How Voltade protects personal data in compliance with Singapore's Personal Data Protection Act 2012 (PDPA): governance, safeguards, sub-processors, transfers, breach response, and retention.
Version 1.0 · Effective 3 August 2026 · Approved by the Management of Voltade Pte. Ltd.
Voltade Pte. Ltd. ("Voltade", UEN 202307668E) processes personal data in compliance with the Personal Data Protection Act 2012 of Singapore ("PDPA") and, where applicable to customer engagements, other data protection regimes such as the EU General Data Protection Regulation (GDPR). This policy applies to all personal data handled by Voltade (that of our customers, our customers' end users, our employees, and our business partners), whether processed electronically or otherwise, and binds all Voltade employees and contractors.
It complements our public Privacy Policy (the notice to individuals) and our Security Policies (the technical controls). Where Voltade processes personal data on behalf of a customer, Voltade acts as a data intermediary and processes such data only on the customer's instructions and for the contracted purposes.
Voltade has designated a Data Protection Officer ("DPO") in accordance with section 11(3) of the PDPA. The DPO is responsible for ensuring Voltade's compliance with the PDPA, maintaining this policy, handling data protection enquiries and complaints, and coordinating breach response. The DPO reports to Voltade's management, which retains overall accountability for data protection.
The DPO can be reached at [email protected] (Attn: Data Protection Officer).
Voltade maintains security arrangements to protect personal data against unauthorised access, collection, use, disclosure, copying, modification, disposal, and loss, including:
The full control set is documented in our Security Policies and summarised in the Trust Centre.
This policy is disseminated to all employees and contractors. Every new joiner receives data protection and security awareness training during onboarding, with an annual refresher for all staff. Access to customer personal data is granted only to personnel who need it to deliver the contracted services, and such access is logged.
Voltade engages a small number of vetted sub-processors to deliver its services, listed publicly in our sub-processor register. For each sub-processor:
Personal data is stored primarily in the AWS Asia Pacific (Singapore) region. Where a processing step involves a transfer outside Singapore, for example, AI inference by a model provider, Voltade complies with the PDPA's transfer limitation obligation (section 26): transfers occur only to recipients bound by legally enforceable obligations (contractual clauses and data processing agreements) that provide a standard of protection comparable to the PDPA. Destination and provider details per service are documented in Data Residency & AI Infrastructure.
Voltade maintains a breach response process aligned with Part 6A of the PDPA:
Voltade has experienced no data breach or cyber security incident to date. A copy of the detailed breach response runbook is available to customers on request via [email protected].