Privacy Policy
Effective date: · Version 1.0
1. About this policy
This Privacy Policy explains how SaaS Global Pte Ltd (UEN 202322132C), a company incorporated in Singapore (“we”, “us”, “our”), collects, uses, stores, and discloses personal information in connection with the DCRM brand and the DCRM platform. DCRM is a trading brand of SaaS Global Pte Ltd.
This policy applies to all personal information collected through our website at www.dcrm.io, through the DCRM platform, and through any other interaction with DCRM.
References to “you” mean any individual whose personal information we hold, including platform account holders, authorised users, website visitors, and the customers of those account holders whose data is processed through the platform.
2. Regulatory framework
We are committed to handling personal information responsibly and in compliance with applicable privacy laws.
| Jurisdiction | Framework |
|---|---|
| Singapore | Personal Data Protection Act 2012 (PDPA), which governs the collection, use, and disclosure of personal data by organisations in Singapore. |
| Australia | Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), applicable to the handling of personal information of Australian individuals. |
| Other jurisdictions | Where we collect or process personal information of individuals in other jurisdictions, we take reasonable steps to comply with applicable local privacy laws. |
Where two applicable frameworks impose different standards, we apply the more protective standard.
3. Our role: Controller and Processor
Our role in relation to personal information varies depending on the context.
| Role | When this applies |
|---|---|
| Data Controller | When we collect personal information about website visitors, prospective customers, and our own account holders (such as billing contacts and platform administrators), we act as the Data Controller and determine the purpose and means of processing. |
| Data Processor / Intermediary | When DCRM customers upload their own customers’ personal information to the platform, including leads and contacts, we act as a Data Processor or Data Intermediary. We process that data only on the instructions of the customer, who remains the Data Controller, and in accordance with our agreement with them. |
You are the Data Controller for your customers’ data. If you are a DCRM customer, you are solely responsible for ensuring you have a lawful basis to collect and process your customers’ personal information, and for obtaining all necessary consents before uploading it to the platform.
4. Information we collect
From website visitors and enquirers:
- Name, email address, phone number, and business name submitted via contact or enquiry forms.
- Technical data including IP addresses, browser type, device type, pages visited, and referral source, collected automatically via analytics tools.
From DCRM account holders and authorised users:
- Account information: name, business entity details, billing address, and login credentials.
- Billing data: payment card details (processed via secure third-party payment providers) and billing address.
- Communication logs: metadata related to SMS, MMS, email, and voice calls sent through the platform.
- User contributions: content, materials, and data uploaded or transmitted through DCRM.
- Technical data: IP addresses, browser types, and usage patterns collected to monitor platform performance and security.
We do not knowingly collect sensitive personal information unless strictly necessary and with express consent or another lawful basis.
5. How we collect information
- Direct interaction: when you create a platform account, fill in a contact form, sign a service agreement, or engage our services.
- Platform use: when you log in, upload data, configure automations, send communications, or use any platform feature.
- Automated technologies: via cookies and analytics tools when you visit our website (see section 7).
- Communications: via email, phone calls, or messages during the course of our engagement.
6. Purpose of processing
| Purpose | Description |
|---|---|
| Platform functionality | To operate the DCRM platform, including CRM, automation, SMS, MMS, email, voice, and AI features. |
| Account management | To onboard customers, manage accounts, process payments, issue invoices, and provide support. |
| Service improvement | To analyse usage patterns and develop new platform features and capabilities. |
| Security and fraud prevention | To monitor for prohibited conduct, detect security incidents, and protect platform integrity. |
| Legal and compliance | To comply with legal obligations, respond to regulatory enquiries, and protect our legal rights. |
7. Cookies and tracking
Our website and the DCRM platform use cookies and similar tracking technologies for authentication, session security, performance measurement, and analytics. Our use of cookies is described separately in the DCRM Cookies Policy.
Where required by applicable law, we will obtain your consent before placing non-essential cookies on your device.
8. Platform infrastructure disclosure
The DCRM platform is built on the Go High Level (GHL) software infrastructure. SaaS Global Pte Ltd operates as a white-label reseller account holder on that platform. Customer sub-accounts, funnels, automations, phone numbers, and associated data reside within SaaS Global’s GHL account.
Important. By creating a DCRM account and uploading data to the platform, you acknowledge this structure and accept that the continuity of DCRM services is dependent on the ongoing availability of the GHL platform. In the event of a material disruption to GHL’s operations, we will use reasonable endeavours to migrate your data and functionality to a comparable alternative platform and will notify you as soon as reasonably practicable.
Data uploaded to the DCRM platform may be processed by GHL’s infrastructure, which operates primarily from servers in the United States. By using the DCRM platform, you acknowledge and consent to this cross-border processing.
9. Third-party services and sub-processors
We engage third-party service providers and sub-processors to assist in operating and delivering the platform. These providers may process personal information on our behalf. We take reasonable steps to ensure they handle personal information consistently with this policy and applicable law.
| Provider | Purpose |
|---|---|
| Go High Level (GHL) | The underlying CRM, automation, and communications infrastructure on which the DCRM platform is built. GHL operates servers primarily in the United States. |
| Telecommunications carriers | SMS, MMS, and voice services, including LeadConnector and Twilio. Message metadata may be processed by these carriers for delivery and compliance purposes. |
| Stripe | Payment processing. We do not store full card numbers. Payment data is handled directly by Stripe in accordance with PCI DSS standards. |
| Google and Meta | Used by customers to manage advertising campaigns through the platform where applicable. |
| Dropbox Sign | Electronic document signing for customer agreements. |
We are not responsible for the independent privacy practices of these third-party providers. We encourage you to review their respective privacy policies.
10. Cross-border data transfers
As a Singapore-incorporated entity, personal information we collect may be transferred to, stored in, or processed in countries other than your home jurisdiction. The primary jurisdictions involved are Singapore and the United States, including through our sub-processors and through GHL.
Where we transfer personal information outside Singapore, we comply with the PDPA’s transfer limitation obligations and take steps to ensure that overseas recipients maintain a comparable standard of protection.
Where we transfer personal information of Australian individuals outside Australia, we take reasonable steps to ensure overseas recipients handle that information consistently with the Australian Privacy Principles, as required by APP 8.
11. Call recording and AI processing
Call recording. The DCRM platform provides tools for recording and transcribing phone calls. Customers who use these features are solely responsible for providing all legally required notices to callers before recording commences, including compliance with state and territory call recording consent laws in Australia.
AI and machine-learning features. DCRM incorporates generative AI and machine-learning features for purposes including call summarisation, lead scoring, automated response suggestions, and voice AI. These features are probabilistic and may produce inaccurate, incomplete, or fabricated outputs.
Human review required. Customers are strictly prohibited from deploying AI-generated content, automated voice interactions, or AI-driven responses in a live environment without prior human review and approval. AI features do not provide, and must not be represented as providing, medical, legal, or professional advice. We are not liable for any errors, regulatory non-compliance, or reputational harm arising from unreviewed AI outputs.
We do not use private customer data to train general AI models for other users or for any purpose outside the delivery of the platform service.
12. Data security and retention
Security. We implement reasonable technical and organisational measures to protect personal information from unauthorised access, disclosure, alteration, or loss. These include password authentication, multi-factor authentication for remote access, encryption in transit, role-based access controls, and audit logging.
No method of digital transmission or storage is entirely secure. We cannot guarantee absolute security but we take reasonable steps consistent with applicable law and industry standards.
Retention.
- Platform account data is retained for as long as the account is active.
- We reserve the right to delete accounts and all associated data that have remained inactive for more than twelve (12) months, with reasonable prior notice where practicable.
- On account termination or cancellation, your right to access the platform and stored data ceases immediately. You are responsible for exporting any data you require before termination.
- Billing and transaction records are retained for seven (7) years in accordance with applicable business record-keeping requirements.
When personal information is no longer required, we take reasonable steps to securely destroy or de-identify it.
13. Your rights
Depending on your location and applicable law, you may have the following rights in relation to your personal information:
| Right | Description |
|---|---|
| Access | Request a copy of the personal information we hold about you. |
| Correction | Request correction of personal information that is inaccurate, incomplete, or out of date. Account information can also be updated directly via the platform settings. |
| Deletion | Request deletion of your personal information, subject to legal or contractual obligations requiring retention. |
| Withdrawal of consent | Where we rely on consent as a basis for processing, you may withdraw consent at any time without affecting the lawfulness of prior processing. |
| Complaints | Lodge a complaint with us or with the relevant supervisory authority (see section 16). |
To exercise any of these rights, please contact our Data Protection Officer using the details in section 17. We may require identity verification before processing certain requests.
Requests about your customers’ data. If an individual’s personal information was uploaded to DCRM by one of our customers, that customer is the Data Controller for that information. Requests from individuals about their data should be directed to the relevant customer, not to us.
14. Customer responsibilities
If you are a DCRM customer who uploads personal information about your own customers, leads, or staff to the platform, you warrant that:
- you have obtained all necessary consents and have a lawful basis to collect and process that personal information;
- you have provided individuals with appropriate privacy notices explaining how their information will be used and processed through the platform;
- you maintain your own privacy policy providing individuals with a level of protection consistent with applicable law;
- you will comply with all applicable privacy laws, professional obligations, telecommunications regulations, and advertising rules relevant to your business and jurisdiction, including call recording consent requirements; and
- all communications sent through the platform comply with the Telephone Consumer Protection Act (TCPA), the CAN-SPAM Act, the Australian Spam Act 2003 (Cth), and any other applicable telecommunications or anti-spam laws.
You indemnify SaaS Global Pte Ltd against any claims, losses, or regulatory action arising from your failure to comply with these obligations.
15. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in the platform, our practices, or legal obligations. When we make material changes, we will update the effective date at the top of this policy and post a notice within the platform.
Your continued use of the DCRM platform after any update constitutes your acceptance of the revised policy.
16. Complaints
If you have a concern about how we have handled your personal information, please contact our Data Protection Officer first. We will acknowledge your complaint within five (5) business days and aim to resolve it within thirty (30) days.
If you are not satisfied with our response, you may lodge a complaint with the relevant supervisory authority:
- Singapore: Personal Data Protection Commission (PDPC) at www.pdpc.gov.sg.
- Australia: Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.
17. Contact and DPO enquiries
For any questions, requests, or complaints regarding this Privacy Policy or our handling of personal information, please contact us. General enquiries and data protection matters are both handled by our Data Protection Officer:
SaaS Global Pte Ltd (UEN 202322132C)
Attention: Data Protection Officer, DCRM
2 Venture Drive #19-18 Vision Exchange, Singapore 608526
Email: eric@dcrm.io
This policy was prepared in accordance with the Singapore Personal Data Protection Act 2012 and the Australian Privacy Act 1988 (Cth) and Australian Privacy Principles.
© SaaS Global Pte Ltd. All rights reserved. UEN 202322132C. Trading as DCRM.