Privacy Policy

How we handle your data

Effective 28 September 2026 · v1.0 · Applies to all Kiralytics users in Malaysia and Singapore

Plain-language summary

We store your business data so the app works.
Client names, invoices, time entries, and the logo you upload live in a Postgres database hosted on Neon (Singapore / US-East regions, depending on the branch your account is allocated to). We use this data only to render the app for you.
We don't sell your data. Ever.
No third-party ad targeting. No analytics resale. No model training on your data. We charge a subscription fee and that's our business model — not your data.
Authentication is handled by Neon Auth.
Your password is hashed and we never see the plaintext. Session cookies are signed and HTTP-only.
You own your data.
Export anytime. Delete your account and we erase your records within 30 days, except where tax law requires us to keep financial records for 7 years.
Two regimes apply.
Malaysia users have full PDPA 2010 rights. Singapore users additionally benefit from PDPA-SG baseline rights. Both groups can request access, correction, or deletion of their personal data.
  1. Who we are (data controller)

    Kiralytics is operated by SP Rekayasa Networks, a company registered in Malaysia. For the purposes of the Personal Data Protection Act 2010 (Malaysia) and the Personal Data Protection Act 2012 (Singapore), SP Rekayasa Networks is the data controller of personal data processed through this service.

    Contact our Data Protection Officer at privacy@kiralytics.com.

  2. What personal data we collect

    We collect personal data in three categories:

    • Account data you give us: name, email address, password (hashed, never stored in plaintext), and business settings (business name, address, SSM/UEN registration number if you choose to provide it, logo image).
    • Customer data you upload: your clients' names, addresses, emails, phone numbers, and any identification numbers you choose to record against their profile. This is the data of your customers, not ours — you are the data controller for it under PDPA and PDPA-SG.
    • Technical data: IP address, browser type, and timestamps of access, used for security and debugging. We retain server access logs for 30 days.
  3. Why we collect it (purposes)

    We process your personal data for the following purposes, each tied to a legal basis under PDPA 2010 (which requires one of the listed exceptions in section 6) and PDPA-SG (which uses the concept of "deemed consent" and notification):

    • To provide the core invoicing, project tracking, and time management service (performance of a contract).
    • To authenticate you and protect your account (our legitimate interest in fraud prevention).
    • To send essential service notices (account, billing, security). These are not marketing.
    • To comply with tax record-keeping obligations (legal obligation — typically 7 years for financial records in both MY and SG).
    • With your separate consent: occasional product updates. You can withdraw this consent at any time.
  4. Where we store and process your data

    Application data is stored in a PostgreSQL database hosted on Neon. The production database runs in AWS ap-southeast-1 (Singapore). Preview and development databases may run in other regions for engineering reasons; those contain synthetic or test data only.

    Authentication is provided by Neon Auth, which is hosted in the same region as your data. Static assets are served from Vercel's edge network.

  5. Who we share it with

    We do not sell, rent, or trade personal data. We share personal data only with the following categories of recipient, each operating under a written agreement that imposes data-protection obligations no less protective than those in this policy:

    • Infrastructure: Neon (database + auth), Vercel (hosting), Cloudflare (DNS).
    • Email delivery: Resend or a comparable transactional email provider, for essential service emails only.
    • Payment processors: Stripe (for paid tiers once launched) and Billplz (FPX for Malaysian users). Card details are collected and stored by the processor; we never see full card numbers.
    • Analytics: Vercel Analytics (privacy- friendly, no third-party cookies, no cross-site tracking). No Google Analytics or Facebook Pixel.
    • Legal: if compelled by a Malaysian or Singaporean court order, regulatory request, or valid subpoena. We will challenge over-broad requests where lawful and notify affected users where permitted.
  6. Cross-border data transfers

    While primary data is hosted in Singapore, some sub-processors (Neon's parent infrastructure, Vercel's global edge) may process or store data in other regions including the US. Where we transfer personal data out of Malaysia or Singapore, we rely on the standard contractual clauses imposed by our sub-processor agreements, which impose PDPA-equivalent obligations on the recipient.

    Customers in Singapore whose data is processed in the US are protected by the PDPA-SG transfer limitation obligations (Part IV). We assess each sub-processor's data-protection posture before onboarding.

  7. Cookies & tracking

    We use only first-party cookies: a session cookie (signed, HTTP-only, secure, strictly necessary for authentication) and a cookie used by Neon Auth for the same purpose. We do not use third-party advertising or analytics cookies.

    Vercel Analytics is cookieless and does not track individual users across sites.

  8. How long we keep your data

    • Account data: kept while your account is active. Deleted within 30 days of account deletion.
    • Customer data you uploaded: kept while your account is active. Deleted within 30 days of account deletion, except as required by tax law.
    • Financial records (invoices, payments): retained for 7 years from the date of the transaction, in line with Malaysian and Singapore tax record-keeping requirements (Income Tax Act 1967; Singapore Income Tax Act).
    • Server access logs: 30 days, then deleted.
    • Backup snapshots: 30 days rolling retention; deleted on rotation.
  9. Your rights — Malaysia PDPA 2010

    Under the PDPA 2010, you have the right to:

    • Access: request a copy of the personal data we hold about you.
    • Correction: request that we correct inaccurate or incomplete personal data.
    • Withdraw consent: where we rely on your consent, you may withdraw it at any time without affecting the lawfulness of processing prior to withdrawal.
    • Prevent processing likely to cause damage or distress: subject to statutory exceptions.

    Exercise these rights by emailing privacy@kiralytics.com. We will respond within 21 days, the maximum period allowed under PDPA 2010.

    If you are not satisfied with our response, you may complain to the Jabatan Perlindungan Data Peribadi (JPDP) , the Malaysian data protection regulator (www.pdp.gov.my).

  10. Your rights — Singapore PDPA

    Under the PDPA 2012 (Singapore), you have the right to:

    • Access: request a copy of your personal data.
    • Correction: request correction of inaccurate or incomplete data.
    • Withdraw consent: in the same circumstances as under MY PDPA.
    • Opt out of marketing communications at any time (we don't currently send any).

    Exercise these rights by emailing privacy@kiralytics.com. We will respond within 30 days, the maximum period allowed under PDPA-SG.

    If you are not satisfied with our response, you may lodge a complaint with the Personal Data Protection Commission (PDPC) , the Singapore data protection regulator (www.pdpc.gov.sg).

  11. Security measures

    We use industry-standard security controls, including:

    • TLS 1.2+ for all data in transit.
    • AES-256 at-rest encryption at the storage layer (Neon).
    • Argon2 / bcrypt-hashed passwords (handled by Neon Auth).
    • Application-level AES-256-GCM encryption for payment-provider API credentials.
    • Row-level data isolation: every query filters by your user id, derived from your authenticated session.
    • Audit logging of authentication events and payment-related actions.

    No system is 100% secure. If we discover a breach affecting your personal data, we will notify you and (where required) the relevant regulator within the statutory window (72 hours under PDPA-SG; as soon as practicable under PDPA 2010).

  12. Children's privacy

    Kiralytics is a business tool. We do not knowingly collect personal data from anyone under 18. If you believe a child has registered, contact privacy@kiralytics.com and we will close the account.

  13. Changes to this policy

    We will update this policy when our practices change. For material changes, we will give you 30 days' notice by email and via an in-app banner. Continued use after the effective date constitutes acceptance. If you do not agree, you may close your account before the effective date.

  14. Contact

    Data Protection Officer: privacy@kiralytics.com

    Or by post to the address listed on our terms page.