Legal

Privacy Policy

Last updated: 11 April 2025  ·  Acceler8 AI Pte. Ltd.

This Privacy Policy describes how Acceler8 AI Pte. Ltd. collects, uses, and protects your personal data in compliance with the Singapore Personal Data Protection Act 2012 (PDPA) and, where applicable, the EU General Data Protection Regulation (GDPR).

1. Introduction

Acceler8 AI Pte. Ltd. ("we", "us", or "our") operates the PAW+™ platform — Asia's first Pet Adventure, Aid & Wellness application — accessible via our website at startpupp.com and associated mobile applications (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data in accordance with the Singapore Personal Data Protection Act 2012 (PDPA), and, where applicable, the European Union General Data Protection Regulation (EU GDPR) and other relevant data protection laws. By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please discontinue use of the Service.

2. Data Controller

The data controller responsible for your personal data is: Acceler8 AI Pte. Ltd. 14 Robinson Rd, Unit 08-01A, Far East Finance Building, Singapore 048545 Email: privacy@acceler8ai.io We have appointed a Data Protection Officer (DPO) who can be contacted at the email above for all personal-data-related inquiries.

3. Personal Data We Collect

We collect the following categories of personal data: 3.1 Data you provide directly • Identity data: name, username, or similar identifier • Contact data: email address, phone number, mailing address • Pet profile data: pet name, species, breed, age, weight, vaccination records, medical history, microchip number • Account credentials: password (stored in hashed, salted form; we never store plaintext passwords) • Financial data: payment card details (processed by PCI-DSS compliant third parties; we do not store raw card numbers) • Marketing preferences and communication preferences • Content you submit: messages, reviews, photos of your pet 3.2 Data collected automatically • Device and technical data: IP address, device type, operating system version, browser type, unique device identifiers • Usage data: pages visited, features accessed, timestamps, click-stream data, session duration • Location data: GPS coordinates, geofence events (only when you grant location permission) • Log data: server logs, error reports, performance telemetry 3.3 Data from third parties • Social media profile data, when you choose to link a social account • Veterinary records from partner clinics, where you authorise transfer • Government/agency data: travel permit status, where relevant to pet travel features

4. How We Use Your Personal Data

We process your personal data for the following purposes, each supported by a lawful basis under the PDPA and GDPR: 4.1 Providing the Service (contractual necessity) • Creating and managing your account • Processing waitlist registrations and early-access allocations • Operating emergency routing, vet-on-demand, and pet safety features • Handling payment transactions 4.2 Legitimate interests • Improving and personalising the Service • Security, fraud detection, and abuse prevention • Internal analytics and product research • Customer support and dispute resolution 4.3 Compliance with legal obligations • Responding to lawful requests from Singapore authorities (e.g., PDPC, courts) • Anti-money-laundering (AML) and know-your-customer (KYC) obligations, where applicable 4.4 Consent (where required) • Sending marketing emails and push notifications (you may withdraw consent at any time) • Processing sensitive pet health data beyond what is strictly necessary for the Service • Sharing your data with third-party research partners

5. Disclosure of Personal Data

We do not sell your personal data. We may disclose your data to: 5.1 Service providers and sub-processors We engage carefully selected third-party vendors who process data on our behalf under data processing agreements, including: • Cloud infrastructure: Amazon Web Services (AWS), Singapore region • Authentication and database: Supabase Inc. • Payment processing: Stripe, Inc. (PCI-DSS Level 1 certified) • Analytics: anonymised usage analytics providers • Communication services: transactional email and SMS providers 5.2 Business partners We share data with partner veterinary clinics, pet-friendly business operators, and insurers only where you have expressly requested or authorised those services. 5.3 Corporate transactions In the event of a merger, acquisition, or sale of assets, your data may be transferred to the successor entity, subject to this Privacy Policy. 5.4 Legal and regulatory requirements We will disclose personal data when required to do so by applicable law, court order, or government regulation, or to protect our rights, property, or safety.

6. International Data Transfers

Our primary data processing infrastructure is located in Singapore. Where data is transferred outside Singapore, we ensure adequate safeguards are in place in accordance with PDPA Schedule 9 and, where applicable, GDPR Chapter V mechanisms (e.g., Standard Contractual Clauses). A list of countries to which data may be transferred is available on request.

7. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes outlined in this Policy, or as required by law: • Account data: retained for the duration of your account plus 5 years after closure • Transaction records: 7 years (Singapore Companies Act and IRAS requirements) • Pet medical records: retained until deletion is requested, minimum 3 years from last interaction • Marketing preferences and logs: 2 years from last interaction • Anonymised aggregate analytics: indefinitely After the applicable retention period, data is securely deleted or anonymised.

8. Security of Personal Data

We implement industry-standard technical and organisational measures to protect your personal data, including: • Encryption in transit (TLS 1.2+) and encryption at rest (AES-256) • Role-based access control and principle of least privilege • Multi-factor authentication for administrative access • Regular penetration testing and vulnerability assessments • ISO 27001-aligned information security management practices • Incident response procedures with PDPC notification within 3 calendar days for notifiable data breaches No method of transmission or storage is 100% secure. In the event of a breach affecting your rights, we will notify you as required by law.

9. Your Rights

Under the PDPA and, where applicable, the GDPR, you have the following rights: 9.1 Right of access — You may request a copy of the personal data we hold about you. 9.2 Right to correction — You may request correction of inaccurate or incomplete data. 9.3 Right to withdraw consent — Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing. 9.4 Right to erasure (GDPR) — You may request deletion of your personal data subject to applicable legal obligations. 9.5 Right to data portability (GDPR) — You may request your data in a structured, machine-readable format. 9.6 Right to object (GDPR) — You may object to processing based on legitimate interests. 9.7 Right to lodge a complaint — You may lodge a complaint with the Singapore Personal Data Protection Commission (PDPC) at pdpc.gov.sg, or with your local supervisory authority. To exercise any right, email privacy@acceler8ai.io. We will respond within 30 calendar days.

10. Cookies and Tracking Technologies

We use cookies and similar tracking technologies on our website. Categories include: • Strictly necessary cookies: required for the Service to function (e.g., authentication tokens). Cannot be disabled. • Analytics cookies: help us understand how visitors use the Service (e.g., page views, session length). These are anonymised where possible. • Marketing cookies: used to deliver relevant advertising and track campaign performance. Only placed with your consent. You can manage cookie preferences through your browser settings or our cookie consent banner. Disabling non-essential cookies will not impair your core experience.

11. Children's Privacy

The Service is not directed to children under 13 years of age. We do not knowingly collect personal data from children under 13 without verifiable parental consent. If you believe we have inadvertently collected data from a child, please contact us at privacy@acceler8ai.io and we will delete it promptly.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Material changes will be notified via email or a prominent notice within the Service at least 14 days before taking effect. The "Last Updated" date at the top of this page reflects the most recent revision. Continued use of the Service after the effective date of any changes constitutes acceptance of the revised Policy.

14. Contact Us

For all privacy-related enquiries, data access requests, or complaints, please contact our Data Protection Officer: Acceler8 AI Pte. Ltd. 14 Robinson Rd, Unit 08-01A, Far East Finance Building, Singapore 048545 Email: privacy@acceler8ai.io For complaints not resolved to your satisfaction, you may contact the PDPC at www.pdpc.gov.sg.