Last updated: MAY 01, 2026

In this Privacy policy, "we," "us," and "our" mean SUPPRESSED PTE. LTD. "You" and "your" mean the person whose personal information we process. The "customer" means the person or entity that accesses, orders, pays for, or uses the services.

This Privacy policy explains what personal information we collect, how we use it, when we disclose it, how long we retain it, how we restrict access to it, and what privacy rights and choices may be available to you.

Scope

This Privacy policy applies to personal information processed through:

  1. our website;
  2. our waitlist;
  3. account registration and authentication;
  4. subscription, billing, and payment workflows;
  5. customer support and operational communications;
  6. exposure discovery;
  7. data broker, search engine, public source, and suppression workflows;
  8. validation and monitoring workflows;
  9. security, fraud prevention, abuse prevention, and service diagnostics;
  10. AI-assisted classification, triage, automation, and workflow support.

This Privacy policy does not apply to third-party websites, data brokers, search engines, public records, external sources, or other services that we do not own or control. Their own privacy policies and terms may apply.

Where we process Customer Personal Data, as defined in the Data processing addendum, as a processor or sub-processor on behalf of a customer, the Data processing addendum applies. Where we process Account Data, Usage Data, billing data, support communications, direct consumer service data, website data, or operational data as an independent controller, this Privacy policy applies.

Personal information

"Personal information" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an identified or identifiable person.

Personal information may include direct identifiers, account information, contact information, online identifiers, public records, source records, profile information, household information, business affiliation information, billing information, support communications, usage data, and other information processed through the services.

Information you provide

We may collect personal information that you provide directly to us, including:

CategoryExamples
Contact informationName, email address, phone number, mailing address, billing address, company name, role, and communication preferences.
Account informationAccount email, authentication events, account settings, plan details, support records, and service preferences.
Waitlist informationEmail address, signup information, interest signals, communications, and launch-related preferences.
Billing informationBilling name, billing contact details, invoice records, subscription status, payment status, tax records, and transaction metadata.
Suppression workflow dataNames, aliases, addresses, phone numbers, email addresses, family or household links, business affiliations, public profiles, URLs, screenshots, source records, search results, broker listings, and suppression instructions.
Verification and authority informationInformation or documents used to verify identity, authority, relationship, representation, or permission to submit a request.
Support and communicationsMessages, requests, feedback, call notes, issue details, attachments, screenshots, and other information you send to us.
Legal and compliance informationPrivacy requests, consent records, opt-out records, contractual records, dispute records, and regulatory or legal correspondence.

You should only provide personal information that is accurate, necessary, and lawful for us to process.

If you submit personal information about another person, you are responsible for ensuring that you have appropriate authority, consent, notice, permission, or another lawful basis to do so.

Information collected automatically

When you access the website or services, we may collect technical and operational information automatically, including:

  1. IP address;
  2. browser type and version;
  3. device type;
  4. operating system;
  5. pages viewed;
  6. referring page;
  7. timestamps;
  8. service logs;
  9. authentication events;
  10. session information;
  11. error reports;
  12. security events;
  13. diagnostic data;
  14. cookie and privacy preference records.

This information is used to operate, secure, maintain, troubleshoot, and improve the website and services.

By default, the website does not use advertising cookies, cookie-based analytics, pixel tags, or local storage for cross-context behavioral advertising. For more information, review our Cookie policy.

Information from third parties

We may receive personal information from third parties where reasonably necessary to provide, validate, secure, support, or operate the services, or where otherwise appropriate for an authorized service, security, legal, or operational purpose, including:

  1. data brokers;
  2. search engines;
  3. public sources;
  4. cached pages;
  5. archives;
  6. business registries;
  7. public records;
  8. customers, account owners, or Authorized Users;
  9. payment processors;
  10. infrastructure, authentication, email, monitoring, and support providers;
  11. vendors or service providers involved in suppression, validation, automation, security, or operational workflows;
  12. other third parties you authorize or instruct us to interact with.

Information received from third parties may be incomplete, inaccurate, outdated, duplicated, or inconsistent. We use reasonable operational processes to support the services, but we do not control third-party records, source data, indexing behavior, or republication.

How we use personal information

We use personal information for the following purposes:

PurposeDescription
Provide the servicesCreate accounts, manage subscriptions, operate the platform, provide customer support, and deliver service functionality.
Exposure discoveryIdentify, analyze, classify, and document personal exposure across relevant sources.
Suppression workflowsPrepare, submit, manage, validate, and document opt-out, suppression, deletion, deindexing, correction, and removal requests.
Validation and monitoringVerify source changes, monitor re-indexing, identify regenerated exposure, and maintain workflow records.
Customer instructionsProcess information according to customer instructions, plan scope, account settings, and applicable agreements.
Billing and paymentsProcess subscriptions, invoices, payment status, taxes, accounting records, payment disputes, and billing support.
Authentication and account securityAuthenticate users, manage sessions, prevent unauthorized access, and protect accounts.
CommunicationsSend service messages, account notices, billing notices, support responses, status updates, legal notices, and other operational communications.
Security and abuse preventionDetect, prevent, investigate, and respond to fraud, misuse, unauthorized access, service abuse, security incidents, and policy violations.
Legal complianceComply with law, legal process, tax obligations, regulatory obligations, dispute resolution, and rights requests.
Service improvementMaintain, debug, measure, improve, and develop the services, systems, workflows, and operational processes using personal information only where reasonably necessary. Where practical, we use deidentified, aggregated, or minimized information for improvement and development.
MarketingSend marketing communications where permitted by law and your communication preferences.

We may use deidentified, aggregated, or statistical information for operational analysis, service improvement, security, benchmarking, product development, and reporting, provided it does not identify you and is not reasonably capable of being used to re-identify you.

We do not use deidentified, aggregated, or statistical information to publish customer-specific exposure profiles, identify individual customers, or disclose customer-level suppression activity.

Where applicable law requires a legal basis for processing, we may rely on one or more of the following legal bases:

  1. performance of a contract with you;
  2. steps taken before entering into a contract;
  3. your consent;
  4. our legitimate interests or the legitimate interests of a customer or third party;
  5. compliance with legal obligations;
  6. establishment, exercise, or defense of legal claims;
  7. protection of vital interests where applicable;
  8. another lawful basis available under applicable law.

Our legitimate interests may include operating and securing the services, preventing misuse, improving workflows, supporting customers, managing business operations, enforcing agreements, and communicating about relevant services.

You may have the right to object to processing based on legitimate interests depending on where you live.

Access controls and zero-trust operations

We apply access controls designed to limit access to personal information to personnel, contractors, service providers, and systems that need access for an authorized service, security, support, compliance, or operational purpose.

We do not permit unrestricted internal access to personal information submitted through the services. Human access to Customer Data is limited to authorized personnel and contractors where reasonably necessary to provide the services, perform suppression workflows, provide support, investigate security or abuse issues, comply with law, enforce agreements, or maintain service integrity.

Where practical, we use least-privilege permissions, role-based access controls, logging, monitoring, encryption, and segregation of duties to reduce unnecessary access to personal information.

Zero-trust does not mean that no system, personnel member, contractor, or service provider can ever process personal information. It means access is restricted, verified, limited to appropriate purposes, and governed by security and confidentiality controls.

AI-assisted workflows

We may use AI-assisted workflows to support classification, triage, source analysis, automation, prioritization, drafting, quality control, and suppression operations.

AI-assisted workflows are used to support operational work. They do not replace customer instructions, access controls, legal review where required, or operational oversight.

AI-assisted workflows are configured to process personal information only where reasonably necessary for the relevant service, workflow, security, support, or operational purpose.

Unless you expressly agree otherwise, we do not use personal information submitted through the services to train public foundation models.

Third-party AI providers may process personal information only as described in the Sub-processors standard, the Data processing addendum, and applicable service configuration, and only where required to support the relevant workflow, security, support, or operational purpose.

Cookies and privacy choices

We may use strictly necessary cookies, local storage, or similar technologies to operate, secure, authenticate, route traffic, prevent abuse, and remember privacy choices.

Analytics cookies, marketing measurement cookies, personalized marketing cookies, and cross-context behavioral advertising technologies are not enabled by default.

You can manage applicable privacy choices through the privacy controls made available on the website. Browser controls may also allow you to delete or block cookies and local storage.

For more information, review our Cookie policy.

How we disclose personal information

We may disclose personal information as described below.

RecipientPurpose
Service providers and sub-processorsHosting, database, authentication, storage, billing, email, monitoring, support, automation, AI-assisted workflows, security, and operational services, subject to confidentiality, security, and processing obligations appropriate to their role.
Data brokers, search engines, public sources, and third-party websitesSubmission, management, verification, or validation of suppression, opt-out, deletion, deindexing, correction, or removal workflows.
Payment processorsBilling, payment processing, subscriptions, invoices, taxes, fraud prevention, and payment disputes.
Customer administrators or Authorized UsersAccount administration, customer support, access management, service management, and workflow visibility.
Professional advisersLegal, accounting, audit, insurance, risk, compliance, and corporate governance purposes.
Authorities and legal partiesCompliance with law, legal process, regulatory requests, court orders, investigations, safety, rights enforcement, or dispute resolution.
Corporate transaction partiesEvaluation or completion of a merger, acquisition, financing, reorganization, sale of assets, change of control, or similar transaction.
Third parties you authorizeWhere you instruct, authorize, or consent to disclosure.

We require service providers and sub-processors to process personal information for the relevant service purpose and subject to appropriate confidentiality, security, and processing obligations.

Current provider roles are listed in the Sub-processors standard.

Sale, sharing, and targeted advertising

We do not sell personal information for money.

By default, we do not use advertising cookies, cookie-based analytics, pixel tags, local storage, or similar technologies for cross-context behavioral advertising.

Where privacy laws define "sale," "sharing," or "targeted advertising" more broadly, you may have the right to opt out of those activities. You can use the privacy controls on the website to record or confirm your opt-out choice.

Because sale, sharing, targeted advertising, personalized marketing, and cross-context behavioral advertising are not enabled by default, submitting an opt-out does not change advertising or analytics cookie behavior on this website.

We do not knowingly sell or share personal information of children.

Sensitive personal information

The services may process sensitive personal information where necessary to provide the services, including contact details, addresses, public record data, family or household links, business affiliations, identity verification information, or other sensitive exposure data.

We use sensitive personal information only for purposes reasonably necessary to provide and secure the services, comply with law, manage customer instructions, prevent misuse, and support related operational purposes.

We do not use sensitive personal information to infer characteristics for advertising purposes.

International processing and transfers

We are based in Singapore and use service providers that may process personal information in Singapore, Switzerland, the United States, the European Economic Area, and other locations where we or our providers operate.

Where required by applicable law, we use appropriate safeguards for international transfers, which may include data processing agreements, standard contractual clauses, transfer risk assessments, vendor due diligence, contractual protections, or other lawful transfer mechanisms.

Provider roles and relevant processing locations are described in the Sub-processors standard.

Retention

We retain personal information for as long as reasonably necessary for the purposes described in this Privacy policy, unless a longer retention period is required or permitted by law.

Retention periods depend on the type of information, service context, legal requirements, customer instructions, account status, operational need, security need, and dispute risk.

We aim to retain personal information in identifiable form only for as long as it remains reasonably necessary for the relevant service, legal, security, compliance, dispute, or operational purpose.

We may retain information to:

  1. provide the services;
  2. maintain account records;
  3. validate suppression outcomes;
  4. monitor regenerated exposure;
  5. maintain suppression evidence and workflow history;
  6. comply with tax, accounting, legal, and regulatory obligations;
  7. resolve disputes;
  8. enforce agreements;
  9. prevent fraud, abuse, and unauthorized access;
  10. maintain backups and business continuity records.

Deleted information may remain in backups, logs, archives, or business records for a limited period before deletion or overwriting, unless longer retention is required or permitted by law.

Security

We use technical and organizational measures designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access.

Security measures include, as applicable to the relevant system or workflow, encryption in transit, encryption at rest where supported by infrastructure providers, access controls, least-privilege practices, logging, monitoring, provider review, internal procedures, and incident response processes.

No method of transmission, storage, hosting, or processing is completely secure. We cannot guarantee that personal information will never be accessed, disclosed, altered, or destroyed by unauthorized persons.

For more information, review our Security standard.

Your privacy rights

Depending on where you live, you may have rights to:

  1. access personal information;
  2. receive a copy of personal information;
  3. correct inaccurate personal information;
  4. delete personal information;
  5. restrict processing;
  6. object to processing;
  7. withdraw consent;
  8. port personal information;
  9. opt out of marketing communications;
  10. opt out of sale, sharing, targeted advertising, or certain profiling where applicable;
  11. limit certain uses of sensitive personal information where applicable;
  12. appeal a decision where applicable;
  13. lodge a complaint with a privacy regulator or supervisory authority.

These rights may be subject to legal limits, exceptions, verification requirements, and retention obligations.

To exercise privacy rights, contact:

priv@suppressed.com

We may ask you to verify your identity before fulfilling a request. If you make a request through an authorized agent, we may require proof of authorization and may also require you to verify your identity directly where permitted by law.

If your request relates to personal information processed on behalf of a customer, we may refer the request to that customer or respond according to the customer's instructions.

Marketing communications

You may opt out of marketing emails by using the unsubscribe link in the email or by contacting us.

Even if you opt out of marketing communications, we may still send service, account, billing, security, legal, transactional, or administrative messages.

Regional privacy disclosures

European Economic Area, United Kingdom, and Switzerland

If you are located in the European Economic Area, United Kingdom, or Switzerland, you may have rights under applicable data protection laws, including access, correction, deletion, restriction, portability, objection, withdrawal of consent, and complaint rights.

Where we process personal data as a controller, you may exercise rights by contacting us at:

priv@suppressed.com

Where we process personal data as a processor or sub-processor on behalf of a customer, the customer is generally responsible for responding to rights requests, and we will assist as required by the Data processing addendum and applicable law.

California and other United States state privacy rights

Depending on your state of residence, you may have rights to know, access, correct, delete, obtain a copy of, opt out of sale, sharing, targeted advertising, or certain profiling, limit certain sensitive personal information uses, and appeal certain decisions.

We do not sell personal information for money. We do not use sensitive personal information to infer characteristics for advertising purposes. By default, we do not enable sale, sharing, targeted advertising, personalized marketing, or cross-context behavioral advertising.

You can record or confirm an opt-out choice through the privacy controls on the website.

California residents may also have rights under California's "Shine the Light" law to request information about certain disclosures to third parties for direct marketing purposes.

Australia

If Australian privacy law applies to your personal information, you may have rights to access and correct personal information, make a privacy complaint, and contact the Office of the Australian Information Commissioner if your complaint is not resolved.

Singapore

If Singapore privacy law applies to your personal data, you may have rights to access and correct personal data, withdraw consent where processing is based on consent, and make a complaint about personal data handling.

Children

The services are not intended for children under 18.

We do not knowingly collect personal information from children under 18 except where a parent, guardian, customer, or authorized representative lawfully provides information as part of an authorized service workflow.

If you believe a child has provided personal information without appropriate authorization, contact us at:

priv@suppressed.com

The website and services may reference or link to third-party websites, platforms, data brokers, search engines, public sources, status pages, payment processors, or other services.

We are not responsible for the privacy practices, security practices, content, terms, or decisions of third parties that we do not own or control.

Changes to this Privacy policy

We may update this Privacy policy from time to time.

If we make material changes, we will update the date above and may provide notice through the website, service, email, account notice, or another reasonable method.

The current version of this Privacy policy applies from the date stated above unless otherwise required by law.

Contact

For privacy questions or requests, contact:

priv@suppressed.com

SUPPRESSED PTE. LTD.
UEN: 202613955G
68 Circular Road
#02-01
Singapore 049422
Republic of Singapore