01

Introduction

Relatix ("Relatix", "we", "us", or "our"), registered at 2 Venture Drive, #11-30 Vision Exchange, Singapore 608526, provides a multi-agent AI workforce platform that unifies Sales, HR, Finance, Property Operations, and WhatsApp workflows, supported by AI copilots and automations (the "Services").

This Privacy Policy explains how we collect, use, disclose, and safeguard personal data when you visit relatix.io, use our web or agent applications (including agents.relatix.io), or otherwise interact with us. It is designed to meet our obligations under the Personal Data Protection Act 2012 (PDPA) of Singapore, and, for individuals located in the European Economic Area, United Kingdom, or Switzerland, the General Data Protection Regulation (GDPR) and equivalent UK legislation.

By using our Services, you acknowledge that you have read and understood this Policy. If you do not agree with it, please do not use the Services.

02

Scope, Roles, and Definitions

This Policy applies to: (a) visitors browsing our website; (b) prospective and current customers and their authorised representatives; (c) registered users of our platform; and (d) individuals whose personal data is uploaded by our business customers into the platform in the course of using our HR, CRM, Finance, or communications modules ("Customer Data").

2.1Data Controller / Organisation

For data collected directly from you as a visitor, prospect, or registered user, Relatix acts as the Data Controller (GDPR) / Organisation (PDPA).

2.2Data Processor

For Customer Data uploaded by a business customer (e.g. employee records, lead lists, tenant details, or WhatsApp contact data), Relatix acts as a Data Processor (GDPR) / Data Intermediary (PDPA). The business customer remains the Controller/Organisation responsible for ensuring a lawful basis exists for that data's collection and upload, and for responding to data subject requests concerning it, unless otherwise agreed in a Data Processing Agreement (DPA).

03

Personal Data We Collect

3.1Information you provide directly

  • Identity and contact data: full name, job title, company name, business email, phone number, business address.
  • Account data: login credentials, account preferences, role/permission settings.
  • Billing data: billing address, tax/GST identifiers, payment method details (processed via a third-party payment processor; we do not store full card numbers).
  • Communications: messages, support tickets, feedback, and content submitted through forms, chat, or WhatsApp integrations.

3.2Information collected automatically

  • Technical data: IP address, browser type and version, device identifiers, operating system.
  • Usage data: pages visited, features used, clickstream data, session duration, timestamps, log files.
  • Cookies and similar technologies (see Section 9).

3.3Customer Data processed on behalf of business customers

Where our business customers use HR, CRM, Finance, Property Ops, or WhatsApp modules, we process personal data of third parties (e.g. employees, job applicants, leads, tenants, or message recipients) strictly as instructed by that customer, under Section 2.2 above.

04

Purposes of Processing and Legal Bases

We process personal data for the following purposes:

  • To provide, operate, and maintain the Services, including AI agent workflows and automations.
  • To create and manage user accounts and authenticate access.
  • To process payments and manage billing.
  • To respond to enquiries, provide customer support, and communicate service updates.
  • To improve, secure, and develop the Services, including analytics and troubleshooting.
  • To comply with legal obligations, including tax, accounting, and regulatory requirements.
  • To detect, investigate, and prevent fraud, misuse, or security incidents.
  • With your consent, for marketing communications about new features or offerings (opt-out available at any time).

Under GDPR, our legal bases include: performance of a contract, compliance with a legal obligation, our legitimate interests (e.g. platform security, service improvement), and consent (e.g. marketing, non-essential cookies).

Under the PDPA, we rely on consent (express, deemed, or notification-based, as applicable) and the exceptions to consent set out in the PDPA's Schedules, such as the business improvement, legitimate interest, and legal/compliance exceptions.

05

AI Agents and Automated Processing

Certain features of the Services use AI copilots and autonomous agents to process data and trigger actions (e.g. drafting communications, updating records, scheduling tasks).

  • Human-in-the-loop review is required before any AI agent performs a sensitive or consequential action, such as sending external communications, modifying core financial or HR records, or taking an action with legal or financial effect.
  • You may request information about the logic involved in significant automated decisions affecting you, and, where applicable under GDPR Article 22 or PDPA obligations, request human review of such decisions.
  • AI models used to power the Services are not trained on customer data without explicit, separate authorisation.
06

Disclosure and Sharing of Personal Data

We do not sell personal data. We may share personal data with:

  • Sub-processors and vendors who support our operations (e.g. cloud hosting, payment processing, analytics, customer support tooling), under contractual confidentiality and data protection obligations.
  • Professional advisers (legal, accounting, audit) as necessary.
  • Regulators, law enforcement, or courts where required by law or to protect our legal rights.
  • A successor entity in the event of a merger, acquisition, financing, or sale of assets, subject to equivalent privacy protections.

A current list of sub-processors is available on request.

07

International Data Transfers

Personal data may be transferred to, stored, and processed in countries other than where you are located, including Singapore and other jurisdictions where our infrastructure or vendors operate.

  • PDPA: Where data is transferred outside Singapore, we take reasonable steps to ensure the recipient is bound by legally enforceable obligations providing a standard of protection comparable to the PDPA (e.g. contractual clauses, or transfer to jurisdictions with comparable data protection laws).
  • GDPR: Where personal data of EEA/UK/Swiss individuals is transferred outside those regions, we rely on adequacy decisions or appropriate safeguards such as the European Commission's Standard Contractual Clauses (SCCs) or the UK International Data Transfer Addendum.
08

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes described in this Policy, including satisfying legal, accounting, or reporting requirements. When personal data is no longer needed, we securely delete, anonymise, or archive it in accordance with our data retention schedule. Customer Data is retained per the terms agreed with the relevant business customer, and deleted or returned upon termination of the applicable service agreement, subject to legal retention obligations.

09

Cookies and Tracking Technologies

We use cookies and similar technologies to operate the Services, remember preferences, and analyse usage. You can manage cookie preferences through our cookie banner/settings or your browser settings. Disabling certain cookies may affect functionality.

10

Security Measures

  • Encryption of data in transit (TLS 1.2+) and at rest (AES-256).
  • Role-based access controls and the principle of least privilege.
  • Multi-factor authentication (MFA) for administrative and privileged access.
  • Continuous monitoring, audit logging, and periodic penetration testing.
  • Processes aligned with GDPR, PDPA, and, where applicable, SOC 2 Type II and HIPAA-aligned practices.

No method of transmission or storage is 100% secure. We cannot guarantee absolute security but will notify affected individuals and the relevant regulator(s) of a data breach where required by law (including under the PDPA's mandatory data breach notification regime and, where applicable, GDPR Articles 33–34).

11

Your Rights

11.1Rights under the PDPA

  • Right to withdraw consent to the collection, use, or disclosure of your personal data (subject to legal or contractual restrictions).
  • Right to access personal data we hold about you and how it has been used or disclosed in the past year.
  • Right to request correction of inaccurate or incomplete personal data.

11.2Rights under the GDPR (EEA/UK/Swiss individuals)

  • Right of access, rectification, and erasure ("right to be forgotten").
  • Right to restrict or object to processing.
  • Right to data portability.
  • Right to withdraw consent at any time, without affecting prior lawful processing.
  • Right to lodge a complaint with a supervisory authority (e.g. your national Data Protection Authority, or the ICO in the UK).

To exercise any of these rights, contact our Data Protection Officer using the details in Section 14. We may need to verify your identity before actioning a request.

12

Children's Data

Our Services are intended for business use by individuals aged 18 and above. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected such data, we will take steps to delete it.

13

Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices or legal requirements. Material changes will be notified via email or a prominent notice on our website prior to the change taking effect. The "Last Updated" date at the top of this Policy indicates when it was last revised.

14

Contact Us / Data Protection Officer

If you have questions, concerns, or requests regarding this Policy or your personal data, please contact:

Relatix

Data Protection Officer
Relatix
Registered Address
2 Venture Drive, #11-30 Vision Exchange, Singapore 608526
PDPC Complaints
Singapore Personal Data Protection Commission — www.pdpc.gov.sg
EU/UK Complaints
Your local Data Protection Authority, or the UK Information Commissioner's Office (ICO) — www.ico.org.uk