KlicForge Data Processing & PDPA Overview — Singapore
Version 0.1 · Last updated: 2026-08-11 · Full detail: klicforge.ai/trust-hub/pdpa
- 1. What is KlicForge's role?
- For personal data in your workspace (contacts, conversations, uploaded content, records), KlicForge is a data intermediary under the PDPA — we process it on your behalf under a written contract. For your team's account and billing data, KlicForge acts as an organisation in its own right under our Privacy Policy.
- 2. Does using KlicForge automatically breach the PDPA?
- No. The PDPA expressly contemplates outsourced processing through data intermediaries. What matters is governance: your purpose and basis for processing, a written contract, and a vendor that protects the data. This document supports that assessment.
- 3. What is our responsibility as the customer?
- You establish the purpose for processing, ensure appropriate authority (consent, notification, or another applicable basis), decide what data is uploaded, manage your authorised users, and respond to your own customers and data subjects. Your DPO or legal adviser determines whether your specific use needs additional consent or notification.
- 4. What does KlicForge do to protect data?
- AES-256-GCM field-level encryption with key rotation, database-level tenant isolation (row-level security, fail-closed), role-based access control with TOTP MFA available (mandatory for platform administrators), append-only audit logging with enforced retention, TLS in transit, and automated security scanning each release.
- 5. Does AI receive customer data?
- Yes — a model receives what it needs to answer: the agent's instructions, the user's message and recent history, relevant knowledge excerpts, and tool results. A default-on guardrail masks common PII patterns first. KlicForge does not train AI models on Customer Data, and platform model routing runs with Zero Data Retention enabled on our aggregator account. Provider-specific terms are listed per subprocessor.
- 6. Are third parties / subprocessors involved?
- Yes — hosting, AI providers, email, billing, and monitoring. Every subprocessor is published at klicforge.ai/subprocessors with its purpose, data categories, and region. Material changes carry 30 days' advance notice under the DPA, with a right to object.
- 7. Can data leave Singapore?
- Application compute and the primary database run in DigitalOcean's Singapore region (SGP1). Specific functions involve globally operating providers (file/knowledge-index storage with Cloudflare; AI, email, billing, and monitoring providers in the US or globally). The DPA commits KlicForge to ensuring overseas subprocessors are bound by legally enforceable data-protection obligations, per the PDPA's Transfer Limitation Obligation.
- 8. What happens during a breach?
- KlicForge detects and contains the incident and notifies affected customers without undue delay with what we know. Your organisation then assesses notifiability under the PDPA — with our assistance — and notifies the PDPC within 3 calendar days of assessing a breach notifiable (and affected individuals where required).
- 9. Can our data be deleted?
- Yes. Self-service deletion from the dashboard, full erasure on workspace closure (including files and search indexes), a published retention schedule enforced by automated jobs, and backups that age out within a 7-day rotation. Records required by law (e.g. billing) are retained.
- 10. Is there a DPA?
- A versioned Data Processing Agreement is published at klicforge.ai/data-processing-addendum. It is currently a draft pending legal review; once finalised it will be incorporated into our Terms of Service, with countersigned copies for Enterprise customers.
- 11. Where can our DPO ask questions?
- [email protected] — KlicForge's (Klicco Pte. Ltd.) designated Data Protection Officer contact. Vulnerability reports: [email protected].
This overview describes KlicForge's services and data-protection practices and is provided for informational purposes. It does not constitute legal advice, and it is not a certification. Customers are responsible for determining their own obligations under applicable data-protection law. Questions: [email protected].