Privacy Policy · 隐私政策
Privacy Policy · 隐私政策
Last updated · 最后更新: 13 July 2026
1. Data we process
KunciPay processes company and user account details, roles and permissions, customer and supplier records, employee information entered by customers, accounting and operational records, approval and audit events, uploaded documents, API and security logs, and support communications required to operate the service.
1. 我们处理的数据
KunciPay为运行服务而处理公司及用户账户资料、角色与权限、客户与供应商记录、客户输入的员工资料、会计与运营记录、审批与审计事件、上传文件、API及安全日志,以及支持通讯。
2. Why we process data
We process data to authenticate users, enforce permissions, operate spend-control and accounting workflows, produce reports and exports, preserve audit evidence, secure and maintain the platform, investigate incidents, and respond to support requests.
2. 处理目的
我们处理数据以验证用户身份、执行权限、运行支出管控及会计工作流、生成报表与导出文件、保存审计证据、保护和维护平台、调查事故,以及回应支持请求。
3. Customer responsibilities
Customers must have a lawful basis and appropriate authority before entering personal data about employees, suppliers, customers, or other individuals. Customers are responsible for providing notices and obtaining consents required for their own collection and use of that data.
3. 客户责任
客户在输入员工、供应商、顾客或其他个人的资料前,必须具备合法依据及适当授权。客户须负责就其自身收集和使用该等资料提供所需通知并取得必要同意。
4. Current subprocessor
KunciPay currently uses one external subprocessor: AWS Lightsail in Singapore. AWS Lightsail hosts the application and the authentication, accounting, audit, and operational data stored by the service. The relevant processing jurisdiction is Singapore.
4. 当前数据处理方
KunciPay目前使用一个外部数据处理方:位于新加坡的AWS Lightsail。AWS Lightsail托管本应用及服务储存的认证、会计、审计和运营数据。相关处理司法管辖区为新加坡。
5. User-directed external transfers
Some features let a user open a WhatsApp link or configure a webhook destination. When a user chooses these actions, the selected message, document link, or event payload is sent to the external destination chosen by that user. Those destinations are not KunciPay subprocessors, and users must confirm that they are authorised to make the transfer.
5. 用户发起的外部传输
部分功能允许用户打开WhatsApp链接或配置webhook目的地。当用户选择这些操作时,所选消息、文件链接或事件数据将发送到该用户指定的外部目的地。这些目的地并非KunciPay的数据处理方,用户须确认其已获授权进行该传输。
6. Cross-border processing
Production data is hosted in Singapore and is therefore transferred outside Malaysia for hosting and service operation. KunciPay will not enable a new external service that receives customer data until the relevant contract or data-processing terms, privacy disclosure, jurisdiction review, and data-minimisation review are complete.
6. 跨境处理
生产数据托管于新加坡,因此会为托管及服务运行目的传输至马来西亚境外。任何会接收客户数据的新外部服务,必须先完成相关合同或数据处理条款、隐私披露、司法管辖区审查及数据最小化审查,KunciPay才会启用。
7. Retention and security
We retain data for as long as needed to provide the service, protect its integrity, address disputes, and meet applicable legal obligations. Access is restricted by authenticated accounts and assigned roles. Customers should contact support to request access, correction, export, or account closure.
7. 保留与安全
我们仅在提供服务、保护数据完整性、处理争议及履行适用法律义务所需期间保留数据。数据访问受认证账户及分配角色限制。客户如需请求访问、更正、导出资料或关闭账户,应联系支持团队。
8. Changes and contact
Material changes to this notice will be published with an updated date. Privacy questions and requests may be sent to the support address below.
8. 变更及联系
本通知如有重大变更,将连同更新日期一并发布。隐私相关问题及请求可发送至下方支持邮箱。