Privacy Policy

CLOUD SERVICE HOSTING – DATA INTERMEDIARY PRIVACY POLICY

1. INTRODUCTION

1.1 This Privacy Policy (this "Policy") sets out how Cloudigo Technology Limited (the "Company," "we," "us," or "our") collects, uses, discloses, processes, and protects personal data when we provide cloud service resource hosting services to you/your organization ("you" or "your").

1.2 In the context of the hosting services provided under the Cloud Service Hosting User Notice (the "Principal Agreement"), we act as a data intermediary – which, under the Singapore Personal Data Protection Act 2012 (the "PDPA"), is the equivalent of a "data processor" – processing personal data on your behalf and for your purposes, pursuant to a written contract between us.

1.3 You, as our customer, are the data controller (or "organisation") and remain solely responsible for complying with all obligations under the PDPA in respect of personal data processed by us on your behalf. As a data intermediary, we are only subject to the Protection Obligation, Retention Limitation Obligation, and Data Breach Notification Obligation under the PDPA, to the extent applicable to a data intermediary.

1.4 This Policy applies to personal data that you provide to us or that we process on your behalf in connection with the hosting services. It does not apply to personal data that we collect directly from you for our own business purposes (e.g., billing, customer relationship management), which is governed by our separate corporate privacy policy.

1.5 By engaging us to provide hosting services and providing personal data to us, you acknowledge that you have read, understood, and agreed to the practices described in this Policy.

2. DEFINITIONS

2.1 In this Policy, unless the context otherwise requires:

Term Definition

"Personal Data" Has the meaning ascribed to it under the PDPA, being data, whether true or not, about an individual who can be identified from that data, or from that data and other information to which the organisation has or is likely to have access.

"Processing" Has the meaning ascribed to it under the PDPA, including collecting, recording, holding, organising, adapting, using, disclosing, erasing, and destroying personal data.

"Data Controller" The organisation that determines the purposes and means of processing personal data.

"Data Intermediary" Has the meaning ascribed to it under the PDPA, being an organisation that processes personal data on behalf of and for the purposes of another organisation pursuant to a contract.

"Cloud Provider" Has the meaning ascribed to it in the Principal Agreement.

"Hosting Services" The cloud service resource account creation, configuration, permission management and other hosting services described in the Principal Agreement.

"LLM Services" Has the meaning ascribed to it in the Principal Agreement.

"LLM Provider" Has the meaning ascribed to it in the Principal Agreement.

3. PERSONAL DATA WE PROCESS ON YOUR BEHALF

3.1 In the course of providing the Hosting Services, we may process the following categories of personal data on your behalf:

(a) Account Credentials: Cloud provider account usernames, passwords, access keys (AK/SK), LLM API Keys, and other access credentials necessary for us to manage cloud resources on your behalf.

(b) Identity and Contact Information: Names, email addresses, phone numbers, and other contact details of your designated representatives or authorised personnel.

(c) Cloud Resource Configuration Data: Information contained in cloud resource configurations that may include personal data (e.g., database contents, application logs, user directories).

(d) Billing and Payment Information: Information necessary for cloud provider billing, to the extent it contains personal data.

(e) LLM Input Data and Output Content: Prompts, instructions, files, and other data in any form submitted by you or your authorised users to the LLM Services, as well as the text, code, images, and other content in any form generated and returned by the LLM Services based on such input data (to the extent such data or content contains personal data).

(f) Other Personal Data: Any other personal data that you upload to, store in, or process through the cloud resources we manage on your behalf.

3.2 We do not proactively collect or access personal data beyond what is necessary to perform the Hosting Services. We do not control the content of the data you store in cloud resources, and we have no knowledge of, and assume no responsibility for, the specific personal data contained therein.

4. PURPOSES OF PROCESSING

4.1 We process personal data solely for the following purposes:

(a) Provision of Hosting Services: To create, configure, manage, and maintain cloud service resources as instructed by you.

(b) Account and Permission Management: To set up and manage user accounts, permissions, and access controls in accordance with your instructions.

(c) LLM Service Calls: To invoke LLM Services through cloud provider APIs as instructed by you, and to submit input data to LLM Providers for processing.

(d) Security and Monitoring: To monitor cloud resources for security threats, detect unauthorised access, and protect against fraud, abuse, and technical issues that could compromise your data.

(e) Technical Support: To respond to your support requests, troubleshoot issues, and perform maintenance activities.

(f) Compliance: To comply with applicable laws, regulations, or valid legal orders, or to enforce our rights under the Principal Agreement.

(g) Billing and Administration: To facilitate payment of cloud provider infrastructure fees and our service fees.

4.2 We will not process personal data for any purpose other than those set out above without your prior written instruction or consent except as may be required by applicable law or competent regulatory authority.

5. DATA PROTECTION OBLIGATIONS (PDPA COMPLIANCE)

5.1 As a data intermediary, we are subject to the following obligations under the PDPA:

(a) Protection Obligation: We shall make industry-standard security arrangements to protect personal data in our possession or under our control against unauthorised access, collection, use, disclosure, copying, modification, disposal, or similar risks.

(b) Retention Limitation Obligation: We shall not retain personal data longer than is necessary for the purposes for which it was processed, and shall cease to retain such data or anonymise it when it is no longer required.

(c) Data Breach Notification Obligation: In the event of a data breach involving personal data processed on your behalf, we shall notify you as soon as practicable and provide all reasonably available information to assist you in fulfilling your obligations under the PDPA (including notifying the Personal Data Protection Commission and affected individuals, where required).

5.2 You, as the data controller, remain solely responsible for:

(a) Obtaining all necessary consents from individuals whose personal data is processed;

(b) Complying with all other obligations under the PDPA, including the Access Obligation, Correction Obligation, Accuracy Obligation, and Transfer Limitation Obligation; and

(c) Notifying affected individuals and the Personal Data Protection Commission of any notifiable data breach.

6. SECURITY MEASURES

6.1 We implement and maintain comprehensive technical and organisational security measures to protect personal data, including:

(a) Access Control: Restricting access to personal data to only those personnel who require such access to perform their duties, and maintaining detailed access logs.

(b) Encryption: We may, in our sole discretion, apply industry-standard encryption to data in transit and at rest. In making such determination, we shall consider industry practices, technical feasibility, and cost-benefit considerations.

(c) Authentication: Requiring multi-factor authentication (MFA) for access to critical systems and accounts.

(d) Audit Logging: Maintaining comprehensive audit logs of all operations performed on cloud resources, including who performed the operation, when, and from which IP address.

(e) Regular Security Assessments: Conducting periodic security reviews and vulnerability assessments of our systems and processes.

(f) Incident Response: Maintaining an incident response plan to detect, contain, and remediate security incidents in a timely manner.

6.2 We rely on the security measures implemented by the Cloud Providers and LLM Providers whose infrastructure and services we use. In the course of selecting Cloud Providers and LLM providers, we will evaluate and consider the security qualifications and compliance certifications held by such suppliers, but we do not control and are not responsible for the underlying security of Cloud Provider or LLM Provider infrastructure.

7. DATA RETENTION AND DELETION

7.1 We retain personal data processed on your behalf only for as long as we reasonably determine necessary to fulfil the purposes set out in Section 4 above, or as otherwise required or permitted by applicable law. The Company shall have no obligation to retain any personal data beyond the period it determines is necessary for the performance of the Hosting Services, unless otherwise agreed in writing.

7.2 Upon termination of the Hosting Services or upon your reasonable request in writing:

(a) We shall cease processing personal data on your behalf;

(b) We shall return to you or, at your direction, securely delete all personal data processed on your behalf, except to the extent we are required by law to retain such data. The specific time limits and procedures for data return shall be governed by Clause 4.3.5 of the Principal Agreement; and

(c) We shall provide you with a written certification of deletion.

7.3 Please note that personal data stored in cloud resources may be subject to the Cloud Provider's own data retention and deletion policies and timelines. LLM input data and output content may also be subject to the LLM Provider's own data retention policies. We are not responsible for any data retention, deletion, or processing conducted by Cloud Providers or LLM Providers beyond our control.

8. CROSS-BORDER DATA TRANSFERS

8.1 In the course of providing the Hosting Services, personal data may be transferred to, stored in, or processed in countries or territories outside of Singapore where Cloud Providers and LLM Providers operate their data centres (including but not limited to the United States, Japan, Singapore, and other regions where Cloud Providers and LLM Providers maintain infrastructure).

8.2 The PDPA does not mandate data residency within Singapore. You acknowledge that you are solely responsible for the selection of Cloud Providers and regions in which your data is stored, and for ensuring that your data storage choices comply with all applicable data protection laws, including any cross-border transfer restrictions under the PDPA. The Company shall have no obligation to assess, monitor, or ensure the adequacy of data protection levels in any jurisdiction in which you elect to store your data. The Company shall not be liable for any non-compliance arising from your data storage choices.

9. SUB-PROCESSORS

9.1 We engage Cloud Providers (AWS, Alibaba Cloud International, GCP, Byteplus, and others) and LLM Providers (Anthropic, OpenAI, Meta, Google, Alibaba Cloud, Byteplus, DeepSeek, Zhipu, and others) as sub-processors to provide the underlying infrastructure and model services for the Hosting Services and LLM Services.

9.2 We shall:

(a) Enter into written agreements with each sub-processor that impose data protection obligations no less stringent than those set out in this Policy and the Principal Agreement with respect to the specific services performed by such sub-processor;

(b) Remain liable to you for our obligations under this Policy, provided that our liability for any act or omission of a sub-processor shall be limited to our failure to select and monitor such sub-processor; and

(c) Provide you with a list of our sub-processors upon request and notify you of any intended changes to our sub-processors in accordance with the Principal Agreement, provided that such notification shall be at our discretion and shall not be required if, in our opinion, the change does not materially affect our ability to perform the Hosting Services.

10. SPECIAL DATA PROTECTION PROVISIONS FOR LLM SERVICES

10.1 You acknowledge and agree that the use of LLM Services will result in your LLM input data being transmitted to LLM Providers' servers for processing, and that such processing is subject to the LLM Providers' own terms of service and data processing agreements [Clause 2.2.2 of the Principal Agreement].

10.2 We shall use commercially reasonable efforts to propose LLM Providers that offer "zero data retention" commitments or commit not to use customer data for model training purposes [Clause 2.2.3 of the Principal Agreement]. However, we do not control the data processing practices of any LLM Provider, and we make no representation or warranty with respect to any LLM Provider's data usage policies or their compliance with the PDPA [Clause 2.2.3 of the Principal Agreement].

10.3 If you have any objection to a particular LLM Provider's data processing policies, you shall notify us in writing before using the relevant features. You are solely responsible for evaluating any alternative LLM Provider, and we make no representation or warranty with respect to any such provider's data processing policies. If no alternative arrangement can be reached, or if you continue to use the relevant features after such objection, you shall be deemed to have accepted the applicable LLM Provider's policies, and you shall cease using the relevant features only at your own discretion [Clause 2.2.4 of the Principal Agreement].

11. YOUR OBLIGATIONS AS DATA CONTROLLER

11.1 By providing personal data to us or instructing us to process personal data on your behalf, you represent and warrant that:

(a) You have obtained all necessary consents and have all requisite legal bases to collect, use, and disclose the personal data and to instruct us to process it on your behalf;

(b) You have provided all necessary notices to individuals regarding the collection, use, and disclosure of their personal data;

(c) To the best of your knowledge, the personal data you provide to us is accurate, complete, and up-to-date;

(d) Your instructions to us regarding the processing of personal data comply with all applicable laws and regulations; and

(e) Your LLM input data does not contain any unauthorised personal data, trade secrets, source code, API keys, database credentials, or other sensitive information [Clause 4.1.6.1 of the Principal Agreement].

11.2 You shall indemnify and hold us harmless from and against any claims, liabilities, damages, losses, and expenses arising out of or in connection with your failure to comply with your obligations as a data controller under applicable data protection laws or any instruction provided by you to us [Clause 4.1.6.4 of the Principal Agreement].

12. INDIVIDUAL RIGHTS

12.1 Individuals whose personal data is processed by us on your behalf have certain rights under the PDPA, including:

(a) The right to request access to their personal data;

(b) The right to request correction of inaccurate personal data; and

(c) The right to withdraw consent to the processing of their personal data (subject to applicable legal limitations).

12.2 As a data intermediary, we do not have a direct relationship with the individuals whose personal data we process on your behalf. If you receive a request from an individual exercising their rights under the PDPA, you shall forward such request to us in writing, with sufficient detail and supporting documentation to enable us to identify the individual and the data in question. Our assistance shall be limited to locating and retrieving the relevant personal data within our systems and providing such data to you for your review and response. You shall be solely responsible for: (a) verifying the identity of the requester; (b) determining the validity and scope of the request; (c) drafting and delivering the response to the requester; and (d) ensuring compliance with all applicable timeframes and legal requirements. We shall have no obligation to respond directly to any individual or to verify the accuracy or completeness of any data provided. Any assistance provided by us beyond the scope set out above shall be at your expense, and we shall have no obligation to provide such assistance unless and until you have agreed in writing to reimburse us for such costs. We shall not be liable for any failure to render timely assistance arising out of your failure to forward data subject requests promptly or to furnish sufficient information.

12.3 We reserve the right to verify the identity of any individual making a request and, in our sole discretion, may either (i) charge a fee for responding to such request, or (ii) decline to respond to any request that we reasonably consider to be manifestly unfounded, excessive, repetitive, or unduly burdensome, in each case as permitted under the PDPA. For the avoidance of doubt, we shall have no obligation to respond to any request unless and until any applicable fee has been paid in full.

13. DATA BREACH RESPONSE

13.1 In the event of a confirmed or reasonably suspected data breach involving personal data processed on your behalf, we shall:

(a) Notify you as soon as practicable and based on the information reasonably available to us at the relevant time after becoming aware of the breach, as required under the PDPA;

(b) Provide you with reasonably available information about the breach, including the nature of the breach, the categories and approximate number of individuals affected, the categories and approximate number of personal data records affected, and the measures taken or proposed to be taken to address the breach; and

(c) Cooperate with you in investigating the breach and in fulfilling your obligations to notify affected individuals and/or the Personal Data Protection Commission, where required.

13.2 Unless we are required to do so by law or you have specifically instructed us to do so in writing, we shall not notify affected individuals or the Personal Data Protection Commission directly. The decision to notify and the content of any notification shall be made by you, as the data controller.

14. CONFIDENTIALITY

14.1 We shall keep all personal data processed on your behalf strictly confidential.

14.2 Our personnel who have access to personal data shall be bound by appropriate confidentiality obligations, both during and after their employment or engagement with us.

14.3 We shall not disclose personal data to any third party except:

(a) As necessary to perform the Hosting Services (including disclosures to sub-processors as set out in Section 9);

(b) As required by applicable law, regulation, or valid legal order (in which case we shall, to the extent permitted by law, notify you in advance of such disclosure);

(c) With your prior written consent; or

(d) As otherwise expressly permitted under this Policy or the Principal Agreement.

15. AUDIT RIGHTS

15.1 Upon your reasonable written request and at your expense, we shall provide you with access to relevant records and documentation necessary demonstrating our compliance with this Policy and applicable data protection laws, as determined by us in our reasonable discretion, provided that such access does not compromise our confidential information, security practices, or obligations to other customers.

15.2 You shall not exercise your audit rights more than once per calendar year, unless a data breach or regulatory investigation has occurred that reasonably warrants additional audits.

15.3 Any audit shall be conducted during normal business hours, with 10-day prior notice, and in a manner that does not unreasonably disrupt our business operations. The audit shall be conducted by your internal staff or by an independent third-party auditor mutually agreed by both parties, and any findings shall be subject to our review and approval before disclosure.

16. LIMITATION OF LIABILITY

16.1 Our liability for any breach of this Policy or applicable data protection laws shall be governed by and subject to the limitations set out in Clause 6.3 of Section 6 of the Principal Agreement (including the liability caps set forth therein).

16.2 Nothing in this Policy shall exclude or limit liability that cannot be excluded or limited under applicable law.

17. AMENDMENTS

17.1 We reserve the right to amend this Policy from time to time to reflect changes in our practices, legal requirements, or Cloud Provider and LLM Provider rules.

17.2 Any amendments to this Policy will be communicated to you in accordance with the notice provisions set out in Clause 7.1 of Section 7 of the Principal Agreement. Continued use of the Hosting Services after the effective date of any amendment constitutes your acceptance of the amended Policy. It is your responsibility to review the updated Policy periodically. We shall not be liable for any loss or damage arising from your failure to do so.

18. GOVERNING LAW AND DISPUTE RESOLUTION

18.1 This Policy shall be governed by and construed in accordance with the laws of the Republic of Singapore[W1] .

18.2 Any dispute arising out of or in connection with this Policy shall be resolved in accordance with the dispute resolution provisions set out in Section 8 of the Principal Agreement.

19. CONTACT INFORMATION

19.1 If you have any questions, concerns, or requests regarding this Policy or our handling of personal data, please contact us at:

Data Protection Officer (DPO)

Cloudigo Technology Limited

Email: dpo@cloudigo.ai

19.2 If you are an individual whose personal data is processed by us on behalf of one of our customers, please contact that customer (the data controller) directly in the first instance.

20. ACKNOWLEDGEMENT

20.1 By engaging us to provide Hosting Services and by accepting the Principal Agreement, you acknowledge that you have read, understood, and agreed to the terms of this Privacy Policy.