Pangolin Intelligence Pte. Ltd. · UEN 202551205W

Privacy Policy

Pangolin Intelligence Pte. Ltd. (“Pangolin Intelligence”, “we”, “us” or “our”) is committed to protecting the personal data of individuals in accordance with the Personal Data Protection Act 2012 of Singapore (“PDPA”). This Privacy Policy explains how we collect, use, disclose, store and protect personal data in the course of our business. “Personal data” means data about an individual who can be identified from that data, or from that data together with other information we have or are likely to have access to.

It applies to personal data we handle through our website, pangolinintelligence.com, our services, consulting engagements, events, communications and related interactions (together, the “Services”).

Effective date: 10 September 2026

Company details

Pangolin Intelligence Pte. Ltd. (UEN 202551205W)
Registered office: 160 Robinson Road #14-04, Singapore 068914

1) What personal data we collect

A. Personal data you provide

  • Name, email address and phone number
  • Company or organisation name, job title and business contact details
  • Information you send us by email or other communications (for example enquiries, meeting notes and support requests)
  • Billing and invoicing details and payment-related information, where applicable
  • Any other information you choose to provide

B. Technical data processed when you visit our website

Our website is a static site hosted by Netlify, Inc. When you visit it, Netlify's servers process the technical information needed to deliver pages and protect the service, such as your IP address, browser and device type, the pages requested, the referring page and the time of access, and keep this information in server logs for a limited period. We do not use analytics, advertising or tracking technologies on the website, and the website does not set cookies (see Section 10).

C. Personal data from third parties

  • Business contact details from our clients, partners, service providers, referrals or public sources, where permitted
  • Risk and integrity signals shared by partners for security and abuse-prevention purposes, where applicable and permitted

2) Purposes: how we use personal data

We may collect, use and disclose personal data for one or more of the following purposes:

  • Providing the Services, including delivering consulting work, reports, briefings and requested outputs
  • Responding to enquiries, communicating with you and providing support
  • Managing business relationships with clients, vendors and partners
  • Contracting and administration, including onboarding, invoicing, payments, accounting and audits
  • Security and misuse prevention, including maintaining the integrity and security of our systems and services
  • Improving our Services, including troubleshooting, quality assurance and internal process improvement
  • Marketing and updates about our Services, where permitted and subject to your preferences
  • Legal and regulatory compliance, including responding to lawful requests and managing risk
  • Any other purpose that we notify you of at the time of collection, unless an exception under the PDPA applies

Where required under the PDPA, we will obtain your consent to collect, use or disclose your personal data. In certain situations the PDPA permits collection, use or disclosure without consent, including for specific legitimate interests, investigations, legal, security and business improvement purposes. Where we rely on such exceptions, we do so in accordance with the PDPA.

You may withdraw your consent at any time (see Section 11). Withdrawal of consent may affect our ability to provide some Services.

4) Data processing for risk intelligence and compliance

To detect, assess and prevent fraud, money-laundering typologies, scams and the abuse of partner platforms, we may process personal data in reliance on the legitimate interests exception and/or the investigations exception under the PDPA, where applicable. This processing is conducted as part of our risk intelligence and security consulting services and is based on online research and collaboration with clients and partners, rather than offline surveillance or fieldwork.

Where we rely on the legitimate interests exception, we conduct a legitimate interests assessment to consider necessity and proportionality and to balance our interests against the individual's interests. A summary is available on request.

Data categories

We may process public blockchain data, network identifiers (for example IP addresses and device or browser signals) and identity information (for example KYC attributes provided by partners, or identity details available from public sources where permitted) to provide risk intelligence, security advisory and platform integrity services. While on-chain transaction data is publicly accessible, when we link blockchain activity to an identifiable individual, for example through partner-provided information or other permitted sources, we treat that linked information as personal data and apply the protections described in this Policy.

5) How we disclose personal data

We may disclose personal data to:

  • Service providers (data intermediaries) that process data on our behalf, such as web hosting, email, collaboration tools, billing and payment processors, under contractual confidentiality and security obligations
  • Professional advisers, such as lawyers, auditors and accountants
  • Clients and partners, where disclosure is necessary to deliver the Services or as instructed or authorised, and where permitted
  • Regulators, law enforcement or authorities, where required or permitted by law
  • A successor entity in connection with a merger, acquisition, reorganisation or sale of assets, subject to applicable safeguards

We do not sell personal data.

6) Accuracy

We take reasonable steps to ensure that personal data we use or disclose is accurate and complete, especially where it may affect you or our Services. Please notify us if your information changes.

7) Protection and security

We implement reasonable security arrangements to protect personal data from unauthorised access, collection, use, disclosure, copying, modification, disposal or similar risks. Measures include access controls, encryption where appropriate, secure configuration and monitoring. In the event of a data breach, we have procedures in place to assess the incident and, where required, notify the Personal Data Protection Commission (PDPC) and affected individuals in accordance with the PDPA.

To report a security vulnerability affecting our website or services, please email security@pangolinintelligence.com.

8) Retention

We retain personal data only for as long as it is necessary to fulfil the purposes for which it was collected, or as required or permitted by applicable law. When personal data is no longer needed, we securely delete or anonymise it.

Accounting and tax records: where personal data forms part of our business and accounting records, we generally retain those records for at least 5 years in line with Singapore tax record-keeping requirements.

9) Transfers outside Singapore

We may transfer personal data outside Singapore, for example when using cloud service providers or sharing deliverables with clients and partners located overseas. Our website hosting provider and some of our other service providers store data outside Singapore, including in the United States and the European Union. Where we transfer personal data outside Singapore, we take steps to ensure that the recipient is bound by legally enforceable obligations to provide a standard of protection comparable to that under the PDPA.

10) Cookies and similar technologies

Our website does not set cookies and does not use analytics, advertising or other tracking technologies. For this reason we do not display a cookie consent banner. The only automatic processing when you visit the website is the server logging by our hosting provider described in Section 1B.

If we introduce cookies or analytics in future, we will update this Policy and, where the PDPA requires it, notify you of the purposes and obtain your consent before they are used.

11) Your rights: access, correction and withdrawal of consent

Subject to the PDPA, you may request to:

  • access personal data we hold about you and information about how it has been used or disclosed in the past year,
  • correct inaccurate or incomplete personal data, and/or
  • withdraw consent for certain uses or disclosures, where applicable.

We may need to verify your identity before processing your request. We aim to respond to access and correction requests within 30 days; if we need longer, we will tell you when to expect a response. Where permitted under the PDPA, we may charge a reasonable fee for access requests and will inform you before any fee applies.

If you are not satisfied with how we have handled your personal data or a request, you may also lodge a complaint with the Personal Data Protection Commission of Singapore.

12) Marketing preferences

Where we send you marketing communications, you may opt out at any time by using any unsubscribe mechanism provided or by contacting us using the details below.

13) Contact us (Data Protection Officer)

If you have questions, requests or complaints about this Privacy Policy or our handling of personal data, please contact our Data Protection Officer:

Data Protection Officer
Pangolin Intelligence Pte. Ltd. (UEN 202551205W)
Email: privacy@pangolinintelligence.com
Registered office: 160 Robinson Road #14-04, Singapore 068914

Information about our personal data protection policies and practices, including how we handle complaints, is available on request.

14) Changes to this Privacy Policy

We may update this Privacy Policy from time to time. The updated version will be published on our website or otherwise made available to you, and will take effect from the stated effective date.