ScribeWealth

Privacy Notice

Last updated: [DATE] · Governing law: Malaysia (PDPA 2010, as amended 2024)
DRAFT — pending legal review. This notice is an engineering draft prepared to satisfy the PDPA "Notice & Choice" principle. It must be reviewed by a Malaysian PDPA practitioner and published in both Bahasa Malaysia and English before you rely on it. Bracketed items [like this] need your input.

This Privacy Notice explains how ScribeWealth ("we", "us") collects, uses, discloses and protects your personal data when you use our portfolio-analysis service (the "Service"), in accordance with the Malaysian Personal Data Protection Act 2010 ("PDPA").

1. Who we are

ScribeWealth is operated by [LEGAL ENTITY NAME], [ADDRESS], Malaysia. Data protection contact: [PRIVACY_EMAIL] (Data Protection Officer: [NAME, if appointed]).

2. Personal data we collect

We do not intentionally collect sensitive personal data. Please do not upload data you are not authorised to process.

3. Purposes and lawful basis

We process your personal data to: create and secure your account; provide portfolio analysis and AI chat; communicate with you (verification, password reset, service messages); and protect the Service against misuse. Our lawful basis is your consent (given at sign-up) and the performance of our contract with you.

4. Disclosure and sub-processors

We do not sell your personal data. We share it only with service providers who process it on our behalf, under contract, to run the Service:

Sub-processorPurposeLocation
Heroku / Salesforce (incl. Heroku Postgres)Application hosting & databaseUnited States
ResendTransactional emailUnited States
SentryError monitoring (no portfolio data / PII sent)United States
Anthropic; OpenAIAI analysis & chatUnited States

5. Cross-border transfer

Because of the providers above, your personal data is transferred to and processed outside Malaysia (primarily the United States). We take steps to ensure a comparable level of protection through our agreements with these providers. [Confirm the specific transfer basis with counsel — e.g., adequacy / contractual safeguards under the PDPA as amended.]

6. Retention

We keep account data for as long as your account is active. Uploaded holdings files are not retained after analysis. Security audit records are retained for [RETENTION PERIOD] for security and legal purposes, after which they are deleted or anonymised. When you delete your account, your account data is erased and your audit records are anonymised.

7. Your rights

Under the PDPA you may: access and obtain a copy of your data; correct inaccurate data; withdraw consent; and request deletion of your account. You can exercise access, portability and deletion yourself from the Account & Data page, or contact us at [PRIVACY_EMAIL]. You also have the right to lodge a complaint with the Personal Data Protection Department (Jabatan Perlindungan Data Peribadi, JPDP), Malaysia.

8. Security

We protect your data with industry-standard measures including encrypted transport (HTTPS), strong password hashing (Argon2id), access controls, rate limiting, and audit logging. No system is perfectly secure, but we work to protect your data against loss and misuse.

9. Cookies

We use a single essential session cookie to keep you signed in. We do not use advertising or third-party tracking cookies.

10. Children

The Service is intended for professional users aged 18 and over and is not directed at children.

11. Changes

We may update this notice; we will post the new version here and update the date above. Material changes will be communicated to registered users.

12. Contact

Questions or requests: [PRIVACY_EMAIL].