Skip to content
PAGAR & CO.A GATEWAY FOR WHAT’S NEXT.

Legal · Privacy

Privacy Notice

This notice explains how Pagar & Co. — the service operated by HumanLed AI Pte. Ltd. — will collect, use, disclose and look after personal data, and the choices and rights available to the individuals whose data we hold. It is written to follow the obligations of Singapore’s Personal Data Protection Act 2012 (the “PDPA”).

The sections below are structured to the PDPA. Each sets out, in plain English, what it will cover. The binding wording is still being prepared and is marked as pending throughout.

Draft — pending legal review

This document is a working draft. It has not yet been reviewed by a legal practitioner and is not yet in force. The headings and descriptions below set out what each section will cover; the operative wording is still to be drafted and is marked [PENDING LEGAL REVIEW]. Nothing here is legal advice, and nothing here should be relied upon until the notice is finalised and published as being in effect.

Last updated 7 September 2026 · Status: draft, not in force

About this notice and the PDPA

Who we are, which entity is the organisation responsible for your personal data under the PDPA, and the scope of this notice — the website, the application process, the client portal, and the ongoing registered-office and mail-handling service. This section will also define the key terms used below, including “personal data”.

We do not make any statement here about corporate status, licence, approval or regulatory standing; the operating entity’s exact description is being confirmed separately.

[Pending legal review — F-10]

Operative scope, defined terms and the identity of the responsible organisation, to be drafted and confirmed.

Personal data we collect

The categories of personal data we collect, and where each comes from — what you give us, what is generated as you use the service, and what we receive from third parties such as screening sources.

  • Contact and account details — name, business role, email address, telephone number, and correspondence.
  • Application and company details — the entities you act for and the information needed to assess an application.
  • Identity and due-diligence documents — collected to meet corporate service provider due-diligence duties, and stored privately with restricted access.
  • Mail and parcel records — including the sender details and photographs of items received at the address on your behalf.
  • Financial and billing records — kept for accounting, tax and dispute purposes.
  • Website and technical data — limited information about how the site and portal are used (see the cookies section).

Identity documents

Identity documents are collected specifically for corporate service provider due-diligence and record-keeping. They are held in private, access-controlled storage, separated from operational data, and are not used for any purpose beyond due-diligence, verification and the records we are required to keep.

[Pending legal review — F-05]

The definitive list of data categories, and the confirmed treatment of national identity numbers, to be settled with the appointed reviewer.

Purposes of collection and use

The purposes for which we collect and use personal data, so that each category of data is tied to a stated reason (PDPA Purpose Limitation Obligation, s18). We collect the minimum needed for each purpose and do not ask for information at a point where it could not affect the outcome.

  • Assessing and processing applications, and carrying out due-diligence and screening.
  • Providing the registered-office address and handling mail and parcels.
  • Operating your account, communicating with you, and providing support.
  • Billing, accounting, tax and the management of any dispute.
  • Meeting legal, regulatory and record-keeping obligations.
  • Maintaining the security and integrity of the service.

[Pending legal review]

The full statement of notified purposes and the legal bases relied on, to be drafted and reconciled against actual use.

Disclosure to third parties

When, and to whom, personal data may be disclosed — for example to service providers acting on our behalf, to banks or counterparties where you have asked us to act, and to regulators, law enforcement or courts where we are required or permitted by law to do so. It will also state that we require those acting for us to protect personal data to a comparable standard.

[Pending legal review]

The categories of recipients and the conditions for each disclosure, to be drafted.

Use of AI and overseas transfer

Some administrative processing may be assisted by artificial intelligence — for example, reading and organising submitted documents, classifying incoming mail, or preparing summaries for a human reviewer. AI assists; it does not make final decisions about an application, and a person remains responsible for every outcome.

AI-assisted processing may involve a provider located outside Singapore. Where that is the case, any transfer of personal data outside Singapore is governed by a transfer assessment carried out under the PDPA Transfer Limitation Obligation (s26) before the transfer takes place. Personal data is minimised or redacted before external processing, and identity documents are excluded from external AI processing by default.

This section will name the provider and processing region, and describe the safeguards relied on, once the assessment is finalised — without overstating them.

[Pending legal review — F-04]

The overseas-transfer assessment, the named AI provider and processing region, and the specific transfer safeguard, to be completed and stated here before any such transfer of personal data occurs.

Protection and security

The measures we take to protect personal data against unauthorised access, use or loss (PDPA Protection Obligation, s24) — access controls, private storage for sensitive documents, encryption in transit, minimised storage of identity numbers, audit logging, and the separation of identity data from operational data. It will also outline how a suspected data breach is handled.

[Pending legal review — F-09]

The described security measures and the written data-breach response procedure, to be confirmed. No specific security claim should be relied upon until this section is finalised.

Retention of personal data

How long personal data is kept (PDPA Retention Limitation Obligation, s25). The principle we follow: personal data is anonymised or destroyed once the purpose it was collected for is served and there is no remaining legal or business need to keep it. Where a record must be kept for a legal, accounting or regulatory purpose, we keep that record but remove or anonymise the identity attached to it — a data item that is merely hidden or archived is still being retained, and that is not what we do.

Specific retention periods for each class of data — due-diligence documents, application records, mail photographs, invoices, waitlist entries and logs — will be set out in a retention schedule and are not yet finalised.

[Pending legal review — F-06]

The retention schedule and the specific retention period for each class of data, to be set and reconciled with the applicable record-keeping requirements. Periods are not yet fixed.

Your access and correction rights

Your right to ask for a copy of the personal data we hold about you and information about how it has been used (PDPA s21), and your right to ask us to correct it (s22). It will explain how to make a request, what we may need to verify your identity, any circumstances in which a request cannot be met in full, and our expectation of responding within 30 days in line with PDPA requirements.

You will also be able to make these requests from within your account, where the options to request a copy of your data and to correct it are provided.

[Pending legal review]

The request procedure, verification steps, any applicable exceptions and fees, and the sign-off workflow, to be confirmed.

Withdrawing your consent

How to withdraw a consent you have given — for example consent to marketing — and what the effect of withdrawal is. It will explain that we will act on a withdrawal within a reasonable time, and that withdrawing consent needed to provide the service may mean we can no longer provide part or all of it. Withdrawal does not affect data we are required by law to retain.

[Pending legal review]

The withdrawal mechanism and the consequences of withdrawal, to be drafted.

Data Protection Officer

The business contact for our Data Protection Officer, who is responsible for ensuring compliance with the PDPA and is the point of contact for any question or request relating to personal data (PDPA Accountability Obligation, ss11–12).

The DPO is a distinct role and may use a dedicated contact address. It is deliberately not shown as our general enquiries address until confirmed, so that a request reaches the right person.

[Pending legal review — F-08]

The named Data Protection Officer and their published business contact, to be confirmed. Until then, please use the general enquiries channel on the contact page and mark your message for the attention of the DPO.

Complaints and the PDPC

How to raise a concern about how we handle personal data, and your right to refer a matter to the Personal Data Protection Commission (PDPC) in Singapore if you are not satisfied with our response. It will ask that you contact our DPO first so we have the opportunity to put things right.

[Pending legal review]

The complaints procedure and the current PDPC referral details, to be confirmed.

Updates to this notice

How and when this notice may change, how we will make a revised version available, and how the “last updated” date should be read. Material changes will be communicated in an appropriate way.

[Pending legal review]

The change and notification mechanism, to be drafted.

Cookies and similar technologies

The cookies and similar technologies used on this website and in the portal, what each is for — strictly necessary, functional or analytics — and how you can manage your preferences. Our approach is to keep non-essential cookies off by default and to ask before setting them.

[Pending legal review]

The cookie inventory, the consent and preference mechanism, and the retention period for any analytics data, to be confirmed.

This notice is a working draft prepared during the build of Pagar & Co.. It has not been reviewed by a legal practitioner and is not yet in force. It names the statutes and PDPC obligations it is built around so that they can be checked. It is not legal advice; please confirm the position with a qualified practitioner before relying on it.

General enquiries: hello@humanledai.sg. A dedicated Data Protection Officer contact will be published once confirmed.