Legal
PDPA notice
Last updated 9 October 2026
This notice explains how Gint complies with Singapore's Personal Data Protection Act 2012 (PDPA), both for our own website and account holders and for the businesses we serve.
1. Purposes for which we collect, use and disclose personal data
[Company legal name] Pte. Ltd. ("we") collects, uses and discloses personal data for these purposes:
- to set up and run your Gint account and the Service;
- to process WhatsApp enquiries, create and manage bookings and send reminders on a business's behalf;
- to bill for the Service and provide customer support;
- to respond to demo requests and enquiries;
- to keep the Service secure, prevent fraud and abuse, and investigate incidents; and
- to meet legal and regulatory requirements.
2. Consent
We collect personal data about you with your consent, which may be given expressly (for example, by ticking a box or submitting a form) or by conduct where the PDPA allows. We will tell you the purposes before or at the time of collection.
You can withdraw consent by emailing dpo@example.com. We will tell you the likely consequences, and we will stop the relevant collection, use or disclosure within a reasonable time unless the PDPA or other law lets us continue.
3. Our role as a data intermediary
When a business uses Gint to talk to its customers, that business is the organisation responsible for the personal data of the people who message it, and we are its data intermediary. In that role we:
- process personal data only to provide the Service, on the business's documented instructions;
- protect it with reasonable security arrangements, including encryption and access controls;
- keep it only as long as the business needs it, and delete or return it on request;
- tell the business without undue delay if we discover a data breach affecting its data; and
- give businesses dashboard tools to export or permanently delete any individual's data.
Businesses using Gint must obtain any consent they need from their customers, including to message them on WhatsApp and to have automated assistants help reply, and should tell customers that an AI assistant is involved. If you are a customer of a business using Gint and want to access, correct or delete your data, please contact that business directly.
4. Access and correction
You may request access to the personal data we hold about you, and ask us to correct it, by emailing dpo@example.com. We may need to verify your identity. We will respond within 30 days; if we need longer, we will tell you when we can respond. We may charge a reasonable administrative fee for access requests and will tell you the amount first. We may decline requests where the PDPA allows.
5. Accuracy and retention
We take reasonable steps to keep personal data accurate and complete if it is likely to be used to make a decision about you or disclosed to another organisation. We keep personal data only for as long as needed for the purposes above or for legal or business reasons, then delete it or anonymise it. Our privacy policy lists typical retention periods.
6. Transfers outside Singapore
Our service providers (for example WhatsApp, AI model, payment, hosting and email providers) may process data outside Singapore. Before any transfer we take appropriate steps, such as contractual protections, to ensure the recipient provides a standard of protection comparable to the PDPA.
7. Data breach notification
If we discover a data breach, we assess promptly whether it is notifiable. If it results in, or is likely to result in, significant harm to individuals, or is of significant scale, we notify the Personal Data Protection Commission as soon as practicable and no later than three calendar days after concluding it is notifiable, and we notify affected individuals where required.
Where a breach affects data we process for a business as its data intermediary, we notify that business without undue delay so it can meet its own obligations.
8. Marketing messages
We send marketing messages only with consent and we respect the Do Not Call Registry. Every marketing email has an unsubscribe link. Service messages, such as billing and security notices, are not marketing.
9. Data Protection Officer
Our Data Protection Officer can be reached at dpo@example.com, or by post at [Registered address], Singapore. If you are not satisfied with our response, you may contact the Personal Data Protection Commission at pdpc.gov.sg.
See also: Privacy policy · Terms of service · PDPA notice