Privacy Notice
1. Who We Are
This Privacy Notice describes how BLUECORE TECHNOLOGY PTE. LTD. ("BLUECORE", "we", "us", "our") — a private limited company incorporated in the Republic of Singapore (UEN: to be inserted) — collects, uses, discloses and protects personal data in connection with the BLUECORE AI productivity assistant (the "Service") available at bluecore.tech.
2. What Personal Data We Collect
| Account data | Name, email address, account credentials (hashed), workspace identifier. |
|---|---|
| Identity & verification | Country of residence, IP-based geolocation, and (where required to deter abuse) phone number. |
| Billing data | Billing name, billing address, invoice history. Card numbers are tokenised by our PCI-DSS-certified payment processor and never stored on our systems. |
| Service-usage data | API and console request metadata: timestamps, latency, model called, token counts, error codes, request IDs. |
| Content you submit | The prompts, task descriptions, schedules, and reference documents you provide to the assistant. By default, request and response bodies are retained for up to 30 days solely for abuse-detection, debugging and quality assurance, and are then permanently deleted. |
| Device & log data | Browser type, operating system, language preference, referrer URL, session identifiers. |
| Cookies | Strictly-necessary session cookies, plus optional analytics cookies that you may decline via the cookie banner. |
What we do not collect. We do not request government identification, bank account numbers, brokerage account credentials, social security / NRIC numbers, or biometric data. We do not link to your stock-brokerage accounts and we do not capture real-time stock-exchange market data.
3. How We Use Personal Data
- To provision and operate the Service (authentication, scheduling, request routing, output delivery).
- To detect abuse — fraud, automated scraping, prompt injection, and prohibited content under our Acceptable Use Policy.
- To improve reliability, latency and accuracy of the Service. We do not use customer prompts or outputs to train foundation models.
- To bill, invoice, and meet tax-record obligations under Singapore law.
- To send service announcements and (with your prior consent) product news.
4. Legal Bases under the PDPA
We rely on the following bases under the Personal Data Protection Act 2012 (PDPA): (i) consent for marketing communications and optional analytics cookies; (ii) necessary for the performance of a contract to operate and bill for the Service; (iii) legitimate interests for security, fraud prevention and service improvement, balanced against your rights; and (iv) legal obligation for tax, accounting and law-enforcement requests.
5. Disclosure to Third Parties
We disclose personal data only to:
- Sub-processors we engage to operate the Service — cloud infrastructure (IaaS), payment processing, email delivery, error monitoring, and customer support tooling — each under a written data-protection agreement.
- Upstream AI model providers when you submit a prompt and the assistant calls a third-party model API on your behalf. The provider's own privacy terms apply to that processing; we forward only the data needed to fulfil your request.
- Authorities when compelled by a valid Singapore legal process (or comparable process under a mutual legal assistance arrangement) or to comply with court orders.
- Successors in the event of a merger, acquisition, or sale of substantially all of our assets, in which case the acquirer becomes bound by this Notice.
We do not sell personal data and we do not share it with advertising networks for cross-context behavioural advertising.
6. International Transfers
Where personal data is transferred outside Singapore (for example, when an inference request is routed to an upstream model provider hosted overseas), we comply with the PDPA's Transfer Limitation Obligation by ensuring the recipient is bound by legally enforceable obligations to provide a standard of protection comparable to that under the PDPA.
7. Retention
- Account and billing records: retained for the duration of the account and for 7 years after closure, as required by Singapore tax and accounting law.
- Service-usage metadata: up to 24 months for capacity planning and security analytics.
- Request and response bodies: up to 30 days by default; can be reduced to zero-day retention by enterprise customers under a separate Data Processing Addendum.
- Marketing-consent records: until you withdraw consent, plus 12 months for audit purposes.
8. Your Rights
Under the PDPA you have the right to (i) request access to your personal data, (ii) request correction of inaccurate data, (iii) withdraw consent for any purpose for which we rely on consent, and (iv) lodge a complaint with the Personal Data Protection Commission (PDPC). To exercise these rights, contact our Data Protection Officer at [email protected]. We will verify your request and respond within 30 days.
9. Security
We implement technical and organisational measures appropriate to the risk, including TLS 1.2+ in transit, AES-256 at rest for stored content, least-privilege IAM, audit logging, periodic penetration testing, and a documented incident-response plan. We will notify affected individuals and the PDPC of any data breach in accordance with the PDPA's Data Breach Notification Obligation.
10. Children
The Service is not directed to individuals under 13, and we do not knowingly collect personal data from children under 13. If you believe we have, please contact us and we will delete the data.
11. Changes
We may update this Privacy Notice from time to time. Material changes will be highlighted in-product and via email at least 14 days before they take effect.
12. Contact
Data Protection Officer
BLUECORE TECHNOLOGY PTE. LTD.
Singapore
Email: [email protected]