AI Receptionist Start free trial →
Legal

Privacy Policy

Effective [DATE] · Version 1.0 · [LEGAL ENTITY NAME] (UEN [UEN])

Before you publish this

Complete every highlighted field and have this reviewed by a Singapore-qualified lawyer. The PDPA requires you to appoint a Data Protection Officer and publish their business contact — clause 10 is not optional.

The short version

There are two different kinds of personal data here, and we treat them differently.

Your account data — your name, work email and company — is ours to look after. This policy explains what we do with it.

Your visitors' data — the names, phone numbers and visit records that appear on your kiosk — belongs to you. We only hold it because you asked us to. We do not sell it, mine it, or use it for anything except running your service. If a visitor wants their record, the organisation they visited is who they should ask.

1. Who we are

AI Receptionist is operated by [LEGAL ENTITY NAME], UEN [UEN], of [REGISTERED ADDRESS], Singapore.

This policy explains how we handle personal data in accordance with Singapore's Personal Data Protection Act 2012 (“PDPA”).

2. Two roles, two sets of data

This distinction determines who is accountable for what.

DataOur roleWho is accountable
Account data
Your name, work email, company, billing, support messages
We decide how it is used Us. This policy governs it.
Visitor data
Visitor names, phone numbers, companies, hosts, visit times, badge records
We process it only on your instructions, as a data intermediary You, the customer whose lobby collected it. See the Data Processing Addendum.

3. What we collect about you

You give us

We collect automatically

We do not collect

4. Why we use it

PurposeBasis under the PDPA
Creating and running your workspaceNecessary to perform our contract with you
Authenticating you and securing accountsLegitimate interests — security
Billing, renewals and receiptsNecessary to perform our contract
Support and service noticesNecessary to perform our contract
Diagnosing faults and improving reliabilityLegitimate interests — service quality
Meeting legal and regulatory obligationsRequired by law

We do not sell personal data. We do not share it with advertisers, and we do not use visitor data to train models.

We will only send you marketing email if you have opted in, and every such message carries an unsubscribe link. Service and security notices are not marketing and cannot be opted out of while you hold an account.

5. Visitor data

5.1 When a visitor checks in at your kiosk, the Service records what you have configured it to record — typically name, company, host, purpose and time, and optionally a phone number or email used to recognise returning visitors.

5.2 We process this only to provide the Service to you. We do not use it for our own purposes, disclose it to anyone except the sub-processors in clause 6, or retain it beyond what clause 8 describes.

5.3 You are responsible for telling visitors what you collect and why. A short notice displayed at the kiosk or on the wall is the usual approach. We provide the tool; the notice obligation is yours.

5.4 If a visitor contacts us directly about their data, we will refer them to the organisation whose lobby they visited, and notify that organisation. We cannot act on such a request without our customer's instruction.

6. Who we share it with

We use a small number of sub-processors. We do not sell or rent data to anyone.

WhoWhat forWhat they see
Supabase Database, authentication and serverless functions Account data and visitor data, encrypted in transit and at rest
Your SMS provider
chosen and contracted by you
Delivering host notifications The recipient's number and the message text
Your web host
where you deploy the files
Serving the application Standard web server logs
Google Fonts, esm.sh, unpkg Fonts and code libraries IP address and browser, as with any web request

We may also disclose personal data where required by law, court order or a lawful request from a public authority, and where necessary to establish or defend a legal claim.

7. Where it is stored

7.1 Data is stored in the [REGION — e.g. Asia Pacific (Tokyo)] region of our hosting provider.

Check this before publishing. Your database is currently provisioned in ap-northeast-1 (Tokyo), not Singapore. Under PDPA section 26 you must ensure overseas recipients provide a comparable standard of protection. This is lawful and common, but you must state the location accurately and be prepared to explain the safeguards. If a customer requires Singapore residency, provision their database in a Singapore region.

7.2 SMS messages are transmitted through your chosen provider, which may route them through infrastructure outside Singapore.

8. How long we keep it

DataRetention
Visitor recordsAs set by you in your retention settings; deleted automatically after that period
Audit logAs set by you; default 180 days
Account dataFor as long as your workspace exists
After terminationExportable for 30 days, then deleted
Billing recordsAs required by Singapore tax and accounting law
BackupsPurged on the ordinary backup cycle, normally within 30 days

9. How we protect it

No system is perfectly secure. We do not warrant that our measures will prevent every incident, and you remain responsible for the physical security of your devices and the confidentiality of your credentials.

10. Your rights and our DPO

Under the PDPA you may:

Write to our Data Protection Officer. We respond within 30 days, or tell you when to expect a response if we cannot.

Data Protection Officer
[DPO NAME]
[DPO EMAIL]
[REGISTERED ADDRESS]

Withdrawing consent may mean we can no longer provide the Service. Requests about visitor data should go to the organisation whose lobby was visited — see clause 5.4.

11. Data breaches

11.1 If we become aware of a data breach affecting personal data we process, we will assess it promptly and, where it is notifiable, notify the Personal Data Protection Commission within 3 calendar days of determining that it is notifiable.

11.2 A breach is notifiable where it is likely to result in significant harm to affected individuals, or where it affects the personal data of 500 or more individuals.

11.3 Where the breach affects visitor data we process on your behalf, we will notify you without undue delay so that you can meet your own obligations as the responsible organisation. Notifying affected individuals is your decision and your duty.

12. Cookies and tracking

12.1 We use browser storage only to keep you signed in and to remember your kiosk pairing. These are strictly necessary for the Service to function.

12.2 [If you add analytics, describe it here and add a consent banner.] As shipped, the Service contains no advertising or cross-site tracking.

13. Children

The Service is for business use and is not directed at children. We do not knowingly collect account data from anyone under 18. A child may be recorded as a visitor if your organisation checks one in; the notice and consent obligations for that are yours.

14. Changes

We may update this policy. Material changes will be notified by email to account owners at least 30 days in advance, and the effective date above will change. Continued use after that date means acceptance.

© 2026 [LEGAL ENTITY NAME]