Privacy Policy
Last updated · 7 Oct 2026
This policy explains how Singfung Group collects, uses, shares and protects your personal data. We process personal data under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, and follow local data protection laws where we provide services in other regions.
01Who is responsible
For personal data relating to the website, accounts, billing and marketing, the controller is Singfung Group Limited, registered in England and Wales. Group companies that provide services in a particular region may be joint controllers for billing and customer relationships in that region.
For Customer Content you store in our cloud services, you are the controller and we act as your processor, following your instructions under our Data Processing Addendum.
02What we collect
- Information you give us: name, email, phone number, company, billing address, tax ID, and what you write in forms, tickets and job applications.
- Information from using the services: sign-in records, IP addresses, console activity, resource usage and billing data.
- Payment information: handled directly by payment providers such as Stripe; we keep only the payment method type, last four digits and the transaction result, never the full card number.
- Website usage: essential cookies and anonymised visit statistics.
03Why we use it and our legal basis
- Providing and managing the services, and processing orders and invoices — performance of a contract.
- Account security and preventing fraud and abuse — our legitimate interests.
- Issuing invoices, keeping accounting records and responding to authorities — legal obligation.
- Answering enquiries and providing support — performance of a contract or your request.
- Product news and marketing — your consent, which you can withdraw at any time.
- Recruitment — handling your application and, with your consent, keeping it for future roles.
04Who we share it with
We do not sell personal data. We share it only:
- with the group company that provides the services you order;
- with service providers that help us operate — such as payments (Stripe, Wise), email (Fastmail) and data-centre providers — who may process data only on our instructions (our live chat system is hosted and run by us);
- where the law, a court order, or protecting the rights of us, our customers or the public requires it;
- in a merger, acquisition or asset transfer, provided the recipient gives equivalent protection.
05International transfers
Our teams and services are located in the UK, the EU, the US, Hong Kong, Singapore and Mainland China. When personal data leaves the UK or the European Economic Area, we protect it with the UK International Data Transfer Agreement, the EU Standard Contractual Clauses or another lawful mechanism.
In Mainland China regions, cross-border provision of personal information follows the Personal Information Protection Law, including separate consent and the required procedures where applicable. Hong Kong follows the Personal Data (Privacy) Ordinance, Singapore the Personal Data Protection Act (PDPA), and our German region the EU GDPR.
06How long we keep it
- Account data: while your account is open and for two years after it closes, to handle disputes and billing questions.
- Invoices and transaction records: as tax and accounting law requires, usually six years.
- Sign-in and security logs: one year.
- Contact forms and enquiries: two years after our last exchange.
- Job applications: six months after the process ends, or two years with your consent.
07Your rights
Depending on the law that applies, you can: access and get a copy of your personal data; correct inaccurate data; ask us to delete it; restrict or object to processing; ask for data portability; and withdraw consent at any time (without affecting earlier processing). Send requests through the contact form and we will reply within one month, after confirming your identity where needed.
If you are unhappy with how we handle your data, you can complain to the UK Information Commissioner’s Office (ICO) or the data protection authority where you live.
08Cookies
The website uses only cookies needed for it to work — such as language preference, a signed-in hint and security protection — and no third-party advertising trackers. Visit statistics are anonymised. The live chat window uses a cookie to remember your conversation; closing it does not affect the rest of the site. To route you to the right support centre, the site reads your browser’s time zone setting; this is not stored.
09Security
We protect personal data with encryption in transit, access controls, least privilege, audit logging and regular security reviews. If a personal data breach is likely to put you at risk, we will notify the relevant authority and the people affected as the law requires.
10Children
The services are not directed at anyone under eighteen, and we do not knowingly collect children’s personal data.
11Changes
We may update this policy. We will tell you about material changes by email or on the website before they take effect.
12Contact
For questions about this policy or your personal data, use the contact form on the website and mention “personal data” — we will pass it to the person responsible.