Skip to content
Notaa
PrivacyTermsOpen Notaa
Back to NotaaLegal · Privacy

Privacy Policy

This notice explains, in plain language, what personal data Notaa handles when people use our website, application, public share links, and agent integrations.

Effective 25 July 2026Last updated 25 July 2026

On this page

1. Who we are and what this notice covers2. Personal data we collect3. Where the data comes from4. How and why we use personal data5. How we disclose personal data6. International transfers7. Retention and deletion8. Security and incidents9. Your choices and rights10. Cookies and analytics11. Children12. Changes and contact
At a glance

Notaa uses personal data to provide and secure a collaborative project-management service. We do not sell personal data, and the marketing website does not currently use advertising cookies or marketing analytics.

1. Who we are and what this notice covers

Notaa (“Notaa”, “we”, “us”, or “our”) is the data controller for the personal data described in this notice. We operate from Malaysia and provide a hosted service for Projects, Tasks, Assignees, Statuses, Tags, Effort, Activity, Project Memory, public sharing, and connections with compatible AI tools.

This notice applies to notaa.my, app.notaa.my, Notaa's public share pages, and Notaa's MCP and OAuth integration endpoints. It does not govern a third-party AI client, Google, or another service you choose to connect; their own notices apply to their processing.

Where an organisation provides your Notaa access, that organisation may separately control personal data placed in its Projects. Ask its administrator about its own privacy practices.

2. Personal data we collect

Account and profile data

When you sign in with Google, we receive the identifiers and profile details needed to create and authenticate your account, including your name and email address. Notaa does not receive your Google password. You may edit your display name in Notaa.

Workspace and content data

We store the information you and other authorised users add to the service, such as Project names and codes; Task titles and descriptions; Assignees; Statuses; Tags; priorities; Effort; deadlines; Updates; Activity; Project Memory; membership and invitation information; and share-link settings. This content may contain personal data if you choose to include it.

Integration and agent data

If you connect an AI tool, we process the authorisation, scopes, token records, and commands needed to operate that connection. Personal access tokens are stored in a protected form rather than displayed again in full. Activity may identify that an action was performed through MCP. Content from an email, document, chat, or other source is stored in Notaa only when you or your authorised agent add it to a Project or Task.

Usage, device, and support data

Our hosting, authentication, and security systems may process IP address, browser and device information, timestamps, requested URLs, session information, and diagnostic or security logs. If you contact us, we process your message and contact details.

3. Where the data comes from

We obtain personal data:

  • directly from you when you sign in, edit your profile, create content, or contact us;
  • from Google when you choose Google sign-in;
  • from Project administrators and members who invite, assign, mention, or collaborate with you;
  • from an AI client or integration that you authorise to act through Notaa; and
  • automatically from the systems used to deliver and protect the service.

4. How and why we use personal data

We use personal data to:

  • create accounts, authenticate users, and maintain sessions;
  • provide Projects, Tasks, collaboration, reporting, sharing, and agent integrations;
  • apply permissions, attribute changes, keep Activity, and help users understand who did what;
  • respond to support, privacy, and operational requests;
  • monitor reliability, diagnose faults, prevent abuse, and protect users and the service;
  • comply with law, enforce our Terms of Use, and establish or defend legal claims; and
  • improve the service using operational feedback and aggregated or de-identified information.

Depending on the applicable law and context, we rely on your consent, the need to provide the service you request, compliance with legal obligations, and our legitimate interests in operating a safe and useful service. You may decline optional data, but required account, authentication, and workspace information is necessary to use the relevant features.

Notaa does not use personal data to make solely automated decisions that produce legal or similarly significant effects. AI tools may recommend or carry out workspace actions at an authorised user's request; those actions remain subject to the user's permissions and the controls of the connected client.

5. How we disclose personal data

We disclose personal data only as needed:

  • Within Projects. Project members can see content, membership details, Assignees, and attributed Activity according to their role and access.
  • Through public share links. Anyone with an active share link may see the Task and related information presented on that page. Project administrators should share carefully and revoke links that are no longer needed.
  • With connected tools. A tool you authorise can access data allowed by its scopes, your Notaa permissions, and the commands you give it.
  • With service providers. We use Google for sign-in, Supabase for authentication and database services, and Vercel for application and website hosting. They process data for us or under your direct relationship with them.
  • For legal and safety reasons. We may disclose information when reasonably necessary to comply with law, protect rights or safety, investigate abuse, or respond to valid legal process.
  • In a business change. Data may be disclosed in connection with a financing, reorganisation, merger, sale, or transfer, subject to appropriate confidentiality and legal safeguards.

We do not sell personal data or share it for cross-context behavioural advertising.

6. International transfers

Notaa operates from Malaysia, while our service providers may process or store data in other countries. For example, our production database infrastructure is configured in Asia, and global hosting and authentication providers may process data where they or their subprocessors operate. Privacy laws in those places may differ from those in your country.

Where required, we use contractual, organisational, and technical measures intended to provide an appropriate level of protection and make transfers only for the purposes described in this notice.

7. Retention and deletion

We retain account and workspace data while it is needed to provide the service, preserve authorised Project history, meet legal obligations, resolve disputes, and protect the service. Retention depends on the type of record, Project administrators' actions, security needs, and legal requirements.

Deleting a Task or Project may first remove it from normal views rather than immediately erasing every record. Revoked tokens and share links cease to provide access, but security, audit, backup, and legal records may remain for a limited period. We delete or de-identify data when it is no longer reasonably required, subject to these needs.

To request account deletion, contact us. If your account belongs to an organisation, its administrator may need to reassign or export shared work before deletion.

8. Security and incidents

We use reasonable administrative, technical, and organisational safeguards designed for the nature of the service. These include managed authentication, encrypted network connections, access controls, database row-level permissions, protected credentials, and Activity records. No online service can guarantee absolute security.

If a personal data breach occurs, we will investigate and notify affected people and regulators when required by applicable law. Please report suspected unauthorised access promptly to privacy@notaa.my.

9. Your choices and rights

Depending on where you live and the law that applies, you may have rights to request access, correction, a copy or portability, deletion, restriction, or objection; to withdraw consent; and to complain to a regulator. These rights can be subject to legal limits, including the rights and records of other Project members.

You can edit your display name, revoke personal access tokens or connected applications, ask a Project administrator to change Project access, and revoke share links you control. For other requests, email privacy@notaa.my. We may need to verify your identity and authority before acting.

In Malaysia, you may also contact the Personal Data Protection Commissioner. If another privacy law applies, you may contact the regulator in your jurisdiction.

10. Cookies and analytics

The Notaa application uses cookies and similar browser storage that are necessary for sign-in, session continuity, security, and user preferences. Blocking them may prevent the application from working.

As of the date of this notice, the public marketing website does not install advertising cookies and does not send events to a marketing analytics platform. Our infrastructure providers may still process ordinary request and security logs. If we introduce optional analytics or advertising technologies, we will update this notice and request consent where required.

11. Children

Notaa is a work service and is not directed to children. You must be at least 18 years old, or the age of legal majority where you live, to create an account. Contact us if you believe a child has provided personal data without appropriate authorisation.

12. Changes and contact

We may update this notice as Notaa, our providers, or legal requirements change. We will post the revised version here, update the date above, and provide additional notice when a change materially affects your rights or our use of personal data.

For questions, requests, or complaints, contact the Notaa privacy team at privacy@notaa.my. Notaa operates from Malaysia.

Notaa

Lightweight project clarity for teams and agents.

HomePrivacy PolicyTerms of UseContact

© 2026 Notaa. Built for clear work.