D · PRIVACY
Privacy policy
How Feed Bloom Vault LLP handles personal data under the Personal Data Protection Act 2012 (PDPA). Last reviewed 14 August 2026.
1. Data controller
Feed Bloom Vault LLP ("we", "us", "our") is the data controller for personal data collected through feedbloomvault.pro and through correspondence with our desk. Our registered address is 247 East Coast Road, #01-04, Singapore 428940. Privacy enquiries: [email protected]. General desk contact: [email protected], telephone +65 6281 7463 during operating hours Tue–Sun 12:00–22:00 SGT.
2. Scope
This policy applies to personal data we collect when you visit our website, email us, telephone the desk, visit the Katong floor, enter into a written scope agreement, or interact with embedded services such as Google Maps after you enable functional cookies. It does not apply to third-party websites linked from our pages. We encourage you to read their privacy policies separately.
3. Personal data we collect
We may collect the following categories of personal data depending on how you interact with us:
- Identity and contact data — name, email address, telephone number, organisation name, job title, postal address when you write to us or enter a partnership scope.
- Correspondence data — content of emails, letters, and notes from meetings or calls, including attachments you send voluntarily.
- Technical data — IP address, browser type, device type, referring URL, pages viewed, and timestamps from server logs and essential cookies.
- Cookie preference data — your choices regarding functional and analytics cookies stored in cookies and local storage as described on our Cookies page.
- Editorial source data — where you are a source for a story, we may hold verification notes, consent records, and contact details subject to separate editorial retention rules.
We do not operate web forms on this site. We do not collect payment card data on feedbloomvault.pro. We do not knowingly collect personal data from children under thirteen without parental consent.
4. How we collect personal data
We collect personal data through direct interaction (email, phone, in-person visits), automated technologies (server logs, essential cookies), and from third parties where lawful (for example, publicly available business contact details for verification). Google Maps may set third-party cookies only after you accept functional cookies or click Load map on a map disclosure block.
5. Purposes of collection, use, and disclosure
We collect and use personal data for purposes including:
- Responding to enquiries and managing correspondence routed through The Mailbox.
- Performing written scope agreements with partners and maintaining editorial records.
- Verifying sources and managing hold shelf clearance documentation.
- Operating, securing, and maintaining feedbloomvault.pro.
- Honouring cookie preferences and loading optional embedded content when permitted.
- Complying with legal obligations and responding to lawful requests from authorities.
- Improving site reliability through aggregated, non-identifying technical review when analytics cookies are enabled.
We do not sell personal data. We disclose personal data to service providers who assist with hosting, email delivery, legal counsel, or technical maintenance under contractual confidentiality obligations. We may disclose personal data where required by Singapore law or court order.
6. Legal basis and consent
Under the PDPA, we rely on consent, contractual necessity, legitimate interests, and legal obligation as appropriate to each processing activity. For non-essential cookies, we obtain consent through the cookie banner before setting functional or analytics cookies. You may withdraw cookie consent at any time via Manage cookies on the Cookies page. Withdrawal does not affect the lawfulness of processing before withdrawal.
7. Retention
We retain personal data only as long as necessary for the purposes collected or as required by law:
- General correspondence: up to twenty-four months from last contact unless a longer period is required for ongoing scope agreements or disputes.
- Partnership and scope records: duration of agreement plus seven years for audit and legal purposes unless a shorter period is agreed in writing.
- Server logs: up to ninety days unless required for security investigation.
- Cookie consent records: up to one hundred eighty days, aligned with cookie max-age settings.
- Source verification notes: retained according to editorial policy, typically until story archive review or hold resolution plus twelve months.
When personal data is no longer required, we delete or anonymise it using reasonable technical measures.
8. Transfer outside Singapore
Our hosting and email providers may process personal data on servers located outside Singapore. Where we transfer personal data overseas, we take steps reasonably required under the PDPA to ensure recipients provide a standard of protection comparable to the PDPA, including contractual safeguards where applicable.
9. Security
We implement reasonable administrative, technical, and physical safeguards to protect personal data against unauthorised access, collection, use, disclosure, copying, modification, disposal, or similar risks. Measures include access controls for desk systems, encrypted transport (HTTPS), restricted physical access to the Katong floor, and staff training on confidentiality. No method of transmission over the internet is completely secure; we cannot guarantee absolute security.
10. Your rights under the PDPA
Subject to exceptions under the PDPA, you may:
- Request access to personal data we hold about you.
- Request correction of inaccurate personal data.
- Withdraw consent for processing that relies on consent, where applicable.
- Request information about how we have used or disclosed your personal data within the preceding year.
Submit requests to [email protected] with sufficient detail to identify you and describe your request. We respond within thirty days where practicable. We may charge a reasonable fee for manifestly unfounded or excessive access requests as permitted by law.
11. Accuracy
We take reasonable steps to ensure personal data is accurate and complete when used. Please notify us promptly if your contact details change or if you believe our records are inaccurate.
12. Do Not Call registry
Where we telephone individuals for purposes that may fall within the Do Not Call provisions, we maintain internal procedures to check the Do Not Call Registry unless an exception applies under the PDPA and related regulations.
13. Third-party links and embeds
Our site links to external resources and may embed Google Maps after consent. Third parties process data under their own policies. Google's privacy policy applies to map embeds. We configure embeds to load only after functional consent to reduce unsolicited third-party processing.
14. Automated decision-making
We do not make decisions with legal or similarly significant effects on individuals based solely on automated processing of personal data without human review.
15. Data breach notification
If we become aware of a data breach likely to result in significant harm or affect a significant number of individuals, we assess the breach promptly and notify the Personal Data Protection Commission and affected individuals where required under the PDPA.
16. Changes to this policy
We may update this policy to reflect legal, technical, or operational changes. Material updates will be indicated by revising the last reviewed date at the top of this page. Continued use of the site after updates constitutes acknowledgement of the revised policy where consent is not separately required.
17. Contact
Privacy Officer contact: [email protected]
Feed Bloom Vault LLP, 247 East Coast Road, #01-04, Singapore 428940
If you remain unsatisfied after contacting us, you may lodge a complaint with the Personal Data Protection Commission of Singapore.