Personal Data Protection Policy

LAST UPDATED: 14 September 2026

SCOPE

Website visitors, clients, prospective clients and other persons who interact with XPS Technologies.

This Policy explains how XPS Technologies collects, uses, discloses, protects, retains and otherwise handles personal data in accordance with Singapore’s Personal Data Protection Act 2012 (PDPA).

1. Introduction

XPS Technologies Pte Ltd (“XPS Technologies”, “we”, “us” or “our”) is committed to safeguarding the personal data entrusted to us. This Policy applies to personal data that we handle in connection with our website, enquiries, communications, client relationships and the provision of our products and services.

Where we provide a specific data protection notice for a particular service, activity or interaction, that notice should be read together with this Policy.

2. What “Personal Data” Means

“Personal data” means data about an individual who can be identified from that data, or from that data together with other information to which we have or are likely to have access.

Examples may include a person’s name, personal contact details and other information that identifies the individual. Information that constitutes “business contact information” under the PDPA may be treated differently under the Act; nevertheless, we aim to handle such information responsibly.

3. Personal Data We May Collect

Depending on how you interact with us, we may collect the following categories of information:

  • Contact information, such as your name, email address and telephone number, including information provided through WhatsApp communications.
  • Business relationship information, such as your company name, professional title, role, enquiry details, service-related information and correspondence with us.
  • Technical and website usage information, such as IP address, browser or device information, and information collected through cookies or similar technologies, where applicable.
  • Other information that you voluntarily provide to us in connection with an enquiry, request, feedback or service engagement.

4. How We Collect Personal Data

We may collect personal data directly from you when you contact us, submit an enquiry, communicate with us by email, telephone or WhatsApp, engage our services, or otherwise interact with us. We may also collect limited technical information automatically when you use our website.

Where required under the PDPA, we will obtain consent for the collection, use or disclosure of personal data. In circumstances permitted by law, we may collect, use or disclose personal data without consent.

5. How We Use Personal Data

We may collect, use or disclose personal data for purposes that are reasonable and appropriate in the circumstances, including:
  • Responding to enquiries, requests, feedback or support matters.
  • Providing, administering and supporting our products and services.
  • Managing our business relationship and communications with clients and prospective clients.
  • Improving our website functionality, user experience and service delivery.
  • Sending service-related announcements and important updates.
  • Sending marketing information where you have opted in, or where otherwise permitted under applicable law, including the Do Not Call provisions of the PDPA where applicable.
  • Complying with legal, regulatory, contractual or professional requirements.
If we intend to use personal data for a materially different purpose that is not otherwise permitted by law, we will notify you and obtain consent where required.

You may opt out of receiving marketing communications from us at any time by using any unsubscribe mechanism provided in the communication or by contacting us using the details in Section 14.

6. Disclosure of Personal Data

We do not sell or trade personal data. We may disclose personal data where necessary for the purposes described in this Policy, including to:

  • Service providers that support our website and business operations, such as IT, hosting, communications, analytics or marketing service providers, where applicable.
  • Professional advisers, such as auditors, accountants or lawyers.
  • Government agencies, regulators, law enforcement bodies or other parties where disclosure is required or permitted by law.

Where third parties process personal data on our behalf, we take reasonable steps to ensure that appropriate data protection arrangements are in place, having regard to the nature of the services and data involved.

7. Transfers of Personal Data Outside Singapore

Where personal data is transferred outside Singapore, we will take appropriate steps to ensure that the recipient is bound to provide a standard of protection for the transferred personal data that is comparable to the protection required under the PDPA, in accordance with applicable legal requirements.

8. Cookies and Website Information

Our website may use cookies and similar technologies to support essential website functionality, understand how visitors interact with our website, perform analytics and improve the user experience.

Where third-party services are used, such service providers may also place cookies or similar technologies on your device in accordance with their respective privacy practices.

You may control or disable cookies through your browser settings. However, disabling certain cookies may affect the functionality or performance of parts of our website.

Where consent for the use of particular cookies or similar technologies is required under applicable law, we will obtain such consent where applicable.

9. Accuracy of Personal Data

We will make reasonable efforts to ensure that personal data collected by or on our behalf is accurate and complete where it is likely to be used to make a decision that affects you or is likely to be disclosed to another organisation.

You may contact us if you believe that personal data we hold about you is inaccurate or incomplete.

10. Protection of Personal Data

We implement reasonable administrative, technical, physical and organisational measures appropriate to the nature of the personal data we hold to protect it against unauthorised access, collection, use, disclosure, copying, modification, disposal or similar risks.

Although no method of storage or transmission can be guaranteed to be completely secure, we review and improve our safeguards where reasonably appropriate.

11. Retention of Personal Data

We retain personal data only for as long as it is reasonably necessary to fulfil the purposes for which it was collected, or as required or permitted for legal, regulatory or legitimate business purposes.

When retention is no longer necessary for any legal or business purpose, we will cease to retain the personal data, or remove the means by which the data can be associated with particular individuals, where reasonably practicable.

12. Data Breach Notification

If a data breach involving personal data occurs, we will assess the breach in a reasonable and expeditious manner and take appropriate steps to contain and address it.

Where we determine that a breach is notifiable under the PDPA, we will notify the Personal Data Protection Commission (PDPC) as soon as practicable and, in any case, no later than three calendar days after making that determination. Where notification to affected individuals is required under the PDPA, we will notify them as soon as practicable, subject to applicable legal requirements.

We may also notify law enforcement authorities, regulators or other relevant parties where required or permitted by applicable law.

13. Access, Correction and Withdrawal of Consent

Access. You may request access to personal data that we hold about you and information about the ways in which such personal data has been or may have been used or disclosed by us within the year before the date of your request, subject to applicable exceptions and limitations under the PDPA.

Correction. You may request that we correct an error or omission in personal data that we hold about you, subject to the PDPA.

Withdrawal of consent. Where we rely on your consent, you may withdraw that consent by giving us reasonable notice. We will inform you of the likely consequences of the withdrawal. Subject to applicable legal requirements and exceptions, we will cease collecting, using or disclosing the relevant personal data after the withdrawal takes effect.

We aim to respond to access and correction requests as soon as reasonably possible. If we are unable to respond within 30 days after receiving your request, we will inform you within that period of the time by which we expect to respond. A reasonable fee may be charged for processing an access request. Where a fee applies, we will provide you with a written estimate of the fee before processing the request.

We may request information reasonably necessary to verify your identity and process your request.

14. Questions, Requests and Complaints

To exercise your rights, withdraw consent, raise a complaint about the handling of your personal data, or ask a question about this Policy or our data protection practices, please contact our Data Protection Officer (DPO):

Organisation:

XPS Technologies Pte Ltd

15. Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices, legal or regulatory requirements, or other operational reasons. The updated Policy will be published on our website with the revised “Last Updated” date. We encourage you to review this Policy periodically for any changes.