Legal

Privacy Policy

Last updated:

DotCo Pte. Ltd. is committed to protecting your personal data. This Privacy Policy explains what data we collect, why we collect it, how we use and protect it, and your rights in relation to it. It applies to our website at dotcoai.com and our AI-native GRC platform.

1. Who We Are

DotCoAi Pte. Ltd. ("DotCoAi", "we", "us", "our") is a technology company incorporated in Singapore. We operate the DotCoAi AI-native Governance, Risk and Compliance (GRC) platform and the website at dotcoai.com.

For the purposes of applicable data protection law, DotCoAi is the data controller in respect of personal data collected through our website and platform, unless otherwise stated in a Data Processing Agreement with a Customer.

2. Personal Data We Collect

We collect personal data in the following ways:

Data you provide directly — when you register for an account, complete a contact or demo-request form, subscribe to our newsletter, or communicate with us. This may include your name, work email address, job title, company name, and phone number.

Data collected automatically — when you visit our website or use the platform, we may collect IP address, browser type and version, operating system, pages visited, time and date of visits, and referring URLs via cookies and similar technologies.

Customer Data — data that Customers and their authorised Users upload or generate within the platform in the course of using our Services. DotCoAi processes this data as a data processor on behalf of the Customer.

Third-party sources — we may receive information about you from publicly available sources, business partners, or analytics providers, which we combine with data we already hold.

3. How We Use Your Data

We use personal data for the following purposes:

  • To provide, operate, and improve our platform and Services;
  • To respond to enquiries, support requests, and demo bookings;
  • To send transactional communications (account confirmations, security alerts);
  • To send marketing communications where you have given consent or we have a legitimate interest;
  • To analyse usage patterns and improve user experience;
  • To comply with legal obligations and enforce our Terms of Service;
  • To detect, prevent, and investigate fraud or security incidents.

5. Cookies and Tracking Technologies

We use cookies and similar technologies (pixels, local storage) to operate our website, remember your preferences, and analyse traffic. Cookies fall into the following categories:

  • Strictly necessary — required for the website to function; cannot be disabled.
  • Analytics — help us understand how visitors interact with our site (e.g. page views, session duration). We use aggregated, anonymised data only.
  • Marketing — used to deliver relevant advertising and track campaign effectiveness. Only activated with your consent.

You can manage cookie preferences through our cookie consent banner or your browser settings. Disabling certain cookies may affect site functionality.

6. Sharing Your Data

We do not sell your personal data. We may share it with:

Service providers — third-party vendors who process data on our behalf (cloud hosting, email delivery, analytics, CRM). All processors are bound by data processing agreements.

Business partners — with your consent, we may share data with trusted partners to provide joint offerings.

Legal and regulatory authorities — where required by law, court order, or to protect the rights, property, or safety of DotCoAi, our customers, or the public.

Corporate transactions — in connection with a merger, acquisition, or sale of assets, subject to the acquirer honouring this Privacy Policy.

7. International Data Transfers

DotCoAi is headquartered in Singapore. Your data may be transferred to and processed in countries outside your country of residence, including Singapore and other jurisdictions where our service providers operate.

Where we transfer personal data from the European Economic Area (EEA) or United Kingdom to a country not deemed adequate by the relevant authority, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) or equivalent mechanisms.

8. Data Retention

We retain personal data for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements.

Account data is retained for the duration of the subscription and for up to 3 years thereafter unless a longer period is required by law. Customer Data uploaded to the platform is retained for 30 days following contract termination, after which it is securely deleted.

Marketing contact data is retained until you unsubscribe or request deletion. Website analytics data is retained in aggregated form for up to 26 months.

9. Your Rights

Depending on your jurisdiction, you may have the following rights in relation to your personal data:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — request correction of inaccurate or incomplete data.
  • Erasure — request deletion of your personal data in certain circumstances.
  • Restriction — request that we restrict processing of your data.
  • Portability — receive your data in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interests or for direct marketing.
  • Withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior processing.

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.

10. Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, or destruction. These include encryption in transit and at rest, access controls, regular security assessments, and employee training.

No method of transmission over the internet is 100% secure. If you believe your data has been compromised, contact us immediately at [email protected].

11. Children's Privacy

Our Services are not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us and we will delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated by email or via a prominent notice on our website at least 14 days before taking effect. The "Last updated" date at the top of this page reflects the most recent revision.

Continued use of our Services after the effective date of any change constitutes your acceptance of the updated policy.

Contact Our Privacy Team

For any privacy-related questions, data subject requests, or to reach our Data Protection Officer, please contact us at [email protected] or write to DotCoAi Pte. Ltd., Singapore.