Legal

Data Processing Agreement

Last updated: 2026-05-27

Parties

Data Processor: envoice.my, Malaysia.

Data Controller: The business that registers a shop on envoice.my and submits invoices through the platform.

By using envoice.my you agree to the terms of this DPA in addition to our Terms of Service.

Data processed

We process the following data on your behalf to deliver the service:

Buyer information: name, TIN, ID number, address, email, phone.
Transaction data: invoice amounts, items, tax codes.
Your shop credentials: TIN, BRN, LHDN client ID and secret (encrypted at rest).
Team members: names and email addresses of staff you invite.

Purpose

Data is processed solely to provide the service you have contracted: submitting invoices to LHDN MyInvois on your behalf, storing records for your access, and operating the B2C portal if you enable it. We do not use buyer data for our own marketing or analytics.

Retention

Invoice records: 7 years (Income Tax Act 1967).
Account data: until you delete your account, after which personal data is anonymised.
LHDN credentials: deleted immediately when removed from shop settings.

Your obligations

As data controller you are responsible for having a lawful basis to collect buyer data and for informing buyers that their data is submitted to LHDN MyInvois for e-invoice purposes.

Our obligations

Process data only on your instructions.
Maintain appropriate technical and organisational security measures.
Notify you within 72 hours of a confirmed personal data breach affecting your data.
Assist with data subject access requests where technically feasible.

Contact

DPA enquiries and breach notifications: [email protected]