Orca — Privacy Policy
Effective: August 2026 | Zenkaivo Pte. Ltd. (UEN: 202619515R)
1.Who We Are
Orca is operated by Zenkaivo Pte. Ltd. (UEN: 202619515R), 246 MacPherson Rd #07-02, Betime Building, Singapore 348578. Our Data Protection Officer can be reached at dpo@zenkaivo.com.
2.What Orca Is
Orca is a rule-based business process automation platform (not AI-driven) that connects a client organisation's Sales, Finance, Operations, Inventory, and HR functions through a cascade engine — so that one event (e.g. a deal closing) automatically triggers every downstream action across departments.
3.Data We Process
When your organisation uses Orca, the following categories of data are collected and processed:
- Business transaction data — deals, invoices, jobs, inventory reservations, commissions, financial records, resource allocation
- Employee data (HR module) — names, roles, commission calculations, payroll tracking, utilisation records
- Client-side customer/CRM data connected via Zoho, HubSpot, or custom CRM integrations
- Communications data via WhatsApp Business, Outlook, and Teams integrations (message metadata and content required to trigger automations)
- User account and login data for client staff accessing the Orca dashboard
4.Why We Process This Data
- To automate cross-departmental business processes and eliminate manual handoffs
- To trigger real-time actions (invoicing, job creation, stock reservation, commission accrual) from a single event
- To provide a live operations dashboard and exceptions queue for the client's operator
- To connect with the client's existing tools (CRM, accounting, email) without requiring replacement
5.Data Controller & Processor Relationship
For most data processed through Orca, the client organisation is the Data Controller and Zenkaivo acts as the Data Processor, processing data strictly on the client's instructions under the Service Agreement. Zenkaivo assists clients in fulfilling their own PDPA obligations to their employees and customers.
6.Who Can Access the Data
- Authorised staff of the client organisation, based on their assigned role and department
- Zenkaivo platform administrators, for technical support and maintenance only
- No cross-client data sharing — each client's data is logically isolated
7.Third-Party Systems & Data Sharing
We do not sell or rent data. Data may pass through the following infrastructure and connectors:
- Google Firebase / Firestore — secure cloud database (project: orca-d0423)
- Cloudflare Worker proxy — for WhatsApp, email, and Teams automation routing
- Client-authorised third-party connectors — Xero, QuickBooks, Zoho, HubSpot, Gmail/Outlook (only where the client has enabled the integration)
8.Data Retention
Data is retained for the duration of the client's active Service Agreement. Upon contract termination, client data is deleted within 90 days unless a longer period is required by law or agreed in writing. Clients may request earlier deletion by contacting the DPO.
9.Data Subject Rights
- Client organisations may request access, correction, or export of their data at any time
- Client organisations are responsible for handling data subject requests from their own employees/customers, with Zenkaivo's assistance as processor
- Any individual believing their data has been mishandled may contact our DPO directly
10.Security Measures
- All data encrypted in transit (HTTPS/TLS)
- Role-based access control per department
- Firestore security rules restrict cross-client data access
- Authentication required for all dashboard access
- Connector tokens (WhatsApp, CRM, accounting) stored securely and rotated periodically
11.Data Breach Notification Commitment
In the unlikely event of a data breach affecting your personal data, Zenkaivo will act promptly to contain the incident and will notify affected individuals and/or the Personal Data Protection Commission (PDPC) where required under the Personal Data Protection Act 2012. Our internal response procedures are governed by a dedicated Data Breach Response SOP maintained by our Data Protection Officer.
12.Contact & Complaints
For any privacy concerns, contact our DPO: dpo@zenkaivo.com
You may also lodge a complaint with the Personal Data Protection Commission (PDPC) Singapore at pdpc.gov.sg.
PULSE — Privacy Policy
Effective: August 2026 | Zenkaivo Pte. Ltd. (UEN: 202619515R)
1.Who We Are
PULSE is operated by Zenkaivo Pte. Ltd. (UEN: 202619515R), 246 MacPherson Rd #07-02, Betime Building, Singapore 348578. Our Data Protection Officer can be reached at dpo@zenkaivo.com.
2.What PULSE Is
PULSE is an industry-agnostic enterprise operations platform, built for businesses of any size or sector. It brings job and order tracking, invoicing, profit & loss, live balance sheet, and document generation into a single connected system — replacing scattered spreadsheets, WhatsApp threads, and manual back-office work with one source of truth for the entire operation.
3.Data We Process
When your organisation uses PULSE, the following categories of data are collected and processed:
- Business operational data — jobs, orders, projects, schedules, and their status history
- Customer and contact master data — company name, UEN, contact person, email, phone, address, credit terms
- Financial documents — invoices, billing records, profit & loss and balance sheet data (no general ledger fields are collected)
- Operational documents generated per job — order forms, confirmations, and other business documents
- User account and audit trail data — staff login records, actions taken, and IP address, for security and accountability purposes
4.Why We Process This Data
- To digitise and coordinate business operations end-to-end, for any industry, replacing manual paper- and spreadsheet-based processes
- To generate accurate, job-linked invoicing and business documentation automatically
- To maintain a real-time profit & loss and balance sheet view of the business
- To maintain an auditable record of who accessed or changed what data, and when
5.Data Controller & Processor Relationship
The client organisation using PULSE is the Data Controller for the business and customer data it inputs into the platform. Zenkaivo acts as the Data Processor, processing data strictly per the client's instructions under the Service Agreement, and assists the client in meeting its own PDPA obligations.
6.Who Can Access the Data
- Authorised staff of the client organisation, based on role-based module access
- Zenkaivo platform administrators, for technical support and maintenance only
- Audit trail records (including IP address) are visible only to designated administrators
7.Third-Party Systems & Data Sharing
We do not sell or rent data. Data may pass through the following infrastructure and connectors:
- Google Firebase / Firestore — secure cloud database, with each client's data logically isolated in dedicated collections
- No data is sold, rented, or shared with unrelated third parties
- Documents generated within PULSE (invoices, order confirmations) may be transmitted by the client to their own customers or partners as part of normal business operations
8.Data Retention
Data is retained for the duration of the client's active Service Agreement and in line with standard business record-keeping requirements under Singapore law. Upon contract termination, data is retained or deleted per the terms agreed with the client. Clients may request earlier deletion of specific records by contacting the DPO, subject to statutory record-keeping obligations (e.g. accounting records).
9.Data Subject Rights
- Client organisations may request access, correction, or export of their operational data at any time
- Client organisations are responsible for handling requests from their own customers/agents whose contact data is held in PULSE, with Zenkaivo's assistance as processor
- Any individual believing their data has been mishandled may contact our DPO directly
10.Security Measures
- All data encrypted in transit (HTTPS/TLS)
- Role-based module access — staff only see modules relevant to their function
- Full audit trail on every create/update/delete action, including IP address logging
- Authentication required for all dashboard access
- Hard-delete actions require typed confirmation to prevent accidental data loss
11.Data Breach Notification Commitment
In the unlikely event of a data breach affecting your personal data, Zenkaivo will act promptly to contain the incident and will notify affected individuals and/or the Personal Data Protection Commission (PDPC) where required under the Personal Data Protection Act 2012. Our internal response procedures are governed by a dedicated Data Breach Response SOP maintained by our Data Protection Officer.
12.Contact & Complaints
For any privacy concerns, contact our DPO: dpo@zenkaivo.com
You may also lodge a complaint with the Personal Data Protection Commission (PDPC) Singapore at pdpc.gov.sg.
Stella — Privacy Policy
Effective: August 2026 | Zenkaivo Pte. Ltd. (UEN: 202619515R)
1.Who We Are
Stella is operated by Zenkaivo Pte. Ltd. (UEN: 202619515R), 246 MacPherson Rd #07-02, Betime Building, Singapore 348578. Our Data Protection Officer can be reached at dpo@zenkaivo.com.
2.What Stella Is
Stella is a paediatric-first therapy coordination platform connecting therapists, children, and parents/guardians — used to coordinate therapy sessions, track developmental progress, and enable secure communication between a child's care team and their family.
3.Data We Process
When your organisation uses Stella, the following categories of data are collected and processed:
- Child's name, date of birth, diagnosis or developmental profile
- Therapy goals, session notes, progress records, and milestone data
- Behavioural observations and exercise completion records
- Parent and therapist communications within the platform
- Parent/guardian name, contact details, and login credentials
This platform processes data relating to a minor (child under 18). Registration requires confirmation that the registrant is the parent or legal guardian of the child.
4.Why We Process This Data
- To coordinate therapy sessions between therapist, child, and parent
- To track developmental progress over time
- To enable therapist–parent communication within the platform
- To generate progress reports for the child
5.Data Controller & Processor Relationship
Zenkaivo Pte. Ltd. is the Data Controller for data collected directly through Stella's consumer-facing platform. Parents/guardians provide consent on behalf of their child at registration, as set out in Section 9 below.
6.Who Can Access the Data
- The therapist(s) directly assigned to the child
- The registered parent or legal guardian
- Zenkaivo platform administrators, for technical support only
- No other therapists, parents, or third parties can view a child's records
7.Third-Party Systems & Data Sharing
We do not sell or rent data. Data may pass through the following infrastructure and connectors:
- Google Firebase / Firestore — secure cloud database (project: stella-9d0db)
- Google Apps Script — email notification delivery
- We do not sell or rent any child or parent data
8.Data Retention
We retain a child's data for 3 years from the date of last active session or account activity, after which all records are permanently deleted. Parents may request earlier deletion at any time.
9.Data Subject Rights
- Access — request a copy of all data held about your child
- Correction — request correction of inaccurate records
- Erasure — request permanent deletion of your child's data at any time
- Withdraw consent — withdraw consent for data processing; this will require account closure
10.Security Measures
- All data encrypted in transit (HTTPS/TLS)
- Authentication required for all access
- Session auto-expires after 20 minutes of inactivity
- Administrative access logged via audit trail
11.Data Breach Notification Commitment
In the unlikely event of a data breach affecting your personal data, Zenkaivo will act promptly to contain the incident and will notify affected individuals and/or the Personal Data Protection Commission (PDPC) where required under the Personal Data Protection Act 2012. Our internal response procedures are governed by a dedicated Data Breach Response SOP maintained by our Data Protection Officer.
12.Contact & Complaints
For any privacy concerns, contact our DPO: dpo@zenkaivo.com
You may also lodge a complaint with the Personal Data Protection Commission (PDPC) Singapore at pdpc.gov.sg.