Skip to main content
FlowFn
IntegrationsTemplatesPricingDocsBlogSign inStart free
All legal documents

Legal & Compliance

PDPA Compliance Statement

Version1.0UpdatedJun 15, 2026Reading time8 min read

1. Introduction

This PDPA Compliance Statement explains how FLOW FN PTE. LTD. (UEN 202617303Z), a company incorporated in Singapore ("we", "us", or "our"), complies with the Singapore Personal Data Protection Act 2012 (No. 26 of 2012) and its subsidiary legislation (collectively, the "PDPA") when collecting, using, disclosing or otherwise processing personal data in or from Singapore. This statement supplements our Privacy Policy and forms part of our overall data protection commitments.

2. Our Commitment to the PDPA

We are committed to handling personal data responsibly and in accordance with the PDPA. We have implemented policies and practices, designated a Data Protection Officer (DPO), and put in place reasonable security arrangements to comply with the PDPA's Data Protection Provisions and Do Not Call (DNC) Provisions.

3. Consent Obligation

We collect, use or disclose your personal data only with your consent (express or deemed) or where the PDPA permits collection, use or disclosure without consent. Where consent is required, we will seek it before or at the time of collection. You may withdraw any consent given at any time by contacting our DPO at legal@flowfn.com or through the controls available in your account settings. On withdrawal, we will inform you of the likely consequences of withdrawal and cease the relevant collection, use or disclosure within a reasonable period, except where retention or processing is required or authorised by law.

4. Purpose Limitation Obligation

We collect, use and disclose your personal data only for purposes that a reasonable person would consider appropriate in the circumstances and that have been notified to you, or as otherwise permitted under the PDPA. Where we wish to use your personal data for a new purpose, we will obtain fresh consent unless an exception applies.

5. Notification Obligation

We will inform you of the purposes for which your personal data will be collected, used or disclosed on or before such collection, use or disclosure. The principal purposes are set out in our Privacy Policy and may be supplemented by service-specific notices at points of collection (for example, signup, billing, support and integration consent screens).

6. Access and Correction Obligation

Subject to the exceptions in the PDPA, you may request: (a) access to personal data we hold about you and information about how it has been or may have been used or disclosed within the past one year; and (b) correction of any error or omission in your personal data. Submit requests to legal@flowfn.com. We will respond within thirty (30) days. If we are unable to do so within that time, we will inform you of the time by which we will be able to respond. We may charge a reasonable fee for access requests as permitted by the PDPA.

7. Accuracy Obligation

We make reasonable efforts to ensure that personal data we collect is accurate and complete, particularly when the personal data is likely to be used to make a decision that affects you or to be disclosed to another organisation. You can keep your account information up to date through your account settings, or contact our Data Protection Officer at legal@flowfn.com to request corrections.

8. Protection Obligation

We make reasonable security arrangements to protect personal data in our possession or under our control from unauthorised access, collection, use, disclosure, copying, modification, disposal or similar risks. Measures include encryption in transit (TLS) and at rest for sensitive fields, access controls and authentication, role-based authorisation, monitoring and logging, vendor due diligence, and secure development practices. In line with the PDPC's Advisory Guidelines on the Personal Data Protection Act for NRIC and Other National Identification Numbers, customers must not collect, use, disclose or otherwise process Singapore NRIC, FIN, work-permit or birth-certificate numbers, or other special-category personal data, through the Service except where permitted under Section 11 of our Acceptable Use Policy.

9. Retention Limitation Obligation

We retain personal data only for as long as it is necessary to fulfil the purposes for which it was collected or as required or permitted by law. When personal data is no longer required for any business or legal purpose, we will cease to retain it or anonymise it. Account data is generally retained while your account is active and for up to thirty (30) days after deletion (longer where required by law or to address fraud, billing or security matters).

10. Transfer Limitation Obligation

Our production infrastructure is located in the United States East Coast (AWS US East / N. Virginia, us-east-1, DigitalOcean New York 3 (NYC3) for managed MongoDB, and Redis Cloud running on AWS us-east-1 for in-memory cache and background-job queue), and our other sub-processors (including DigitalOcean, Redis Ltd., Stripe, OpenAI and AWS Simple Email Service for transactional email) operate primarily in the United States. Personal data collected in or from Singapore is therefore routinely transferred to those jurisdictions in the ordinary course of providing the Service. We rely on Section 26 of the PDPA and the Personal Data Protection (Transfer of Personal Data Outside Singapore) Regulations 2014. Specifically, the transfer is supported by (a) legally enforceable contractual obligations binding each recipient to provide a standard of protection at least comparable to the PDPA — implemented through the AWS Service Terms / Data Processing Addendum (which covers AWS Simple Email Service), the DigitalOcean Data Processing Agreement, the Redis Cloud Data Processing Addendum, the Stripe Data Processing Agreement, and OpenAI's enterprise terms; and (b) the recipients' independent compliance certifications (including SOC 2, ISO 27001, ISO 27018 and PCI-DSS as applicable). For dual-track GDPR coverage we additionally apply the European Commission's Standard Contractual Clauses and the EU-US Data Privacy Framework where the recipient is self-certified. We have completed an internal Transfer Impact Assessment for the United States East Coast transfer (covering AWS us-east-1, DigitalOcean NYC3 and Redis Cloud) and refresh it on material change. A copy of the relevant transfer mechanisms can be requested from legal@flowfn.com. For clarity, re-assigning an app or item from one team to another within the Service (a "cross-team transfer" you initiate) is not a transfer of personal data outside Singapore for the purposes of this obligation — the data remains in the same production infrastructure and sub-processors; that re-assignment is a controller-to-controller disclosure governed by Section 11 of our Data Processing Agreement.

11. Openness Obligation and Data Protection Officer

We have designated a Data Protection Officer (DPO) under section 11 of the PDPA. The DPO can be contacted at legal@flowfn.com. The DPO is responsible for ensuring our compliance with the PDPA, including handling queries, complaints and access/correction requests. This statement and our Privacy Policy are made publicly available on our website.

12. Data Breach Notification Obligation

We have processes to assess and respond to data breaches. If we determine that a data breach is a notifiable data breach under section 26B of the PDPA (i.e. it results in, or is likely to result in, significant harm to affected individuals, or is of a significant scale of 500 or more individuals), we will: (a) notify the Personal Data Protection Commission (PDPC) as soon as practicable, and in any case no later than three (3) calendar days after we have assessed the breach to be notifiable; and (b) notify affected individuals where the breach is likely to result in significant harm to them, unless an exception in the PDPA applies. We maintain records of data breaches in accordance with the PDPC's guidance.

13. Accountability Obligation

We have implemented internal policies and practices to comply with our PDPA obligations. We train our personnel on data protection, conduct periodic reviews of our processing activities, and require our data intermediaries (sub-processors) to provide a standard of protection comparable to the PDPA. We make information about our data protection policies, practices and complaint process available on request to legal@flowfn.com.

14. Do Not Call (DNC) Provisions

We do not currently send marketing voice calls, text messages or fax messages to Singapore telephone numbers. If we begin sending such marketing messages in the future, we will check the relevant Do Not Call Registers maintained by the PDPC under Part IX of the PDPA and obtain clear and unambiguous consent in evidential form where required, or rely on the ongoing relationship exemption with a clear opt-out mechanism.

15. Withdrawal of Consent

You may withdraw consent for the collection, use or disclosure of your personal data at any time by contacting legal@flowfn.com or through your account settings. We will inform you of the likely consequences of withdrawal (which may include inability to provide certain features or the Service in whole or in part) and will give effect to the withdrawal within a reasonable period, except where continued processing is required or authorised by law.

16. Submitting Complaints

If you believe that we have not handled your personal data in accordance with the PDPA, please contact our DPO at legal@flowfn.com. We will investigate and respond within thirty (30) days. If you are not satisfied with our response, you have the right to lodge a complaint with the PDPC at www.pdpc.gov.sg.

17. Children's Personal Data

Our Service is restricted to individuals aged 18 or older. We require every prospective user to affirmatively confirm at signup that they are at least 18; we record only that boolean attestation and do not collect date of birth or other age-proof documents, applying PDPA s.18 (purpose limitation) and the data-minimisation principle. Because we do not offer the Service to minors, the PDPA's restrictions on minors' personal data (including the requirement for parental consent for individuals under 13) are addressed by exclusion. If you become aware that someone under 18 has created an account, please contact legal@flowfn.com and we will delete the account and associated personal data as soon as practicable.

18. Changes to This Statement

We may update this PDPA Compliance Statement to reflect changes in our practices or in applicable law. The "updated_at" date indicates when this statement was last revised. Material changes will be notified via email or through the Service.

19. Contact Information

For PDPA-related queries, access or correction requests, withdrawal of consent, or to contact our Data Protection Officer designated under section 11 of the PDPA, please email legal@flowfn.com. For general support, visit https://www.flowfn.com/dashboard/support.

Questions about this document?

legal@flowfn.com
Submit a data request →