Relatix ("Relatix", "we", "us", or "our"), registered at 2 Venture Drive, #11-30 Vision
Exchange, Singapore 608526, provides a multi-agent AI workforce platform that unifies
Sales, HR, Finance, Property Operations, and WhatsApp workflows, supported by AI
copilots and automations (the "Services").
This Privacy Policy explains how we collect, use, disclose, and safeguard personal data
when you visit relatix.io, use our web or agent applications (including
agents.relatix.io), or otherwise interact with us. It is designed to meet our
obligations under the Personal Data Protection Act 2012 (PDPA) of Singapore, and, for
individuals located in the European Economic Area, United Kingdom, or Switzerland, the
General Data Protection Regulation (GDPR) and equivalent UK legislation.
By using our Services, you acknowledge that you have read and understood this Policy.
If you do not agree with it, please do not use the Services.
02
Scope, Roles, and Definitions
This Policy applies to: (a) visitors browsing our website; (b) prospective and current
customers and their authorised representatives; (c) registered users of our platform;
and (d) individuals whose personal data is uploaded by our business customers into the
platform in the course of using our HR, CRM, Finance, or communications modules
("Customer Data").
2.1Data Controller / Organisation
For data collected directly from you as a visitor, prospect, or registered user,
Relatix acts as the Data Controller (GDPR) / Organisation (PDPA).
2.2Data Processor
For Customer Data uploaded by a business customer (e.g. employee records, lead lists,
tenant details, or WhatsApp contact data), Relatix acts as a Data Processor (GDPR) /
Data Intermediary (PDPA). The business customer remains the Controller/Organisation
responsible for ensuring a lawful basis exists for that data's collection and upload,
and for responding to data subject requests concerning it, unless otherwise agreed in a
Data Processing Agreement (DPA).
03
Personal Data We Collect
3.1Information you provide directly
Identity and contact data: full name, job title, company name, business email, phone number, business
address.
Billing data: billing address, tax/GST identifiers, payment method details (processed via a
third-party payment processor; we do not store full card numbers).
Communications: messages, support tickets, feedback, and content submitted through forms, chat, or
WhatsApp integrations.
3.2Information collected automatically
Technical data: IP address, browser type and version, device identifiers, operating system.
3.3Customer Data processed on behalf of business customers
Where our business customers use HR, CRM, Finance, Property Ops, or WhatsApp modules, we
process personal data of third parties (e.g. employees, job applicants, leads, tenants,
or message recipients) strictly as instructed by that customer, under Section 2.2 above.
04
Purposes of Processing and Legal Bases
We process personal data for the following purposes:
To provide, operate, and maintain the Services, including AI agent workflows and automations.
To create and manage user accounts and authenticate access.
To process payments and manage billing.
To respond to enquiries, provide customer support, and communicate service updates.
To improve, secure, and develop the Services, including analytics and troubleshooting.
To comply with legal obligations, including tax, accounting, and regulatory requirements.
To detect, investigate, and prevent fraud, misuse, or security incidents.
With your consent, for marketing communications about new features or offerings (opt-out available at
any time).
Under GDPR, our legal bases include: performance of a contract, compliance with a legal
obligation, our legitimate interests (e.g. platform security, service improvement), and
consent (e.g. marketing, non-essential cookies).
Under the PDPA, we rely on consent (express, deemed, or notification-based, as
applicable) and the exceptions to consent set out in the PDPA's Schedules, such as the
business improvement, legitimate interest, and legal/compliance exceptions.
05
AI Agents and Automated Processing
Certain features of the Services use AI copilots and autonomous agents to process data
and trigger actions (e.g. drafting communications, updating records, scheduling tasks).
Human-in-the-loop review is required before any AI agent performs a sensitive or consequential action,
such as sending external communications, modifying core financial or HR records, or taking an action
with legal or financial effect.
You may request information about the logic involved in significant automated decisions affecting you,
and, where applicable under GDPR Article 22 or PDPA obligations, request human review of such decisions.
AI models used to power the Services are not trained on customer data without explicit, separate
authorisation.
06
Disclosure and Sharing of Personal Data
We do not sell personal data. We may share personal data with:
Sub-processors and vendors who support our operations (e.g. cloud hosting, payment processing,
analytics, customer support tooling), under contractual confidentiality and data protection obligations.
Professional advisers (legal, accounting, audit) as necessary.
Regulators, law enforcement, or courts where required by law or to protect our legal rights.
A successor entity in the event of a merger, acquisition, financing, or sale of assets, subject to
equivalent privacy protections.
A current list of sub-processors is available on request.
07
International Data Transfers
Personal data may be transferred to, stored, and processed in countries other than
where you are located, including Singapore and other jurisdictions where our
infrastructure or vendors operate.
PDPA: Where data is transferred outside Singapore, we take reasonable steps to ensure
the recipient is bound by legally enforceable obligations providing a standard of protection comparable
to the PDPA (e.g. contractual clauses, or transfer to jurisdictions with comparable data protection
laws).
GDPR: Where personal data of EEA/UK/Swiss individuals is transferred outside those
regions, we rely on adequacy decisions or appropriate safeguards such as the European Commission's
Standard Contractual Clauses (SCCs) or the UK International Data Transfer Addendum.
08
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes described
in this Policy, including satisfying legal, accounting, or reporting requirements. When
personal data is no longer needed, we securely delete, anonymise, or archive it in
accordance with our data retention schedule. Customer Data is retained per the terms
agreed with the relevant business customer, and deleted or returned upon termination of
the applicable service agreement, subject to legal retention obligations.
09
Cookies and Tracking Technologies
We use cookies and similar technologies to operate the Services, remember preferences,
and analyse usage. You can manage cookie preferences through our cookie banner/settings
or your browser settings. Disabling certain cookies may affect functionality.
10
Security Measures
Encryption of data in transit (TLS 1.2+) and at rest (AES-256).
Role-based access controls and the principle of least privilege.
Multi-factor authentication (MFA) for administrative and privileged access.
Continuous monitoring, audit logging, and periodic penetration testing.
Processes aligned with GDPR, PDPA, and, where applicable, SOC 2 Type II and HIPAA-aligned practices.
No method of transmission or storage is 100% secure. We cannot guarantee absolute
security but will notify affected individuals and the relevant regulator(s) of a data
breach where required by law (including under the PDPA's mandatory data breach
notification regime and, where applicable, GDPR Articles 33–34).
11
Your Rights
11.1Rights under the PDPA
Right to withdraw consent to the collection, use, or disclosure of your personal data (subject to
legal or contractual restrictions).
Right to access personal data we hold about you and how it has been used or disclosed in the past
year.
Right to request correction of inaccurate or incomplete personal data.
11.2Rights under the GDPR (EEA/UK/Swiss individuals)
Right of access, rectification, and erasure ("right to be forgotten").
Right to restrict or object to processing.
Right to data portability.
Right to withdraw consent at any time, without affecting prior lawful processing.
Right to lodge a complaint with a supervisory authority (e.g. your national Data Protection Authority,
or the ICO in the UK).
To exercise any of these rights, contact our Data Protection Officer using the details
in Section 14. We may need to verify your identity before actioning a request.
12
Children's Data
Our Services are intended for business use by individuals aged 18 and above. We do not
knowingly collect personal data from children. If we become aware that we have
inadvertently collected such data, we will take steps to delete it.
13
Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices or
legal requirements. Material changes will be notified via email or a prominent notice
on our website prior to the change taking effect. The "Last Updated" date at the top of
this Policy indicates when it was last revised.
14
Contact Us / Data Protection Officer
If you have questions, concerns, or requests regarding this Policy or your personal
data, please contact: