Privacy Policy
Your privacy matters. This policy explains how we handle your data in compliance with the Malaysia Personal Data Protection Act 2010 (PDPA).
Last updated: 14 September 2026
1. Introduction
TwentyCore Sdn Bhd (Registration No. 1670365P), a company incorporated in Malaysia with its principal place of business in Petaling Jaya, Selangor (“TwentyCore”, “we”, “us”, or “our”), is committed to protecting the privacy and personal data of our users in accordance with the Personal Data Protection Act 2010 (Act 709) (“PDPA”).
This Privacy Policy describes how we collect, use, disclose, and protect personal data when you use our platform at app.twentycore.ai and our website at twentycore.ai (together, the “Service”).
2. Data We Collect
2.1 Account Information. When you register, we collect your name, email address, phone number, company name, company registration number, and job title.
2.2 Business Data. Data you enter into the Service in the course of using our ERP modules, including but not limited to customer records, financial transactions, inventory data, employee records (for HR/Payroll), production data, and quality records (“Customer Data”). You are the data controller for Customer Data; we process it on your behalf.
2.3 Payment Information. Payment card details are collected and processed directly by our payment processor, Stripe, Inc. We receive only a tokenised reference and the last four digits of your card. We do not store full card numbers on our servers.
2.4 Usage Data. We automatically collect technical information when you use the Service, including IP address, browser type, device information, pages visited, features used, timestamps, and error logs.
2.5 Communication Data. Records of support requests, emails, and feedback you send to us.
3. How We Use Your Data
We process personal data for the following purposes:
- Service Delivery: To provide, operate, and maintain the TwentyCore platform and its features.
- Account Management: To manage your account, process subscriptions, and handle billing.
- Support: To respond to your enquiries, provide technical support, and communicate service updates.
- Security: To detect, prevent, and address fraud, abuse, security incidents, and technical issues.
- Improvement: To analyse usage patterns and improve the Service, including through aggregated and anonymised analytics.
- Compliance: To comply with legal obligations, including Malaysian statutory requirements.
- Communication: To send you important notices about the Service, security alerts, and (with your consent) product updates or newsletters. You may opt out of marketing communications at any time.
4. Legal Basis for Processing (PDPA)
Under the PDPA, we process your personal data based on the following grounds:
- Consent: By using the Service and providing your data, you consent to its processing as described in this policy. You may withdraw consent at any time, though this may affect our ability to provide the Service.
- Contractual Necessity: Processing required to perform our obligations under the Terms of Service.
- Legal Obligation: Processing required to comply with applicable laws (e.g., tax records, employment records, LHDN e-Invoice requirements).
- Legitimate Interest: Processing for security, fraud prevention, and service improvement where such interests are not overridden by your data protection rights.
5. Data Sharing & Third Parties
We do not sell your personal data. We share it only with the following recipients, and only to the extent necessary:
- Our sub-processors — the vendors below, which host, carry or process data for us, including the account, billing and usage data we keep about you. This is the list our Data Processing Agreement incorporates. A vendor used only by a feature that is switched off does not appear on it, and a new vendor is announced here 14 days before it is switched on.
- Services you connect — an accounting, commerce, messaging or other integration you switch on sends data to your own account with that provider, at your direction.
- Website measurement — twentycore.ai includes the Google tag for measuring Google Ads conversions, which sends pages viewed, device, approximate location and ad clicks to Google when it runs. It is not part of the application.
- Fonts and maps — the website and the application load fonts from Fontshare and Google Fonts, and the fleet and shipment-tracking maps load tiles from OpenStreetMap; those servers receive your IP address and browser details.
| Provider | Purpose | Data shared | Location |
|---|---|---|---|
| DigitalOcean LLC | Application hosting, managed PostgreSQL and object storage for uploaded files | all customer data — primary infrastructure, including uploaded files and database backups | Singapore (DigitalOcean SGP1) |
| Cloudflare, Inc. | Edge network in front of the API: TLS termination, DDoS protection, and the signup bot check (Turnstile) | all Customer Data in transit to and from the API; request metadata (IP address, user agent, timing) | Global (anycast) |
| Vercel Inc. | Hosting of the web application and twentycore.ai, and the proxy that carries the application's API requests to DigitalOcean | all Customer Data in transit between the browser and the API; request metadata (IP address, user agent, timing) | Global edge network |
| Stripe, Inc. | Subscription billing and payments | billing contact, card last-4 (tokenised), invoice metadata | US (with EU/SG sub-processors per Stripe DPA) |
| Resend | Transactional email delivery | recipient email, email body, delivery events | US / global sub-processors per Resend DPA |
| Sentry (Functional Software, Inc.) | Error monitoring and performance telemetry for the API and the web application | error reports and stack traces with request metadata; the signed-in user's id and email on events from the web application; web application sessions with an error, and a sample of the rest, replayed with text and inputs masked | US (EU region available on request) |
| Google LLC (Gemini API) | AI text + vision generation for tenant-facing AI features | chat prompts and the ERP context retrieved for them — email addresses, phone numbers, NRIC and payment-card numbers are masked; names, company names, amounts and addresses are not; prompts for reporting, anomaly explanation, negotiation briefs, quality inspection and the operations agent — not masked; document images for extraction — not masked; business records indexed for AI search (embeddings): customers and suppliers with their email and phone, employees' names and positions, products, quotations, orders, invoices, payments, bills of materials, quality, maintenance and shipment records, and CRM inquiry notes — not masked; the user's request and the AI's answer from each AI feature — email addresses, phone numbers, NRIC and payment-card numbers masked; names, companies, amounts and addresses not — re-sent for automated quality grading: every one while a server process has handled fewer than 500 that day, a sample beyond that | US |
| LHDN MyInvois (Inland Revenue Board of Malaysia) | Government e-Invoice clearance for MY tenants | invoice header + line items + buyer TIN | MY (Malaysia, government cloud) |
Reviewed 2026-09-14. Source: https://api.twentycore.ai/api/v1/legal/sub-processors
We may also disclose personal data if required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of TwentyCore, our users, or the public.
6. Cross-Border Data Transfers
Your data is primarily stored on DigitalOcean servers in the Singapore region, which provides low latency for Malaysian users. Some data may be processed in other jurisdictions through our third-party service providers (e.g., Stripe in the United States, Sentry in the United States).
In accordance with Section 129 of the PDPA, we ensure that any transfer of personal data outside Malaysia is made only to jurisdictions that provide an adequate level of data protection, or with appropriate safeguards including contractual obligations on the receiving party.
By using the Service, you consent to such cross-border transfers as described in this policy.
7. Data Retention
We retain your data as follows:
- Account Data: Retained for the duration of your active subscription, plus 30 days after account closure to allow for data export.
- Customer Data: Retained for the duration of your active subscription. Permanently deleted 30 days after account closure.
- Financial Records: Retained for 7 years as required by Malaysian tax and corporate law (Companies Act 2016, Income Tax Act 1967).
- Usage & Log Data: Retained for up to 12 months for security and analytical purposes, then anonymised or deleted.
- Support Records: Retained for 3 years after resolution.
8. Cookies & Tracking
We use the following types of cookies:
- Essential Cookies: Required for authentication, session management, and security (e.g., JWT tokens, CSRF protection). These cannot be disabled.
- Functional Cookies: Remember your preferences such as language, timezone, and interface settings.
- Analytics Cookies: Help us understand how the Service is used so we can improve it. These are anonymised and do not track you across other websites.
The application uses no third-party advertising cookies or cross-site tracking. On the website, the Google tag described in section 5 can set Google advertising cookies when it runs. You can manage cookie preferences through your browser settings, though disabling essential cookies may prevent the Service from functioning correctly.
9. Data Security
We implement appropriate technical and organisational measures to protect your personal data, including:
- Encryption of data in transit (TLS 1.2+) and at rest (AES-256).
- Multi-tenant row-level security ensuring strict data isolation between tenants.
- Regular security assessments and vulnerability scanning.
- Two-factor authentication (TOTP) available for all user accounts.
- Role-based access control (RBAC) limiting data access to authorised personnel.
- Automated backups with point-in-time recovery capability.
- Structured audit logging of all data access and modifications.
While we strive to use commercially acceptable means to protect your personal data, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security.
10. Your Rights Under the PDPA
Under the Personal Data Protection Act 2010, you have the following rights regarding your personal data:
- Right of Access (Section 12): You may request access to the personal data we hold about you and obtain a copy.
- Right of Correction (Section 34): You may request correction of any inaccurate or incomplete personal data.
- Right to Withdraw Consent: You may withdraw your consent to the processing of your personal data at any time by contacting us. This does not affect the lawfulness of processing before withdrawal.
- Right to Prevent Processing (Section 42): You may request that we cease processing your personal data in certain circumstances, such as for direct marketing purposes.
- Right to Data Portability: You may export your Customer Data at any time through the Service’s built-in export functions.
To exercise any of these rights, please contact us at hello@twentycore.ai. We will respond to your request within 21 days as required by the PDPA.
11. Employee & HR Data
If you use our HR & Payroll module, you may store employee personal data including identification numbers (IC/passport), bank account details, salary information, and statutory contribution records (EPF, SOCSO, EIS, PCB). As the employer, you are the data controller for this data, and you are responsible for:
- Obtaining appropriate consent from your employees for the processing of their personal data.
- Providing your employees with a privacy notice regarding their data.
- Ensuring accuracy and completeness of employee records.
- Complying with the PDPA and Employment Act 1955 with respect to employee data.
We process employee data on your behalf and in accordance with your instructions, subject to the security measures described in this policy.
12. Children’s Privacy
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without appropriate consent, we will take steps to delete that data promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will notify you of material changes at least 14 days before they take effect by email or through the Service. The “Last updated” date at the top of this policy indicates when it was last revised.
14. Complaints
If you believe that we have not handled your personal data in accordance with the PDPA, you may lodge a complaint with the Jabatan Perlindungan Data Peribadi (Department of Personal Data Protection):
Jabatan Perlindungan Data Peribadi (JPDP)
Aras 6, Kompleks Kementerian Komunikasi dan Digital
Lot 4G9, Persiaran Perdana, Presint 4
62100 Putrajaya, Malaysia
Website: www.pdp.gov.my
We encourage you to contact us first at hello@twentycore.ai so that we can try to resolve your concern directly.
15. Contact Us
For any questions or requests regarding this Privacy Policy or your personal data, please contact us:
TwentyCore Sdn Bhd
Registration No. 1670365P
Block E, Level 11-01, Oasis Square, Ara Damansara, 47301 Petaling Jaya, Selangor, Malaysia
Email: hello@twentycore.ai
Website: twentycore.ai