Privacy Notice

This is a drafting framework, not final legal advice or a statement of current live processing. Before publication, BizPro must verify the website’s forms, recipients, vendors, hosting, analytics, cookies, retention periods, cross-border processing and DPO contact details, then obtain appropriate factual and legal review.

> Publication control: Replace this notice with a factually completed and reviewed version before the public website collects personal data. The wording below identifies the matters the final notice should cover. It is not legal advice.

About this notice

The final notice should identify BizPro Consulting Pte Ltd using its verified legal name and business details. It should explain which website and related enquiry channels it covers, its effective date and how it relates to any separate client, employee or recruitment privacy notices.

Who is responsible for personal data

State the organisation responsible for the website processing and provide a verified data-protection contact. If another entity operates a form, scheduling tool, newsletter or hosting service, distinguish BizPro’s role from the service provider’s role.

Personal data the website may collect

After a field and log inventory, describe the actual categories, which may include:

  • name and business contact details;
  • employer or business name;
  • service interest and enquiry message;
  • appointment preferences;
  • marketing preference, if an optional subscription exists;
  • technical and security information such as IP address, timestamps and request logs; and
  • cookie or analytics identifiers only if the approved live configuration uses them.

Do not imply that BizPro collects categories the website does not use. The initial enquiry form should discourage sensitive records, passwords, identification documents and unnecessary personal data.

How personal data may be collected

Explain actual collection points: direct form submission, email or telephone contact, appointment booking, cookie or server logs, and information supplied by an authorised representative. If third-party sources exist, identify the category and purpose clearly.

Purposes of collection, use and disclosure

The final, fact-checked purposes may include:

  • responding to and managing an enquiry;
  • assessing service fit and preparing a requested proposal;
  • arranging a meeting;
  • meeting professional, security or legal requirements;
  • operating, securing and troubleshooting the website;
  • maintaining records of communications; and
  • sending optional updates only where approved and with an appropriate choice.

The collection notice beside each form should state its immediate purpose and link here. The legal or consent basis, where the final notice discusses it, needs review against the actual facts and current Singapore requirements.

When information may be disclosed

Identify real recipient categories, not a generic unlimited list. They may include authorised BizPro personnel, contracted website or communication providers, professional advisers where needed, and public authorities where required or appropriately authorised. State that providers receive only information needed for their role and are subject to appropriate arrangements, if that is factually true.

An enquiry should not be presented as confidential professional advice before an engagement and appropriate conflict or acceptance checks.

Service providers and overseas processing

Create and maintain a processor register covering hosting, email, spam protection, analytics, scheduling, forms, backups and support. For each provider, verify the contracting entity, purpose, data categories, storage or access locations, retention, security settings and deletion or export options.

The final notice should accurately explain overseas transfer or access arrangements. Do not state that data remains in Singapore unless technically and contractually confirmed.

Cookies and analytics

Summarise only the technologies actually deployed and link to the Cookie Notice. If non-essential analytics or marketing tools are not approved, the notice should not reserve an unnecessarily broad right to use them. Consent controls, where required, must match the deployed scripts.

Retention

State the criteria and, where practical, specific retention periods for enquiries, security logs, marketing preferences and backups. The final periods must match system settings and operational deletion routines. “As long as necessary” should be supplemented with meaningful criteria.

Security

Describe safeguards at an appropriate level without exposing configuration. Possible controls include encrypted transport, restricted access, multi-factor authentication, updates, backups, logging, secure transfer methods and provider review—but only controls that are implemented and verified should be stated.

No website or transmission method should be described as completely secure.

Access, correction and other enquiries

Provide a verified route for individuals to ask about personal data and request access or correction. The operational procedure should cover identity verification, authorised representatives, request logging, response ownership, exceptions and current statutory requirements. The notice should avoid promising an unverified timeframe or outcome.

Marketing choices

If BizPro introduces a newsletter or marketing messages, state how the recipient can opt in or out and how suppression preferences are retained. Marketing choice must be separate from the service-enquiry purpose. If no marketing is used, remove this section or say so accurately.

Third-party websites

Explain that external links lead to services with their own practices. This should not attempt to waive responsibility for BizPro’s own choice or configuration of processors.

Changes to this notice

Show an effective date and material-change process. Review should be triggered by new forms, analytics, AI features, vendors, international processing, service channels or regulatory change.

Contact the DPO

Publish only the owner-approved DPO or data-protection contact, postal contact where required, and escalation route. Do not expose a personal address or unmonitored mailbox. Clarify whether the channel is appropriate for incidents, access or correction requests, and general privacy questions.


Discuss the next step