LEGAL
Privacy Policy
Last updated July 23, 2026
1. Overview
This Privacy Policy explains how STIV Pte. Ltd. (Singapore UEN 202630466E), registered at 50 Raffles Place #30-00, Singapore Land Towers, Singapore 048623 ("STIV," "we," "us") collects, uses, discloses, and protects information in connection with our website and software (the "Service"), in accordance with Singapore's Personal Data Protection Act 2012, as amended (the "PDPA"). By using the Service, you agree to the practices described here.
2. Controller & Processor Roles
For account, billing, and website usage data, STIV acts as the data controller. For Customer Data you submit to a division's software or STIV Unified (e.g. documents, records, and communications processed through your organization's integrations), STIV acts as a data processor on your organization's behalf as controller. Enterprise customers may request a Data Processing Agreement (DPA) governing this relationship by contacting us below.
3. Information We Collect
We collect information in the following ways:
- Information you provide — account details, billing information, and content you submit when using a division's software (e.g. documents, messages, records connected through integrations you authorize).
- Information collected automatically — usage data, device and browser information, and log data generated as you interact with the Service.
- Information from integrations — data from third-party systems (such as your CRM, accounting, or email tools) that you explicitly connect to STIV.
4. How We Use Information
- To operate, maintain, and improve the Service.
- To power the software's underlying AI systems within the scope you configure for each division.
- To provide support and respond to your requests.
- To detect, investigate, and prevent misuse or fraud.
- To comply with legal obligations.
5. AI Systems & Model Training
Customer Data processed by a division's software or STIV Unified is used solely to provide the Service to your organization. We do not use Customer Data to train foundation models — ours or our AI subprocessors' — and our subprocessor agreements require the same commitment from them. Customer Data is never used to improve models for the benefit of other customers or the public.
6. Data Sharing & Disclosure
We do not sell your information. We share information only with:
- Subprocessors who help us operate the Service, under contractual confidentiality, security, and (where applicable) data processing obligations (see our Subprocessors page).
- Authorities, where required by law or valid legal process.
- A successor entity in the event of a merger, acquisition, or asset sale, subject to the same protections described here.
7. Data Security & Breach Notification
Data is encrypted in transit and at rest. Access within STIV is scoped by role, and access by each division's software is limited to what that division requires. Every consequential action is logged and auditable. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
Where a data breach is likely to result in significant harm, we will notify Singapore's Personal Data Protection Commission (PDPC) within 3 calendar days as required under the PDPA, and notify affected individuals without undue delay.
8. Data Retention
We retain information according to the following schedule:
- Account and billing records: for the duration of your subscription, plus the period required by applicable tax and accounting law.
- Usage and log data: up to 12 months.
- Customer Data processed by a division's software: retained per your organization's configured retention settings, and deleted within 30 days of contract termination unless a longer period is legally required.
You may request deletion of your data subject to any retention required by law or active contractual obligations.
9. Your Rights
Under the PDPA and, where applicable, other data protection laws, you may have rights to access, correct, export, or delete your personal information, and to withdraw consent or object to certain processing. To exercise these rights, contact us using the details below; we aim to respond to access and correction requests within 30 days. If you are not satisfied with our response, you may lodge a complaint with the PDPC (pdpc.gov.sg) or your local data protection authority.
10. Cookies & Tracking
We use cookies and similar technologies to operate the Service, remember preferences, and understand usage, including third-party analytics cookies (see our Subprocessors page). Where required by law, we will request your consent before setting non-essential cookies. You can control cookies through your browser settings at any time.
11. International Transfers
STIV is based in Singapore. Information may be processed by subprocessors located outside Singapore, including in the United States and India, which may have different data protection laws. Where required by the PDPA's Transfer Limitation obligation, we put in place contractual safeguards comparable to Singapore's data protection standards before transferring personal data outside Singapore.
12. Data Protection Officer
Our Data Protection Officer can be reached at privacy@iamstivai.com.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by an updated "Last updated" date above.
14. Contact Us
Questions about this Privacy Policy can be sent to privacy@iamstivai.com.