Version 2.0 · Effective 4 August 2026 · Supersedes the version dated 10 May 2026
Data Protection Officer — [email protected] · NKKTECH GLOBAL PTE. LTD. (UEN 202445701K), 18 Sin Ming Lane, #07-13 Midview City, Singapore, 573960
NKKTECH GLOBAL PTE. LTD. (UEN 202445701K), whose registered office is at 18 Sin Ming Lane, #07-13 Midview City, Singapore, 573960, is the organisation responsible for personal data collected through this website and our related services. In this policy, "NKKTech", "we" and "us" mean that company. Our Vietnam group companies process personal data on our instructions as data intermediaries under written agreement; they are not separately responsible to you for it. This policy is written to Singapore's Personal Data Protection Act 2012 ("PDPA"). Where you are in the EU or UK we also apply the GDPR standards described in sections 4 and 8; where you are in Japan we apply the APPI, and in Vietnam Decree 13/2023/ND-CP.
As required by sections 11(3) and 11(5) of the PDPA we have designated a Data Protection Officer. Contact the Data Protection Officer at [email protected], or by post at Data Protection Officer, NKKTECH GLOBAL PTE. LTD. (UEN 202445701K), 18 Sin Ming Lane, #07-13 Midview City, Singapore, 573960. Use this address for access requests, correction requests, withdrawal of consent, complaints, or any question about this policy. We acknowledge every request within 5 business days.
Data you give us: name, work email, company, country, job title, project type, indicative budget, timeline and any free text you enter, submitted through our contact form, newsletter sign-up, capability-deck download, AI-readiness assessment, or Calendly booking. Data collected automatically: IP address, user-agent, referrer, pages viewed and server logs (strictly necessary), and — only after you accept the corresponding consent category — Google Analytics 4 measurement data, Microsoft Clarity session recordings and heatmaps, which capture your mouse movement, scrolling, clicks and the pages you view on this site, and Meta Pixel advertising-attribution events. Clarity recordings are masked so that text you type into form fields is not captured. We do not knowingly collect data about children, and we do not collect special categories of data such as health, biometric or political data.
We use personal data to respond to your enquiries and prepare proposals; to deliver and administer engagements you have asked for; to send you our newsletter where you have opted in; to measure and improve this website; to keep our systems secure and prevent fraud; and to meet legal, tax and accounting obligations. Under the PDPA we rely on your consent for newsletter and non-essential analytics and marketing, and on the legitimate-interests and business-improvement exceptions in the First Schedule for security, fraud prevention and service improvement. For visitors in the EU or UK the equivalent GDPR bases are Article 6(1)(b) for enquiries and engagements, 6(1)(a) for newsletter and non-essential cookies, 6(1)(f) for security and improvement, and 6(1)(c) for legal obligations. We do not carry out automated decision-making that produces legal or similarly significant effects.
We do not sell, trade or rent personal data. We disclose it to the service providers listed in section 6, each engaged under a written data-processing agreement that limits them to acting on our instructions; to professional advisers under a duty of confidence; and where we are required to by law or valid legal process. If our business or any part of it is transferred, personal data may be transferred with it; we will notify you and the receiving organisation will remain bound by the PDPA.
Website and infrastructure: DigitalOcean LLC (hosting, Singapore region) and Cloudflare, Inc. (DNS, CDN, WAF, bot mitigation; global points of presence). Communications: Resend (Drift.com, Inc.) for transactional email and Calendly LLC for call scheduling. Analytics and advertising, loaded only on consent: Google LLC (Google Analytics 4), Microsoft Corporation (Clarity) and Meta Platforms, Inc. (Meta Pixel). Content: Sanity AS (headless CMS — public marketing content only, no visitor data). Internal handling of enquiries: Notion Labs, Inc., Slack Technologies, LLC and HubSpot, Inc. Outbound programmes: Apollo.io (ZenProspect, Inc.) and Instantly.ai — see section 7. Anthropic PBC provides workflow automation used in internal lead triage. Each provider operates under its own privacy policy. We update this list when a provider is added or removed.
We do run business-to-business outbound campaigns, using the providers named in section 6. We describe this plainly because an earlier version of this policy said we did not, while listing the tools that do it. Where we send outbound email we identify ourselves and our postal address in the message, include a working unsubscribe facility, honour unsubscribe requests promptly, and apply the labelling requirements of the Spam Control Act 2007 where they apply to the message. Before making a marketing call or sending a marketing text message to a Singapore telephone number we check the number against the Do Not Call Registry. You can opt out of all outbound marketing at any time by writing to [email protected].
Several of the providers in section 6 are located outside Singapore, principally in the United States and the European Union. Before transferring personal data out of Singapore we take steps, as required by section 26 of the PDPA and Regulation 10 of the Personal Data Protection Regulations 2021, to satisfy ourselves that the recipient is bound by legally enforceable obligations to protect the data to a standard at least comparable to the PDPA. In practice we rely on written contracts with each provider that impose those obligations, incorporating the European Commission's Standard Contractual Clauses where the provider offers them and, for United States providers certified under it, the EU–US Data Privacy Framework. A copy of the transfer terms for a specific provider is available from our Data Protection Officer on request.
Enquiry and lead records: 24 months from your last interaction, then deleted or anonymised. Newsletter subscriptions: until you unsubscribe, plus 30 days on a suppression list so we do not re-add you. Google Analytics 4: 14 months. Microsoft Clarity recordings: 13 months. Server access logs: 90 days. Backup volumes: 14 days on a rolling basis. Records we must keep for tax and accounting: 10 years. We cease to retain personal data once the purpose it was collected for is no longer served by retention and retention is no longer necessary for legal or business purposes.
Under sections 21 and 22 of the PDPA you may ask us for the personal data we hold about you and information about how it has been used or disclosed in the past year, and you may ask us to correct an error or omission. Write to [email protected]. We will respond as soon as reasonably possible. If we cannot respond within 30 days of receiving your request we will tell you, within that period, the time by which we will respond. There are limited situations in which the PDPA does not require or permit us to provide access — for example where doing so would reveal personal data about another individual — and we will explain if any applies. We may need to verify your identity first. A reasonable fee may apply to an access request, and we will tell you the amount before proceeding. If you are unhappy with our handling you may complain to the Personal Data Protection Commission at pdpc.gov.sg. Visitors in the EU or UK additionally have the GDPR rights of erasure, restriction, objection and portability, and may complain to their national supervisory authority; visitors in Japan and Vietnam have the equivalent rights under the APPI and Decree 13/2023.
You may withdraw consent for any purpose you consented to, at any time, by writing to [email protected] or — for analytics and marketing cookies — through the "Cookie preferences" control in the footer of every page. We will action the withdrawal and confirm it. What it means in practice: withdrawing newsletter consent stops the newsletter; withdrawing analytics or marketing consent stops those scripts loading and stops further collection through them. Withdrawal does not affect processing carried out before you withdrew, and it does not require us to delete data we must keep to meet a legal obligation or to administer an engagement already under way. Where withdrawal would prevent us from continuing to provide something you have asked for, we will tell you before it takes effect.
Three categories. Strictly necessary: site security, session integrity and storing your consent choice; these cannot be switched off. Analytics: Google Analytics 4 and Microsoft Clarity, loaded only after you accept the Analytics category. Marketing: Meta Pixel, loaded only after you accept the Marketing category. Analytics and Marketing are off by default and no third-party script runs before you accept. Change or withdraw your choice at any time through "Cookie preferences" in the footer, or by clearing the nkktech_consent entry in your browser's local storage. We honour browser Do-Not-Track and Global Privacy Control signals as a withdrawal of analytics and marketing consent.
We protect personal data with encryption in transit (TLS 1.2 or higher, with HSTS) and encryption at rest on managed cloud storage. Access to production systems is restricted to named administrators, authenticated with keys rather than passwords, and logged. Secrets are held in a managed secret store and never committed to source control. Servers are hardened and patched, with automated blocking of repeated failed authentication. We take encrypted backups on a defined schedule and test restoration. Staff are bound by confidentiality obligations and receive data-protection training. Further detail is available to clients and prospective clients under NDA. No method of transmission or storage is completely secure, and we do not claim otherwise.
If a data breach occurs we assess it promptly. Where the breach is notifiable under Part 6A of the PDPA — because it results in, or is likely to result in, significant harm to affected individuals, or is of a significant scale — we notify the Personal Data Protection Commission as soon as practicable and in any case no later than 3 calendar days after we determine that it is notifiable. We notify affected individuals as soon as practicable, at the same time as or after notifying the Commission, unless an exception in the Act applies. Where the GDPR also applies we notify the relevant supervisory authority within 72 hours in accordance with Articles 33 and 34.
We may update this policy. Each version carries a version number and effective date at the top of this page. Material changes take effect 30 days after publication, except where a change is required by law or addresses a security risk, in which case it takes effect immediately. For any privacy matter contact the Data Protection Officer at [email protected], or by post at NKKTECH GLOBAL PTE. LTD. (UEN 202445701K), 18 Sin Ming Lane, #07-13 Midview City, Singapore, 573960. For general enquiries: [email protected].