Privacy notice
This notice explains how MarkVault Drift LLP ("we", "us", "our") collects, uses, discloses, and protects personal data when you visit markvaultdrift.pro, contact us, or engage our brand strategy services. We comply with the Singapore Personal Data Protection Act 2012 (PDPA) and related regulations as amended from time to time.
1. Data controller
MarkVault Drift LLP
72 Tyrwhitt Road, #02-01, Singapore 207565
Email: [email protected]
Telephone: +65 6486 3027
For the purposes of the PDPA, MarkVault Drift LLP is the organisation responsible for personal data described in this notice, except where we process data solely on behalf of a client under a written contract (see Section 8).
2. Personal data we collect
2.1 Website visitors
When you browse markvaultdrift.pro, we may collect technical data automatically through server logs and essential cookies: IP address (often truncated or aggregated in logs), browser type and version, operating system, referring URL, pages viewed, and timestamps. We do not operate third-party analytics scripts on this website; analytics cookies remain disabled by design.
2.2 Correspondence
When you email [email protected] or [email protected], we receive your email address, name (if provided), message content, and any attachments you send voluntarily. We do not require you to create an account or complete a web form to contact us.
2.3 Client engagements
When you become a client, we collect business contact details (name, job title, company, business address, telephone, email), billing information necessary to issue invoices, briefing materials you supply, meeting notes, and correspondence related to the engagement. Briefing materials may contain personal data about your employees or customers that you choose to share; you are responsible for ensuring you have a lawful basis to disclose that data to us.
2.4 Visits to our studio
Visitors to 72 Tyrwhitt Road may be recorded on a visitor log (name, company, time of entry) for security and fire safety purposes. We do not operate continuous CCTV in client meeting areas unless explicitly notified for a specific event.
3. Purposes of collection, use, and disclosure
We use personal data for purposes that a reasonable person would consider appropriate in the circumstances, including:
- responding to enquiries and scheduling briefings;
- delivering brand strategy services under contract;
- issuing invoices and maintaining accounting records;
- complying with legal and regulatory obligations in Singapore;
- maintaining website security and troubleshooting technical faults;
- remembering your cookie preferences on this site;
- protecting our legitimate interests in defending legal claims and enforcing agreements.
We do not sell personal data. We do not use your data for automated profiling or targeted advertising on third-party platforms.
4. Legal bases and consent
Under the PDPA, we rely on consent, contractual necessity, legal obligation, and legitimate interests as applicable. Where consent is required, we seek it clearly and allow withdrawal without undue penalty to unrelated services already completed. Cookie preferences are managed through our consent banner and Cookie notice; essential cookies do not require consent because they are strictly necessary to store your choice.
5. Disclosure to third parties
We may disclose personal data to:
- professional advisers (lawyers, accountants) bound by confidentiality;
- IT service providers hosting our email and website infrastructure in Singapore or jurisdictions with comparable safeguards;
- banks and payment processors for invoice settlement;
- public authorities when required by law or court order.
Google Maps embeds on this website may cause your browser to connect to Google servers when you interact with a map. Google may collect data under its own policies. See our Cookie notice for detail.
We require processors to protect personal data by contract and to use it only for specified purposes.
6. International transfers
Our primary systems are hosted in Singapore. If we transfer personal data overseas—for example, because you are headquartered outside Singapore and request cloud delivery to your region—we ensure protection comparable to the PDPA through contractual clauses or your written instructions as part of the engagement letter.
7. Retention
Enquiry emails unrelated to a contract are deleted within twenty-four months unless a business relationship develops. Client project materials follow the archive policy on Dispatch: read-only studio archive for twenty-four months after handover, then deletion unless extended storage is contracted. Accounting records are retained for seven years per IRAS requirements. Server logs rotate on a short cycle and are not kept as permanent records.
8. Processing on behalf of clients
When we analyse briefing materials containing your customers' or employees' personal data, we act as a data intermediary under your instructions. You remain the organisation primarily responsible for that data unless we agree otherwise in writing. We use such data only to perform the engagement, do not merge it with marketing lists, and delete working copies per our archive policy.
9. Security
We implement administrative, physical, and technical measures appropriate to the sensitivity of the data: access controls on studio systems, encrypted transport for file delivery, locked storage for printed materials, and staff confidentiality obligations. No method of transmission over the internet is completely secure; we encourage clients to use encrypted channels for highly sensitive briefs.
10. Your rights under the PDPA
Subject to exceptions in the PDPA, you may:
- request access to personal data we hold about you;
- request correction of inaccurate or incomplete data;
- withdraw consent where processing is consent-based;
- request information about how we have used or disclosed your data in the past year.
Submit requests to [email protected]. We respond within thirty days unless an extension is permitted. We may apply a reasonable administrative charge for manifestly unfounded or excessive requests, as allowed under the PDPA.
11. Accuracy
Please inform us if your contact details change so correspondence and invoices reach the correct person. We rely on clients to supply accurate briefing information; we annotate but do not independently verify personal data appearing in client-supplied materials unless contracted to do so.
12. Data breach notification
If we assess that a data breach is likely to result in significant harm or affect a significant number of individuals, we will notify the Personal Data Protection Commission and affected individuals as required by law, and cooperate with remedial steps.
13. Children
Our services and website are directed at business professionals. We do not knowingly collect personal data from individuals under eighteen without parental or guardian involvement in a client relationship.
14. Marketing communications
We do not send unsolicited bulk marketing email. If you correspond with us and a business relationship develops, we may occasionally share studio notes or folio updates relevant to your engagement. You may opt out of non-essential messages at any time by replying unsubscribe or writing to [email protected]. Opting out of marketing does not affect transactional correspondence about active projects or legal notices we must deliver.
15. Do Not Track and similar signals
Some browsers transmit Do Not Track or Global Privacy Control signals. We do not respond to these signals with additional tracking because we do not operate cross-site analytics or advertising networks on markvaultdrift.pro. Your cookie banner choices remain the primary control mechanism on this site.
16. Records of processing
We maintain an internal register of processing activities for client and website data, reviewed annually. The register documents categories of data, purposes, retention periods, recipients, and safeguards. Summaries are available to clients under contract on request where relevant to joint controller or processor arrangements.
When we act as a data intermediary for client-supplied materials, the register notes the instruction set, deletion schedule, and whether any subprocessors assisted with transcription or secure file transfer. We do not merge client briefing data into our own marketing records.
17. Third-party recipients in practice
Our website is hosted with a Singapore-based provider under contract requiring confidentiality and security standards. Email is provided through a business mailbox with two-factor authentication on administrative access. Printed materials are shredded when no longer required unless returned to you. We do not permit providers to use your data for their own marketing. Before adding a new sub-processor that handles personal data, we assess their safeguards and update this notice if the change is material to website visitors.
18. Changes to this notice
We may update this notice to reflect legal or operational changes. Material updates will be posted on this page with a revised date. Continued use of the website after changes constitutes acknowledgement of the updated notice where permitted by law. We encourage periodic review if you rely on this site for understanding how we handle correspondence data.
18. Contact and complaints
Privacy enquiries: [email protected]
General contact: [email protected]
If you are not satisfied with our response, you may contact the Personal Data Protection Commission of Singapore (pdpc.gov.sg).