Privacy & Data Protection Policy
How HEOSSI protects the confidentiality, integrity, and availability of information entrusted to us
Last Updated: February 24, 2026
Your Privacy Matters
HEOSSI (Pte.) Ltd. is committed to protecting your personal data in accordance with Singapore PDPA, EU GDPR, UK GDPR, California CCPA, and other applicable data protection frameworks. This policy explains how we collect, use, disclose, and safeguard Personal Data.
Scope & Applicability
This Policy applies to all Personal Data processed by HEOSSI in connection with our solutions, platforms, APIs, research initiatives, events, and outreach activities. It governs data collected through our websites, portals, APIs, communication channels, and any service relationship where we act as a data controller or data processor on behalf of our customers.
Where we process Personal Data on behalf of our customers, we do so under the instructions of the relevant data controller and the contractual terms agreed. In such cases, this Policy supplements - rather than replaces - those agreements.
Key Definitions
Personal Data
Data, whether true or not, about an individual who can be identified from that data or from that data and other information to which we have or are likely to have access.
Processing
Any operation performed on Personal Data, including collection, use, disclosure, storage, adaptation, destruction, or transfer.
Data Subject
The individual to whom Personal Data relates.
Data Processor
An organisation that processes Personal Data on behalf of another organisation but does not process it for its own purposes.
Personal Data We Collect
Identity & Contact Data
Full name, business title, identification documents (where legally required), email address, phone number, postal address.
Professional & Engagement Data
Organisation, role, areas of interest, contractual relationship details, due diligence information, project requirements, and communications history.
Technical & Usage Data
Server logs, IP address, device identifiers, authentication data, secure telemetry from our platforms and APIs, and configuration metadata necessary to provide services.
Compliance & Verification Data
Sanctions screening results, beneficial ownership information, regulatory filings, certifications, and attestations submitted as part of risk management.
Sensitive Information
Only collected where strictly necessary and with explicit consent or other lawful basis (e.g., biometric identifiers for secure facilities, health data for event access controls). Such data is subject to enhanced safeguards.
How We Collect Personal Data
- Directly from you when you submit contact forms, request materials, enter into contracts, participate in events, or interact with our platforms
- Automatically through secure telemetry, access logs, and platform instrumentation necessary to protect and maintain our infrastructure
- From third-party sources such as partners, information providers, public registries, or regulatory filings, where lawful and relevant to our service relationships
Lawful Grounds for Processing
We process Personal Data only where a valid legal basis exists:
Consent
Obtained explicitly or implied where permitted under PDPA and other laws.
Performance of a Contract
To deliver solutions, services, support, and obligations outlined in agreements.
Legitimate Interests
Such as securing our systems, pursuing business development, conducting due diligence, or improving services - provided such interests are not overridden by individual rights.
Compliance with Legal Obligations
Including regulatory filings, audits, sanctions screening, and law enforcement requests.
How We Use Personal Data
- Responding to enquiries and providing solution documentation, demos, and platform access
- Delivering, operating, and supporting our platforms and solutions
- Conducting security monitoring, incident response, fraud prevention, and risk assessments
- Managing contractual relationships, billing, and compliance obligations
- Improving our solutions, research, and development roadmap
- Communicating updates, insights, or invitations that align with your stated interests (you may opt out at any time)
- Complying with laws, regulations, court orders, or governmental requests
Data Residency & Sovereignty
Data Location
For SaaS deployments, customer data is primarily stored in Singapore and may be replicated to additional regions (EU, US) based on customer selection. Metadata, logs, and operational telemetry may be processed in multiple regions for service delivery and security monitoring.
Deployment Options
Customers with specific data residency requirements may select:
- SaaS with region selection (Singapore, EU, US)
- Private cloud deployment in customer-specified cloud regions
- On-premises deployment with full customer control of data location
Cross-Border Transfers
When data is transferred internationally, we comply with applicable data protection laws including GDPR (Standard Contractual Clauses), PDPA (transfer impact assessments), and CCPA. Transfers to countries without adequacy decisions are protected by appropriate safeguards.
Government Access
HEOSSI does not provide government agencies with direct access to customer data. We respond to lawful requests in accordance with applicable law and notify customers unless legally prohibited. For sovereign deployment models, customers maintain full control over government access decisions.
Your Data Protection Rights
Depending on your jurisdiction, you may have the following rights:
Access
Request copies of your personal data
Rectification
Correct inaccurate or incomplete data
Erasure
Request deletion of your personal data
Portability
Receive your data in a structured format
Restriction
Limit how we process your data
Objection
Object to certain processing activities
Data Security
We implement appropriate technical and organizational measures to protect Personal Data against unauthorized access, alteration, disclosure, or destruction:
- End-to-end encryption for data in transit and at rest
- Post-quantum cryptographic algorithms (CRYSTALS-Kyber, CRYSTALS-Dilithium)
- Multi-factor authentication and access controls
- Regular security audits and penetration testing
- Incident response and breach notification procedures
- Employee training on data protection and security
Data Retention
We hold very little personal data, and we would rather tell you exactly what and for how long than publish a schedule that sounds thorough but describes systems we do not operate.
| What | Where it lives | How long |
|---|---|---|
| Contact-form messages | Not stored in any database. The form delivers your message to our mailbox and retains nothing. | 24 months in the mailbox, then deleted |
| Marketing opt-outs (suppression list) | Our own database | Kept indefinitely - deliberately. We must keep a record of your opt-out in order to honour it. Deleting it would mean we could contact you again. |
| Business contact records | Our own systems, not this website | Duration of the relationship, plus 24 months |
| Server logs and website analytics | Our hosting provider, aggregated | Per that provider's retention (see sub-processors) |
| Accounting and tax records | Our finance systems | 5 years (Singapore Companies Act) |
If you want anything above erased sooner, email privacy@heossi.com and we will action it - except the suppression record, which exists solely to protect you and which we will not delete unless you ask us to re-contact you.
Marketing Communications
We send business-to-business communications only to business addresses, and only where the subject matter is relevant to the recipient's professional role. In Singapore this relies on the business-contact-information provisions of the PDPA; elsewhere it relies on the equivalent lawful basis for that jurisdiction.
- Every message identifies us, names our registered entity and UEN, carries our postal address, and includes a working one-click unsubscribe.
- An opt-out is honoured immediately and permanently, and applies across every HEOSSI solution - not just the one that contacted you.
- We do not send unsolicited commercial email into jurisdictions that require prior consent for it - including Germany and Austria (UWG §7) and Canada (CASL). This is enforced in our sending systems, not left to discretion.
- Marketing is never sent from the domain that carries our transactional mail (login codes, receipts), so a marketing complaint can never affect delivery of security-critical messages to you.
United States State Privacy Rights (CCPA/CPRA and equivalents)
We do not sell your personal information, and we do not share it for cross-context behavioural advertising - as those terms are defined by the California Consumer Privacy Act (as amended by the CPRA). We have not done so in the preceding 12 months.
If you are a resident of California - or of another US state with comparable legislation, including Virginia, Colorado, Connecticut, Utah and Texas - you have the right to know what personal information we hold, to request its deletion or correction, to obtain a portable copy, to limit the use of sensitive personal information, and to not be discriminated against for exercising any of these rights.
To exercise any of them, email privacy@heossi.com. You may use an authorised agent. We will verify your identity before acting, and we will respond within the period the applicable statute requires.
Children
Our business services and website are not directed to children under 18, and we do not knowingly solicit personal data from them. A parent or guardian who believes a child has provided personal data should contact privacy@heossi.com so we can assess and delete it where required. Research involving minors requires a separately approved protocol, appropriate consent or assent, safeguards, and all legally required ethics and regulatory approvals.
Contact Form Attachments
Public contact-form uploads are disabled. The production portal has no connected file-upload store and did not retain attachments through that endpoint. If a document is necessary, HEOSSI will arrange an appropriate transfer channel after verifying the enquiry. Never send confidential, classified, privileged, special-category, payment-card, credential, private-key, or other sensitive material through an unapproved channel.
Contact & Complaints
For questions about this Privacy Policy or to exercise your data protection rights:
Data Protection Officer
Email: privacy@heossi.com
Address: 552 Ang Mo Kio Avenue 10, Singapore 560552
If you are not satisfied with our response, you may refer the matter to:
- Personal Data Protection Commission (Singapore)
- Information Commissioner's Office (UK)
- Relevant EU Data Protection Authority
- California Attorney General (for CCPA matters)