Learn how we collect, process, and safeguard your personal and enterprise data.
Last updated: Sep 20, 2026
BITSTRIC Pte. Ltd. · Version 3.0 · Effective Sep 20, 2026
1.1 Who we are. This Privacy Policy is issued by BITSTRIC Pte. Ltd. (UEN 202641466Z), a company incorporated in Singapore ("BITSTRIC", "we", "us", "our").
1.2 What it covers. This Policy explains how we collect, use, disclose, transfer, protect, retain, and dispose of personal data in connection with our website, our business operations, and the services we provide. It applies to website visitors, prospects, clients, partners, suppliers, contractors, job applicants, and other individuals whose personal data we handle.
1.3 Governing framework. Our primary data protection law is the Personal Data Protection Act 2012 of Singapore ("PDPA") and its subsidiary legislation, including the Do Not Call provisions and the data breach notification obligations. Where the laws of another jurisdiction apply to our handling of an individual's personal data, we also comply with those laws to the extent they apply (see Section 16).
1.4 Client engagements. Where we provide services to a client, the handling of personal data supplied by or on behalf of that client is governed by our written agreement with that client, including any Data Processing Agreement ("DPA"). If this Policy and an executed DPA differ in respect of that client's data, the DPA prevails. Where we act for a Singapore public agency, the handling of government data is governed by the government contract and the public sector data governance requirements that apply to it.
1.5 Nature of this Policy. This Policy is a notice of our practices. It does not form part of any contract with you unless expressly incorporated into one. Nothing in this Policy limits or excludes any right you have under applicable law.
We handle personal data in one of two capacities. The capacity determines who decides how the data is used, and who you should contact about it.
| Capacity | When it applies | Who decides purpose and means | Who to contact |
|---|---|---|---|
| Organisation (controller) | Our website, marketing, sales, contracting, billing, supplier management, recruitment, personnel, and corporate records | BITSTRIC | BITSTRIC's Data Protection Officer (Section 21) |
| Data intermediary (processor), within the meaning of the PDPA | Delivery of client services where we process personal data on behalf of, and on the documented instructions of, a client | The client | The client organisation, in the first instance |
When acting as a data intermediary, we are subject to the PDPA's Protection, Retention Limitation, and data breach notification obligations that apply to data intermediaries, and to our contractual obligations to the client. If you contact us about personal data that we process for a client, we will refer your request to that client and let you know we have done so.
| Term | Meaning |
|---|---|
| Personal Data | Data, whether true or not, about an individual who can be identified from that data, or from that data and other information to which we have or are likely to have access. |
| Client Data | Information supplied by or on behalf of a client for the delivery of services. It may contain Personal Data. |
| Engagement Materials | Documents and records received or produced during a client engagement, such as system inventories, policy documents, control evidence, risk registers, and configuration exports. |
| Operational Trace Data | Execution logs, tool-call records, prompts, model inputs, and model outputs generated or captured by our systems during a client engagement. We treat this as our highest-sensitivity category, because it may contain personal data that has not been identified or classified in advance. |
| Evaluation Data | Test inputs, outputs, and scoring records generated when we evaluate AI models or systems. |
| Regulated Engagement | An engagement for (a) a financial institution regulated by the Monetary Authority of Singapore, or (b) a Singapore public agency, or (c) any engagement that we and the client designate in writing as sovereign, air-gapped, or regulated. |
| Category | Examples | Our role |
|---|---|---|
| Contact and enquiry | Name, work email, phone number, company, job title, enquiry content, event registrations | Organisation |
| Technical and security | IP address, browser and device information, access and security logs | Organisation |
| Commercial | Proposals, contracts, invoices, payment and procurement records, business contact details of client and supplier personnel, meeting notes | Organisation |
| Recruitment and personnel | Applications, CVs, references, contractor and employment records, IP assignment records | Organisation |
| Client engagement data | Personal data within Client Data, Engagement Materials, and Operational Trace Data | Data intermediary |
| Evaluation Data | Test sets and results | As specified in the engagement; personal data excluded by default (Section 6.5) |
We collect personal data directly from you (for example, when you submit a form, correspond with us, or sign a contract); automatically through our website and systems (Section 15); from your employer or organisation where you are its representative; and from public sources and business partners where permitted by law.
We do not collect NRIC numbers, passport numbers, or other national identification numbers unless required by law or strictly necessary to verify identity to a high degree of fidelity, consistent with PDPC guidance. We do not intentionally collect health, biometric, financial account, religious, or political data about you for our own purposes. Where such data is contained in Client Data, we process it only as a data intermediary on the client's instructions.
If you provide us with personal data about another individual (for example, a colleague's contact details), you confirm that you have the authority or consent needed to do so and that the individual has been informed of the purposes for which it will be used.
When acting as an organisation, we use personal data to:
We rely on one or more of the following:
You may withdraw consent at any time by contacting our Data Protection Officer. We will acknowledge your request within 10 business days, inform you of the likely consequences of withdrawal, and give effect to it within a reasonable time. Withdrawal does not affect processing that relies on a basis other than consent, or processing already carried out. If withdrawal means we can no longer perform a contract or provide a service, we will tell you.
These are commitments about how we treat data entrusted to us by our clients.
6.1 No training on Client Data. We do not use Client Data, Engagement Materials, or Operational Trace Data to train, fine-tune, or otherwise adapt any machine learning model — whether our own, the client's, or a third party's — unless the client has given specific written instruction for its own dedicated environment, recorded in the applicable agreement. Agreeing to receive our services is not agreement to model training.
6.2 Third-party AI providers. Where an engagement uses a third-party model or inference provider, that provider is identified to the client before processing begins and is contractually prohibited from using the client's data to train its models. Any data retention by the provider is limited to what the provider requires for security, abuse monitoring, or legal compliance, as disclosed to the client.
6.3 AI-specific transparency. We do not treat this general Policy as sufficient notice for using personal data to develop or train AI models. Any such use for our own purposes would be preceded by specific notice and, where required, consent, consistent with the PDPC's advisory guidelines on the use of personal data in AI systems.
6.4 Operational Trace Data. Operational Trace Data is kept within the processing environment designated for the engagement, accessible only to authorised engagement personnel, and retained in accordance with Section 12.
6.5 Evaluation Data. Our model and system evaluations use public benchmark material and synthetic or client-supplied test sets. Personal data is excluded from evaluation inputs by default. Where a client supplies a test set that contains personal data, it is processed under the client's DPA and is never included in any published result, index, or comparison.
6.6 Anonymised and aggregated data. We may create and use anonymised or aggregated information — for example, for methodology improvement and research. We apply anonymisation techniques intended to ensure that individuals are not reasonably re-identifiable, having regard to PDPC guidance, and we do not attempt, or permit our service providers to attempt, re-identification. Information that is properly anonymised is not personal data.
We disclose personal data only as described below, and only to the extent necessary:
| Recipient | Purpose |
|---|---|
| Our personnel and contractors | On a need-to-know basis, under written confidentiality obligations |
| Service providers and sub-processors | Hosting, cloud, communications, CRM, payment, security, collaboration, and AI inference services |
| Specialist subcontractors | Engineering and delivery support, subject to Section 8 |
| Professional advisers | Legal, accounting, audit, and insurance advisers, under duties of confidentiality |
| Prospective investors, financiers, acquirers, and their advisers | Due diligence and corporate transactions, subject to Section 18 |
| Client-authorised parties | Integrations and third parties the client instructs us to use |
| Courts, regulators, and authorities | Where required or authorised by law, or to establish, exercise, or defend legal claims |
We do not sell personal data. We maintain a list of sub-processors used in client engagements, including their function and processing location, which is available on request from our Data Protection Officer. Clients' notification and objection rights regarding new sub-processors are set out in their DPA.
All recipients who process personal data on our behalf are bound by written terms requiring them to protect it to a standard no less protective than this Policy.
8.1 Our delivery model. BITSTRIC acts as prime contractor for its engagements. Some engineering and operational support may be performed by subcontracted personnel located outside Singapore, including in Vietnam.
8.2 The boundary. For every Regulated Engagement:
8.3 Other engagements. For engagements that are not Regulated Engagements, processing outside Singapore may occur. Processing locations are disclosed to the client before work begins, and the client may elect a Singapore-only delivery model.
8.4 Subcontractor obligations. Every subcontractor is bound by written confidentiality, data protection, and intellectual property assignment terms.
9.1 Transfer standard. Where we transfer personal data outside Singapore, we take appropriate steps to ensure that the recipient is bound by legally enforceable obligations to provide the transferred data a standard of protection comparable to that under the PDPA, as required by the PDPA's Transfer Limitation Obligation and the Personal Data Protection Regulations 2021.
9.2 How we do this. We rely primarily on contractual clauses in our agreements with service providers and sub-processors. Where other jurisdictions' laws require additional steps before a transfer (for example, a transfer impact assessment or a regulatory filing), we take those steps where they apply to us.
9.3 Client-elected residency. Clients may specify processing regions and hosting locations for their engagements, including Singapore-only configurations. These elections are recorded in the applicable agreement.
9.4 Infrastructure dependencies. Some of the service providers we use for our own business operations may process data outside Singapore. Clients requiring full Singapore residency should confirm the applicable configuration with us before the engagement begins.
We make reasonable security arrangements to protect personal data in our possession or under our control against unauthorised access, collection, use, disclosure, copying, modification, disposal, loss, or similar risks, having regard to the nature and sensitivity of the data. Our measures include, as appropriate to the data and system concerned:
No method of transmission or storage is completely secure. We encourage you not to send passwords or other credentials to us by email or other unsecured channels.
11.1 Assessment. Where we have reason to believe a data breach has occurred, we will take reasonable and expeditious steps to assess whether it is notifiable, and in any case within 30 days of becoming aware of it.
11.2 As an organisation. Where a breach is notifiable under the PDPA, we will notify the Personal Data Protection Commission as soon as practicable, and no later than 3 calendar days after determining that it is notifiable. We will notify affected individuals on or after notifying the Commission, unless an exception under the PDPA applies (for example, where we have taken remedial action that makes significant harm unlikely) or we are directed by the Commission or a law enforcement agency not to do so. Where the laws of another jurisdiction apply, we notify the relevant authority and individuals within the timeframes that law requires.
11.3 As a data intermediary. Where a breach affects personal data we process for a client, we notify that client without undue delay, and within any timeframe agreed in the client's DPA, so that the client can meet its own obligations. We do not notify regulators or individuals on the client's behalf unless the client instructs us to or the law requires us to.
11.4 Regulated clients. For financial institution clients, we support the client's incident reporting obligations under applicable MAS requirements on the terms of the engagement agreement.
We retain personal data only for as long as it is needed for the purpose for which it was collected, or for legal or business purposes, after which we delete, destroy, or anonymise it. The table below shows our default periods. A longer period applies where required by law or agreed in a client contract.
| Category | Default retention |
|---|---|
| Enquiries from prospects that do not proceed | 24 months from last interaction |
| Marketing contacts | Until you opt out; thereafter only on a suppression list so we honour your preference |
| Technical and security logs | 12 months |
| Contracts, invoices, and accounting records | At least 5 years, as required by Singapore law |
| Engagement Materials | 90 days after the engagement ends, then returned or deleted as the client instructs |
| Operational Trace Data | 30 days after the engagement ends, or longer if the client's regulatory retention requirement so requires |
| Evaluation Data containing no personal data | As long as useful for methodology and research |
| Job applicant records (unsuccessful) | 12 months from the decision |
| Personnel and contractor records | For the duration required by employment law and applicable limitation periods |
| Data breach records | 5 years from closure |
Legal holds. We may retain specific personal data beyond these periods where reasonably necessary to establish, exercise, or defend legal claims, respond to a regulatory inquiry, or comply with a legal obligation, and only for as long as that need continues.
Backups. Deleted data may persist in backups until those backups are overwritten in the ordinary course. Backup data is protected to the same standard and is not restored except for disaster recovery.
Subject to the PDPA and to verification of your identity, you may:
If you are located in a jurisdiction whose law applies to our handling of your personal data, you may have additional rights — for example, rights to erasure, restriction, objection, or portability. We will respond to such requests in accordance with that law.
| Request | Response |
|---|---|
| Access | As soon as reasonably possible. If we cannot respond within 30 days, we will tell you within that period when we expect to respond. |
| Correction | As soon as practicable. Where required, we will send the corrected data to organisations to which we disclosed it within the preceding year. |
| Withdrawal of consent | Acknowledged within 10 business days (Section 5.3). |
| Complaints | Acknowledged within 5 business days. |
Fees. We do not charge for correction requests. For access requests, we may charge a reasonable fee to cover the incremental cost of responding; if so, we will give you a written estimate before proceeding.
Limits. We may decline or limit a request where permitted by law — for example, where the request is frivolous or vexatious, where providing the data could reveal personal data about another individual or confidential commercial information, where the data is subject to legal privilege, or where it relates to an ongoing investigation or proceedings. If we decline, we will tell you why, to the extent we lawfully can.
Client engagement data. Where your request concerns data we process as a data intermediary, we will refer it to the client organisation (Section 2).
We encourage you to contact us first so we can try to resolve your concern. You also have the right to complain to the Personal Data Protection Commission of Singapore, or to the data protection authority in your jurisdiction.
14.1 Do Not Call. Before sending a marketing message by voice call, text, or fax to a Singapore telephone number, we check the relevant Do Not Call Registry as required by law, unless you have given us clear and unambiguous consent in written or other accessible form. Our marketing messages identify BITSTRIC and include our contact details.
14.2 Email. Our marketing emails include an unsubscribe facility and our contact details, in accordance with the Spam Control Act 2007. We give effect to unsubscribe requests within 10 business days.
14.3 Service communications. Opting out of marketing does not stop communications we need to send in connection with a contract or service you have with us.
Our website uses cookies and similar technologies. Details of the cookies we use, their purposes, and how to manage your preferences are set out in our Cookie Policy. Where the law requires your consent for non-essential cookies, we do not set them until you have given it.
Our business is based in Singapore. Where we handle the personal data of individuals located in another jurisdiction and that jurisdiction's law applies to us, we comply with its applicable requirements, including — where they apply to us — appointing a local representative or data protection officer, conducting required impact assessments before cross-border transfers, and meeting local breach notification timeframes. These laws may include:
| Jurisdiction | Principal legislation |
|---|---|
| Malaysia | Personal Data Protection Act 2010, as amended |
| Vietnam | Law on Personal Data Protection and implementing decrees |
| India | Digital Personal Data Protection Act 2023 and Rules |
| Australia | Privacy Act 1988 |
| Hong Kong SAR | Personal Data (Privacy) Ordinance (Cap. 486) |
| Japan | Act on the Protection of Personal Information |
| South Korea | Personal Information Protection Act |
| Philippines | Data Privacy Act of 2012 |
| Thailand | Personal Data Protection Act B.E. 2562 |
| Indonesia | Law No. 27 of 2022 on Personal Data Protection |
Information about rights and contacts specific to your jurisdiction is available on request from our Data Protection Officer.
Our services are intended for businesses and professionals and are not directed at children. We do not knowingly collect personal data from individuals under 13 years of age, or under any higher age of digital consent that applies in their jurisdiction. If you believe a child's personal data has been provided to us, please contact our Data Protection Officer and we will review and delete it as appropriate.
18.1 Corporate transactions. If BITSTRIC is involved in, or considering, a financing, merger, acquisition, restructuring, or sale of all or part of its business or assets, we may disclose personal data to the prospective party and its advisers where permitted by the PDPA's business asset transaction provisions. Any such disclosure will be limited to what is necessary for evaluating or completing the transaction, and made under written confidentiality obligations requiring the recipient to use the data only for that purpose and to return or destroy it if the transaction does not proceed.
18.2 Continuity of protection. If a transaction completes, personal data transferred as part of it will continue to be protected in accordance with this Policy, or a policy offering comparable protection, and — for Client Data — in accordance with the applicable DPA. Where required by law, affected individuals will be notified.
18.3 Service continuity. We maintain backup and recovery arrangements designed to protect the availability and integrity of personal data. If we cease to provide a service, Client Data will be returned or deleted in accordance with the applicable client agreement.
Our website may link to third-party websites, platforms, or services. We are not responsible for their privacy practices, and we encourage you to read their privacy policies. Where a client instructs us to integrate with a third-party service, that service's handling of data is governed by the client's arrangement with it.
We review this Policy periodically, and at least annually, and update it to reflect changes in our practices, service providers, or applicable law. The current version is published on this page with its version number and effective date.
Where we make a material change, we will notify clients and subscribed contacts at least 14 days before it takes effect, except where an earlier change is required by law or is needed to address an urgent security matter, in which case we will notify you as soon as practicable. Changes do not reduce the protection of personal data collected before the change without your consent where the law requires it.
We have appointed a Data Protection Officer to oversee our compliance with the PDPA. Appointing a Data Protection Officer does not relieve BITSTRIC of its own responsibility under the PDPA.
| Purpose | Contact |
|---|---|
| Data Protection Officer — rights requests, complaints, consent withdrawal | [email protected] |
| General privacy enquiries | [email protected] |
| Requests relating to a client engagement | Your organisation, or your account contact at BITSTRIC |
This Policy is governed by the laws of Singapore. This does not deprive you of the protection of any mandatory data protection law of the jurisdiction in which you are located that applies to our handling of your personal data.
Our legal team is available to discuss enterprise-specific MSAs and compliance requirements.