1. Introduction
Nuvexia (“Nuvexia”, “we”, “us”, or “our”) respects the privacy of individuals and is committed to protecting personal data entrusted to us.
This Privacy Policy explains how Nuvexia collects, uses, discloses, stores, protects and otherwise processes personal data in connection with our website, communications, consulting services, AI governance and compliance services, AI infrastructure and engineering services, AI security services, AIOps and Cloud FinOps services, data analysis and visualisation services, process automation, implementation services and related solutions.
Nuvexia is committed to responsible, ethical and sustainable use of technology and artificial intelligence. We seek to apply principles of privacy, security, transparency, accountability, fairness, proportionality and responsible innovation throughout our activities.
This Policy is intended to address applicable obligations under the Singapore Personal Data Protection Act 2012 (“PDPA”) and, where applicable, the European Union General Data Protection Regulation (“GDPR”) and other applicable data-protection laws.
The application of the GDPR depends on the circumstances and territorial scope of the processing. Nothing in this Policy constitutes a representation that the GDPR applies to every individual or every processing activity carried out by Nuvexia.
2. Who We Are
For purposes of this Policy, “Nuvexia” refers to the Nuvexia business operating the relevant website and services.
- Jurisdiction
- Singapore
- Registered address
- 60, Paya Lebar, Singapore
- Privacy contact
- DPO · connect@nuvexiaai.com
Where a particular service is provided by a specific Nuvexia group entity, affiliate, contractor or other legal entity, the applicable contract or service documentation may identify that entity separately.
3. Personal Data We May Collect
Depending on how you interact with Nuvexia, we may collect information such as:
- Name and contact details, including email address, telephone number and business contact information.
- Company, organisation, job title and professional information.
- Information provided when submitting enquiries, booking consultations or requesting services.
- Information contained in communications with Nuvexia.
- Information necessary to evaluate, scope, deliver and support a project or engagement.
- Account, authentication or access information where applicable.
- Technical information such as IP address, browser type, device information, operating system and information relating to use of our website.
- Information contained in files, datasets, documents or other materials that a client voluntarily provides to us for an agreed service.
- Billing, transaction and contractual information where applicable.
- Information required to comply with legal, regulatory, accounting, audit, security or fraud-prevention requirements.
We seek to collect only information that is reasonably necessary for the relevant purpose.
4. Information You Provide to Us
You may provide personal data when you:
- Contact us.
- Request a consultation or proposal.
- Enter into a contract or statement of work.
- Participate in a project.
- Provide information for analysis, implementation, testing or support.
- Subscribe to communications where offered.
- Communicate with our personnel.
- Use features of our website or services.
You should not provide Nuvexia with sensitive, confidential or regulated personal data unless doing so is necessary for an agreed service and appropriate contractual, technical and organisational safeguards have been established.
Where you provide personal data relating to another individual, you represent that you are authorised to provide that information and that any required notices or permissions have been appropriately addressed.
5. How We Use Personal Data
Subject to applicable law, Nuvexia may process personal data for purposes including:
- Responding to enquiries and requests.
- Providing, managing and supporting contracted services.
- Preparing proposals, statements of work and project documentation.
- Performing AI governance, AI security, data analysis, engineering, automation, infrastructure and related consulting activities.
- Communicating with clients and prospective clients.
- Managing business relationships.
- Processing payments and maintaining financial records.
- Maintaining website and information-security operations.
- Detecting, preventing and investigating fraud, abuse, security incidents and unlawful activity.
- Maintaining business continuity and operational resilience.
- Meeting legal, regulatory and contractual obligations.
- Improving our processes, services and internal operations where permitted by applicable law.
- Establishing, exercising or defending legal claims.
We will not use personal data for a new purpose that is incompatible with the purpose for which it was collected unless permitted or required by applicable law or otherwise appropriately authorised.
6. We Do Not Sell Personal Data
Nuvexia does not sell personal data to third parties for monetary consideration or for third-party advertising purposes.
We may, however, disclose or make personal data available where reasonably necessary to provide services, operate our business, comply with law, protect our rights or use service providers acting on our behalf.
Examples may include:
- Technology and cloud-service providers.
- Hosting, infrastructure and security providers.
- Professional advisers.
- Payment and accounting providers.
- Communications providers.
- Contractors or subcontractors involved in delivering contracted services.
- Government authorities, regulators, courts or law-enforcement bodies where required or permitted by law.
- A purchaser, investor, successor or other transaction participant in connection with a corporate transaction, subject to applicable law.
Such disclosures do not constitute a sale of your personal data.
7. AI Services and Client Data
Nuvexia may provide services involving artificial intelligence, machine learning, data analytics, automation, cloud infrastructure, security or related technologies.
Unless expressly agreed otherwise in writing, client data supplied to Nuvexia for a particular engagement is processed for the purpose of delivering that engagement and related contractual, security and operational purposes.
Nuvexia will not knowingly use confidential client information to train a publicly available AI model for unrelated third-party purposes without appropriate authorisation or another lawful basis.
Where third-party AI, cloud or technology providers are required to deliver a service, processing may be subject to the applicable provider's contractual and technical arrangements.
Clients remain responsible for ensuring that they have appropriate rights, permissions and lawful bases to provide personal data, confidential information, datasets or other materials to Nuvexia.
8. Legal Bases Where the GDPR Applies
Where the GDPR applies, Nuvexia may rely on one or more lawful bases for processing, depending on the circumstances, including:
- Performance of a contract.
- Taking steps at the request of an individual prior to entering into a contract.
- Compliance with a legal obligation.
- Legitimate interests, where those interests are not overridden by applicable rights and interests.
- Consent, where consent is required or appropriate.
- Protection of vital interests where legally applicable.
The applicable legal basis depends on the specific processing activity.
Where processing is based on consent, consent may generally be withdrawn subject to applicable law. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
9. Singapore PDPA
Where the Singapore PDPA applies, Nuvexia will handle personal data in accordance with applicable PDPA requirements, including requirements concerning notification and appropriate consent, purpose limitation, access and correction, protection, retention limitation and transfer limitation.
We will take reasonable steps appropriate to the circumstances to protect personal data in our possession or control from unauthorised access, collection, use, disclosure, copying, modification, disposal or similar risks.
10. International Data Transfers
Nuvexia may use service providers or infrastructure located outside Singapore or outside the country in which an individual is located.
Where personal data is transferred across borders, Nuvexia will take steps required by applicable law to ensure an appropriate level of protection.
Where the Singapore PDPA applies, Nuvexia will comply with applicable transfer limitation requirements.
Where the GDPR applies, Nuvexia will use an appropriate transfer mechanism where required, which may include an adequacy decision, appropriate safeguards such as Standard Contractual Clauses, or another lawful mechanism recognised by applicable data-protection law.
11. Data Retention
Nuvexia retains personal data only for as long as reasonably necessary for the purposes for which it was collected or processed, including contractual, legal, regulatory, accounting, security and dispute-resolution requirements.
Retention periods may vary depending on:
- The nature of the information.
- The purpose of processing.
- The contractual relationship.
- Legal or regulatory requirements.
- Security and audit requirements.
- The establishment, exercise or defence of legal claims.
When personal data is no longer reasonably required, Nuvexia will take appropriate steps to delete, anonymise or otherwise dispose of it, subject to applicable law and legitimate retention requirements.
12. Security
Nuvexia seeks to maintain reasonable technical and organisational safeguards appropriate to the nature and risks associated with personal data.
Depending on the circumstances, safeguards may include access controls, authentication, encryption, secure infrastructure, monitoring, backups, contractual controls, personnel confidentiality requirements and incident-management procedures.
No internet transmission, information system or electronic storage system can be guaranteed to be completely secure.
Accordingly, while Nuvexia takes reasonable measures to protect information, Nuvexia does not warrant that security will be absolute or that unauthorised access, loss, alteration or disclosure can never occur.
13. Data Breaches and Security Incidents
Where required by applicable law, Nuvexia will assess and respond to personal-data breaches and make notifications to affected individuals, regulators or other parties within the legally applicable timeframe.
Clients are responsible for promptly informing Nuvexia of any suspected compromise involving credentials, systems, datasets or information supplied to Nuvexia where such information may assist Nuvexia in mitigating the incident.
14. Your Rights
Depending on applicable law and the circumstances, individuals may have rights including:
- Requesting access to personal data.
- Requesting correction of inaccurate or incomplete personal data.
- Requesting deletion or erasure where legally applicable.
- Requesting restriction of processing where legally applicable.
- Objecting to certain processing.
- Requesting portability of certain personal data where applicable.
- Withdrawing consent where processing is based on consent.
- Lodging a complaint with an applicable data-protection authority.
These rights are not absolute and may be subject to statutory exceptions, exemptions, verification requirements and other legal limitations.
15. Singapore Access and Correction Requests
Individuals may contact Nuvexia using the privacy contact details below to request access to or correction of personal data, subject to applicable PDPA requirements and exceptions.
Nuvexia may take reasonable steps to verify the identity of the requester before responding.
We may also charge a reasonable fee where permitted by applicable law and where necessary to cover costs associated with responding to an access request.
16. GDPR Requests
Where the GDPR applies, individuals may exercise applicable GDPR rights by contacting Nuvexia using the privacy contact details below.
Nuvexia will respond within the period required by applicable law, subject to permitted extensions, identity verification requirements and lawful grounds for refusing or limiting a request.
Where an individual believes that processing infringes applicable data-protection law, that individual may also have the right to lodge a complaint with the competent supervisory authority.
18. Children
Our services are primarily intended for businesses, organisations and professional users.
Nuvexia does not knowingly seek to collect personal data from children where such collection is prohibited by applicable law.
If you believe that a child has provided personal data to Nuvexia contrary to applicable requirements, please contact us.
19. Third-Party Websites and Services
Our website may contain links to third-party websites, applications or services.
Nuvexia is not responsible for the privacy practices, security, content or policies of third parties that we do not control.
Users should review the privacy policies applicable to those third-party services before providing personal data.
20. Business and Client Responsibilities
Where Nuvexia processes personal data on behalf of a client, the allocation of responsibilities between Nuvexia and the client may be further defined in the applicable agreement, statement of work or data-processing agreement.
Clients remain responsible for determining the lawful basis for collecting personal data from their personnel, customers or other data subjects and for providing required notices and obtaining required permissions.
Where appropriate, Nuvexia may act as a processor or service provider on behalf of a client rather than as an independent controller.
21. Ethical and Responsible Technology Principles
Nuvexia seeks to conduct its activities according to principles of:
- Responsible and lawful use of AI.
- Privacy and data protection by design.
- Appropriate security and risk management.
- Transparency and accountability.
- Fairness and avoidance of unjustified discrimination.
- Human oversight of consequential decisions.
- Respect for intellectual property and confidentiality.
- Responsible sourcing and technology use.
- Social responsibility.
- Environmental awareness and sustainable technology practices.
These principles describe Nuvexia's intended approach and do not constitute a guarantee that every outcome of an AI system or third-party technology will be free from error, bias, security risk or environmental impact.
22. No Absolute Security or Privacy Guarantee
To the maximum extent permitted by applicable law, Nuvexia does not guarantee that:
- The website will always be available or uninterrupted.
- Any system will be completely free from vulnerabilities.
- Personal data can never be accessed by an unauthorised party.
- Third-party infrastructure or services will never experience a security incident.
- Every AI-generated or automated output will be accurate, complete, unbiased or suitable for a particular purpose.
Nothing in this Policy excludes or limits any liability or right that cannot lawfully be excluded or limited.
23. Changes to This Policy
Nuvexia may update this Privacy Policy from time to time to reflect changes in our services, technology, legal requirements or privacy practices.
The updated version will be published through an appropriate channel and will identify its effective or updated date.
Where applicable law requires notification or consent for a material change, Nuvexia will take the required steps.
24. Contact
For privacy questions, requests or complaints, please contact:
Nuvexia — Privacy Contact: DPO
Registered Address: 60, Paya Lebar, Singapore
Email: connect@nuvexiaai.com
Important
Please do not send passwords, payment-card details or highly sensitive information through ordinary email unless specifically requested through a secure channel.
25. Governing Law
Unless otherwise required by applicable data-protection law, this Privacy Policy is governed by the laws of Singapore.
Nothing in this section is intended to remove rights or protections that cannot lawfully be excluded under the mandatory laws applicable to an individual.
END OF PRIVACY POLICY