🇸🇬
Singapore Compliance
PDPA Compliance Statement
Personal Data Protection Act 2012 (amended 2020) — Marco Reid’s obligations, data processing pipeline, and your rights as a Singapore user.
Effective: 1 January 2021 · Last reviewed: June 2026
Data Protection Officer (DPO)
dpo@marcoreid.com
Designated DPO per PDPA Section 11. Responds within 2 business days. Subject access requests fulfilled within 30 days.
Supervisory authority
PDPC — Personal Data Protection Commission.
The Personal Data Protection Commission (PDPC) of Singapore is the competent supervisory authority for PDPA compliance. Singapore users may lodge complaints directly with the PDPC at pdpc.gov.sg.
Data collection
What we collect and why.
Account information
Name, email address, firm name, hashed password.
Account creation and authentication. Required to provide the platform.
Professional information
Practice area, jurisdiction, professional credentials (where provided).
Personalise the platform experience and jurisdictional features.
Client data
Information you upload about your clients: names, contact details, matter information, documents, time entries, trust records.
Delivering case management, billing, and document services. You are the data controller for client data; we process it on your behalf.
Research queries
Queries submitted to Marco, AI-generated responses, citation verification status, user feedback.
Delivering AI research results and improving research accuracy.
Voice data
Audio recordings submitted for transcription, transcribed text, detected language.
Delivering dictation and transcription services via Marco Reid Voice.
Payment data
Billing information processed by Stripe. No card numbers stored by Marco Reid.
Subscription billing and invoice management.
AI processing pipeline
How AI processing works.
When you submit a research query or voice recording, data is transmitted to third-party processors operating under contractual safeguards. This disclosure is required under both the PDPA Transfer Limitation obligation (Singapore) and NZ Privacy Amendment Act IPP 3A (New Zealand).
AI processing disclosure
AI processing on Marco Reid occurs via the Anthropic Claude API. Anthropic operates servers in the United States. All data transmitted to Anthropic is protected by a Data Processing Agreement with contractual safeguards meeting the PDPA Transfer Limitation requirements under Section 26 of the PDPA 2012 (amended 2020). Your data is never used to train AI models. Anthropic does not retain API data beyond the API session.
Transfer limitation (PDPA Section 26)
Third-party processors and safeguards.
Every processor that handles Singapore user data operates under a contractual Data Processing Agreement meeting PDPA Transfer Limitation requirements. No data is transferred without a legal basis.
| Processor | Location | Purpose | Data type | Safeguard |
|---|---|---|---|---|
| Anthropic (Claude API) | United States | AI research query processing and response generation | Research query text | Contractual data processing agreement with PDPA Transfer Limitation safeguards. Data not used for model training. |
| Neon | EU / United States | PostgreSQL database hosting for all platform data | Account data, matter data, billing records | AES-256 encryption at rest. TLS 1.3 in transit. Contractual DPA executed. |
| Vercel | United States | Platform hosting and global edge delivery | Request metadata, session tokens | Contractual DPA. Data processed only for delivery of platform services. |
| Stripe | United States | Payment processing and subscription management | Billing and payment information | PCI DSS Level 1 certified. Contractual DPA. No card data retained by Marco Reid. |
| Mailgun | United States | Transactional email delivery (account notifications, security alerts) | Email address, notification content | Contractual DPA. Email content limited to service communications. |
Your rights
Rights under the PDPA.
Right of Access
Request a copy of your personal data held by Marco Reid. We will respond within 30 days.
Right to Correction
Request correction of any inaccurate or incomplete personal data. We will correct or update within 10 business days.
Right to Withdraw Consent
Withdraw consent to processing at any time. Withdrawal does not affect lawfulness of prior processing. Contact dpo@marcoreid.com.
Right to Data Portability
Receive your data in a structured, machine-readable format (JSON or CSV) suitable for transfer to another service.
Right to Lodge a Complaint
File a complaint with the Personal Data Protection Commission (PDPC) of Singapore at pdpc.gov.sg if you believe we have breached the PDPA.
Breach notification
How we respond to data incidents.
In the event of a data breach that may result in significant harm to affected individuals, Marco Reid will notify: (a) the Personal Data Protection Commission (PDPC) as soon as practicable and within the timeframe required under the PDPA mandatory breach notification obligation (effective 1 February 2021); and (b) affected individuals as soon as practicable with information about the breach, likely consequences, and measures taken.
All security incidents are logged in our immutable audit trail. Our incident response plan is reviewed quarterly. For security concerns, contact dpo@marcoreid.com.
Questions about your data?
Contact our Data Protection Officer at any time. We respond within 2 business days. Subject access requests fulfilled within 30 days.
Singapore supervisory authority: Personal Data Protection Commission (PDPC) — pdpc.gov.sg