Last updated: 16 August 2026
AI Super Private Limited (“AI Super”, “we”, “us”, or “our”) is committed to protecting personal data in accordance with Singapore’s Personal Data Protection Act 2012 (“PDPA”) and other applicable laws.
This Data Protection Policy explains how we collect, use, disclose, process, retain, transfer, and protect personal data in connection with our websites, AI-powered chatbot systems, messaging automation, integrations, and related services (collectively, the “Services”).
Depending on the context, AI Super may act as:
We act as an organisation (sometimes referred to as a data controller) when we determine the purposes and means of collecting, using, or disclosing personal data. This includes personal data relating to website visitors, prospective customers, direct customers, and our business contacts.
We act as a data intermediary (sometimes referred to as a data processor) when we process personal data on behalf of and for the purposes of a customer under a written agreement.
Where we act as a data intermediary, we:
Process personal data only in accordance with the customer’s documented instructions and the applicable agreement.
Do not use customer-controlled personal data for our own independent purposes.
Implement reasonable security arrangements and appropriate retention and disposal measures.
Notify the relevant customer of a suspected or confirmed data breach affecting customer-controlled personal data as soon as practicable.
Assist the customer, where reasonably required and contractually agreed, in meeting applicable data-protection obligations.
Customers remain responsible for matters under their control, including establishing a lawful purpose, providing required notices, obtaining valid consent where required, and configuring and using the Services lawfully.
We may collect or process the following categories of personal data.
Name, company name, and job title.
Email address, telephone number, and WhatsApp number.
Account and business contact information.
IP address, device, browser, and operating-system information.
System logs, timestamps, API activity, and security events.
Information about how the Services are accessed and used.
Billing details, invoices, subscription information, and transaction records.
Payment-card information may be processed directly by our payment providers and may not be stored by AI Super.
Messages, chatbot conversations, voice notes, attachments, and uploaded files.
Information provided during onboarding, consultations, support requests, or other communications.
Personal data submitted to or processed through the Services under a customer’s instructions, including information relating to the customer’s chatbot users, contacts, leads, enquiries, appointments, and bookings.
We may collect personal data when you:
Visit or use our websites, applications, chatbots, or other Services.
Register for an account, request a demonstration, subscribe to a Service, or enable an integration.
Communicate with us by email, telephone, web form, or messaging platform.
Authorise a third-party platform to share information with us.
Interact with the Services as an end-user of one of our customers.
We may also receive personal data from our customers, service providers, messaging platforms, integration partners, and publicly available sources where permitted by law.
Where permitted by applicable law, we may collect, use, or disclose personal data to:
Provide, operate, maintain, and support the Services.
Configure accounts, integrations, chatbots, and automation workflows.
Understand communications and generate requested chatbot responses.
Manage customer relationships and respond to enquiries.
Process subscriptions, billing, invoices, and payments.
Monitor performance, security, fraud, misuse, and service reliability.
Improve the Services using data that we are authorised to use, including aggregated or de-identified information where appropriate.
Maintain business, tax, audit, and compliance records.
Enforce our agreements and protect our rights, users, systems, and the public.
Comply with applicable legal and regulatory requirements.
Where we process customer-controlled personal data as a data intermediary, the purposes of processing are determined by the relevant customer and limited by the customer’s documented instructions and applicable agreement.
The Services use artificial-intelligence technologies, including services provided by third-party AI providers such as OpenAI, to process, analyse, and respond to communications.
This may include:
Understanding message content, context, and intent.
Transcribing or interpreting supported media.
Generating automated replies or recommended actions.
Routing communications or initiating configured workflows.
Automated processing may affect how a communication is classified, routed, or answered without immediate human intervention. Customers are responsible for deciding when human review is appropriate for their use case.
We do not use customer-controlled personal data to train general-purpose AI models unless the customer has expressly authorised that use and the processing is otherwise lawful.
Any use of information to evaluate or improve our Services must be consistent with the applicable agreement, notices, permissions, and law.
Our Services may integrate with or rely on third parties, including:
Meta platforms, such as WhatsApp, Instagram, and Facebook.
Google services, such as Google Calendar and Google Sheets.
AI providers, including OpenAI.
Cloud and infrastructure providers, including Contabo for hosting in Singapore.
Analytics, communications, payment, and customer-support providers.
Professional advisers, auditors, and insurers.
We disclose personal data to these parties only where reasonably necessary for the relevant purpose, permitted by law, and subject to appropriate contractual or other safeguards.
A third party may also process personal data independently under its own privacy policy and terms.
Third-party services may experience outages, delivery failures, policy changes, restrictions, or other events outside our reasonable control. This does not exclude any responsibility that AI Super has under applicable law.
We may disclose personal data to:
Authorised employees, contractors, and affiliates who require access for their work.
Cloud, hosting, AI, analytics, messaging, communications, integration, and technology providers.
Payment processors and financial institutions.
Professional advisers, auditors, and insurers.
A purchaser, investor, or successor in connection with a proposed or completed corporate transaction, subject to appropriate confidentiality safeguards.
Regulators, courts, law-enforcement agencies, or other parties where required or permitted by law.
We do not sell personal data.
Customers using the Services must:
Comply with applicable data-protection, privacy, marketing, communications, and sector-specific laws.
Provide required notices and obtain valid consent or establish another lawful basis where applicable.
Ensure that their instructions to AI Super are lawful.
Use appropriate account permissions and protect their credentials.
Configure retention, access, integrations, messaging, and automation features appropriately.
Respond to requests from individuals where the customer is responsible for doing so.
Avoid uploading or processing personal data that is unnecessary for the intended purpose.
Customers must not use the Services to send spam, conduct unauthorised marketing, or engage in unlawful, fraudulent, abusive, or deceptive activities.
We may suspend or terminate access where necessary to protect individuals, customers, third parties, or the Services, or to comply with law.
Where AI Super relies on consent, we will provide appropriate notice and obtain consent before collecting, using, or disclosing personal data.
An individual may withdraw consent by contacting our Data Protection Officer using the details in Section 22, subject to applicable legal or contractual restrictions and reasonable notice.
We will explain the likely consequences of withdrawal where appropriate. Withdrawal of consent may affect our ability to provide some or all of the Services.
Where AI Super processes personal data solely on behalf of a customer, requests relating to consent should generally be directed to that customer. We will provide reasonable assistance where required and appropriate.
Subject to the PDPA and any applicable exceptions, an individual may request:
Access to personal data under our possession or control and information about how it has been used or disclosed.
Correction of inaccurate or incomplete personal data.
We may verify the requester’s identity and may charge a reasonable fee for an access request where permitted by law.
If a request concerns customer-controlled data, we may refer the requester to the relevant customer and assist that customer where required and appropriate.
Requests may be submitted to our Data Protection Officer using the details in Section 22.
We take reasonable steps to ensure that personal data collected by us is accurate and complete where it is likely to be used to make a decision affecting an individual or disclosed to another organisation.
Customers are responsible for the accuracy and completeness of customer-controlled data they submit to the Services.
We retain personal data only for as long as it is reasonably necessary to fulfil the purpose for which it was collected or processed, meet contractual requirements, resolve disputes, protect the Services, or comply with legal, accounting, audit, or regulatory obligations.
Account and customer records may be retained for the duration of the business relationship and a reasonable period afterwards.
System and security logs may be retained for security, troubleshooting, audit, and operational purposes.
Financial and transaction records are retained for the period required by applicable law.
Customer-controlled data is retained in accordance with the applicable agreement, customer instructions, and configured retention settings.
When personal data is no longer required for a legal or business purpose, we will cease retaining it or remove the means by which it can be associated with an individual.
Depending on the circumstances, personal data may be securely deleted, destroyed, or anonymised. Residual copies may remain temporarily in backups until they are overwritten or securely deleted under our backup-retention process.
We implement reasonable administrative, technical, and physical safeguards appropriate to the nature of the personal data and the risks involved.
These safeguards may include:
Access controls, authentication, and permission management.
Encryption in transit and encryption at rest where appropriate.
Secure hosting and network infrastructure.
Monitoring, logging, backups, and recovery measures.
Vulnerability, patch, and incident-management procedures.
Confidentiality obligations and security awareness for authorised personnel.
Vendor assessment and contractual data-protection requirements.
No system or method of transmission is completely secure.
Customers are also responsible for securing their accounts, devices, credentials, integrations, configurations, and authorised users.
We maintain procedures to identify, contain, investigate, assess, remediate, and document suspected personal-data breaches.
We will assess whether a breach is notifiable and notify the Personal Data Protection Commission and affected individuals where required by the PDPA and within the applicable timeframes.
We will notify the relevant customer of a suspected or confirmed personal-data breach affecting customer-controlled data as soon as practicable after becoming aware of it.
We will provide reasonable information and assistance to support the customer’s assessment and response, subject to the applicable agreement and law.
Our primary hosting infrastructure is located in Singapore through Contabo.
Personal data may be transferred to, accessed from, or processed in other countries when we use third-party platforms or service providers, including Meta, Google, OpenAI, and other technology providers.
Before transferring personal data outside Singapore, we take appropriate steps to ensure that the recipient is bound by legally enforceable obligations or specified certifications, or that another permitted transfer mechanism applies.
These measures are intended to ensure that personal data receives a standard of protection comparable to that required under the PDPA.
Safeguards may include:
Contractual commitments.
Access restrictions.
Encryption.
Data minimisation.
Vendor assessments.
Customers are responsible for assessing and configuring any third-party integrations they independently choose to enable.
We may use cookies and similar technologies for:
Essential website and account functionality.
Security and fraud prevention.
Analytics and performance measurement.
User preferences and experience improvements.
Users may manage cookies through their browser settings and any cookie controls we make available.
Disabling certain cookies may affect website or Service functionality.
Where AI Super sends marketing communications, we will comply with applicable consent, opt-out, and Singapore Do Not Call requirements.
Recipients may use the unsubscribe method in the communication or contact us to opt out, subject to communications that we are legally permitted or required to send.
Customers that use the Services for marketing or messaging remain responsible for:
Recipient lists.
Required notices and consents.
Opt-out handling.
Do Not Call checks.
Message content.
Compliance with applicable laws and platform rules.
The Services are intended for businesses and are not directed to children under 13.
Customers must not intentionally use the Services to collect personal data from children without implementing appropriate notices, consent, age-verification, and other safeguards required by law.
Customers should avoid processing sensitive or higher-risk personal data unless it is necessary, lawful, and subject to safeguards appropriate to the potential harm.
Customers in regulated sectors are responsible for determining whether the Services are suitable for their requirements and implementing any additional controls required by law or professional obligations.
AI Super is responsible for meeting the obligations that apply to its role and activities under the PDPA and other applicable laws.
Customers are responsible for their own collection and use of personal data, the lawfulness of their instructions, and matters within their control.
These matters include their users, content, configurations, integrations, notices, and consents.
AI Super is not responsible for a customer’s unlawful use or unauthorised configuration of the Services, or for the independent acts and omissions of third-party platforms outside our reasonable control.
Nothing in this Policy excludes or limits any responsibility that cannot lawfully be excluded or limited.
If AI Super undergoes a merger, acquisition, restructuring, financing, sale of assets, insolvency proceeding, or similar transaction, personal data may be disclosed or transferred as part of that transaction.
We will require the recipient to handle personal data consistently with applicable law and will provide notice where required.
Questions, requests, complaints, and notices concerning this Policy or personal data may be directed to:
AI Super Private Limited
Email: hello@asi.sg
Phone: +65 8085 8100
Address: 60 Paya Lebar Road, #11-22, Paya Lebar Square, Singapore 409051
To help us respond, please provide:
Your name and contact details.
Your relationship with AI Super or the relevant customer.
Sufficient information to identify the personal data or issue concerned.
We may request additional information to verify your identity or authority.
We may update this Policy from time to time to reflect changes in our Services, practices, providers, or legal obligations.
The latest version will be published with its updated effective date. Material changes may also be communicated through the Services or other appropriate channels.