Legal Document
Privacy Policy
Effective date: 18 February 2026 · Last updated: 18 February 2026
This policy describes how zivantoes collects, uses, and handles personal data in connection with our legal advisory services. It is written to be read by ordinary people, not only legal professionals.
1. Introduction
zivantoes ("we", "us", "our") is a legal advisory firm based in Singapore. We are committed to handling personal data with care and in accordance with the Personal Data Protection Act 2012 (PDPA) of Singapore.
This Privacy Policy applies to personal data collected through our website, email communications, and in the course of providing our legal services. By engaging with us or using our website, you acknowledge the practices described here.
If you have questions about how we handle your data, you are welcome to contact us before submitting any information.
2. Personal Data We Collect
We collect personal data in a limited and purposeful manner. The categories of data we may collect include:
- Identity information: name, as provided in an enquiry or engagement
- Contact information: email address, phone number, and postal address where relevant
- Matter-related information: details about your legal situation that you share with us voluntarily
- Technical data: IP address, browser type, and pages visited (via analytics cookies, if consented)
- Communication records: emails or messages exchanged in connection with a matter
We collect this data in the following ways: directly from you via our website contact form, by email, by telephone, or in person. We do not purchase contact lists or collect personal data from third-party marketing sources.
Legal bases for processing under the PDPA: consent (for website enquiries and analytics), contractual necessity (for active client engagements), and legitimate interests (for internal records and service improvement).
3. How We Use Your Personal Data
We use personal data only for the purposes for which it was collected. These include:
- Responding to enquiries submitted via our contact form or by email
- Providing legal advisory services to clients who have engaged us
- Maintaining accurate records of matters handled
- Sending administrative communications related to an engagement (e.g. invoices, updates)
- Improving the usability of our website using anonymised analytics data
- Complying with applicable laws, court orders, or regulatory requirements
We do not use personal data for automated decision-making or profiling. We do not send promotional emails unless you have specifically requested updates from us.
4. Sharing of Personal Data
We do not sell, rent, or trade personal data. We may share personal data only in the following limited circumstances:
- Professional obligations: where required by law, court order, or a regulatory authority
- Service providers: trusted third parties who assist us in operating our website or business (e.g. email hosting, accounting software), bound by confidentiality obligations
- Opposing or related parties: only to the extent necessary and instructed by you in the course of a legal matter
Where data is transferred to a third-party service provider, we take reasonable steps to ensure that they provide comparable levels of data protection.
International transfers: Our primary data processing occurs within Singapore. Where service providers are based outside Singapore, we ensure appropriate contractual protections are in place.
5. Retention of Personal Data
We retain personal data for as long as reasonably necessary for the purpose it was collected, or as required by applicable law. General retention guidelines:
- Website enquiries (no engagement): up to 12 months from initial contact
- Client matter records: up to 7 years following conclusion of the matter, in line with standard professional practice
- Financial records: 5 years, as required under Singapore law
- Analytics data: retained in aggregated, anonymised form; individual session data not stored beyond 26 months
After applicable retention periods, data is securely deleted or anonymised.
6. Security Measures
We take reasonable and appropriate steps to protect personal data from unauthorised access, disclosure, alteration, or destruction. Measures in place include:
- TLS encryption for data transmitted via our website and email
- Access controls limiting personal data to personnel who require it
- Regular review of data handling practices
- Secure disposal of physical documents containing personal data
In the event of a data breach that poses a significant risk of harm to affected individuals, we will notify the Personal Data Protection Commission (PDPC) and affected individuals in accordance with the Notifiable Data Breach obligations under the PDPA.
No method of electronic transmission or storage is entirely without risk. While we take this responsibility seriously, we cannot guarantee absolute security.
7. Cookies and Tracking Technologies
Our website uses cookies to function correctly and to understand how visitors interact with our content. Cookies are small text files stored on your device by your browser.
- Essential cookies: required for the website to operate (e.g. session management). These cannot be disabled.
- Analytics cookies: used to understand visitor behaviour in aggregate. Enabled only with your consent.
- Marketing cookies: used for advertising personalisation. Enabled only with your consent.
- Preference cookies: remember settings you have chosen. Enabled only with your consent.
You can manage your cookie preferences at any time by visiting our Cookie Policy page. You may also control cookies through your browser settings.
8. Your Rights Under the PDPA
As an individual whose data we hold, you have the following rights:
- Access: to request a copy of the personal data we hold about you
- Correction: to request that inaccurate or incomplete data be corrected
- Withdrawal of consent: to withdraw consent you have given, subject to legal or contractual restrictions
- Data portability: to request that data provided by you be transferred in a structured, machine-readable format where technically feasible
- Objection: to object to processing based on legitimate interests where you have grounds to do so
To exercise any of these rights, please contact us at [email protected]. We will respond within 30 calendar days. In some cases we may need to verify your identity before processing a request.
If you have concerns about how we handle your data that we have not resolved to your satisfaction, you may lodge a complaint with the Personal Data Protection Commission Singapore at www.pdpc.gov.sg.
9. External Links
Our website may contain links to external websites or resources. Once you leave our site, this Privacy Policy no longer applies. We encourage you to review the privacy policies of any external sites you visit. We are not responsible for the content or data practices of third-party websites.
10. Children's Privacy
Our legal services are directed at individuals aged 18 and over. We do not knowingly collect personal data from individuals under the age of 18. If you believe a minor has submitted personal data to us, please contact us at [email protected] so that we can take appropriate steps to remove it.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the services we offer. When we do, we will revise the "Last updated" date at the top of this page.
If changes are material, we will take reasonable steps to bring them to your attention — for example, by displaying a notice on our website. Continued use of our website or services after any update constitutes acceptance of the revised policy.
12. Contact — Data Protection Enquiries
For any questions, concerns, or requests relating to your personal data, please reach out to us directly: