Personal Data Protection Act (Singapore) Notice

BizLiveGo Singapore PDPA Privacy Notice

Specific statutory privacy disclosure for individuals located in the Republic of Singapore pursuant to the Personal Data Protection Act 2012 (PDPA). Outlining our operational compliance with the 11 Data Protection Obligations, strict NRIC collection bans, overseas transfer parity, and mandatory breach reporting to the PDPC.

Data Controller: BizLiveGo | Operator: MD Joshim Biswas | Malda, WB, India - 732206 | Version: 2026.1

1. Statutory Framework

Application to Singapore Users

This Notice governs the collection, use, disclosure, and cross-border transfer of personal data by BizLiveGo concerning individuals located in the Republic of Singapore, pursuant to the Personal Data Protection Act 2012 (PDPA).

BizLiveGo functions as an Organization under the PDPA for personal data collected during account registration, profile publication, and service subscriptions, ensuring full institutional accountability.

2. Scope & Do Not Call (DNC)

Commercial Profiling & DNC Provisions

BizLiveGo respects user preferences regarding voice, SMS, and messaging communications:

  • Do Not Call (DNC) Registry: BizLiveGo does not engage in telemarketing or send unsolicited commercial voice/fax communications to Singapore numbers.
  • Electronic Messaging: Transactional communications, billing receipts, and profile recovery notices are sent strictly pursuant to contract execution.
  • Marketing Opt-In: Informational newsletters require explicit opt-in consent with functional one-click unsubscribe links.
3. Legal Pillars

The 11 Data Protection Obligations Under the PDPA

How BizLiveGo operationalizes compliance with the foundational obligations of Singapore data law:

1. Consent Obligation

Collecting, using, or disclosing data only with explicit consent, allowing easy withdrawal upon reasonable notice.

2. Purpose Limitation

Processing data only for purposes that a reasonable person would consider appropriate in the circumstances.

3. Notification Obligation

Notifying individuals of the purposes for collection, use, or disclosure on or before collecting their data.

4. Access & Correction

Providing access to personal data and disclosures within the past year, and correcting errors as soon as practicable.

5. Accuracy Obligation

Taking reasonable steps to ensure personal data is accurate and complete if used for decision-making.

6. Protection Obligation

Making reasonable security arrangements (TLS 1.3, AES-256) to prevent unauthorized access or disclosure.

7. Retention Limitation

Ceasing retention or disposing of data once the purpose is no longer served and legal retention is expired.

8. Transfer Limitation

Transferring data overseas only where recipients provide a standard of protection comparable to the PDPA.

9. Accountability Obligation

Designating an accessible DPO, implementing data policies, and maintaining internal audit readiness.

10. Data Breach Notification Obligation

Notifying the Personal Data Protection Commission (PDPC) and affected individuals within prescribed timeframes for notifiable breaches.

11. Data Portability Obligation

Transmitting individual data in our possession to another organization in a commonly used machine-readable format upon request.

PDPC Advisory Guidelines on NRIC

4. Strict Exclusion of Singapore NRIC, FIN & Official Government IDs

In strict compliance with the PDPC's Advisory Guidelines on the Collection, Use, and Disclosure of NRIC and other National Identification Numbers, BizLiveGo prohibits the collection or storage of official Singapore identity records:

Strictly Prohibited Singapore Identifiers

Users and clients must never submit, display, or upload:

  • National Registration Identity Card (NRIC) numbers or Foreign Identification Numbers (FIN).
  • Birth Certificate numbers, Singapore Passport numbers, or Work Permit identity cards.
  • Photocopies, scans, or physical card images of NRIC/FIN identification cards.
  • Raw banking card CVVs, private banking PINs, or confidential password keys.

Voluntary Sensitive Parameters

Specialized public directory entries (e.g., blood group donor networks, matrimonial resumes):

  • Processed strictly on the basis of explicit affirmative opt-in consent.
  • Completely shielded from commercial marketing pixels and external audience discovery.
  • Expunged immediately upon user deletion request without secondary retention.
5. Cross-Border Safeguards

Transfer Limitation Obligation (Overseas Parity)

How BizLiveGo satisfies Regulation 10 of the Personal Data Protection Regulations when routing data outside Singapore:

1. Primary Storage (India)

Core application databases and user account configurations are hosted in secure, certified cloud clusters in India (Mumbai / Bengaluru regions).

Protected by legally binding agreements providing a standard of protection comparable to the PDPA.

2. Global Edge CDN (Cloudflare)

Static media assets, profile layouts, and dynamic QR SVG images are cached on Cloudflare's international edge nodes (including Singapore edge locations).

Ensures lightning-fast local performance across Singapore and Southeast Asia.

3. Contractual Due Diligence

All cloud infrastructure sub-processors execute enforceable Data Processing Addendums containing standard data protection clauses that mirror the requirements of the PDPA.

6. Individual Rights

Access, Correction & Portability Workflows

Singapore users maintain statutory rights under the PDPA:

  • Self-Service Updates: Edit business listings, hours, catalogs, and images in real time via user settings.
  • Right to Access: Obtain confirmation of personal data held and records of how data has been used or disclosed within the past 12 months.
  • Data Portability: Export structured account and profile records in machine-readable JSON, CSV, and PDF packages.
  • Response Window (7–15 Days SLA): Requests are executed within our standard 7 to 15 working days SLA (well within the PDPA 30-day statutory limit).
7. Incident Management

Mandatory Data Breach Notification (Part 6A)

BizLiveGo maintains an automated incident response protocol under Part VIA of the PDPA:

  • Notifiable Thresholds: Breaches that result in, or are likely to result in, significant harm to individuals, or affect 500 or more individuals.
  • PDPC Notification Window: Notified as soon as practicable, and no later than 3 calendar days after determining that a breach is notifiable.
  • Affected Individuals: Notified as soon as practicable concurrently with or after the PDPC notice where significant harm is likely.
8. Designated Authority

Designated Data Protection Officer & Redressal Desk

In accordance with Section 11(3) of the PDPA, BizLiveGo has appointed an accessible Data Protection Officer (DPO):

Data Protection Officer (DPO) Contact

Appointed DPO: Joshim Biswas

Role: Lead Data Protection Officer & Compliance Lead, BizLiveGo

Official Compliance Email: support@bizlivego.com

Direct Helpline / WhatsApp: +91 7001100494

Headquarters: Masimpur, Post-Mosimpur, P.S. Kaliachak, Malda, West Bengal, India - 732206

Personal Data Protection Commission (PDPC) Escalation

We acknowledge privacy inquiries within 24 to 48 hours and resolve issues within our 7 to 15 working days SLA.

If you believe our processing infringes the PDPA and your complaint has not been resolved satisfactorily, you may file a complaint with the Personal Data Protection Commission (PDPC):

  • Website: www.pdpc.gov.sg
  • Address: 10 Pasir Panjang Road, #03-01 Mapletree Business City, Singapore 117438
Quick Summary

Singapore PDPA Privacy Notice Quick Reference

Consolidated review of Singapore privacy governance, PDPA obligations, and operational benchmarks:

Compliance Dimension BizLiveGo Operational Implementation PDPA Legal Reference
Primary Governing Statute Personal Data Protection Act 2012 (PDPA) & Personal Data Protection Regulations. Act 26 of 2012
11 Protection Obligations Comprehensive adherence to all 11 core data protection obligations. Parts III to VIA
NRIC / FIN Collection Strictly prohibited; national identity numbers and card scans are barred. PDPC Advisory Guidelines
Overseas Transfer Parity Primary cloud hosting in India; edge CDN worldwide; secured via enforceable DPAs. Transfer Limitation Obligation
Breach Notification Window Notifiable breaches reported to PDPC within 3 calendar days; individuals notified. Part VIA (Mandatory Breach)
Data Subject Rights SLA Access, correction, and portability fulfilled within 7 to 15 working days. Access & Correction Obligation
Do Not Call (DNC) Rules Zero telemarketing; transactional and essential service communications only. Parts VIII & IX
Appointed DPO Joshim Biswas, permanently reachable at support@bizlivego.com. Accountability Obligation

Singapore Privacy Enquiries & DPO Contact Desk

If you have questions regarding our compliance with the PDPA, wish to submit an access or correction request, or need assistance from our Data Protection Officer, contact our privacy desk.

Data Protection Officer: Joshim Biswas | Location: Masimpur, Kaliachak, Malda, West Bengal, India - 732206