AI SUPERStart free

Data Protection Policy

Last updated: 16 August 2026

1. Purpose

AI Super Private Limited (“AI Super”, “we”, “us”, or “our”) is committed to protecting personal data in accordance with Singapore’s Personal Data Protection Act 2012 (“PDPA”) and other applicable laws.

This Data Protection Policy explains how we collect, use, disclose, process, retain, transfer, and protect personal data in connection with our websites, AI-powered chatbot systems, messaging automation, integrations, and related services (collectively, the “Services”).

2. Our Roles under the PDPA

Depending on the context, AI Super may act as:

Organisation

We act as an organisation (sometimes referred to as a data controller) when we determine the purposes and means of collecting, using, or disclosing personal data. This includes personal data relating to website visitors, prospective customers, direct customers, and our business contacts.

Data Intermediary

We act as a data intermediary (sometimes referred to as a data processor) when we process personal data on behalf of and for the purposes of a customer under a written agreement.

Where we act as a data intermediary, we:

Process personal data only in accordance with the customer’s documented instructions and the applicable agreement.

Do not use customer-controlled personal data for our own independent purposes.

Implement reasonable security arrangements and appropriate retention and disposal measures.

Notify the relevant customer of a suspected or confirmed data breach affecting customer-controlled personal data as soon as practicable.

Assist the customer, where reasonably required and contractually agreed, in meeting applicable data-protection obligations.

Customers remain responsible for matters under their control, including establishing a lawful purpose, providing required notices, obtaining valid consent where required, and configuring and using the Services lawfully.

3. Personal Data We Collect or Process

We may collect or process the following categories of personal data.

Customer and Business Information

Name, company name, and job title.

Email address, telephone number, and WhatsApp number.

Account and business contact information.

Technical and Usage Data

IP address, device, browser, and operating-system information.

System logs, timestamps, API activity, and security events.

Information about how the Services are accessed and used.

Financial and Transaction Data

Billing details, invoices, subscription information, and transaction records.

Payment-card information may be processed directly by our payment providers and may not be stored by AI Super.

Communications and Support Data

Messages, chatbot conversations, voice notes, attachments, and uploaded files.

Information provided during onboarding, consultations, support requests, or other communications.

Customer-Controlled Data

Personal data submitted to or processed through the Services under a customer’s instructions, including information relating to the customer’s chatbot users, contacts, leads, enquiries, appointments, and bookings.

4. How We Collect Personal Data

We may collect personal data when you:

Visit or use our websites, applications, chatbots, or other Services.

Register for an account, request a demonstration, subscribe to a Service, or enable an integration.

Communicate with us by email, telephone, web form, or messaging platform.

Authorise a third-party platform to share information with us.

Interact with the Services as an end-user of one of our customers.

We may also receive personal data from our customers, service providers, messaging platforms, integration partners, and publicly available sources where permitted by law.

5. Purposes of Collection, Use, and Disclosure

Where permitted by applicable law, we may collect, use, or disclose personal data to:

Provide, operate, maintain, and support the Services.

Configure accounts, integrations, chatbots, and automation workflows.

Understand communications and generate requested chatbot responses.

Manage customer relationships and respond to enquiries.

Process subscriptions, billing, invoices, and payments.

Monitor performance, security, fraud, misuse, and service reliability.

Improve the Services using data that we are authorised to use, including aggregated or de-identified information where appropriate.

Maintain business, tax, audit, and compliance records.

Enforce our agreements and protect our rights, users, systems, and the public.

Comply with applicable legal and regulatory requirements.

Where we process customer-controlled personal data as a data intermediary, the purposes of processing are determined by the relevant customer and limited by the customer’s documented instructions and applicable agreement.

6. AI and Automated Processing

The Services use artificial-intelligence technologies, including services provided by third-party AI providers such as OpenAI, to process, analyse, and respond to communications.

This may include:

Understanding message content, context, and intent.

Transcribing or interpreting supported media.

Generating automated replies or recommended actions.

Routing communications or initiating configured workflows.

Automated processing may affect how a communication is classified, routed, or answered without immediate human intervention. Customers are responsible for deciding when human review is appropriate for their use case.

We do not use customer-controlled personal data to train general-purpose AI models unless the customer has expressly authorised that use and the processing is otherwise lawful.

Any use of information to evaluate or improve our Services must be consistent with the applicable agreement, notices, permissions, and law.

7. Third-Party Platforms and Service Providers

Our Services may integrate with or rely on third parties, including:

Messaging and Social Platforms

Meta platforms, such as WhatsApp, Instagram, and Facebook.

Productivity Services

Google services, such as Google Calendar and Google Sheets.

Artificial-Intelligence Providers

AI providers, including OpenAI.

Hosting and Infrastructure Providers

Cloud and infrastructure providers, including Contabo for hosting in Singapore.

Other Service Providers

Analytics, communications, payment, and customer-support providers.

Professional advisers, auditors, and insurers.

We disclose personal data to these parties only where reasonably necessary for the relevant purpose, permitted by law, and subject to appropriate contractual or other safeguards.

A third party may also process personal data independently under its own privacy policy and terms.

Third-party services may experience outages, delivery failures, policy changes, restrictions, or other events outside our reasonable control. This does not exclude any responsibility that AI Super has under applicable law.

8. Disclosure of Personal Data

We may disclose personal data to:

Authorised employees, contractors, and affiliates who require access for their work.

Cloud, hosting, AI, analytics, messaging, communications, integration, and technology providers.

Payment processors and financial institutions.

Professional advisers, auditors, and insurers.

A purchaser, investor, or successor in connection with a proposed or completed corporate transaction, subject to appropriate confidentiality safeguards.

Regulators, courts, law-enforcement agencies, or other parties where required or permitted by law.

We do not sell personal data.

9. Customer Responsibilities

Customers using the Services must:

Comply with applicable data-protection, privacy, marketing, communications, and sector-specific laws.

Provide required notices and obtain valid consent or establish another lawful basis where applicable.

Ensure that their instructions to AI Super are lawful.

Use appropriate account permissions and protect their credentials.

Configure retention, access, integrations, messaging, and automation features appropriately.

Respond to requests from individuals where the customer is responsible for doing so.

Avoid uploading or processing personal data that is unnecessary for the intended purpose.

Customers must not use the Services to send spam, conduct unauthorised marketing, or engage in unlawful, fraudulent, abusive, or deceptive activities.

We may suspend or terminate access where necessary to protect individuals, customers, third parties, or the Services, or to comply with law.

10. Consent and Withdrawal of Consent

Where AI Super relies on consent, we will provide appropriate notice and obtain consent before collecting, using, or disclosing personal data.

An individual may withdraw consent by contacting our Data Protection Officer using the details in Section 22, subject to applicable legal or contractual restrictions and reasonable notice.

We will explain the likely consequences of withdrawal where appropriate. Withdrawal of consent may affect our ability to provide some or all of the Services.

Where AI Super processes personal data solely on behalf of a customer, requests relating to consent should generally be directed to that customer. We will provide reasonable assistance where required and appropriate.

11. Access and Correction

Subject to the PDPA and any applicable exceptions, an individual may request:

Access

Access to personal data under our possession or control and information about how it has been used or disclosed.

Correction

Correction of inaccurate or incomplete personal data.

We may verify the requester’s identity and may charge a reasonable fee for an access request where permitted by law.

If a request concerns customer-controlled data, we may refer the requester to the relevant customer and assist that customer where required and appropriate.

Requests may be submitted to our Data Protection Officer using the details in Section 22.

12. Accuracy

We take reasonable steps to ensure that personal data collected by us is accurate and complete where it is likely to be used to make a decision affecting an individual or disclosed to another organisation.

Customers are responsible for the accuracy and completeness of customer-controlled data they submit to the Services.

13. Data Retention and Disposal

We retain personal data only for as long as it is reasonably necessary to fulfil the purpose for which it was collected or processed, meet contractual requirements, resolve disputes, protect the Services, or comply with legal, accounting, audit, or regulatory obligations.

Account and Customer Records

Account and customer records may be retained for the duration of the business relationship and a reasonable period afterwards.

System and Security Logs

System and security logs may be retained for security, troubleshooting, audit, and operational purposes.

Financial and Transaction Records

Financial and transaction records are retained for the period required by applicable law.

Customer-Controlled Data

Customer-controlled data is retained in accordance with the applicable agreement, customer instructions, and configured retention settings.

Disposal of Personal Data

When personal data is no longer required for a legal or business purpose, we will cease retaining it or remove the means by which it can be associated with an individual.

Depending on the circumstances, personal data may be securely deleted, destroyed, or anonymised. Residual copies may remain temporarily in backups until they are overwritten or securely deleted under our backup-retention process.

14. Data Protection and Security

We implement reasonable administrative, technical, and physical safeguards appropriate to the nature of the personal data and the risks involved.

These safeguards may include:

Access Security

Access controls, authentication, and permission management.

Encryption

Encryption in transit and encryption at rest where appropriate.

Infrastructure Security

Secure hosting and network infrastructure.

Monitoring, logging, backups, and recovery measures.

Vulnerability, patch, and incident-management procedures.

Organisational Security

Confidentiality obligations and security awareness for authorised personnel.

Vendor assessment and contractual data-protection requirements.

No system or method of transmission is completely secure.

Customers are also responsible for securing their accounts, devices, credentials, integrations, configurations, and authorised users.

15. Data Breach Management and Notification

We maintain procedures to identify, contain, investigate, assess, remediate, and document suspected personal-data breaches.

When AI Super Acts as an Organisation

We will assess whether a breach is notifiable and notify the Personal Data Protection Commission and affected individuals where required by the PDPA and within the applicable timeframes.

When AI Super Acts as a Data Intermediary

We will notify the relevant customer of a suspected or confirmed personal-data breach affecting customer-controlled data as soon as practicable after becoming aware of it.

We will provide reasonable information and assistance to support the customer’s assessment and response, subject to the applicable agreement and law.

16. Overseas Transfers

Singapore-Based Hosting

Our primary hosting infrastructure is located in Singapore through Contabo.

Overseas Processing

Personal data may be transferred to, accessed from, or processed in other countries when we use third-party platforms or service providers, including Meta, Google, OpenAI, and other technology providers.

Transfer Safeguards

Before transferring personal data outside Singapore, we take appropriate steps to ensure that the recipient is bound by legally enforceable obligations or specified certifications, or that another permitted transfer mechanism applies.

These measures are intended to ensure that personal data receives a standard of protection comparable to that required under the PDPA.

Safeguards may include:

Contractual commitments.

Access restrictions.

Encryption.

Data minimisation.

Vendor assessments.

Customers are responsible for assessing and configuring any third-party integrations they independently choose to enable.

17. Cookies and Similar Technologies

We may use cookies and similar technologies for:

Essential Functions

Essential website and account functionality.

Security and fraud prevention.

Analytics and Preferences

Analytics and performance measurement.

User preferences and experience improvements.

Users may manage cookies through their browser settings and any cookie controls we make available.

Disabling certain cookies may affect website or Service functionality.

18. Marketing and Do Not Call Compliance

Where AI Super sends marketing communications, we will comply with applicable consent, opt-out, and Singapore Do Not Call requirements.

Recipients may use the unsubscribe method in the communication or contact us to opt out, subject to communications that we are legally permitted or required to send.

Customers that use the Services for marketing or messaging remain responsible for:

Recipient lists.

Required notices and consents.

Opt-out handling.

Do Not Call checks.

Message content.

Compliance with applicable laws and platform rules.

19. Children and Higher-Risk Personal Data

Children’s Personal Data

The Services are intended for businesses and are not directed to children under 13.

Customers must not intentionally use the Services to collect personal data from children without implementing appropriate notices, consent, age-verification, and other safeguards required by law.

Sensitive or Higher-Risk Personal Data

Customers should avoid processing sensitive or higher-risk personal data unless it is necessary, lawful, and subject to safeguards appropriate to the potential harm.

Customers in regulated sectors are responsible for determining whether the Services are suitable for their requirements and implementing any additional controls required by law or professional obligations.

20. Shared Responsibility and Third-Party Services

AI Super’s Responsibilities

AI Super is responsible for meeting the obligations that apply to its role and activities under the PDPA and other applicable laws.

Customer Responsibilities

Customers are responsible for their own collection and use of personal data, the lawfulness of their instructions, and matters within their control.

These matters include their users, content, configurations, integrations, notices, and consents.

Third-Party Services

AI Super is not responsible for a customer’s unlawful use or unauthorised configuration of the Services, or for the independent acts and omissions of third-party platforms outside our reasonable control.

Nothing in this Policy excludes or limits any responsibility that cannot lawfully be excluded or limited.

21. Changes of Business Ownership

If AI Super undergoes a merger, acquisition, restructuring, financing, sale of assets, insolvency proceeding, or similar transaction, personal data may be disclosed or transferred as part of that transaction.

We will require the recipient to handle personal data consistently with applicable law and will provide notice where required.

22. Data Protection Officer and Contact Information

Questions, requests, complaints, and notices concerning this Policy or personal data may be directed to:

Data Protection Officer

AI Super Private Limited

Email: hello@asi.sg

Phone: +65 8085 8100

Address: 60 Paya Lebar Road, #11-22, Paya Lebar Square, Singapore 409051

To help us respond, please provide:

Your name and contact details.

Your relationship with AI Super or the relevant customer.

Sufficient information to identify the personal data or issue concerned.

We may request additional information to verify your identity or authority.

23. Updates to This Policy

We may update this Policy from time to time to reflect changes in our Services, practices, providers, or legal obligations.

The latest version will be published with its updated effective date. Material changes may also be communicated through the Services or other appropriate channels.

Return to Home

WhatsApp