Legal
Privacy Policy
1. Introduction
KangCrime Pte. Ltd. ("KangCrime," "we," "us," or "our") respects your privacy and is committed to protecting personal data in accordance with the Personal Data Protection Act 2012 of Singapore ("PDPA") and applicable subsidiary legislation. This Privacy Policy explains what personal data we collect when you visit kangcrime.pro, submit a growth brief, engage our marketing services, or otherwise interact with us, how we use that data, who we share it with, and the choices available to you.
By using our website or services, you acknowledge that you have read this Privacy Policy. Where consent is required under the PDPA, we will obtain it through clear opt-in mechanisms — for example, the consent checkbox on our contact form labelled consent_pdpa. You may withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice.
This policy applies to personal data processed by KangCrime as a data organisation. It does not cover third-party websites linked from our pages; those sites operate under their own privacy terms.
2. Data controller
The data organisation responsible for personal data collected through kangcrime.pro and our client engagements is:
KangCrime Pte. Ltd.
UEN 202781627M
533 Choa Chu Kang Street 51, #02-16 Limbang Shopping Centre
Singapore 680533
Email: [email protected]
Phone: +65 6769 4173
For data protection enquiries, contact us using the details above with the subject line "PDPA Request."
3. Personal data we collect
We collect only personal data reasonably necessary for the purposes described in this policy. Categories include:
3.1 Data you provide directly
- Contact and identity data: name, job title, company name, email address, telephone number, and mailing address when you submit a growth brief, visit our desk, or correspond with us.
- Enquiry content: messages, service preferences, budget indications, and postcode priorities included in form submissions or briefing documents.
- Consent records: timestamps and affirmative consent flags when you agree to data processing via our web forms.
- Client engagement data: campaign briefs, brand assets, login credentials for platforms you authorise (Google Ads, Meta, GA4), invoicing details, and communication logs during active board engagements.
3.2 Data collected automatically
- Technical data: IP address, browser type and version, device type, operating system, referring URL, pages viewed, and timestamps when you browse kangcrime.pro.
- Cookie data: identifiers stored on your device as described in our Cookie Policy.
3.3 Data from third parties
- Referral partner introductions where you have authorised sharing.
- Publicly available business registry information for verification of corporate clients.
- Advertising and analytics platforms when you have granted us access to your accounts — we process performance metrics, not end-customer PII unless explicitly scoped.
We do not intentionally collect NRIC numbers, financial account numbers, or sensitive health data through our website. If such data is inadvertently submitted, we will delete it upon discovery unless legal obligations require retention.
4. How we use personal data
We use personal data for the following purposes:
- Responding to growth brief submissions and scheduling briefing sessions at our Choa Chu Kang desk.
- Delivering contracted marketing services — local SEO, paid media management, content production, and board reporting.
- Managing client relationships, invoicing, and account administration.
- Improving our website, services, and internal workflows through aggregated analytics.
- Complying with legal obligations, including tax record-keeping and responses to lawful requests from authorities.
- Protecting our rights, property, and safety, and that of our clients and the public, including fraud prevention.
- Sending service-related communications you reasonably expect — board updates, appointment reminders, policy changes.
- Marketing KangCrime services to existing clients and opted-in prospects where permitted by law.
We will not use your personal data for purposes incompatible with those above without notifying you and, where required, obtaining fresh consent.
5. Legal basis and consent
Under the PDPA, we rely on one or more of the following bases:
- Consent: when you tick the PDPA consent checkbox on our contact form or sign a client agreement containing data-processing clauses.
- Contractual necessity: processing required to perform a contract with you or to take pre-contractual steps at your request — for example, preparing a scoped proposal after your brief.
- Legal obligation: processing necessary to comply with Singapore law.
- Legitimate interests: processing that is reasonably necessary for our business operations, balanced against your privacy interests — such as basic website security logging. You may object where applicable.
Withdrawal of consent does not affect the lawfulness of processing conducted prior to withdrawal. Some services cannot be delivered without certain data — we will explain consequences when you withdraw.
6. Disclosure to third parties
We do not sell personal data. We may disclose personal data to:
- Service providers: email hosting, cloud storage, project management, accounting, and IT security vendors bound by confidentiality and data-processing terms.
- Advertising platforms: Google, Meta, and similar providers when managing campaigns on your behalf under your authorised access.
- Professional advisers: lawyers, auditors, and insurers under duty of confidentiality.
- Regulators and law enforcement: when required by applicable law or court order.
- Business transfers: in connection with a merger, acquisition, or asset sale, with notice to affected individuals where practicable.
Third parties may only use personal data for the purposes we specify and must implement appropriate security measures.
7. Cross-border transfers
Some service providers store or process data outside Singapore — commonly in the United States, European Union, or Australia. Where we transfer personal data overseas, we take steps reasonably required under the PDPA to ensure recipients provide a standard of protection comparable to the PDPA. These steps may include contractual clauses, provider certifications, or your explicit consent where appropriate.
8. Retention
We retain personal data only as long as necessary for the purposes collected, unless a longer period is required by law. Typical retention periods:
- Enquiry records: twenty-four months from last contact unless an engagement begins.
- Active client files: duration of engagement plus seven years for financial and contractual records.
- Website logs: twelve months unless needed for security investigations.
- Marketing consents: until withdrawn plus a suppression record to honour opt-out.
When retention expires, we securely delete or anonymise personal data so it can no longer identify you.
9. Security measures
We implement administrative, technical, and physical safeguards appropriate to the sensitivity of personal data, including access controls on a need-to-know basis, encrypted transmission (TLS) for website traffic, password-protected systems, and staff training on PDPA obligations. No method of transmission or storage is completely secure; we cannot guarantee absolute security but will notify you and the Personal Data Protection Commission of Singapore where required if a breach likely to cause significant harm occurs.
10. Your PDPA rights
Subject to exceptions under the PDPA, you may:
- Access personal data we hold about you and information about how it has been used or disclosed in the past year.
- Correct inaccurate or incomplete personal data.
- Withdraw consent for processing that relies on consent.
- Request deletion where retention is no longer necessary and no legal exception applies.
- Data portability — where technically feasible, receive certain data in a structured, commonly used format.
Submit requests to [email protected]. We respond within thirty days unless an extension is permitted. We may charge a reasonable fee for manifestly unfounded or excessive requests. If you are unsatisfied with our response, you may contact the Personal Data Protection Commission of Singapore.
11. Cookies and analytics
Our website uses essential and optional cookies. Optional analytics cookies load only after you accept them via our cookie banner. Details — including how to change preferences — are in our Cookie Policy.
12. Children
Our services are directed at businesses and adults. We do not knowingly collect personal data from individuals under eighteen. If you believe a minor has submitted data, contact us and we will delete it promptly.
13. Policy changes
We may update this Privacy Policy to reflect legal, technical, or business changes. Material updates will be posted on this page with a revised "Last updated" date. Continued use of our website or services after changes constitutes acceptance where permitted by law. For active clients, we will provide direct notice of material changes affecting ongoing processing.
14. Contact our DPO
For privacy questions, access requests, or complaints:
Data Protection Contact
KangCrime Pte. Ltd.
533 Choa Chu Kang Street 51, #02-16 Limbang Shopping Centre, Singapore 680533
[email protected] · +65 6769 4173