Privacy Policy

Privacy Policy

This Privacy Notice explains what personal data we collect, how we use it, who we share it with, how long we keep it, and what rights you have over it. We recommend you read it carefully.

This notice applies to personal data we collect through our websites and through use of the Sovablu platform.


Who we are

Sovablu is an enterprise no-code platform owned and provided by S2K2 Holdings Pte. Ltd., a company established in Singapore under the laws of Singapore, with its registered office at Level 39 Marina Bay Financial Centre Tower 2, 10 Marina Boulevard, Singapore 018983. In this notice, “we”, “us” and “our” refer to S2K2 Holdings Pte. Ltd., which is the controller of the personal data described below. “Sovablu” refers to the platform.

Sovablu株式会社 (Sovablu KK), our Japanese subsidiary, operates www.sovablu.co.jp and provides Sovablu in Japan. Personal data collected through that site is governed by the privacy policy published there.

For any question about personal data, privacy or security, contact us at [email protected] or write to the postal address above.


Scope

This notice covers personal data collected through:

  • www.sovablu.com and any other site from which you access this notice
  • Our official accounts on LinkedIn, X, Facebook, Instagram, YouTube and Mastodon
  • Email messages and surveys we send that link to this notice
  • Your use of the Sovablu platform
  • Events, exhibitions and webinars we host or attend

Personal data collected through www.sovablu.co.jp is covered by the privacy policy on that site, which is written to Japanese law.


Personal data we collect

You can browse our website without telling us who you are. There are points where we need personal data from you.

Information you give us Name, business email address, company name, job title, telephone number, company website, and the content of your enquiry.

Information from your use of the platform Account details, platform activity and usage statistics, and the content of support requests you submit.

Information collected automatically IP address, date and time of access, referring website, device type, and the pages you view and actions you take on our sites.

Information from other sources Marketing partners, social media platforms, talent acquisition partners, publicly available sources, and data enrichment services.

If you give us personal data about another person, you confirm you have the authority to do so and to permit us to use it as described here.


How we collect personal data

  • When you contact us. We collect the details you provide and your contact information so we can respond. This includes applications for employment.
  • When you subscribe to updates. We collect your email address and country.
  • When you submit a support request. We collect your email address and the details of the issue. We recommend you do not include production data, confidential information or personal data belonging to others in screenshots or attachments.
  • When you visit our sites. We collect the technical information described above.
  • When you use the Sovablu platform. We collect account details and usage statistics.
  • When you register for a webinar, event or training session. We collect the registration details requested at sign-up.
  • Offline. At events and exhibitions we may collect your details by scanning your badge or through conversation with our team.

How we use personal data

We use personal data only where we have a legal basis to do so: to perform a contract with you or your employer, with your consent, where it is necessary for our legitimate interests and those interests are not overridden by your rights, or to meet a legal obligation.

We use personal data to:

  • Provide access to the Sovablu platform and authenticate your account
  • Provide the products, services and information you have requested
  • Respond to your enquiries and manage our relationship with you
  • Send administrative information, including changes to our terms and policies
  • Provide support, maintenance and issue resolution
  • Send marketing communications where you have asked to receive them or where we are otherwise permitted to
  • Run webinars, events and training sessions
  • Analyse use of our platform and services in order to improve them
  • Detect and prevent fraud and misuse, and carry out audits
  • Measure the effectiveness of our marketing and analyse our business activity
  • Assess applications for employment
  • Comply with applicable law, respond to lawful requests from public authorities, enforce our terms, and protect our rights, property and operations

Legitimate interests. Where we rely on legitimate interests, we have assessed that our interest is not overridden by your rights. This applies principally to product improvement, security and fraud prevention, and business-to-business marketing to professional contacts.


Sharing personal data

We do not sell personal data.

We share personal data in the following circumstances:

  • Service providers. We use other companies for website hosting, data analysis, IT infrastructure, customer support, email delivery, auditing and payment processing. They receive only the data needed to perform their function, under contractual confidentiality obligations.
  • Within our group. S2K2 Holdings Pte. Ltd. and its subsidiaries, including Sovablu株式会社 and Vaken Technologies Pvt. Ltd., may access personal data where necessary for group management, product development and service delivery, under equivalent safeguards.
  • Event partners. Where an event is co-hosted, we share registration data with the partners named on the registration page, for the purposes of that event only. If a partner intends to use your data for any other purpose, they will contact you separately.
  • Business transfers. In the event of a reorganisation, merger, sale, joint venture, assignment or transfer of all or part of our business or assets, personal data may be disclosed to the party involved.
  • Legal. Where we believe it is necessary under applicable law, to comply with legal process, to respond to requests from public authorities, to enforce our terms, or to protect our rights, property, safety and operations.

International transfers

We operate from Singapore with group entities in Japan and India, and Sovablu runs on Amazon Web Services. Personal data may therefore be transferred to and processed in countries other than the one you are in.

Where we transfer personal data internationally, we take steps to ensure it remains protected to the standard described in this notice.

For customer data held on the platform, the AWS region is selected according to your requirements. If you have data residency obligations, contact us and we will configure your deployment accordingly.


Security

We treat personal data as confidential and apply technical and organisational measures against loss and unlawful processing. These include role-based access control, encryption of data in transit and at rest, audit logging, continuous monitoring, and independent vulnerability assessment and penetration testing in line with OWASP standards.

No transmission or storage system can be guaranteed completely secure. If you believe your interaction with us is no longer secure, contact us immediately.


Cookies

Cookies are small files stored on your device that distinguish you from other users. By default only strictly necessary cookies are active, and these do not collect information that identifies you. Analytics and advertising cookies are set only where you choose them through the consent banner on your first visit. You can change your choices at any time.


Your rights

You may ask us to:

  • Give you access to the personal data we hold about you
  • Correct personal data that is inaccurate or incomplete
  • Delete personal data we hold about you
  • Restrict how we process your personal data
  • Object to processing we carry out on the basis of legitimate interests
  • Provide your personal data in a portable format
  • Stop sending you marketing communications

To exercise any of these, contact us at [email protected]. Please tell us what you are asking for.

Identity verification. To protect you against impersonation, we will verify your identity before acting on a request. We will generally only act on requests made from the email address already associated with the data.

Timeframe. We will respond as soon as reasonably practicable.

Retained data. We may need to keep certain information to meet legal or record-keeping obligations. Some residual data may remain in backups and archives and cannot be removed immediately.

To stop receiving our newsletter or updates, use the unsubscribe link at the bottom of any such email.


Data storage, retention and deletion

Purpose. We collect, store, archive and delete customer data only to fulfil our contractual obligations, provide support, and comply with applicable law.

Minimisation. We collect only the data needed for those purposes.

Access control. Access to customer data is restricted to authorised personnel with a legitimate need.

Encryption. Customer data is encrypted in transit and at rest using industry-standard methods.

Retention. Customer data is retained only for as long as needed for the purpose it was collected, as set out in the agreement with the customer, or as required by law.

Storage. Customer data is stored securely in line with industry practice and applicable law.

Deletion requests. Customers may request deletion of their data at any time. We process such requests within a reasonable timeframe, subject to any legal obligation requiring retention.

Destruction. When the retention period expires or a deletion request is completed, data is securely destroyed using industry-standard methods so that it cannot be recovered.

Archival. Data no longer required for contractual or legal purposes may be archived for record-keeping, stored securely with access restricted to authorised personnel.

Backup and recovery. We maintain regular backups and disaster recovery measures so that customer data can be restored following a system failure.

Breach notification. We notify customers of any data breach or unauthorised access affecting their data, as required by law.


Deletion request process

  1. Acknowledgement. We acknowledge deletion requests within three business days and give an estimated completion timeframe.
  2. Verification. We verify the identity of the requester, asking for additional information where necessary.
  3. Location. We identify all relevant data within our systems and flag it for deletion.
  4. Deletion. We securely delete the data using industry-standard methods.
  5. Confirmation. We confirm to you once deletion is complete.
  6. Follow-up. We check back after a reasonable period to confirm you are no longer receiving communications from our systems.

Links to other websites

Our sites may link to websites we do not operate. We are not responsible for their privacy practices or content, and a link does not imply endorsement. We suggest you read the privacy policy of any site you visit.


Changes to this notice

Our business and our sites change over time, and we may need to update this notice. We will publish any revised version on this page. Where a change is significant, we will say so clearly on the site. We recommend you review this notice periodically.