respond to a data subject access request (DSAR) within 30 days.
- Correction: Update or correct inaccurate or incomplete personal data.
- Withdraw Consent: Withdraw your consent to the processing of your personal data, subject to legal retention requirements.
- Limit Processing: Request that we limit the processing of your personal data for certain purposes, including direct marketing.
- Data Portability: Export your data in standard formats (Excel, PDF, JSON).
To exercise these rights, contact us at aiaccounting@quipu.in. You may also lodge a complaint with the Department of Personal Data Protection (Jabatan Perlindungan Data Peribadi, JPDP).
9. Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and interests, we will take prompt remedial action and notify affected users and, where appropriate, the Department of Personal Data Protection (JPDP) without undue delay.
10. Cookies
We use essential cookies for authentication and session management. We do not use third-party advertising or tracking cookies. Analytics cookies are used only in aggregated form to improve the platform.
11. Children's Privacy
Quipu is a business accounting platform and is not intended for use by individuals under the age of 18. We do not knowingly collect data from minors.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or an in-app notification at least 30 days before they take effect.
13. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at: