Skip to content

Data Processing Agreement

How TwentyCore handles the personal data you put into the service, and what we commit to as your data processor.

Version 2026-09 · Last updated: September 2026

This Data Processing Agreement (“DPA”) forms part of the TwentyCore Terms of Service between TwentyCore Sdn Bhd (Registration No. 1670365P), Block E, Level 11-01, Oasis Square, Ara Damansara, 47301 Petaling Jaya, Selangor, Malaysia (“TwentyCore”, the “Processor”) and the customer identified in the account (“Customer”, the “Controller”). It applies to the extent TwentyCore processes Personal Data on the Customer’s behalf while providing the service.

A counter-signed copy for your procurement file is available on request from hello@twentycore.ai.

1. Definitions


“Personal Data”, “processing”, “data subject”, “data user” and “data processor” have the meanings given in the Personal Data Protection Act 2010 (Malaysia) as amended by the Personal Data Protection (Amendment) Act 2024 (the “PDPA”).

“Customer Data” means data submitted to the service by or for the Customer, including Personal Data of the Customer’s employees, customers and suppliers. “Sub-processor” means a third party engaged by TwentyCore to process Customer Data.

2. Roles


2.1 The Customer is the data user (controller) of Customer Data and determines the purposes and means of processing.

2.2TwentyCore is a data processor and processes Customer Data only on the Customer’s documented instructions, which are: to provide, secure, support and improve the service as described in the Terms and the Customer’s configuration of the service.

3. TwentyCore’s obligations


3.1Process Customer Data only on the Customer’s instructions, unless required by Malaysian law, in which case TwentyCore will inform the Customer unless the law prohibits it.

3.2 Ensure that personnel authorised to process Customer Data are bound by confidentiality.

3.3 Implement the technical and organisational measures described in clause 6 and at twentycore.ai/security, and not reduce their overall level of protection during the term.

3.4Assist the Customer, at reasonable cost, in responding to data-subject requests (access, correction, withdrawal of consent) and in meeting the Customer’s PDPA obligations, using the tooling in the service where available.

3.5 Breach notice. Notify the Customer without undue delay and in any case within 72 hours of becoming aware of a personal data breach affecting Customer Data, with the information reasonably available (nature, categories and approximate volume, likely consequences, measures taken), and keep the Customer updated.

3.6 Return and deletion. The Customer may export its data from the service at any time while the account is open. On the Customer’s written request following termination, TwentyCore deletes the Customer’s production data within 30 days, and backups containing it expire within a further 7 days under the rolling backup window, unless Malaysian law requires retention. Absent such a request, data is retained so that the account can be reopened.

3.7Make available the information reasonably necessary to demonstrate compliance with this DPA, and allow for audits by the Customer or an independent auditor mandated by the Customer, no more than once a year on 30 days’ notice, at the Customer’s cost, subject to confidentiality and without disrupting the service.

4. Sub-processors


4.1 The Customer authorises TwentyCore to engage the sub-processors published at the sub-processor list, which names each provider, its purpose and where it processes data.

4.2TwentyCore will give at least 14 days’ notice (by email to the account’s administrators and on the sub-processor list) before adding or replacing a sub-processor. If the Customer objects on reasonable data-protection grounds and no solution is agreed, the Customer may terminate the affected service with a pro-rata refund of prepaid fees.

4.3 TwentyCore remains responsible for its sub-processors and imposes data-protection obligations on them no less protective than this DPA.

5. International transfers


5.1Customer Data is hosted in Singapore. Certain sub-processors process data outside Malaysia as stated in the sub-processor list, including AI model providers. The Customer instructs TwentyCore to make those transfers, and TwentyCore will only do so where the recipient is bound by obligations providing a level of protection substantially similar to the PDPA, in line with section 129 of the PDPA and the Commissioner’s guidance on cross-border transfers.

5.2The Customer controls what reaches an AI provider, in the application under Settings → AI Agents. Choosing No AI stops all Customer Data being sent to AI model providers. Choosing Mask contact details replaces email addresses, phone numbers, NRIC and payment-card numbers in every prompt before it is sent, and stops uploaded documents being read by AI. Names, company names and amounts are sent in either of the other modes; TwentyCore does not represent that they are removed.

6. Security measures


Encryption in transit (TLS 1.2 or higher) and at rest; tenant isolation enforced in the application and by database row-level security; role-based access control and optional two-factor authentication; audit logging of administrative actions; daily encrypted backups; vulnerability and dependency monitoring; access to production limited to named TwentyCore staff under confidentiality; incident response and notification per clause 3.5. The current description is maintained at twentycore.ai/security.

7. Customer’s obligations


The Customer warrants that it has the right to disclose Customer Data to TwentyCore for processing, has given data subjects the notices required by the PDPA, and will not submit data the service is not designed to hold (for example medical or biometric data) without written agreement.

8. Liability, term and law


8.1 Liability under this DPA is subject to the limitations in the Terms of Service.

8.2 This DPA lasts as long as TwentyCore processes Customer Data for the Customer.

8.3 This DPA is governed by the laws of Malaysia, and disputes are resolved as set out in the Terms of Service.

8.4 If there is a conflict between this DPA and the Terms, this DPA prevails for the processing of Personal Data.

Annex A — Processing details


Subject matter. Operation of the TwentyCore ERP service for the Customer.

Duration. The term of the service plus the deletion period in clause 3.6.

Nature and purpose. Storage, retrieval, computation and transmission needed to run the CRM, finance, inventory, production, HR and related modules the Customer enables, and AI features where enabled.

Categories of data subjects. The Customer’s employees and users, its customers and their contacts, and its suppliers and their contacts.

Categories of Personal Data. Names, business contact details, roles, identification numbers required for statutory documents (such as tax identification numbers and employee identifiers), payroll data where the HR module is enabled, and transaction records.

Contact


TwentyCore Sdn Bhd

Registration No. 1670365P

Block E, Level 11-01, Oasis Square, Ara Damansara, 47301 Petaling Jaya, Selangor, Malaysia

Email: hello@twentycore.ai