Personal Data Protection Notice

Effective date: 1 September 2026 · Version 1

1. Who we are and what this Notice covers

Tai & Khan Partnership (“we”, “us” or the “Firm”) is a Malaysian law firm with its office at No. 36A, Jalan SS 21/58, Damansara Utama, 47400 Petaling Jaya, Selangor, Malaysia. For the purposes of the Personal Data Protection Act 2010 [Act 709], as amended by the Personal Data Protection (Amendment) Act 2024 [Act A1727] (together, the “PDPA”), the Firm is the data controller for the personal data described in this Notice.

This Notice explains how we collect, use, store, disclose and transfer personal data in connection with:

  • our internal staff-only expense-claims and accounting web portal (“Staff Portal”);
  • our client-matter record system;
  • visitors to, and enquiries made through, our public marketing website at www.tkp.com.my (the “Website”); and
  • related authentication, document-storage, messaging, email-delivery and security services.

Clients do not log in to the Staff Portal. However, personal data about clients and other third parties may be contained in receipts, invoices, claim documents and client-matter records held in the systems.

The Firm has appointed Harith Khan as its Data Protection Officer. His contact details are in section 12.

2. Personal data we process

Depending on your relationship with the Firm and the contents of the records, we may process the following personal data:

  • Staff and portal-user data: names, email addresses, claimant phone numbers, user roles, access permissions, login and authentication information (including password hashes, authentication tokens and reset tokens), and account activity.
  • Expense and accounting data: receipt and invoice images or PDFs, claim amounts, claimant identity, claim category, dates, descriptions, approval information, reimbursement status and related messages or supporting documents.
  • Client and matter data: client names and matter records, together with contact details, matter identifiers, correspondence, transaction details and supporting documents.
  • Website enquiry data: name, email address, telephone number, message content and related technical metadata submitted through the Website’s contact or enquiry facilities.
  • Third-party data: personal data appearing on receipts, invoices, correspondence, matter records or other documents, including data relating to counterparties, witnesses, service providers, payees and other individuals.
  • Technical and security data: IP addresses, request logs, timestamps, user-agent or browser information, device or network signals, challenge tokens, error logs and security-event information.

Some documents may incidentally contain sensitive personal data or financial information. Staff must follow the Firm’s data-minimisation and document-handling policy and avoid uploading unnecessary personal data.

3. Why we process personal data

We process personal data for the following purposes:

  • creating and administering staff accounts, authenticating users and managing access permissions;
  • receiving, reviewing, approving, paying, recording and auditing expense claims and reimbursements;
  • bookkeeping, accounting, tax, financial reporting, audit preparation, regulatory compliance and internal administration;
  • opening, administering and maintaining client and matter records, providing legal services and managing client engagements;
  • extracting information from receipt and invoice images or PDFs using automated OCR and data-extraction tools, subject to human review;
  • storing, retrieving, linking and managing receipts, invoices, claim records and matter documents;
  • responding to enquiries and messages submitted through the Website or otherwise sent to the Firm;
  • sending user invitations, authentication emails, password-reset emails, security alerts and administrative communications;
  • protecting the Staff Portal and systems against bots, fraud, unauthorised access, misuse and security incidents;
  • maintaining logs, troubleshooting, monitoring performance, investigating incidents and enforcing Firm policies;
  • complying with legal, professional, regulatory, tax, accounting, audit and record-keeping obligations; and
  • establishing, exercising or defending legal rights, supporting legal proceedings, obtaining legal advice and assisting the administration of justice.

4. Conditions permitting processing

Under the PDPA, we will process personal data only where a permitted condition applies. Depending on the data and context, this may include processing that is necessary:

  • to perform a contract to which the individual is a party, including an employment contract or client engagement;
  • to take steps at the individual’s request with a view to entering into a contract;
  • to comply with a legal obligation imposed on the Firm, other than an obligation imposed only by contract;
  • to protect the individual’s vital interests;
  • for the administration of justice;
  • for the exercise of functions conferred on a person by or under law; or
  • where the individual has consented, including express consent where required for sensitive personal data or where another statutory condition is not available.

Separate PDPA provisions may permit the processing of sensitive personal data, or an overseas transfer, for legal proceedings, obtaining legal advice, or establishing, exercising or defending legal rights. Those provisions are applied only in their proper context.

The PDPA does not provide a general “legitimate interests” basis. Where we refer to an operational or security interest, we rely on it only as supporting rationale and pair it with one of the statutory conditions above (typically contractual necessity, legal obligation or consent).

5. Where the personal data comes from

We may obtain personal data from:

  • you directly, including when you are invited to the Staff Portal, submit a claim, send a message, complete a Website enquiry form or contact the Firm;
  • Firm partners, employees, trainees, contractors or authorised administrators;
  • clients, prospective clients, client representatives, counterparties, witnesses, service providers, payees and other persons connected with a matter or transaction;
  • receipts, invoices, claim documents, emails, correspondence, matter files and other records submitted to or created by the Firm; and
  • the Staff Portal, client-matter system, the Website and its enquiry forms, access logs, security tools and connected service providers.

6. When supplying personal data is required or optional

Some personal data is required so that we can administer employment, operate the Staff Portal, process claims, maintain accounting records, comply with legal or professional obligations, or act in a client matter. If required data is not supplied, we may be unable to create an account, allow portal access, process or reimburse a claim, maintain an accurate record, comply with an obligation, or accept or continue a client engagement.

Use of the Telegram claim-submission bot is optional and is limited to a staff member submitting their own personal expense claims. Staff have access to an alternative submission method — direct upload through the Staff Portal. Refusing or withdrawing consent to use Telegram will not affect employment or the ability to submit a claim through the alternative channel.

Cloudflare Turnstile is used on the staff login page for security. If it cannot be completed, portal access may not be available through that login route. Contact Harith Khan at harith@tkp.com.my for an alternative verification or access process.

7. Who we disclose personal data to

We disclose personal data only where reasonably necessary for the purposes above, subject to appropriate controls. The service providers we use are set out below.

ProviderService and personal data disclosed
SupabaseHosted PostgreSQL database and authentication. Receives and stores all portal and client-matter personal data, including staff account data, authentication information, claimant phone numbers, claims, documents or document links, and client/matter records. Hosted in Singapore.
NetlifyFrontend web hosting and serverless functions. Processes IP addresses, request and function logs, browser or device information and any personal data passed through serverless functions. Services may operate through a US/global content-delivery network.
Google Gemini APIAutomated OCR and data extraction from receipt or invoice images and PDFs. Receives the uploaded file and its contents. The Firm uses the paid Gemini API, under which Google does not use submitted data to improve its models. Contracting/processing entity: Google LLC and/or Google Asia Pacific Pte. Ltd.
Microsoft OneDrive / Microsoft GraphDocument storage and retrieval for receipts and claim documents via Microsoft Graph. The Firm uses a Microsoft account governed by the Microsoft Services Agreement and Microsoft Privacy Statement (contracting entity Microsoft Corporation, USA). Files are stored on Microsoft servers, which may involve transfer to the United States and other locations.
TelegramOptional submission of a staff member’s own personal expense claims through a bot. Receives the staff member’s phone number or account identifier, messages, receipt photos and files. Operated by Telegram FZ-LLC (Dubai, United Arab Emirates) under Telegram’s Terms of Service, Bot Developer Terms and Privacy Policy; Telegram acts as an independent controller for its service, not as the Firm’s processor. Bot messages are cloud chats accessible to Telegram and processed on Telegram’s servers in international locations. Use of the bot is restricted to a staff member’s own personal expense claims and must not be used for any document containing client or third-party personal data (see section 9).
ResendDelivery of user invitations, authentication and password-reset emails. Receives recipient email addresses, email content, links and delivery metadata. Processing is primarily in the United States. Contracting entity: Plus Five Five, Inc. trading as Resend.
Cloudflare TurnstileBot protection on the staff login page. Processes signals such as IP address, TLS fingerprint, user-agent header, site key/origin and a challenge token. Cloudflare, Inc. is based in the United States and uses a global network.

We may also disclose personal data to professional advisers, auditors, insurers, banks, regulators, courts, law-enforcement bodies and other persons where required or permitted by law or reasonably necessary for a client matter.

8. Overseas transfers

Some providers, their affiliates or subprocessors may process or store personal data outside Malaysia, including in Singapore, the United States, the United Arab Emirates and other countries in which they or their subprocessors operate.

Before or while making an overseas transfer, the Firm ensures that a condition under section 129 of the PDPA applies and that reasonable safeguards are used, including written data-processing terms, encryption, access restrictions, data minimisation, audit logging, and retention and deletion controls.

For each overseas transfer, the Firm relies on the following section 129 condition(s):

  • Supabase (Singapore), Netlify, Resend and Cloudflare (United States): the transfer is necessary for the performance of the contract between the Firm and the data subject (employment or client engagement), and the Firm has taken reasonable precautions and exercised due diligence to ensure the data is not processed in breach of the PDPA;
  • Google Gemini (United States and the regions where Google operates): the staff member’s consent together with contractual necessity, with data minimisation and redaction applied before upload;
  • Microsoft OneDrive (United States and other Microsoft locations): necessity for the performance of the contract and for the Firm’s record-keeping, supported by reasonable precautions and due diligence; and
  • Telegram (United Arab Emirates and other locations): the explicit consent of the staff member, the channel being restricted to the member’s own personal expense claims.

Standard contractual clauses in a provider’s terms are treated as a supporting safeguard, not as a substitute for a section 129 condition.

9. Telegram and client or third-party information

Because Telegram is a consumer messaging service with weaker, non-enterprise contractual controls, the Firm relies on the specific, informed and revocable consent of the staff member for use of the bot, with a non-Telegram alternative (direct upload through the Staff Portal). Use of the bot is restricted to the staff member’s own personal expense claims. Staff must not submit any client, privileged, confidential or third-party personal data through Telegram.

10. Security and retention

We use reasonable organisational, contractual and technical measures designed to protect personal data, including role-based access, multi-factor authentication, encryption, row-level security, secure secrets management, logging, backups and staff policies. No system is completely secure.

We retain personal data only for as long as reasonably required for the stated purposes and applicable legal, professional, accounting, tax, audit, limitation and record-keeping requirements, in accordance with the Firm’s retention schedule. We then delete, anonymise or securely dispose of it where practicable.

11. Your rights and choices

Subject to the PDPA and any lawful exceptions, you may:

  • ask whether we process your personal data and request access to it;
  • request correction of personal data that is inaccurate, incomplete, misleading or not up to date;
  • withdraw consent for future processing where we rely on consent;
  • ask us to stop processing that is likely to cause damage or distress in the circumstances permitted by the PDPA; and
  • ask us not to process personal data for direct marketing.

To exercise a right, contact Harith Khan at harith@tkp.com.my and provide enough information to identify you, the relevant records and the request. We may request proof of identity, charge a fee where permitted, or refuse or limit a request where the PDPA allows us to do so. We will explain any refusal where required.

You may also lodge a complaint with the Personal Data Protection Commissioner.

12. Contact us

The Firm has appointed Harith Khan as its Data Protection Officer. Questions, requests and complaints about this Notice or our processing of personal data should be sent to:

Harith Khan — Partner and Data Protection Officer, Tai & Khan Partnership, No. 36A, Jalan SS 21/58, Damansara Utama, 47400 Petaling Jaya, Selangor, Malaysia. Email: harith@tkp.com.my · Telephone: +60163365110

13. Changes to this Notice

We may update this Notice to reflect changes in law, guidance, our systems or our service providers. The current version will be displayed at https://www.tkp.com.my/pdpa-notice. Material changes will be communicated by email and/or portal notice.