Singapore PDPA Notice
Singapore-specific information about how Gerai collects, uses, discloses, protects, retains, and responds to requests concerning personal data.
1. Scope and organisation
This notice supplements Gerai’s Privacy Policy with information relevant to Singapore’s Personal Data Protection Act 2012 (PDPA). Gerai is a product of World Council for AI PTE. LTD., a Singapore company with UEN 202412852R.
It applies to personal data handled through Gerai’s corporate website, merchant platform, Gerai-powered storefronts, and related communications. Under the PDPA, personal data generally means data about an individual who can be identified from that data alone or with other information to which an organisation has or is likely to have access.
Some business contact information used solely for business purposes may be treated differently under the PDPA. Gerai nevertheless aims to handle corporate contact information responsibly and only for relevant business purposes.
2. Roles and personal data
| Category | Examples | Typical source |
|---|---|---|
| Contact and business data | Name, work details, organisation, role, enquiry, and correspondence | You, your organisation, or a person introducing you |
| Merchant account data | Account identifiers, contact details, permissions, settings, and access records | The merchant and its authorised users |
| Catalogue and media | Product information, files, images, pricing, and availability | The merchant |
| Buyer and order data | Contact, delivery, cart, order, payment-status, and fulfilment information | The buyer, merchant, and licensed payment service |
| Technical and operational data | IP address, request details, browser or device information, and diagnostic or security events | Generated through use of Gerai |
3. Purposes
Gerai may collect, use, or disclose personal data for purposes that include:
- responding to enquiries and discussing merchant onboarding or partnerships;
- creating, administering, authenticating, and securing merchant access;
- building and operating storefronts, catalogues, carts, and order workflows;
- routing buyer order information to the relevant merchant;
- connecting order records with limited payment references and statuses;
- supporting fulfilment communications and resolving technical issues;
- operating, diagnosing, improving, and protecting Gerai;
- detecting fraud, abuse, unlawful activity, and security threats;
- complying with law, legal process, and regulatory obligations; and
- establishing, exercising, or defending legal rights.
If Gerai wishes to use personal data for a materially different purpose that is not already permitted by law or reasonably connected to the original purpose, Gerai will provide any additional notification or seek any consent that the PDPA requires.
4. Consent and notification
Gerai seeks to notify individuals of relevant purposes at or before collection, through this notice, the Privacy Policy, merchant storefront notices, forms, account flows, and transaction context. Depending on the circumstances, personal data may be handled with consent, as reasonably needed to provide a requested service or respond to an enquiry, under an applicable PDPA exception, or as otherwise permitted or required by law.
A merchant is responsible for obtaining any consent and providing any notification required for its own collection and use of buyer data. Supplying data to Gerai does not cure a merchant’s failure to meet those obligations.
Consent can be withdrawn for future use or disclosure by contacting Gerai or, for a merchant-controlled buyer purpose, the merchant. Withdrawal does not undo processing that was lawful before withdrawal. Gerai or the merchant will explain any likely consequences; some data is necessary to operate an account, process an order, meet a legal duty, protect security, or resolve a dispute.
5. Disclosure and payments
Personal data may be disclosed, as relevant to the purpose and legal context, to:
- the merchant from whom a buyer places an order and that merchant’s authorised users;
- service providers supporting Gerai’s infrastructure, communications, security, diagnostics, or operations;
- licensed payment services involved in a transaction;
- professional advisers and legitimate counterparties under appropriate duties;
- a successor or proposed successor in a legitimate corporate transaction; and
- public authorities, regulators, courts, or other recipients where disclosure is lawfully required or permitted.
Gerai does not state a fixed public provider list because providers can depend on the merchant engagement and service scope. Procurement teams can request current, relevant information through the Data Processing Addendum page.
6. Overseas processing
Gerai serves Southeast Asia and personal data may be accessed or processed outside Singapore. The countries involved can vary with the service configuration, merchant, payment option, and provider used. This public notice therefore does not claim a universal storage country or provide a fixed country list that may not apply to every engagement.
Where the PDPA’s transfer limitation obligation applies, Gerai will take steps required in the circumstances so that transferred personal data receives a standard of protection comparable to that under the PDPA. Merchants with specific location or transfer requirements should raise them before onboarding so they can be assessed and, where agreed, documented.
7. Accuracy, protection, and retention
Accuracy
Gerai takes reasonable steps to use accurate and complete personal data where it is likely to make a decision affecting an individual or disclose the data to another organisation. Merchants, buyers, and account users should provide accurate information and notify the relevant party when it changes.
Protection
Gerai uses reasonable technical and organisational measures appropriate to the nature and context of the data to protect against unauthorised access, collection, use, disclosure, copying, modification, disposal, or similar risks. We do not publish unverified encryption standards, certification claims, audit claims, or absolute security guarantees.
Retention
Gerai ceases to retain personal data, or removes the means by which it can be associated with an individual, when it is reasonable to conclude that the purpose is no longer served and retention is no longer necessary for legal or business purposes. The relevant period varies according to data type, merchant instructions, account and order status, security needs, disputes, and legal requirements. No universal fixed period is stated where one has not been verified.
8. Access, correction, and withdrawal
Subject to the PDPA’s requirements and exceptions, an individual may ask Gerai for access to personal data in Gerai’s possession or control and information about how it was used or disclosed within the applicable period. An individual may also ask Gerai to correct an error or omission.
Send the request to hello@gerai.shop with a subject such as “PDPA access request”, “PDPA correction request”, or “withdraw consent”. Include enough information to identify the person, account, storefront, order, or enquiry and describe the data concerned. Do not email unnecessary identity documents.
Gerai may ask for proportionate verification before disclosing or changing data. A request may be limited where the PDPA permits or requires that result, including to protect another person, privileged material, confidential commercial information, an investigation, or a legal obligation. If a fee is lawfully chargeable for an access request, Gerai will explain it before proceeding rather than state an invented standard fee here.
For buyer information controlled by a merchant, contact the merchant first. Gerai may refer the request to that merchant or assist it as the organisation responsible for the sales purpose.
9. Marketing and browser storage
Gerai does not use the Services as permission to send unlawful marketing. Where Singapore’s Do Not Call provisions or another marketing rule applies, the sender is responsible for checking and complying with it, identifying itself, and respecting a valid opt-out. Operational messages about an enquiry, account, order, security issue, or service are distinct from promotional messages.
Gerai storefronts use functional localStorage named gerai-cart to retain a buyer’s cart. Gerai uses server-side operational analytics, not browser analytics cookies or advertising cookies. There is no fake cookie-consent control for technologies Gerai does not deploy. See the Cookie and Browser Storage Notice.
10. AI-assisted features
Gerai may use narrow, labelled AI-assisted features for defined commerce tasks. They are fallible and can produce incorrect or incomplete output. Live-shop material is subject to human review, and matters requiring judgement or an exception should be escalated to a person.
Gerai does not describe these features as making significant legal or practical decisions about individuals without human involvement. If an AI-assisted interaction concerns you and appears wrong, identify the interaction when contacting the merchant or Gerai. Read the AI Transparency Notice.
11. Incidents and complaints
Gerai assesses suspected personal-data incidents to understand what happened, contain risk, preserve relevant information, and determine whether notification to the Personal Data Protection Commission or affected individuals is required. This page does not promise a response time beyond what applicable law requires.
Raise a privacy concern with Gerai first so it can be investigated. If you remain dissatisfied, you may contact Singapore’s Personal Data Protection Commission through its official website at pdpc.gov.sg. A merchant-controlled buyer issue may also need to be raised with that merchant.
12. Contact and updates
Gerai’s public data-protection contact is hello@gerai.shop. Use this address for PDPA requests, questions, complaints, and notices. Mail may be addressed to:
World Council for AI PTE. LTD.Attention: Data Protection
1 Paya Lebar Link, #04-01
Paya Lebar Quarter
Singapore 408533
Gerai may update this notice when the Services, law, or data practices change. The effective and last-updated dates above identify the current public version. Where a change requires additional notification or consent, Gerai will address that requirement in the relevant context.
Legal review notice
This published document explains Gerai’s current approach and intended practices. It does not constitute legal advice to the reader. Gerai recommends obtaining advice from a qualified lawyer about the laws and contractual requirements that apply to your circumstances.