Legal
Privacy Policy
Vectasense Pte. Ltd. ("Vectasense," "we," "us," or "our") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and protect personal data when you use our platform, products, and services ("Services").
This Privacy Policy is governed by the Personal Data Protection Act 2012 ("PDPA") of Singapore and, where applicable, the General Data Protection Regulation ("GDPR") of the European Union.
1. Personal Data We Collect
1.1 Information You Provide Directly
| Category | Examples |
|---|---|
| Identity Data | Name, job title, company name, professional role |
| Contact Data | Email address, telephone number, business address |
| Account Data | Username, password, account preferences |
| Transaction Data | Subscription details, payment history, invoices |
| Communication Data | Correspondence, support requests, feedback |
| Customer Content | Data you upload to the Platform for analysis |
1.2 Information Collected Automatically
| Category | Examples |
|---|---|
| Technical Data | IP address, browser type and version, device type, operating system |
| Usage Data | Pages visited, features used, time spent on Platform, clickstream data |
| Log Data | Access times, error logs, referring URLs |
1.3 Cookies and Similar Technologies
We use cookies and similar tracking technologies to enhance your experience, analyze usage patterns, and improve our Services. You may control cookie preferences through your browser settings. Essential cookies required for Platform functionality cannot be disabled.
2. How We Use Your Personal Data
We use your personal data for the following purposes:
(a) Service Delivery: To provide, maintain, and improve the Services, including processing your requests and delivering Output.
(b) Account Management: To create and manage your account, authenticate your identity, and communicate with you about your account.
(c) Payment Processing: To process payments, send invoices, and manage billing.
(d) Communication: To respond to your inquiries, provide customer support, and send service-related notifications.
(e) Analytics and Improvement: To analyze usage patterns, diagnose technical issues, and improve the Platform's performance and features.
(f) Security: To detect, prevent, and address fraud, unauthorized access, and other security issues.
(g) Legal Compliance: To comply with applicable laws, regulations, and legal processes.
3. AI-Specific Data Practices
3.1 Customer Content Processing. When you upload Customer Content to the Platform, our AI agents process this data to generate Output. This processing occurs solely to provide the Services you have requested.
3.2 No Training on Customer Content. Vectasense does not use Customer Content to train its foundation AI models without your express written consent.
3.3 Aggregated and Anonymized Data. We may collect, anonymize, and aggregate data derived from your use of the Services for industry analysis, benchmarking, analytics, and service improvement ("Aggregated Data"). Aggregated Data does not identify you or any individual and is the sole property of Vectasense. We do not attempt to re-identify anonymized data.
3.4 Usage Data. We collect and use Usage Data (metadata, performance metrics, error logs, latency statistics) to maintain, improve, and optimize the Services. Usage Data does not include the substance of your Customer Content.
4. Disclosure of Personal Data
We may disclose your personal data to:
(a) Service Providers: Third-party vendors who assist in providing the Services, including cloud infrastructure providers, payment processors, and analytics services. These providers are contractually bound to protect your data and use it only for the purposes we specify.
(b) Professional Advisors: Legal, accounting, and other professional advisors as necessary for our business operations.
(c) Legal Requirements: Government authorities or other parties when required by law, regulation, legal process, or enforceable governmental request.
(d) Business Transfers: In connection with a merger, acquisition, reorganization, or sale of assets, in which case your personal data may be transferred to the successor entity.
We do not sell your personal data to third parties.
5. Cross-Border Data Transfers
As a cloud-based platform, your personal data may be transferred to and processed in jurisdictions outside of Singapore, including the United States and other countries where our service providers operate.
To ensure lawful transfer and adequate protection of your personal data:
(a) For transfers within Southeast Asia, we utilize the ASEAN Model Contractual Clauses ("MCCs") to ensure the recipient provides a standard of protection comparable to the PDPA.
(b) For transfers involving personal data from the European Union, we incorporate the EU Standard Contractual Clauses (2021), Module Two (Controller-to-Processor), by reference.
(c) For all other transfers, we implement appropriate safeguards, including contractual obligations on recipients to protect personal data to a standard comparable to the PDPA.
6. Data Security
We implement reasonable security arrangements to protect personal data against unauthorized access, collection, use, disclosure, copying, modification, disposal, or similar risks. Our security measures include:
(a) Encryption of data in transit and at rest;
(b) Access controls and authentication mechanisms;
(c) Regular security assessments and penetration testing;
(d) Employee training on data protection;
(e) Incident response procedures.
While we take reasonable precautions, no method of transmission over the Internet or electronic storage is completely secure. We cannot guarantee absolute security of your personal data.
7. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements. When personal data is no longer required, we securely delete or anonymize it in accordance with our data retention policies.
8. Your Rights Under the PDPA
Under the PDPA, you have the following rights regarding your personal data:
8.1 Right of Access. You may request access to your personal data in our possession or control, as well as information about how such data has been used or disclosed within the past year.
8.2 Right of Correction. You may request correction of any error or omission in your personal data. We will correct the data and, where applicable, send the corrected data to organizations to which we disclosed the data within the past year.
8.3 Right to Withdraw Consent. You may withdraw your consent for the collection, use, or disclosure of your personal data at any time, subject to legal or contractual restrictions and reasonable notice. Please note that withdrawal of consent may affect our ability to provide the Services to you.
8.4 Right to Data Portability. Upon request, we will transmit your personal data to another organization in a commonly used machine-readable format, subject to applicable regulations.
We will respond to your request within thirty (30) days. We may charge a reasonable fee to cover administrative costs for access requests.
9. Additional Rights for EU Data Subjects
If you are located in the European Economic Area, you have additional rights under the GDPR, including the right to erasure, the right to restrict processing, and the right to object to processing. To exercise these rights, please contact us using the details below.
10. Children's Privacy
The Services are not directed to individuals under the age of eighteen (18). We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child, we will take steps to delete such data promptly.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or through the Platform at least thirty (30) days before they take effect. The "Last Updated" date at the top of this page indicates when this Privacy Policy was last revised.
12. Contact Us
If you have questions, concerns, or complaints regarding this Privacy Policy or our data protection practices, please contact our Data Protection Officer:
Data Protection Officer
Vectasense Pte. Ltd.
Email: dpo@vectasense.com
Location: Singapore
If you are not satisfied with our response, you may lodge a complaint with the Personal Data Protection Commission of Singapore at https://www.pdpc.gov.sg.
13. Governing Law
This Privacy Policy shall be governed by and construed in accordance with the laws of the Republic of Singapore. Any dispute arising out of or in connection with this Privacy Policy shall be referred to and finally resolved by arbitration administered by the Singapore International Arbitration Centre ("SIAC") in accordance with the Arbitration Rules of the Singapore International Arbitration Centre for the time being in force.
BY USING THE PLATFORM, YOU ACKNOWLEDGE THAT YOU HAVE READ AND UNDERSTOOD THIS PRIVACY POLICY.