Privacy Policy
This Privacy Policy explains how we collect, use, disclose, retain, and protect personal data when you use our online platform and related expense management services. Our services provide insights into expense structures and support cost structure analysis, expense optimisation, budget planning, financial reporting, and vendor management.
We handle personal data in accordance with applicable privacy laws, including the Singapore Personal Data Protection Act 2012 and, where applicable, the European Union General Data Protection Regulation.
Personal Data We Collect
Depending on how you use this service, we may collect the following categories of information:
- Account and identity information, such as your name, business role, organisation details, and account credentials.
- Expense and financial information, such as transaction descriptions, amounts, dates, currencies, categories, budgets, cost centres, and financial reports.
- Vendor and procurement information, such as supplier names, contract-related records, payment terms, and purchasing information.
- Usage and technical information, such as device type, browser details, access times, approximate location, IP address, log data, and interactions with our online platform.
- Information you provide when requesting support, submitting feedback, or otherwise interacting with this service.
How We Use Personal Data
We use personal data for the following purposes:
- To provide expense analysis, cost structure analysis, expense optimisation, budget planning, financial reporting, and vendor management features.
- To create dashboards, reports, comparisons, forecasts, and recommendations based on information supplied by authorised users.
- To operate, maintain, secure, troubleshoot, and improve our online platform.
- To verify accounts, administer access permissions, and prevent fraud, misuse, or unauthorised activity.
- To provide service-related support and respond to requests.
- To comply with legal obligations, enforce our agreements, and establish, exercise, or defend legal claims.
- To produce aggregated or anonymised insights that do not reasonably identify an individual.
Legal Bases for Processing
Where the GDPR applies, we process personal data on one or more of the following legal bases:
- Performance of a contract or steps taken at your request before entering into a contract.
- Compliance with legal or regulatory obligations.
- Our legitimate interests in operating, securing, and improving the service, provided those interests do not override your rights.
- Your consent, where consent is required by law. You may withdraw consent at any time, without affecting processing that occurred before withdrawal.
Financial and Business Information
Our service may process business expense and financial records submitted by an organisation or its authorised users. Organisations are generally responsible for determining what information is uploaded and for providing any required notices to their personnel, vendors, or other individuals. We use such information only for authorised service purposes and do not treat expense insights as regulated financial, tax, legal, or investment advice.
Cookies and Similar Technologies
We may use essential cookies and similar technologies to authenticate users, maintain sessions, remember preferences, protect the service, and understand platform performance. Where required by law, we will request consent before using non-essential analytics or similar technologies. You can manage cookies through your browser settings, although disabling essential cookies may affect functionality.
Sharing Personal Data
We may disclose personal data to the following categories of recipients where necessary and lawful:
- Service providers that host, secure, maintain, analyse, or support our online platform.
- Professional advisers, auditors, insurers, and legal representatives subject to appropriate confidentiality obligations.
- Government authorities, regulators, courts, or law enforcement where required or permitted by law.
- A successor or transaction party in connection with a merger, restructuring, financing, acquisition, or sale of assets, subject to applicable safeguards.
We do not sell personal data. We require service providers to process personal data only for authorised purposes and to apply appropriate security and confidentiality measures.
International Data Transfers
Some service providers may process personal data outside Singapore or the country where you access this service. Where required, we use legally recognised transfer mechanisms and appropriate contractual, technical, and organisational safeguards to protect personal data.
Data Security
We use reasonable administrative, technical, and physical safeguards designed to protect personal data against unauthorised access, alteration, disclosure, loss, or destruction. No online service can guarantee absolute security, and you are responsible for keeping account credentials confidential and notifying the appropriate account administrator of suspected misuse.
Data Retention
We retain personal data only for as long as necessary to provide the service, fulfil the purposes described in this policy, resolve disputes, enforce agreements, meet legal and accounting obligations, and protect our legitimate interests. Retention periods depend on the type and sensitivity of the information, the relationship with the relevant organisation, and applicable legal requirements. We securely delete or anonymise information when it is no longer required.
Your Privacy Rights
Subject to applicable law, you may have the right to:
- Request access to personal data we hold about you.
- Request correction of inaccurate or incomplete personal data.
- Request deletion or restriction of processing in appropriate circumstances.
- Object to processing based on legitimate interests or direct marketing.
- Request portability of information where the right applies.
- Withdraw consent where processing is based on consent.
- Make a complaint to a relevant data protection authority.
Requests may be subject to identity verification and legal limitations. If you use the service through an organisation, that organisation may be the data controller and should normally receive your request first.
Children’s Privacy
This service is intended for business and professional use and is not directed to children. We do not knowingly collect personal data from children where prohibited by applicable law.
Changes to This Policy
We may update this Privacy Policy to reflect changes in our services, practices, or legal obligations. The revised policy will be published through our online platform, and the updated version will apply from its stated publication or effective date.
Privacy Enquiries
For privacy requests or concerns, please write to the organisation responsible for this service at the following physical address:
Holland Green Linear Park,Singapore 277829
Singapore