Data Processing Agreement (DPA)
Effective: 3 July 2026
AiAkaun is a product of Data Brain Sdn. Bhd. (1335252-P), Tingkat 1, 2309, Jalan SJ 10/1, Taman Seremban Jaya, 70450 Seremban, Negeri Sembilan, Malaysia.
This Data Processing Agreement ("DPA") supplements the AiAkaun Terms of Service and sets out the terms under which Data Brain Sdn. Bhd. (the "Processor") processes personal data on your behalf (the "Controller") under the Personal Data Protection Act 2010 (Amendment 2024).
1. Subject matter & duration
This DPA applies throughout your active account tenure and any legally mandated retention periods (e.g. seven years for tax documentation).
2. Nature & purpose of processing
Data is processed exclusively to deliver AiAkaun's accounting functionality — including optical character recognition (OCR), AI extraction, classification, verification, report generation, encrypted archiving, and system monitoring.
3. Categories of personal data
(a) your company financial documents (customer-supplied, confidential); (b) director/individual identification details including signatures (regulated); (c) account credentials (from registration); (d) transaction information (excluding sensitive payment card details).
4. Processor obligations
We: process only per your lawful instructions; maintain confidentiality; deploy safeguards meeting statutory standards; restrict third-party engagements; assist with data subject rights requests; report incidents within 48 hours; destroy/anonymise records post-termination; and provide compliance documentation.
5. Authorised sub-processors
We use the following sub-processors to deliver the Service:
| Sub-processor | Function | Location |
|---|---|---|
| Google LLC | OCR & AI reading (Gemini) | USA / Singapore |
| Anthropic PBC | AI classification (Claude) | USA |
| Billplz Sdn. Bhd. | Payment processing | Malaysia |
| Contabo GmbH | Server hosting | Germany / Singapore |
| Resend | Email delivery | USA |
We will give prior notice of material changes to this list.
6. Cross-border transfer
International transfers involve sub-processors operating under agreements providing equivalent protection standards per Section 129 of the PDPA.
7. Security measures (technical & organisational)
TLS 1.2+ in transit and AES-256 at rest; password security with optional 2FA; hierarchical permission architecture (RBAC); a comprehensive audit trail retained for 5 years; suspicious-activity monitoring; daily encrypted backups with a 30-day window; and automated code vulnerability scanning plus systematic testing.
8. Data subject rights
Self-service tools enable statutory rights: exporting information, editing your profile, and revoking consent with a 30-calendar-day waiting period before permanent erasure.
9. Breach notification
We will notify the Controller within 48 hours, detailing the incident's nature, affected data categories, foreseeable impact, and remedial actions — to enable timely official notification.
10. Audits & inspections
The Controller may conduct one annual compliance review with 30 days' notice, requesting summary-level security metrics. In-person inspections require mutual consent and are borne by the customer.
11. Termination & return of data
Within 30 days of termination: information is either exported via the automated export function or rendered non-identifiable; anonymised activity logs may be retained for regulatory compliance.
12. Liability
Contractual liability follows the general liability limitations in the AiAkaun Terms of Service, excluding statutory obligations under Malaysian data protection law.
13. Governing law & jurisdiction
Malaysian jurisdiction applies, with exclusive venue in Seremban, Negeri Sembilan.
Acceptance: Commercial use of AiAkaun constitutes acceptance of this DPA. Organisations requiring a formally executed letterhead version may contact admin@aiakaun.com.