Privacy Policy
Last updated: July 23, 2026
‘Poiro’ is a brand under which artificial-intelligence-enabled content-production services and software are offered. The Poiro entity that determines the purposes and means of the processing described in this Privacy Policy, and which is therefore the controller of your personal data, is Poiro Pte. Ltd. (UEN 202424341K), a private limited company incorporated under the laws of the Republic of Singapore and having its registered address at 160 Robinson Road, 19-08 SBF Center, Singapore 068914 (“Poiro”, “we”, “us”, or “our”). This Privacy Policy explains what personal data we collect, how and why we use, disclose, transfer, and protect it, and the rights available to the individuals concerned. It should be read together with our Terms of Service and our Cookie Policy.
1.Scope of this Policy
1.1 This Policy applies to personal data that we process in our own right as a controller (or an 'organisation' in Singapore under the Personal Data Protection Act 2012), including the personal data of: (a) visitors to our website; (b) users of the Poiro platform and/or services (the "Platform"); and (c) individuals who make an enquiry or request a proposal.
1.2 This Policy does not apply to personal data contained in materials supplied to us by a client for the purpose of producing content (the "Client Materials"). In relation to that personal data, we act as a data processor (or a 'data intermediary' in Singapore), and the client is the controller. Our processing of it is governed by the service agreement agreed with that client, and any request in relation to it should be directed to the client.
1.3 We provide our services from Singapore to clients globally. Depending on where you are located, one or more of the following may apply to our processing of your personal data: (a) the Personal Data Protection Act 2012 of Singapore (the "PDPA"); (b) the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 of India (together, the "DPDP Framework"); (c) Law No. 27 of 2022 on Personal Data Protection of the Republic of Indonesia (the "Indonesian PDP Law"); (d) Regulation (EU) 2016/679 (the "GDPR") and the United Kingdom GDPR; and (e) the privacy laws of certain states of the United States. Rights and obligations specific to a jurisdiction are set out in Clause 12 (Jurisdiction-Specific Rights).
2.Our Role: Controller & Processor
2.1 We act as a 'controller' in respect of personal data collected through our website and the Platform, and in connection with inquiries and proposals, marketing, client and supplier relationship management, billing, and recruitment.
2.2 We act as a 'processor' with respect to personal data contained in Client Materials. In that capacity, we process personal data only in accordance with the client's documented instructions, and we make data-processing terms available to every client.
2.3 Where we act as a processor, the client remains responsible for establishing the lawful basis for the processing and for giving the notices and obtaining the consents required in respect of it.
3.Personal Data We Collect
3.1 Data you provide to us. Your name; business or personal email address; telephone number; job title; company name and business information; the content of your inquiry, brief, or correspondence with us; billing and payment details; and, where you apply for a role with us, your curriculum vitae and related information.
3.2 Data you provide through the Platform. Account registration details, authentication data, subscription and billing information, prompts and instructions you enter, content you upload, and the outputs you generate. Where you use the Platform as a consumer rather than on behalf of a business, we process the same categories of data in our capacity as controller.
3.3 Data collected automatically. Internet protocol address, device and browser type, operating system, referring page, pages viewed, features used, and time spent. Further information is set out in our Cookie Policy at https://poiro.com/cookie-policy.
3.4 Data obtained from third parties. Publicly available business information; information from professional networks; referrals; and information from our hosting, analytics, payment, and communications providers.
3.5 Images and content supplied by clients. Client Materials supplied to us for content production may contain photographs, video, audio, or other content depicting an identifiable individual. We process that content as a processor in accordance with Clause 2.2. We do not collect it from the individual concerned, and the client is responsible for the lawful basis, notices, and consents required in respect of it.
3.6 Special & Sensitive Categories. We do not intentionally collect special categories of personal data, sensitive personal data, or specific personal data, as those expressions are used under the GDPR, the DPDP framework, and the Indonesian PDP Law. Clients shall not supply such data to us, save where expressly agreed in writing and subject to appropriate safeguards.
4.Purposes of Processing & Legal Bases
4.1 We process personal data for the purposes and on the legal bases set out below.
4.1.1 Responding to inquiries and preparing proposals — Personal Data: name, email, telephone, company, inquiry content. Legal Basis: Consent; performance of a contract or steps taken at your request prior to entering into a contract; legitimate interests in responding to business inquiries.
4.1.2 Providing the Platform and administering your account — Personal Data: account, authentication, subscription, usage, and content data. Legal Basis: Performance of a contract; legitimate interests in operating and securing the Platform.
4.1.3 Providing the managed services and managing the client relationship — Personal Data: contact and account data; correspondence; Client Materials. Legal Basis: Performance of a contract; legitimate interests in managing the relationship.
4.1.4 Invoicing, payment, accounting, and tax — Personal Data: billing and payment data. Legal Basis: Performance of a contract; compliance with a legal obligation.
4.1.5 Marketing — Personal Data: name, email, company. Legal Basis: Consent; legitimate interests where permitted. In Singapore, subject to the Do Not Call provisions of Part IX of the PDPA.
4.1.6 Security, fraud prevention, and service improvement — Personal Data: technical and usage data, in aggregated and de-identified form. Legal Basis: Legitimate interests in securing and improving our services.
4.1.7 Compliance with law and the establishment or defence of legal claims — Personal Data: any of the above, as relevant. Legal Basis: Compliance with a legal obligation; legitimate interests in establishing or defending legal claims.
4.2 Where we rely on consent, you may withdraw it at any time in accordance with Clause 11 (Your Rights). Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
5.Artificial-Intelligence Systems & Your Data
5.1 We may configure, tune, or build brand-specific systems and workflows using a client's brand assets and content, solely in order to deliver the services requested by that client.
5.2 We do not use a client's brand assets, creative content, or proprietary materials to train foundation models or other publicly available artificial-intelligence models, and we do not use them to inform, improve, or benefit the outputs generated for any other client.
5.3 We maintain logical separation between the data of each client.
5.4 Where we use third-party artificial-intelligence models to deliver the services, we contract with the relevant providers, whether directly or through an aggregator, on terms that restrict their use of client inputs, including, where available, terms providing that inputs are not used for training and are subject to zero retention.
5.5 We do not use personal data collected through our website or the Platform to train any artificial-intelligence model.
6.Disclosure of Personal Data
6.1 We also provide a managed service. Authorized Poiro personnel may access, review, and work with the Client Materials, and with the content generated from them, in order to produce the deliverables requested, to carry out quality assurance, and to diagnose and improve the Services. Access is limited to personnel who require it to perform their roles, and every such person is bound by a confidentiality obligation.
6.2 We may also disclose personal data to:
6.2.1 service providers and sub-processors who act on our instructions, including hosting, storage, analytics, communications, payment, and artificial-intelligence model providers;
6.2.2 other entities operating under the Poiro brand, for the purposes set out in this Policy;
6.2.3 our professional advisers, including legal, accounting, audit, and insurance advisers;
6.2.4 a purchaser or prospective purchaser, in connection with a merger, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality undertakings;
6.2.5 a court, regulator, or law-enforcement authority, where required by law or where necessary to establish, exercise, or defend legal claims; and
6.2.6 any other person with your consent.
6.3 We do not sell personal data. We use third-party analytics and advertising technologies on our website, including Google Analytics and the Meta Pixel, which may involve a sharing of personal data for cross-context behavioural advertising or targeted advertising, as those expressions are used under the privacy laws of certain states of the United States. You may opt out at any time as described in Clause 12 (Jurisdiction-Specific Rights) and in our Cookie Policy.
7.International Transfers
7.1 We process personal data in Singapore. Our service providers and sub-processors may process personal data in other jurisdictions, including India.
7.2 Where we transfer personal data out of Singapore, we do so only where the recipient is bound by legally enforceable obligations to provide the transferred personal data with a standard of protection comparable to that under the PDPA, in accordance with Section 26 of the PDPA and Regulation 10 of the Personal Data Protection Regulations 2021.
7.3 Where we transfer personal data out of the European Economic Area or the United Kingdom, we do so on the basis of an adequacy decision or, where none applies, the standard contractual clauses approved by the European Commission, together with the United Kingdom Addendum, where relevant, supplemented by additional measures where necessary.
7.4 Where the DPDP framework applies, we transfer personal data only in accordance with that framework and subject to any restriction notified by the Central Government of India.
7.5 Where the Indonesian PDP Law applies, we transfer personal data only in accordance with Article 56 of that Law.
7.6 A copy of the safeguards applicable to a transfer is available on request from the contact in Clause 16 (Contact & Data Protection Officer).
8.Security
8.1 We implement technical and organizational measures appropriate to the risk, including encryption of personal data in transit and at rest, role-based access controls and multi-factor authentication, logical separation of client data, logging and monitoring, vendor due diligence, and staff training.
8.2 No method of transmission or storage is entirely secure, and we cannot guarantee absolute security.
9.Personal Data Breach Notification
If we become aware of a personal data breach affecting personal data for which we are responsible, we shall act without undue delay to contain and assess it, and shall notify affected individuals and the relevant authorities as required by applicable law, including as set out below.
9.1 Singapore. Where a data breach is assessed to be notifiable under Part VIA of the PDPA, that is, where it results in, or is likely to result in, significant harm to an affected individual, or is of a significant scale, we shall notify the Personal Data Protection Commission as soon as practicable and in any event no later than 3 (Three) calendar days after completing that assessment, and shall notify the affected individuals where the breach is likely to result in significant harm to them.
9.2 Indonesia. Where the Indonesian PDP Law applies, we shall provide written notice to the affected data subjects and the competent authority within 72 (Seventy Two) hours of becoming aware of the breach.
9.3 European Union & United Kingdom. Where the GDPR or the United Kingdom GDPR applies, we shall notify the competent supervisory authority without undue delay and, where feasible, not later than 72 (Seventy-Two) hours after becoming aware of the breach, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons, and we shall inform the affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
9.4 India. Where the DPDP framework applies, we shall intimate each affected data principal without delay, in a concise, clear, and plain manner, describing the nature and extent of the breach, its likely consequences, the measures we are taking to mitigate it, the steps that the data principal may take, and a contact point for queries. We shall also intimate the Data Protection Board of India, giving an initial description of the breach without delay and a detailed report within 72 (Seventy-Two) hours of becoming aware of it, or within such longer period as the Board may allow on a request made in writing.
9.5 United States. Where the law of a state of the United States applies, we shall notify affected residents and, where required, the relevant Attorney General, within the period prescribed by that law.
9.6 Where we act as a Processor. Where we process personal data on behalf of a client, we shall notify that client without undue delay on becoming aware of a personal data breach affecting that personal data, so that the client may discharge its own notification obligations.
10.Retention
10.1 We retain personal data only for as long as necessary for the purposes for which it was collected, or for as long as required by law.
10.2 Inquiry and prospect data is retained for 36 (Thirty-Six) months from the last interaction. Platform account data is retained for the subscription term and for 36 (Thirty-Six) months thereafter. Client records are retained for the term of the engagement and thereafter for the applicable limitation period. Accounting records are retained for the period prescribed by law.
10.3 On termination of an engagement or of a Platform subscription, we delete or anonymize the Client Materials and your content within 90 (Ninety) days, subject to the export window in the Terms of Service, to any legal-retention requirement, and to the terms of the applicable Service Order.
11.Your Rights
11.1 Subject to the law applicable to you, you may have the right to request access to (a) your personal data; (b) to request its correction, completion, or updating; (c) to request its erasure; (d) to withdraw consent; (e) to object to or restrict processing; (f) to request portability; and (g) to lodge a complaint with a supervisory authority.
11.2 To exercise a right, please contact our Data Protection Officer using the details in Clause 16 (Contact & Data Protection Officer). We may require information sufficient to verify your identity before acting on a request.
11.3 We shall respond within the period required by the law applicable to you and, in any event, without undue delay. We do not charge a fee unless a request is manifestly unfounded or excessive.
12.Jurisdiction-Specific Rights
12.1 Singapore. You may request access to, and correction of, your personal data under Parts V and VI of the PDPA, and may withdraw consent on reasonable notice. Where we are unable to respond to an access request within 30 (Thirty) days, we shall inform you of the time by which we will respond. You may lodge a complaint with the Personal Data Protection Commission.
12.2 India. Where the DPDP framework applies, you have the right: (a) to obtain a summary of the personal data processed and of the processing activities undertaken; (b) to seek correction, completion, updating, and erasure; (c) to nominate another individual to exercise your rights in the event of death or incapacity; and (d) to grievance redressal. Grievances should be addressed to our Data Protection Officer in the first instance, and may thereafter be made to the Data Protection Board of India.
12.3 European Economic Area & United Kingdom. Where the GDPR or the United Kingdom GDPR applies, you have the rights of access, rectification, erasure, restriction of processing, data portability, and objection, including the right to object at any time to processing for direct marketing. You have the right not to be subject to a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you. You may lodge a complaint with your supervisory authority. Our representatives appointed under Article 27 of the GDPR and of the United Kingdom GDPR are identified in Clause 16 (Contact & Data Protection Officer). We shall respond without undue delay and in any event within 1 (One) month of receipt of your request. That period may be extended by up to a further 2 (Two) months where necessary, taking into account the complexity and number of requests, in which case we shall inform you of the extension, and of the reasons for it, within 1 (One) month of receipt. Where we do not act on your request, we shall inform you without delay, and at the latest within 1 (One) month of receipt, of the reasons why and of your right to lodge a complaint with a supervisory authority and to seek a judicial remedy. You may lodge a complaint with your supervisory authority at any time.
12.4 Indonesia. Where the Indonesian PDP Law applies, you have the rights: (a) to information about, and access to, your personal data; (b) to rectification; (c) to erasure and destruction; (d) to withdraw consent; (e) to object to decision-making based solely on automated processing; (f) to restrict processing; (g) to data portability; and (h) to claim compensation for loss arising from a breach of that law.
12.5 United States, including California. We do not sell personal information. We use the Meta Pixel and similar advertising technologies, which may constitute a sharing of personal information for cross-context behavioural advertising or targeted advertising. You have the right to opt out, which you may exercise through the 'Do Not Sell or Share My Personal Information' link on our website or through the cookie preference centre, and we honour opt-out preference signals, including the Global Privacy Control. Subject to the state law applicable to you, you have the right: (a) to know what personal information we have collected; (b) to obtain a copy of it; (c) to request its deletion or correction; (d) to opt out of any sale, sharing, or targeted advertising; and (e) not to be discriminated against for exercising a right. We shall acknowledge a request within 10 (Ten) business days and respond within 45 (Forty-Five) days, which period may be extended once by a further 45 (Forty-Five) days upon notice to you. An authorized agent may submit a request on your behalf, subject to verification. We do not use or disclose sensitive personal information for any purpose that gives rise to a right to limit its use.
13.Children
13.1 Our website, the Platform, and our services are not directed to minors, and we do not knowingly collect personal data from any person under the age of 18 (Eighteen) years.
13.2 Where we knowingly process the personal data of a child, we shall do so only on the basis of verifiable consent given by a parent or lawful guardian, and we shall not undertake tracking, behavioural monitoring, or advertising directed at children.
13.3 If you believe that a person under the age of 18 (Eighteen) years has provided personal data to us, please contact us using the details in Clause 16 (Contact & Data Protection Officer), and we shall delete it promptly.
14.Cookies
We use cookies and similar technologies on our website. Our use of them, the categories of cookies we set, and the means by which you may give, refuse, and withdraw consent, are described in our Cookie Policy at https://poiro.com/cookie-policy.
15.Third-Party Websites
Our website and the Platform may contain links to third-party websites. This Policy does not apply to those websites, and we are not responsible for their content or their privacy practices. You should review the privacy notice of any third-party website that you visit.
16.Contact & Data Protection Officer
We have designated a Data Protection Officer, in accordance with Section 11(3) of the PDPA and with the DPDP framework. Any question, request, or complaint concerning this Policy or our processing of personal data may be addressed to:
Sameer Pendse (Data Protection Officer, Poiro Pte. Ltd.)
Address: 160 Robinson Road, 19-08 SBF Center, Singapore 068914
Email: explore@poiro.com
17.Changes to this Policy
We may amend this Policy from time to time. The amended Policy takes effect when posted on our website, and we shall update the 'Last updated' date accordingly. Where an amendment is material, we shall take reasonable steps to bring it to your attention.
This document is a template provided for informational purposes and does not constitute legal advice. Replace with counsel-reviewed policy before production launch.