top of page
3108-AiPrepares.png

Privacy Policy

1. ABOUT THIS PRIVACY NOTICE

Ai Tax Advisors Pte Ltd ("AiTA", "we", "us" or "our") is committed to handling Personal Data in accordance with the Personal Data Protection Act 2012 of Singapore ("PDPA") and other applicable laws.
This Privacy Notice applies to our website, the iTax platform and related services, customer support, business communications, events and recruitment activities (collectively, the "Services").
"Personal Data" means data about an individual who can be identified from that data, or from that data together with other information to which the relevant organisation has or is likely to have access.

2. OUR ROLE AND CUSTOMER DATA

2.1 Information handled for AiTA’s own purposes

AiTA handles certain Personal Data for its own business and operational purposes. This includes information relating to user accounts, customer and prospective customer contacts, billing, support communications, website usage, events and recruitment.
2.2 Customer Data processed on behalf of customers
Customers may use the Services to process accounting, financial, tax and related information concerning their own organisation or other persons or entities that they are authorised to act for or support.
Information and documents submitted by or on behalf of a customer through the Services are referred to in this Privacy Notice as "Customer Data". Customer Data may relate to the customer’s own organisation or to another entity for which the customer is authorised to act.
Customer Data may contain Personal Data relating to directors, officers, employees, customers, suppliers or other individuals connected with the customer, the relevant entity or engagement. The customer determines what Customer Data is submitted, the purpose for which it is processed, who is authorised to access it and how the resulting outputs are used.
When AiTA processes Personal Data contained in Customer Data solely to provide the Services, AiTA generally acts as a data intermediary on behalf of the relevant customer. AiTA processes such Personal Data in accordance with the customer’s instructions, the customer agreement and applicable law.
The customer remains responsible for ensuring that it is authorised to collect, use, disclose and submit the Customer Data to AiTA. AiTA does not ordinarily have a direct relationship with individuals whose Personal Data is contained in Customer Data and may rely on the customer’s instructions and confirmation of authority.
Nothing in this Privacy Notice limits any obligation imposed directly on AiTA under applicable law.
3. PERSONAL DATA WE COLLECT OR RECEIVE
Depending on how an individual or organisation interacts with us, we may collect or receive:

  • account and business contact information, such as names, business email addresses, telephone numbers, organisation details, user roles and account credentials;

  • Customer Data submitted through the Services, which may include accounting, financial, tax and supporting information relating to the customer’s own organisation or another entity for which the customer is authorised to act;

  • billing, subscription and transaction information;

  • communications, enquiries, support information and feedback;

  • event, demonstration, webinar and survey information;

  • job application information; and

  • technical and usage information, such as IP addresses, device and browser information, login information, activity logs, and error or diagnostic information.

We may receive Personal Data directly from an individual, from the individual’s organisation or authorised representative, through Customer Data submitted by a customer, automatically through use of the Services, or from service providers and other lawful sources.
4. PURPOSES FOR WHICH WE HANDLE PERSONAL DATA
We may collect, use, disclose or otherwise process Personal Data for purposes including:

  • providing, administering, maintaining and supporting the Services;

  • creating and managing accounts, access rights, subscriptions and billing;

  • processing Customer Data and producing the services and outputs requested by the customer;

  • responding to enquiries, providing support and communicating service-related information;

  • protecting the security, integrity and availability of our systems and investigating errors, misuse or incidents;

  • evaluating and improving the performance, reliability and usability of the Services;

  • managing business relationships, events and recruitment;

  • complying with legal and regulatory requirements and protecting our legal rights; and

  • other purposes notified to the relevant individual or customer, or otherwise permitted or required by law.

Where practicable, we use aggregated or anonymised information when evaluating and improving the Services. We do not use identifiable Personal Data contained in Customer Data for unrelated purposes unless instructed or authorised by the relevant customer, or otherwise permitted or required by law.
4.1 Redaction feature
Where available, the Services may include a redaction feature that allows a customer to provide specified identifiers, such as a legal entity name, Unique Entity Number (UEN) and directors’ names, for masking in a document. To provide this feature, the Services process the relevant document and the identifiers supplied by the customer.
The redaction feature is intended to support data minimisation. The customer is responsible for providing accurate and sufficiently complete identifiers and for reviewing the resulting document before further use or processing. The feature may not identify or remove every reference, indirect identifier or item of Personal Data and does not guarantee that a document has been anonymised. Use of the feature does not alter the customer’s responsibilities under applicable law.
5. AI AND TECHNOLOGY SERVICE PROVIDERS
The Services may use artificial intelligence, automated processing and other technology services. Information reasonably necessary to provide the relevant feature may be processed by external technology providers on AiTA’s behalf.
We use established cloud and technology service providers, including Microsoft Azure, and may engage providers supporting AI-enabled processing, technical support, payment processing, communications, analytics and business administration. These providers receive or process Personal Data only to the extent reasonably necessary to provide the relevant services to us.
Authorised external developers or technical support personnel may be given limited access to Personal Data where reasonably necessary to maintain the Services, investigate and resolve technical issues or address security incidents. Such access is subject to appropriate restrictions and confidentiality obligations.
6. DISCLOSURE OF PERSONAL DATA
We do not sell Personal Data.
We may disclose or make Personal Data available, where reasonably necessary, to:

  • the relevant customer and users authorised by that customer;

  • cloud, technology, AI, support, payment, communications and other service providers acting on our behalf;

  • professional advisers, such as lawyers, accountants, auditors, insurers and security advisers;

  • government agencies, regulators, courts, law-enforcement authorities or other persons where required or permitted by law; and

  • parties involved in an actual or proposed corporate transaction, subject to appropriate confidentiality safeguards.

Customer Data and outputs are made available within the Services according to access permissions set or authorised by the relevant customer. The customer is responsible for managing its users and access rights.
7. OVERSEAS TRANSFERS
Some of our service providers, systems or support personnel may be located outside Singapore or may process or access Personal Data from outside Singapore. Where Personal Data is transferred outside Singapore, we will take appropriate steps to ensure that it receives a standard of protection that is at least comparable to that provided under the PDPA.
8. SECURITY AND RETENTION
We implement reasonable administrative, technical and organisational measures designed to protect Personal Data in our possession or under our control against unauthorised access, collection, use, disclosure, copying, modification, loss or similar risks. No method of electronic transmission or storage is completely secure.
We retain Personal Data only for as long as reasonably necessary for the purposes for which it was collected or processed, to provide and support the Services, to comply with legal or contractual requirements, to resolve disputes or to protect legitimate legal and business interests. When Personal Data is no longer required, we will take reasonable steps to delete, anonymise or otherwise cease retaining it.
In the event of a security incident or data breach affecting Personal Data under our control or processed on behalf of a Customer, we maintain a documented incident response plan. Where we act as a data intermediary, we will notify the affected Customer without undue delay upon becoming aware of a confirmed or suspected data breach involving Customer Data, enabling the Customer to fulfil its assessment and notification obligations under the PDPA or other applicable laws.
 
9. ACCESS, CORRECTION AND WITHDRAWAL OF CONSENT
Subject to the PDPA and applicable exceptions, an individual may request access to or correction of Personal Data that AiTA holds for its own purposes. Where we rely on consent, the individual may withdraw that consent by giving reasonable notice, although this may affect our ability to provide certain Services or fulfil a request.
Where Personal Data forms part of Customer Data processed on behalf of a customer, the individual should ordinarily direct any request concerning that Personal Data to the relevant customer. If AiTA receives such a request, we may refer or forward it to the customer and provide reasonable assistance as required by the customer agreement or applicable law.
AiTA will not independently amend, disclose or delete Customer Data contrary to the relevant customer’s instructions unless required or permitted by law.
10. CUSTOMER RESPONSIBILITIES
A customer submitting Customer Data, whether relating to its own organisation or another entity, is responsible for ensuring that:

  • it is authorised to submit the Customer Data to AiTA and to instruct AiTA to process it;

  • any required notices have been given and any required consent or other legal basis has been obtained;

  • the Customer Data submitted is relevant and reasonably necessary for the intended purpose;

  • its instructions and use of the Services comply with applicable law;

  • its users access Customer Data only as authorised by the customer; and

  • where it uses the redaction feature, the identifiers provided are accurate and the resulting document is reviewed before further use or processing.

The customer remains responsible for communicating with relevant individuals regarding its collection, use, disclosure and processing of their Personal Data, including its use of service providers such as AiTA.
11. COOKIES AND BUSINESS COMMUNICATIONS
Our website and Services may use cookies and similar technologies for essential functions, authentication, security, preferences, usage analysis and technical diagnostics. Browser settings may allow users to manage cookies, although disabling certain cookies may affect some features.
Subject to applicable law and communication preferences, we may use business contact information to respond to enquiries, provide information about the Services and invite individuals to demonstrations, webinars or events. Promotional email communications may be unsubscribed from at any time. Necessary administrative and service-related communications may still be sent.


9. CONTACT US

If you have any questions about this Privacy Notice or wish to exercise your rights under the PDPA, please contact us:

Ai Tax Advisors Pte. Ltd.

60 Paya Lebar Road #04-51 Paya Lebar Square Singapore 409051

Email: enquiry@itax.sg

bottom of page