Privacy

Privacy Policy

How RiseMark Growth Pte. Ltd. collects, uses, discloses and protects personal data under Singapore's Personal Data Protection Act 2012 (PDPA). Last updated: 27 July 2026.

1. Organisation identity

This Privacy Policy applies to personal data collected by RiseMark Growth Pte. Ltd. (UEN 202791473K), a marketing agency registered in Singapore with its office at 12 Kallang Avenue, #09-08, Aperia Tower 2, Singapore 339511 ("RiseMark", "we", "us", "our"). We operate the website risemark.life and provide growth marketing, paid media, SEO, conversion rate optimisation, analytics, reporting and related professional services to client organisations.

We are a data controller in respect of personal data described in this policy. For client campaign data processed on behalf of clients, we may act as a data intermediary under instructions set out in a signed scope of work or data processing arrangement.

2. Scope and commitment

We are committed to protecting personal data in accordance with the PDPA and applicable subsidiary legislation. This policy explains what data we collect, why we collect it, the legal bases for processing, how long we retain it, who we share it with, and the rights available to individuals in Singapore.

By submitting an enquiry, engaging our services, visiting our website, or otherwise interacting with us, you acknowledge that you have read this Privacy Policy. Where consent is required, we will obtain it through clear opt-in mechanisms — for example, an unticked consent checkbox on our contact form.

3. Personal data we collect

3.1 Enquiry and contact data

When you use our contact form, email us, call our office, or meet us at our Kallang premises, we may collect your name, email address, telephone number, company name, job title, message content, and any other information you choose to provide. We record the date and time of enquiries and the subject line selected.

3.2 Client and project data

If you become a client, we collect business contact details, billing information, signed contracts, scope-of-work documents, briefs, brand assets, campaign materials, analytics credentials or exports, advertising account access logs, CRM data necessary to deliver services, meeting notes, and correspondence relating to your project or retainer.

3.3 Website and technical data

When you visit risemark.life, we may automatically collect IP address, browser type, device type, operating system, referring URL, pages viewed, and approximate session duration. If you accept analytics cookies, additional usage data may be collected as described in our Cookie Policy.

3.4 Marketing and events

If you subscribe to updates, attend a workshop, or download materials we publish, we may collect your registration details and attendance records. We do not purchase mailing lists or contact databases from third-party brokers.

4. Purposes of collection, use and disclosure

We collect and use personal data for the following purposes, and we do not use data for incompatible purposes without notifying you and, where required, obtaining fresh consent:

  • Responding to enquiries and scheduling growth review consultations;
  • Preparing proposals, scopes of work and fee quotations;
  • Delivering marketing agency services including paid media management, SEO, CRO, content marketing, analytics setup, dashboard reporting and lifecycle automation;
  • Managing client accounts, invoicing and payment follow-up;
  • Communicating about project progress, reporting cadence and service changes;
  • Complying with legal, regulatory and tax obligations in Singapore;
  • Maintaining website security, troubleshooting and preventing fraud or abuse;
  • Improving our website and understanding aggregate audience behaviour where analytics cookies are accepted;
  • Exercising or defending legal claims.

We may disclose personal data to employees and contractors who need access to perform their roles, subject to confidentiality obligations. We do not sell personal data.

5. Consent and other legal bases

Under the PDPA, we rely on consent, contractual necessity, legitimate interests, and legal obligation as appropriate to each processing activity.

Consent: Contact form submissions require explicit consent via an unchecked checkbox before submission. Marketing communications, where sent, include an unsubscribe mechanism. You may withdraw consent at any time by contacting [email protected], subject to legal or contractual restrictions on retention.

Contractual necessity: Processing client contact and project data is necessary to perform a signed scope of work or pre-contractual steps at your request.

Legitimate interests: We may process limited business contact data to respond to unsolicited B2B enquiries, maintain CRM records, and secure our website, balanced against your privacy rights.

Legal obligation: We retain certain records to meet accounting, tax and regulatory requirements in Singapore.

6. Client, enquiry and campaign data handling

Enquiry data is accessed only by team members involved in business development and administration. Client campaign data — including ad account structures, analytics configurations, audience definitions and performance reports — is accessed only by personnel assigned to your account and authorised subcontractors bound by confidentiality terms.

We treat client data as confidential. We do not use one client's campaign data, creative assets or performance figures for another client's benefit without permission. Illustrative case studies published on our website use anonymised or hypothetical scenarios, not identifiable client records.

Where we access third-party platforms on your behalf (Google Ads, Meta Ads, analytics tools, CRM systems), we follow your access permissions and document handover procedures at project end. Credentials are stored using access controls appropriate to sensitivity; we recommend role-based access rather than shared passwords.

7. Data Protection Officer and contact

Our Data Protection Officer can be reached at:

Email: [email protected]
Postal address: Data Protection Officer, RiseMark Growth Pte. Ltd., 12 Kallang Avenue, #09-08, Aperia Tower 2, Singapore 339511

For general enquiries unrelated to privacy, use [email protected]. We aim to acknowledge privacy requests within ten business days.

8. Retention

We retain personal data only as long as necessary for the purposes collected, unless a longer period is required by law.

  • Enquiry records: up to twenty-four months from last contact if no client relationship forms, unless you request earlier deletion and no legal hold applies;
  • Client project files: duration of engagement plus up to seven years for contractual, accounting and dispute-resolution purposes;
  • Marketing subscriptions: until you unsubscribe or withdraw consent;
  • Server and security logs: typically up to twelve months;
  • Cookie consent records: six months, aligned with our cookie banner storage period.

When retention periods expire, we delete or anonymise data using procedures appropriate to the medium.

9. Access, correction and other rights

Under the PDPA, you may request access to personal data we hold about you and information about how it has been used or disclosed within the past year. You may request correction of inaccurate or incomplete data.

Submit requests to [email protected] with sufficient detail for us to verify your identity. We may charge a reasonable fee for manifestly unfounded or excessive requests as permitted by law. We respond within thirty days where possible.

You may also withdraw consent, subject to legal and contractual consequences. Withdrawal does not affect processing already performed lawfully before withdrawal.

10. PDPC contact

If you have concerns about our handling of personal data that we cannot resolve, you may contact the Personal Data Protection Commission (PDPC) in Singapore:

Website: www.pdpc.gov.sg
General enquiry line: +65 6377 3131

We encourage you to contact us first so we can address your concern directly.

11. Cookies and similar technologies

Our website uses strictly necessary cookies for basic operation and, with your consent, analytics cookies. Details of categories, vendors, durations and opt-out methods are in our Cookie Policy. Cookie-related personal data is processed according to this Privacy Policy.

12. Security measures

We implement administrative, technical and physical safeguards proportionate to the sensitivity of data we hold, including access controls on business systems, encrypted connections (HTTPS) on our website, password policies for staff accounts, and confidentiality terms in employment and contractor agreements.

No method of transmission or storage is completely secure. While we work to protect personal data, we cannot guarantee absolute security. You are responsible for keeping any credentials we issue to you confidential and notifying us promptly of suspected unauthorised access.

13. Cross-border transfers and sub-processors

Our primary hosting is in Singapore. Some tools we use for analytics, advertising management, email delivery, cloud storage, CRM, project management or AI-assisted workflows may process data on servers located outside Singapore, including in the United States, European Union or other jurisdictions.

Where personal data is transferred overseas, we take steps required under the PDPA to ensure recipients provide a comparable standard of protection, such as contractual clauses, vendor due diligence, and minimising data fields transferred. Common categories of sub-processors include:

  • Website hosting and content delivery providers;
  • Analytics platforms (e.g. Google Analytics, when enabled with consent);
  • Advertising platforms (Google Ads, Meta Ads, LinkedIn) when managing client campaigns;
  • Email and calendar services for client communication;
  • Cloud productivity and file storage services;
  • AI tool providers used for internal drafting and analysis under human review.

A current list of material sub-processors is available on request to [email protected]. We update due diligence when vendors change.

14. Third-party links

Our website may link to third-party sites such as advertising platforms or professional networks. We are not responsible for the privacy practices of those sites. Review their policies before providing personal data.

15. Children

Our services are directed at businesses and professional contacts. We do not knowingly collect personal data from individuals under eighteen without appropriate parental or guardian involvement. Contact us if you believe we have collected a minor's data in error.

16. Automated decision-making

We do not make solely automated decisions with legal or similarly significant effects on individuals using personal data from our website enquiry forms. AI tools may assist our team with drafts and analysis; human staff review outputs before client-facing use.

17. Data breach notification

If a data breach likely to result in significant harm occurs, we will assess the incident, take containment steps, and notify the PDPC and affected individuals as required under Singapore law and our internal incident response plan.

18. Changes to this policy

We may update this Privacy Policy to reflect legal, technical or business changes. The "Last updated" date at the top will change when we publish a revision. Material changes affecting how we use personal data already collected will be communicated where required — for example, by email to active clients or a notice on our website.

19. Change log

  • 27 July 2026: Initial publication of PDPA-compliant Privacy Policy for risemark.life.

20. Contact summary

RiseMark Growth Pte. Ltd.
12 Kallang Avenue, #09-08, Aperia Tower 2, Singapore 339511
UEN 202791473K
General: [email protected]
Privacy / DPO: [email protected]
Phone: +65 6796 2418