This Privacy and Data Use Notice explains how ZETTA SOLUTION PTE. LTD, UEN 201206718K, collects, uses, discloses, stores and protects Personal Data in connection with FluxonSys, our websites, applications, customer relationships, advertisements, analytics, platform insights and related services.
In this Notice, "we", "us" and "our" refer to ZETTA SOLUTION PTE. LTD.
1. Scope
This Notice applies to Personal Data relating to:
- prospective customers;
- customers and their representatives;
- Account administrators and Authorised Users;
- website and application visitors;
- business partners and suppliers;
- sales and support contacts;
- recipients of marketing communications; and
- other individuals who interact with us.
Where a Customer enters Personal Data concerning its employees, customers, suppliers or other individuals into the Services, the Customer generally determines why and how that Personal Data is used. In such circumstances, we generally process the Personal Data on behalf of the Customer.
2. Personal Data we may collect
Depending on the interaction, we may collect the following types of Personal Data.
2.1 Identity and Account information
- name;
- job title;
- company name;
- username;
- Account identifier;
- role and permissions; and
- verification information where required.
2.2 Contact information
- email address;
- telephone number;
- business address; and
- communication preferences.
2.3 Subscription and billing information
- selected plan;
- quotation and contract details;
- billing information;
- invoices;
- payment status;
- renewal and cancellation status;
- transaction references; and
- limited payment information received from our payment processor.
2.4 Technical and usage information
- IP address;
- device and browser information;
- operating system;
- login activity;
- audit records;
- feature usage;
- performance information;
- error records;
- security events;
- advertisement impressions and clicks; and
- cookie and similar identifiers.
2.5 Communications
- emails;
- support tickets;
- chat messages;
- feedback;
- surveys; and
- call recordings where appropriate notice is provided.
2.6 Information entered by Customers
The Services may process Personal Data entered by Customers relating to their employees, customers, suppliers, directors, shareholders, contractors, contacts and other individuals. The exact information depends on how each Customer configures and uses the Services.
3. How we collect Personal Data
We may collect Personal Data:
- directly from an individual;
- from their employer or organisation;
- through our websites and Services;
- from sales and support interactions;
- through authorised partners or resellers;
- from payment and security providers;
- through cookies, logs and similar technologies;
- from publicly available business sources; and
- from other lawful sources.
4. Purposes of processing
We may collect, use and disclose Personal Data to:
- create and administer Accounts;
- verify users and organisations;
- provide, configure and maintain the Services;
- process subscriptions, renewals, automatic billing, failed-payment notifications, cancellations, invoices and payments;
- provide implementation, training and support;
- respond to enquiries;
- communicate service, security and maintenance notices;
- monitor performance and availability;
- protect Accounts and prevent fraud or abuse;
- investigate incidents;
- enforce contractual rights;
- improve the Services and user experience;
- administer customer and partner relationships;
- comply with legal, tax, audit and regulatory obligations;
- establish, exercise or defend legal claims;
- send marketing communications where permitted;
- display and measure advertisements;
- create aggregated and anonymised information;
- develop analytics, benchmarks and recommendations; and
- carry out other purposes notified at or before collection or otherwise permitted by law.
5. Customer-controlled Personal Data
Where we process Personal Data on behalf of a Customer, we generally:
- process it according to the Customer's documented instructions;
- use it to provide, support and secure the Services;
- restrict access to authorised personnel and providers;
- assist with reasonable data-protection requests where applicable; and
- delete or return it according to the relevant contractual and retention arrangements if any.
Customers are responsible for determining whether they have lawful authority to enter Personal Data into the Services.
6. Platform analytics
We may analyse how the Services are used to:
- improve performance;
- identify errors;
- enhance security;
- develop new features;
- improve automation;
- provide reporting and recommendations;
- understand general usage trends; and
- develop analytical and business-intelligence services.
Where possible and appropriate, analytics are conducted using aggregated, anonymised or de-identified information.
7. Aggregated and anonymised information
We may process Customer Data, technical information and usage information to create aggregated and anonymised information.
Before externally disclosing or commercialising such information, we use measures intended to prevent the reasonable identification of individuals, Customers, specific businesses, counterparties and individual transactions. These measures may include:
- removing direct identifiers;
- combining information from multiple businesses;
- generalising dates, products, categories or locations;
- applying minimum sample thresholds;
- suppressing uncommon results;
- using ranges, averages, medians, percentiles or indices;
- delaying publication;
- limiting the contribution of any single source; and
- assessing identification and re-identification risk.
We may use aggregated and anonymised information to:
- improve the Services;
- develop new features;
- provide industry benchmarks;
- provide pricing and market comparisons;
- develop business recommendations;
- provide premium analytics;
- prepare economic or industry reports;
- conduct research;
- identify market and operational trends;
- create forecasts and models;
- develop Data Products;
- combine it with other lawful information sources; and
- carry out lawful commercial and analytical activities.
8. Data Products
We may publish, provide, license, distribute or sell reports, benchmarks, statistics, indices, dashboards and other Data Products created from aggregated and anonymised information.
Recipients may include:
- customers;
- businesses;
- professional advisers;
- researchers;
- financial institutions;
- industry organisations;
- government agencies;
- technology providers;
- advertisers; and
- other lawful recipients.
We do not knowingly sell or disclose as a Data Product:
- Personal Data;
- raw Customer Data;
- identifiable business records;
- identifiable individual transactions;
- identifiable customer or supplier lists;
- confidential pricing attributable to a specific Customer;
- information identifying which Customer supplied a particular transaction or price; or
- information that could reasonably reconstruct a specific Customer's transaction history.
Aggregated information that cannot reasonably identify or be attributed to an individual, Customer, business or transaction may be retained indefinitely.
9. Benchmarks and business recommendations
The Services may use aggregated information to provide:
- price-position comparisons;
- industry ranges;
- payment-performance benchmarks;
- sales and purchasing trends;
- inventory indicators;
- cash-flow indicators;
- operating comparisons; and
- other analytical recommendations.
These insights may be based on historical, sampled, estimated or modelled information and may not represent the entire market. Individual businesses and transactions will not be intentionally identified in such benchmarks.
Each Customer remains responsible for making its own commercial, pricing, purchasing and operational decisions.
10. Free Tier advertisements
The Free Tier may include:
- advertisements;
- sponsored content;
- partner offers;
- product recommendations; and
- messages promoting paid features.
We may use limited information to select, display or measure advertisements, including:
- broad industry category;
- general business type;
- country or broad region;
- language;
- Account type;
- selected modules;
- feature usage;
- advertisement impressions; and
- advertisement interactions.
We do not use raw invoice contents, employee records, customer lists, supplier lists or confidential transaction-level pricing for third-party personalised advertising unless separate express authorisation has been obtained.
Advertisers may receive:
- total impressions;
- total clicks;
- broad audience categories;
- campaign-performance statistics; and
- aggregated conversion information.
Advertisers do not receive direct access to raw Customer Data or Personal Data merely because their advertisements are displayed.
When a user interacts with a third-party advertisement, the third party may independently collect information under its own privacy notice. Users should review the applicable third-party terms before providing information directly to an advertiser.
11. Cookies and similar technologies
Our websites and Services may use cookies, local storage, pixels, SDKs and similar technologies for:
- authentication;
- security;
- session management;
- preferences;
- analytics;
- performance;
- advertising;
- attribution; and
- functionality.
Some technologies are necessary to provide the requested Services. Others may be optional and subject to available consent or preference controls. Disabling certain technologies may affect functionality or reduce advertisement relevance.
12. Marketing and service communications
We may use contact information, business contact information and Account information to send administrative, transactional, security, billing, support and service-related communications.
These communications are necessary for the operation, administration and security of the Services and may include:
- account notices;
- billing and renewal reminders;
- payment-related communications;
- security alerts;
- maintenance notices;
- system incident notifications;
- support updates;
- feature-change notices;
- legal, policy and terms updates; and
- other operational communications relating to the Services.
We may also use business contact information to send product updates, feature announcements, educational content, event invitations, promotional offers, surveys and other marketing communications relating to our products, services, partners, events and business offerings.
Recipients may opt out of marketing communications at any time by using the unsubscribe link provided, updating their communication preferences where available, or contacting us. Opting out of marketing communications does not prevent us from sending service-related communications, including security, billing, legal, maintenance, support, renewal and account notices.
Where required, we will obtain consent before sending marketing communications through channels such as email, SMS, telephone, WhatsApp or other messaging platforms. We may also check applicable do-not-call or preference registers where required before sending specified marketing messages.
13. Disclosure of Personal Data
We may disclose Personal Data to:
- hosting and infrastructure providers;
- communications providers;
- payment processors and financial institutions;
- implementation and support partners;
- security and monitoring providers;
- analytics and advertising providers;
- professional advisers, auditors and insurers;
- affiliated companies;
- government, regulatory, law-enforcement and judicial authorities where required; and
- purchasers or successors involved in a corporate transaction.
Service providers are authorised to process Personal Data only for appropriate purposes and subject to applicable obligations. We do not sell Personal Data to data brokers.
14. Product development and models
We may use information to develop, test and evaluate:
- software features;
- automation;
- analytical models;
- forecasting tools;
- fraud and security controls;
- classification systems; and
- business recommendations.
Where feasible, such work will use aggregated, anonymised or de-identified information. Where Personal Data remains involved, it will be handled according to this Notice and applicable law.
15. Artificial Intelligence and automated features
We may use artificial intelligence, machine learning, automation, generative AI or similar technologies to provide, support, secure, improve and develop the Services.
These technologies may support functions such as document processing, transaction classification, data entry assistance, report generation, summarisation, recommendations, forecasting, anomaly detection, workflow automation, customer support and product analytics.
Depending on how the Services are used, AI Features may process:
- Account information;
- Customer Data;
- Personal Data contained in Customer Data;
- Platform Data;
- user prompts and instructions;
- system settings;
- usage interactions; and
- Aggregated Data.
We may use information processed through AI Features to:
- provide the requested AI-assisted function;
- generate outputs, recommendations or summaries;
- monitor safety, quality and performance;
- detect misuse, security issues or errors;
- improve the Services and AI Features;
- develop new features and analytical models; and
- create aggregated and anonymised insights.
Where feasible and appropriate, we use aggregated, anonymised or de-identified information to improve AI Features and analytical models. We will not knowingly use Personal Data or raw Customer Data to train third-party general-purpose AI models for the third party's independent use unless this is disclosed and permitted under applicable law or separately authorised.
AI-generated outputs may not always be accurate or complete. Users should review and verify outputs before relying on them or using them for accounting, tax, legal, financial, regulatory, operational or commercial decisions.
16. Overseas transfers
Personal Data may be processed outside Singapore where our infrastructure, service providers or partners operate. Where required, we take reasonable steps to ensure that transferred Personal Data receives protection comparable to that required under Singapore law.
17. Security
We use reasonable administrative, technical and physical safeguards appropriate to the nature of the information processed. These may include:
- access controls;
- authentication measures;
- encryption in transit;
- logging and monitoring;
- vulnerability management;
- backups;
- incident-response procedures;
- staff confidentiality obligations; and
- service-provider controls.
Users must protect their credentials and notify us promptly of suspected unauthorised access.
18. Retention
We retain Personal Data only for as long as reasonably necessary for:
- providing the Services;
- fulfilling the purpose for which it was collected;
- contractual and support requirements;
- legal, tax, audit and regulatory obligations;
- fraud and security prevention;
- resolving disputes; and
- enforcing agreements.
When Personal Data is no longer required, we will delete, anonymise or otherwise dispose of it according to our retention practices. Residual copies may remain temporarily in backups until overwritten through normal backup cycles.
Aggregated information that cannot reasonably identify an individual, Customer, business or transaction may be retained and used after the original Personal Data or Customer Data is deleted.
19. Access and correction
An individual may request access to Personal Data we hold about them or request correction of inaccurate or incomplete Personal Data, subject to applicable legal exceptions.
Requests must contain sufficient information to verify the requester and identify the relevant data. Where the information is controlled by one of our Customers, we may refer the request to that Customer. A reasonable fee may be charged for an access request where permitted.
20. Withdrawal of consent
Where processing is based on consent, an individual may withdraw consent by contacting us. We will explain the likely consequences and cease the affected processing within a reasonable period unless continued processing is required or permitted by law.
Withdrawal does not require us to delete information that has already been lawfully transformed into aggregated and anonymised information that cannot reasonably identify the individual.
21. Data breaches
We maintain procedures to assess and respond to suspected Personal Data breaches. Where required by law, we will notify the Personal Data Protection Commission and affected individuals.
22. Children
The Services are intended for business users and are not directed at individuals below 18 years old. Where Customer Data contains Personal Data relating to children, the Customer is responsible for ensuring that it has lawful authority to process that information.
23. Business transfers
Information may be transferred as part of a proposed or completed merger, acquisition, financing, restructuring, sale of assets or other corporate transaction, subject to applicable confidentiality and legal requirements.
24. Changes to this Notice
We may update this Notice to reflect changes to:
- the Services;
- advertising practices;
- analytics and Data Products;
- processing activities;
- service providers; or
- applicable legal requirements.
The updated version will display a revised "Last Updated" date. Material changes may be communicated by email, through the Services or through another appropriate channel.
25. Contacting our Data Protection Officer
Questions, complaints and requests may be directed to our Data Protection Officer. Please provide sufficient information for us to identify and respond to the request.
Data Protection Officer
ZETTA SOLUTION PTE. LTD.
Email: dpo@zetta-solution.com
Address: 18 Sin Ming Ln, #06-22, Singapore 573960
Telephone: 6334 1013