Legal & Compliance

Government & Law-Enforcement Request Policy

Principles for lawful, proportionate, and secure handling of official demands.

Effective and last updated: July 13, 2026

This public policy is a baseline. A signed order form, enterprise agreement, or data-processing agreement may contain additional terms and prevails to the extent of a conflict.

Valid legal process

HEOSSI responds to binding legal process issued by an authority with jurisdiction. Requests should identify the authority and officer, legal basis, account or data sought, relevant period, return date, confidentiality requirement, and secure response channel. Routine service should be directed to legal@heossi.com; emergencies involving imminent risk to life should be clearly marked and supported by the facts and legal authority relied upon.

Review and minimisation

We verify authenticity, jurisdiction, scope, legality, and consistency with applicable data-protection and secrecy duties. We may reject, narrow, preserve, challenge, or seek clarification of requests that are defective, overbroad, disproportionate, conflict with law, or seek data we do not control. We disclose only responsive data we are legally required or validly authorised to disclose.

Customer notice

Where legally permitted and operationally reasonable, HEOSSI will notify the affected customer before disclosure so they may seek protection. We may delay or withhold notice where prohibited, where notice would create a material safety or security risk, or in a genuine emergency. We may later provide notice when the restriction ends, unless law continues to prohibit it.

Cross-border and costs

Foreign authorities should use applicable mutual legal-assistance, treaty, or recognised cross-border procedures unless Singapore law permits another route. HEOSSI may seek reimbursement of reasonable costs where law permits. Nothing here promises that HEOSSI holds particular data or waives objections, privileges, immunities, or customer rights.