Privacy Policy

Last Updated: January 15, 2026

Quoralis is committed to protecting your privacy and handling your personal data responsibly. This Privacy Policy explains how we collect, use, disclose, and safeguard personal information in accordance with Singapore's Personal Data Protection Act 2012 (PDPA) and other applicable data protection laws.

1. Introduction

Quoralis ("we", "us", "our") operates as a provider of intelligent document processing solutions for legal and financial sectors in Singapore. We collect and process personal data as necessary to deliver our services, maintain client relationships, and fulfil legal obligations.

This policy applies to personal data collected through our website, client engagements, and business communications. By using our services or providing us with personal data, you consent to the collection and use of information in accordance with this policy.

If you have questions about this Privacy Policy or our data practices, please contact us at [email protected].

2. Data We Collect

We collect personal data that you provide directly and data generated through your use of our services:

Personal Information You Provide:

  • Name, email address, and phone number when you contact us or request services
  • Company name, job title, and business address for client engagements
  • Payment and billing information for service delivery
  • Communications content when you correspond with us
  • Document samples provided during assessment or implementation phases

Automatically Collected Information:

  • Website usage data through cookies and similar technologies
  • IP addresses, browser types, and device information
  • Pages viewed, time spent, and navigation patterns
  • Referral sources and search queries leading to our website

Service-Related Data:

  • Processing logs and performance metrics from deployed solutions
  • Document metadata and processing results (as contractually agreed)
  • Support interactions and technical assistance requests

3. How We Use Your Data

We process personal data for the following purposes, based on legitimate business interests, contractual necessity, or legal obligations:

  • Delivering document processing solutions and related services
  • Responding to enquiries, consultation requests, and support needs
  • Processing service agreements, invoices, and payments
  • Improving our solutions through performance analysis and model refinement
  • Communicating service updates, technical notices, and security alerts
  • Conducting business operations, including administration and record-keeping
  • Complying with legal requirements and regulatory obligations
  • Protecting against fraud, security breaches, and unauthorised access

4. Legal Basis for Processing

Our processing of personal data is based on:

  • Consent: Where you have provided explicit consent for specific processing activities
  • Contract Performance: Where processing is necessary to deliver services you have engaged us to provide
  • Legitimate Interests: Where processing serves our legitimate business interests in improving services, maintaining security, and conducting ordinary business operations
  • Legal Compliance: Where processing is required to fulfil regulatory obligations under Singapore law

5. Data Sharing and Disclosure

We do not sell personal data. We may share personal data with the following categories of recipients:

Service Providers:

Third-party vendors who assist with infrastructure hosting, payment processing, and business operations. These providers are contractually obligated to protect data confidentiality and security.

Legal Requirements:

Government authorities, regulators, or legal entities when required by law, court order, or to protect our legal rights and interests.

Business Transfers:

In the event of merger, acquisition, or sale of assets, personal data may be transferred to the successor entity, subject to equivalent privacy protections.

6. Data Security

We implement technical and organisational measures to protect personal data against unauthorised access, loss, or misuse:

  • Encryption of data in transit and at rest using industry-standard protocols
  • Role-based access controls limiting data access to authorised personnel
  • Regular security assessments and vulnerability testing
  • Secure infrastructure hosted with reputable service providers
  • Employee training on data protection and confidentiality obligations
  • Incident response procedures for breach notification and remediation

While we maintain robust security measures, no system is entirely immune to security risks. We cannot guarantee absolute security but commit to promptly addressing any identified vulnerabilities.

7. Data Retention

We retain personal data for as long as necessary to fulfil the purposes outlined in this policy, unless longer retention is required by law:

  • Client data during active service engagement and for six years following contract completion
  • Financial records for seven years in accordance with Singapore tax regulations
  • Communication records for two years after last contact
  • Website analytics data for two years from collection
  • Processing logs and performance metrics as contractually specified with clients

Upon expiry of retention periods, we securely delete or anonymise personal data to prevent identification.

8. Cookies and Tracking Technologies

Our website uses cookies and similar technologies to enhance functionality and analyse usage patterns. For detailed information about cookie types, purposes, and management options, please refer to our Cookie Policy.

9. Your Rights

Under Singapore's Personal Data Protection Act, you have the following rights regarding your personal data:

Access:

Request confirmation of whether we hold your personal data and obtain copies of such data.

Correction:

Request correction of inaccurate or incomplete personal data.

Withdrawal of Consent:

Withdraw consent for processing based on consent, though this may affect our ability to provide certain services.

Objection:

Object to processing based on legitimate interests, subject to our assessment of overriding grounds.

To exercise these rights, contact us at [email protected]. We will respond to requests within 30 days and may require identity verification before processing.

10. International Data Transfers

Our primary operations are based in Singapore. If personal data is transferred outside Singapore, we ensure adequate safeguards through contractual clauses, certification schemes, or other mechanisms approved under the PDPA. Service providers processing data outside Singapore are required to maintain equivalent data protection standards.

11. Third-Party Links

Our website may contain links to third-party websites or services. We are not responsible for the privacy practices of these external sites. We recommend reviewing their privacy policies before providing personal information.

12. Updates to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices, legal requirements, or operational needs. Material changes will be communicated through prominent notice on our website or direct notification to clients. Continued use of our services after policy updates constitutes acceptance of the revised terms.

13. Contact Information

For questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact:

Email: [email protected]

Address: 6 Battery Road, #14-06, Singapore 049909

Phone: +65 6831 4267

14. Regulatory Authority

If you believe we have not addressed your data protection concerns adequately, you have the right to lodge a complaint with Singapore's Personal Data Protection Commission (PDPC). Information about filing complaints can be found at www.pdpc.gov.sg.