Data protection
Privacy notice
How MarkBloom Wave Pte. Ltd. handles personal data under Singapore PDPA principles. Last updated 2026-08-12.
1. Who we are
MarkBloom Wave Pte. Ltd. ("we", "us") operates markbloomwave.pro and provides brand craft services from 28 Blair Road, #01-02, Singapore 089928. For privacy enquiries contact [email protected]. This notice explains what we collect, why, and how you can exercise your rights.
2. Scope
This notice covers personal data collected through this website, email correspondence, phone calls to our published number, and in-person meetings at our studio. It does not cover third-party sites linked from our pages. Client work may be governed by additional terms in signed agreements.
3. Categories of personal data
Identity and contact. Name, job title, organisation, email address, phone number, postal address when you provide them.
Correspondence content. Messages, attachments, call notes, and meeting summaries you share with us.
Technical data. IP address, browser type, device characteristics, referring URL, timestamps in server logs.
Consent records. Cookie choices stored in sg_studio_consent and cookie_consent_v1 as described on Cookies.
Map interaction data. When Google Maps embeds load, Google may process data under its policies. We do not receive precise location from maps unless you use Google controls directly.
4. Sources
Data comes directly from you, from your organisation when colleagues copy you on mail, from server logs generated by routine hosting, and from cookie/storage APIs in your browser when you set preferences.
5. Purposes and legal bases
We process data to respond to enquiries, prepare proposals, perform contracts, maintain website security, comply with law, and document consent. Consent applies to non-essential cookies. Contract necessity applies when you become a client. Legitimate interests include fraud prevention and improving reliability, balanced against your rights.
6. Retention schedule
Enquiry emails: retained while active and for a reasonable period afterward unless you request deletion. Client project files: per agreement, typically until handover plus agreed advisory period. Server logs: rolling window suitable for security review. Cookie consent: six months unless refreshed. Marketing lists: we do not maintain unsolicited bulk lists.
7. Sharing and processors
We do not sell personal data. Processors may include hosting providers in Singapore, email services, backup storage, and Google for Maps embeds. Processors act under instruction and confidentiality expectations. We assess subprocessors before engagement.
8. International transfers
Some processors may store or route data outside Singapore. Where required we implement appropriate safeguards consistent with PDPA cross-border expectations and document transfer mechanisms.
9. Security measures
We use HTTPS, access controls, staff confidentiality obligations, and device policies. No system is perfectly secure; we monitor for anomalies and respond to incidents as law requires, including notification when mandatory.
10. Your rights
You may request access, correction, deletion, or withdrawal of consent where applicable. Contact [email protected]. We verify identity before releasing data. We respond within reasonable timeframes under PDPA. Some requests may be limited by law or ongoing contractual duties.
11. Marketing and newsletters
We do not send bulk marketing without opt-in. Replies to your enquiries are service communication, not newsletters. If we ever publish a voluntary mailing list, sign-up will be separate and documented here.
12. Automated decision-making
We do not use automated profiling to make decisions about enquiries or clients. Review of proposals is human.
13. Children
This site addresses business audiences. We do not knowingly collect data from minors. Contact us to remove inadvertent submissions.
14. Data breach notification
If a breach likely to cause significant harm occurs, we will notify affected individuals and regulators as PDPA requires, describing steps taken and recommended actions.
15. Cookies in detail
Essential storage records consent. Functional storage enables map embeds without placeholders when accepted. Analytics remains off unless opted in. See the storage table on Cookies and use Manage cookies to change choices.
16. Third-party links
Linked sites have their own policies. Review them before submitting data elsewhere.
17. Client materials
Project files may contain personal data about your customers or staff supplied by you. You are responsible for lawful collection; we process as processor under agreement terms.
18. Records of processing
We maintain an internal register of processing activities for website and client operations, reviewed periodically.
19. Changes to this notice
Updates appear with a revised date above. Material changes may be highlighted on Cookies or the home page footer when appropriate.
20. Complaints
Contact us first at [email protected]. Unresolved complaints may be referred to the Personal Data Protection Commission in Singapore.
21. Contact summary
Controller: MarkBloom Wave Pte. Ltd., 28 Blair Road, #01-02, Singapore 089928. Phone: +65 6728 5193. General: [email protected]. Privacy: [email protected].
22. Lawful basis summary table
Enquiry handling: legitimate interest and pre-contract steps. Client delivery: contract. Cookie preferences: consent for non-essential categories. Security logging: legitimate interest. Legal compliance: obligation under law.
23. Data minimisation
We ask only for information needed to respond or perform work. If you send excess personal data, we delete or anonymise what is not required after review.
24. Accuracy
Keep contact details current by writing to us. We correct factual errors in stored correspondence when notified.
25. Processor agreements
Written terms with hosting and tooling providers include confidentiality and security expectations. We review providers periodically.
26. Employee access
Only staff who need data to respond or deliver projects can access it. Access is revoked when roles change.
27. Backups
Backups may retain deleted mail for a limited technical window. Backups rotate and expire automatically.
28. Public communications
We do not publish client names in case studies without approval. Portfolio mentions elsewhere follow the same rule.
29. Social platforms
We maintain minimal social presence. Messages sent via those platforms are subject to the platform's own policies in addition to this notice when we download them to respond.
30. Your responsibilities
When you supply lists or materials containing third-party personal data, ensure you have a lawful basis to share them with us for the stated purpose.
31. Detailed retention examples
Unsuccessful enquiry threads may be deleted after twelve months unless you request earlier removal. Successful client projects follow handover schedules in contracts, typically retaining working files until advisory periods end. Consent logs refresh when you interact with Manage cookies.
32. Access request process
Email [email protected] with sufficient detail to locate your records. We may ask for verification. We respond with copies or summaries where appropriate and explain any withheld fields under law.
33. Correction and deletion
Request correction of inaccurate fields or deletion where no overriding legal or contractual need remains. Deletion may limit our ability to reference prior work if you return later.
34. Objection and restriction
Where processing relies on legitimate interests, you may object. We assess and respond. Restriction may apply while disputes are reviewed.
35. Maps and functional consent
Rejecting functional cookies limits map loading until you opt in or press Load map. That choice is stored in sg_studio_consent as described on Cookies.
36. Data protection officer contact
Our privacy contact handles day-to-day PDPA questions even though we use a small-team structure without a separately titled officer.
37. Training
Staff with access to personal data receive periodic reminders on confidentiality, phishing awareness, and secure handling of attachments.
38. Incident log
We maintain an internal register of security and privacy incidents, reviewed quarterly, even when notification is not required.
39. Aggregated statistics
We may compile non-identifying statistics about site traffic from server logs for reliability planning. These statistics do not identify individuals.
40. Third-party recipients
Google receives interaction data when maps load. Hosting providers process IP addresses in logs. Email providers process message metadata. Each relationship is governed by contract or public terms.
41. Voluntary data
Beyond required enquiry fields, any information you volunteer in correspondence is processed only as needed to respond or deliver services you request.
42. Withdrawal of consent
Withdraw cookie consent via Manage cookies. Withdraw marketing consent, if ever applicable, by email. Withdrawal does not affect prior lawful processing.
43. Anonymisation
We may anonymise project notes for internal training after engagements end. Anonymised data is no longer personal data.
44. Contact frequency
We do not contact you repeatedly after an enquiry closes unless you initiate a new thread or hold an active contract.
45. Paper records
Occasional printed notes during studio sessions are scanned or transcribed into project folders when needed, then shredded when no longer required.
46. Video calls
Calls may be recorded only with explicit consent for training or absent colleagues. Default is no recording.
47. Physical access
Studio visitors sign a simple visitor log for safety. Logs are destroyed after a short retention period unless incident investigation requires otherwise.
48. Data portability
Where feasible we provide correspondence exports in common formats when you request portability for data you supplied.
49. Questions
If anything in this notice is unclear, write to [email protected] and we will explain in plain language without unnecessary delay. We aim to respond within reasonable PDPA timeframes and document significant requests internally for audit purposes.
50. Effective date
This notice takes effect on 2026-08-12 and replaces prior versions published on this domain. Printed copies are not distributed by postal mail here.