Privacy Policy
Version 1.5 · effective 2026-09-14
1. Who we are, and which role we are in
Straits Compliance provides AML/CFT and ACRA compliance software to registered corporate service providers in Singapore.
For almost all personal data in this product we are a data intermediary, not the organisation. A corporate service provider uses the product to conduct customer due diligence on its own clients. That firm decides what is collected and why; we process it on their instructions under the Data Processing Addendum. If you are a client of such a firm and want to know what is held about you, the firm is the organisation you should ask — not us — and we will assist them in answering.
We are the organisation for a narrower set of data: the account details of the people who actually use the product, and the ordinary records of running a business.
2. What we hold as the organisation
- Account data — name, work email address, the firm you belong to and your access level within it.
- Authentication records — sign-in events and password reset requests, which exist so an account can be recovered and so unauthorised access can be investigated.
- Audit records — an append-only trail of actions taken in the product, attributed to the person who took them. These cannot be edited or deleted, by design and by database permission, because a compliance audit trail that can be altered is not one.
We do not sell personal data, we do not use it for advertising, and we do not use customer content to train any model of our own.
3. Where it is stored
Uploaded documents, extracted personal data, screening results, audit stamps and backups are stored in the Singapore region (ap-southeast-1), and the application that serves the product executes in that region.
Document extraction is the exception, and we say so rather than rounding it off. Extracting data from an uploaded identity document involves sending that document's content to a third-party AI service which is not located in Singapore. The specific provider, its retention terms, and whether content is used for model training are recorded in DPA section 7.2, which states the current position precisely. We would rather name an unresolved question than publish a residency claim we cannot stand behind.
4. Sub-processors
We use third parties to run the product. The ones in the path of personal data today are:
- Our hosting and database platform, in the Singapore region, which stores everything described in section 3.
- An AI extraction provider, which receives uploaded document content. Named and qualified in DPA section 7.2.
- An email provider, which receives recipient addresses and message content for sign-in, password reset, invitation and data protection officer notification emails. No customer content is sent by email — no identity documents, no extracted data, no screening results, no case files.
- A screening data provider, where a firm enables one. Only the minimum query terms necessary for the search are transmitted, and the provider is named in that firm's own configuration.
We do not yet publish a consolidated list naming each sub-processor and its location. That is a gap and naming it is more useful than a list we would not keep current. Ask us and we will tell you who they are — support@straitscompliance.sg. We will publish the list once we can commit to keeping it accurate.
5. How long we keep it
Customer due diligence records are retained for five years from the end of the firm's relationship with its client, because CSP record-keeping obligations require it. That clock is the firm's, not ours, and the product enforces it rather than letting a record be deleted early.
Account and authentication data is kept while the account is active. Audit records are append-only and are retained for as long as the underlying compliance obligation requires.
6. Your rights, and how to exercise them
Under the Personal Data Protection Act 2012 you may ask for access to personal data we hold about you and for correction of it. If you are a client of a corporate service provider that uses this product, address that request to that firm, which is the organisation responsible for it.
For data we hold as the organisation — your account with us — write to our Data Protection Officer below. We will respond as completely as we reasonably can. If we cannot respond within 30 days we will write within that time to tell you when we will.
7. Data Protection Officer
Our Data Protection Officer is the individual designated under PDPA section 11(3) as responsible for our compliance with the Act.
Designating an individual does not relieve us of any obligation under the Act — section 11(6) says so expressly, and we mention it because it is the part organisations most often get wrong about their own duties.
8. Changes to this policy
This policy is versioned alongside our Terms and our Data Processing Addendum. Where a change withdraws or narrows something we previously said, we will say that it does, rather than quietly restating it — the DPA's own section 7.2 records three such changes for exactly that reason.