
PRIVACY
Privacy Policy
How we handle personal data under Singapore PDPA.
Last updated: 3 August 2026
Reach Spark Pte. Ltd. respects your privacy under Singapore's Personal Data Protection Act. This policy describes how we collect, use and protect personal data when you visit reachsparkpro.pro or contact our Duxton studio.
1. Organisation identity
Reach Spark Pte. Ltd. ("we", "us") is the data controller for personal data collected through reachsparkpro.pro. Our registered office is 30 Duxton Road, #02-01, Singapore 089494. For data protection enquiries contact [email protected].
2. Purposes of collection
We collect personal data only for defined purposes: responding to contact-form enquiries; maintaining essential site security logs; storing cookie preferences you choose; and, if you consent, measuring anonymous site usage through analytics cookies. We do not sell personal data or use it for unrelated marketing without consent.
3. Legal bases and consent
Under the Personal Data Protection Act 2012 (PDPA) of Singapore, we rely on consent for contact-form submissions and optional analytics cookies. Essential cookies and security processing rely on legitimate interests necessary to operate the site safely. You may withdraw consent for optional cookies at any time via the cookie banner or browser settings.
4. Categories of data
Contact forms may collect your name, email address, subject selection and message content. Server logs may include IP address, browser user-agent, request timestamps and referring page. Cookie preferences are stored locally in your browser. Analytics cookies, if accepted, may collect aggregated page views and session duration without identifying you by name in our reports.
5. Retention
Contact-form correspondence is retained only as long as needed to respond and maintain reasonable business records, typically up to twenty-four months unless a longer period is required for dispute resolution. Security logs rotate on a short cycle. Cookie consent choices are stored for six months before the banner reappears. Analytics data follows vendor retention schedules described in our cookie policy.
6. Access, correction and withdrawal
You may request access to personal data we hold about you, ask for correction of inaccurate data, or withdraw consent for optional processing. Write to [email protected] with sufficient detail for us to locate your records. We respond within reasonable timeframes consistent with PDPA guidance from the Personal Data Protection Commission (PDPC).
7. Disclosure to third parties
We use hosting providers and email transport that may process data on our behalf under contractual safeguards. Google Maps embedded on site pages may set third-party cookies and collect usage data according to Google's policies. We do not disclose contact details to unrelated third parties except where required by applicable law or with your explicit consent.
8. Google Maps embed
Pages on this site embed a Google Maps iframe showing our Singapore address. Loading the map may cause your browser to connect to Google servers and accept Google's terms. Google may collect device identifiers, approximate location derived from IP address and interaction data. You can avoid this by blocking third-party cookies. See Cookies for detail.
9. International transfers
Primary hosting and correspondence handling are oriented to Singapore. Where subprocessors store data outside Singapore, we assess adequacy and contractual protections consistent with PDPA cross-border transfer requirements.
10. Security measures
We apply proportionate technical and organisational measures: HTTPS transport, rate limiting on forms, honeypot spam filtering, minimal data collection and restricted access to mailboxes. No method of transmission is perfectly secure; please avoid sending highly sensitive identifiers through the general contact form.
11. Children
This site is intended for adults making business or reading enquiries. We do not knowingly collect personal data from children under thirteen without parental consent.
12. Changes to this policy
We may update this policy to reflect legal or operational changes. Material updates will adjust the "Last updated" date above. Continued use after changes constitutes acknowledgement of the revised policy where permitted by law.
13. Complaints
If you believe we have handled your personal data improperly, contact us first at [email protected]. You may also refer matters to the Personal Data Protection Commission (PDPC) in Singapore if unresolved.
14. Marketing communications
We do not send unsolicited marketing email to contact-form submitters unless you explicitly opt in during a separate consent flow. Routine enquiry replies are service messages, not marketing broadcasts. You may ask us to stop non-essential follow-up at any time.
15. Automated decision-making
We do not use automated decision-making or profiling that produces legal or similarly significant effects on individuals. Form spam filtering uses simple rate limits and honeypot fields — not behavioural scoring.
16. Data minimisation practice
We collect only fields necessary to respond to your message: name, email, subject selection and message body. Please do not include national identification numbers, full payment card details or medical records in the contact form. If you must share sensitive documents, wait for a secure channel agreed in direct correspondence.
17. Breach notification
If a personal data breach likely to cause significant harm occurs, we will assess notification duties under PDPA and contact affected individuals and the PDPC where required. We maintain internal incident notes and corrective actions for hosting or mail transport failures.
18. Relationship to Terms and Cookies
This Privacy Policy should be read alongside our Terms of Use and Cookie Policy. Where cookies process personal data, both documents apply. Conflicts are resolved in favour of more specific cookie disclosures for analytics and map embeds.
19. Language
This policy is published in English (Singapore). Translations for convenience do not override the English version if meaning diverges.
20. Contact summary
Data controller: Reach Spark Pte. Ltd., 30 Duxton Road, #02-01, Singapore 089494. Email: [email protected]. General enquiries: [email protected]. We aim to acknowledge data subject requests within five business days and complete reasonable requests within thirty days unless complexity requires extension with notice.
21. Personal Data Protection Act overview
Singapore's Personal Data Protection Act 2012 establishes baseline obligations for organisations collecting, using and disclosing personal data. Reach Spark Pte. Ltd. complies with the Act's consent, purpose limitation, notification, access and correction, accuracy, protection, retention limitation, transfer limitation and openness principles. We review practices when PDPC guidance updates and adjust this policy accordingly.
22. Purpose limitation in practice
Data collected through the contact form is used solely to respond to your enquiry, maintain reasonable correspondence records and improve form reliability. We do not repurpose contact details for unrelated marketing lists. Analytics data, if consented, is aggregated for structural improvements — for example identifying which pages readers reach before writing in.
23. Accuracy and correction
Please provide accurate contact details so we can reply. If your email address changes after submitting a form, send an update to [email protected]. We correct factual errors in stored correspondence when verified.
24. Protection measures detail
Transport security uses HTTPS. Forms apply honeypot and rate-limit controls. Mailboxes are access-controlled. Hosting providers are selected for reasonable security certifications. Staff with mailbox access are instructed on confidentiality and PDPA basics.
25. Retention schedule examples
General enquiries: up to twenty-four months from last message. Reprint or permission threads: duration of permission plus twelve months. Security logs: rolling thirty to ninety days depending on host configuration. Cookie consent JSON: six months in browser storage.
26. Third-party processor assessment
Before engaging subprocessors handling personal data, we assess data handling descriptions and contractual clauses requiring confidentiality and security. Google Maps is used as an embed without passing your form data to Google — only standard embed requests when you load the map.
27. Your responsibilities
Do not submit third-party personal data without their consent. Do not use the form for bulk automated submissions. Report suspected misuse of your correspondence to [email protected] promptly.
28. Policy archive
Prior versions may be available on request for compliance reviews. The current version always appears on this page with the last-updated date at the top.
29. Definitions
"Personal data" means data about an individual who can be identified from that data or from that data and other information we possess. "Processing" includes collection, storage, use and disclosure. "Consent" means voluntary agreement obtained under PDPA standards — clear, informed and revocable.
30. Regulatory context
The Personal Data Protection Commission publishes advisory guidelines on topics including notification, consent and data breach management. We align internal checklists with current guidance and update this policy when material guidance changes affect how we operate reachsparkpro.pro.
31. Contact-form field purposes
Name: to address you correctly in replies. Email: to respond and maintain correspondence thread. Subject: to route your enquiry internally. Message: to understand your request. Consent checkbox: to record PDPA agreement before processing. Honeypot field: ignored if empty; if filled, submission is treated as spam without processing.