Privacy Policy

Last Updated: January 15, 2026

Introduction

clarionto ("we," "our," or "us") is committed to protecting the privacy and security of your personal and financial information. This Privacy Policy explains how we collect, use, store, and protect your data when you use our AI financial assistant services.

We operate in accordance with Singapore's Personal Data Protection Act (PDPA) and maintain strict data protection standards. This policy applies to all services provided by clarionto, including Financial Calendar Coordinator, Healthcare Business Analytics, and Comprehensive Financial Awareness.

For privacy-related inquiries, please contact us at [email protected]

Information We Collect

Personal Information

When you create an account or use our services, we collect the following personal information:

  • Name and contact details (email address, phone number)
  • Business information (for healthcare business clients: practice name, registration details)
  • Account credentials (username, encrypted password)
  • Correspondence and communications with our support team

Financial Data

To provide our AI financial assistant services, we access and process the following financial information with your explicit consent:

  • Bank account information and transaction history
  • Investment account details and holdings
  • Bill payment schedules and recurring expenses
  • Insurance policy information
  • Healthcare revenue data (for healthcare business clients: patient billing, insurance claims, CPF Medisave submissions)
  • Calendar events related to financial obligations

Technical Information

We automatically collect certain technical information when you use our services:

  • Device information (operating system, browser type, device identifiers)
  • IP address and approximate geographic location
  • Usage data (features accessed, time spent, interaction patterns)
  • Log files and error reports for system maintenance

Data Collection Methods

We collect information through:

  • Direct input during account registration and service configuration
  • Secure API connections to your financial institutions (with your authorization)
  • Cookies and similar technologies for service functionality
  • Communications with our customer support team

How We Use Your Information

Service Delivery

We use your information primarily to provide and improve our AI financial assistant services:

  • Monitoring your financial accounts and obligations
  • Learning your financial patterns through machine learning algorithms
  • Generating personalized insights and notifications
  • Creating financial reports and summaries
  • Maintaining service functionality and performance

Legal Basis for Processing

We process your personal data based on:

  • Consent: You provide explicit consent when connecting financial accounts
  • Contract: Processing is necessary to fulfill our service agreement with you
  • Legitimate Interest: We have legitimate interest in improving service quality and preventing fraud
  • Legal Obligation: We comply with applicable laws and regulations in Singapore

Communications

We may use your contact information to send:

  • Service notifications and financial alerts (essential communications)
  • Account updates and security notices
  • Responses to your support inquiries
  • Service updates and feature announcements (you may opt out)

Data Retention

We retain your information for the following periods:

  • Active account data: Duration of your subscription plus 12 months
  • Financial transaction records: 7 years (in compliance with Singapore regulations)
  • Communication logs: 3 years for support quality assurance
  • Technical logs: 90 days for system maintenance

Data Protection & Security

Encryption

All financial data is protected using industry-standard encryption:

  • AES-256 encryption for data at rest in our secure databases
  • TLS 1.3 encryption for data in transit between your device and our servers
  • Encrypted backups with separate encryption keys

Access Controls

We implement strict access controls to protect your information:

  • Multi-factor authentication required for all user accounts
  • Role-based access restrictions for clarionto employees
  • Comprehensive audit logging of all data access
  • Regular access reviews and privilege management

Infrastructure Security

Our technical infrastructure includes:

  • ISO 27001 certified information security management
  • Regular penetration testing by independent security firms
  • Continuous monitoring for security threats
  • Incident response procedures with defined notification protocols

Breach Notification

In the unlikely event of a data breach affecting your personal information, we will:

  • Notify affected users within 72 hours of breach discovery
  • Report to Singapore's Personal Data Protection Commission as required
  • Provide clear information about the nature of the breach and recommended actions
  • Implement immediate measures to prevent further unauthorized access

Data Sharing & Third Parties

Service Providers

We engage limited third-party service providers who may access your data only as necessary to provide services on our behalf:

  • Cloud infrastructure providers (secure hosting)
  • Payment processors (subscription billing only)
  • Banking API aggregators (secure financial account connections)

All third-party providers are bound by strict confidentiality agreements and must comply with data protection standards equivalent to this policy.

No Data Selling

We do not sell, rent, or trade your personal or financial information to any third parties. Your data is never used for advertising purposes or shared with marketing companies.

Legal Disclosures

We may disclose your information when required by law or to:

  • Comply with valid legal process (court orders, subpoenas)
  • Respond to government requests as required under Singapore law
  • Protect our legal rights and prevent fraud or illegal activity
  • Protect the safety and security of users or the public

Cookies & Tracking Technologies

We use cookies and similar technologies to provide and improve our services. For detailed information about our cookie usage, please review our Cookie Policy.

Essential cookies are necessary for service functionality. You may manage optional cookie preferences through our cookie settings, though disabling certain cookies may affect service performance.

Your Privacy Rights

Under Singapore's Personal Data Protection Act, you have the following rights:

Right to Access

You may request a copy of the personal data we hold about you. We will provide this information in a commonly used electronic format within 30 days of your request.

Right to Correction

You may request correction of inaccurate or incomplete personal data. We will update your information promptly upon verification of the corrections.

Right to Erasure

You may request deletion of your personal data. We will comply unless we have a legal obligation to retain certain information. Note that deletion will result in service termination.

Right to Data Portability

You may request transfer of your data to another service provider. We will provide your data in a structured, machine-readable format.

Right to Withdraw Consent

You may withdraw consent for data processing at any time. Withdrawal may limit or prevent our ability to provide certain services.

Right to Object

You may object to processing of your personal data for direct marketing purposes. We will cease such processing upon receiving your objection.

Exercising Your Rights

To exercise any of these rights, please contact us at [email protected] with your request. We may require identity verification before processing your request.

Children's Privacy

clarionto's services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected information from a child, we will delete such information promptly.

Parents or guardians who believe we may have collected information from a child should contact us at [email protected]

International Data Transfers

Your personal and financial data is stored on servers located in Singapore. We do not transfer data outside of Singapore unless required for specific service operations, in which case we ensure adequate data protection measures are in place through:

  • Standard contractual clauses approved by data protection authorities
  • Verification that recipient countries provide adequate data protection
  • Additional security measures for sensitive financial data

Policy Updates

We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. Material changes will be communicated through:

  • Email notification to registered account holders
  • Prominent notice on our website and within our services
  • Updated "Last Updated" date at the top of this policy

Continued use of our services after policy updates constitutes acceptance of the revised terms. If you disagree with changes, you may cancel your subscription.

Contact Information

For questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Data Protection Officer

Email: [email protected]

Phone: +65 6583 2714

Address:
clarionto
10 Collyer Quay, #15-09
Ocean Financial Centre
Singapore 049315

Supervisory Authority: If you believe we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with Singapore's Personal Data Protection Commission at www.pdpc.gov.sg