PANTHERFIELD RESEARCH
Company established 2014 · Site preview

Privacy notice - draft

PDPA-aware · operational details pending

This draft must be completed against the actual hosting, analytics, intake and storage configuration before any personal data is collected.

Controller and contact

The intended controller is Pantherfield Pte. Ltd. (UEN 201418222D), operating the Pantherfield Research identity. Confirm the current ACRA extract, registered address and the published data protection officer contact before collecting personal data.

Data and purposes

Proposed categories: contact details, role and organisation, messages, proposal summaries, authorised attachments, consent records and limited security logs. Intended purposes: respond to enquiries, assess proposals, conduct requested research discussions, protect the site, comply with legal duties and keep a record of permitted correspondence. Any analytics, marketing or newsletter programme needs a separate, accurate disclosure and opt-in where required.

Sharing, storage and rights

Only authorised staff and contracted providers should access data as needed for these purposes, under suitable protections. Overseas transfers must be assessed and given legally required comparable protection. Retain data only as long as needed for the stated purpose or legal obligation, then erase or anonymise it. Publish actual retention periods or criteria after choosing the backend. Individuals may ask about access, correction or withdrawal of consent through the DPO route, subject to applicable law.

Security and incidents

Production controls must include transport encryption, private storage, least-privilege access, MFA, scanning, monitoring, deletion and incident response. No system can promise absolute security. Assess and notify reportable breaches as required by the PDPA. These are launch requirements, not claims that the preview already operates an intake system.

PDPC reference: data protection obligations and breach management guidance.