Archived Version — This is the version of our Privacy Policy as published on 25 April 2026 (2026-04-25-v1). For the current notice, see /privacy.

Privacy Policy

Last updated: April 25, 2026 · Version: 2026-04-25-v1

1. Introduction

com1 ("we", "us", or "our") operates the com1.app platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service. It is published in English and Bahasa Malaysia in accordance with section 7 of the Personal Data Protection Act 2010 (Malaysia). In the event of any inconsistency between the two language versions, the English version prevails.

2. Information We Collect

Account Information

When you create an account, we collect your name, email address, and password. We also store your language and theme preferences. If you subscribe to a paid plan, payment is processed by Paddle — we do not store your credit card details directly.

Team and Organization Data

We store your team name, locale, timezone, date and time format preferences, country, and subscription details (plan, trial dates, subscription status).

Business Data

We store the data you enter into com1, including but not limited to: projects, tickets, milestones, contacts, corporations, invoices, estimates, recurring invoices, payments, time logs, notes, comments, items, bank accounts, hourly rates, payment terms, and business cards. Where you enter information about other individuals (such as contacts, employees, or invoice parties) you confirm that you are authorised to provide that information to us for the purposes described in this notice.

File Uploads

Files you upload (attachments on invoices, estimates, tickets, and team logos) are stored in Amazon S3. Each file is scoped to your team and accessible only via time-limited signed URLs.

Hosting and Infrastructure Data

If you use our hosting features, we store metadata about servers, databases, deployments, SSL certificates, container configurations, environment variables, and backup schedules that you configure through com1. Servers and databases are provisioned in your own AWS account — we access them only through temporary, scoped IAM credentials (AssumeRole) to perform the operations you request.

AI Assistant Data

If you use the AI assistant feature, your messages and conversation history are sent to Anthropic (Claude) for processing. We also use Voyage AI to generate text embeddings for semantic search. We track token usage for billing purposes. AI features are optional and can be disabled in your privacy settings.

Audit Logs

We maintain audit logs of significant actions within your team (such as server provisioning, deployments, and configuration changes) for accountability and troubleshooting purposes.

Source of Data

Most personal data we hold is provided directly by you when you register, configure your team, or use the service. We may also receive personal data about you indirectly when you are invited to join an existing team by another user, or when a team owner enters your information as a contact, employee, or invoice party. For data received indirectly, the team owner is the source and is responsible for ensuring you have been informed of this notice.

Obligatory and Optional Information

Your name, email address, and password are obligatory in order to create an account and use the service — without these we cannot authenticate you, send you transactional notifications, or recover your account. Tax identifiers, business registration numbers, and addresses are obligatory only if you use invoicing or e-invoicing features (LHDN MyInvois requires them). AI assistant usage, hosting integrations, and optional third-party connections (Dropbox, AWS S3 backup) are entirely optional. Refusal to provide obligatory information will mean we cannot provide the relevant feature; refusal of optional information has no consequence beyond unavailability of that specific feature.

3. How We Use Your Information

We use your information to:

4. Data Storage and Security

Your data is stored on secure servers hosted by Amazon Web Services (AWS), using managed PostgreSQL databases (RDS). We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, alteration, disclosure, or destruction, as required under the Security Principle (section 9) of the Personal Data Protection Act 2010.

Passwords are hashed using Argon2. Session tokens are cryptographically signed and hashed (SHA-256) before storage. Sensitive credentials (Dropbox tokens, backup storage keys, database passwords, MyInvois credentials) are encrypted at rest in our database.

File uploads are stored in Amazon S3 with private access controls. Downloads are served through time-limited signed URLs.

5. Third-Party Services

We use the following third-party services to operate com1. Each processes only the data necessary for its function:

Optional Integrations You Connect

You may optionally connect the following services. We access only the data necessary to provide the requested functionality, using credentials you provide:

Cross-Border Transfers

Your personal data is processed and stored on infrastructure located outside Malaysia. Specifically: AWS infrastructure (RDS, S3, SES, EC2) is hosted in our designated AWS region; Anthropic, Voyage AI, and Sentry process data on infrastructure located in the United States; Cloudflare operates a global content delivery network.

Under section 129 of the Personal Data Protection Act 2010 (as amended in 2024), we transfer your personal data outside Malaysia on the following bases: (a) the transfer is necessary for the performance of our contract with you; (b) for optional features (AI assistant), we rely on your express consent recorded in your privacy settings; and (c) we have assessed that the receiving jurisdictions provide a level of protection substantially similar to the Act, supported by data processing agreements with each processor that bind them to equivalent security and confidentiality obligations. You may request a copy of the cross-border transfer impact assessment by contacting our Data Protection Officer.

6. Data Retention

We retain your account data for as long as your account is active. Session tokens expire after 14 days. Magic login links expire after 15 minutes.

If you delete your account, we will delete or anonymise your personal data, including notes, comments, and associated records, except where we are required to retain it for legal, tax, or regulatory purposes. In particular, financial records (invoices, payments, related audit entries) are retained for seven (7) years to comply with the Income Tax Act 1967 and the Companies Act 2016, with personally identifying fields anonymised on account deletion.

Database backups are retained according to the schedule and retention policy you configure. Backup files may be stored in our S3 bucket, your own S3 bucket, or your Dropbox account depending on your configuration.

7. Your Rights Under PDPA

Under the Personal Data Protection Act 2010 (Malaysia, as amended in 2024), you have the following rights with respect to your personal data:

To exercise any of these rights, use the controls in your in-app privacy settings (Settings → Privacy) or contact our Data Protection Officer at [email protected]. We will respond within twenty-one (21) days as required by the Act.

8. Cookies

We use essential cookies to maintain your session and authenticate your requests. We also use a signed cookie to remember your login across browser sessions if you choose the "remember me" option, and a cookie to record your acknowledgement of this notice. We do not use third-party tracking cookies or advertising cookies.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page, updating the version identifier, and where appropriate prompting you to acknowledge the new version on your next login. Previous versions remain accessible at /privacy/v/<version>.

10. Contact Us

For questions about this Privacy Policy or to exercise your rights under the Act, contact our Data Protection Officer at [email protected]. For general support inquiries, contact [email protected].