Privacy Policy

Last updated: 22 September 2026

This Notice explains how AAZ Consulting Sdn Bhd (“Tallyo”, “we”, “us”), a company incorporated in Malaysia, collects, uses, discloses, and protects personal data in connection with the Tallyo cloud accounting service (“Service”). It is issued in accordance with the Personal Data Protection Act 2010 (“PDPA”) of Malaysia and should be read together with our Terms of Service.

Two roles matter here. If you are an individual using the Service (an account holder or someone your company has invited), we are the data user in relation to your own account data, as described below. If your company enters its own customers', suppliers', or employees' personal data into the Service (for invoicing, payroll, etc.), your company is the data user for that data and we process it only on your company's instructions, as a service provider — Sections 1–2 describe both cases.

The Service is intended for business use by individuals aged 18 and over — see Section 1 of our Terms of Service. We do not knowingly collect personal data from individuals under 18, and an account holder confirms they meet this requirement when creating an account.

1. Personal Data We Collect

a. About you, as an account holder

b. About your company

c. Payment information

We do not collect or store your full card number. Payments are processed by our payment processor, Curlec (a Razorpay Malaysia service), which provides us only with a payment status, a masked card summary, and billing identifiers we use to manage your subscription.

2. Why We Process It, and Our Legal Basis

Under the PDPA, we process personal data for the following purposes:

Providing your name, email, and password is necessary to create an account — without it, we cannot provide the Service to you. Providing company registration/tax numbers is optional at sign-up but may be required to use certain features (such as SST filing) or to issue compliant invoices.

3. AI Features (Receipt Scanning and Chat Assistant)

If you use receipt scanning, the image you upload is sent to Microsoft Azure (Azure AI Document Intelligence) to extract text, and the extracted merchant name may be sent to OpenAI to suggest an expense category. If you use the AI chat assistant, your messages and relevant company data needed to answer your question are sent to OpenAI to generate a response. These providers process this data to return a result to us and do not use it to train their own models under our commercial agreements with them. AI features are optional — you can enter data manually instead.

4. Who We Share Personal Data With

We do not sell personal data. We share it only with the following categories of recipients, each acting on our instructions to help us run the Service:

Some of these providers may process data outside Malaysia. Where they do, we rely on their own contractual and technical safeguards (such as standard contractual clauses and encryption in transit) as the basis for that transfer, consistent with PDPA's data export requirements. We may also disclose personal data if required by law, such as in response to a valid court order or regulatory request.

Within the Service, your company's data is isolated from every other company's using database-level access controls (row-level security) — other Tallyo customers cannot see your data, and our own staff do not access it except as necessary to provide support you request or to maintain the Service.

5. Security

We apply technical and organizational measures appropriate to the sensitivity of the data, including: encryption of company tax/registration numbers at rest, encryption in transit (HTTPS), hashed passwords, database-level tenant isolation (row-level security) so one company can never query another's data, and audit logging of sensitive administrative actions. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

6. How Long We Keep Personal Data

We keep your account data for as long as your account is active. If you delete your account, we deactivate your login and anonymize your personal identifying information (name and email) promptly; your company's financial records are retained for the period required under the Income Tax Act 1967 and Companies Act 2016 (generally seven years), since these are your company's legal records, not yours personally to delete on demand where you are not its sole owner.

Uploaded receipt images are kept for as long as the related financial record exists, so you can always view the original document behind an entry.

7. Your Rights

Under the PDPA, you have the right to:

You can access and correct most of your own account information directly in Settings. For anything else, or to exercise any of the above rights, contact us using the details in Section 9. We may need to verify your identity before acting on a request, and may charge a reasonable processing fee for an access request as permitted under the PDPA.

8. Cookies and Similar Technologies

We use a small number of cookies and browser storage that are necessary for the Service to work — keeping you signed in, and remembering your language/theme preference — and none for third-party advertising or cross-site tracking. Disabling cookies in your browser will prevent you from staying signed in to the Service.

9. Contact Us

For any question about this Notice, or to make a data access, correction, or withdrawal-of-consent request, contact us via our Contact page.

10. Changes to This Notice

We may update this Notice from time to time. If we make material changes, we will notify you by email or an in-app notice before they take effect.