Privacy Policy
How we collect, use, and protect your personal data
Last updated: January 2025
1. Introduction
AlrightyDocs Pte. Ltd. ("we," "our," or "us") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our document processing platform and services.
We are a Singapore-based company and comply with the Singapore Personal Data Protection Act 2012 ("PDPA") and the European Union General Data Protection Regulation ("GDPR") for our international users.
2. Information We Collect
2.1 Personal Information
- Account Information: Name, email address, company name, job title
- Contact Information: Phone number, business address
- Payment Information: Billing address, payment method details (processed securely through third-party payment processors)
- Profile Information: User preferences, profile photo
2.2 Document Data
- Uploaded Documents: Files you upload for processing (invoices, contracts, proposals, etc.)
- Extracted Data: Information extracted from your documents by our AI processing system
- Processing Results: Structured data, insights, and analysis results
2.3 Technical Information
- Usage Data: How you interact with our platform, features used, time spent
- Device Information: IP address, browser type, operating system, device identifiers
- Log Data: Server logs, error reports, performance metrics
- Cookies: Session data, preferences, authentication tokens
3. How We Use Your Information
3.1 Service Provision
- Process your documents using our AI technology
- Provide structured data extraction and analysis
- Maintain and improve our platform functionality
- Provide customer support and technical assistance
3.2 Business Operations
- Process payments and manage billing
- Send service-related communications
- Prevent fraud and ensure platform security
- Comply with legal obligations
3.3 Improvement and Development
- Analyze usage patterns to improve our services
- Develop new features and functionalities
- Train and improve our AI models (using anonymized data only)
3.4 Marketing (with consent)
- Send promotional materials and product updates
- Provide information about new features
- Conduct surveys and research
4. Legal Basis for Processing (GDPR)
For our EU users, we process personal data based on:
- Contract: Processing necessary to provide our services
- Legitimate Interest: Platform improvement, security, and business operations
- Consent: Marketing communications and non-essential features
- Legal Obligation: Compliance with applicable laws
5. Data Sharing and Disclosure
We do not sell your personal data. We may share information with:
5.1 Service Providers
- Cloud infrastructure providers (AWS, Google Cloud)
- Payment processors (Stripe, PayPal)
- Email service providers
- Analytics and monitoring tools
5.2 Legal Requirements
- When required by law or legal process
- To protect our rights and property
- In connection with business transfers or mergers
- With your explicit consent
6. Data Security
We implement comprehensive security measures:
- Encryption: Data encrypted in transit and at rest using AES-256
- Access Controls: Multi-factor authentication and role-based access
- Infrastructure: Secure cloud hosting with regular security audits
- Monitoring: 24/7 security monitoring and incident response
- Compliance: SOC 2 Type II and ISO 27001 certified infrastructure
7. Data Retention
- Account Data: Retained while your account is active and for 3 years after closure
- Document Data: Retained for the duration specified in your service agreement
- Usage Data: Aggregated data may be retained indefinitely for analytics
- Legal Data: Some data may be retained longer to comply with legal obligations
8. Your Rights
8.1 PDPA Rights (Singapore residents)
- Access: Request access to your personal data
- Correction: Request correction of inaccurate data
- Withdrawal: Withdraw consent for data processing
8.2 GDPR Rights (EU residents)
- Access: Obtain a copy of your personal data
- Rectification: Correct inaccurate personal data
- Erasure: Request deletion of your personal data
- Portability: Receive your data in a portable format
- Restriction: Limit processing of your personal data
- Objection: Object to processing based on legitimate interests
To exercise your rights, contact us at privacy@alrightydocs.com
9. International Data Transfers
Your data may be processed in countries outside Singapore and the EU. We ensure adequate protection through:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- APEC Cross-Border Privacy Rules (CBPR) certification
- Adequacy decisions where applicable
- Other appropriate safeguards as required by law
10. Cookies and Tracking
We use cookies and similar technologies for:
- Essential: Authentication, security, and basic functionality
- Functional: Remember your preferences and settings
- Analytics: Understand how you use our platform (with consent)
- Marketing: Deliver relevant advertisements (with consent)
You can manage cookie preferences through your browser settings or our cookie banner.
11. Third-Party Links
Our platform may contain links to third-party websites or services. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies before providing any information.
12. Children's Privacy
Our services are not intended for children under 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal data from a child, we will take steps to delete such information promptly.
13. Data Breach Notification
In the event of a data breach that may cause harm, we will:
- Notify the relevant authorities within 72 hours (GDPR) or 3 days (PDPA)
- Inform affected users without undue delay
- Provide information about the breach and mitigation measures
- Take immediate steps to prevent further unauthorized access
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Posting the updated policy on our website
- Sending email notifications for significant changes
- Providing in-app notifications
Your continued use of our services after changes constitute acceptance of the updated policy.
15. Contact Information
Data Protection Officer
AlrightyDocs Pte. Ltd.
Email: privacy@alrightydocs.com
Address: [Singapore Business Address]
Phone: +65 XXXX XXXX
Supervisory Authorities
- Singapore: Personal Data Protection Commission (PDPC) - www.pdpc.gov.sg
- EU: Your local Data Protection Authority for GDPR-related concerns