Privacy · Last updated 14 August 2026

Privacy policy

PDPA notice — full text

Reach Drift Wave LLP ("we", "us") operates reachdriftwave.pro and provides brand-heading services from 12 Chapel Road, Singapore. This notice explains how we collect, use, disclose, and protect personal data under the Personal Data Protection Act 2012 (PDPA).

Collection

We collect personal data you provide by email or phone: name, organisation, role, email address, phone number, and message content. We collect technical data through hosting logs: IP address, browser type, pages visited, timestamps. Cookie consent choices are stored locally as described in the cookie notice.

Purpose

We use personal data to respond to enquiries, perform engagements, issue invoices where applicable, comply with law, and improve site security. Marketing mail is sent only with consent or existing client relationship as permitted by law.

Disclosure

We may disclose data to hosting providers, mail processors, professional advisers, and authorities when required by law. We do not sell personal data.

Transfer

Data may be processed outside Singapore when you correspond from abroad or when processors host abroad. We require appropriate protection measures.

Retention

Enquiry mail: up to twenty-four months if no engagement follows. Client records: duration of engagement plus seven years. Consent records: one hundred and eighty days per cookie notice.

Rights

You may request access, correction, withdrawal of consent, or information about policies and complaints. Contact [email protected]. You may lodge a complaint with the Personal Data Protection Commission.

Security

We use access controls, encrypted transport, and vendor review. No method is perfectly secure; we respond to incidents as required by law.

Updates

We may update this notice; the date at top reflects the latest version. Material changes will be noted here.

Children

Our services are directed to business clients. We do not knowingly collect data from individuals under eighteen.

Automated decision-making

We do not use profiling or automated decisions with legal or similarly significant effects.

Do Not Call

We honour Singapore Do Not Call preferences for marketing voice and text where applicable.

Data breach

If a breach likely to cause significant harm occurs, we will notify affected individuals and the Commission as required.

Processors list

Hosting in Singapore; mail transport providers; professional advisers under confidentiality. Updated on request via [email protected].

Consent withdrawal

Withdrawal does not affect prior processing. Some data must be retained for legal obligations after withdrawal.

Accuracy

Please notify us of inaccurate data so we can correct records promptly.

Access procedure

Write with sufficient identity verification. We may charge a reasonable fee for manifestly unfounded or excessive requests as permitted by law.

Cross-border clients

APAC clients corresponding from Malaysia, Indonesia, Hong Kong, or Australia remain protected under the terms here; local mandatory rights may also apply.

Schedule of purposes

(1) Respond to enquiries via mail or phone. (2) Perform contracted heading and governance services. (3) Issue invoices and maintain accounts. (4) Comply with statutory obligations including tax and regulatory requests. (5) Secure the website and investigate abuse. (6) Record cookie consent preferences. (7) Improve internal training using anonymised engagement patterns — never client-identifiable copy without permission.

Schedule of disclosure

Professional advisers bound by confidentiality; hosting and mail processors under contract; courts and regulators when law requires; no advertising networks receive personal data from us.

Overseas recipients

Mail may route through international servers; we assess provider practices and contractual clauses.

Care of data

Access limited to staff who need it; passwords and device policies enforced; vendor review annually.

Complaints

Contact [email protected] first; then PDPC if unresolved.

Version history

Material changes logged here with date. Prior versions available on request.

Marketing opt-out

Reply unsubscribe to marketing mail or write [email protected]. Mooring-related service mail is excluded.

Volunteered attachments

Redact sensitive data before sending unless we agree otherwise in writing.

Research

We do not sell datasets. Internal training uses anonymised patterns only.

Policy requests

Request paper copy of this notice by mail to our Chapel Road address.

We maintain a record of processing activities internally as required by accountability principles under the PDPA. That record includes categories of data subjects, categories of personal data, purposes, disclosures, retention, and safeguards. Summaries are available to clients on request under confidentiality. We train staff who handle personal data on confidentiality and incident reporting annually.

Data protection enquiries from former clients are handled with the same response time as active moorings. Identity verification may be required before we release records. We log requests and responses for accountability.

This notice is reviewed at least annually and when processing changes materially.

Where we rely on legitimate interests, we balance our needs against your rights and provide objection rights where applicable. Objections should cite the specific processing activity. We pause non-essential processing while reviewing objections unless law requires continuation.

Contact [email protected] for any PDPA request; we respond within thirty days.

Data breach notification

We maintain an internal incident register and review it quarterly. If we assess that a breach of personal data in our possession is likely to result in significant harm to affected individuals, we will notify the Personal Data Protection Commission without undue delay and, where practicable, within seventy-two hours of becoming aware of the breach. Affected individuals will receive direct notice when the breach involves their contact details, client documents, or correspondence content — unless notification would compromise an active investigation or is prohibited by law.

Our notification will describe the nature of the breach, the categories of data involved, likely consequences, and measures we have taken or propose to take. We will provide a contact point for further enquiries. Breaches involving encrypted client deliverables where the encryption key was not compromised are assessed individually; we do not treat encryption alone as elimination of harm if metadata or filenames expose sensitive context.

Overseas transfer of personal data

Our primary hosting and mail infrastructure is located in Singapore. However, when you correspond from outside Singapore, your message may transit servers in other jurisdictions before reaching us. When we engage processors who store or process data outside Singapore — for example, international mail transport or cloud backup — we evaluate their data protection practices and require contractual commitments consistent with the PDPA's transfer obligations.

Before transferring personal data overseas, we confirm that the recipient country or the contractual arrangement provides a standard of protection comparable to the PDPA, or we obtain your consent for the transfer where required. Client engagement letters may specify approved transfer routes for document exchange. You may request details of current overseas recipients by writing to [email protected]; we update the list when processors change.

Children's personal data

Our studio services are directed exclusively at business clients and professional correspondents. We do not knowingly collect personal data from individuals under eighteen years of age through this website or through unsolicited enquiry. If a minor submits an enquiry without parental or guardian involvement, we will delete the correspondence upon discovery and will not retain the contact details.

Client materials occasionally reference end users who may include minors — for example, product copy aimed at families. We process such materials solely under the client engagement and do not use them to build profiles of individual children. If you believe we have inadvertently collected a minor's personal data directly from that minor, notify [email protected] and we will delete it promptly unless retention is required by law.

Data controller address

Mon–Sat 09:00–17:00 SGT · +65 6449 2750