Legal
Last updated: 22 August 2026
Security Decoded is a business-to-business cybersecurity firm registered in Singapore (ACRA 202201048K). This policy explains what we collect through this website, why we collect it, and what we do with it. We have tried to write it in the same plain language we use everywhere else.
This policy covers two different situations, and it is worth being clear about which is which.
Visitors to this website and business enquiries. When you browse this site or contact us, we decide how that information is handled. Everything below applies.
Information we handle for our clients. When we deliver services such as virtual CISO, virtual DPO, penetration testing, audits or incident response, we may access information belonging to a client organization. In those cases we act on that client's instructions, not our own. That work is governed by the engagement contract and any accompanying data protection agreement, not by this policy. If you are an employee, customer or contact of one of our clients and you have a question about your information, please contact that organization directly.
We sell to organizations, not to consumers. The information we hold about individuals is almost entirely business contact information, meaning a person's name, job title, work email address and work telephone number, provided for business purposes. Under Singapore's Personal Data Protection Act, business contact information is treated differently from personal data given in a private capacity. We nevertheless apply the protections described in this policy to it.
We do not knowingly collect information about individuals in a personal capacity through this website, and our services are not directed at children.
Our contact form asks for your name, your email address, and a description of what you need. We ask you not to include confidential material, credentials, or details of a live security incident in that form. If you are reporting an incident, contact us by telephone and we will arrange a secure channel.
If you email or call us, we hold whatever you choose to tell us, along with our correspondence with you.
We do not operate any analytics on this website. However, like any website, ours is served by infrastructure that keeps operational and security logs. These logs may record your IP address, the pages requested, timestamps, and your browser and operating system. They exist so the site can be delivered, kept available, and defended against attack. We do not use them to build a profile of you, and we do not combine them with anything else.
This website sets no cookies of its own. We have no cookie banner because we have nothing to ask your consent for.
Our hosting provider may set strictly necessary cookies for security purposes, such as distinguishing automated traffic from human visitors. These are not used for tracking or advertising. You can block or delete cookies in your browser settings, and this site will continue to work.
Like any business, we use external providers rather than building everything ourselves. We would rather explain plainly how they are involved than publish a list that goes out of date the moment we change something.
This site is delivered by a hosting and content delivery provider, and some assets such as typefaces, stylesheets and scripts are loaded from public delivery networks. When you open a page, your browser requests those files directly, which means your IP address and basic request details are visible to those providers. We do not use any of them to track you, and none of them place advertising or analytics on this site.
We use established business platforms for email, calendars, documents, and for receiving and storing enquiries submitted through this site. Your correspondence with us, and the notes we keep about an enquiry or an engagement, are held in those systems. The same hosting provider that serves this site also provides the security layer in front of it and generates the operational logs described above.
We select providers with recognised security practices, and we prefer those that can demonstrate independent assurance. Where a provider handles personal data on our behalf, we rely on the data protection terms in their agreements, and we review those arrangements periodically. No provider is permitted to use your information for their own purposes or their own marketing.
If you are evaluating us as a supplier and need the specific providers and locations we use, ask us and we will give you a current list. We would rather answer that accurately on request than maintain a list here that risks becoming inaccurate.
Where the General Data Protection Regulation applies, we rely on your consent for enquiries you initiate, on the performance of a contract for client work, on our legitimate interest in operating and securing this website, and on legal obligation where the law requires something of us.
We do not add enquirers to a marketing list automatically.
We do not sell personal data, and we do not share it with anyone for their own marketing.
We share information only with the service providers described above who help us operate, with professional advisers where necessary, where the law or a regulator requires it, and in the event of a merger or sale of the business, in which case we would give notice before your information became subject to a different policy.
We are based in Singapore. The service providers listed above operate globally, so your information may be processed on servers outside Singapore and outside your own country. Where that happens, we take reasonable steps to ensure a comparable standard of protection to that required under Singapore law.
Contact form submissions and enquiry correspondence are kept for 12 months from our last exchange with you, unless the enquiry becomes a client engagement.
Client engagement records are kept for the duration of the engagement and for as long afterwards as we are required to keep them for legal, regulatory, insurance or audit reasons.
Server and security logs are kept for a short operational period and then discarded.
This site is served over encrypted connections. Access to enquiry data and client records is restricted to the people who need it, protected by multi-factor authentication, and reviewed. We are a cybersecurity firm and we hold ourselves to the standards we recommend to clients, but no method of transmission or storage is completely secure and we cannot promise absolute security.
If a data breach occurs that is likely to result in significant harm, or that meets the notification thresholds under the Personal Data Protection Act, we will notify the Personal Data Protection Commission and affected individuals as the law requires.
You may ask us to confirm what personal data we hold about you and how it has been used, ask us to correct anything inaccurate, withdraw consent you have previously given, ask us to delete information we no longer have a reason to keep, or ask for a copy of what you gave us in a portable format.
Write to our Data Protection Officer at security [@] securitydecoded.com and we will respond within the timeframe the law allows. We may need to verify your identity first.
If you are not satisfied with our response, you may complain to the Personal Data Protection Commission of Singapore. If you are in the European Economic Area or the United Kingdom, you may also complain to your local supervisory authority.
This site links to other websites, including the sites of regulators, certification bodies and partners. We do not operate those sites, we are not responsible for their content or their privacy practices, and we suggest reading the policy of any site you visit.
We also link to lifefirewall.com, which is our own product. It is a separate service with its own privacy policy, and information you provide there is not covered by this one.
We may update this policy. When we do, we will post the new version here and update the date at the top. Changes take effect when posted.
For any question about this policy or about information we hold, email hi [@] securitydecoded.com or use our contact page. Our Data Protection Officer can be reached at security [@] securitydecoded.com.
Security Decoded, Singapore. ACRA registration number 202201048K.