How TrueWatch collects, uses, shares and protects personal information.
This PRIVACY NOTICE (this “Privacy Notice”) describes how TrueWatch Technology Inc Pte. Ltd. (“TrueWatch”, “we”, “us”, or “our”) collects, uses, discloses, and otherwise processes personal data in connection with our websites, mobile applications, products, services, SDKs, and related offerings that link to or reference this Privacy Notice (collectively, the “Services”). It also explains the choices and rights available to individuals and how to contact us.
By accessing, registering for, or using the Services, you acknowledge that you have read and understood this Privacy Notice. This Privacy Notice should be read together with any applicable TrueWatch terms, service agreements, Data Processing Agreements (“DPA”) and other agreements that apply to your use of the Services. Where we process personal data on behalf of a customer as a processor, the applicable agreement and DPA govern that processing.
1. Scope and Roles
We take your privacy seriously. This Privacy Notice explains how we handle your personal data. Our role in processing your data depends on how you interact with us.
In this Privacy Notice, “TrueWatch Mobile” refers to our mobile applications, including any iOS or Android application, and “Device” refers to any mobile phone, tablet, personal computer, or other hardware used to access or use the Services.
a. TrueWatch acts as a controller for personal data where we determine the purposes and means of processing, such as data relating to website visitors, app users, sales and marketing, account administration, billing, service usage, security, diagnostics, and communications.
For data that our customers submit to or collect through the Services (e.g. metrics, logs, traces, RUM data, session replay recordings, synthetic test results), TrueWatch acts as a processor and the customer is the controller. Customers are responsible for the lawfulness of their inputs, the configuration of collection, and honoring end-user notices and choices.
Customers are responsible for configuring collection and masking/filtering, limiting sensitive data, and providing notices/obtaining consents where required by law.
b. This Privacy Notice applies to:
i. visits to our website, TrueWatch Mobile app, and other online properties we control;
ii. interactions with our sales, events, and support teams;
iii. account registration and administration for the Services;
iv. service communications, alerts, and push notifications; and
v. product telemetry, diagnostics, and security data we collect as controller.
Where TrueWatch processes personal data on behalf of a customer, the applicable agreement, DPA and the customer’s documented instructions govern that processing. This Privacy Notice provides a general description of those processing activities.
c. This Privacy Notice does not apply to information that you voluntarily post, upload, or make publicly available through community forums, comment features, or similar interactive services, or that you choose to disclose publicly while using the Services, including in public profiles, public dashboards, or public communications.
d. Records, assessments and internal documentation relating to investigations, credit evaluations, suspected or actual breaches of applicable law, contract or TrueWatch policies, and any measures taken in connection with them, are subject to the access and correction exceptions available under applicable law, including the Fifth and Sixth Schedules to the Singapore PDPA.
2. Personal Data We Collect as Controller
Depending on your interactions with us, we may collect the following categories of personal data:
a. Website, TrueWatch Mobile app and Marketing Data: We may collect device identifiers, IP addresses, general location inferred from your IP, browser type, device type, operating system, app version, mobile network information, and similar technical information. We also collect information about pages or screens you view, links or features you use, and referring or exit pages through similar technologies.
b. Contact and Account Data: This includes your name, business contact details, organization, role, authentication credentials, account identifiers, and communication preferences.
c. Commercial and Billing Data: When you make a purchase, we collect transaction records, order history, payment information, billing addresses, and tax IDs where legally required.
d. Notification Data: If you enable notifications, we may process notification preferences, notification tokens or identifiers, delivery status, and related technical information to send service alerts, incident updates, security notices, billing notices, and other service communications.
e. Support and Communications: We collect the content of your requests to our support or sales teams, meeting scheduling details, and feedback from surveys.
f. Events and Programs: If you register for our events, such as webinars or trainings, we collect your registration information.
Some telemetry is required for security, fraud prevention, service reliability, crash reporting, diagnostics, and performance monitoring and cannot be disabled. Optional telemetry can be controlled through product settings, device settings, and SDK configuration where available.
3. Personal Data Collected or Processed within the Services
Customers may enable collection of data types such as metrics, logs, traces, profiles, infrastructure data, Real User Monitoring events, session replay, synthetic test data, alerting artifacts, incident data, dashboard data, and data accessed or displayed through TrueWatch Mobile. Customers determine which data to ingest, how long to retain it, which fields to index, and which redaction or obfuscation controls to enable. As to this personal data, TrueWatch acts as processor under our Data Processing Agreement. Individuals wishing to exercise rights in relation to such data should contact the relevant customer. See Section 11.
Customer Data Ownership and Control
All data, including any personal data, that customers, resellers, or authorized users submit to, upload, generate, access, display, or process through the Services (the “Customer Data”) remains business data of the relevant customer or reseller. TrueWatch does not claim ownership over Customer Data, and processes Customer Data only to provide, secure and support the Services and as otherwise permitted by the applicable agreement, DPA and customer instructions.
Sensitive Data Caution
The Services are not intended to be used to collect or store special category or sensitive personal data (e.g. government-issued IDs, precise geolocation of consumers, financial account numbers, payment card data, health or biometric data) unless expressly permitted by the applicable agreements, DPA and applicable laws, and configured with appropriate safeguards. Customers should use masking, filtering, or drop-rules to prevent ingestion of such data.
If we become aware that sensitive data has been ingested, we may restrict processing, apply additional safeguards, and/or delete the data where feasible, consistent with the relevant agreement, DPA, and applicable law. Customers should contact support for assistance.
4. Sources of Personal Data
We collect personal data in a few ways. You provide data to us directly when you fill out a form, create an account, or contact support. We also collect data automatically through our website, TrueWatch Mobile app, SDKs, and similar technologies. In addition, we may obtain data from third-party sources like integration partners, event organizers, identity providers, resellers, public databases, and marketing providers, all in accordance with applicable laws.
5. Purposes and Legal Bases
We use personal data for the following purposes and rely on these legal bases for processing:
| Purposes | Activities | Legal Bases |
|---|---|---|
| Provide and administer the Services | Create accounts, provision workspaces, process transactions, provide support, enable mobile app access, send service alerts and notifications, and maintain security and availability | Contract necessity, legitimate interests |
| Secure and protect users, customers, and the Services | Fraud prevention, incident detection, debugging, crash reporting, diagnostics, performance monitoring, access controls, audit logs, and enforcing terms | Legitimate interests, legal obligation |
| Improve and develop the Services | Analytics, testing, quality assurance and product development using aggregated or de-identified information and, where permitted, limited controller data. | Legitimate interests, consent where required. |
| Communicate with you | Transactional notices, updates, service communications, alerts, push notifications, and, with consent or as permitted, marketing. | Contract necessity, legitimate interests, consent where required. |
| Compliance with laws and legal process, and to defend legal claims | - | Legal obligation, legitimate interests |
We do not sell personal data, and we do not use personal data for cross-context behavioral advertising.
Where required by applicable law, TrueWatch will obtain your consent before using your personal data for direct marketing purposes or sharing such data with partners for their own marketing activities. You may withdraw your consent at any time in accordance with Section 11 of this Privacy Notice.
AI/ML and Model Training
a. Customer Personal Data: We do not use personal data to train generalized or foundation AI models unless expressly agreed in writing with the customer. We process the Customer Personal Data only to provide and secure our Services and as otherwise permitted by the applicable agreement and DPA.
b. Controller Data: We may use aggregated and/or de-identified information derived from controller data (e.g., website analytics, product telemetry that does not identify an individual) to develop and improve our features, including for quality, reliability, and security. We never attempt to re-identify this data.
c. Your Choices: You have control over optional analytics or telemetry via product settings and SDK configurations.
d. AI Services: When you use TrueWatch AI Services:
• We may process prompts, instructions, Customer Data used for the requested task, generated outputs, feedback, approval records and activity logs.
• AI Services may analyze, recommend or perform actions with varying levels of automation, subject to applicable features, configurations, permissions and approval controls.
• Customers control the data made available, the configuration of the AI Services and the use of generated outputs or actions.
• We process the Customer Personal Data as a processor under the applicable agreement and DPA. Customers remain responsible for the legal basis, required notices and appropriate access, permission and approval controls.
Where enabled, certain features of the AI Services may be accessed through the TrueWatch Mobile. Regardless of how the AI Services are accessed, in limited cases, authorized personnel may review AI interactions and related records to provide support, investigate incidents, and prevent misuse, subject to access controls.
Aggregated, Anonymized and De-identified Information
We may use information that has been aggregated, anonymized or de-identified so that it cannot reasonably identify an individual.
We apply reasonable measures to maintain such information in that form and do not attempt to re-identify it, except to validate the effectiveness of our de-identification measures or as otherwise permitted by applicable law.
Information that remains capable of identifying an individual will continue to be treated as personal data.
6. Cookies and Similar Technologies
We currently do not use non-essential cookies on our website. Our TrueWatch Mobile app and SDKs may use similar technologies or identifiers that are necessary to provide, secure, monitor, and improve the Services, including for authentication, notifications, crash reporting, diagnostics, and performance monitoring. If we introduce cookies or similar technologies in the future, we will update this Privacy Notice and provide consent controls where required by law.
7. Disclosure of Personal Data
We may disclose your personal data to the following third parties for the purposes described below:
a. Professional Advisers: We may share data with professional advisers, such as lawyers, auditors, and insurers, under strict confidentiality agreements.
b. Legal Authorities: We may disclose your data to legal authorities when required by law or to protect our rights, safety, or integrity, as well as the rights, safety, or integrity of others.
c. Corporate Transactions: Your data may be disclosed in connection with a merger, financing, acquisition, or dissolution. We will ensure appropriate safeguards and provide notice as required by law.
d. Service Providers: We may disclose personal data to service providers that host, secure, support, operate or improve the Services, including providers of cloud infrastructure, TrueWatch Mobile app infrastructure, communications, push notifications, payment processing, customer support, analytics, crash reporting, diagnostics, performance monitoring and, where used, AI models or AI infrastructure.
e. Our Affiliates: Your data may be shared with our affiliated companies for internal administration, in a manner consistent with this Privacy Notice.
f. Partners and Resellers: If you procure our services through a partner or reseller, we may disclose your data to them.
We place strict contractual obligations on all recipients to protect your personal data. We also do not allow them to use your data for their own marketing purposes without your explicit consent.
Restrictions on Third-Party Use of Personal Data
Third parties receiving personal data from TrueWatch may process it only for the permitted purpose, subject to applicable law and contractual restrictions. They may not sell the personal data or use it for their own marketing unless authorized by the individual or otherwise permitted by applicable law.
Additional Lawful Disclosures
Where permitted by applicable law, TrueWatch may disclose limited and relevant personal data when necessary to:
a. provide or deliver the products or services requested by you;
b. facilitate, complete, support, or resolve transactions or disputes between users or business counterparties;
c. investigate, prevent, or address suspected or actual violations of applicable law, contractual obligations, or TrueWatch policies; or
d. protect the rights, property, security, or integrity of TrueWatch, our users, customers, partners, or others.
8. International Transfers
TrueWatch and its service providers may process personal data in countries other than the country where it was collected.
Where required by applicable law, TrueWatch uses recognized transfer mechanisms and safeguards, such as adequacy decisions, standard contractual clauses, transfer assessments and supplementary measures.
For transfers from Singapore, TrueWatch takes appropriate steps to ensure that transferred personal data receives a standard of protection comparable to that required under the Singapore PDPA.
9. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Notice, including to comply with legal obligations, maintain security, resolve disputes and enforce agreements.
Retention periods are determined by the nature and sensitivity of the data, the processing purpose, security risks, contractual requirements, applicable limitation periods and legal obligations. In particular:
| Type of Data | Duration |
|---|---|
| Website and Marketing Data | During relevant interaction or marketing relationship and for a reasonable period thereafter Opt-out records may be retained to honour communication preferences |
| Contact and Account Data | While the account or business relationship remains active and for a reasonable period thereafter for administration, security and dispute management |
| Commercial and Billing Data | During the transaction or contractual relationship and for any additional period required by tax, accounting or other applicable laws |
| Support and Communications | Until the relevant matter is resolved and for a reasonable period thereafter for service continuity, security and legal claims |
| Events and Programs Data | During the administration of the relevant event or program and a reasonable follow-up period |
| Telemetry, Diagnostics, Crash, Notification and Security Data | As long as reasonably necessary to provide, secure, monitor, troubleshoot and improve our Services |
| Customer Data | according to the customer’s configuration, the applicable agreement and DPA |
Backups
Personal data contained in backups is retained and overwritten on a rolling basis in accordance with our internal backup and disaster recovery procedures.
Backup data is not used for ordinary business purposes and will be deleted, overwritten or rendered inaccessible when the relevant backup expires, unless longer retention is required by applicable law or necessary to establish, exercise or defend legal claims.
Customer-Controlled Data Management and Deletion
Customers may manage, export or delete Customer Data through the product features made available by TrueWatch.
For a more convenient experience, TrueWatch Mobile may remember limited account and profile information on your Device. You remain in control and can clear this information through the TrueWatch Mobile settings.
Following termination of the Services or receipt of a valid documented request, TrueWatch will delete or return Customer Data in accordance with the applicable agreement, Data Processing Agreement, product functionality and applicable law.
Deletion may not be immediate where data remains in backups, security logs or records that TrueWatch is required to retain. Such data will remain protected and will be deleted or isolated in accordance with TrueWatch’s retention procedures.
Once Customer Data has been permanently deleted, it cannot be restored. Deletion or return of Customer Data applies to data held by TrueWatch within the Services. Customers and users remain responsible for any copies stored outside TrueWatch’s possession or control, including on user devices, customer systems, exports, screenshots, or third-party services.
10. Data Security
We hold ISO/IEC 27001, ISO/IEC 27017 and ISO/IEC 27018 certifications, and obtain a SOC 2 Type II report on a recurring basis, in each case within the scope stated in the applicable certificates and report. These certifications and reports do not constitute a guarantee that the Services will be free from all security incidents.
We take the security of your personal data seriously. We have implemented administrative, technical, and physical safeguards to protect your data from accidental or unlawful destruction, loss, alteration, and unauthorized access or disclosure. Our security measures include logical access controls, encryption for data both in transit and at rest, vulnerability management, secure software development practices, network segmentation, logging, monitoring, and safeguards for TrueWatch Mobile app access, where applicable. We also use continuous monitoring, logging, and personnel security measures.
In the event of a security incident, we have a defined incident response procedure. Where we act as controller, we will notify the relevant regulator and affected individuals where required by applicable law. Where we act as processor, we will notify the affected customer in accordance with the applicable agreement and DPA, and that customer is responsible for any notification to regulators or individuals.
11. Your Rights and Choices
Depending on your location, you may have specific rights regarding your personal data. These rights often include the ability to request access, correction, or deletion of your data, as well as the right to request a restriction on its processing, data portability, or to object to certain types of processing.
Where we process personal data on behalf of a customer as a processor, we are not able to respond to requests directly. We will refer the request to the relevant customer where we are able to identify them, or otherwise direct you to contact the organisation that provided the service you used. That customer is responsible for responding as the controller, and we will assist that customer as required under the applicable agreement and DPA.
Requests for deletion are subject to applicable legal, regulatory, contractual, or legitimate business obligations that may require us to retain certain personal data. To make a request, email [email protected] and tell us which right you wish to exercise.
Withdrawal of Consent
You may withdraw your consent for any optional data processing at any time by contacting us. Before giving effect to your withdrawal, we will inform you of the likely consequences, which may include our being unable to continue providing certain Services or features to you. Withdrawal will not affect the lawfulness of processing based on consent before its withdrawal.
Marketing Choices
You may opt out of marketing emails at any time by using the unsubscribe link in the email or by contacting us. You may continue to receive transactional, security or service-related communications.
Our Response Time
We will acknowledge and respond to verified requests within the period required by applicable law. Where permitted, we may extend the response period and will provide notice of the extension where required by applicable law.
a. EEA/UK (GDPR): We will respond within one month of receiving your request. This period can be extended by up to two further months for complex requests, and we will inform you of the extension and the reason for it within one month of receiving your request.
b. Singapore (PDPA): We will respond as soon as reasonably possible, and in any event within 30 calendar days of receiving your request. If we need more time, we will inform you within those 30 days of the timeframe within which we will respond. Where we are unable to provide the personal data or information requested, we will inform you of our reasons, except where we are not required to do so under applicable law.
c. California (CCPA): We will respond within 45 calendar days of receiving your request. This period can be extended by an additional 45 calendar days, and we will notify you of the extension. We will also acknowledge receipt of requests to know, delete or correct within 10 business days.
d. Indonesia (PDP Law): We will respond within the period required by applicable law, including within 3 × 24 hours where the PDP Law expressly requires the relevant action, subject to applicable conditions and exceptions.
Verifying Your Identity
To protect your personal data, we may take reasonable steps to verify your identity before fulfilling your request. This is to ensure that we are not providing your data to an unauthorized person. An authorized agent may submit a request on your behalf where permitted by law, subject to verification of the agent's authority. We will not discriminate against you for exercising any of your privacy rights. If identity cannot be verified, we may decline the request, and information collected for verification is used only for that purpose.
12. Region-Specific Disclosures
This section outlines specific data protection practices and rights that apply to individuals in certain jurisdictions.
12.1 European Economic Area (EEA), United Kingdom, and Switzerland
Where we act as controller and the GDPR or UK GDPR applies to our processing, our legal bases for processing are described in Section 5. You have the right to lodge a complaint with the competent data protection authority.
In our capacity as controller, we do not use personal data to make solely automated decisions that produce legal or similarly significant effects on individuals. Customers determine whether and how the Services, including the AI Services, are used within their own environments.
12.2 Singapore (PDPA)
As a Singapore company, TrueWatch processes personal data in accordance with the Singapore PDPA where it applies.
We limit the collection of NRIC or FIN numbers and use alternative identifiers where reasonably practicable, unless collection is required or permitted by applicable law.
Where permitted under the PDPA, we may charge a reasonable fee for responding to an access request. We will inform you of the fee before processing your request, and you may withdraw the request at that point.
12.3 California (CCPA)
For California residents, we act as a "business" in respect of personal information we control, to the extent the CCPA applies to us, and as a "service provider" in respect of personal information we process on behalf of our customers.
Subject to applicable conditions and exceptions, California residents may have the right to:
a. Know the categories and specific pieces of personal information collected about them.
b. Know the sources, purposes and categories of third parties involved.
c. Request access to, correction or deletion of personal information.
d. Opt out of the sale or sharing of personal information, where applicable.
e. Limit certain uses or disclosures of sensitive personal information, where applicable.
f. Exercise their rights without unlawful discrimination.
We do not sell or share personal information as those terms are defined under California privacy law, and we do not use or disclose sensitive personal information for purposes that would give rise to a right to limit that use under California law.
Requests may be submitted using the contact details in Section 16 or through any privacy request method made available through our Services. We may verify the requester’s identity and may accept requests submitted by an authorized agent where permitted by law.
12.4 Indonesia (PDP Law)
Where Indonesian law applies, we act as a personal data controller in respect of the personal data described in Section 2, and as a personal data processor in respect of Customer Data described in Section 3.
We have appointed a Data Protection Officer, whose contact details are set out in Section 16.
12.5 Other Jurisdictions
TrueWatch is established in Singapore and provides the Services to customers in a number of countries. Where the data protection law of your country applies to our processing, we will comply with that law and honour the rights it gives you.
In addition, as a minimum standard across all personal data we process, we apply technical, organisational and contractual measures that are no less protective than those required of a data processor under Articles 28, 32 and 33 of the GDPR, whether or not the GDPR applies. Where your local law imposes a stricter requirement, that requirement prevails.
13. Children’s Privacy
Our Services are intended for businesses and are not directed to children under the age of 13, or such other age as may be specified by applicable law in your jurisdiction.
We do not knowingly collect personal data from children except as permitted by applicable law.
If you believe that a child has provided personal data to TrueWatch, please contact us at [email protected]. We will review the request and take appropriate action in accordance with applicable law.
14. Third Party Links and Integrations
This Privacy Notice applies solely to our collection, use, and disclosure of your personal data. Our Services may, from time to time, contain links to third party websites, applications, plug-ins, or other services. We do not own, operate, or control these third parties, and they are not governed by this Privacy Notice.
We are not responsible for the privacy practices, data security, or content of such third-party services. We strongly encourage you to review the privacy notices and policies of any third-party websites or services you interact with before providing any personal data. Your use of such third-party services is at your own risk.
15. Changes to this Privacy Notice
We may update this Privacy Notice from time to time to reflect changes to our Services, data practices or legal requirements. The Last Updated date shows when this Privacy Notice was last revised.
We will post the updated Privacy Notice through our Services and provide additional notice or obtain consent where required by applicable law.
Changes take effect on the date stated in the updated Privacy Notice. Continued use of our Services after the stated effective date indicates that you have been informed of the updated Privacy Notice.
16. How to Contact Us
If you have any questions about our Privacy Notice, or to exercise your rights as detailed in this Privacy Notice, appeal our decision related to the exercise of your rights, or other related privacy issues, you may contact our Data Protection Officer at [email protected]
If you have any concerns about our adherence to this Privacy Notice, we encourage you to contact us directly. We will review and work to resolve any complaints or disputes related to the use and sharing of personal data in line with this Privacy Notice and relevant laws and regulations.
You may also reach out to us in writing at the following address:
TrueWatch Technology Inc Pte. Ltd.
Aspial One 55 Ubi Ave 3 #02-07
Singapore 408864
(+65) 6924-1094
[email protected]
