Legal

    Privacy Policy

    PRVW Pte. Ltd.

    Privacy Policy

    Effective Date: March 22, 2026

    Last Updated: March 22, 2026

    PRVW Pte. Ltd. (UEN: 202537271E) ("PRVW", "we", "our", or "us") is committed to protecting the privacy and personal data of our customers, website visitors, and other individuals whose data we process. This Privacy Policy explains how we collect, use, disclose, and protect personal data in accordance with the Singapore Personal Data Protection Act 2012 ("PDPA") and, where applicable, the EU General Data Protection Regulation ("GDPR") and other relevant data protection laws.

    By using our website, platforms, or services, you acknowledge that you have read and understood this Privacy Policy.

    1. Who We Are

    PRVW Pte. Ltd. provides Decision Intelligence and Data Asset Management Platforms, alongside data and AI consultancy services. Our registered office is at 18 Robinson Road #15-01, Singapore 048547.

    For the purposes of data protection law, PRVW is the data controller for personal data collected through our website and in connection with our business operations. When we process personal data on behalf of our customers through the Services, we act as a data processor on the customer's behalf.

    Our Data Protection Officer can be contacted at infosec@prvw.ai.

    2. Personal Data We Collect

    We collect personal data in the following categories:

    2.1 Data You Provide Directly

    - Account registration information: name, email address, job title, company name

    • Contact form submissions: name, email address, message content

    - Contractual information: billing details, company registration information, contact details for Order Forms

    - Communications: emails, support requests, and other correspondence with us

    2.2 Data We Collect Automatically

    - Website usage data: pages visited, time spent, referral source, browser type, device type, operating system

    • IP address and approximate geolocation (country/region level)
    • Cookies and similar technologies (see Section 8 below)

    2.3 Data We Process on Behalf of Customers

    When customers use our Services, they may submit data that contains personal data of their own users, employees, or customers ("Customer Data"). We process Customer Data strictly on our customers' instructions and in accordance with our contractual agreements. Our customers are the data controllers for their Customer Data.

    3. How We Use Personal Data

    We use personal data for the following purposes:

    ----------------------- ----------------------- ----------------------- Purpose Data Used Legal Basis

    Providing and Account information, Performance of operating the Customer Data contract; Legitimate Services interest

    Responding to Contact details, Legitimate interest; enquiries and support message content Consent requests

    Billing and Billing details, Performance of invoicing company information contract; Legal obligation

    Improving our website Website usage data, Legitimate interest and Services aggregated analytics

    Security and fraud IP address, access Legitimate interest; prevention logs, account activity Legal obligation

    Compliance with legal As required by Legal obligation obligations applicable law

    Sending product Name, email address Consent; Legitimate updates and interest communications ----------------------- ----------------------- -----------------------

    We do not sell personal data to third parties. We do not use personal data for automated decision-making or profiling that produces legal or similarly significant effects.

    4. How We Share Personal Data

    We may share personal data with the following categories of recipients:

    - Cloud infrastructure providers: Amazon Web Services (AWS), for hosting the Services in the Asia-Pacific (Singapore) region

    - Productivity and collaboration tools: Microsoft (Entra ID, Microsoft 365) for internal operations

    • Compliance and security tools: Vanta for compliance management

    - Professional advisors: legal counsel, auditors, and accountants where necessary for business operations

    - Law enforcement or regulators: where required by applicable law or to protect our legal rights

    All third-party service providers are subject to contractual obligations to protect personal data in accordance with our Third-Party Management Policy. We do not transfer personal data to third parties for their own marketing purposes.

    5. International Data Transfers

    PRVW's primary infrastructure is hosted on AWS in the Asia-Pacific (Singapore) region. Some of our service providers may process personal data in other jurisdictions. Where personal data is transferred outside of Singapore or the European Economic Area (EEA), we ensure that appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission, or reliance on the recipient's participation in recognised data protection frameworks.

    6. Data Retention

    We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Specific retention periods include:

    - Customer Data: retained for the duration of the contract and deleted within sixty (60) days of contract termination

    - Account information: retained for the duration of the customer relationship and a reasonable period thereafter for legal and audit purposes

    - Website analytics data: retained in aggregated, anonymised form; raw data retained for no longer than 12 months

    - Communications and support records: retained for the duration of the business relationship

    Personally identifiable information is deleted or de-identified as soon as it no longer serves a legitimate business purpose, consistent with our Data Management Policy.

    7. Your Rights

    Depending on your jurisdiction, you may have the following rights in relation to your personal data:

    7.1 Under the PDPA (Singapore)

    • Access: Request access to your personal data held by us

    - Correction: Request correction of inaccurate or incomplete personal data

    - Withdrawal of consent: Withdraw consent for the collection, use, or disclosure of your personal data (subject to legal and contractual restrictions)

    - Data portability: Request a copy of your data in a commonly used machine-readable format (where applicable under the PDPA data portability provisions)

    7.2 Under the GDPR (EEA individuals)

    • Access: Request access to your personal data
    • Rectification: Request correction of inaccurate personal data

    - Erasure: Request deletion of your personal data ("right to be forgotten")

    • Restriction: Request restriction of processing of your personal data

    - Portability: Request transfer of your personal data in a structured, machine-readable format

    - Objection: Object to processing based on legitimate interests or direct marketing

    • Complaint: Lodge a complaint with your local supervisory authority

    To exercise any of these rights, please contact us at infosec@prvw.ai. We will respond to verified requests within thirty (30) days, or within the timeframe required by applicable law.

    8. Cookies and Tracking Technologies

    Our website may use cookies and similar technologies to improve your browsing experience and to analyse website usage. Cookies are small text files stored on your device when you visit our website.

    We may use the following categories of cookies:

    - Strictly necessary cookies: Required for the website to function (e.g., session management, security). These cannot be disabled.

    - Analytics cookies: Help us understand how visitors interact with our website (e.g., pages visited, time on site). These are only set with your consent where required by law.

    We do not use advertising or tracking cookies. You can manage your cookie preferences through your browser settings. Disabling certain cookies may affect the functionality of our website.

    9. Data Security

    We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:

    - Encryption of data at rest (AES-256) and in transit (TLS 1.2 or higher)

    - Role-based access control with multi-factor authentication for privileged access

    • Regular vulnerability assessments and continuous monitoring

    - An information security management system aligned to ISO/IEC 27001:2022 and SOC 2 Trust Services Criteria

    • Incident response procedures with defined notification timelines

    Further details on our security practices are available through our Trust Center.

    10. Children's Privacy

    Our Services are not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If you believe that we have inadvertently collected personal data from a child, please contact us at infosec@prvw.ai and we will take steps to delete the data promptly.

    11. Third-Party Links

    Our website or Services may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to review the privacy policies of any third-party services you access through our website.

    12. Changes to This Privacy Policy

    We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you by updating the "Last Updated" date at the top of this policy and, where appropriate, providing additional notice (such as via email or a prominent notice on our website). We encourage you to review this policy periodically.

    13. Contact Us

    If you have any questions about this Privacy Policy, wish to exercise your data protection rights, or have a complaint about how we handle your personal data, please contact:

    PRVW Pte. Ltd.

    Data Protection Officer: Blair Ferguson

    18 Robinson Road #15-01, Singapore 048547

    Email: infosec@prvw.ai

    If you are not satisfied with our response, you may lodge a complaint with the Personal Data Protection Commission (PDPC) in Singapore at www.pdpc.gov.sg, or with your local data protection supervisory authority if you are located in the EEA.