← Back to home

Privacy Policy

Effective Date: 1 April 2026 · Last updated: 19 July 2026

1. Introduction

AcctBridge (“we”, “our”, “us”) operates the AcctBridge platform accessible at acctbridge.com and portal.acctbridge.com. This Privacy Policy explains how we collect, use, disclose, and protect personal data in accordance with the Personal Data Protection Act 2010 (PDPA) of Malaysia.

By using the Service, you consent to the practices described in this Privacy Policy.

2. Who We Are

AcctBridge is an accounting API gateway providing companies, internal software teams, ISVs, system integrators, and developers with secure REST API access to on-premise SQL Accounting and AutoCount Accounting installations across Malaysia and Southeast Asia.

Data Controller: AcctBridge — privacy@acctbridge.com

3. Personal Data We Collect

Account and Subscription Data: Name, company name, business email, billing address when provided, selected accounting product, subscription tier, usage totals, and billing-provider references. Payments are processed by the selected third-party payment provider, currently Creem; we do not store card numbers.

Connection and Configuration Data: Tenant and connection identifiers, tunnel hostname and status, connector configuration, and setup credentials needed to provision and operate the selected accounting connection. These records are separate from the accounting documents that pass through the API.

Accounting API Data (Processed in Transit): Supported request and response bodies may contain invoice, payment, customer, supplier, inventory, and other accounting values. They are forwarded between the calling application and local connector and are not persisted in our hosted application database or API usage logs.

API Usage and Technical Data: Tenant and API key identifiers, accounting brand, request method, endpoint path without query values, timestamp, response status, latency, request and response size, error category, request ID, IP-derived security signals, browser or device information, and tunnel or connection status. API usage records do not contain request or response bodies.

Contact and Support Data: Information submitted through contact or support channels, such as name, company, email, phone number, accounting product, message, and the records needed to manage our response.

4. How We Use Your Personal Data

PurposeLegal Basis
Provision of ServiceContractual necessity
Billing and subscription managementContractual necessity
Security monitoring and fraud preventionLegitimate interests
Service notificationsContractual necessity / Consent
Legal obligationsLegal obligation

We do not use your data for advertising or sell it to third parties.

5. Accounting Data Boundary

Our non-persistence statement applies to accounting request and response bodies, not to every category of customer or service data. Accounting document contents are processed in transit without being persisted in the hosted application database or API usage logs. We retain the account, subscription, connection configuration, limited request metadata, and contact or support records needed to operate the Service.

For a plain-language breakdown, see our Data Handling page.

6. Data Retention

Data TypeRetention
Account, subscription, and connection configurationWhile needed to provide the account and connection, followed by the period required for security, support, dispute handling, deletion processing, or applicable obligations
Raw API usage eventsNormally 30 days by default; these events contain request metadata but no request or response body
Daily aggregate usage totalsRetained for account reporting and service analysis; aggregates contain counts, status classes, latency totals, and byte totals, not accounting payload content
Billing-provider and transaction referencesAs needed to administer payment, refunds, disputes, accounting, and applicable obligations
Contact and support recordsWhile needed to handle the inquiry, provide support, and maintain appropriate business records

7. Your Rights Under PDPA

You have the right to access, correct, withdraw consent, and request deletion of your personal data. Email privacy@acctbridge.com with subject “PDPA Data Request”. We respond within 21 days.

8. Data Security

Network traffic is protected using HTTPS/TLS, and the local connector uses an outbound Cloudflare Tunnel rather than an inbound public port. AcctBridge uses authentication keys and tokens to restrict API and portal access. No transmission or storage system can eliminate all risk; please do not send passwords, API keys, database credentials, or customer financial records through the contact form.

9. Contact

Privacy Officer: privacy@acctbridge.com

If unsatisfied with our response, you may lodge a complaint with the Department of Personal Data Protection Malaysia at pdp.gov.my.