Version 2026-08-21.1 · Last updated 21 AUG 2026
Two kinds of data. Account data you give us when signing up: your name, work email, mobile number, and your company's registered details. Company data you put into the workspace: contacts, documents, employee records, bank lines and journals.
Payment credentials and mandates are collected by the payment provider. We receive provider references, payment status, amount, billing identity and limited method information needed for billing, reconciliation and support; we do not receive online-banking passwords.
We also collect support communications, consent and audit records, device/browser information, IP address, security events, usage and diagnostic data, and information received from integrations you enable.
We process data to create and secure accounts; provide requested features; calculate and display business records; process subscriptions; send transactional communications; prevent fraud; troubleshoot; support users; maintain audit evidence; improve reliability; and meet legal, tax, accounting and dispute obligations.
Depending on the activity, processing is necessary to perform our contract, comply with law, pursue legitimate interests such as security and service improvement, or act with your consent. Optional marketing can be withdrawn at any time without affecting service messages.
Primary application infrastructure is currently hosted in Singapore. Service providers or support personnel may process data in other countries where necessary. We apply contractual, access-control and security safeguards appropriate to the transfer and applicable Malaysian requirements.
Do not rely on a data-residency representation unless it is expressly included in your order or enterprise agreement.
We disclose data only as needed to infrastructure, database, communications, payment, monitoring, analytics, identity, integration and professional-service providers; to authorised workspace users and integrations; to authorities where legally required; or in a corporate transaction subject to appropriate protections.
Providers act under their own terms or our instructions. We do not sell personal data. We do not disclose one customer’s workspace data to another customer.
We retain data while the account is active and afterwards only as reasonably required for contractual records, security, backup recovery, fraud prevention, disputes and applicable statutory retention. Different records have different periods. Financial, payroll, tax and e-invoice records may have to be retained despite a deletion request.
When retention is no longer required, we delete, anonymise or securely isolate the data. Backup copies expire through scheduled rotation rather than immediate deletion.
Subject to applicable exceptions, individuals may ask whether we process their data, request access or correction, withdraw consent where processing relies on consent, object to direct marketing, or ask us to limit processing likely to cause damage or distress. You may also complain to Malaysia’s Personal Data Protection Commissioner.
Workspace administrators usually control business data about their staff, customers and suppliers. We may refer such a request to the relevant Customer while assisting it as required.
Submit a privacy request through our contact page or email sales@urushq.my. We may verify your identity and authority before acting. Include the relevant workspace and the right you wish to exercise.