Home/Privacy
LegalPrivacy & PDPA notice
How we handle personal data, written in plain English rather than in the usual fog.
Last updated: 14 August 2026
Template — have this reviewed. This is a reasonable starting point drafted to reflect PDPA expectations, but it is not legal advice. Before you go live, have a Singapore-qualified practitioner review it against how your business actually operates, and update the bracketed fields.
1. Who we are
One Degree AI is an IT solutions provider based in Singapore. In this notice, "we", "us" and "our" mean One Degree AI.
We are responsible for the personal data we collect and use, in accordance with the Personal Data Protection Act 2012 ("PDPA").
2. Our Data Protection Officer
As required under the PDPA, we have appointed a Data Protection Officer. You can reach them at:
- Name / role
- The Data Protection Officer
- dpo@onedegreeai.com
- Post
- By email in the first instance; postal address supplied on request.
3. What we collect
We keep this deliberately small. Depending on how you interact with us:
- Enquiries. Name, company, email address, phone number, and whatever you choose to write in the message field.
- Clients. Contact details for the people we work with, billing details, and the contractual documents for the engagement.
- Client system data. Delivering managed IT support means we hold administrative access to your systems, and during support or security testing we may encounter personal data belonging to your customers or staff. We handle this under a separate written agreement — see section 8.
- Website usage. Standard server logs (IP address, browser type, pages requested, timestamp) kept by our hosting provider for security and reliability purposes.
We do not knowingly collect data from anyone under 18, and we do not buy contact lists.
4. Why we use it
- To respond to your enquiry and prepare a proposal
- To deliver the services you've engaged us for
- To invoice you and keep the accounting records the law requires
- To meet our legal, regulatory and professional obligations
- To keep our own systems secure
We do not use your details for marketing unless you have specifically asked us to, and we do not sell or rent personal data to anyone. Ever.
5. Consent and withdrawal
When you submit the contact form, you consent to us using your details to respond. You can withdraw that consent at any time by emailing dpo@onedegreeai.com. We'll act on it promptly and confirm once it's done. Withdrawing consent may mean we can no longer provide a service you've asked for, and we'll tell you if that's the case.
Some records — invoices and engagement documentation, for instance — we are legally required to retain even after you withdraw consent for other purposes.
6. Who we share it with
We share personal data only where necessary, and only with:
- Service providers who support our operations — website hosting, email, accounting and secure file transfer. Each is bound by contract to protect the data and use it only on our instructions.
- Professional advisers such as our accountants or lawyers, where required.
- Authorities, where we are legally obliged to disclose.
Where a provider stores data outside Singapore, we take steps to ensure a comparable standard of protection as required by the PDPA's transfer limitation obligation. Support and security testing are delivered from Singapore — we do not subcontract helpdesk or testing work to an offshore delivery centre.
7. How long we keep it
- Enquiries
- Up to 12 months from last contact if they don't become an engagement
- Engagement evidence
- Destroyed on an agreed schedule after the engagement closes — typically 90 days unless you ask for something different
- Client documentation
- Held for the duration of the agreement and handed over to you on termination
- Reports
- Retained for the period agreed in your contract, so we can support you on a retest or dispute
- Financial records
- As required by Singapore law
- Server logs
- Typically 30 days
8. Client engagements
Delivering managed IT support or security testing means we may access, and sometimes process, personal data belonging to your customers or employees. In that context we act as a data intermediary processing data on your behalf, under a written agreement that covers scope, handling, retention and destruction.
Our standing practice:
- We access client systems only for agreed support, maintenance or testing purposes, and that access is logged
- We collect the minimum evidence needed to demonstrate a finding, and stop there
- We do not extract bulk datasets to prove a point
- Evidence is encrypted at rest and in transit, and access is limited to the consultant on the engagement
- Personal data appearing in reports is redacted or masked unless you ask otherwise
- Nothing from a client engagement is used to train any system, ours or anyone else's
9. How we protect it
We would be poor advertisements for our own services if we handled this badly. We use encryption in transit and at rest, multi-factor authentication on all business accounts, least-privilege access, endpoint protection, logging, and a documented incident response plan that we actually rehearse.
No system is perfectly secure — anyone who tells you otherwise is selling something. If a data breach occurs that is likely to result in significant harm or is of significant scale, we will notify the PDPC and affected individuals in accordance with the PDPA.
10. Your rights
Under the PDPA you may ask us to:
- Access the personal data we hold about you, and information about how it has been used or disclosed in the past year
- Correct anything inaccurate or incomplete
- Withdraw consent for any purpose you previously agreed to
Email dpo@onedegreeai.com. We'll acknowledge within 5 working days and respond substantively within 30 days, or tell you when to expect a response if it will take longer. A reasonable fee may apply to access requests, and we'll tell you before doing any chargeable work.
If you're not satisfied with how we've handled things, you may raise the matter with the Personal Data Protection Commission of Singapore.
11. Cookies
This website sets no advertising or tracking cookies. We don't run Google Analytics, advertising pixels, or third-party trackers. Our hosting provider keeps standard access logs for security and reliability.
12. Changes
We'll update this notice when our practices change and revise the date at the top. For material changes affecting how we use your data, we'll contact you directly where we can.
13. Contact
Questions about this notice or about how we handle your data: dpo@onedegreeai.com.