Public BetaJoin as a Founding User and lock in 50% off while the offer is active. Register and create AI agents

Trust Hub · Singapore

Singapore PDPA & KlicForge

Version 0.1 · Last updated: 2026-08-11 · Informational — DPA pending legal review

KlicForge processes information on your behalf to provide AI agent services. When that information includes personal data, its processing must be appropriately governed. This page describes how KlicForge fits into your organisation's governance under the Personal Data Protection Act 2012 — the technical, organisational, and contractual safeguards we provide, and the responsibilities that remain yours.

At a glance

You control your data

You retain ownership of all data you upload. KlicForge processes it only to provide the contracted service, on your instructions.

Data intermediary role

For personal data in your workspace, KlicForge acts as a data intermediary under the PDPA — processing on your behalf under a written contract.

Encrypted & isolated

Sensitive fields are encrypted with AES-256-GCM, and tenant isolation is enforced at the database level with row-level security.

Retention & deletion

A published retention schedule, self-service deletion, workspace-closure erasure, and a 7-day backup rotation.

Disclosed subprocessors

Every provider that can process customer data is published with its purpose, region, and data categories. Material changes carry 30 days' notice under the DPA.

Primary database in Singapore

Application compute and the primary database run in DigitalOcean's Singapore region. Providers that operate globally are disclosed per subprocessor.

Who is responsible for what?

Under the PDPA, KlicForge typically acts as a data intermediary for the personal data inside your workspace — contacts, conversations, uploaded knowledge, and records. We process it on your behalf and on your instructions, under a written contract. Even as a data intermediary, the PDPA binds KlicForge directly on Protection, Retention Limitation, and notifying you of data breaches without undue delay.

Engaging KlicForge does not transfer your own obligations to us: your organisation remains responsible for the purposes of processing and for your own customers. For the account and billing data of your team members, KlicForge acts as an organisation in its own right, governed by our Privacy Policy.

Your organisation — the organisation under the PDPA

  • Establishes the purpose for processing personal data
  • Ensures appropriate authority — consent, notification, or another applicable basis — for using and disclosing it
  • Decides what information is uploaded or connected to KlicForge
  • Configures authorised users, agents, and channel connections
  • Responds to its own customers and data subjects

KlicForge — data intermediary for Customer Data

  • Processes Customer Data only to provide the service, on your instructions
  • Implements the protection measures described on this page
  • Restricts and audits access to your data
  • Manages and discloses subprocessors, with contractual flow-down
  • Honours retention limits, deletion, and return of data
  • Notifies you of data breaches without undue delay and assists your assessment

Subprocessors — infrastructure, AI, and service providers

  • Process only the data required for their specific function, under contractual data-protection arrangements — see the subprocessor list

Does using KlicForge require consent from your customers?

Using a technology provider is not, by itself, a PDPA breach — and it does not always require a fresh consent form. The PDPA permits organisations to disclose personal data to a data intermediary that processes it on their behalf under a written contract.

Whether your particular use needs consent, a notification, or can rely on another basis under the Act depends on how the information was originally collected, what the individuals were told at the time, and the purpose you are processing it for now. Those are questions about your data, not ours.

Your DPO, compliance team, or legal adviser should determine the appropriate mechanism for your circumstances. This page and our Data Processing Agreement are designed to give them what they need to assess KlicForge as a vendor.

What about AI?

AI does not create a separate PDPA regime, and it does not remove one. Any external service that processes personal data — a cloud platform, a CRM, or an AI provider — raises the same governance questions: what data is processed, why, by whom, where, and under what safeguards. The PDPC's advisory guidelines on AI systems treat AI service providers processing personal data on a customer's behalf as data intermediaries — the same framework described above.

  • KlicForge does not train AI models on Customer Data and does not opt in to provider training programmes.
  • Platform model requests route through an AI-model aggregator with Zero Data Retention enabled on our account, restricting routing to upstream endpoints that do not retain or train on request data. Some models run on Cloudflare's AI infrastructure, where response caching is disabled for our requests.
  • Provider-specific retention and training treatment is documented per provider on the subprocessor list — we do not make one blanket claim across providers.
  • If your workspace connects its own model provider credentials (bring-your-own-key), requests to that provider run under your own account and terms, not KlicForge's.

How data flows through KlicForge

The systems that can receive Customer Personal Data during a conversation, and what each receives.

Your customer / end user

Website widget · Telegram · WhatsApp · your dashboard

KlicForge runtime — DigitalOcean Singapore (SGP1)

PII-redaction guardrail (default on) · field-encrypted database · tenant isolation

Storage

PostgreSQL in Singapore; uploaded files and knowledge search index with Cloudflare

AI providers

Model requests via our aggregator (Zero Data Retention) or Cloudflare AI — only what the conversation needs

Tools you connect

Optional integrations (calendar, documents, channels) receive only the data needed for that tool

Responses return to your customer through KlicForge

Security safeguards

Controls listed here are implemented in the platform today. Qualifications are stated inline — we would rather you know a control's limits than assume a guarantee.

Field-level encryption at rest

Sensitive fields — message content, contact details, credentials, security tokens — are encrypted with AES-256-GCM using versioned, rotatable keys. Customers can additionally mark their own data-table fields (including NRIC-typed fields) as encrypted, with masked reads and audited reveals.

Tenant isolation

PostgreSQL row-level security enforces workspace isolation across all tenant tables, in addition to application-level scoping. The database policy fails closed: without a valid tenant context, queries return nothing.

Encryption in transit

All traffic is served over TLS, including database connections.

Access control

Role-based access control for workspace members (owner, admin, member). TOTP multi-factor authentication is available to all users and mandatory for KlicForge platform administrators. Full conversation transcripts are restricted to workspace owners and admins, and every transcript access is audit-logged.

Audit logging

Security-relevant events — sign-ins, MFA changes, PII reveals, transcript access, privacy-request handling — are recorded in an append-only audit log retained for 24 months (12 months for data-change audit logs), enforced by an automated monthly retention job.

PII redaction before AI models

A guardrail, on by default, masks emails, phone numbers, card numbers, and US SSN patterns in user messages before any model request. It is pattern-based and configurable per agent, so it is a safeguard rather than a guarantee — and its patterns do not yet cover NRIC or 8-digit Singapore phone formats. Raw channel identifiers (Telegram IDs, WhatsApp numbers) are never sent to models.

Security testing

Automated OWASP ZAP scans run against staging on each release and nightly. KlicForge holds no third-party certifications today — SOC 2 is on our roadmap.

Backups

The managed database takes automated daily backups with a 7-day retention window, encrypted at rest by the hosting provider.

Data retention and deletion

You can delete records, contacts, conversations, and knowledge sources from the dashboard at any time. Closing your workspace erases workspace data across our stores — including uploaded files and search indexes — and deleted data ages out of encrypted backups within the 7-day rotation. Retention is enforced by automated jobs, not manual clean-ups.

DataKept for
Conversations, contacts, data tables, knowledgeUntil you delete them or close the workspace
Agent memoryUntil the related contact or workspace is deleted
Data-change audit log12 months
Security audit log24 months
Billing records7 years (legal requirement)
Database backups7-day rolling window

Data location and international transfers

KlicForge's application compute and primary database run in DigitalOcean's Singapore region (SGP1). Specific functions involve providers that operate globally: uploaded files and the knowledge search index are stored with Cloudflare, AI model requests are routed to the model providers described above, and our email, billing, error-monitoring, and analytics providers operate in the United States. Each provider's role and region is listed on the subprocessor list.

When personal data leaves Singapore, the PDPA's Transfer Limitation Obligation requires a comparable standard of protection. KlicForge addresses this contractually: our Data Processing Agreement commits us to ensuring overseas subprocessors are bound by legally enforceable data-protection obligations for the personal data they handle.

What happens if there is a data breach?

KlicForge operates a documented incident-response process. For a breach affecting personal data we process on your behalf, the PDPA allocates the steps like this:

  1. 1

    Detect & contain

    KlicForge

  2. 2

    Notify affected customer without undue delay

    KlicForge

  3. 3

    Assess whether the breach is notifiable

    Customer, with KlicForge's assistance

  4. 4

    Notify PDPC within 3 calendar days of assessing it notifiable; notify individuals where required

    Customer

  5. 5

    Remediate & review

    KlicForge

A breach is notifiable under the PDPA when it is likely to result in significant harm to affected individuals, or affects 500 or more individuals. The contractual notification commitment between KlicForge and customers is set out in the Data Processing Agreement.

Management & DPO FAQ

Supporting documents

Data Protection Officer

KlicForge (Klicco Pte. Ltd.) has designated a Data Protection Officer function, reachable at [email protected]. Your DPO, security, or procurement team can use this address for vendor assessments and any data-protection question.

This page describes KlicForge's services and data-protection practices and is provided for informational purposes. It does not constitute legal advice, and it is not a certification. Customers are responsible for determining their own obligations under applicable data-protection law, including whether consent, notification, or another basis applies to their processing.