Elitez EOR

Privacy Notice

How we collect, use, store and protect personal data under Singapore's Personal Data Protection Act 2012 (PDPA).

Last updated: 29 May 2026 · Effective: 29 May 2026

1. Who we are

This service ("Elitez EOR", "we", "us") is operated by Elitez Group of Companies, a Singapore-incorporated entity. Our Data Protection Officer (DPO) can be reached at [email protected].

2. Scope

This notice covers personal data we process when:

3. Personal data we collect

CategoryExamplesSource
Business representativeName, work email, mobile, role, IP addressYou
Company identifiersUEN, registered address, contact phoneYou + ACRA records you upload
KYC documentsACRA bizfile (PDF), director's NRIC scanYou
Employee personal dataNRIC/FIN, full name, DOB, address, bank, CPF, salaryThe client business (acting as authorised employer)
Operational logsAudit log (sign-in events, document uploads, admin actions), IP, user-agentAutomatic

4. How we use it

5. Legal basis under PDPA

We rely on consent (explicit at signup), legitimate interests (account security and fraud prevention), and statutory obligations (CPF Act, Income Tax Act, Employment Act). Your consent can be withdrawn — see Section 9.

6. Sharing

We disclose personal data only to:

We do not sell personal data. We do not transfer data outside Singapore for marketing or analytics.

7. Cross-border transfers

All primary data is stored in Singapore (Supabase region ap-southeast-1). Some sub-processors (e.g. Resend) may transit data across regions for email delivery — these processors are contractually bound to PDPA-equivalent protections under our Data Processing Agreement.

8. Retention

Data classRetention
Active account data (profile, tenant, employees)For the life of the contract + 7 years (statutory)
KYC documents7 years from contract end (AML/PDPA)
Payroll records (CPF, IR8A, payslips)5 years from year-end (IRAS)
Audit logs (sign-in, admin actions)3 years
OTP codes (transient)10 minutes (auto-purged)

9. Your rights (data subject)

Under PDPA you may request:

Email [email protected] with subject line "PDPA data request". We respond within 30 calendar days.

10. Security

11. Breach notification

If a notifiable data breach occurs (per PDPA s.26B), we notify affected users and the PDPC within 72 hours of confirming the breach.

12. Changes

Material changes to this notice are emailed to the registered address of every active tenant 14 days before they take effect.

13. Contact

Data Protection Officer
Elitez Group of Companies
Email: [email protected]

If you are not satisfied with our response, you may contact the Personal Data Protection Commission of Singapore: pdpc.gov.sg.