Trust Hub · Singapore
Singapore PDPA & KlicForge
Version 0.1 · Last updated: 2026-08-11 · Informational — DPA pending legal review
KlicForge processes information on your behalf to provide AI agent services. When that information includes personal data, its processing must be appropriately governed. This page describes how KlicForge fits into your organisation's governance under the Personal Data Protection Act 2012 — the technical, organisational, and contractual safeguards we provide, and the responsibilities that remain yours.
At a glance
You control your data
You retain ownership of all data you upload. KlicForge processes it only to provide the contracted service, on your instructions.
Data intermediary role
For personal data in your workspace, KlicForge acts as a data intermediary under the PDPA — processing on your behalf under a written contract.
Encrypted & isolated
Sensitive fields are encrypted with AES-256-GCM, and tenant isolation is enforced at the database level with row-level security.
Retention & deletion
A published retention schedule, self-service deletion, workspace-closure erasure, and a 7-day backup rotation.
Disclosed subprocessors
Every provider that can process customer data is published with its purpose, region, and data categories. Material changes carry 30 days' notice under the DPA.
Primary database in Singapore
Application compute and the primary database run in DigitalOcean's Singapore region. Providers that operate globally are disclosed per subprocessor.
Who is responsible for what?
Under the PDPA, KlicForge typically acts as a data intermediary for the personal data inside your workspace — contacts, conversations, uploaded knowledge, and records. We process it on your behalf and on your instructions, under a written contract. Even as a data intermediary, the PDPA binds KlicForge directly on Protection, Retention Limitation, and notifying you of data breaches without undue delay.
Engaging KlicForge does not transfer your own obligations to us: your organisation remains responsible for the purposes of processing and for your own customers. For the account and billing data of your team members, KlicForge acts as an organisation in its own right, governed by our Privacy Policy.
Your organisation — the organisation under the PDPA
- Establishes the purpose for processing personal data
- Ensures appropriate authority — consent, notification, or another applicable basis — for using and disclosing it
- Decides what information is uploaded or connected to KlicForge
- Configures authorised users, agents, and channel connections
- Responds to its own customers and data subjects
KlicForge — data intermediary for Customer Data
- Processes Customer Data only to provide the service, on your instructions
- Implements the protection measures described on this page
- Restricts and audits access to your data
- Manages and discloses subprocessors, with contractual flow-down
- Honours retention limits, deletion, and return of data
- Notifies you of data breaches without undue delay and assists your assessment
Subprocessors — infrastructure, AI, and service providers
- Process only the data required for their specific function, under contractual data-protection arrangements — see the subprocessor list
Does using KlicForge require consent from your customers?
Using a technology provider is not, by itself, a PDPA breach — and it does not always require a fresh consent form. The PDPA permits organisations to disclose personal data to a data intermediary that processes it on their behalf under a written contract.
Whether your particular use needs consent, a notification, or can rely on another basis under the Act depends on how the information was originally collected, what the individuals were told at the time, and the purpose you are processing it for now. Those are questions about your data, not ours.
Your DPO, compliance team, or legal adviser should determine the appropriate mechanism for your circumstances. This page and our Data Processing Agreement are designed to give them what they need to assess KlicForge as a vendor.
What about AI?
AI does not create a separate PDPA regime, and it does not remove one. Any external service that processes personal data — a cloud platform, a CRM, or an AI provider — raises the same governance questions: what data is processed, why, by whom, where, and under what safeguards. The PDPC's advisory guidelines on AI systems treat AI service providers processing personal data on a customer's behalf as data intermediaries — the same framework described above.
- KlicForge does not train AI models on Customer Data and does not opt in to provider training programmes.
- Platform model requests route through an AI-model aggregator with Zero Data Retention enabled on our account, restricting routing to upstream endpoints that do not retain or train on request data. Some models run on Cloudflare's AI infrastructure, where response caching is disabled for our requests.
- Provider-specific retention and training treatment is documented per provider on the subprocessor list — we do not make one blanket claim across providers.
- If your workspace connects its own model provider credentials (bring-your-own-key), requests to that provider run under your own account and terms, not KlicForge's.
How data flows through KlicForge
The systems that can receive Customer Personal Data during a conversation, and what each receives.
Your customer / end user
Website widget · Telegram · WhatsApp · your dashboard
KlicForge runtime — DigitalOcean Singapore (SGP1)
PII-redaction guardrail (default on) · field-encrypted database · tenant isolation
Storage
PostgreSQL in Singapore; uploaded files and knowledge search index with Cloudflare
AI providers
Model requests via our aggregator (Zero Data Retention) or Cloudflare AI — only what the conversation needs
Tools you connect
Optional integrations (calendar, documents, channels) receive only the data needed for that tool
Responses return to your customer through KlicForge
Security safeguards
Controls listed here are implemented in the platform today. Qualifications are stated inline — we would rather you know a control's limits than assume a guarantee.
Field-level encryption at rest
Sensitive fields — message content, contact details, credentials, security tokens — are encrypted with AES-256-GCM using versioned, rotatable keys. Customers can additionally mark their own data-table fields (including NRIC-typed fields) as encrypted, with masked reads and audited reveals.
Tenant isolation
PostgreSQL row-level security enforces workspace isolation across all tenant tables, in addition to application-level scoping. The database policy fails closed: without a valid tenant context, queries return nothing.
Encryption in transit
All traffic is served over TLS, including database connections.
Access control
Role-based access control for workspace members (owner, admin, member). TOTP multi-factor authentication is available to all users and mandatory for KlicForge platform administrators. Full conversation transcripts are restricted to workspace owners and admins, and every transcript access is audit-logged.
Audit logging
Security-relevant events — sign-ins, MFA changes, PII reveals, transcript access, privacy-request handling — are recorded in an append-only audit log retained for 24 months (12 months for data-change audit logs), enforced by an automated monthly retention job.
PII redaction before AI models
A guardrail, on by default, masks emails, phone numbers, card numbers, and US SSN patterns in user messages before any model request. It is pattern-based and configurable per agent, so it is a safeguard rather than a guarantee — and its patterns do not yet cover NRIC or 8-digit Singapore phone formats. Raw channel identifiers (Telegram IDs, WhatsApp numbers) are never sent to models.
Security testing
Automated OWASP ZAP scans run against staging on each release and nightly. KlicForge holds no third-party certifications today — SOC 2 is on our roadmap.
Backups
The managed database takes automated daily backups with a 7-day retention window, encrypted at rest by the hosting provider.
Data retention and deletion
You can delete records, contacts, conversations, and knowledge sources from the dashboard at any time. Closing your workspace erases workspace data across our stores — including uploaded files and search indexes — and deleted data ages out of encrypted backups within the 7-day rotation. Retention is enforced by automated jobs, not manual clean-ups.
| Data | Kept for |
|---|---|
| Conversations, contacts, data tables, knowledge | Until you delete them or close the workspace |
| Agent memory | Until the related contact or workspace is deleted |
| Data-change audit log | 12 months |
| Security audit log | 24 months |
| Billing records | 7 years (legal requirement) |
| Database backups | 7-day rolling window |
Data location and international transfers
KlicForge's application compute and primary database run in DigitalOcean's Singapore region (SGP1). Specific functions involve providers that operate globally: uploaded files and the knowledge search index are stored with Cloudflare, AI model requests are routed to the model providers described above, and our email, billing, error-monitoring, and analytics providers operate in the United States. Each provider's role and region is listed on the subprocessor list.
When personal data leaves Singapore, the PDPA's Transfer Limitation Obligation requires a comparable standard of protection. KlicForge addresses this contractually: our Data Processing Agreement commits us to ensuring overseas subprocessors are bound by legally enforceable data-protection obligations for the personal data they handle.
What happens if there is a data breach?
KlicForge operates a documented incident-response process. For a breach affecting personal data we process on your behalf, the PDPA allocates the steps like this:
- 1
Detect & contain
KlicForge
- 2
Notify affected customer without undue delay
KlicForge
- 3
Assess whether the breach is notifiable
Customer, with KlicForge's assistance
- 4
Notify PDPC within 3 calendar days of assessing it notifiable; notify individuals where required
Customer
- 5
Remediate & review
KlicForge
A breach is notifiable under the PDPA when it is likely to result in significant harm to affected individuals, or affects 500 or more individuals. The contractual notification commitment between KlicForge and customers is set out in the Data Processing Agreement.
Management & DPO FAQ
Supporting documents
One-page PDPA overview
→Data Processing Agreement
→Subprocessor list
→Trust Hub — security controls
→Privacy Policy
→Terms of Service
→Submit a data request
→Data Protection Officer
KlicForge (Klicco Pte. Ltd.) has designated a Data Protection Officer function, reachable at [email protected]. Your DPO, security, or procurement team can use this address for vendor assessments and any data-protection question.
This page describes KlicForge's services and data-protection practices and is provided for informational purposes. It does not constitute legal advice, and it is not a certification. Customers are responsible for determining their own obligations under applicable data-protection law, including whether consent, notification, or another basis applies to their processing.