Singapore PDPA 2012 & IMDA Governance Compliant
Data Privacy Policy (DPP)
Effective Date: July 23, 2026 | Version 2.0 | Legal & DPO Contact: legal@letschat.asia
🔒 Privacy Summary & PDPA Guarantees
- PDPA Compliance: Let's Chat strictly adheres to the Singapore Personal Data Protection Act 2012 (PDPA).
- No LLM Training on Customer Data: Customer chat contents, knowledge sources, and vector embeddings are never used to train external foundational AI models.
- Audit Trajectory Tracing: System logs execution trajectories (`AgentTrajectoryLog`) for compliance and security auditing.
- Data Subject Rights: To exercise data access or erasure rights, email legal@letschat.asia.
1. Data Processor Roles & Scope
Under the Singapore PDPA, customer organizations act as Data Controllers determining the purposes of processing, while Let's Chat acts as a Data Processor operating the underlying RAG infrastructure.
2. Information Collection & Usage
- Account & Registration: Email addresses, domain records, and authentication tokens.
- Crawled Documentation: Text content ingested from customer sites (`KnowledgeSource`).
- Interaction & Trajectory Logs: User messages, LLM reasoning traces, confidence match scores, and user ratings.
3. AI Data Protection Safeguards
In accordance with IMDA's Model AI Governance Framework for Agentic AI (v1.5):
- Customer data is isolated by multi-tenant domain IDs (`VerifiedDomain`).
- PII masking pre-processors scrub sensitive personal identifiers prior to model inference.
- Data trajectory records are secured with access controls for audit defense.
4. Data Protection Officer (DPO) Contact
For privacy inquiries, data access requests, or regulatory disclosures under the PDPA:
Legal & DPO Contact: legal@letschat.asia | dpo@letschat.asia