Privacy Policy
Sarong Partners ("we", "us", or "our") is committed to handling your personal data responsibly and in accordance with Singapore's Personal Data Protection Act 2012 (PDPA). This Privacy Policy describes how we collect, use, disclose, and protect personal data in connection with our legal services and this website.
If you have any questions about this policy or how your data is handled, please contact us at [email protected].
1. Data Controller
Sarong Partners
71 Ayer Rajah Crescent, #06-14, Block 71, Singapore 139951
Phone: +65 6483 7152
Privacy enquiries: [email protected]
2. Personal Data We Collect
We collect only the personal data necessary to provide our legal services and respond to enquiries. This may include:
Contact and Identity Information
Full name, email address, phone number, and company name provided through our contact form or during a client engagement.
Service-Related Information
Details shared in the context of obtaining legal services, such as corporate structure, funding arrangements, or employment terms.
Website Usage Data
Technical data collected via cookies and analytics tools, including IP address, browser type, pages visited, and session duration. See our Cookie Policy for details.
Communication Records
Correspondence by email, phone, or post for the purpose of responding to and managing your enquiry or engagement.
3. Legal Basis for Processing
Under the PDPA, we process your personal data based on one or more of the following grounds:
- Consent — where you have provided voluntary, informed consent, such as when submitting our contact form or accepting optional cookies.
- Contract performance — when processing is necessary to fulfil a legal services engagement you have entered into with us.
- Legitimate interests — where we have a legitimate business interest that does not override your rights, such as improving our services or preventing fraud.
- Legal obligation — where processing is required to comply with Singapore law, court orders, or regulatory requirements.
4. How We Use Your Data
Personal data collected is used for the following purposes:
- Responding to initial enquiries and scoping legal service requests
- Preparing, delivering, and managing legal documentation and advice
- Communicating important updates related to your matter
- Processing payments and maintaining proper billing records
- Improving and securing our website based on aggregated usage data
- Complying with our professional obligations under Singapore law
- Sending relevant updates about our services (only where you have opted in)
We do not use your data for automated decision-making or profiling in a manner that produces significant legal or material effects on you.
5. Data Sharing and Disclosure
We do not sell your personal data. We may share it in limited circumstances:
Technology Service Providers
We use third-party platforms for website analytics (Google Analytics), email delivery, and document management. These providers access only the minimum data required to operate their services under appropriate data processing agreements.
Regulatory and Legal Requirements
We may disclose personal data if required by Singapore law, court order, or regulatory authority. As a legal practice, we are also subject to professional confidentiality obligations that provide additional protection for client information.
Business Transfers
If the firm undergoes a merger, acquisition, or transfer of practice, personal data held may transfer to the successor entity, subject to equivalent data protection obligations.
6. Data Retention
We retain personal data only as long as necessary for the purposes for which it was collected:
| Data Type | Retention Period |
|---|---|
| Client engagement records | 7 years post-engagement |
| Contact form submissions (no engagement) | 12 months |
| Website analytics data | Up to 24 months |
| Marketing communication preferences | Until opt-out or 3 years |
| Payment and billing records | 7 years (statutory requirement) |
After the retention period, data is securely deleted or anonymised.
7. Data Protection Measures
Encryption
Data in transit is protected via TLS encryption. Sensitive documents are stored using encrypted file systems.
Access Controls
Access to client data is restricted to team members directly involved in your matter, on a need-to-know basis.
Regular Review
We conduct periodic reviews of our data handling practices and update them in response to changes in legislation or risk profile.
Breach Response
In the event of a data breach, we will notify affected individuals and the PDPC in accordance with Singapore's mandatory breach notification obligations.
8. Cookies
We use cookies and similar technologies to operate our website and, where you consent, to analyse usage and improve our content. For a full explanation of the types of cookies we use and how to manage your preferences, please see our Cookie Policy.
9. Your Rights
Under the PDPA and general data protection principles, you have the right to:
- Access — request a copy of the personal data we hold about you.
- Correction — request that inaccurate or incomplete data be corrected.
- Withdrawal of consent — withdraw consent for non-essential processing at any time without affecting the lawfulness of prior processing.
- Data portability — where technically feasible, request your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interests where you believe your rights override those interests.
- Complaint — lodge a complaint with the Personal Data Protection Commission (PDPC) of Singapore if you believe your data has been mishandled.
To exercise any of these rights, contact [email protected]. We will respond within 30 days. Some rights may be subject to professional confidentiality obligations.
10. Third-Party Links
Our website may contain links to external resources, government portals, or industry organisations. We are not responsible for the privacy practices of those websites and recommend reviewing their policies before submitting any personal data.
11. Children's Privacy
Our services are directed at businesses and adult individuals (18 years and above). We do not knowingly collect personal data from persons under the age of 18. If you believe a minor has provided us with their data, please contact us and we will arrange for its prompt deletion.
12. Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the services we offer. When we make material changes, we will update the "Last Updated" date at the top of this page. We encourage you to review this policy periodically. Continued use of our website after any update constitutes acceptance of the revised terms.
13. Contact for Data Enquiries
Reach Our Privacy Team
For data access requests, corrections, consent withdrawals, or any other privacy-related question, please get in touch using the details below. We aim to respond within 30 business days.