Legal
Privacy policy
Audience Blaze Pte. Ltd. · Effective 21 July 2026 · Singapore PDPA 2012
1. Organisation identity
This Privacy policy is issued by Audience Blaze Pte. Ltd. (UEN 202471835W), a marketing agency registered in Singapore with its principal place of business at 51 Tras Street, #02-04, Singapore 078988. We provide B2B marketing agency services — audience intelligence, segment architecture, message ignition, and observatory retainer programmes — to organisations in Singapore and the wider ASEAN region. This policy explains how we collect, use, disclose, and protect personal data when you visit audienceblaze.pro, submit an enquiry, or engage us as a client.
We are a professional services organisation, not a data broker, bot shop, or consumer course provider. Our `.pro` domain reflects our focus on audience intelligence for business clients.
2. Scope and applicability
This policy applies to personal data collected through our website, contact forms, email correspondence, phone calls, in-person meetings at our Tanjong Pagar studio, and client engagements. It does not cover third-party websites linked from our pages. Where we process personal data on behalf of a client under a separate data processing agreement, the client engagement terms may supplement certain sections for project-specific data.
We align our practices with the Personal Data Protection Act 2012 (PDPA) of Singapore and applicable subsidiary legislation. We review this policy periodically and publish material updates on this page with a revised effective date.
3. Personal data we collect
Depending on your interaction with us, we may collect:
- Identity and contact data: name, job title, company name, business email, business phone number, and mailing address.
- Enquiry and brief data: messages you submit via our contact form, audience requirements, budget indications, and attachments you choose to send.
- Client engagement data: statements of work, billing contacts, audience data supplied for intelligence work, segment reports, and correspondence related to project delivery.
- Technical data: IP address, browser type, device information, pages viewed, and referral URLs when you use our website — primarily via cookies and server logs as described in our Cookie policy.
- Consent records: timestamps and choices relating to PDPA consent checkboxes, cookie preferences, and marketing communication opt-ins where applicable.
We do not intentionally collect sensitive personal data through our public website forms. If your engagement requires processing of sensitive categories, we address that explicitly in contract and with additional safeguards.
4. Purposes of collection and use
We collect and use personal data for legitimate business purposes connected to our marketing agency services, including:
- Responding to enquiries and scheduling audience briefings or discovery calls.
- Preparing proposals, statements of work, and project scope documentation.
- Delivering audience intelligence, message ignition, and retainer services under contract.
- Managing accounts, invoicing, and payment follow-up with authorised client contacts.
- Operating, securing, and improving our website and internal systems.
- Complying with legal obligations, resolving disputes, and enforcing agreements.
- Conducting PDPA-aware marketing about our own agency services to business contacts who have not opted out, where permitted.
We do not sell personal data. We do not use your enquiry data to train public AI models without explicit written agreement. AI-assisted workflows inside client projects follow engagement terms and client instructions.
5. Legal bases and consent
Under the PDPA, we rely on consent, contractual necessity, legitimate interests, and legal obligation as appropriate to each processing activity. When you submit our contact form, you must tick the PDPA consent checkbox — it is not pre-selected. You may withdraw consent for optional processing (such as analytics cookies or non-essential marketing email) without affecting core enquiry handling.
For client project data, processing is typically necessary to perform the contract between Audience Blaze and your organisation. Additional consent may be sought for specific uses such as uploading client materials to third-party AI tools.
6. Disclosure to third parties
We disclose personal data only where needed for the purposes above, including to cloud hosting and email infrastructure providers, analytics vendors if you consent to analytics cookies, professional advisers, and government authorities when required by law. We require processors to protect personal data under contractual obligations consistent with the PDPA.
We do not disclose personal data to data brokers for resale. Cross-border transfers, if any, are conducted with appropriate safeguards consistent with PDPA requirements. Where we engage subprocessors for client campaign or analytics work, we limit access to the minimum data required and document processing instructions in client agreements or data processing addenda.
7. Retention
We retain personal data only as long as necessary for the purposes collected, unless a longer period is required by law. Enquiry records are typically retained for twenty-four months. Client project records are retained for seven years after engagement completion for legal and accounting purposes. Cookie consent preferences are stored for six months before re-prompting. Technical logs are rotated on a ninety-day cycle unless required for security investigations.
When retention periods expire, we securely delete or anonymise personal data. Anonymised aggregate data used for internal benchmarking may be retained indefinitely because it no longer constitutes personal data under the PDPA. If you request deletion before standard retention periods end, we will assess your request against legal obligations — for example, we may need to retain invoicing records for tax compliance even after you withdraw marketing consent.
Client-provided datasets used during audience intelligence engagements are returned or destroyed according to contractual schedules, typically within thirty days of project completion unless ongoing retainer monitoring requires continued secure storage under agreed access controls and encryption standards.
8. Security
We implement administrative, technical, and physical safeguards appropriate to the sensitivity of personal data, including access controls, encrypted connections (HTTPS), secure file transfer for client datasets, staff training on data handling, and incident response procedures. Access to personal data is limited to personnel with a legitimate business need. We review security practices annually and after significant infrastructure changes.
Multi-factor authentication protects administrative systems. Client datasets processed during engagements are stored on encrypted volumes with audit logging. Our Tras Street studio maintains physical access controls for devices containing client materials. Third-party processors undergo due diligence reviews before engagement and contractual data protection clauses are standard in vendor agreements.
No method of transmission or storage is completely secure. We commit to notifying affected individuals and the Personal Data Protection Commission where required in the event of a data breach. We maintain an incident response plan reviewed at least annually and tested when significant infrastructure changes occur.
9. Your rights under the PDPA
Subject to exceptions under the PDPA, you have the right to request access to personal data we hold about you, request correction of inaccurate or incomplete personal data, withdraw consent for processing based on consent, and request information about how your personal data has been used or disclosed within the past year.
To exercise these rights, email [email protected] with sufficient detail to verify your identity. We aim to respond within thirty days. We may charge a reasonable fee for access requests as permitted by law. If you believe we have not handled your personal data appropriately, you may contact the Personal Data Protection Commission of Singapore.
Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal. Where we rely on contractual necessity or legal obligation, we may continue to process certain data even after you withdraw consent for optional activities such as analytics cookies or non-essential marketing communications.
10. Children
Our website and services are directed at business professionals. We do not knowingly collect personal data from individuals under eighteen years of age. If you believe we have inadvertently collected such data, contact us and we will delete it promptly.
11. Changes
We may update this Privacy policy to reflect legal, technical, or business changes. Material updates will be posted on this page with a revised effective date. Continued use of our website after changes constitutes acknowledgement of the updated policy where permitted by law.
12. Contact
Audience Blaze Pte. Ltd.
51 Tras Street, #02-04, Singapore 078988
Email: [email protected]
Phone: +65 6980 4217