隐私政策 · Privacy Policy
How personal data is used, protected and retained, and how to make a rights request.
Responsible organisation and contact
OCEANGO PTE. LTD. (UEN: 202612964M; registered address: 68 Circular Road, #02-01, Singapore 049422) is responsible for personal data processing for this website and its Singapore services. For privacy questions, access, correction, withdrawal of consent or deletion requests, contact our data protection officer at dpo@oceango.sg. The data protection officer is currently the sole handler of privacy requests, with no backup handler. We aim to acknowledge receipt within one business day; this is not a promise to complete every request within that time. General enquiries go to hello@oceango.sg.
Data and purposes
Browsing this information website does not require registration or document submission. Serving pages, maintaining security and diagnosing faults may involve the website and its infrastructure processing IP addresses, browser information, access times and request logs; cookie-free analytics may also process visit data. When you contact us by email or an external messaging service, we receive the name, contact details, enquiry and subsequent correspondence you provide, to respond, understand your needs, arrange agreed services and handle complaints. Do not send identity documents or detailed children's information in an initial enquiry.
This website has no registration, form or upload facility of its own; this does not mean that no personal data is processed. External communication platforms also process data under their own policies. If a later service requires additional data, its categories, purposes and applicable notice will be explained before collection. Initial contact is not consent to unrestricted uses.
Consent, choices and accuracy
We explain collection, use and disclosure purposes and obtain consent where required; other processing permitted or required by law may apply separately. Contact the DPO to withdraw consent. We will explain reasonable notice and service implications and stop subsequent processing that depends on that consent. Data subject to a legal retention duty or another lawful basis may not be deleted as a result. Please help correct outdated or inaccurate information; we take reasonable steps to check accuracy before using data to make a decision or disclosing it.
Recipients and overseas processing
Authorised personnel with a work-related need and service providers supporting hosting, security, email or agreed services may process data for the relevant purposes. Before a referral to a professional provider, we explain the recipient and purpose and obtain consent where needed; data is not an unrestricted customer list. Disclosures required by law are handled separately.
Before transferring data outside Singapore, we check applicable requirements and recipient safeguards and take measures to provide the protection required by applicable law. Additional notice or consent required for a transfer will be addressed beforehand. Service-specific notices explain their applicable data flows; this paragraph does not replace them.
Protection, retention and incidents
We take reasonable, risk-proportionate security measures to restrict access and protect against unauthorised access, disclosure, loss or alteration. Data is securely deleted or anonymised when its purposes and legal or business retention needs no longer require it. Disputes and legal retention obligations may require some records to be retained. We do not apply a universal indefinite retention period.
Enquiry leads that have not become clients are retained for 24 months from the last meaningful interaction. Spam or material with no business value is deleted within 30 days, with a monthly cleanup. Necessary records for enquiries that become clients follow separately explained service retention arrangements, without indefinite duplicate retention. Any extension for a legal hold or dispute is documented with a reason and review date.
Our retention policy for raw access logs is 30 days. Confirmed security-incident evidence is reviewed after 90 days for continued necessity. Statistics not requiring individual identification are retained only in aggregate. If an infrastructure provider has a different minimum retention period, the applicable arrangements will be explained.
For a data security incident, we assess and contain it and notify the relevant authority and affected individuals where applicable law requires. Suspected incidents can be reported to the DPO.
Access, correction, deletion and complaints
You may request access to your data and legally required information about its use or disclosure, seek correction, withdraw consent or request deletion. We reasonably verify the requester's identity and explain the process, any applicable fees and legal exceptions. We do not request account passwords or one-time codes by ordinary email. Deletion is not an unrestricted right; we explain applicable retention grounds. See Data Deletion Requests. If dissatisfied, raise a complaint with the DPO; you may also contact Singapore's Personal Data Protection Commission (PDPC).
Children and sensitive documents
For children's data, we verify guardian identity and authority and obtain required consent under applicable requirements. A general website enquiry does not replace a service-specific collection notice. Submit formal sensitive documents only through a separately arranged, controlled Client Portal channel, not through WeChat, WhatsApp or ordinary email.
OceanGo does not request or store Singpass, Corppass, banking, securities or government account passwords, one-time codes or account recovery codes. Clients operate those accounts themselves.
Updated: 2026-10-08