← Back to home

Privacy Policy

Effective Date: 1 April 2026

1. Introduction

AcctBridge (“we”, “our”, “us”) operates the AcctBridge platform accessible at acctbridge.com and portal.acctbridge.com. This Privacy Policy explains how we collect, use, disclose, and protect personal data in accordance with the Personal Data Protection Act 2010 (PDPA) of Malaysia.

By using the Service, you consent to the practices described in this Privacy Policy.

2. Who We Are

AcctBridge is a Developer API Gateway providing ISVs, system integrators, and developers with secure REST API access to on-premise SQL Accounting and AutoCount Accounting installations across Malaysia and Southeast Asia.

Data Controller: AcctBridge — privacy@acctbridge.com

3. Personal Data We Collect

Account Data: Full name, company name, business email, billing address, subscription tier and usage records. Payment information is processed by approved third-party payment providers such as Stripe, PayPal, Payoneer, or banking providers; we do not store card numbers.

API Request Data (Transient Only): API payloads are proxied in real-time and are not written to our database. Only metadata (API call status, timestamp, tenant ID, response code) is retained.

Technical Data: IP addresses, browser/device information, API request logs (tenant ID, endpoint, timestamp, status code — no payload content), Cloudflare Tunnel connection metadata.

4. How We Use Your Personal Data

PurposeLegal Basis
Provision of ServiceContractual necessity
Billing and subscription managementContractual necessity
Security monitoring and fraud preventionLegitimate interests
Service notificationsContractual necessity / Consent
Legal obligationsLegal obligation

We do not use your data for advertising or sell it to third parties.

5. Zero-Persistence Architecture

API requests are proxied in real-time and not written to our database. Our cloud systems retain operational metadata such as tenant ID, endpoint, timestamp, status code, latency, and tunnel or connection status, but not accounting document payloads. This architecture is designed with PDPA data minimisation principles in mind.

6. Data Retention

Data TypeRetention
Account and profile dataDuration of subscription + 2 years
Operational metadata2 years from event date
Billing records7 years (Malaysian tax compliance)
API access logs90 days

7. Your Rights Under PDPA

You have the right to access, correct, withdraw consent, and request deletion of your personal data. Email privacy@acctbridge.com with subject “PDPA Data Request”. We respond within 21 days.

8. Data Security

All data in transit encrypted via TLS 1.2+. API authentication via SHA-256 hashed keys and Ed25519 JWT tokens. Cloudflare Tunnel encrypts all traffic between our cloud and your local agent.

9. Contact

Privacy Officer: privacy@acctbridge.com

If unsatisfied with our response, you may lodge a complaint with the Department of Personal Data Protection Malaysia at pdp.gov.my.