Privacy

eXAI Partners Privacy Notice

Effective date: 30 September 2026

eXAI Partners Pte. Ltd. ("eXAI Partners", "eXAI", "we", "us" or "our") is a Singapore company. This Privacy Notice explains how we collect, use, disclose, protect and retain personal data when you interact with exai.partners, use website features that we make available, contact us, participate in a public eXAI Coach experience, submit an enterprise enquiry or qualified-lead brief, or use future account, subscription or purchase features that are expressly enabled on the website.

This notice is intended to support our obligations under Singapore's Personal Data Protection Act 2012 ("PDPA") and our information-security management programme. It does not state or imply that eXAI Partners is ISO certified, that every future processing activity is already live, or that a feature shown as unavailable has been activated.

1. Who is responsible for your personal data

eXAI Partners Pte. Ltd. is responsible for personal data in its possession or under its control.

Data Protection Officer

Data Protection Officer: Alex Tan
Business email: alex@exai.partners
General company contact: contact@exai.partners
Location: Singapore

The DPO contact is for questions, requests or complaints about how eXAI Partners handles personal data.

2. What personal data we may collect

Depending on how you interact with us, we may collect the following categories.

A. Information you provide directly

This may include:

  • your name;
  • role or job title;
  • company or organisation;
  • official work email address;
  • LinkedIn profile, if you choose to provide it;
  • messages, questions or other information you send to us;
  • an Executive Problem Brief or other structured information that you review and choose to share;
  • preferences or follow-up interests you expressly provide;
  • account profile information if account features are later enabled;
  • billing contact and transaction-related information if commercial features are later enabled.

Some work contact information may constitute "business contact information" under the PDPA. Where the PDPA applies to personal data we handle, we apply this notice and our applicable data-protection practices.

B. Public Coach/session information

If and when the public eXAI Coach is enabled, we may process:

  • the problem statement and context you provide;
  • limited conversation/session state needed to provide the experience;
  • the structured brief generated from the session;
  • your edits, review and confirmation of that brief;
  • an opaque session reference and minimum security/audit metadata.

Please do not submit customer or policyholder data, private Advisor conversations, confidential insurer datasets, unreleased production data, passwords, secrets, payment-card details or other sensitive information that is not required for the public Coach experience.

The raw public Coach conversation is not included in the ordinary qualified-lead payload by default. Our intended production design is to minimise durable application-level retention of raw public Coach conversation content. Raw content may still be processed transiently to provide the service and may be subject to necessary provider/security logging where disclosed and governed.

C. Technical and security information

When you use our website, our hosting, delivery and security systems may process limited technical information such as:

  • IP address and network information;
  • browser and device information;
  • requested pages, timestamps and referring information;
  • security, abuse-prevention and rate-limit signals;
  • error and diagnostic information.

We use this information to operate, secure and troubleshoot the website and services, prevent misuse and maintain evidence required for security and incident response.

D. Payment information

If and when payment features are enabled, payments will be handled through our approved hosted/tokenised payment provider. eXAI Partners may receive transaction status, transaction references, billing/contact information and limited payment metadata needed to manage the transaction, subscription, refund or support request.

We do not intend to store full payment-card details in eXAI application systems.

3. Why we collect, use or disclose personal data

We may process personal data for purposes that include:

  • providing and operating our website and enabled services;
  • providing the public Coach experience where enabled;
  • generating, displaying and allowing you to review/edit a structured Executive Problem Brief;
  • responding to enquiries and conducting enterprise follow-up that you have expressly requested or submitted;
  • creating and administering accounts, subscriptions or purchases where enabled;
  • processing and reconciling transactions, refunds or billing support where enabled;
  • securing our systems, preventing abuse, investigating errors and responding to incidents;
  • maintaining records needed for audit, accountability, legal or contractual obligations;
  • responding to access, correction, consent-withdrawal, complaint or other data-protection requests;
  • improving our services using appropriately minimised, aggregated or de-identified information where reasonably practicable;
  • complying with applicable law, regulatory requirements and lawful requests.

We do not treat submission of an enterprise brief as bundled consent for unrelated newsletters, case studies, model training or general marketing. If we seek consent for a separate purpose, we will present it separately where required.

4. Notification, consent and choices

Where the PDPA requires notification, we will notify you of the relevant purposes on or before collecting, using or disclosing your personal data.

Where consent is required, we will seek consent in a manner appropriate to the context. In some circumstances, the PDPA permits collection, use or disclosure without fresh express consent, including where a statutory exception or other permitted basis applies.

You may withdraw consent for a purpose by contacting our DPO. We will explain the likely consequences of withdrawal and will stop the affected processing where required, subject to applicable legal, regulatory, security, contractual or legitimate record-keeping requirements.

5. Qualified-lead review and sharing

Before a qualified enterprise lead is sent to eXAI, the website must show you:

  • the identity/contact fields that will be shared;
  • the exact structured brief that will be shared;
  • the enterprise follow-up purpose;
  • a statement that the raw Coach conversation is not included by default;
  • a link or reference to this Privacy Notice; and
  • a clear affirmative share/submit action.

Editing a brief, entering an email address, opening a lead form or abandoning a session does not by itself create a qualified-lead record.

6. AI and automated processing

Where AI-supported features are enabled, they are used to support an interactive working experience, generate or structure content, and help frame business questions.

The public Coach is not intended to make decisions about you that have legal or similarly significant effects. It does not create insurer authentication, tenant membership or access to private insurer data merely because you provide a work email or company name.

Before live AI processing is enabled, eXAI will govern the actual provider/model route, data-use/training settings, retention/logging, processing region, access controls, abuse controls and failure behaviour.

7. How we disclose personal data

We may disclose personal data only where reasonably necessary for the stated purposes, including to:

  • hosting, cloud, security and infrastructure service providers;
  • AI/model service providers where an AI feature is expressly enabled;
  • data/storage providers where persistence is expressly enabled;
  • communications, CRM or enterprise-follow-up providers where approved and enabled;
  • payment providers where commercial features are enabled;
  • professional advisers, auditors or insurers where reasonably necessary;
  • regulators, law-enforcement bodies, courts or other authorities where required or permitted by law;
  • a successor entity in a genuine corporate restructuring, merger or sale, subject to appropriate protections.

We require service providers handling personal data for us to be subject to appropriate contractual, security and data-protection controls according to the nature of the service and risk.

We do not sell personal data.

8. Overseas transfers

Some service providers may process or store personal data outside Singapore.

Where the PDPA's Transfer Limitation Obligation applies, we take steps designed to ensure that transferred personal data receives a standard of protection comparable to that required under the PDPA, using appropriate contractual, organisational and technical measures and supplier due diligence.

We will not publish a claim about a specific processing region, transfer mechanism or provider configuration unless that production configuration is actually governed and evidenced.

9. Retention

We retain personal data only for as long as the purpose for which it was collected continues to be served, or as required for legal, regulatory, security, contractual or legitimate business purposes.

For the public Coach / enterprise-lead flow, the current governed defaults are:

  • unsubmitted public Coach session/draft state: transient, with a design target of expiry after 30 minutes of inactivity and an absolute session boundary no longer than 24 hours once the production store is enabled;
  • raw public Coach conversation: no durable application-level retention by eXAI by default; transient processing and necessary provider/security logging may still occur according to the actual governed production configuration;
  • approved qualified-lead record: normally up to 12 months from the latest substantive eXAI/lead interaction, unless it converts into another separately governed customer/contractual relationship or a documented legal/contractual need requires longer retention;
  • security/audit records: retained only for a period justified by security, incident, audit or legal needs and kept separate from the ordinary business lead record where appropriate;
  • billing, tax or contractual records: retained for the applicable legal, accounting, tax or contractual period.

When retention is no longer justified, we will delete, anonymise or otherwise remove the means of associating the data with an identifiable individual where required and reasonably practicable.

10. Security

We maintain administrative, organisational and technical safeguards designed to protect personal data against unauthorised access, collection, use, disclosure, copying, modification, disposal, loss or similar risks.

Our information-security programme is managed through documented governance, access control, supplier management, secure development, incident response, risk management, logging/monitoring and continual-improvement practices aligned to our active ISO/IEC 27001:2022 programme.

No security measure can guarantee absolute security. We therefore use risk-based controls, monitor for issues and improve controls as our systems and processing change.

11. Data incidents

We maintain processes to assess and respond to suspected personal-data or information-security incidents.

Where a data breach is notifiable under the PDPA, we will notify the Personal Data Protection Commission and/or affected individuals as required by applicable law.

12. Access and correction

Subject to the PDPA and applicable exceptions, you may request:

  • access to personal data about you that is in our possession or under our control and information about how it has been used or disclosed during the applicable period; and
  • correction of an error or omission in personal data about you that is in our possession or under our control.

We may need to verify your identity before acting on a request and may decline or limit a request where permitted by law.

13. Withdrawal, deletion and complaints

You may contact our DPO to:

  • withdraw consent where applicable;
  • ask a question about our data-protection practices;
  • make an access or correction request;
  • request deletion or anonymisation where applicable;
  • raise a complaint or concern.

A deletion request is not an absolute right under every circumstance. We may need to retain information where required or permitted by law, for security/incident evidence, dispute handling, contractual obligations or other legitimate purposes.

14. Children

Our public website and enterprise services are directed to business professionals and are not designed for children.

If you believe a child has provided personal data to us inappropriately, contact our DPO.

15. Third-party sites and services

Our website may link to third-party websites or services. Their privacy practices are governed by their own notices and terms.

Where a third party acts as our service provider, we manage that relationship through our supplier and security/privacy governance. Where a third party acts independently, its own privacy practices apply.

16. Changes to this Privacy Notice

We may update this notice when our services, processing, suppliers, legal requirements or controls change.

Material changes will be reflected through an updated effective date and, where appropriate, additional notice.

The current approved version should remain publicly accessible from the website and from the qualified-lead review/share journey.

17. Contact us

For privacy and data-protection matters:

Data Protection Officer — Alex Tan
eXAI Partners Pte. Ltd.
Email: alex@exai.partners
General contact: contact@exai.partners
Singapore