0123 Digital Pte. Ltd.
Privacy Policy
Latest update: 30 July 2026
This Privacy Policy explains how 0123 Digital Pte. Ltd., trading as 01 Digital (01 Digital, we, us or our), collects, uses, discloses, transfers, protects and retains Personal Data.
It applies to our websites, enquiries, customers, projects, support and three service categories: Software, Branding and Websites.
Personal Data means data about an identifiable individual, whether identified from that data alone or with other information an organisation has or is likely to access.
1. Our role
We act as an organisation or controller when we decide why and how Personal Data is processed, including website, enquiry, sales, billing, recruitment, security and service-administration information.
We act as a data intermediary or processor when we process Personal Data for a customer under its instructions, including information handled through Software, an AI agent or a connected workflow.
Where we process Personal Data for a customer, the customer’s privacy notice, instructions and applicable written agreement may also apply.
2. Personal Data we may process
We process only information reasonably relevant to the relationship or configured service.
2.1. Business and account information
(a) name, role, organisation and business contact details;
(b) account identifiers, roles and authentication records;
(c) enquiry, proposal, contract, project and support communications;
(d) billing, payment status, transaction and tax records; and
(e) preferences, feedback and meeting records.
2.2. Website information
(a) IP address, browser, device and operating system;
(b) approximate location, pages, links, referring source and timestamps;
(c) cookies, local storage and consent preferences; and
(d) newsletter, campaign and form interactions.
2.3. Branding and Website project information
(a) brand, product, website and campaign materials;
(b) text, images, audio, video, files and creative assets;
(c) research, feedback, analytics and content;
(d) source code, configuration and access information needed for delivery; and
(e) customer-provided contact or end-user information.
2.4. Software and connected-service information
(a) prompts, messages, instructions, files, documents and images;
(b) customer-service, booking, lead, content and operational information;
(c) transaction, vendor, receipt, accounting and tax-related information where configured;
(d) mappings, approval rules and workflow settings;
(e) usage, audit, timestamp, error and security logs;
(f) connected organisation, account and platform identifiers; and
(g) delegated-authorisation information, including OAuth tokens.
We do not request a connected-service password where OAuth or another delegated method is available.
2.5. Recruitment information
(a) application, CV, portfolio, employment and education information;
(b) interview notes, references and eligibility information.
Customers should not submit sensitive Personal Data that is unnecessary for a configured service.
How we collect information
We may collect Personal Data:
(a) directly from an individual;
(b) from a customer, authorised representative, employer or referral;
(c) through forms, email, calls, meetings, files and support channels;
(d) through customer-controlled repositories and submission channels;
(e) from services a customer chooses to connect;
(f) automatically through websites, Software, logs and service telemetry; and
(g) from public professional or business sources where lawful.
Why we process information
We may process Personal Data to:
(a) respond to enquiries and provide proposals;
(b) establish and manage customer, supplier and employment relationships;
(c) design, configure, deliver and support Software, Branding and Websites;
(d) authenticate users and maintain authorised connections;
(e) manage projects, billing, accounting and administration;
(f) create, organise, analyse, extract, classify, summarise or generate content;
(g) carry out customer-configured workflows and authorised actions;
(h) read from or write to connected business systems;
(i) preserve documents and audit records where configured;
(J) monitor performance, troubleshoot and improve reliability;
(k) protect security and prevent misuse;
(l) send updates or marketing where permitted;
(m) recruit personnel;
(n) enforce agreements and resolve disputes; and
(o) comply with law.
We collect, use and disclose Personal Data only for notified purposes, on customer instructions where it acts for the individual, or as otherwise permitted by law.
AI and automated processing
Software may use artificial intelligence, machine learning, optical character recognition, rules and other automated methods.
These methods may generate drafts, recommendations, classifications, extracted fields or proposed actions. They may be inaccurate, incomplete, biased or unsuitable.
Depending on the workflow, we may use confidence thresholds, approval gates, exception handling, testing and audit records. Customers determine the human oversight appropriate before an output affects customers, finances, legal rights, regulated decisions or business records.
We do not use identifiable Customer Data to train a general-purpose model for unrelated customers unless the customer separately and expressly agrees following a specific notice.
We may use aggregated or anonymised information to operate, secure, measure and improve our capabilities only where it does not reasonably identify a customer or individual and is not reasonably capable of re-identification.
Connected services
A customer may connect Software with platforms such as Google Workspace, messaging, content, advertising, CRM and accounting platforms.
Before connection, the customer receives a Connected Service Authorisation Notice describing the relevant data, permissions, actions, approval model, exclusions and disconnection effect.
For QuickBooks Online, processing may include company, vendor, account, tax-code and transaction information; preparing or posting authorised expenses, purchases or bills; uploading documents; and maintaining sync, reporting and audit records.
Disconnecting stops future access through that connection. It does not automatically reverse completed actions or delete information already stored in our systems, the platform or a customer-controlled repository.
Connected platforms operate under their own terms and privacy policies.
Disclosure and service providers
We may disclose Personal Data only as reasonably necessary to:
(a) our personnel, affiliates and professional advisers;
(b) providers supporting hosting, storage, communications, analytics, monitoring, security, support, OCR and AI processing;
(c) platforms selected or connected by the customer;
(d) payment, accounting and administration providers;
(e) regulators, courts or law-enforcement bodies where legally required;
(f) parties needed to establish, exercise or defend legal rights; and
(g) transaction parties in a merger, financing, reorganisation or sale, subject to safeguards.
Providers receive only access reasonably required for their role and are subject to appropriate contractual, confidentiality and data-protection obligations.
We do not sell Customer Data or disclose one customer’s identifiable confidential or accounting data to another customer for competitive insight.
We maintain an internal register of providers, functions and processing locations. Customers may request information relevant to their service from our Data Protection Officer.
International transfers
Our personnel and providers may process Personal Data in Singapore and other countries required for the service.
For transfers outside Singapore, we take steps intended to provide protection comparable to the Personal Data Protection Act 2012, including contractual, technical and organisational safeguards as appropriate.
Security and incidents
We use administrative, technical and organisational measures designed to protect Personal Data against unauthorised access, collection, use, disclosure, copying, modification, loss and disposal.
Depending on the service, measures may include least-privilege access, multifactor authentication where supported, encryption in transit, protected credential and token storage, environment separation, scoped permissions, approval controls, logging, monitoring, duplicate controls, backup and incident-response procedures.
No method is completely secure, and we cannot guarantee absolute security.
We assess suspected Personal Data breaches and make notifications required by law. Where we process Personal Data for a customer, we will notify the customer without undue delay after confirming an incident affecting its Personal Data, subject to law and the applicable written agreement.
Retention, disconnection and deletion
We retain Personal Data only for as long as reasonably necessary for the relevant business or legal purpose.
We consider the active relationship, documented customer instructions, reporting and audit needs, accounting and tax requirements, sensitivity and risk, security needs, dispute periods, backup cycles and legal obligations.
Some Software is designed to preserve documents and audit records. These may be retained for a customer’s reporting, accounting or legal requirements and are not subject to short-term automatic deletion unless configured or agreed.
When retention is no longer required, we delete, anonymise or render Personal Data inaccessible using reasonable measures.
An authorised customer representative may request export, correction or deletion, subject to identity and authority verification, law, technical limitations, backup cycles and agreed retention.
Individual rights
Subject to law, an individual may request:
(a) access to Personal Data and information about its use or disclosure;
(b) correction of inaccurate or incomplete Personal Data;
(c) withdrawal of consent with reasonable notice; or
(d) deletion where retention is no longer justified.
Withdrawal may affect our ability to provide a service. We may continue processing where another legal permission or obligation applies.
Where we process data only for a customer, we may refer the request to that customer or assist it.
Cookies and marketing
Our websites may use essential technologies for security, routing, forms and preferences; analytics technologies to understand performance and aggregate use; and marketing technologies only where enabled and permitted.
Where required, non-essential technologies will not be activated until a visitor makes a choice.
Visitors may use available cookie controls or browser settings. Blocking some technologies may affect functionality.
Marketing recipients may unsubscribe through the message or contact us. Service, security and contractual communications may still be sent.
Children
Our business services are not directed to children.
A customer using a service in education or another context involving minors is responsible for authority, notices, consent and appropriate safeguards. We will implement any agreed processing controls.
Changes
We may update this Policy for changes in our services, providers, practices or law. We will publish a revised date and give appropriate notice of material changes.
Where a new use requires fresh consent or a specific AI notice, we will not rely solely on a general policy update.
Data Protection Officer
0123 Digital Pte. Ltd.
UEN: [insert UEN]
Registered office: [insert registered address]
Data Protection Officer: [insert name or role]
DPO/privacy email: [insert DPO email; recommended: privacy@01-digital.com]
General contact: hello@01-digital.com
Questions, complaints and Personal Data requests may be sent to the Data Protection Officer.
Individuals may also contact Singapore’s Personal Data Protection Commission at https://www.pdpc.gov.sg/.