Legal / Privacy

Privacy Policy

How Tamira Technologies Pte. Ltd., operating the ALFREDx platform, collects, uses, discloses, transfers, retains, and protects personal data across Singapore, Southeast Asia, the European Economic Area, the United Kingdom, and the United States.

Last updated · 23 July 2026
01 / Controller

Who we are and our role

ALFREDx is owned and operated by Tamira Technologies Pte. Ltd. (UEN 202021011E), a company incorporated in Singapore, with its registered office at 63 Hillview Avenue, #08-04A Lam Soon Industrial Building, Singapore 669569 ("ALFREDx", "we", "us", or "our"). This Policy explains how we collect, use, disclose, transfer, retain, and protect personal data when you use our websites, web application, mobile applications, APIs, AI features, support channels, and other services that link to this Policy (the "Services").

Our privacy role depends on how personal data is processed:

  • We act as a controller or organisation when we determine why and how personal data is processed, including for our website, marketing, recruitment, account administration, security, and direct communications.
  • We generally act as a processor, data intermediary, or service provider when we process information submitted to the Services by or for a customer. The customer organisation controls that data and its own privacy notice and agreement with us also apply.

If you use ALFREDx through your employer or another organisation, that organisation administers your workspace and may access, manage, export, retain, or delete information associated with it. Requests relating to customer-controlled data should normally be directed to that organisation. We will assist customers with valid requests as required by law and our agreements.

02 / Scope

Scope

This Policy applies to the ALFREDx website and to the ALFREDx web and mobile applications for iOS and Android, APIs, support services, AI- enabled features, and related services that link to this Policy.

It does not apply to third-party websites, products, or services that have their own privacy notices, or to employee personal data governed by an internal workforce notice.

Different privacy laws may apply depending on where you are located and how you use the Services. These may include Singapore's Personal Data Protection Act 2012, other applicable Southeast Asian privacy laws, the EU General Data Protection Regulation, the UK GDPR and Data Protection Act 2018, and applicable United States state privacy laws. Where applicable law gives you additional rights, we will respect those rights.

03 / Sources

How we obtain personal data

We may obtain personal data:

  • directly from you when you create or use an account, submit information, contact us, request a demonstration, apply for a role, or use a device feature;
  • from the customer organisation that creates or administers your account;
  • automatically from your browser, device, and use of the Services;
  • from systems, devices, sensors, or third-party services that a customer chooses to integrate with ALFREDx; and
  • from business partners, service providers, event organisers, or publicly available business sources, where permitted by law.
04 / Data

Personal data we collect

The data we collect depends on the ALFREDx modules, device features, integrations, and permissions you or your organisation enable.

Identity, contact, and account data

Name, business email, telephone, employer, role, country, account identifier, username, authentication or single sign-on identifier, permissions, preferences, and account status. Passwords are stored only in protected or cryptographically hashed form where ALFREDx manages authentication.

Customer Content

Customers and their authorised users may submit asset and location records, work orders, maintenance history, inspections, reliability records, safety and environmental records, permits, compliance records, workforce records, schedules, documents, photographs, videos, audio or voice notes, QR or barcode data, signatures, comments, and other operational content.

Depending on the customer's industry and configuration, Customer Content may include sensitive information such as occupational health and safety information, incident information, identity documents, medical or treatment information, or photographs of patients or other individuals. ALFREDx processes such information on the customer's documented instructions and subject to the applicable customer agreement.

AI interaction data

When you use an AI-enabled feature, we may process your prompts, instructions, uploaded files, relevant Customer Content, system context, generated responses, and feedback to provide the requested function, maintain security, and improve the feature within the permitted scope described in the AI-enabled features section.

Device, technical, usage, and diagnostic data

IP address, device type, operating system, browser type, app version, language, time zone, device or app identifiers, session information, login events, pages or screens viewed, feature interactions, timestamps, crash reports, performance data, and security or audit logs.

Mobile device permissions and features

ALFREDx may request access only when needed for a feature you choose to use:

  • Camera — to scan QR codes or barcodes and capture asset, inspection, maintenance, safety, compliance, or other authorised evidence.
  • Photos and files — to select, upload, download, or attach authorised images and documents.
  • Location — to associate an authorised field activity, asset, incident, inspection, or service record with a location, where the feature is enabled. The app will indicate whether approximate or precise location is requested.
  • Microphone — to record an authorised voice note or use a voice-enabled function, where available.
  • Notifications — to deliver work assignments, alerts, approvals, reminders, security notices, and other service messages. A push-notification token may be processed for this purpose.

You can deny or later withdraw a device permission through your device settings. Some optional features may not function without the relevant permission, but unrelated features will remain available.

ALFREDx does not use mobile permissions, photographs, health information, or location information for advertising. Unless a separately disclosed integration is enabled, ALFREDx does not access your contacts, Apple HealthKit, or Google Health Connect data.

Website, sales, support, recruitment, and communications data

Information you provide when requesting a demonstration, contacting support, subscribing to communications, attending an event, responding to a survey, or applying for a role, together with our correspondence and notes about the interaction.

Cookies and similar technologies

Our website and web application may use cookies, local storage, pixels, and similar technologies. Further information is provided in the Cookies section below.

05 / No advertising

Information we do not use for advertising

We do not sell personal data. We do not share personal data for cross-context behavioural advertising or targeted advertising, and we do not use advertising SDKs in the ALFREDx mobile application.

We do not use Customer Content to build advertising profiles. We do not use facial images for facial recognition or biometric identification unless a customer has expressly enabled a separately disclosed, legally authorised feature and all required notices and consents have been provided.

06 / Use

How and why we use personal data

We use personal data for the following purposes:

PurposeTypical legal basis under EU/UK law, where applicable
Create, administer, and authenticate accounts; provide requested features; process Customer Content; and perform our customer agreementsPerformance of a contract; steps requested before entering a contract; legitimate interests
Operate mobile features requested by the user, including camera, files, location, microphone, and notificationsPerformance of a contract; consent where required
Provide AI-enabled features requested by the user or customerPerformance of a contract; consent where required
Respond to enquiries, demonstrations, support requests, and communicationsPerformance of a contract; steps requested before entering a contract; legitimate interests
Maintain security, prevent fraud and misuse, troubleshoot, audit access, and protect the Services and usersLegitimate interests; legal obligation
Monitor performance, understand use, and improve the ServicesLegitimate interests; consent for non-essential analytics where required
Send service messages and, where permitted, marketing communicationsPerformance of a contract; legitimate interests; consent where required
Evaluate employment applicationsSteps requested before entering a contract; legitimate interests; legal obligation
Comply with legal, tax, accounting, regulatory, and dispute-resolution obligationsLegal obligation; legitimate interests; establishment, exercise, or defence of legal claims

Where we rely on legitimate interests, we consider the impact on individuals and do not use that basis where our interests are overridden by your rights and interests. Where we rely on consent, you may withdraw it at any time without affecting processing that occurred before withdrawal.

Some account and business information is required to provide the Services or enter into a customer relationship. If required information is not provided, we may be unable to create an account or provide the relevant service. Optional permissions and optional marketing consent are not required to use unrelated ALFREDx features.

For Singapore and other jurisdictions that require notification or consent, we collect, use, and disclose personal data for notified purposes and obtain consent where required, unless an applicable deemed-consent provision or legal exception applies.

07 / AI

AI-enabled features

ALFREDx uses AI to assist users with tasks such as document analysis, data entry, troubleshooting, recommendations, search, workflow support, and operational insights.

  • AI inputs and outputs may contain personal data if a user includes personal data in a prompt, attachment, or relevant record.
  • We process AI interaction data to provide the feature, maintain security, evaluate quality, and improve ALFREDx within the limits of the customer agreement and this Policy.
  • We do not use one customer's Customer Content to train models for another customer, and we do not permit Customer Content to be used to train public or shared general-purpose AI models unless the customer has expressly agreed in writing.
  • Some AI functions may use contracted third-party AI or infrastructure providers. Before personal data is sent to a third- party AI provider, ALFREDx will disclose the relevant sharing and obtain explicit permission where required. Current providers and processing locations are identified on our Subprocessor List at alfredx.com/subprocessors.
  • Contracted AI providers may process the minimum data needed to return the requested result and are subject to confidentiality, security, retention, and use restrictions.

AI-generated outputs may be incomplete or inaccurate. They are intended to support, not replace, authorised human review and professional judgment. In our role as controller, we do not make decisions based solely on automated processing that produce legal or similarly significant effects about an individual. A customer may configure workflows that use automated recommendations; in that case, the customer is responsible for appropriate notices, lawful authority, safeguards, and human review.

08 / Sharing

How we disclose personal data

We may disclose personal data only as needed to:

  • Customer organisations and authorised users, including administrators of the workspace in which you work.
  • Service providers and subprocessors, including cloud hosting, database, content delivery, authentication, communications, push-notification, analytics, diagnostics, customer support, security, and AI providers.
  • Customer-directed integrations, when a customer or authorised user connects ALFREDx to another system or directs information to be sent to that system.
  • Professional advisers, such as lawyers, auditors, insurers, and financial advisers under appropriate confidentiality duties.
  • Authorities and other parties for legal or safety reasons, where required by law or legal process, or where reasonably necessary to protect rights, safety, security, and property.
  • Transaction participants, in connection with a proposed or completed merger, financing, acquisition, restructuring, or sale of all or part of our business, subject to appropriate confidentiality and data-protection safeguards.

We require third parties that process personal data on our behalf to use it only for authorised purposes and to provide the same or an equivalent level of protection required by this Policy, our contracts, and applicable law. We do not permit our service providers to use Customer Content for their own advertising.

09 / Transfers

International data transfers

ALFREDx is based in Singapore and may use service providers in Singapore, the European Economic Area, the United Kingdom, the United States, India, and other countries identified in our Subprocessor List.

Where personal data is transferred internationally, we use safeguards appropriate to the applicable law. These may include adequacy decisions, the European Commission's Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, contractual and technical supplementary measures, and assessments of the destination and recipient. For transfers from Singapore, we take appropriate steps to ensure a standard of protection comparable to the Singapore PDPA. We apply equivalent contractual and security safeguards where required by other applicable laws.

10 / Retention

Retention

We retain personal data only for as long as reasonably necessary for the relevant purpose, customer agreement, and legal obligations. Our standard retention periods are:

Data categoryStandard retention
Account and profile dataFor the account or customer relationship and up to 90 days after account deletion or termination, unless the customer agreement or law requires otherwise
Customer ContentFor the period selected by the customer or stated in the customer agreement; deleted or returned following valid customer instructions or termination
Backup copies of deleted account data or Customer ContentIsolated from ordinary use and overwritten or deleted through the backup cycle, normally within 90 days
Security, access, and audit logsNormally 12 months, or longer where configured by the customer or reasonably required for security, investigation, legal, or regulatory purposes
Support records and general correspondenceNormally 24 months after resolution or the last interaction
Sales and marketing contact dataUntil you opt out or normally 24 months after the last meaningful interaction
Unsuccessful recruitment recordsNormally 12 months after the relevant recruitment process, unless you consent to longer retention or law requires otherwise
Contracts, invoices, tax, corporate, and legal recordsNormally 7 years, or longer where required by applicable law or a legal hold

We may retain a limited record of a consent, privacy request, account deletion, security incident, or legal matter for as long as reasonably necessary to demonstrate compliance, prevent fraud, resolve disputes, or establish, exercise, or defend legal claims.

When a retention period ends, we securely delete or irreversibly anonymise the information. Aggregated or anonymised information that can no longer reasonably identify an individual may be retained.

11 / Deletion

Account deletion and data deletion

Deleting the ALFREDx app from a device does not delete your ALFREDx account.

If you have an ALFREDx account, you may initiate account deletion:

  • in the mobile app through Settings → Account & Privacy → Delete Account; or
  • through our public account-deletion page at alfredx.com/account-deletion.

You may also request deletion or exercise another privacy right by emailing privacy@alfredx.com. We may take reasonable steps to verify your identity and protect the account from unauthorised deletion.

After a valid account-deletion request, we will delete or de-identify the account profile and associated personal data that we control, subject to the retention periods and exceptions described in this Policy. We will tell you if completion will take additional time and will confirm when the request has been completed.

Where your account is managed by a customer organisation:

  • deleting your user account will end your access to that organisation's workspace;
  • operational records, audit trails, safety records, work orders, or other Customer Content may remain under the customer's control or where retention is required for security, legal, contractual, or regulatory reasons; and
  • we will refer or assist with requests concerning customer-controlled data as required by law and our customer agreement.

Information retained under an applicable exception will be limited, protected from ordinary use, and deleted when the reason for retention ends. Residual copies in backups are removed through the normal backup cycle described above.

You may withdraw optional device permissions through your iOS or Android settings, withdraw cookie consent through Cookie Settings on our website, and unsubscribe from marketing emails through the link in the message. Withdrawing an optional permission or consent will not affect prior lawful processing.

12 / Security

Security

We maintain administrative, technical, and physical safeguards designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Depending on the service and deployment, these safeguards include encryption in transit and at rest, role-based access, least-privilege controls, multi-factor authentication options, tenant separation, logging and monitoring, secure development practices, backups, vulnerability management, incident-response procedures, employee confidentiality obligations, and vendor due diligence.

No method of transmission or storage is completely secure. You are responsible for protecting your credentials, using the Services only through authorised devices and networks, and promptly notifying us or your organisation's administrator of suspected unauthorised access.

13 / Rights

Your rights and choices

Depending on your location and the circumstances, you may have the right to:

  • request access to or a copy of your personal data;
  • request correction of inaccurate or incomplete data;
  • request deletion;
  • restrict or object to certain processing;
  • receive certain data in a portable format;
  • withdraw consent at any time;
  • opt out of marketing;
  • complain to a competent data-protection or supervisory authority; and
  • appeal a decision we make on a privacy request, where applicable.

To exercise a right, email privacy@alfredx.com or use the account-deletion page identified above. We will verify and respond to requests within the period required by applicable law. If we deny a request, we will explain the reason where required. To appeal, reply to our decision or email the same address with the subject "Privacy Request Appeal."

If we process the relevant information solely for a customer organisation, we may direct your request to that customer or assist the customer in responding.

United States state privacy rights

Where an applicable United States state privacy law applies, residents may have rights to know the categories and specific pieces of personal information collected, the sources, purposes, and categories of recipients; to access, correct, delete, or obtain a portable copy; to opt out of sale, sharing, targeted advertising, or certain profiling; to limit certain uses of sensitive personal information; to appeal; and to receive equal service when exercising a right.

ALFREDx does not sell personal information and does not share it for cross-context behavioural advertising or targeted advertising. We will honour legally valid browser-based opt-out preference signals, such as Global Privacy Control, where required. An authorised agent may submit a request where permitted by law, subject to verification of the agent's authority and the individual's identity.

Complaints

You may contact our Data Protection Officer first so that we can try to resolve your concern. You may also complain to your local authority, including the Personal Data Protection Commission in Singapore, a national data protection authority in the EEA, the Information Commissioner's Office in the United Kingdom, or the applicable United States state regulator.

14 / Cookies

Cookies, analytics, and similar technologies

We use strictly necessary cookies and similar technologies to authenticate users, maintain sessions, remember preferences, balance traffic, and protect the Services.

Where permitted, and only after consent where required, we may use analytics technologies to understand website and app performance and usage. We do not use advertising cookies or SDKs for cross-context behavioural advertising.

You can manage non-essential website technologies through our cookie banner and Cookie Settings link. You can also control cookies through your browser, although blocking necessary cookies may prevent parts of the Services from working. Mobile operating-system permissions and SDK disclosures are managed separately from browser cookies and are described in this Policy and in the applicable app-store privacy disclosures.

15 / Children

Children

The Services are business and enterprise services and are not directed to children. Individuals under 18 may not create an ALFREDx account for their own use.

A customer in a healthcare, education, or other authorised setting may process information relating to a minor as Customer Content. In that situation, the customer is responsible for having a lawful basis, providing required notices, obtaining any required parental or guardian consent, and configuring access appropriately. ALFREDx processes that information on the customer's documented instructions and does not use it for advertising.

If you believe a child has created an account or provided personal data directly to us without appropriate authorisation, contact privacy@alfredx.com.

16 / Third parties

Third-party services

The Services may contain links to or integrations with third-party services. A third party's privacy notice governs its own processing. Before enabling an integration, the customer or user should review the third party's terms and privacy practices. We are not responsible for independent processing by a third party that is not acting as our service provider.

17 / Updates

Changes to this Policy

We may update this Policy to reflect changes in the Services, our practices, or applicable law. We will update the "Last updated" date and, where required, provide additional notice through the Services, email, or another appropriate channel. If a change materially affects processing based on consent, we will request new consent where required.

18 / Contact

Contact us

Data Protection Officer
Tamira Technologies Pte. Ltd.
63 Hillview Avenue, #08-04A
Lam Soon Industrial Building
Singapore 669569

Privacy and data-protection enquiries: privacy@alfredx.com
General enquiries: hello@alfredx.com

Singapore residents may also contact the Personal Data Protection Commission at www.pdpc.gov.sg. EEA and UK residents may contact their competent local supervisory authority.