Legal

Privacy Policy

Last Updated: 20 August 2026

ALLPS Consultancy LLP (UEN: [UEN]) ("ALLPS", "we", "us" or "our") is committed to protecting the personal data of individuals who interact with us. This Privacy Policy sets out how we collect, use, disclose, process, store, protect and transfer personal data in connection with our website, services and business activities. It is issued in compliance with the Singapore Personal Data Protection Act 2012 (No. 26 of 2012), as amended by the Personal Data Protection (Amendment) Act 2020 ("PDPA"), and, where applicable, the European Union General Data Protection Regulation (EU) 2016/679 ("GDPR") and other applicable data protection laws. By engaging with our website or services, you acknowledge that you have read and understood this Privacy Policy.

1.

Scope

This Privacy Policy applies to personal data collected, used or disclosed by ALLPS in connection with: our corporate website and digital platforms; consultancy, advisory and professional services; supply chain and AI consultancy; corporate training and capability development programmes; audit preparation and compliance consultancy; association management and secretariat services; the ALLPS Association Management Platform ("AMP"); events, workshops and professional programmes; ASEAN market entry and business development activities; business enquiries, partnerships and marketing; and any other services provided by ALLPS. Where a specific service, platform or engagement is governed by additional data processing terms, those terms apply alongside this Privacy Policy.

2.

Personal Data We Collect

Depending on your interaction with ALLPS, we may collect: identification and contact information (name, job title, company or organisation, email address, telephone number, country or location); professional and business information; training, event and programme registration information; association membership and certification records (where applicable); billing, payment and transaction information; business enquiries and areas of professional interest; communications and correspondence with ALLPS; information submitted through website forms or digital platforms; technical information (IP address, browser type, device identifiers, operating system); website usage, analytics and cookie data; and other information voluntarily provided to us. We collect only personal data that is reasonably necessary for the identified purpose, consistent with the data minimisation principle under the PDPA and GDPR Article 5(1)(c).

3.

How We Collect Personal Data

We collect personal data directly from you when you visit our website; submit an online enquiry or contact form; request a consultation or proposal; engage our professional services; register for training, events or programmes; use an ALLPS technology platform; interact with an association managed by ALLPS; participate in surveys, assessments or workshops; subscribe to communications; or enter into a business relationship with us. We may also collect personal data indirectly from clients, associations, business partners, referrals, publicly available sources, or other third parties where permitted by applicable law. Where personal data is collected indirectly, we will take reasonable steps to ensure that the individual is notified of the collection and its purposes, to the extent required by law.

4.

Purposes of Collection, Use and Disclosure

ALLPS collects, uses and discloses personal data for purposes including: responding to enquiries and providing requested information; providing consultancy, advisory and professional services; delivering corporate training and capability development; administering training registrations, attendance and certification records; providing audit preparation and compliance consultancy; managing association operations, membership administration and secretariat services; operating and supporting the AMP; managing events and professional programmes; managing client and business relationships; processing payments and transactions; managing contracts and service delivery; sending administrative, service and transactional communications; providing relevant updates, insights or programme information where permitted; improving our website, platforms and services; conducting business analytics and service improvement; maintaining information security and preventing fraud or misuse; meeting legal, regulatory and compliance obligations under applicable Singapore and international law; establishing, exercising or defending legal rights; and other purposes reasonably related to the services requested or our business relationship. Where required by the PDPA or GDPR, we will obtain appropriate consent before collecting, using or disclosing personal data for a new purpose not previously notified.

5.

Association Management and Data Intermediary Services

ALLPS provides association management, secretariat and technology services to associations and other organisations. In these engagements, ALLPS may act as a data intermediary within the meaning of the PDPA, processing personal data on behalf of and in accordance with the instructions of the relevant organisation (the data controller). The client organisation retains responsibility for determining the purposes and means of processing. ALLPS will process personal data only as authorised by the client and will implement appropriate contractual and technical safeguards. Data processing responsibilities are governed by the applicable service agreement or data processing addendum between ALLPS and the client. Individuals with questions about personal data held by an association should contact the relevant association directly, unless otherwise directed.

6.

ALLPS Association Management Platform

The AMP may process membership records, contact information, event registrations, training and certification records, communications, payment status and other information required by the relevant client association. The specific data processed depends on each client's configuration and requirements. Where the AMP integrates with external systems via APIs or other technologies, data may be exchanged with authorised third-party platforms in accordance with the client's requirements and applicable contractual arrangements. ALLPS implements reasonable technical and organisational security measures to protect data processed through the AMP. Where a Data Protection Impact Assessment (DPIA) is warranted for high-risk processing activities on the AMP, ALLPS will conduct or support such assessments as appropriate.

7.

Artificial Intelligence and Automated Processing

ALLPS may use artificial intelligence, machine learning, automation and digital tools to support business operations and service delivery, including workflow automation, data analysis, reporting, document processing, knowledge management, business analytics, administrative support, and operational decision support. We seek to use such technologies responsibly, proportionately and transparently. Where personal data is processed using AI or automated technologies, ALLPS will apply appropriate safeguards having regard to the nature, purpose and sensitivity of the information and applicable legal requirements. Consistent with GDPR Article 22 and applicable PDPA obligations, ALLPS does not make decisions producing significant legal or similarly significant effects on individuals solely through automated processing without establishing an appropriate lawful basis and implementing suitable safeguards, including the right to human review where required.

8.

Marketing Communications

Where permitted by applicable law, or with your consent where required by the PDPA or GDPR, ALLPS may send information relating to professional services, training programmes, events, business opportunities, industry insights, new services, technology solutions and relevant ALLPS activities. Under the PDPA, we will honour do-not-call registrations and unsubscribe requests. You may withdraw consent for marketing communications at any time by using the unsubscribe mechanism provided in our communications or by contacting us at [email protected]. Administrative, transactional or service-related communications may continue where necessary to provide requested services or fulfil contractual or legal obligations.

9.

Lawful Basis for Processing (GDPR)

Where GDPR applies, ALLPS processes personal data on one or more of the following lawful bases under GDPR Article 6: (a) consent — where you have given clear consent for a specific purpose; (b) contract — where processing is necessary for the performance of a contract with you or to take steps at your request before entering into a contract; (c) legal obligation — where processing is necessary to comply with a legal obligation applicable to ALLPS; (d) legitimate interests — where processing is necessary for the legitimate interests of ALLPS or a third party, provided those interests are not overridden by your fundamental rights and freedoms; and (e) other lawful grounds under applicable legislation. Where processing of special category data is required, ALLPS will rely on an appropriate basis under GDPR Article 9. Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.

10.

Disclosure of Personal Data

ALLPS does not sell personal data. We may disclose or provide access to personal data where reasonably necessary to: employees and authorised representatives of ALLPS; consultants, contractors and professional advisers engaged by ALLPS; technology, cloud and hosting service providers; payment processors and financial institutions; training partners and event co-organisers; clients or associations where relevant to the service engagement; business partners where required for an agreed service or project; regulatory authorities, government agencies and law enforcement where legally required or authorised; and other parties where you have provided consent or where disclosure is permitted by applicable law. Third-party service providers processing personal data on our behalf are required by contract to maintain appropriate safeguards and to use personal data only for authorised purposes consistent with this Privacy Policy and applicable law.

11.

International Data Transfers

ALLPS is headquartered in Singapore and operates across ASEAN and international markets. Personal data may be transferred to, processed in, or stored in countries outside Singapore or the jurisdiction in which it was originally collected. Where personal data is transferred outside Singapore, ALLPS will comply with the PDPA's transfer limitation obligation and ensure that the recipient provides a standard of protection comparable to that under the PDPA, including through contractual arrangements or other approved mechanisms. Where GDPR applies to a transfer to a third country, ALLPS will use an appropriate transfer mechanism, such as Standard Contractual Clauses approved by the European Commission, or rely on an applicable adequacy decision or derogation.

12.

Data Security

ALLPS implements reasonable and appropriate administrative, organisational and technical security measures to protect personal data against unauthorised access, collection, use, disclosure, copying, modification, disposal, loss, misuse or destruction. Security measures include access controls, encryption where appropriate, system security monitoring, data handling policies and procedures, and contractual obligations on service providers. Employees and authorised personnel with access to personal data are subject to appropriate confidentiality obligations. Notwithstanding these measures, no electronic transmission, online service or storage system can be guaranteed to be completely secure. In the event of a personal data breach, ALLPS will respond in accordance with Section 20 of this Privacy Policy.

13.

Data Retention

ALLPS retains personal data only for as long as reasonably necessary to fulfil the purpose for which it was collected, provide requested services, maintain appropriate business and professional records, meet contractual requirements, comply with legal or regulatory obligations (including applicable limitation periods), resolve disputes, protect legitimate business interests, and enforce agreements. Retention periods are determined having regard to the nature of the data, the purpose of processing, applicable legal requirements and business necessity. When personal data is no longer required, ALLPS will take appropriate steps to securely delete, anonymise or otherwise dispose of the information in a manner that prevents unauthorised recovery or reconstruction.

14.

Accuracy of Personal Data

ALLPS takes reasonable steps to ensure that personal data held is accurate and complete, particularly where the information is likely to be used to make a decision affecting an individual or disclosed to another organisation. We rely on individuals to provide accurate information and to inform us of any changes. If you believe that personal data held by ALLPS is inaccurate, incomplete or outdated, please contact us so that we may take appropriate corrective action.

15.

Access and Correction Rights (PDPA)

Subject to the PDPA and applicable law, you have the right to: (a) request access to personal data held by ALLPS about you and information regarding how it has been used or disclosed within the past year; and (b) request correction of personal data that is inaccurate, incomplete or misleading. Requests should be submitted in writing to our Data Protection Officer at [email protected]. ALLPS will respond within the timeframe required by the PDPA. We may charge a reasonable fee for access requests as permitted by law. Certain exceptions and limitations apply as provided under the PDPA, including where providing access would be contrary to national interest, would reveal personal data of another individual, or is subject to legal privilege.

16.

Withdrawal of Consent

Where ALLPS relies on consent as the basis for collecting, using or disclosing personal data, you may withdraw that consent at any time by contacting our Data Protection Officer. We will process withdrawal requests within a reasonable time and in accordance with applicable legal requirements. Upon withdrawal, we will inform you of the likely consequences, which may include our inability to continue providing certain services where the relevant personal data is necessary. Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal.

17.

Additional Rights Under GDPR

Where GDPR applies to the processing of your personal data, you may have the following additional rights, subject to applicable conditions, limitations and exceptions: (a) right of access (Article 15) — to obtain confirmation of whether we process your personal data and to receive a copy; (b) right to rectification (Article 16) — to have inaccurate personal data corrected; (c) right to erasure (Article 17) — to request deletion in applicable circumstances; (d) right to restriction of processing (Article 18) — to request that we restrict processing in certain circumstances; (e) right to data portability (Article 20) — to receive your personal data in a structured, commonly used and machine-readable format where applicable; (f) right to object (Article 21) — to object to processing based on legitimate interests or for direct marketing; (g) rights related to automated decision-making (Article 22); and (h) right to lodge a complaint with a supervisory authority. To exercise these rights, please contact our Data Protection Officer. We will respond within the timeframe required by GDPR.

18.

Cookies and Website Technologies

Our website may use cookies and similar tracking technologies (including web beacons and pixel tags) to enable website functionality, maintain security, understand and analyse website usage, improve visitor experience, remember preferences, and support analytics and marketing where applicable. Cookies may be session-based (deleted when you close your browser) or persistent (retained for a defined period). Where required by applicable law, we will provide appropriate choices regarding non-essential cookies through a cookie consent mechanism. You may also manage or disable cookies through your browser settings; however, disabling certain cookies may affect website functionality. For further information, please refer to our Cookie Notice where available.

19.

Third-Party Platforms and Links

Our website and services may contain links to, or integrate with, third-party websites, applications or platforms, including technology providers, payment processors, event platforms, social media services and other external systems. These third parties operate independently and are governed by their own privacy policies and practices. ALLPS is not responsible for the privacy practices, security or content of independent third-party websites or services. We encourage you to review the relevant third-party privacy policies before providing personal data to those parties.

20.

Personal Data Breach Management

If ALLPS becomes aware of a personal data breach, we will promptly assess the incident and take reasonable steps to: contain the breach and prevent further unauthorised access or disclosure; investigate the cause, scope and impact; remediate identified vulnerabilities; assess applicable mandatory notification obligations under the PDPA (which requires notification to the Personal Data Protection Commission and affected individuals where the breach is of a significant scale or likely to cause significant harm) and GDPR (which requires notification to the supervisory authority within 72 hours and, where applicable, to affected individuals without undue delay); and notify relevant parties and authorities in accordance with applicable legal requirements. ALLPS maintains an internal incident response procedure to support timely and effective breach management.

21.

Children and Minors

ALLPS services are primarily directed at businesses, professionals, associations and organisations. We do not knowingly seek to collect personal data from children under the age of 18 through our general corporate website. Where ALLPS administers a programme, association, training activity or other service that involves minors, appropriate additional safeguards and parental or guardian consent arrangements will be implemented as required by applicable law.

22.

Data Protection Officer

ALLPS has designated a Data Protection Officer (DPO) responsible for overseeing compliance with applicable data protection laws, handling data protection queries and requests, and managing our data protection programme. The DPO may be contacted at: Data Protection Officer, ALLPS Consultancy LLP, Singapore. Email: [email protected]. When submitting a request or query, please provide sufficient information to identify yourself and describe the nature of your request. We may request additional information to verify your identity before processing certain data protection requests, as permitted by applicable law.

23.

Complaints

If you have concerns regarding how ALLPS handles your personal data, we encourage you to contact our Data Protection Officer in the first instance so that we may investigate and respond. If you are not satisfied with our response, you may have the right to lodge a complaint with the relevant data protection authority. In Singapore, this is the Personal Data Protection Commission (www.pdpc.gov.sg). Where GDPR applies, you may also lodge a complaint with the competent European data protection supervisory authority in your country of residence or place of work.

24.

Updates to This Privacy Policy

ALLPS may update this Privacy Policy from time to time to reflect changes to our business, services, technologies, legal requirements or data protection practices. Material changes will be communicated through our website or by other appropriate means. The most current version will be published on our website with the date of the most recent update. Your continued use of our website or services following the publication of an updated Privacy Policy constitutes your acknowledgement of the changes, to the extent permitted by applicable law. We encourage you to review this Privacy Policy periodically.

25.

Contact Us

For all privacy and data protection enquiries, access or correction requests, consent withdrawal requests, or complaints, please contact: Data Protection Officer, ALLPS Consultancy LLP, Singapore. Email: [email protected]. We aim to acknowledge receipt of all enquiries promptly and to respond substantively within the timeframe required by applicable law.

Data Protection Enquiries

For questions, access requests or concerns relating to this Privacy Policy, contact our Data Protection Officer.

[email protected]