Legal
Privacy policy
Last updated 9 October 2026
Your privacy matters, and so does your customers'. This policy explains what Gint collects, why, who sees it and how you stay in control.
1. Who we are
Gint is operated by [Company legal name] Pte. Ltd. (UEN [UEN]), [Registered address], Singapore ("we", "us"). We provide an AI receptionist that answers WhatsApp enquiries and books appointments for businesses in Singapore (the "Service").
This policy explains how we handle personal data under Singapore's Personal Data Protection Act 2012 ("PDPA"). Our PDPA notice covers our two roles in more detail.
2. Our two roles
As an organisation, we collect and use personal data about people who visit our website, ask for a demo or create an account ("Account holders"). For that data we decide the purposes and means.
As a data intermediary, we process personal data on behalf of the businesses that use the Service ("Business customers"), such as the names, phone numbers and messages of the people who contact them on WhatsApp ("End customers"). The Business customer decides why that data is collected and is responsible for having a valid basis, including consent, to collect it. If you are an End customer and want to see, correct or delete your data, please contact the business you messaged first.
3. What we collect
- Account data: name, email address, password hash (or Google sign-in identifier), business name and type, and your role.
- Business configuration: services, prices, opening hours, staff names and schedules, policies, FAQ answers and AI tone settings that you give us.
- End-customer data (processed for Business customers): name, WhatsApp number, language, messages and media metadata, booking history, notes and tags added by staff.
- Billing data: plan, subscription status and invoices. Card details are collected and stored by our payment processor, not by us.
- Demo and contact requests: the details you type into our forms, such as name, work email, phone number and message.
- Technical data: IP address, device and browser type, pages visited and error logs, used to run and secure the Service.
4. How we use personal data
We use personal data to:
- provide the Service: receive WhatsApp messages, generate replies, manage bookings, send reminders and reports;
- create and secure accounts, authenticate users and prevent abuse;
- bill for the Service and respond to support, demo and sales requests;
- maintain, debug and improve the reliability and safety of the Service;
- send service messages (for example, trial and billing notices) and, with consent, product updates; and
- comply with law and enforce our terms.
We do not sell personal data. We do not use End-customer conversations to train AI models, and we do not allow our AI providers to do so on our behalf.
5. Consent and other bases
We rely on consent (including deemed consent by conduct, such as when you submit a form or create an account), contractual necessity, and the exceptions allowed by the PDPA, including legitimate interests where the PDPA permits. You may withdraw consent at any time by contacting our Data Protection Officer; depending on what you withdraw, we may no longer be able to provide the Service to you.
7. Transfers outside Singapore
Some of our providers process data outside Singapore, including in the United States and the European Union. Before transferring personal data overseas we take steps to ensure the recipient provides a standard of protection comparable to the PDPA, typically through contractual commitments.
8. How long we keep data
- Account and business data: for as long as your account is active, and for up to 90 days after closure.
- End-customer conversations and bookings: for as long as the Business customer keeps them, unless the Business customer deletes them sooner. Business customers can export or permanently delete any customer's data from the dashboard.
- Billing records: for the period required by Singapore tax and accounting law (generally five years).
- Demo requests: up to 24 months.
- Security and audit logs: up to 12 months.
9. Security
We encrypt data in transit (TLS) and encrypt sensitive credentials, such as WhatsApp access tokens and calendar tokens, at rest. Each Business customer's data is logically isolated from others, access is restricted to staff who need it, and we log exports and deletions. No system is perfectly secure; if we become aware of a notifiable data breach we will tell the affected Business customers, the Personal Data Protection Commission and, where required, affected individuals, as described in our PDPA notice.
10. Your rights
Under the PDPA you may ask us for access to personal data we hold about you, request correction of it, and withdraw your consent. We respond within 30 days of receiving a valid request and may charge a reasonable fee for access, which we will tell you about in advance. Send requests to dpo@example.com.
For End customer data, we will pass your request to the relevant Business customer, or help them respond to you.
12. Children
The Service is for businesses and is not directed at children. Business customers are responsible for how they handle enquiries from minors, and should obtain parental consent where required.
13. Changes to this policy
We may update this policy from time to time. We will post the new version here and, for material changes, notify account holders by email or in the dashboard.
14. Contact us
Data Protection Officer: dpo@example.com. General support: support@example.com. Postal address: [Registered address], Singapore.
See also: Privacy policy · Terms of service · PDPA notice