PRIVACY · PDPA · SINGAPORE
Privacy Policy
How EngageForge Pte. Ltd. collects, uses, discloses, and protects personal data in accordance with the Personal Data Protection Act 2012 (PDPA) of Singapore.
Document version: 26 June 2026
Chapter I — Data steward and scope
I.1 Who is responsible
EngageForge Pte. Ltd. (Unique Entity Number 202715928M), registered at 2 Science Park Drive, #01-08 Ascent, Singapore 118222, operates the website https://engageforge.life and delivers audience engagement, community programme design, and social activation services for commercial brands ("EngageForge", "we", "us", or "our"). For the purposes of the Personal Data Protection Act 2012 (PDPA) of Singapore, EngageForge is the organisation responsible for personal data described in this Privacy Policy.
I.2 Who this policy applies to
This Privacy Policy applies to individuals who visit engageforge.life, submit enquiries through our contact form at engageforge.life/contact.php, communicate with us by email or telephone, attend forge sessions at our Science Park studio, or engage us for marketing agency services. It explains what personal data we collect, how we use and disclose it, how long we retain it, and the choices available to you under Singapore law.
This policy does not govern third-party websites, social platforms, or services linked from our Site. External properties operate under their own privacy practices. We encourage you to review their policies before submitting personal data elsewhere. EngageForge is a marketing agency — not a wellness platform, life coaching practice, or dating service — and this policy covers data processed in that commercial context only.
I.3 Consent and notification
Where the PDPA requires consent, we obtain it through explicit mechanisms such as unchecked consent checkboxes on our contact form. By using the Site or submitting personal data to us, you acknowledge that you have read this Privacy Policy. We notify individuals of the purposes for which personal data is collected at or before the point of collection, to the extent practicable.
Chapter II — Personal data categories
II.1 Data you provide directly
When you interact with EngageForge, you may provide personal data including:
- Identity and contact data: full name, job title, company name, email address, telephone number, and postal address
- Enquiry content: messages submitted via contact.php, email correspondence, and notes from telephone calls or in-person meetings
- Engagement preferences: stated interest in specific programmes, services, or engagement tracks
- Consent records: timestamps and affirmative indications of PDPA consent and, where applicable, marketing communication preferences
II.2 Data collected during client engagements
When you become a client, additional categories may include billing contact details, project briefs, brand assets, stakeholder contact lists, community moderation logs shared for programme design, campaign performance data, and contractual correspondence. These categories are governed by service agreements and may involve stricter confidentiality obligations than website enquiries.
II.3 Technical and usage data
When you browse engageforge.life, we may automatically collect technical data including IP address, browser type and version, device identifiers, operating system, pages visited, time spent on pages, referral URLs, and cookie consent preferences stored in local storage. See our Cookie Policy for details on cookies and similar technologies.
II.4 Sensitive data
We do not intentionally collect sensitive personal data — such as NRIC numbers, financial account credentials, health records, or biometric identifiers — through the Site contact form. If sensitive data is inadvertently included in a free-text message, we will delete it where practicable unless retention is required by law or necessary for a legitimate business purpose disclosed at collection.
Chapter III — Purposes of use
III.1 Primary purposes
EngageForge collects and uses personal data for purposes that a reasonable person would consider appropriate in the circumstances, including:
- Responding to enquiries submitted through contact.php, email, or telephone
- Scheduling and conducting forge sessions, community audits, and client briefings at our Science Park studio or via video conference
- Preparing proposals, quotations, and service agreements for engagement programmes and studio services
- Delivering contracted audience engagement, community programme, and social activation services
- Invoicing, payment processing, and accounts receivable management for client engagements
- Maintaining internal records of communications, project history, and service delivery
- Complying with legal, regulatory, and tax obligations applicable in Singapore
III.2 Secondary purposes
With your consent or where permitted under the PDPA, we may also use personal data to:
- Send informational updates about EngageForge programmes, services, or studio events relevant to your stated interests
- Improve engageforge.life functionality and content based on aggregated usage patterns
- Conduct internal quality reviews and staff training using anonymised or redacted enquiry examples
You may withdraw consent for marketing communications at any time by emailing [email protected]. Withdrawal does not affect the lawfulness of processing before withdrawal or processing based on other legal grounds.
III.3 Purpose limitation
We do not use personal data collected for enquiry response to make automated decisions producing legal or similarly significant effects. We do not sell personal data to third parties for their independent marketing purposes.
Chapter IV — Disclosure and processors
IV.1 Categories of recipients
EngageForge may disclose personal data to:
- Service providers: email hosting, cloud storage, analytics platforms (where consented), payment processors, and professional advisers bound by confidentiality obligations
- Platform partners: social and advertising platforms where client campaigns require audience data handling under separate platform terms
- Legal authorities: regulators, courts, or law enforcement when required by applicable law or to protect rights, safety, and property
- Corporate transactions: acquirers or successors in the event of merger, acquisition, or asset sale, subject to continued protection consistent with this policy
IV.2 Data processors
Where we engage third-party processors to handle personal data on our behalf, we require contractual terms imposing PDPA-equivalent protection obligations, limiting processing to documented instructions, and requiring deletion or return of data upon contract termination where practicable.
IV.3 No unauthorised disclosure
We do not disclose personal data to unrelated third parties for their own marketing without your consent. Case notes or portfolio examples published on engageforge.life use anonymised or aggregated information unless you have agreed otherwise in writing.
Chapter V — Retention and security
V.1 Retention periods
We retain personal data only as long as necessary for the purposes described in this policy or as required by law. Indicative retention periods include:
- Enquiry records: up to twenty-four months from last meaningful contact unless a client relationship develops
- Client engagement records: duration of contract plus seven years for legal, tax, and dispute resolution purposes
- Cookie consent preferences: up to six months in local storage, after which we request consent again
- Server logs: up to twelve months unless required for security investigations
When retention periods expire, we delete or anonymise personal data using methods appropriate to the storage medium.
V.2 Security measures
EngageForge implements reasonable administrative, technical, and physical safeguards to protect personal data against unauthorised access, collection, use, disclosure, copying, modification, disposal, or similar risks. Measures include access controls limiting staff access to data required for their role, encrypted transmission where supported, secure storage for client materials, and staff awareness of PDPA obligations.
No method of electronic transmission or storage is completely secure. While we strive to protect personal data, we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of credentials associated with any client portal or shared workspace we provide.
V.3 Data breach response
In the event of a data breach posing significant harm, we will assess notification obligations under the PDPA and, where required, notify the Personal Data Protection Commission (PDPC) and affected individuals without undue delay.
Chapter VI — Your rights under PDPA
VI.1 Access and correction
You may request access to personal data we hold about you and request correction of inaccurate or incomplete data. Submit requests to [email protected] with sufficient information to verify your identity. We respond within thirty days or inform you if an extension is required under the PDPA.
VI.2 Withdrawal of consent
Where processing is based on consent, you may withdraw consent by contacting [email protected]. Withdrawal may limit our ability to respond to ongoing enquiries or deliver services requiring the withdrawn data category.
VI.3 Complaints
If you believe EngageForge has not handled your personal data in accordance with the PDPA, contact us first at [email protected] to seek resolution. Unresolved concerns may be referred to the Personal Data Protection Commission (PDPC) of Singapore.
VI.4 Do Not Call Registry
Where we send marketing messages to Singapore telephone numbers, we check against the Do Not Call Registry unless an exception applies under the PDPA. Email marketing includes unsubscribe mechanisms where applicable.
Chapter VII — Cross-border transfers
VII.1 Transfer circumstances
Personal data may be transferred outside Singapore when we use cloud service providers, video conferencing platforms, email services, or analytics tools with servers located abroad. Transfers occur only where the recipient jurisdiction provides a comparable standard of protection, or where we implement appropriate safeguards such as contractual clauses requiring PDPA-equivalent obligations.
VII.2 Your acknowledgement
By submitting personal data to EngageForge, you acknowledge that cross-border transfers may occur for the purposes described in this policy. You may request additional information about safeguards applied to specific transfers by contacting [email protected].
Chapter VIII — Updates and contact
VIII.1 Policy updates
We may update this Privacy Policy to reflect changes in our practices, services, or legal requirements. The document version date at the top of this page indicates when the policy was last revised. Material changes will be communicated through a notice on engageforge.life or direct communication where appropriate. Continued use of the Site after updates constitutes acknowledgement of the revised policy.
VIII.2 Contact details
For privacy enquiries, access or correction requests, consent withdrawal, or questions about this policy:
EngageForge Pte. Ltd.
Privacy contact: [email protected]
General enquiries: [email protected]
Address: 2 Science Park Drive, #01-08 Ascent, Singapore 118222
Telephone: +65 6955 8472
VIII.3 Related documents
This Privacy Policy should be read alongside our Cookie Policy, Terms of Use, and Legal Information page.