Legal Singapore PDPA

Privacy policy

What we collect, why we collect it, who else ever sees it, and how to make us delete it. Written to be read rather than to be survived.

In short

  • We collect the minimum. Contact details you give us, ordinary web analytics, and whatever a client engagement requires.
  • We never sell it. No list trading, no data brokering.
  • You can withdraw consent at any time by emailing us, and ask what we hold, correct it, or have it deleted.
  • Singapore PDPA governs this. Unresolved complaints can go to the PDPC.

Most privacy policies are written to be unreadable. This one is meant to actually answer the question, so it is short, in plain English, and organised so you can jump to the part you care about.

01 · Policy

Who this policy covers

This policy explains how Big Wall Digital (“we”, “us”) collects, uses, discloses and protects personal data. It applies to this website, to enquiries you send us, and to the personal data we handle while delivering services to clients.

We are based at Paya Lebar Square, Singapore, and we handle personal data in line with the Singapore Personal Data Protection Act 2012 (PDPA). Where we act for clients whose own users are in other jurisdictions, additional obligations may apply and are handled in the relevant client agreement.

02 · Policy

What we collect

We try to collect as little as will do the job. In practice that falls into three groups.

  • Information you give us. Name, email address, phone number, company name, website address, and whatever you choose to write in an enquiry or consultation booking.
  • Information we collect automatically. IP address, browser and device type, referring page, pages viewed and time on page, the ordinary web analytics record.
  • Information from client engagements. Where a client grants us access to their analytics, advertising, search console or CMS accounts, we necessarily see the data those systems hold. We treat it as the client’s data, not ours.

We do not knowingly collect personal data from anyone under 13, and we do not collect special categories of data such as health or biometric information.

03 · Policy

How we use it

  • To reply to your enquiry and arrange a consultation.
  • To provide, manage and improve the services a client has engaged us for.
  • To send updates or marketing you have asked to receive, and only then.
  • To understand how this website is used, so we can make it better.
  • To meet legal, accounting and regulatory obligations, including grant administration where a client is applying for PSG or EDG support.

We do not sell personal data. We do not trade contact lists.

04 · Policy

Consent and withdrawal

Under the PDPA we rely on your consent, or on an exception permitted by the Act, to collect and use personal data. Submitting a form or booking a consultation is your consent for us to contact you about that enquiry.

You can withdraw consent at any time by writing to us at [email protected]. We will act on the request within a reasonable period and tell you if withdrawal means we can no longer provide part of a service. Withdrawal does not affect anything done lawfully before the request.

05 · Policy

Cookies and analytics

This site uses cookies and similar technologies for two purposes: keeping the site working, and measuring how it is used. Analytics tell us which pages are read and where people leave, they are not used to identify you personally.

Most browsers let you refuse or delete cookies in their settings. Blocking them will not break this site, though some conveniences will stop working.

06 · Policy

Who we share it with

We disclose personal data only where there is a reason to, and only to these groups:

  • Service providers who process data on our behalf, hosting, email, analytics, CRM and scheduling tools, under obligations of confidentiality.
  • Government agencies where a client is applying for a grant and the application requires it, such as Enterprise Singapore and IMDA.
  • Professional advisers such as accountants and lawyers, where necessary.
  • Authorities, where we are required to by law.

07 · Policy

Transfers outside Singapore

Some of the tools we use store data outside Singapore. Where personal data is transferred abroad, we take reasonable steps to satisfy ourselves that the recipient is bound to a standard of protection comparable to the PDPA.

08 · Policy

How long we keep it

We keep personal data only as long as it serves the purpose it was collected for, or as long as the law requires. Enquiries that do not become engagements are cleared out periodically. Records tied to a client engagement or a grant application are kept for the retention period those obligations set.

09 · Policy

Your rights

Under the PDPA you may ask us to:

  • Tell you what personal data we hold about you and how it has been used or disclosed in the past year.
  • Correct anything that is inaccurate or incomplete.
  • Withdraw your consent to further use.
  • Delete data we no longer have a legal or business reason to keep.

Write to [email protected] and we will respond as soon as we reasonably can. We may need to verify your identity before acting, and a reasonable fee may apply to an access request, as the Act permits.

10 · Policy

Security

We apply reasonable administrative and technical measures to protect personal data against unauthorised access, loss or misuse, access controls, encryption in transit, and limiting access to the people who need it.

No method of transmission or storage is completely secure, and we will not claim otherwise. If a data breach occurs that is likely to result in significant harm, we will notify affected individuals and the Personal Data Protection Commission as the Act requires.

11 · Policy

Third-party sites

This site links to sites we do not control, including client websites, LinkedIn and government portals such as GoBusiness. Their privacy practices are their own, and we would encourage you to read them.

12 · Policy

Changes to this policy

We may update this policy as our services or the law change. The revision date at the top of this page always reflects the current version. Material changes will be flagged on this page.

13 · Policy

Contact us

Questions, requests or complaints about personal data can go to our Data Protection Officer:

If you are not satisfied with our response, you may raise the matter with the Personal Data Protection Commission (PDPC) of Singapore.

Data requests

Want to know what we hold?

Ask, and we will tell you. One email is enough; you do not need to quote a clause number.