Privacy Policy

Last Updated: January 2025

Our Commitment to Privacy

metamminds is committed to protecting your privacy and transparently processing your personal data. This Privacy Policy informs you about the nature, scope, and purposes of data processing on our website and within our services.

As a Singapore-based company, we strictly adhere to the provisions of Singapore's Personal Data Protection Act (PDPA) and the General Data Protection Regulation (GDPR) of the European Union. Your data is processed and stored exclusively in secure Singaporean data centers.

Data Controller

Contact Details:

metamminds

10 Collyer Quay, #15-01

Ocean Financial Centre, Singapore 049315

Phone: +65 6789 1234

Email: [email protected]

Data Protection Officer:

Sarah Tan

Head of Security & Compliance

Email: [email protected]

For any questions about data protection, you can contact our Data Protection Officer directly.

Data Collection and Processing

Contact Data

For contact and service inquiries

Data Collected:

  • • First and last name
  • • Email address
  • • Phone number (optional)
  • • Company/Organization (optional)
  • • Message content

Purpose and Legal Basis:

Purpose: Processing your inquiries, providing our services, customer support

Legal Basis: Consent (Art. 6(1)(a) GDPR) and legitimate interest (Art. 6(1)(f) GDPR)

Technical Data

Automatically collected during website visits

Log Files:

  • • IP address (anonymized)
  • • Browser type and version
  • • Operating system
  • • Referrer URL
  • • Time of access
  • • Amount of data transferred

Purpose of Processing:

  • • Ensuring IT security
  • • System stability and optimization
  • • Detecting and preventing attacks
  • • Statistical analysis
  • • Legal compliance

Analytics Data

With your consent via cookies

Google Analytics 4:

We use Google Analytics to analyze website usage. Data processing is pseudonymized and uses shortened IP addresses.

Data Collected:
  • • Page views and session duration
  • • Demographic characteristics
  • • Interest categories
  • • Device information
Data Protection:
  • • IP anonymization activated
  • • Privacy-by-default settings
  • • Data processing in compliant regions
  • • 24-month retention period

Legal Basis for Processing

Consent

Art. 6(1)(a) GDPR / PDPA

For marketing communications, non-essential cookies, newsletters, and voluntary data submissions.

Performance of a Contract

Art. 6(1)(b) GDPR / PDPA

For providing our AI services, project management, and customer support.

Legitimate Interest

Art. 6(1)(f) GDPR / PDPA

For IT security, spam protection, business optimization, and legitimate communication.

Legal Obligation

Art. 6(1)(c) GDPR / PDPA

For tax retention, legal reporting duties, and compliance requirements.

Data Retention and Security

Retention Periods

Contact Form Data 3 Years
Project-Related Data 5 Years
Invoicing Data 5 Years (Statutory)
Website Logs 6 Months
Cookie Data Until withdrawal

Data Security Measures

Technical Security:

  • • TLS 1.3 encryption for all data transmissions
  • • AES-256 encryption for data at rest
  • • Regular security updates and patches
  • • Firewall and intrusion detection systems
  • • Backup systems with disaster recovery

Organizational Security:

  • • ISO 27001 certified ISMS
  • • Employee training on data protection
  • • Access control on a need-to-know basis
  • • Regular Data Protection Impact Assessments
  • • Incident response procedures

Data Center: All data is exclusively stored and processed in ISO 27001 certified data centers in Singapore.

Your Rights

Right to Access

You have the right to know what personal data we have stored about you and how it is processed.

Right to Rectification

You can request the correction of inaccurate or the completion of incomplete personal data.

Right to Erasure

You can request the deletion of your personal data, provided there are no legal retention obligations.

Right to Data Portability

You can receive and transfer your data in a structured, common, and machine-readable format.

Right to Object

You can object to the processing of your data based on legitimate interest or withdraw your consent.

Right to Restriction

You can request the restriction of the processing of your data if certain conditions are met.

Exercising Your Rights

To exercise your rights or for any questions about data protection, please contact us at:

Data Protection Inquiries:

Email: [email protected]
Phone: +65 6789 1234
Mail: metamminds, 10 Collyer Quay, #15-01, Singapore 049315

We will process your request within 30 days and provide you with the requested information free of charge.

Third-Party Providers and International Transfers

Services We Use

Website and Analytics:

Google Analytics 4

Google LLC, USA - Appropriate Safeguards & Standard Contractual Clauses

Google Fonts

Locally embedded - no data transfer to Google

Hosting and Infrastructure:

Singapore Cloud Provider

Singapore data center - no international transfer

Cloudflare CDN

Cloudflare Inc., USA - Data Privacy Framework

Data Protection Guarantees

Adequacy Decisions

Data transfer only to countries with recognized adequacy levels

Standard Contractual Clauses

EU Standard Contractual Clauses for all third-country transfers

Additional Safeguards

Encryption, pseudonymization, and regular compliance checks

Changes to This Policy

We reserve the right to adapt this privacy policy to reflect changes in legal situations or our services.

The current version is always available at www.metamminds.com/privacy. For significant changes, we will inform you via email or on our website.

Right to Lodge a Complaint

You have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data.

Competent Authority (Singapore):

Personal Data Protection Commission (PDPC)

10 Pasir Panjang Road, #03-01, Singapore 117438

www.pdpc.gov.sg