Privacy Policy
Your privacy and data security are fundamental to how we operate at Compliz.
In Short
- We collect only what we need to answer your enquiry, deliver our services and meet the law.
- We do not sell your personal data.
- We share it only with the people and providers listed below, and only as far as needed.
- Some of our providers process data outside Singapore and Malaysia, and we take steps to keep it protected there.
- You can ask to see, correct or delete your data, or withdraw your consent, by using the form at the end of this page.
- Please do not send passports, identity numbers or bank details through the website form. We will tell you how to send them securely if we need them.
Who We Are and Where This Policy Applies
This policy applies to personal data that Compliz Pte. Ltd. (UEN 202303106H, “Compliz”, “we” or “us”) collects through this website, by email, on WhatsApp and while providing our services.
It covers individuals in Singapore and Malaysia, including owners, directors, shareholders and staff of overseas-owned companies that are setting up or operating a business in either country.
It is written to meet Singapore’s Personal Data Protection Act 2012 (PDPA) and Malaysia’s Personal Data Protection Act 2010, as amended (Malaysia PDPA).
It also reflects widely accepted data protection principles: collect only what is needed, use it only for stated purposes, keep it accurate and secure, keep it no longer than necessary, and be open about what we do.
If the data protection law of another country applies to us in relation to you, we will handle your data in line with that law to the extent it applies.
Our Role
When we act for ourselves. We are responsible for the personal data we collect about people who enquire about our services, our clients’ contacts, and our own suppliers and staff.
This covers handling enquiries, onboarding, billing and our own legal and regulatory obligations.
When we act for our clients. When we process personal data on a client’s behalf, for example employee details for payroll or data protection support, we act as the client’s data intermediary (in Malaysia, data processor).
We process that data only for the purpose and on the instructions of the client, keep it secure, and do not keep it longer than needed.
The client remains responsible for its own compliance, including telling its people how their data is used.
Data about other people. If you give us personal data about someone else, such as a co-director, shareholder, beneficial owner or employee, you confirm that you have the authority or consent to do so.
You also confirm that they have been told how it will be used. Please keep the data you give us accurate and up to date.
Information We Collect
Enquiry Details
When you use the quote form, we collect your name, email address, mobile number, company name, country, industry, the solutions you are interested in, and your message.
When you press the button on the quote form, we email your request to ourselves and open a WhatsApp chat with your details written in a first message. You choose whether to send it.
If you contact us by email or WhatsApp, we also collect your address or phone number and the content of your messages and any attachments.
If you use the data protection form at the end of this page, we collect your name, email address, the topic you choose and your message.
Identity and Due Diligence Information
Once you engage us, or where the law requires it before we can act, we may collect details such as:
- your full name and former names, nationality and date of birth
- your passport or national identity number and a copy of the document
- residential and business addresses, occupation and tax residency
- your role and shareholding in a company
- information about the source of funds or wealth
We collect this only where it is needed for a service, such as setting up a company, or to meet legal duties such as customer due diligence and anti-money-laundering checks.
We collect national identity numbers and copies only where the law requires or a service clearly needs them.
Business Information
To deliver our services we may collect company registration details, financial and accounting records, tax information, employee information and other data that a service needs.
Website Technical Data
When you visit this website, our hosting provider records technical data such as your IP address, browser and device type, the pages requested and the date and time.
We use it to keep the website secure and available, to block abuse and to limit repeated form submissions.
We use Cloudflare Web Analytics and Google Analytics to count visits and see how the website performs.
Together they show us figures such as which pages are viewed, visitors’ country, device and browser, how they found us, and how they use the site.
Cloudflare Web Analytics does not set cookies. Cloudflare states that it does not collect or use visitors’ personal data and does not track individuals across its customers’ websites.
Google Analytics only runs if you accept it on the cookie banner. Once accepted, it sets cookies on your device to recognise repeat visits and measure how you use the site.
It shares this data with Google, which processes it under its own privacy policy and may transfer it outside Singapore and Malaysia. See Cookies and Similar Technologies below to change your choice.
We do not use advertising cookies or trackers beyond Google Analytics. If that changes, we will update this policy first.
Sensitive Information
We do not need, and ask you not to send us, information about your health, religion, race, political opinions or biometric data.
If a service does require any of this, we will tell you why and ask for your specific consent first.
How We Use Your Information
Service Delivery
To provide our services, including company set-up in Singapore, company secretary services, Single Family Office set-up and management, management consulting, and our finance, people, personal data and technology solutions.
Communication
To reply to your enquiry, prepare a quotation, give service updates and send important notices about your engagement.
Compliance and Legal Obligations
To meet legal and regulatory requirements in Singapore and, where relevant, Malaysia, including ACRA filings, tax compliance, customer due diligence, statutory reporting and responding to lawful requests from authorities.
Business Operations and Protection
To manage billing and accounts, keep records, protect the website and our systems against spam and abuse, prevent fraud, and establish, exercise or defend legal claims.
Marketing
We use your details to reply to the request you made. We send marketing messages only with your consent, we respect Singapore’s Do Not Call Registry, and you can withdraw your consent to marketing at any time.
On What Basis
We rely on:
- your consent, for example the box you tick on our form
- what is needed to enter into or perform a contract with you
- our legal obligations
- where the PDPA allows, our legitimate interests, such as those in this section, having weighed them against the effect on you
We do not sell personal data.
New Purposes and Automated Decisions
We use personal data only for the purposes in this policy and purposes closely connected to them.
If we want to use it for a new purpose, we will tell you and, where the law requires, ask for your consent first.
We do not make decisions that have legal or similarly significant effects on you by fully automated means.
Who We Share Your Information With
We share personal data only as needed for the purposes above, with:
- Government agencies and regulators, such as ACRA, IRAS, the Ministry of Manpower, the CPF Board and, where relevant, the Companies Commission of Malaysia and Malaysian tax authorities, when a filing or the law requires it.
- Authorities in other countries, directly or through Singapore or Malaysian authorities, where the law requires it, for example for tax reporting.
- Banks, auditors, lawyers, tax advisers and other professionals, where your service involves them or you ask us to.
- Your own business contacts, such as a foreign parent company, co-directors, shareholders and advisers, where your service involves them or you ask us to. For example, we may send company documents to an overseas parent company.
- Companies in the Compliz group that work with us to deliver services.
- Service providers that support our operations, listed in the next section.
- Courts, law enforcement and other authorities, where the law requires or allows it.
- A buyer or successor, if our business is restructured or sold, on terms that protect your data.
We share only what the recipient needs, and we do not share personal data with anyone for their own marketing.
Where a provider handles data for us, we require it to protect that data and use it only for our purposes.
Service Providers and Where Your Data Is Processed
We use the following providers when you use our website or contact us:
- Cloudflare, Inc. hosts and delivers this website, runs the security checks and rate limits that protect it, provides the Turnstile check that tells people from bots on our form, counts visits with its Web Analytics tool, and keeps request logs.
- Google LLC provides Google Analytics, which measures how visitors use this website using cookies on your device, only if you accept it on the cookie banner. Its servers are outside Singapore and Malaysia, and Google’s own privacy policy applies to the data it processes.
- Resend delivers the email created when you submit the quote form to our mailbox. It may keep a copy of that email and delivery records for a limited period under its own terms.
- HostGator, our email hosting provider, stores our mailbox, including the enquiries and emails you send us. Its servers are in the United States.
- WhatsApp (Meta) carries your messages if you contact us there. Its own privacy policy applies to how it handles them.
Compliz is based in Singapore, so personal data collected from individuals in Malaysia and elsewhere is transferred to and processed in Singapore.
Cloudflare, Google and Resend operate internationally, and our mailbox is hosted in the United States, so your data may also be processed in the United States and other countries.
When personal data leaves the country where it was collected, we take steps to make sure it receives a standard of protection comparable to the PDPA and, for Malaysia, the Malaysia PDPA.
These steps include using providers that commit to data protection in their contracts and terms, and sending only the data needed.
If you ask us to send your data to someone in another country, such as an overseas parent company or adviser, or your service requires it, we will send it there.
Once it reaches them, their own country’s laws apply, so please consider what you ask us to send. You can ask our Data Protection Officer for more information about the safeguards we use for overseas transfers.
Data Protection and Security
Our Approach
We handle personal data in line with Singapore’s PDPA. Where we handle the personal data of individuals in Malaysia, we do so in line with the Malaysia PDPA.
Security Measures
We make reasonable security arrangements to protect personal data, including encrypted connections (HTTPS) on this website, access limited to staff who need the data, confidentiality obligations on our people, and contracts with our providers.
No method of sending or storing data is completely secure, so we cannot guarantee absolute security. Please use the secure method we give you for sensitive documents.
Data Breaches
If a breach affects personal data we hold, we will assess it promptly.
Where the law requires, we will notify the Personal Data Protection Commission of Singapore, the Personal Data Protection Commissioner of Malaysia and the affected individuals, within the time the law sets.
If we hold the data for a client, we will tell the client without delay.
Data Retention
We keep personal data only for as long as we need it for the purpose it was collected, or for legal or business reasons.
For enquiries that do not lead to an engagement, we keep the details only as long as needed to follow up and to keep a record of the enquiry, and then delete or anonymise them.
For clients, we keep records while we act for you and afterwards as the law requires. For example, accounting and customer due diligence records are generally kept for at least five years.
When data is no longer needed, we delete it, anonymise it or return it securely.
Your Rights
Under Singapore’s PDPA, you have the right to:
- Ask for access to the personal data we hold about you and how it has been used or disclosed
- Ask us to correct inaccurate or incomplete data
- Withdraw your consent to our collecting, using or disclosing your data
If you are in Malaysia, you also have rights under the Malaysia PDPA, including the right to:
- access and correct your personal data
- withdraw your consent
- ask us to stop processing that is likely to cause you damage or distress
- ask us not to use your data for direct marketing
- where the law provides, ask for your data in a portable format
If the law of another country gives you further rights that apply to us, please tell us and we will consider your request under that law.
How to Make a Request
Use the form at the end of this page to contact our Data Protection Officer. We may ask you to confirm who you are before we act.
We aim to reply within 30 days (21 days for access requests under the Malaysia PDPA), and if we need longer we will tell you why.
We may charge a reasonable fee for an access request where the law allows, and will tell you the amount first. We may refuse or limit a request where the law permits, and we will explain why.
If You Withdraw Consent
We will act on your withdrawal within a reasonable time and tell you what it means for you.
If you withdraw consent we need for a service, we may be unable to continue that service. We may still keep data we are legally required to keep, or need to handle a dispute.
Complaints
Please contact us first so we can put things right. You may also contact the Personal Data Protection Commission of Singapore or the Personal Data Protection Commissioner of Malaysia.
Other Matters
Cookies and Similar Technologies
This website does not use advertising cookies. Cloudflare Web Analytics counts visits without setting cookies.
Google Analytics sets cookies on your device to measure how you use the site, but only after you choose Accept on the cookie banner shown on your first visit. If you choose Reject, or make no choice, Google Analytics does not load and sets no cookies.
You can change your choice at any time using the Cookie Preferences link in the footer of every page. Google’s privacy policy applies to the cookies it sets when you accept. You can also opt out using Google’s browser add-on, or clear cookies in your browser settings.
The Cloudflare Turnstile check on our form looks at signals from your browser to tell visitors from bots, and Cloudflare’s privacy policy applies to that check.
Links to Other Services
Our website links to WhatsApp and may link to other sites. We are not responsible for how those services handle your data, so please read their privacy policies.
Children
Our services are for businesses and their owners and are not directed at anyone under 18. If we learn that we hold data from a child without a parent’s consent, we will delete it.
Changes to This Policy
We may update this policy from time to time. The date at the bottom shows when it last changed, and we will tell existing clients about any important change.
If we provide a translation of this policy, the English version prevails.
Contact Us
For privacy-related enquiries or to exercise your data protection rights, please contact us:
Data Protection Officer Compliz Pte. Ltd.Use the form below to send us feedback or raise an issue about personal data protection.
Data protection form
Feedback, requests and concerns about your personal data go straight to our Data Protection Officer.
Last Updated: 26 September 2026
