Notaa uses personal data to provide and secure a collaborative project-management service. We do not sell personal data, and the marketing website does not currently use advertising cookies or marketing analytics.
1. Who we are and what this notice covers
Notaa (“Notaa”, “we”, “us”, or “our”) is the data controller for the personal data described in this notice. We operate from Malaysia and provide a hosted service for Projects, Tasks, Assignees, Statuses, Tags, Effort, Activity, Project Memory, public sharing, and connections with compatible AI tools.
This notice applies to notaa.my, app.notaa.my, Notaa's public share pages, and Notaa's MCP and OAuth integration endpoints. It does not govern a third-party AI client, Google, or another service you choose to connect; their own notices apply to their processing.
Where an organisation provides your Notaa access, that organisation may separately control personal data placed in its Projects. Ask its administrator about its own privacy practices.
2. Personal data we collect
Account and profile data
When you sign in with Google, we receive the identifiers and profile details needed to create and authenticate your account, including your name and email address. Notaa does not receive your Google password. You may edit your display name in Notaa.
Workspace and content data
We store the information you and other authorised users add to the service, such as Project names and codes; Task titles and descriptions; Assignees; Statuses; Tags; priorities; Effort; deadlines; Updates; Activity; Project Memory; membership and invitation information; and share-link settings. This content may contain personal data if you choose to include it.
Integration and agent data
If you connect an AI tool, we process the authorisation, scopes, token records, and commands needed to operate that connection. Personal access tokens are stored in a protected form rather than displayed again in full. Activity may identify that an action was performed through MCP. Content from an email, document, chat, or other source is stored in Notaa only when you or your authorised agent add it to a Project or Task.
Usage, device, and support data
Our hosting, authentication, and security systems may process IP address, browser and device information, timestamps, requested URLs, session information, and diagnostic or security logs. If you contact us, we process your message and contact details.
3. Where the data comes from
We obtain personal data:
- directly from you when you sign in, edit your profile, create content, or contact us;
- from Google when you choose Google sign-in;
- from Project administrators and members who invite, assign, mention, or collaborate with you;
- from an AI client or integration that you authorise to act through Notaa; and
- automatically from the systems used to deliver and protect the service.
4. How and why we use personal data
We use personal data to:
- create accounts, authenticate users, and maintain sessions;
- provide Projects, Tasks, collaboration, reporting, sharing, and agent integrations;
- apply permissions, attribute changes, keep Activity, and help users understand who did what;
- respond to support, privacy, and operational requests;
- monitor reliability, diagnose faults, prevent abuse, and protect users and the service;
- comply with law, enforce our Terms of Use, and establish or defend legal claims; and
- improve the service using operational feedback and aggregated or de-identified information.
Depending on the applicable law and context, we rely on your consent, the need to provide the service you request, compliance with legal obligations, and our legitimate interests in operating a safe and useful service. You may decline optional data, but required account, authentication, and workspace information is necessary to use the relevant features.
Notaa does not use personal data to make solely automated decisions that produce legal or similarly significant effects. AI tools may recommend or carry out workspace actions at an authorised user's request; those actions remain subject to the user's permissions and the controls of the connected client.
6. International transfers
Notaa operates from Malaysia, while our service providers may process or store data in other countries. For example, our production database infrastructure is configured in Asia, and global hosting and authentication providers may process data where they or their subprocessors operate. Privacy laws in those places may differ from those in your country.
Where required, we use contractual, organisational, and technical measures intended to provide an appropriate level of protection and make transfers only for the purposes described in this notice.
7. Retention and deletion
We retain account and workspace data while it is needed to provide the service, preserve authorised Project history, meet legal obligations, resolve disputes, and protect the service. Retention depends on the type of record, Project administrators' actions, security needs, and legal requirements.
Deleting a Task or Project may first remove it from normal views rather than immediately erasing every record. Revoked tokens and share links cease to provide access, but security, audit, backup, and legal records may remain for a limited period. We delete or de-identify data when it is no longer reasonably required, subject to these needs.
To request account deletion, contact us. If your account belongs to an organisation, its administrator may need to reassign or export shared work before deletion.
8. Security and incidents
We use reasonable administrative, technical, and organisational safeguards designed for the nature of the service. These include managed authentication, encrypted network connections, access controls, database row-level permissions, protected credentials, and Activity records. No online service can guarantee absolute security.
If a personal data breach occurs, we will investigate and notify affected people and regulators when required by applicable law. Please report suspected unauthorised access promptly to privacy@notaa.my.
9. Your choices and rights
Depending on where you live and the law that applies, you may have rights to request access, correction, a copy or portability, deletion, restriction, or objection; to withdraw consent; and to complain to a regulator. These rights can be subject to legal limits, including the rights and records of other Project members.
You can edit your display name, revoke personal access tokens or connected applications, ask a Project administrator to change Project access, and revoke share links you control. For other requests, email privacy@notaa.my. We may need to verify your identity and authority before acting.
In Malaysia, you may also contact the Personal Data Protection Commissioner. If another privacy law applies, you may contact the regulator in your jurisdiction.
11. Children
Notaa is a work service and is not directed to children. You must be at least 18 years old, or the age of legal majority where you live, to create an account. Contact us if you believe a child has provided personal data without appropriate authorisation.
12. Changes and contact
We may update this notice as Notaa, our providers, or legal requirements change. We will post the revised version here, update the date above, and provide additional notice when a change materially affects your rights or our use of personal data.
For questions, requests, or complaints, contact the Notaa privacy team at privacy@notaa.my. Notaa operates from Malaysia.