Privacy Policy
Last updated: 28 August 2026
This Privacy Policy explains how TKH Global Group, Singapore ("appsg.ai", "we", "us") collects, uses, discloses and protects personal data in connection with the appsg.ai platform (the "Service"). We are committed to handling personal data in accordance with Singapore's Personal Data Protection Act 2012 ("PDPA").
appsg.ai is a multi-tenant platform that lets businesses ("Customers") build AI agents grounded in their own knowledge base and deploy them across WhatsApp, Telegram, email and a web widget. In doing so, two different relationships arise, and this policy addresses both:
- When you are our Customer (you sign up, subscribe and administer a workspace) — we act as the data controller of your account data.
- When you are an end-customer of one of our Customers (you message a Customer's AI agent) — the Customer is the data controller and appsg.ai is the data processor acting on that Customer's instructions. For those interactions, the Customer's own privacy notice governs, and our Data Processing Addendum sets out our obligations.
- Personal data we collect
- How we use personal data
- Sub-processors and disclosure to third parties
- AI processing and cross-border transfers
- Retention
- Security
- Your PDPA rights
- Data Protection Officer & complaints
- Changes to this policy
1. Personal data we collect
a. Account and billing data (we are the controller)
- Account data — name, work email, password (stored only as a salted hash), organisation name, role and workspace settings.
- Billing data — plan, subscription status, GST details and billing contact. Card details are collected and stored by Stripe, our payment processor; we do not store full card numbers.
- Usage and technical data — log-in events, IP address, device/browser information, audit logs, feature usage and token/consumption metering used to operate and secure the Service.
- Support and communications — messages you send us and records of our correspondence.
b. End-customer data (we are the processor, on the Customer's behalf)
- End-customer personal data (PII) that flows through the channels a Customer connects — for example a person's name, phone number, WhatsApp/Telegram identifier, email address, and the content of messages they exchange with the Customer's AI agent, including anything they voluntarily disclose in a conversation.
- Knowledge-base content that the Customer uploads to ground its agents, which may contain personal data the Customer chooses to include.
The Customer decides what data is collected through its agents and is responsible for having a lawful basis and appropriate notice/consent for that collection under the PDPA.
2. How we use personal data
We use account and billing data to: provide, maintain and secure the Service; authenticate users; process subscriptions, payments and GST; meter usage and enforce plan limits; provide support; send service and administrative notices; detect and prevent fraud, abuse and security incidents; and comply with legal obligations.
We process end-customer data only to provide the Service to the relevant Customer — routing messages, generating AI responses, maintaining conversation context, and producing the Customer's own analytics. We do not use end-customer data for our own independent purposes and we do not sell personal data.
3. Sub-processors and disclosure to third parties
To operate the Service we rely on the third-party sub-processors below. Personal data — including, where applicable, end-customer PII and message content — is transmitted to these providers strictly to deliver the functionality described.
| Sub-processor | Purpose | Data involved | Location |
|---|---|---|---|
| Anthropic (Claude) | AI inference — generating agent responses | Prompts, knowledge-base excerpts and conversation content, which may include end-customer PII | United States |
| OpenAI | AI inference — generating agent responses | Prompts, knowledge-base excerpts and conversation content, which may include end-customer PII | United States |
| Google (Gemini) | AI inference — generating agent responses | Prompts, knowledge-base excerpts and conversation content, which may include end-customer PII | United States |
| Stripe | Payment processing and card storage | Customer billing and card data | United States / Singapore |
| Meta Platforms (WhatsApp) | Message delivery over the WhatsApp channel | End-customer phone number and message content | United States / global |
| Telegram | Message delivery over the Telegram channel | End-customer Telegram identifier and message content | Global |
| Email provider ([email provider name]) | Transactional and channel email delivery | Recipient email address and message content | [location] |
We may also disclose personal data to professional advisers, or where required to comply with law, a court order or a lawful request by a public authority, or to protect our rights, users or the security of the Service. A current sub-processor list is maintained and Customers are notified of material changes as described in the Data Processing Addendum.
4. AI processing and cross-border transfers
Data is transmitted to third-party AI providers for processing. To generate agent responses, prompt content — which can include knowledge-base material and end-customer PII contained in a conversation — is sent to the AI inference providers listed above (Anthropic, OpenAI and Google), which are based in the United States. This means personal data leaves your workspace and Singapore for processing. We do not claim that "no data leaves your tenant".
Under the API terms on which we access these providers, Customer and end-customer data submitted through the API is not used to train the providers' models. The AI providers process the data to return a response and for limited abuse-monitoring and service-operation purposes permitted by their terms.
Where we transfer personal data outside Singapore, we take steps required by the PDPA to ensure a comparable standard of protection, including contractual data-protection commitments with our sub-processors. By using the Service and connecting AI-powered channels, Customers acknowledge and instruct these transfers.
5. Retention
We retain account and billing data for as long as your account is active and thereafter as needed to meet legal, tax and accounting obligations. End-customer data processed on a Customer's behalf is retained for as long as the Customer's workspace requires it, subject to the Customer's configured retention settings and our Data Processing Addendum. On termination, data is deleted or returned as described in the DPA and our Refund & Cancellation Policy. We may retain minimal records where the law requires.
6. Security
We apply administrative, technical and physical safeguards appropriate to the risk, including encryption of data in transit (TLS), hashed passwords, tenant isolation, role-based access controls, session hardening, audit logging, and least-privilege access to production systems. No method of transmission or storage is completely secure, but we work to protect personal data and to notify affected parties of data breaches as required by the PDPA.
7. Your PDPA rights
Subject to the PDPA, you may:
- Access the personal data we hold about you and information about how it has been used or disclosed;
- Correct personal data that is inaccurate or incomplete;
- Withdraw consent to our collection, use or disclosure of your personal data, on reasonable notice (this may affect our ability to provide the Service).
To exercise these rights, use our Data Rights Request page or contact our Data Protection Officer below. If you are an end-customer of one of our Customers, please direct your request to that Customer as the controller; we will support them in responding.
8. Data Protection Officer & complaints
You can reach our Data Protection Officer at dpo@appsg.ai or by writing to [Legal Entity Name], Singapore. We aim to respond to requests within the timeframes set by the PDPA.
If you are not satisfied with our response, you may lodge a complaint with Singapore's Personal Data Protection Commission (PDPC) at www.pdpc.gov.sg.
9. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes we will update the "Last updated" date and, where appropriate, notify Customers. Your continued use of the Service after an update constitutes acceptance of the revised policy.
Questions about any of this? Talk to us. To ask for a copy of your data, a correction or an erasure, use the data rights request form.