Skip to content
Now soft-launching in New Zealand & AustraliaJoin the founding cohort →US & UK rolling out 2026/2027
Pricing

Soft-launching NZ & AU · US & UK rolling out 2026/2027

🇸🇬

Singapore Compliance

PDPA Compliance Statement

Personal Data Protection Act 2012 (amended 2020) — Marco Reid’s obligations, data processing pipeline, and your rights as a Singapore user.

Effective: 1 January 2021 · Last reviewed: June 2026

Data Protection Officer (DPO)

dpo@marcoreid.com

Designated DPO per PDPA Section 11. Responds within 2 business days. Subject access requests fulfilled within 30 days.

Supervisory authority

PDPC — Personal Data Protection Commission.

The Personal Data Protection Commission (PDPC) of Singapore is the competent supervisory authority for PDPA compliance. Singapore users may lodge complaints directly with the PDPC at pdpc.gov.sg.

Data collection

What we collect and why.

Account information

Name, email address, firm name, hashed password.

Account creation and authentication. Required to provide the platform.

Professional information

Practice area, jurisdiction, professional credentials (where provided).

Personalise the platform experience and jurisdictional features.

Client data

Information you upload about your clients: names, contact details, matter information, documents, time entries, trust records.

Delivering case management, billing, and document services. You are the data controller for client data; we process it on your behalf.

Research queries

Queries submitted to Marco, AI-generated responses, citation verification status, user feedback.

Delivering AI research results and improving research accuracy.

Voice data

Audio recordings submitted for transcription, transcribed text, detected language.

Delivering dictation and transcription services via Marco Reid Voice.

Payment data

Billing information processed by Stripe. No card numbers stored by Marco Reid.

Subscription billing and invoice management.

AI processing pipeline

How AI processing works.

When you submit a research query or voice recording, data is transmitted to third-party processors operating under contractual safeguards. This disclosure is required under both the PDPA Transfer Limitation obligation (Singapore) and NZ Privacy Amendment Act IPP 3A (New Zealand).

AI processing disclosure

AI processing on Marco Reid occurs via the Anthropic Claude API. Anthropic operates servers in the United States. All data transmitted to Anthropic is protected by a Data Processing Agreement with contractual safeguards meeting the PDPA Transfer Limitation requirements under Section 26 of the PDPA 2012 (amended 2020). Your data is never used to train AI models. Anthropic does not retain API data beyond the API session.

Transfer limitation (PDPA Section 26)

Third-party processors and safeguards.

Every processor that handles Singapore user data operates under a contractual Data Processing Agreement meeting PDPA Transfer Limitation requirements. No data is transferred without a legal basis.

ProcessorLocationPurposeData typeSafeguard
Anthropic (Claude API)United StatesAI research query processing and response generationResearch query textContractual data processing agreement with PDPA Transfer Limitation safeguards. Data not used for model training.
NeonEU / United StatesPostgreSQL database hosting for all platform dataAccount data, matter data, billing recordsAES-256 encryption at rest. TLS 1.3 in transit. Contractual DPA executed.
VercelUnited StatesPlatform hosting and global edge deliveryRequest metadata, session tokensContractual DPA. Data processed only for delivery of platform services.
StripeUnited StatesPayment processing and subscription managementBilling and payment informationPCI DSS Level 1 certified. Contractual DPA. No card data retained by Marco Reid.
MailgunUnited StatesTransactional email delivery (account notifications, security alerts)Email address, notification contentContractual DPA. Email content limited to service communications.

Your rights

Rights under the PDPA.

Right of Access

Request a copy of your personal data held by Marco Reid. We will respond within 30 days.

Right to Correction

Request correction of any inaccurate or incomplete personal data. We will correct or update within 10 business days.

Right to Withdraw Consent

Withdraw consent to processing at any time. Withdrawal does not affect lawfulness of prior processing. Contact dpo@marcoreid.com.

Right to Data Portability

Receive your data in a structured, machine-readable format (JSON or CSV) suitable for transfer to another service.

Right to Lodge a Complaint

File a complaint with the Personal Data Protection Commission (PDPC) of Singapore at pdpc.gov.sg if you believe we have breached the PDPA.

Breach notification

How we respond to data incidents.

In the event of a data breach that may result in significant harm to affected individuals, Marco Reid will notify: (a) the Personal Data Protection Commission (PDPC) as soon as practicable and within the timeframe required under the PDPA mandatory breach notification obligation (effective 1 February 2021); and (b) affected individuals as soon as practicable with information about the breach, likely consequences, and measures taken.

All security incidents are logged in our immutable audit trail. Our incident response plan is reviewed quarterly. For security concerns, contact dpo@marcoreid.com.

Questions about your data?

Contact our Data Protection Officer at any time. We respond within 2 business days. Subject access requests fulfilled within 30 days.

Singapore supervisory authority: Personal Data Protection Commission (PDPC) — pdpc.gov.sg