Governance · Compliance
Privacy Policy &
PDPA Governance
Last Updated: 28 June 2026 · LUMORA AI PTE. LTD. (UEN: 202451613D)
[01] · Policy sections
1. Introduction
Lumora (referred to as "we", "us", or "our") is operated by LUMORA AI PTE. LTD., an exempt private company limited by shares registered in Singapore (UEN: 202451613D). We are committed to protecting the privacy, confidentiality, and security of personal data in accordance with the Singapore Personal Data Protection Act 2012 (PDPA).
This Privacy Policy governs the collection, use, disclosure, and processing of personal data provided by visitors, prospects, and clients who interact with our marketing website, consultation tools, and automated pipelines.
2. Compliance with PDPA Principles
We adhere strictly to the core obligations mandated by the PDPA:
- Consent Obligation: We collect, use, or disclose personal data only with your explicit consent (e.g., when you opt-in to WhatsApp alerts or submit a lead form).
- Purpose Limitation: Personal data is processed solely for the specific intent disclosed at intake (e.g., scheduling a consultation or providing automated audit briefs).
- Notification Obligation: We inform users of the purpose for data collection at or before the time of intake.
- Security Obligation: We implement strict technical guardrails to prevent unauthorized access, alteration, or disclosure of data.
3. Data Collection and Retention
We collect personal data that you voluntarily submit to us, including:
- Name, email address, corporate phone number, and company name.
- Estimated operational parameters entered in the Interactive ROI Calculator.
- Historical chat messages exchanged with our simulated qualification widgets.
We retain personal data only for as long as necessary to fulfill the business and operational purposes for which it was collected, or to comply with Singapore legal frameworks.
4. Secure AI Processing and Sandboxing
When we build and run custom lead qualification tools and AI integrations, client data safety is our priority:
- Zero Model Training: We enforce direct API configurations (e.g., via OpenAI, Anthropic, or Make.com) where your internal files, transcripts, and customer profiles are **never** utilized for LLM model training.
- Local Data-Hosting: We align data flows with your local compliance policies, ensuring customer information remains sandboxed and protected under enterprise-grade transit encryptions.
5. Data Protection Officer (DPO)
If you have questions regarding our data policies, wish to withdraw your consent for data processing, or require access/correction of your personal data records, please contact our designated Data Protection Officer: