Skip to content
GroundDesk

Legal · Privacy Policy

Privacy Policy.

Last updated: 19 July 2026

This is a template for review.

Have it reviewed by a qualified Singapore lawyer before relying on it. Nothing here is legal advice.

This Privacy Policy explains how GroundDesk, a product of On The Ground(“OTG”, “we”, “us”, “our”), collects, uses, discloses, and protects personal data when you use the GroundDesk platform and related websites and services (the “Service”). It is written to comply with Singapore’s Personal Data Protection Act 2012 (PDPA).

GroundDesk is a multi-tenant back-office platform for Singapore SMEs. In most cases you use GroundDesk as, or on behalf of, an organisation (your “Workspace”). Where your Workspace uploads documents and content into GroundDesk, that Workspace is the organisation responsible for the personal data it puts into the Service, and we handle that data on its behalf under our Terms of Service.

1. Personal data we collect

  • Account information — your name, work email address, organisation / Workspace name, role, password credentials (stored hashed), and authentication metadata.
  • Uploaded documents and content — the files, notes, invoices, receipts, contracts, messages, and other materials you or your Workspace add to GroundDesk. These may themselves contain personal data about you, your colleagues, your customers, or third parties.
  • Usage data — logs of how you interact with the Service, including pages visited, features used, actions taken, timestamps, device and browser type, and IP address.
  • Cookies and similar technologies— strictly necessary cookies for authentication and session management, and limited analytics to understand and improve the Service. See the “Cookies” section below.
  • Billing information — for paid plans, billing contact details and subscription records. Card payments are processed by our payment processor (Stripe); we do not store full card numbers.
  • Communications — messages you send us for support, feedback, or enquiries.

2. Purposes for which we use personal data

We use personal data to:

  • provide, operate, secure, and maintain the Service;
  • create and manage your account and authenticate you and your Workspace members;
  • process, index, and make your uploaded content searchable, and generate AI-assisted answers, summaries, and drafts on your request;
  • process subscriptions, billing, and payments;
  • provide customer support and respond to your requests and enquiries;
  • monitor, troubleshoot, and improve the Service, including product analytics and security;
  • send you service, security, and administrative communications, and — where you have consented or where permitted — product updates;
  • comply with legal obligations and enforce our terms and policies.

3. Consent

We collect, use, and disclose personal data in accordance with the PDPA’s consent obligation. By creating an account and using the Service, you consent to the collection, use, and disclosure of your personal data for the purposes set out in this Policy. Where we rely on deemed consent or an exception under the PDPA (for example, to fulfil a contract you have entered into, or for legitimate interests permitted under the Act), we will do so only as allowed by law. You may withdraw consent at any time (see “Your rights” below); withdrawing consent may mean we can no longer provide parts of the Service to you.

4. AI processing and subprocessors

GroundDesk uses artificial intelligence to help you search, summarise, analyse, and draft. To do this, relevant content you submit may be sent to and processed by third-party AI providers acting as our subprocessors — primarily Anthropic (for the Claude models). Where enabled for your Workspace, open-source models may be run on our own infrastructure instead.

We select AI providers that do not use your submitted content to train their foundation models by default, and we contract with them to process data only on our instructions. Some AI processing may occur on infrastructure located outside Singapore. Where personal data is transferred outside Singapore, we take steps required under the PDPA to ensure the recipient provides a standard of protection comparable to the PDPA — for example, through contractual data-protection clauses with our subprocessors (a “cross-border transfer with comparable-protection safeguards”).

AI outputs are generated automatically and may be inaccurate or incomplete. They are assistive only and are not professional advice — see our Terms of Service.

5. Data residency

Your account data and uploaded content are stored on infrastructure hosted in Singapore. Our primary database (Neon Postgres) and file storage (Vercel Blob) are provisioned in the ap-southeast-1 (Singapore) region, and application hosting is provided by Vercel. As described above, limited processing (such as AI inference and certain support tooling) may involve transfers outside Singapore under comparable-protection safeguards.

6. Disclosure of personal data

We may disclose personal data to:

  • other members of your Workspace, according to the access controls and permissions your Workspace configures;
  • service providers and subprocessors who help us run the Service (hosting, storage, AI inference, payment processing, analytics, customer support, email delivery), bound by confidentiality and data-protection obligations;
  • professional advisers, or in connection with a corporate transaction (such as a merger, acquisition, or asset sale), subject to appropriate protections;
  • authorities or third parties where required or permitted by law, or to protect our rights, users, or the public.

We do not sell personal data.

7. Retention

We retain personal data for as long as your account is active and as needed to provide the Service, and thereafter only for as long as necessary to fulfil the purposes set out in this Policy, or to meet legal, accounting, tax, or record-keeping requirements. In particular, financial documents (such as invoices and receipts) may need to be retained for longer periods to meet statutory record-keeping needs — for example, the Inland Revenue Authority of Singapore (IRAS) generally requires business records to be kept for 7 years. When personal data is no longer needed for any legal or business purpose, we will take reasonable steps to delete or anonymise it.

8. Security

We implement reasonable administrative, technical, and physical safeguards to protect personal data against unauthorised access, collection, use, disclosure, copying, modification, disposal, or similar risks. These include encryption in transit (TLS), encryption of data at rest, tenant isolation between Workspaces enforced in our application code and covered by automated tests, role-based access controls within each Workspace, hashed credentials, and request and usage logging. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Staff access to your Workspace. By default, On The Ground staff have no access to the documents and content inside your Workspace. Staff can only access a Workspace if (a) your Workspace has invited them as a member, which you can revoke at any time, or (b) you ask us for hands-on support and consent to a time-limited support session, which is technically restricted, recorded against the session, and removed when the support request is resolved. As the operator of the underlying infrastructure we retain administrative access to our systems for maintenance, backup, and legal-compliance purposes; such access is restricted to a need-to-know basis and governed by internal policy.

9. Your rights under the PDPA

Subject to the PDPA, you may:

  • Access — request access to the personal data we hold about you and information about how it has been used or disclosed;
  • Correction — request that we correct an error or omission in your personal data;
  • Withdraw consent — withdraw your consent to our collection, use, or disclosure of your personal data, on reasonable notice.

To exercise these rights, contact our Data Protection Officer using the details below. We will respond within the timeframes required by the PDPA. Where the data was uploaded by your Workspace, we may direct your request to the relevant Workspace, who is responsible for that data. We may charge a reasonable fee for an access request as permitted under the Act, and will tell you in advance.

10. Cookies

We use strictly necessary cookies to keep you signed in and to secure the Service, and limited analytics cookies to understand usage and improve the product. You can control cookies through your browser settings; disabling strictly necessary cookies may prevent you from signing in or using core features.

11. Data breach handling

We maintain a data-breach response process. If a data breach occurs that results in, or is likely to result in, significant harm to affected individuals, or is of a significant scale, we will assess and notify the Personal Data Protection Commission (PDPC) and affected individuals in accordance with the PDPA’s mandatory data breach notification requirements and the applicable timelines, and take steps to contain and remediate the breach.

12. Children

The Service is intended for business use and is not directed to individuals under 18. We do not knowingly collect personal data from children.

13. Changes to this Policy

We may update this Policy from time to time. We will post the updated version here and revise the “Last updated” date. Material changes will be communicated where required.

14. Data Protection Officer

Our Data Protection Officer is responsible for overseeing our compliance with the PDPA. For any questions, requests, or complaints about your personal data, contact:

Data Protection Officer
On The Ground (GroundDesk)
Email: dpo@ontheground.agency

If you are not satisfied with our response, you may lodge a complaint with the Personal Data Protection Commission (PDPC) of Singapore.