Acuity
ACUITY INTELLIGENCE SG PTE. LTD.
Singapore UEN 202633032N
1

1. About this Global Privacy Policy

Acuity is a Singapore-based business that provides a proactive business operating system, Website Intelligence, AI-assisted analysis, recommendations, controlled workflow preparation, customer workspaces and related services. In this Policy, "Acuity", "we", "us" and "our" mean ACUITY INTELLIGENCE SG PTE. LTD., trading as Acuity.

Legal entity: ACUITY INTELLIGENCE SG PTE. LTD.

Singapore UEN: 202633032N

Registered office: 68 Circular Road, #02-01, Singapore 049422

Acuity serves customers and users worldwide. Singapore's Personal Data Protection Act 2012 ("Singapore PDPA") is a foundational home-jurisdiction standard for this Policy. Where another applicable law gives an individual greater or different protection, Acuity will apply that protection to the relevant person and processing activity.

1.2 What this Policy covers

This Policy explains how Acuity collects, uses, stores, discloses and otherwise processes personal data when you visit an Acuity website, request a Website Intelligence report, communicate with us, apply for a programme, create or use an account or workspace, connect a third-party service, subscribe or pay, attend an event, receive marketing, or otherwise interact with Acuity.

This Policy also covers personal data that Acuity processes for its own business operations. It does not replace a customer's own privacy notice, and it does not apply to an independent third-party service merely because that service can connect to Acuity.

1.3 How to use this Policy

Read this Policy together with any just-in-time notice displayed at collection, the Terms of Service, the Data Processing Addendum ("DPA"), the Subprocessor Register, and any customer order form. If those documents conflict on the processing of Customer Content, the DPA and applicable order form control to the extent stated in them, without reducing rights that cannot lawfully be waived.

2

2. Scope, roles and responsibility

2.1 When Acuity determines the purposes of processing

Acuity acts as the organisation, controller or business responsible for personal data when it decides why and how to process data for website operation, Website Intelligence requests, account administration, authentication, security, billing, support, service communications, direct marketing, service improvement, legal compliance and its own corporate operations.

2.2 When Acuity processes data for a customer

Acuity generally acts as a data intermediary, processor, service provider or contractor when it processes Customer Content in a customer workspace on the customer's documented instructions. The customer determines which data is submitted or connected, who may access it, what business purposes apply, and which actions are authorised. Acuity processes that data under the DPA and the customer's configuration and instructions.

2.3 Customer responsibilities

Customers must have a lawful basis and provide any required notice or consent before submitting personal data to Acuity or connecting a source. Customers must configure roles and permissions appropriately, limit data to what is necessary, respond to individuals whose data they control, and avoid using Acuity for prohibited or unlawful purposes. If you submit personal data about another person, you confirm that you are authorised to do so and have provided any required information.

2.4 Third-party services

Third-party websites, social networks, payment processors, identity providers and connected services operate under their own terms and privacy practices. Acuity is not responsible for an independent third party's processing outside Acuity's instructions or control. We encourage you to review the third party's notice before authorising a connection.

3

3. Key Definitions

3.1 Personal data

"Personal data" or "personal information" means information that identifies, relates to, describes, is reasonably capable of being associated with, or can reasonably be linked to an identified or identifiable individual or household, as applicable under relevant law. It does not include data that has been validly anonymised or de-identified so that it cannot reasonably be linked to an individual.

3.2 Sensitive personal data

"Sensitive personal data" includes information given special protection by applicable law, such as government identifiers, account credentials, precise geolocation, financial account details, health information, biometric or genetic data, racial or ethnic origin, religious or philosophical beliefs, trade-union membership, sexual orientation, information about children, and the contents of certain private communications.

3.3 Customer Content

"Customer Content" means data, files, records, prompts, messages, documents and other material that a customer or authorised user submits to, generates in, or connects with an Acuity workspace, excluding Acuity's own service telemetry and account administration data.

3.4 Connected Service

"Connected Service" means a third-party platform, account, application or data source that a user authorises Acuity to access or interact with through an API, OAuth connection, file transfer, webhook or other integration.

3.5 Processing

"Processing" includes collecting, recording, organising, storing, adapting, retrieving, consulting, analysing, using, disclosing, transmitting, combining, restricting, deleting or otherwise handling personal data.

4

4. Personal data we collect

4.1 Account, identity and contact data

We may collect your name, business email address, telephone number, job title, organisation, account identifier, login and authentication records, profile preferences, role, permissions, language, time zone and communications preferences. If an identity provider is used, we receive the identifiers and profile fields that you and the provider authorise.

4.2 Website Intelligence data

When you submit a domain or URL, we collect the submitted value, normalised domain, request time, technical request data, security and rate-limit signals, and the public web content and technical signals retrieved for the report. Reports may contain business contact details or other personal data already published on the submitted website. If you save, share or request delivery of a report, we also process the related account or contact information and access records.

4.3 Customer Content and workspace data

We process Customer Content selected by the customer, which may include business, sales, customer, finance, operations, people, marketing, project, support and communications information. The precise categories depend on customer configuration. Customers should not submit sensitive personal data unless it is necessary, authorised, permitted by the service terms, and protected by appropriate access controls.

4.4 Connected-Service data

Depending on the service and permissions selected, we may receive account identifiers, profile information, page or organisation information, posts, campaign and advertising data, analytics, messages, files, contacts, leads, events, transaction or operational records, metadata, permission scopes, refresh status and access tokens. The connection screen will identify the requested scopes and intended functions. We do not obtain a broader permission merely because a provider makes it available.

4.5 Usage, device, log and security data

We may collect IP address, device and browser type, operating system, referral and landing information, coarse location inferred from IP, pages and features used, timestamps, clicks, session and request identifiers, configuration changes, audit events, error records, performance telemetry, authentication events and suspected abuse or security indicators.

4.6 Billing and transaction data

We use Stripe to process subscriptions, payments, invoices, taxes, refunds, fraud signals and disputes. Depending on the Stripe service used, Stripe may collect a payer's name, email address, billing address, payment-method details, card, bank or wallet information, IP address, device information and transaction data. Full payment credentials are intended to be entered into Stripe-hosted or Stripe-provided fields and transmitted directly to Stripe. Acuity does not intend to receive or store complete card numbers or card-security codes. We may receive limited payment and transaction information from Stripe, such as the payment method type, card brand and last four digits, expiry date, billing contact, amount, currency, payment status, invoice, subscription, tax, refund, fraud-risk, chargeback and dispute references. Stripe's processing is also governed by its Privacy Policy and Privacy Center.

4.7 Communications, applications and support

We collect information you provide in emails, forms, surveys, event registrations, programme applications, interviews and support requests, including attachments, feedback, issue descriptions, troubleshooting information and records of our response. Calls or meetings will be recorded only with the notice or consent required by applicable law.

4.8 Inferences and AI-generated data

Acuity may generate classifications, summaries, relationships, priorities, recommendations, forecasts, risk indicators, confidence information and prepared work from permitted inputs. These outputs may be personal data when they relate to an identifiable person. They are not guaranteed to be complete or correct and must be reviewed in context.

4.9 Data we ask you not to provide

Do not submit passwords, secret authentication values, payment-card security codes, unrestricted government identifiers, highly sensitive health or biometric data, or personal data that is not necessary for an authorised business purpose. Never place credentials or secrets in prompts, support messages or free-text fields.

5

5. Sources of personal data

We collect personal data from the following sources:

  • you, when you use the website, request a report, apply, register, communicate, pay, configure preferences or submit content;
  • a customer, workspace administrator or authorised colleague who creates an account, assigns a role, uploads information or invites you;
  • Connected Services that you or a customer authorise, subject to the selected permissions and provider terms;
  • publicly accessible websites and public business sources submitted or selected for Website Intelligence or other authorised analysis;
  • service providers such as hosting, authentication, security, analytics, communications, support and payment providers;
  • business partners, advisers, event organisers and referral sources where lawful and expected; and
  • our own systems, through usage, security, audit, diagnostic and service-operation records.

Where we receive personal data indirectly and applicable law requires us to notify the individual, we will provide the required information within the applicable period unless a lawful exception applies or the customer responsible for the data must provide the notice.

6

6. Why we process data and our legal grounds

6.1 Service delivery and contract

We process personal data to take steps you request, provide the website and services, generate and deliver reports, create and administer accounts and workspaces, enable authorised connections, provide support, process subscriptions, enforce customer configurations, and perform our agreements. Where relevant law uses the concept of contractual necessity, we rely on it only for processing objectively necessary to provide the requested service.

6.2 Consent

We rely on consent where required, including for optional cookies, certain marketing, sensitive data, particular Connected-Service permissions, recording, or other processing for which consent is the appropriate ground. You may withdraw consent at any time through the relevant control or by contacting us. Withdrawal does not affect processing already carried out lawfully, and some services may no longer be available if the data is necessary for them.

6.3 Legitimate interests and comparable permitted purposes

Where permitted, we process data for legitimate interests such as securing and operating the service, preventing fraud and abuse, supporting users, understanding and improving product performance, communicating with business contacts, administering our organisation, establishing or defending legal claims, and developing relevant services. We assess necessity, proportionality and the effect on individuals, and we provide objection rights where required. We do not rely on legitimate interests where an individual's rights and interests override them.

6.4 Legal obligations, public interest and vital interests

We process data when necessary to comply with law, tax and accounting rules, valid legal process, regulatory obligations, sanctions and export-control requirements, or to protect rights, safety and security. In rare situations, we may process data to protect a person's vital interests or for another ground recognised by applicable law.

6.5 Purposes

The specific purposes include:

  • operating, maintaining and delivering Acuity and its features;
  • validating domains, retrieving permitted public evidence and producing Website Intelligence reports;
  • administering identity, accounts, organisations, workspaces, permissions and approvals;
  • connecting, synchronising, analysing and acting on data within authorised scopes;
  • providing AI-assisted summaries, recommendations, prioritisation and prepared work;
  • processing subscriptions, invoices, taxes, refunds and disputes;
  • answering enquiries, onboarding customers and resolving support issues;
  • sending transactional and service communications;
  • sending marketing where permitted and managing opt-outs;
  • monitoring availability, performance, quality, security, fraud, abuse and compliance;
  • improving and developing the service using appropriately controlled data;
  • meeting legal, regulatory, audit, reporting and recordkeeping obligations; and
  • establishing, exercising or defending legal rights.

6.6 Payment processing with Stripe

We process billing and transaction data to establish and perform a subscription or purchase, issue invoices, calculate or collect applicable taxes, authenticate and complete payments, prevent fraud, manage refunds and disputes, maintain financial records and meet legal obligations. Stripe processes payment data for these purposes under the role that applies to the relevant activity. Stripe may act as Acuity's processor or service provider for some payment functions and as an independent controller for functions such as fraud prevention, regulatory compliance and operation of its payment network. Acuity relies on performance of a contract, legitimate interests, consent or legal obligations as applicable to the activity and jurisdiction.

6.7 New purposes

If we intend to use personal data for a materially different purpose that is not compatible with the original purpose, we will provide additional notice and obtain consent or another valid legal ground where required before the new processing begins.

7

7. Website Intelligence

7.1 What happens when a domain is submitted

Acuity validates and normalises the submitted domain, performs security checks, retrieves permitted publicly accessible content and technical signals, and analyses observed evidence across areas such as positioning, conversion, visibility, performance and trust. A report is generated only from evidence the system actually obtains; we do not represent that a scan is complete before analysis returns.

7.2 Public-source boundaries

Website Intelligence is designed for lawful analysis of publicly accessible business websites and associated public signals. It is not designed to bypass authentication, access controls or technical restrictions, obtain private account data, or infer confidential internal business facts from public material. A person submitting a domain must have a legitimate purpose and must not use the service to harass, profile or harm individuals.

7.3 Personal data in public material

Public pages may contain names, roles, business contact details, testimonials, social links or other personal data. We process such data only to the extent relevant to the requested business analysis, security and report quality. Public availability does not remove privacy obligations. We will consider correction, objection and deletion requests in light of applicable law, the source and the report context.

7.4 Report privacy, sharing and retention

Reports are private by default and should not be publicly indexed. Sharing must be initiated by an authorised user through the approved sharing method and may be revoked where the feature permits. Sensitive access tokens, credentials, private findings and full submitted URLs must not be sent to analytics providers. Retention periods are stated in Appendix A.

8

8. Customer workspaces and business data

8.1 Processing on customer instructions

For Customer Content, Acuity processes data to provide the configured service, maintain security, troubleshoot, prevent misuse, comply with law and perform the customer agreement. We do not determine an independent commercial purpose for Customer Content except as expressly described in the DPA or with the customer's valid instruction.

8.2 Workspace administration and access

Workspace administrators may invite or remove users, assign roles, manage connections, view activity, configure retention and export or delete content according to the customer's agreement. Users should direct requests concerning customer-controlled workspace data to the relevant customer. We will assist the customer as required by the DPA and applicable law.

8.3 Data minimisation and sensitive data

Customers should connect the smallest useful data set and grant the least privilege needed for the intended outcome. Sensitive personal data should be used only where necessary, authorised and supported by the service configuration and contract. Acuity may restrict or remove data that violates the Acceptable Use Policy or creates an unmanaged security or legal risk.

8.4 Service improvement and model training

Acuity may use service telemetry, feedback and data that has been aggregated or de-identified so it no longer identifies an individual or customer to understand reliability and improve the service. Acuity will not use Customer Content to train a shared or general-purpose AI model unless the customer has expressly agreed through a written term or an explicit product control. Where a customer enables such use, the purpose, provider, data categories, retention and withdrawal effect must be clearly disclosed.

9

9. Connected Services and API Data

9.1 Authorisation and scope

A Connected Service is activated only after an authorised user selects the service and completes the provider's authorisation flow or another approved connection method. Before connection, Acuity will identify the requested permissions, the data to be imported or exported, the purpose, relevant actions, and whether the connection can write or publish data. We request least-privilege scopes appropriate to the selected feature.

9.2 How connected data is used

Acuity uses connected data to provide the features selected by the customer, such as synchronising records, combining business context, identifying changes, generating recommendations, preparing work, or carrying out an action after the required permission and approval. Connected data is not used for unrelated advertising or sold for monetary consideration.

9.3 Tokens and credentials

Access and refresh tokens are confidential authentication data. We use them only to maintain the authorised connection, restrict access to authorised systems and personnel, and protect them with safeguards appropriate to their sensitivity. Users must never paste passwords or secret keys into ordinary prompts or support messages.

9.4 Human authority and outbound actions

Connecting data does not automatically authorise Acuity to take consequential external action. A write, publish, message, transaction or other material action must stay within the provider scope, customer configuration, user permissions and applicable approval workflow. Acuity is designed to prepare and recommend work while keeping the appropriate person in control.

9.5 Disconnect and deletion

When an authorised user disconnects a service, Acuity will stop new synchronisation and webhooks as soon as reasonably practicable, revoke or delete stored tokens where technically available, and delete or de-identify connected data according to the customer's instruction, contractual obligations and Appendix A. Disconnecting a service may not automatically delete data previously copied into customer records, legally required records or time-limited backups. The user may submit a deletion request for remaining eligible data.

9.6 Provider terms

The provider's terms, developer requirements, data-use rules and privacy policy also govern the provider's own processing and Acuity's use of its service. Acuity uses each approved provider in accordance with the applicable agreement, data-protection terms, platform and API policies, documented purpose, permitted data types, approved scopes and configured controls. Acuity maintains a vendor and subprocessor register, role and data-flow records, a permission matrix, accountable owners and review evidence appropriate to the provider's risk. Acuity's availability on, connection to, or use of a provider API does not imply endorsement, certification or approval unless Acuity expressly states a current, verifiable approval.

9.7 Review, changes and suspension

Provider services, permissions and policies may change. Before deployment and periodically thereafter, Acuity reviews material providers and connections for purpose, necessity, data access, security, retention, international transfers, downstream recipients and current platform requirements. Acuity will update, restrict, suspend or disconnect an integration if a material change cannot be addressed consistently with applicable law, Acuity's contract, this Policy and the provider's binding requirements. Customers will receive material notice where required.

10

10. Artificial Intelligence and Automated Processing

10.1 How Acuity uses AI

Acuity uses AI and other analytical methods to organise evidence, extract and classify information, identify relationships, generate summaries, prioritise signals, recommend actions, prepare drafts and support controlled workflows. Inputs may include Customer Content, connected data, public evidence, prompts, instructions and service context. Outputs may include inferences about people where the source data relates to them.

10.2 AI providers

Acuity may use approved model and infrastructure providers as subprocessors. Provider access, retention and training settings must follow Acuity's contract, DPA, security controls and Subprocessor Register. We minimise data sent to a provider, use enterprise or API configurations appropriate to the feature, and do not authorise a provider to use Customer Content to train a general-purpose model unless the customer has expressly agreed.

10.3 Human review and limitations

AI outputs can be incomplete, inaccurate or affected by the quality and context of input data. Users must review material outputs, assumptions and source evidence before relying on them. Acuity provides permissions, approval states, corrections and audit information appropriate to the feature. Nothing consequential should move without the approval required by the customer's policy and configuration.

10.4 Significant decisions

Acuity does not make decisions on its own behalf that produce legal or similarly significant effects about individuals solely by automated means. If a feature is used in a context that could significantly affect an individual, Acuity and the customer must conduct the required assessment, provide the required notice, identify meaningful information about the use and expected effects, and provide human review, challenge or opt-out rights where applicable. Customers remain responsible for the lawfulness of their decision process and should not use Acuity as the sole basis for employment, credit, insurance, housing, healthcare, education or other high-impact decisions unless expressly authorised by contract and law.

11

11. Cookies and similar technologies

11.1 Technologies covered

Cookies and similar technologies include browser cookies, local storage, software development kits, pixels, tags and comparable identifiers stored on or read from a device. They may support security, sessions, preferences, functionality, measurement and marketing. Appendix B states Acuity's global categories and default limits. The live Cookie Preferences panel must identify the specific technologies and providers actually deployed.

11.2 Strictly necessary technologies

Strictly necessary technologies may operate without optional consent where permitted because they are required to deliver a service requested by the user, maintain security, authenticate, balance traffic, remember a privacy choice or provide core functionality. Blocking them may prevent parts of the service from working.

11.3 Optional technologies and consent

Where consent is required, Acuity will not set or access functional, analytics, advertising or other non-essential technologies before the user makes an informed choice. Accept and Reject choices must be comparably available. Consent must be freely given, specific, informed and indicated by a clear affirmative action. Continuing to browse is not treated as consent where affirmative consent is required.

11.4 Changing preferences

You may change or withdraw optional choices at any time through the persistent Cookie Preferences control. Withdrawal applies prospectively. You may also use browser controls, but blocking all cookies may affect essential functions.

11.5 Opt-out preference signals

Where required by applicable law, Acuity will recognise and process a valid browser-based universal opt-out preference signal, such as Global Privacy Control, for the browser or profile sending the signal. A legally valid signal will be treated as an opt-out of sale, sharing or targeted advertising as applicable, without requiring identity verification that is not legally necessary.

12

12. How we disclose personal data

12.1 Service providers and subprocessors

We disclose personal data to approved vendors that provide hosting, cloud infrastructure, databases, AI models, authentication, security, monitoring, analytics, communications, customer support, payment processing, document processing and professional services. Before use and periodically thereafter, Acuity assesses material providers according to risk, including their role, data access, security, retention, transfers and relevant provider requirements. Providers acting for Acuity may process data only for agreed purposes and under contractual, confidentiality, security and data-protection obligations appropriate to their role. Material subprocessors and processing locations are listed in the Subprocessor Register.

12.2 Customers, users and authorised recipients

We disclose data within a customer workspace according to the customer's roles, permissions and sharing choices. We may disclose a report or prepared output to a recipient selected by an authorised user. Customers and users are responsible for choosing appropriate recipients and not exposing confidential or personal data through public links.

12.3 Stripe and payment partners

Acuity discloses payment and transaction data to Stripe to process payments and subscriptions, issue invoices, calculate or support taxes, prevent fraud, manage refunds and disputes, and maintain payment records. Stripe may disclose relevant data to acquiring and issuing banks, card networks, payment-method and wallet providers, identity, fraud and security services, tax or regulatory services, and other parties described in Stripe's privacy materials. Stripe independently determines some processing needed to operate its payment services, prevent fraud and comply with financial regulation. Stripe's Privacy Policy therefore applies in addition to this Policy. Acuity uses Stripe under its services agreement and data-protection terms and remains responsible for its own merchant, integration, notice, security, tax and recordkeeping obligations.

12.4 Connected Services

We send data to a Connected Service when an authorised user configures an export, action, synchronisation or publication. The connection screen and feature context identify the type of data and action. The third party independently processes data it receives under its own terms, except where it acts solely as Acuity's processor.

12.5 Professional advisers and corporate events

We may disclose data to lawyers, accountants, auditors, insurers, banks, investors and advisers under duties of confidence. In a merger, financing, acquisition, reorganisation, insolvency or sale of assets, data may be disclosed under appropriate safeguards and used consistently with this Policy or with additional notice where required.

12.6 Legal, safety and security disclosures

We may disclose data if we reasonably believe disclosure is necessary to comply with applicable law or valid legal process; respond to lawful requests; protect the rights, property, safety or security of Acuity, customers, users or others; investigate fraud, abuse or security incidents; enforce agreements; or establish, exercise or defend legal claims. We assess requests and disclose only what is legally required or proportionate where we are permitted to do so.

12.7 Sale, sharing and targeted advertising

Acuity does not sell personal data for monetary consideration. If Acuity uses an advertising or analytics technology that applicable US law defines as a "sale", "sharing" or disclosure for targeted advertising, Acuity will provide the legally required notice and opt-out method, honour applicable opt-out preference signals, and contractually restrict the recipient. Acuity does not knowingly sell or share the personal data of children.

13

13. International data transfers

13.1 Why transfers occur

Acuity is based in Singapore and serves users worldwide. Personal data may be processed in Singapore and in other countries where Acuity, Stripe and other subprocessors, Connected Services or authorised customers operate. Those countries may have privacy laws different from the place where the data originated. Current material processing locations must be identified in the Subprocessor Register.

13.2 Singapore transfer protection

For transfers subject to the Singapore PDPA, Acuity will use legally recognised measures intended to ensure that overseas recipients provide a standard of protection comparable to the protection under the Singapore PDPA, unless a lawful exception applies. Measures may include enforceable contractual obligations, assessments, policies and technical controls.

13.3 EEA, United Kingdom and Switzerland

Where personal data protected by European, United Kingdom or Swiss law is transferred to a country not recognised as adequate, Acuity will use an approved transfer mechanism as applicable, such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, or another valid safeguard. We will conduct any required transfer assessment and apply supplementary measures appropriate to risk.

13.4 Other cross-border requirements

For Australia, New Zealand, Canada, Brazil, Japan and other jurisdictions with cross-border requirements, Acuity will take the steps required by applicable law, which may include contractual protection, comparable-protection assessment, data-residency configuration, notice or consent. We do not rely on consent as a routine substitute for safeguards where the law requires more.

13.5 Obtaining information

You may contact the Privacy Office to request information about the transfer mechanism relevant to your data. We may provide a redacted copy where needed to protect confidential or security-sensitive information. Stripe uses the transfer safeguards described in its privacy materials for payment data it processes internationally; Acuity assesses the relevant Stripe terms and transfer mechanism as part of its provider review.

14

14. Security and personal data breaches

14.1 Safeguards

Acuity maintains administrative, technical and organisational safeguards designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, and other misuse. Measures are selected according to data sensitivity and risk and may include access controls, least privilege, authentication, encryption where appropriate, tenant separation, logging, monitoring, secure development, vulnerability management, vendor review, backups, incident response and staff confidentiality obligations.

14.2 Shared responsibility

Security also depends on customers and users. You must protect credentials, use appropriate authentication, review permissions, keep devices secure, promptly remove access that is no longer needed, and notify Acuity of suspected compromise. Customers are responsible for configuring their workspace and Connected Services according to their risk and legal obligations.

14.3 No absolute guarantee

No service or transmission method is completely secure. Acuity does not claim that incidents are impossible or that it holds a certification unless the Security & Trust page expressly identifies a current certification.

14.4 Breach response and notification

Acuity maintains a process to identify, contain, investigate and remediate suspected personal data breaches. We assess notification obligations and notify customers, affected individuals and regulators as required by applicable law and contract. For customer-controlled data, Acuity will notify the responsible customer without undue delay after confirming a breach affecting that data, consistent with the DPA. Notifications will describe known facts, likely consequences and measures taken where legally required and safe to disclose.

14.5 Payment security and PCI DSS

Acuity designs payment collection to use Stripe Checkout or Stripe-hosted or embedded payment fields so that full payment-card data is transmitted directly to Stripe rather than through Acuity's application servers. Acuity does not store card-security codes. Stripe's PCI DSS Service Provider Level 1 status does not by itself certify Acuity or remove Acuity's merchant responsibilities. Acuity must maintain the PCI DSS scope and annual validation applicable to its integration, use supported Stripe components, protect restricted API keys and webhook signing secrets, verify webhook signatures, limit access, monitor payment events, and remediate integration or security issues.

15

15. Retention, account closure and deletion

15.1 Retention principle

Acuity keeps personal data only for as long as reasonably necessary for the purpose collected, to provide the service, comply with legal and contractual obligations, resolve disputes, enforce agreements, maintain security and auditability, and establish or defend claims. Appendix A provides the proposed maximum standard periods for legal and operational confirmation. A customer order, DPA, mandatory law or documented legal hold may require a different period.

15.2 How periods are selected

We consider the amount, nature and sensitivity of the data; the risk of harm; the purpose and whether it can be achieved another way; customer instructions; expected account lifecycle; security and audit needs; limitation periods; and tax, accounting and regulatory requirements.

15.3 Account closure

When an account or workspace closes, Acuity will provide any contractually required export period, restrict routine access, and delete or de-identify eligible data after the applicable waiting period. Customers should export required data before closure. Closure does not erase records that Acuity must retain for billing, security, fraud prevention, dispute, legal hold or other lawful purposes.

15.4 Deletion process

Deletion removes data from active production systems or renders it no longer reasonably linked to an individual, subject to technical and legal limitations. Acuity propagates deletion to processors where required and technically available. Encrypted backups are isolated from ordinary use and expire on a rolling schedule; data may remain in a backup until that backup expires, unless restoration is necessary for disaster recovery, in which case applicable deletions will be re-applied.

15.5 Legal holds and exceptions

We may suspend deletion for data reasonably necessary to comply with law, preserve evidence, investigate abuse, protect security, exercise or defend claims, complete a transaction requested by the individual, or meet another lawful exception. Access remains restricted to the purpose justifying retention.

16

16. Your global privacy rights

16.1 Rights available

Depending on the law that applies, you may have the right to:

  • receive clear information about collection, use, disclosure, retention and transfer;
  • confirm whether Acuity processes your personal data and obtain access and a copy;
  • correct inaccurate or incomplete personal data;
  • request deletion, anonymisation or de-identification where applicable;
  • restrict processing or object to processing based on particular grounds;
  • receive data you provided in a structured, commonly used and machine-readable format and transmit it to another provider where applicable;
  • withdraw consent at any time;
  • opt out of direct marketing;
  • opt out of sale, sharing or targeted advertising where those concepts apply;
  • limit certain uses and disclosures of sensitive personal data;
  • obtain information about and request human review of qualifying automated decisions;
  • appeal a refusal where applicable; and
  • complain to Acuity, a privacy regulator or a court or tribunal.

16.2 How to submit a request

Submit a request through the privacy request form or contact the Privacy Office using clause 21. Describe the right you wish to exercise and the Acuity service or customer relationship involved. If the data is controlled by an Acuity customer, we may refer the request to that customer and support its response. We provide accessible alternatives where reasonably necessary.

Privacy and rights requests: support@acuityintelligence.io

16.3 Verification and authorised agents

We verify identity and authority proportionately to the sensitivity of the request. We may ask for information already associated with the account or a signed authorisation for an agent. We will not ask for more personal data than reasonably necessary, and we will not require identity verification for an opt-out when applicable law prohibits it.

16.4 Response and appeal

We respond within the period required by applicable law and will explain any permitted extension. Requests are normally free. We may charge a reasonable fee or refuse a manifestly unfounded, excessive or repetitive request only where law permits and after explaining the reason. If we deny a request in whole or part, we will provide the reason and available appeal or complaint route.

16.5 Non-discrimination

Acuity will not unlawfully discriminate against or retaliate against an individual for exercising a privacy right. A service difference is permitted only where it is reasonably related to the data or otherwise allowed by law.

17

17. Communications and marketing choices

17.1 Service communications

Acuity sends communications needed to provide and secure the service, such as verification, report availability, account, billing, integration, security, policy and support notices. These messages are not marketing merely because they relate to Acuity. You may not be able to opt out of essential service communications while using the relevant service.

17.2 Marketing

Where permitted, Acuity may send product news, research, invitations or offers based on consent, an existing business relationship or another lawful basis. Marketing consent is separate from report delivery, account operation and other transactional messages. Every electronic marketing message will identify the sender and provide the opt-out mechanism required by applicable law.

17.3 Opting out

You may unsubscribe using the link in the message or contact us. We may retain minimal suppression information so that we can respect the choice. Opting out of marketing does not stop essential service or legal communications.

18

18. Worldwide standards and additional local rights

18.1 One global baseline

Acuity applies the core protections in this Policy globally: accountability, transparency, purpose limitation, data minimisation, appropriate legal grounds, security, retention limits, controlled transfers, individual rights and complaint handling. This clause summarises additional regional treatment. It does not reduce a right or obligation under mandatory law.

18.2 Singapore

For processing subject to the Singapore PDPA, Acuity will designate at least one Data Protection Officer and make the DPO's business contact information public; notify purposes; obtain, manage and permit withdrawal of consent where required; use data for reasonable notified purposes; maintain accuracy, protection, retention and transfer controls; provide applicable access and correction; and assess and notify notifiable breaches. Any data portability obligation will apply when and to the extent brought into force.

18.3 European Economic Area, United Kingdom and Switzerland

Where European, UK or Swiss data-protection law applies, Acuity will identify the controller and any required representative; state the legal bases; provide required information when data is collected directly or indirectly; support access, correction, erasure, restriction, portability, objection and consent withdrawal; provide protections for special-category data; conduct required impact and transfer assessments; and support the right not to be subject to qualifying solely automated significant decisions. Individuals may complain to the supervisory authority where they live or work or where an alleged infringement occurred.

Acuity will appoint and publish contact details for an EEA representative, a UK representative, or both before beginning relevant processing if counsel determines that an appointment is required. Until then, the Acuity Privacy Office remains the public contact point for questions and requests.

18.4 California and other United States jurisdictions

Where a US state privacy law applies, the categories of personal data collected, sources, purposes and recipients are described in clauses 4, 5, 6 and 12. Acuity provides applicable rights to know, access, correct, delete and obtain a portable copy; to opt out of sale, sharing or targeted advertising; to limit or consent to certain sensitive-data processing; to appeal; to use an authorised agent; and to receive equal treatment. Acuity honours legally recognised opt-out preference signals where required. We do not sell personal data for monetary consideration. If production advertising practices are legally treated as sale, sharing or targeted advertising, Acuity will display the required opt-out control and update this Policy.

18.5 Australia and New Zealand

Where Australian or New Zealand privacy law applies, Acuity will maintain an accessible and current policy; collect and use information for lawful and notified purposes; support applicable access and correction; protect information; assess notifiable breaches; and apply applicable cross-border accountability and comparable-protection requirements. From the date relevant Australian automated-decision transparency provisions apply, Acuity will include the required information if Acuity arranges for a computer program to use personal information to make a decision reasonably expected to significantly affect a person's rights or interests.

18.6 Canada

Where Canadian federal or provincial private-sector law applies, Acuity follows accountability, identified purposes, meaningful consent, limited collection, limited use/disclosure/retention, accuracy, safeguards, openness, individual access and challenge principles, and any applicable breach, cross-border or Quebec-specific requirements.

18.7 Brazil

Where Brazil's General Data Protection Law applies, Acuity will identify an applicable legal basis; support confirmation, access, correction, anonymisation, blocking, deletion, portability, information about recipients and consent consequences, consent withdrawal and review of qualifying automated decisions; maintain security and incident processes; and identify the responsible contact or officer where required.

18.8 Asia-Pacific, Africa, Middle East and other jurisdictions

For Japan, South Korea, India, South Africa and other jurisdictions, Acuity will apply the notices, legal grounds or consent, sensitive-data protections, individual rights, localisation or transfer measures, security, breach notification, officer or representative requirements and regulator engagement required by the law applicable to the processing. Acuity may provide a supplemental notice where mandatory local information cannot be communicated clearly within this global Policy. A supplemental notice forms part of this Policy and does not reduce the global baseline.

18.9 Conflicts

If mandatory local law conflicts with this Policy, Acuity will follow the law for the affected processing and preserve the higher level of protection where the two can operate together.

19

19. Children and age restrictions

Acuity is a business service and is not directed to children. You must be at least 18 years old, or the age of legal majority in your place of residence if higher, to create an account or authorise a Connected Service. Acuity does not knowingly sell or share children's personal data or use it for targeted advertising.

Customer Content may concern children if a customer has a lawful, authorised business reason to process it. The customer is responsible for required notices, consent, age assurance and safeguards, and must not use Acuity in a child-directed context unless expressly agreed and legally assessed. If we learn that we collected a child's personal data through our own website or account flow contrary to this clause, we will take reasonable steps to delete it. A parent, guardian or other authorised person may contact the Privacy Office.

20

20. Changes to this policy

We may update this Policy to reflect changes in law, technology, services, data practices or organisational structure. We will post the updated version at the canonical URL and state the effective date and version. We will keep prior versions available or provide them on request where required.

If a change materially affects how we use personal data or an individual's rights, we will provide additional notice through the website, service or direct communication as appropriate before the change takes effect. We will obtain fresh consent where the law requires it. Continued use is not treated as consent where affirmative consent is legally required.

21

21. Contact, Data Protection Officer and complaints

21.1 Acuity Privacy Office

Questions, privacy requests and complaints may be directed to:

Organisation:ACUITY INTELLIGENCE SG PTE. LTD.
Singapore UEN:202633032N
Attention:Data Protection Officer / Acuity Privacy Office
Registered Address:68 Circular Road, #02-01, Singapore 049422

Submit Privacy Inquiry

Describe the right you wish to exercise and the Acuity service or customer relationship involved. Do not send passwords or secret keys.

21.2 Complaints

We will acknowledge and investigate a privacy complaint, involve the Data Protection Officer or responsible privacy lead, and respond within the period required by applicable law. Please provide enough information to identify the issue, but do not send passwords, secret keys or unnecessary sensitive data.

21.3 Regulators

You may contact the Personal Data Protection Commission of Singapore at https://www.pdpc.gov.sg. If another privacy law applies, you may also complain to the competent authority in your country or region, including an EEA data protection authority, the UK Information Commissioner, the California Privacy Protection Agency or Attorney General, the Office of the Australian Information Commissioner, the Office of the Privacy Commissioner of Canada, the New Zealand Privacy Commissioner, Brazil's National Data Protection Authority, or another competent regulator. We encourage you to contact us first so we can try to resolve the concern, but you are not required to do so where the law provides a direct complaint right.

Appendix A - Proposed Retention Schedule

The following periods are proposed policy commitments for legal and operational confirmation. They are maximum standard periods unless a shorter customer setting, contract or law applies. Data may be retained longer only for a documented legal obligation, legal hold, security investigation, fraud prevention, dispute or claim.

Record categoryProposed periodReason
Website Intelligence request and reportUp to 90 days after generation if not saved to an account; saved reports follow the account/workspace periodDeliver report, prevent abuse, allow return and correction
Account and profileAccount term plus up to 90 daysAccount administration, reactivation window and deletion processing
Customer ContentCustomer term plus up to 30 days, unless the customer deletes earlier or the contract states otherwiseService delivery and controlled offboarding
Connected-Service tokensConnection term; revoke/delete as soon as reasonably practicable after disconnect, normally within 24 hoursMaintain authorised connection; stop future access promptly
Imported connected dataCustomer Content period, subject to customer instruction and provider requirementsConfigured service features
Security, access and audit logsUp to 13 months; longer for an active incident or legal requirementSecurity, abuse prevention, audit and investigation
Support recordsThree years after closureService history, quality, disputes and training of support staff
Billing, tax and transaction recordsSeven years after the relevant financial year or longer if law requiresAccounting, tax, audit, fraud and disputes
Consent and privacy-rights recordsSix years after closure of the record or longer if needed to demonstrate complianceEvidence of choice, response and compliance
Marketing contact and engagementUntil opt-out or two years after last meaningful engagement; suppression record retained as needed to honour opt-outRelevant communications and opt-out compliance
BackupsRolling expiry within 90 daysDisaster recovery; isolated from ordinary use

Appendix B - Cookie and Similar-Technology Schedule

The production Cookie Preferences panel must list each active cookie, SDK, pixel, tag or local-storage key by name, provider, purpose and duration. The categories and limits below form part of this Policy and must be reconciled against a production scan before launch.

CategoryPurposeControlMaximum default
Strictly necessarySecurity, fraud prevention, load balancing, session continuity, authentication and privacy choicesNot used for cross-site advertisingSession to 12 months, according to function
FunctionalRemember optional settings and provide user-requested enhanced functionalityConsent where requiredUp to 12 months
AnalyticsMeasure traffic, performance and feature use to improve the serviceConsent before activation where required; aggregate or minimise dataUp to 13 months
Advertising / socialMeasure campaigns or provide relevant advertising through third-party platformsOff by default until applicable consent; opt-out and preference signals honoured where requiredUp to 13 months or shorter provider setting

Appendix C - Official Legal-Review References

These sources informed the draft and are included for counsel and operational reviewers. They are not a substitute for legal advice, applicability analysis or review of the current statutory text.

  • Accounting and Corporate Regulatory Authority of Singapore, Business Profile for ACUITY INTELLIGENCE SG PTE. LTD., UEN 202633032N, dated 21 July 2026
  • Singapore Personal Data Protection Commission, Data Protection Obligations: https://www.pdpc.gov.sg/overview-of-pdpa/the-legislation/personal-data-protection-act/data-protection-obligations
  • Singapore Personal Data Protection Commission, Register Your Data Protection Officer: https://www.pdpc.gov.sg/overview-of-pdpa/data-protection/business-owner/data-protection-officers
  • European Commission, Information for Individuals: https://commission.europa.eu/law/law-topic/data-protection/information-individuals_en
  • European Commission, Information that must be given when personal data is collected: https://commission.europa.eu/law/law-topic/data-protection/rules-business-and-organisations/principles-gdpr/what-information-must-be-given-individuals-whose-data-collected_en
  • European Data Protection Board, Standard Contractual Clauses: https://www.edpb.europa.eu/topics/international-transfers-and-international-cooperation/standard-contractual-clauses_en
  • UK Information Commissioner's Office, Cookies and Similar Technologies: https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/guide-to-pecr/cookies-and-similar-technologies/
  • California Privacy Protection Agency, Rights under the CCPA: https://privacy.ca.gov/california-privacy-rights/rights-under-the-california-consumer-privacy-act/
  • California Privacy Protection Agency, CCPA regulations and 2025 ADMT updates: https://cppa.ca.gov/regulations/
  • Office of the Australian Information Commissioner, APP 1: https://www.oaic.gov.au/privacy/australian-privacy-principles/australian-privacy-principles-guidelines/chapter-1-app-1-open-and-transparent-management-of-personal-information
  • Office of the Australian Information Commissioner, APP 8: https://www.oaic.gov.au/privacy/australian-privacy-principles/australian-privacy-principles-guidelines/chapter-8-app-8-cross-border-disclosure-of-personal-information
  • Office of the Privacy Commissioner of Canada, PIPEDA Fair Information Principles: https://www.priv.gc.ca/en/privacy-topics/privacy-laws-in-canada/the-personal-information-protection-and-electronic-documents-act-pipeda/p_principle/
  • Office of the Privacy Commissioner of New Zealand, Principle 12: https://www.privacy.org.nz/privacy-principles/12/
  • Stripe Singapore Privacy Center: https://stripe.com/en-sg/legal/privacy-center
  • Stripe Privacy Policy: https://stripe.com/privacy
  • Stripe, Integration Security and PCI DSS Guide: https://docs.stripe.com/security/guide
  • Stripe Checkout documentation: https://docs.stripe.com/payments/checkout
  • Stripe Data Processing Agreement FAQs: https://stripe.com/legal/dpa/faqs