Definitions
The terms below explain key concepts used in this privacy notice so you can better understand how Zephara Soul handles information when providing AI software development and business AI integration services to clients in Singapore and beyond.
- Personal data means any information that identifies or can be used to identify an individual directly or indirectly, such as name, email address, phone number, job title, or business contact details gathered during project onboarding, support, or marketing communications.
- Processing refers to any operation performed on personal data including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, or erasure. Processing enables us to deliver services, maintain client accounts, and improve AI solutions.
- User refers to any individual who interacts with Zephara Soul services, including prospective clients, registered customers, employees of client organisations, and site visitors who provide contact information or otherwise engage with our digital properties.
- Service means the AI software development, systems integration, consulting, and managed AI solutions that Zephara Soul provides to organisations seeking to adopt business AI capabilities, hosted via client infrastructure or Zephara Soul-managed environments.
- Cookies are small data files placed on a device when visiting a website. We and our third-party partners use cookies and similar technologies to enable the site to function, to analyze usage, and to provide tailored content and service interactions.
What Data We Collect
We collect personal and non-personal data from users through several channels. Collection is limited to data necessary to perform contractual obligations, improve service delivery, and meet compliance requirements. Below are the categories of data we commonly collect.
Data You Provide Directly
When you contact us, request a proposal, sign a contract, or use client-facing services, we may collect the following information to deliver and support our AI solutions efficiently:
- Contact details: name, business email, business phone number, job title, company name and business address (e.g., 22 Malacca Street, Singapore, 048980).
- Project and contractual information: scope descriptions, technical requirements, onboarding documents, and communications platform to design and implement AI solutions.
- Billing and business identifiers: invoicing details, purchase orders, and our Business ID S4988525A when required for administrative and compliance processes.
- Support and performance data: feedback, support tickets, logs shared by clients to troubleshoot integration or performance issues.
- Marketing opt-ins and consents: preferences you set for receiving newsletters, event invitations, or product updates from Zephara Soul.
- Any additional documentation or files you upload in the course of project work, which may include non-sensitive business datasets used to configure AI models under applicable agreements.
Automatically Collected Data
When you visit our website or use certain service tools we may automatically collect information needed to maintain and improve our digital presence and to secure services. This helps us personalise interactions and detect anomalies.
- Device and browser information such as IP address, device type, browser version, and operating system to ensure compatibility and security.
- Usage data: pages visited, time spent on site, referral sources, and interaction patterns that help us optimize website content and service flows.
- Technical logs and diagnostic data for maintenance, debugging, and performance tuning of our web properties and service components.
- Analytics and aggregated behavioral metrics used to evaluate marketing effectiveness and to guide product decisions without exposing individual identities.
- Tracking identifiers stored in cookies or similar technologies consistent with cookie preferences and consent choices.
- Security-related signals, such as failed login attempts and suspicious activity indicators, used to protect accounts and infrastructure.
Data from Third Parties
We may receive information from service providers and partners that support our operations, analytics, and integrations. Third-party data supplements direct data to improve service delivery while respecting contractual limits on use.
- Professional networks and business directories that provide basic contact or company details used to respond to inquiries and verify credentials.
- Cloud hosting and platform providers that supply logs and performance telemetry related to hosted client services or development environments.
- Analytics and marketing partners that provide aggregated reporting to help us measure marketing campaigns and site usage.
Purposes of Processing
We process personal data for a limited set of business purposes that align with contract performance, legitimate interests, and compliance obligations. Each purpose is narrowly tailored to achieve operational needs and client outcomes.
- To provide and manage AI software development projects, including onboarding, technical delivery, and ongoing maintenance of integrations.
- To communicate with clients and prospects about project status, proposals, invoices, and service updates using provided contact details.
- To analyze and improve our products and services by using usage and performance data to refine models, workflows, and user experiences.
- To secure services and detect or respond to incidents, protecting client data and system integrity through monitoring and logging.
- To meet legal, regulatory, and contractual obligations, including recordkeeping, audits, or compliance with law enforcement requests where applicable.
- To process billing, invoicing, and administrative tasks tied to client engagements and our Business ID S4988525A for Singapore operations.
- To send marketing communications where you have opted in, and to manage preferences related to events, reports, and newsletters.
- To enable integrations with client systems and third-party platforms as required to implement AI workflows and data connectors under explicit client instructions.
Legal Basis for Processing
We rely on appropriate legal bases for processing personal data depending on the context and jurisdiction, including contract necessity, legitimate interests, consent where required, and compliance with legal obligations.
- Contract performance: processing necessary to perform contractual obligations when delivering AI development and integration services.
- Legitimate interests: internal business purposes such as security, fraud prevention, direct business communications, and service improvement where those interests do not override individual rights.
- Consent: where required by law, for example certain marketing communications or optional tracking technologies after explicit user consent.
- Legal obligations: processing necessary to comply with legal requirements, audits, tax, or other statutory duties.
Your Rights under Applicable Data Protection Law
For users in jurisdictions where GDPR-style rights apply, Zephara Soul respects the data subject rights outlined by such frameworks and provides mechanisms to exercise those rights in a timely manner.
- Right of access: you may request a copy of personal data we hold about you and details on processing purposes and recipients.
- Right to rectification: request corrections to inaccurate or incomplete personal data.
- Right to erasure: request deletion of personal data when retention is no longer necessary and no overriding lawful basis exists.
- Right to restriction of processing: request limited use of data while a dispute or review is underway.
- Right to data portability: where applicable, request a machine-readable copy of data you provided to us for transfer to another provider.
- Right to object: object to processing based on legitimate interests or direct marketing where applicable, subject to certain exemptions.
Cookies and Tracking Technologies
Zephara Soul uses cookies and similar technologies to operate our site, tailor interactions, and measure performance. You can manage cookie preferences via your browser or our cookie preference controls where available.
We use session cookies (temporary), persistent cookies (stored between visits), and third-party cookies for analytics and marketing. Some cookies are essential for site functionality and cannot be disabled without impacting service performance.
Cookie categories include essential (site operation), performance (analytics and improvements), functionality (preferences), and marketing (advertising and tracking). We strive to limit marketing cookies and obtain consent where required.
Manage cookies through browser settings or the cookie consent tool on our site. To opt out of targeted advertising, use industry tools such as YourAdChoices or adjust settings with specific partners listed in our cookie policy.
View our full cookie policy at vjolrasoul.digital/cookie-policy for current details on technologies and third-party partners.
Sharing and Disclosure of Personal Data
We share personal data only as necessary to deliver services, comply with legal obligations, and operate our business. Where we share, we require recipients to protect data consistent with this policy and applicable law.
- Service providers and subprocessors: cloud hosts, analytics vendors, payment processors, and other vendors that support our operations under contract.
- Clients and project partners: when data is required to implement integrations or when clients supply data to be processed as part of an engagement.
- Legal and regulatory authorities: when required by law, court order, or to respond to valid legal requests.
- Business transfers: in the event of a merger, sale, reorganization, acquisition or bankruptcy, personal data may be transferred as part of business assets.
- Affiliated entities and subcontractors who perform services on our behalf with contractual safeguards in place.
- Aggregated or anonymized information that no longer identifies individuals may be shared freely for analytics or product development purposes.
International Data Transfers
Zephara Soul may transfer data across borders to support global operations, cloud providers, and project delivery. Transfers are subject to safeguards such as standard contractual clauses, data protection agreements, or other appropriate mechanisms to maintain a level of protection consistent with applicable law.
When transferring personal data internationally we implement contractual protections, assess third-party privacy practices, and where required use approved transfer mechanisms to protect data subjects’ rights and maintain security.
Data Retention
We retain personal data for as long as necessary to provide services, comply with legal obligations, resolve disputes, enforce agreements, and as otherwise permitted by law. Retention periods are reviewed periodically and based on legitimate business needs.
Account and contractual records, including contact information and invoicing records, are retained for a period required for contractual and tax purposes, typically a minimum of 7 years where applicable to meet business recordkeeping obligations.
Communications such as proposals, support tickets, and project correspondence are retained for the duration of the engagement and for a reasonable period afterwards to support ongoing service needs and potential follow-up.
System logs and technical telemetry used for security and diagnostics are retained according to internal policies and regulatory requirements, typically for periods between 6 months and 3 years depending on the data type and compliance needs.
When retention periods expire or when a valid deletion request is approved and no legal basis to retain remains, we will securely delete or anonymize personal data in our systems and backups in a controlled manner.
Security Measures
Protecting client and user data is integral to our delivery practices. We implement a combination of administrative, technical, and physical measures appropriate to the sensitivity of data processed, and we continually review controls as technology and threats evolve.
- Access controls and least-privilege access for employees and contractors involved in project delivery and support.
- Encryption of data in transit and at rest for sensitive datasets and secure key management for hosted environments.
- Monitoring, logging, vulnerability assessment, and periodic security reviews to identify and reduce risks to systems and data.
How to Exercise Your Rights
You have a set of rights to control and inquire about personal data that Zephara Soul processes. We provide processes to exercise these rights subject to verification and legal limitations.
- Access: request confirmation whether we process your personal data and request a copy of that data.
- Rectification: request corrections to inaccurate or incomplete personal data held by Zephara Soul.
- Erasure: request deletion of personal data when retention is no longer required and no overriding legal basis exists for continued processing.
- Restriction: request limitation of processing if you contest accuracy or lawfulness while issues are reviewed.
- Portability: where applicable, request a structured, commonly used, machine-readable copy of the personal data you provided.
- Objection: object to processing based on legitimate interests or direct marketing where permitted by law.
- Withdraw consent: withdraw consent for processing activities that rely on consent going forward, without affecting processing performed before withdrawal.
- Complaint: lodge a complaint with a supervisory authority if you believe your rights have been infringed; contact details are available in your jurisdiction.
Access, Correction and Deletion Requests
At Zephara Soul, you can request access to, correction of, or deletion of personal data we hold about you. Submit a clear request describing the records or action you seek. We will verify your identity and process requests in accordance with applicable Singapore data protection requirements and industry practices for AI service providers.
We aim to acknowledge requests within 7 business days and complete routine requests within 30 days. Complex requests that require coordination with third-party providers or extensive review may take longer; we will keep you informed of progress and any reasonable extensions.
Marketing Communications
Zephara Soul may use your contact details to send updates, product news, and invitations to events relevant to AI software development and business AI integration. Communications are tailored to help you evaluate new capabilities, implementation support, and integration services that enhance operational efficiency and decision-making.
You can opt out of marketing communications at any time using the unsubscribe link in emails or by contacting our data protection team. Unsubscribing will not affect transactional messages related to services you actively use.
Children's Privacy
Our services are intended for professionals and businesses. We do not knowingly collect personal information from children under 16. If we become aware that we have collected data from a minor without proper consent, we will take reasonable steps to delete it.
Third-Party Links
Our website and products may link to third-party services, analytics, cloud providers, or integration partners. These third parties have their own privacy practices. Zephara Soul is not responsible for the content or privacy practices of external sites; review third-party policies before sharing personal information.
Changes to This Policy
We periodically review and update our privacy practices to reflect regulatory changes and product evolution. Material changes will be posted on our website at vjolrasoul.digital with an updated effective date. We encourage customers to review this policy regularly to stay informed.