This Privacy Notice explains what personal data we collect, how we use it, who we share it with, how long we keep it, and what rights you have over it. We recommend you read it carefully.
This notice applies to personal data we collect through our websites and through use of the Sovablu platform.
Sovablu is an enterprise no-code platform owned and provided by S2K2 Holdings Pte. Ltd., a company established in Singapore under the laws of Singapore, with its registered office at Level 39 Marina Bay Financial Centre Tower 2, 10 Marina Boulevard, Singapore 018983. In this notice, “we”, “us” and “our” refer to S2K2 Holdings Pte. Ltd., which is the controller of the personal data described below. “Sovablu” refers to the platform.
Sovablu株式会社 (Sovablu KK), our Japanese subsidiary, operates www.sovablu.co.jp and provides Sovablu in Japan. Personal data collected through that site is governed by the privacy policy published there.
For any question about personal data, privacy or security, contact us at [email protected] or write to the postal address above.
This notice covers personal data collected through:
Personal data collected through www.sovablu.co.jp is covered by the privacy policy on that site, which is written to Japanese law.
You can browse our website without telling us who you are. There are points where we need personal data from you.
Information you give us Name, business email address, company name, job title, telephone number, company website, and the content of your enquiry.
Information from your use of the platform Account details, platform activity and usage statistics, and the content of support requests you submit.
Information collected automatically IP address, date and time of access, referring website, device type, and the pages you view and actions you take on our sites.
Information from other sources Marketing partners, social media platforms, talent acquisition partners, publicly available sources, and data enrichment services.
If you give us personal data about another person, you confirm you have the authority to do so and to permit us to use it as described here.
We use personal data only where we have a legal basis to do so: to perform a contract with you or your employer, with your consent, where it is necessary for our legitimate interests and those interests are not overridden by your rights, or to meet a legal obligation.
We use personal data to:
Legitimate interests. Where we rely on legitimate interests, we have assessed that our interest is not overridden by your rights. This applies principally to product improvement, security and fraud prevention, and business-to-business marketing to professional contacts.
We do not sell personal data.
We share personal data in the following circumstances:
We operate from Singapore with group entities in Japan and India, and Sovablu runs on Amazon Web Services. Personal data may therefore be transferred to and processed in countries other than the one you are in.
Where we transfer personal data internationally, we take steps to ensure it remains protected to the standard described in this notice.
For customer data held on the platform, the AWS region is selected according to your requirements. If you have data residency obligations, contact us and we will configure your deployment accordingly.
We treat personal data as confidential and apply technical and organisational measures against loss and unlawful processing. These include role-based access control, encryption of data in transit and at rest, audit logging, continuous monitoring, and independent vulnerability assessment and penetration testing in line with OWASP standards.
No transmission or storage system can be guaranteed completely secure. If you believe your interaction with us is no longer secure, contact us immediately.
Cookies are small files stored on your device that distinguish you from other users. By default only strictly necessary cookies are active, and these do not collect information that identifies you. Analytics and advertising cookies are set only where you choose them through the consent banner on your first visit. You can change your choices at any time.
You may ask us to:
To exercise any of these, contact us at [email protected]. Please tell us what you are asking for.
Identity verification. To protect you against impersonation, we will verify your identity before acting on a request. We will generally only act on requests made from the email address already associated with the data.
Timeframe. We will respond as soon as reasonably practicable.
Retained data. We may need to keep certain information to meet legal or record-keeping obligations. Some residual data may remain in backups and archives and cannot be removed immediately.
To stop receiving our newsletter or updates, use the unsubscribe link at the bottom of any such email.
Purpose. We collect, store, archive and delete customer data only to fulfil our contractual obligations, provide support, and comply with applicable law.
Minimisation. We collect only the data needed for those purposes.
Access control. Access to customer data is restricted to authorised personnel with a legitimate need.
Encryption. Customer data is encrypted in transit and at rest using industry-standard methods.
Retention. Customer data is retained only for as long as needed for the purpose it was collected, as set out in the agreement with the customer, or as required by law.
Storage. Customer data is stored securely in line with industry practice and applicable law.
Deletion requests. Customers may request deletion of their data at any time. We process such requests within a reasonable timeframe, subject to any legal obligation requiring retention.
Destruction. When the retention period expires or a deletion request is completed, data is securely destroyed using industry-standard methods so that it cannot be recovered.
Archival. Data no longer required for contractual or legal purposes may be archived for record-keeping, stored securely with access restricted to authorised personnel.
Backup and recovery. We maintain regular backups and disaster recovery measures so that customer data can be restored following a system failure.
Breach notification. We notify customers of any data breach or unauthorised access affecting their data, as required by law.
Our sites may link to websites we do not operate. We are not responsible for their privacy practices or content, and a link does not imply endorsement. We suggest you read the privacy policy of any site you visit.
Our business and our sites change over time, and we may need to update this notice. We will publish any revised version on this page. Where a change is significant, we will say so clearly on the site. We recommend you review this notice periodically.