Data protection

Privacy
Policy

This policy explains what personal data we collect through this website, why we collect it, how long we keep it, and what rights you have. It applies to the EU General Data Protection Regulation (GDPR) and the Singapore Personal Data Protection Act (PDPA).

Last updated: August 2026  ·  Version 1.1

1. Who is responsible

The controller responsible for the processing of personal data on this website, within the meaning of Article 4(7) GDPR and as the organisation responsible under the PDPA, is:

ControllerAISIVEN PTE LTD
RegistrationUEN 202518397K, Singapore
Address68 Circular Road, #02-01
Singapore 049422
Contact for data mattersleo@aisiven.com

We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 GDPR. Data protection enquiries should be sent to the address above and will be handled by the CEO.

2. What data we collect

This section covers the public website. If you hold access to our Deal Portal, additional data is processed there — see section 3.

2.1 Data you actively provide

When you submit the accreditation request form on our Projects page, we collect the information you enter:

Category Data Required
Identity First name, last name Yes
Professional Company or institution, position, company website Company and position: yes. Website: no.
Contact Business email address, telephone number Email: yes. Telephone: no.
Location Country of residence or domicile Yes
Request content Investor or counterparty category, areas of interest, regions of interest, free-text description of your request Category and description: yes. Others: no.
Declarations Confirmation of qualified status, acknowledgement of the NDA process, consent to data processing Yes

If you contact us by email instead, we process the data contained in your message together with your email address and any information in your signature.

2.2 Data collected automatically

When you visit this website, our hosting provider automatically records technical information in server log files. This is standard for all web servers and is necessary for the site to function and remain secure. These logs typically contain:

We do not merge this data with other data sources and we do not use it to identify individual visitors.

2.3 Spam prevention

To protect the accreditation form against automated abuse, we apply a rate limit per IP address. Your IP address is processed for this purpose in irreversibly hashed form only; the original address is not stored. The hashed value is deleted automatically after one hour.

3. The Deal Portal

Separately from this website, we operate a password-free access portal at /portal for counterparties whose accreditation we have approved. If you have not been granted access to it, nothing in this section applies to you.

3.1 How signing in works

The portal does not use passwords. To sign in, you enter your email address and we send you a link that works once and expires after fifteen minutes. We therefore never store a password for you, and no password of yours can be exposed through us.

Access is granted individually. Your email address is placed on an internal list by us after your accreditation has been reviewed and a confidentiality agreement executed. If an address is not on that list, no link is sent. For your protection, the sign-in page shows the same message either way, so that the form cannot be used by third parties to discover who holds access.

3.2 What we hold about portal users

Category Data Why
Access record Email address, name, company or institution, internal notes, the date access was granted, and any expiry date set To operate the access list and to know who we have admitted and on what basis
Agreement record Date a confidentiality agreement was signed and the date it expires To confirm that materials are only shared under a valid agreement
Sign-in tokens A one-time link, stored only as an irreversible hash, together with its expiry To let you sign in without a password. Deleted once used or expired
Activity record Date and time of each sign-in, each sign-in link requested, each document downloaded and which document it was, and each sign-out See 3.3 below
Technical IP address, processed only as an irreversible hash to limit repeated requests, deleted after one hour To protect the portal against automated abuse

3.3 The download record — please read this

We record which documents you download and when. We do this because the material in the portal belongs to third parties who have entrusted it to us under confidentiality agreements, and we must be able to demonstrate to them who has seen it. This is a condition of our being able to show you anything at all.

The record contains your email address, the document, and the time. It does not track how long you spent reading, what you did afterwards, or anything you do outside the portal. It is visible only to us, is not shared for marketing or analytics, and is not used to profile you or to make any automated decision about you.

Where an asset holder asks us to account for who has received their material, we may disclose that you accessed it. That disclosure is the purpose the record exists for, and it is the basis on which the material can be made available in the first place.

3.4 Legal basis and retention for portal data

Purpose Legal basis (GDPR) Retention
Operating your portal access Art. 6(1)(b) — performance of, or steps prior to, a contract For as long as access is granted, then 24 months
Sign-in links Art. 6(1)(b) — necessary to provide the access you requested Deleted on use, or after 15 minutes
Download and activity record Art. 6(1)(f) — our legitimate interest, and that of the asset holders we act for, in being able to evidence who received confidential material Up to 24 months, or longer where a transaction or dispute requires it
Abuse prevention Art. 6(1)(f) — legitimate interest in protecting our systems 1 hour (hashed IP only)

You may object to processing based on our legitimate interests under Article 21 GDPR. In the case of the download record, we are likely to have compelling grounds to continue, because the record is what allows us to account to the parties whose material you accessed. If you would prefer that no such record exists, the alternative is not to access the material.

3.5 Ending your access

You can ask us to withdraw your portal access at any time by writing to leo@aisiven.com. Withdrawal takes effect immediately and ends any open session. Your access record and the activity record are retained for the periods stated above, because confidentiality obligations and our accountability to asset holders survive the end of access.

4. What we do not collect

The public website uses no cookies, no analytics or tracking, no advertising pixels, and no social media plug-ins. We do not create user profiles and we do not track behaviour across sessions or websites. This is why no cookie consent banner is shown: there is nothing to consent to.

The Deal Portal sets a single session cookie, without which signing in would not be possible. It is strictly necessary within the meaning of Article 5(3) of the ePrivacy Directive, requires no consent, contains no identifier that can be used to track you elsewhere, and is deleted when you sign out or the session expires.

5. Why we process your data and on what legal basis

Purpose Legal basis (GDPR) Basis (PDPA)
Assessing and responding to your accreditation request Art. 6(1)(b) — steps prior to entering into a contract; and Art. 6(1)(a) — your consent Consent under s. 13
Responding to general enquiries by email Art. 6(1)(f) — our legitimate interest in answering enquiries directed to us Deemed consent under s. 15
Operating and securing the website; server logs Art. 6(1)(f) — legitimate interest in a functioning, secure website Legitimate interests exception
Preventing automated abuse of the contact form Art. 6(1)(f) — legitimate interest in protecting our systems Legitimate interests exception
Retaining correspondence to meet legal and regulatory obligations Art. 6(1)(c) — compliance with a legal obligation Legal obligation exception

6. Who receives your data

Data submitted through this website is delivered to an internal AISIVEN email address and is accessible only to those members of our organisation who need it to assess and respond to your request.

We do not sell personal data, and we do not share it with third parties for their own marketing purposes. Data may be disclosed to the following categories of recipient:

Where your request concerns an investment opportunity, we may be required to carry out identity verification and anti-money-laundering checks before any further information is shared. If so, we will inform you separately at that point about any additional processing involved.

7. International transfers

AISIVEN PTE LTD is established in Singapore. If you access this website from the European Economic Area and submit data to us, that data will be transferred to and processed in Singapore.

Singapore has not received an adequacy decision from the European Commission under Article 45 GDPR. Such transfers therefore take place on the basis of your explicit consent pursuant to Article 49(1)(a) GDPR, or because the transfer is necessary for the performance of a contract or pre-contractual steps taken at your request pursuant to Article 49(1)(b) GDPR.

Singapore maintains a comprehensive data protection framework under the PDPA, overseen by the Personal Data Protection Commission. We apply the protections described in this policy to all personal data we hold, regardless of where the data subject is located.

8. How long we keep your data

Data Retention period
Accreditation requests that do not lead to a business relationship 24 months from last contact, then deleted
Accreditation requests that lead to a business relationship Retained for the duration of the relationship and thereafter as required by applicable commercial, tax, and anti-money-laundering law
General email correspondence 24 months from last contact, unless a longer retention obligation applies
Server log files As determined by our hosting provider, typically no longer than 30 days
Hashed IP addresses used for rate limiting 1 hour
Deal Portal access records For as long as access is granted, then 24 months
Deal Portal download and activity record Up to 24 months, or longer where a transaction or dispute requires it

Retention specific to the Deal Portal is set out in full in section 3.4.

9. Your rights

If the GDPR applies to the processing of your data, you have the following rights:

Under the PDPA, you have the right to request access to personal data we hold about you and information about how it has been used or disclosed in the past year, and the right to request correction of inaccurate data.

To exercise any of these rights, contact us at leo@aisiven.com. We will respond within one month, or within 30 days for PDPA access requests. We may need to verify your identity before acting on a request.

10. Is providing data mandatory?

Providing personal data is entirely voluntary. However, the fields marked as required in the accreditation form are necessary for us to assess your request. If you do not provide them, we will not be able to process the request. There is no other consequence to withholding data.

11. Automated decision-making

We do not use automated decision-making or profiling within the meaning of Article 22 GDPR. Every accreditation request is reviewed by a person, and access to the Deal Portal is granted by a person on the basis of that review. The activity record described in section 3.3 is not used to score, rank, or draw inferences about you.

12. Data security

This website is served exclusively over an encrypted TLS connection (HTTPS), which protects data in transit between your browser and our server. We apply appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.

No method of transmission over the internet is entirely secure. While we take reasonable measures to protect your data, we cannot guarantee absolute security.

13. Changes to this policy

We may update this policy to reflect changes in our practices or in applicable law. The version in force is the one published on this page, identified by the date shown at the top. Material changes affecting how we process data already collected will be notified to affected individuals where we hold contact details for them.

14. Contact

For any question about this policy or about how we handle personal data, write to leo@aisiven.com, or by post to AISIVEN PTE LTD, 68 Circular Road, #02-01, Singapore 049422.