Privacy Policy

Last updated: September 2026

If there is any conflict between the English and Chinese versions, the English version shall prevail.

1. Overview

This policy is issued by 1965 Intelligence Pte. Ltd. (UEN [UEN], registered address [Registered Address], Singapore) ("we", "us", "our") and explains how we collect, use, disclose and protect personal data under Singapore's Personal Data Protection Act 2012 (PDPA) and other applicable law. It applies to our marketing website, application and related services (the "Platform").

2. Our Role: Controller and Data Intermediary

In respect of an advisor's own account data, we act as the data controller and decide the purposes for which that data is collected and used. In respect of personal data about an advisor's clients that the advisor enters into the planning tools, we act as a data intermediary, processing that data solely on the advisor's behalf and instructions. The purposes, legal basis and retention of that client data are determined and owned by the advisor, see Section 5.

3. Data We Collect

We collect the following categories of data:

  • Account data: Email address, name, job title, phone number, password hash, subscription and billing status, two-factor authentication settings (including a phone number if SMS is used), and sign-in method details (including the identifiers provided when you sign in with Google or Apple).
  • Client data: Information about an advisor's clients that the advisor enters into client files and planning tools. This may include name, contact details, date of birth, marital status, number of dependents, residency status, occupation, income, and free-text notes written by the advisor. This data is stored on our servers (see Section 6). It is not limited to the browser session.
  • Payment data: Processed and stored by Airwallex. We retain only what is necessary to reference your subscription (such as subscription status, your Airwallex customer ID, and the brand and last four digits of the card). We do not store full card details.
  • Communications and support data: Information you provide when you contact us through a support ticket, email, or other channel, including the content of the ticket and any replies.
  • Technical and security data: IP address, browser/device information, sign-in timestamps, and audit log entries kept for account security and fraud-prevention purposes.
  • Prospect data: If you contact us through a website form, a sales enquiry, or a similar channel, even before you register an account, we may record your name, email, company, and the history of our communications in our internal customer-relationship system.

4. How We Use Data

We collect, use and disclose data for the following purposes:

  • providing, maintaining and improving the Platform and its tools
  • creating and administering your account, and authenticating sign-ins
  • processing payments, subscriptions and refunds
  • sending service messages (such as password resets and billing notices) and, where you have consented, marketing communications
  • responding to support requests
  • detecting, investigating and preventing fraud, abuse and security incidents
  • complying with applicable legal obligations

5. Your Responsibility for Client Data

When you enter personal data about your clients into the Platform, you, not us, are the data controller for that data. You are responsible for obtaining any consent or other lawful basis required under the PDPA and any other applicable law before entering, storing or processing your clients' data, and for disclosing to them that their data will be stored on this Platform. We process this data only on your instructions, as your data intermediary; we do not use client data for any purpose outside your instructions and never use it for our own marketing.

6. Data Storage & Security

Account data and client data are stored in a PostgreSQL database hosted on AWS infrastructure in Singapore. Passwords are stored as hashes; one-time codes, refresh tokens and recovery codes are stored as hashes, never in plain text. Data is encrypted in transit and at rest using industry-standard protocols. Internal access is restricted on a least-privilege basis, and staff actions are recorded in an audit log. While we take reasonable technical and organisational measures to protect data, no system can be guaranteed to be completely secure.

7. Third-Party Service Providers

We use the following third-party service providers to process data:

  • Amazon Web Services (AWS) for database hosting
  • Airwallex for payment processing
  • Zoho ZeptoMail for transactional and notification emails
  • Twilio for two-factor authentication SMS, if you enable SMS verification
  • Google and Apple, if you choose to sign in using their services
  • Vercel for marketing website hosting
  • Google Analytics for website usage measurement, only where you have consented — see Section 9

These providers each maintain a Singapore data centre and hold the relevant licence to operate in Singapore, process data only on our instructions, and are bound by contractual confidentiality obligations. Other than these providers and where required by law, we do not sell or share your data.

Where any of the above providers uses an AI/ML model to carry out a minor processing task on their platform (for example, fraud detection or support-ticket triage), that processing follows the provider's own privacy policy, and data may as a result pass through the data centre where that model runs, which may be located outside Singapore. We select providers only where their policies commit not to use the data to train their own models and to maintain a standard of protection no lower than the PDPA requires.

8. Overseas Transfer of Data

The service providers we use process and store data through their Singapore data centres, and we do not route data to overseas infrastructure by default. To the extent any incidental overseas transfer occurs as a function of how a service operates (for example, international card-network routing for payment processing), we take reasonable steps, including contractual safeguards, in accordance with section 26 of the PDPA to ensure that any overseas recipient provides a standard of protection comparable to that required under the PDPA.

One exception is Google Analytics, which processes data on Google's global infrastructure, which may be outside Singapore, under Google's data processing terms. That processing happens only after you consent to analytics cookies, and only for the product-level event data described in Section 9; an advisor's client data is never sent to it.

9. Cookies and Analytics

We use essential cookies to maintain your login session and account security (for example, to recognise a refresh token). These are necessary for the Platform to work and cannot be switched off.

With your consent, we use Google Analytics (GA4, measurement ID G-D1YT7VV4QL) to understand which pages are read, how many sign-ups and subscriptions complete, and how often each planning tool is used. Until you consent, Google Consent Mode holds analytics storage at "denied": no analytics cookie is written and no visit is attributed. We run no advertising or remarketing cookies.

The events we send to Google carry product-level labels only — which tool was used, which file format was exported, which plan was chosen. They never include client personal data entered into the planning tools, any financial figure, or a name or email address. Client data we process as a data intermediary (Section 5) never reaches analytics.

Google processes this data as an independent controller under its own privacy policy. You can change your choice at any time: . Choosing "Essential only" keeps analytics off.

10. Data Retention

We retain account data and client data for as long as your account remains active. If you cancel your subscription, account data is retained for 30 days in case you reactivate, after which it is permanently deleted, except for records we are required to keep by law (such as billing and audit records). You may request deletion of your account and associated data at any time by contacting dpo@1965intelligence.sg; we will action verified requests within a reasonable period, subject to records we are required to retain by law.

11. Your Rights Under the PDPA

In respect of your own account data, you have the right to:

  • request access to the data we hold about you
  • request correction of data that is inaccurate or incomplete
  • withdraw any consent you previously gave (this may affect our ability to continue providing some or all of our services to you)
  • request deletion of your account and associated data, subject to the statutory retention obligations described in Section 10

To exercise any of these rights, contact our Data Protection Officer (Section 13). If you are an end client of one of our advisor customers and wish to exercise rights over your own personal data held on the Platform, please contact your advisor directly, as they are the controller of that data.

12. Children's Data

The Platform is intended for professional financial advisors and is not directed at, and does not knowingly register accounts for, individuals under 18 years of age.

13. Data Protection Officer

We have appointed a Data Protection Officer, as required under the PDPA, responsible for overseeing our compliance with our data protection obligations. For any privacy-related question, complaint or request, contact: dpo@1965intelligence.sg.

14. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated by email or in-platform notice, with reasonable advance notice before they take effect.

15. Contact

For general questions about this policy, contact support@1965intelligence.sg; for data protection matters, contact dpo@1965intelligence.sg.