PolusMarketingTroy Digital marketing · Singapore

Privacy policy

This policy explains what personal data Polus Marketing Troy Pte. Ltd. collects through this website and in the course of providing services, why we collect it, who we share it with, and the choices available to you under Singapore's Personal Data Protection Act 2012 (PDPA).

1. Who we are

Polus Marketing Troy Pte. Ltd. ("PolusMarketingTroy", "we", "us") is a private limited company incorporated in Singapore.

  • Registered address: 20 Cecil Street, #14-01 PLUS, Singapore 049705
  • Business registration number (UEN): 201934782W
  • Telephone: +65 6817 3920
  • General email: [email protected]
  • Website: polusmarketingtroy.pro

We are the organisation responsible for the personal data described in this policy, except where we process data on behalf of a client, in which case the client is responsible and we act as a data intermediary under their instructions.

2. Data Protection Officer

Our appointed Data Protection Officer is Nadia Rahman. You can reach the DPO at [email protected], by telephone on +65 6817 3920, or by post at the registered address above marked "Attn: Data Protection Officer".

3. What we collect

3.1 Information you give us

  • Enquiry details — name, company, work email, telephone number where provided, the service you are interested in, an optional budget range, and the content of your message.
  • Marketing preferences — whether you have opted in to our insights email, and the date, form and consent wording shown at the time.
  • Client and prospect correspondence — emails, meeting notes, call notes and documents exchanged during a proposal or engagement.
  • Supplier and applicant data — contact and contractual details for vendors, and CVs and application materials for job candidates.

3.2 Information collected automatically

  • Technical and usage data — IP address (in truncated form where our analytics configuration allows), browser and device type, operating system, referring page, pages viewed, time on page, and approximate location at city level.
  • Cookie and similar identifiers — as described in our cookie policy. Analytics and advertising identifiers are only set where you have consented.

3.3 Information from other sources

Where you contact us through a professional network or are introduced by a mutual contact, we may record the business contact information provided. For client engagements we receive access to the client's own advertising, analytics and CRM platforms, which may contain personal data belonging to their customers. That data is processed only as described in section 8.

We do not knowingly collect data from children, and this website is not directed at anyone under 16.

4. Why we use it, and our legal basis

Purposes for processing personal data and the basis for each
PurposeData usedBasis under the PDPA
Responding to an enquiry and preparing a proposalEnquiry details, correspondenceConsent given when you submit the form
Delivering contracted services and account managementClient contact and correspondence dataNecessary to perform our contract with you
Invoicing, accounting and statutory record-keepingBilling contacts, transaction recordsLegal obligation under Singapore tax and company law
Sending the insights emailName, email, preferencesYour separate opt-in consent, withdrawable at any time
Measuring and improving this websiteAnalytics and usage dataConsent through the cookie notice
Advertising measurement and remarketingAdvertising identifiersConsent through the cookie notice
RecruitmentApplication materialsConsent given when you apply
Security, fraud prevention and dispute resolutionLogs, correspondenceOur legitimate business interests, balanced against your interests

We do not sell personal data, and we do not use enquiry data for automated decision-making that has a legal or similarly significant effect on you.

5. Who we share it with

We share personal data only with the categories of recipient listed below, and only to the extent necessary.

  • Technology providers that host our systems and deliver our communications — including cloud hosting, email, CRM, project management and email delivery services.
  • Analytics and advertising platforms — such as Google Analytics, Google Ads, Meta and LinkedIn, where you have consented to the relevant cookie category.
  • Professional advisers — accountants, auditors and lawyers, under duties of confidentiality.
  • Government authorities — where we are required by Singapore law or a valid legal process to disclose information.
  • A successor entity — in the event of a reorganisation, merger or sale of the business, subject to the recipient continuing to protect the data on terms consistent with this policy.

Every processor we engage is bound by a written agreement requiring them to process data only on our instructions and to apply appropriate security measures.

6. Transfers outside Singapore

Some of our providers store or process data outside Singapore, including in the European Union, the United States, Australia and Malaysia (our Kuala Lumpur office). Where personal data is transferred out of Singapore we take reasonable steps to ensure the recipient is bound to a standard of protection comparable to that required by the PDPA, through contractual terms with each provider.

7. How long we keep it

  • Unsuccessful enquiries — 24 months from the last contact, then deleted.
  • Client records — for the duration of the engagement and 6 years afterwards, to meet contractual, tax and accounting requirements.
  • Marketing subscribers — until you unsubscribe, plus a suppression record kept indefinitely so we do not email you again by accident.
  • Job applications — 12 months after the recruitment decision, unless you ask us to keep them longer.
  • Website analytics — retained according to the platform's configured retention period, currently 14 months in Google Analytics.

8. Data we process for clients

When we manage advertising, analytics or CRM systems for a client, any personal data in those systems belongs to the client. We act as a data intermediary: we process it only on the client's documented instructions, restrict access to team members assigned to the engagement, do not use it for our own purposes, and delete or return it on termination in line with the engagement terms. Individuals with questions about that data should contact the client organisation, though we will assist them in routing a request correctly.

9. How we protect it

We apply organisational and technical measures proportionate to the sensitivity of the data, including encryption in transit (TLS) across our website and systems, multi-factor authentication on all business accounts, role-based access limited to those who need it, a password manager for shared credentials, annual access reviews, and staff training on data handling at onboarding and yearly thereafter. No system is completely secure, and we do not claim otherwise. If a data breach occurs that is likely to result in significant harm, we will notify the affected individuals and the Personal Data Protection Commission as required by the PDPA.

10. Your rights and choices

  • Access — ask what personal data we hold about you and how it has been used or disclosed in the past year.
  • Correction — ask us to correct inaccurate or incomplete data.
  • Withdrawal of consent — withdraw consent for any purpose based on consent, including marketing. Withdrawal does not affect processing that already took place, and may mean we can no longer provide a service.
  • Unsubscribe — use the link in any marketing email, or email the DPO. We action requests within 10 working days and usually the same day.
  • Cookies — change or withdraw your cookie choices at any time through the notice on this site or your browser settings, as described in our cookie policy.

To exercise any of these, email [email protected]. We will acknowledge within 3 business days and respond substantively within 30 days. We may ask you to verify your identity before releasing information, and a reasonable fee may apply to an access request as permitted under the PDPA — we will tell you before proceeding.

If you are not satisfied with our response, you may lodge a complaint with the Personal Data Protection Commission of Singapore through the PDPC website.

11. Third-party links

This website links to external sites, including the Personal Data Protection Commission and Google's advertising policy documentation. We are not responsible for the privacy practices of any site we do not operate, and we encourage you to read their policies.

12. Changes to this policy

We review this policy at least annually. Where a change materially affects how we use your data, we will update the date at the top of this page and, where we hold your contact details and the change requires it, notify you directly. Previous versions are available from the DPO on request.

Questions about your data? Email our Data Protection Officer at [email protected] or call +65 6817 3920 between 09:00 and 18:30 SGT, Monday to Friday.