PDPA Compliance Statement
Effective Date: May 30, 2026
Applies to: Singapore and Asia-Pacific services
1. Our Commitment to Data Protection
HumanLed AI is committed to protecting your personal data in compliance with Singapore's Personal Data Protection Act (PDPA) and applicable Asia-Pacific data protection regulations. We handle all client and customer data with care, respect, and security.
2. PDPA Compliance Principles
We Comply With These PDPA Principles:
- Consent: We collect personal data only with explicit consent
- Purpose Limitation: We use data only for stated purposes
- Notification: We inform you of data collection and use
- Accuracy: We keep data accurate and up-to-date
- Protection: We use encryption and secure systems
- Retention: We keep contact data for two years from your last interaction, then permanently strip identifying details from the record. PDPC Key Concepts 18.10(d) treats anonymisation as ceasing to retain; a hidden-but-present record would not qualify (18.11).
- Access & Correction: You can request your data or correct errors
- Transfer Limitation: Some of our service providers process data outside Singapore. Where they do, we rely on contractual protections so the data receives a standard comparable to the PDPA, as required by s26. Each provider and its processing location is named in our Privacy Policy.
3. Types of Personal Data We Collect
From Contact Forms
- Name, email, phone number
- Company name and industry
- Business challenges and inquiries
From Website Interactions
- Pages visited, links clicked
- Browser type and IP address
- Time spent on website
During Implementation
- Business process information
- Customer interaction data (for AI training, if provided)
- Performance metrics and usage data
4. How We Use Your Data (PDPA Purpose Limitation)
- Respond to your inquiries about AI automation services
- Provide implementation and training services
- Send newsletters and service updates (with consent)
- Improve website functionality and user experience
- Comply with legal obligations
- Train AI models (only with explicit consent and data anonymization)
5. Data Security Measures
We Protect Data Using:
- HTTPS encryption for all website communications
- Secure encrypted storage for databases
- Limited access controls (staff need-to-know)
- Regular security updates and patches
- Secure API connections with third-party services
- Firewalls and intrusion detection systems
- Annual security audits (recommended)
6. Third-Party Data Processors
We share data only with service providers who help us operate:
- Email Services: SendGrid (for newsletters and confirmations)
- Hosting & Infrastructure: Vercel (for website and API hosting)
- Automation Platforms: Make.com (for workflow integration)
- CRM Systems: HubSpot (if you consent to CRM integration)
All processors are bound by data protection agreements and comply with PDPA.
7. Your PDPA Rights
You Have the Right To:
- Access your personal data: Request a copy of data we hold about you
- Correct inaccurate data: Update or fix incorrect information
- Withdraw consent: Opt out of emails and communications
- Request deletion: Delete your data (subject to legal retention requirements)
- Lodge a complaint: Report concerns to PDPC Singapore
8. How to Exercise Your Rights
To access, correct, withdraw consent, or delete your personal data:
Email: hello@humanledai.sg
Phone: +65 8051 4988
Address: Singapore (to be provided upon request)
We will respond to your request within 30 days as required by PDPA.
9. Data Retention Policy
- Contact form data: Retained for 2 years; deleted upon request
- Website analytics: Retained for 1 year
- Implementation data: Retained for duration of engagement + 2 years
- Email communications: Retained until you unsubscribe
10. AI Training and Data Anonymization
If you provide data for AI training purposes:
- We use anonymization techniques to remove identifying information
- We require explicit written consent before using data for training
- You can revoke consent and request data deletion at any time
- Anonymized data is not subject to PDPA (cannot identify individuals)
11. International Data Transfers
If you work with HumanLed AI in other Asia-Pacific countries, we comply with local data protection laws:
- Malaysia: Personal Data Protection Act 2010
- Indonesia: Law No. 27 of 2022 on Data Protection
- Thailand: Personal Data Protection Act B.E. 2562
- Philippines: Data Privacy Act of 2012
- Vietnam: Law on Information Security
12. Changes to This Statement
We may update this statement to reflect changes in our practices or PDPA requirements. We will notify you of material changes via email or on our website.
13. Report a Data Breach
If you believe your data has been compromised:
Contact us immediately: hello@humanledai.sg or +65 8051 4988
Report to PDPC Singapore: PDPC Complaint Portal
14. Contact Our Data Protection Officer
For PDPA questions or concerns:
Email: hello@humanledai.sg
Phone: +65 8051 4988