STIDE Pte. Ltd. · Personal Data Protection
Privacy Policy
Last updated: 22 February 2026 (Asia/Singapore)
Introduction and Scope
This Privacy Policy applies to personal data handled by STIDE in connection with: (a) your use of www.stide.asia and any pages that link to this Privacy Policy; (b) enquiries or communications submitted via the website or by email to contact@stide.asia; and (c) related business communications and service delivery interactions.
It does not apply to third-party websites or services that may be linked from our website (see Section 15).
Definitions (plain English)
- âPersonal dataâ generally means data about an individual who can be identified from that data, or from that data and other information to which an organisation has or is likely to have access, in line with the PDPA concept.
- âProcessingâ in this Policy refers to collecting, using, disclosing, storing, and otherwise handling personal data.
- âData intermediaryâ generally refers to a service provider that processes personal data on behalf of an organisation, under the organisationâs instructions (for example, hosting or cloud service providers), as contemplated in PDPC guidance.
What Personal Data We Collect
The personal data we handle depends on how you interact with us. Where practicable, we identify specific fields at the point of collection (for example, on a form).
3.1 Data you provide directly
Depending on your interactions, we may collect personal data you submit to us, which may include:
- Contact and professional identifiers: name, business email, phone number, company/organisation, role/title, business address and similar details.
- Enquiry and correspondence content: messages, attachments, call notes, meeting details, and related communications you send us.
- Client/vendor due diligence information: information required to administer a professional engagement, including invoicing and contract administration information.
- Recruitment information (if applicable): CV/resume, employment history, references, and related information.
3.2 Data collected automatically (website use)
When you visit our website, we may collect limited technical and usage information, which may include: IP address, device identifiers, browser type, operating system, referring page, pages viewed, and date/time of access. Whether we use cookies/analytics tools (and which ones) is stated here. (see Section 6).
3.3 Data from third parties
We may receive personal data from third parties in the context of professional introductions, referrals, service providers, or counterparties, where relevant and permitted. Categories/sources as stated.
How We Collect Personal Data
- Directly from you when you submit forms, send emails, schedule meetings, or communicate with us.
- Automatically through website operation and security logging, and (if implemented) cookies and similar technologies.
- From third parties such as service providers, professional advisers, counterparties, or referrers, where relevant.
Purposes of Collection, Use and Disclosure
We collect, use and disclose personal data for purposes that are reasonable and appropriate in the circumstances and, where applicable, that have been notified to you at or before collection/use/disclosure (for example, in a form notice or engagement documentation), consistent with PDPC guidance on the PDPAâs purpose and notification concepts.
5.1 Core purposes (may include)
- Responding to enquiries: to respond to questions, provide requested information, and follow up on your request.
- Service delivery and administration: to perform and administer professional engagements, including project coordination and communications relevant to those engagements.
- Contracting and billing: to prepare, enter into and manage contracts, invoices, and payments (payment processing arrangements, if any, will be stated).
- Operational, security and risk management: to maintain website security, prevent fraud/abuse, manage access controls, and ensure business continuity.
- Compliance and legal purposes: to comply with applicable laws, respond to lawful requests, enforce our rights, and manage disputes.
5.2 Marketing (if applicable)
Whether STIDE offers a newsletter or marketing updates is optional. If you opt in to receive marketing communications, we may use your contact details to send you updates that you have requested or consented to receive. You may opt out using the mechanism in the message or by contacting us (see Section 13).
Cookies and Similar Technologies
Whether STIDE uses cookies, analytics, or marketing tags on www.stide.asia (and which providers) is stated. If used, cookies and similar technologies may be used to operate the site, remember preferences, perform security functions, and (where implemented) measure site usage and improve performance.
If we deploy non-essential cookies (for example, analytics/marketing cookies), we will typically provide a cookie banner or preference mechanism where appropriate. Please refer to our Cookies Notice at /cookies for details.
Marketing Messages and Do Not Call (âDNCâ) (only where applicable)
If STIDE sends marketing messages to Singapore telephone numbers, the PDPAâs Do Not Call provisions may apply and generally prohibit sending certain marketing messages to Singapore telephone numbers registered on the DNC Registry, subject to applicable exceptions (for example, where clear and unambiguous consent has been obtained), as described by the PDPC.
More information: PDPC âDo Not Call Registry & Your Businessâ and related PDPC guidance.
Disclosure to Third Parties
We may disclose personal data to third parties where necessary for the purposes in Section 5, including:
- Service providers (data intermediaries): hosting, IT support, cloud storage, email systems, CRM, scheduling tools, website analytics (providers: appointed by STIDE).
- Professional advisers: lawyers, auditors, consultants, or other advisers where appropriate for professional, compliance, or dispute-related purposes.
- Counterparties and stakeholders: where relevant to an engagement and consistent with your instructions and the engagement context where required.
- Authorities: where required by applicable law or to respond to lawful requests.
We do not âsellâ personal data as a business model. However, we use third-party service providers in the ordinary course of business operations.
Cross-Border Transfers
STIDE may use service providers or operational arrangements that involve transferring personal data outside Singapore (countries/regions: ASEAN and globally). Where we transfer personal data outside Singapore, we will take steps intended to ensure the transferred personal data is accorded a standard of protection that is comparable to that under the PDPA, consistent with the PDPCâs guidance on the Transfer Limitation Obligation.
Protection / Security
We take reasonable security arrangements to protect personal data in our possession or under our control against unauthorised access, collection, use, disclosure, copying, modification, disposal, or similar risks, and against loss of storage media/devices, consistent with PDPC guidance on the Protection Obligation.
No method of transmission over the Internet or method of electronic storage is completely secure. We therefore cannot guarantee absolute security.
Retention
We retain personal data only for as long as it is reasonably necessary for the purposes for which it was collected (and any legal or business purposes), and thereafter we will cease to retain it or remove the means by which it can be associated with particular individuals, consistent with the PDPCâs guidance on the Retention Limitation Obligation.
Retention periods/approach by data category: Enquiries: up to 24 months from last contact; Client/vendors: 7 years from end of engagement; Website logs: Up to 12 months; Marketing: Until opt-out.
Accuracy
Where personal data is likely to be used to make a decision that affects you, or disclosed to another organisation, we take reasonable steps to ensure it is accurate and complete, consistent with PDPC guidance on the Accuracy Obligation.
Your Rights and Choices
Under the PDPA framework, individuals may request access to and correction of their personal data in an organisationâs possession or under its control, subject to applicable exceptions, as described in PDPC guidance. We will respond as soon as reasonably possible in accordance with the PDPA framework and applicable requirements.
- Access request: you may request a copy of personal data we hold about you and certain information about how it has been used or disclosed in the relevant period, consistent with PDPC guidance.
- Correction request: you may request correction of an error or omission in your personal data.
- Withdrawal of consent: where we rely on consent, you may withdraw consent by contacting us. Withdrawal may affect our ability to provide certain services or respond to requests, depending on the context.
- Marketing preferences: where applicable, you may opt out of marketing communications.
To submit a request, contact our Data Protection Officer (âDPOâ) at: +65 6589 8303, or email dpo@stide.asia. We may need to verify your identity and request additional information to process your request.
Data Breach Management
We maintain processes intended to assess and respond to suspected data breaches. Where a data breach is assessed to be a notifiable data breach under the PDPA framework (for example, where notification thresholds are met), organisations are required to notify the PDPC and/or affected individuals in accordance with the PDPA framework and PDPC guidance. The PDPCâs guide provides that where notification to the PDPC is not made within three (3) calendar days of ascertaining that a breach is notifiable, organisations must provide reasons for late notification.
Reference: PDPC âGuide on Managing and Notifying Data Breaches under the PDPAâ.
Third-Party Links
Our website may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. Please review their privacy notices before providing personal data to them.
Updates to This Policy
We may update this Privacy Policy from time to time. The âLast updatedâ date at the top indicates when this Privacy Policy was last revised. Your continued use of the website after an update constitutes acknowledgment of the updated policy to the extent permitted by applicable law.
Contact (DPO and Complaints)
Data Protection Officer (DPO): Mr Martin Wongpatsakorn
General contact: contact@stide.asia
If you have a concern about how we handle personal data, we encourage you to contact us first so we can try to resolve the issue. You may also contact the PDPC or submit a complaint through the PDPCâs complaints channels, which the PDPC indicates may require Singpass for submission.




















