Legal · Privacy
Privacy Policy
This Policy explains how Civentia Pte. Ltd. ("Civentia", "we"), as the operator of the Civentia marketplace and business platform, processes information about visitors, business customers and service providers, and the rights available under the Personal Data Protection Act 2012 (Singapore) and other applicable data-protection law.
Effective: 2026-09-02 · Updated: 2026-09-03 · Version: v3.1
This is a draft provided for transparency and is pending formal legal review. Contact us with any question.
Scope
This Policy applies to your interaction with the Service — browsing this website and the public marketplace, operating a customer (Client) tenant, or operating a provider (Vendor) tenant — via our web clients and the provider desktop testing client. It does not apply to third-party systems you choose to use alongside the Service (including the systems of Payment Providers), which are governed by their own privacy practices.
For account, marketplace, transaction and security data that we collect to run the platform, we act as controller / personal-information handler. Where a Vendor processes personal data about its own customers and contacts inside its workspace, the Vendor is the controller and we act as processor on its documented instructions, in accordance with this Policy, the applicable agreement and any separately signed Data Processing Agreement.
Information we process
To deliver the Service and operate it safely, we process the following categories of information:
- Account & identity: name, sign-in email and contact phone (stored encrypted), password (stored only as a salted cryptographic hash, never in plain text), company details, team membership, roles and permissions, language preference, IP address and device information.
- Payment verification status: the fact and status of your KYC/KYB verification with a Payment Provider. Identity documents and due-diligence materials are collected and held by the Payment Provider under its own regulatory obligations; we do not receive or store the underlying documents.
- Transactions & billing: inquiries, quotes, orders, contracts, engagement records, invoices, payment status and payment-method metadata. Card details are collected directly by the Payment Provider and are never stored on our systems; bank-transfer references and payment proofs you submit are stored for review.
- Marketplace content: reviews and ratings, Tender/RFQ postings and bids, consultation and chat messages with other businesses, support tickets, and files you attach.
- Vendor workspace records: business data Vendors enter about their own customers, assets and jobs — processed by us as processor on the Vendor's behalf.
- Measurement & testing data: instrument readings and test records uploaded by Vendors' authorised testing clients, with associated device identifiers and metadata.
- Logs & security telemetry: system operation logs, API call records, audit events (including flagged access to data across tenant boundaries), error reports and anomaly alerts, used for operations, security and compliance.
- Cookies, local storage & measurement: see the cookies section below for the limited, current categories.
Purposes and legal bases
We process this information only for the following purposes, each supported by an appropriate legal basis (performance of contract, compliance with legal obligation, legitimate interest, or consent where required):
- operating the marketplace and tenant workspaces, including connecting Clients with the Vendors they choose to contact;
- processing transactions: quotes, orders, payment instruction handling, credit invoicing and refunds, in cooperation with Payment Providers;
- maintaining the integrity of reviews, Tenders and bidding, and preventing fraud and abuse;
- risk, security and compliance control, including identity verification coordination, Sanctions and fraud screening, bot protection and abuse prevention;
- sending service notifications in-product and by email — such as verification codes, order and engagement updates, review invitations and subscription renewal notices;
- customer support, troubleshooting and product improvement based on aggregated usage;
- compliance with applicable commercial, tax, industry-safety, anti-money-laundering, cybersecurity and data-protection law;
- optional analytics or research carried out only with your separate consent.
Our role: controller and processor
For your account information, marketplace activity, transactions, billing, operational logs, security defences and compliance auditing — activities where we determine the purposes and means — we are the controller / handler and are directly accountable to you.
For business records a Vendor keeps about its own customers and contacts inside its workspace (including personal data of Client-side personnel it serves), the Vendor is the controller and decides the purposes and means; we act solely as processor following the Vendor's instructions.
Cross-border data transfers
The Service is hosted on reputable cloud infrastructure, and some recipients described above (including Payment Providers and sub-processors) may be located outside your country. Where personal data is transferred out of Singapore, we do so in accordance with the transfer-limitation obligations of the Personal Data Protection Act 2012, requiring recipients to provide a standard of protection comparable to the PDPA (for example by contract). For personal data of EU/UK data subjects we execute Standard Contractual Clauses and apply GDPR safeguards. For personal information of individuals in mainland China, cross-border provision follows a lawful route under the Personal Information Protection Law — a security assessment organised by the competent authority, the Chinese standard contract, personal-information protection certification, or another path permitted by law — and is made only for the purposes listed in this Policy.
Retention
We retain your information for the shortest period necessary to fulfil the purpose of processing, then delete or anonymise it. In the Service, user-initiated deletion first marks records as deleted and removes them from normal use; irreversible destruction follows under our data-destruction policy. The principal retention periods are:
- Account and workspace data — retained for the life of the account, plus the post-termination export window described in the Terms, then deleted or anonymised;
- Transaction, order, invoice, payment-instruction and accounting records — at least five (5) years from completion of the relevant transaction, as required under Singapore commercial and tax law;
- Security, access and audit logs — at least five (5) years, to satisfy cybersecurity and anti-money-laundering obligations and to investigate abuse;
- Payment verification status records — retained for the life of the account and thereafter as needed to establish or defend legal claims or respond to regulators; the underlying KYC/KYB documents are retained by the Payment Provider under its own regulatory obligations;
- Inspection and testing data and reports held by Vendors — at least the period required by the regulations applicable to the relevant service line;
- Marketing leads submitted through this website — until the inquiry is resolved and no more than twenty-four (24) months thereafter, unless a longer period is required by law;
- Longer retention — where, and for as long as, necessary to bring, exercise or defend legal claims.
After account closure or subscription termination you may export your data within the export window described in the Terms; thereafter we perform irreversible deletion in line with our data-destruction policy and keep only the minimum required by law.
Security measures
We apply technical and organisational measures commensurate with industry standards, including but not limited to:
- encryption in transit (TLS) and at-rest encryption of sensitive contact fields; passwords stored only as salted cryptographic hashes;
- role- and permission-based access control with strict tenant isolation enforced at the data layer;
- end-to-end audit logging — including heightened logging of any cross-tenant administrative access — with anomaly alerting and periodic security review;
- rate limiting, bot protection and abuse detection on public endpoints;
- confidentiality undertakings from staff, need-to-know access and periodic permission review;
- incident-response plans and statutory notification of high-risk events to regulators and affected parties.
Your rights
Under the PDPA and other applicable law, and to the extent provided by them, you and the data subjects you represent may exercise the following rights:
- access and obtain a copy of personal data, and information about how it has been used or disclosed;
- correct or supplement inaccurate or incomplete personal data;
- request deletion or anonymisation where applicable;
- withdraw a previously given consent (with reasonable notice, subject to legal and contractual restrictions — note that withdrawal may affect our ability to provide the Service);
- obtain information about, or human review of, significantly automated decision-making where applicable;
- data portability (a portable copy of personal data) where applicable;
- close an account.
If your personal data is held inside a Vendor's workspace, please first exercise your rights with that Vendor (the controller); where they cannot respond, you may contact us at [email protected] and we will assist. We respond within the timeframes required by applicable law and may need to verify your identity and authority first.
Minors
The Service is intended for adult users acting for business customers. We do not knowingly collect personal data from minors. If you become aware of any such situation, please contact us and we will delete the data without delay.
Updates to this Policy
We may update this Policy in line with law, business changes or security best practice. Material changes will be notified at least thirty (30) days before they take effect via in-product message, email or sign-in prompt, and the current version with its effective date is always available on this page. Your continued use after the effective date is taken as acceptance of the updated version.
Contact and complaints
For questions about this Policy, the exercise of data-protection rights or other compliance matters, contact our Data Protection Officer at [email protected] or our privacy contact at [email protected], or by post at 25 Seah Street, #02-01, Singapore 188381 (UEN: 202639527G). If you believe our processing breaches law or this Policy, you may complain to the competent authority of your jurisdiction — in Singapore, the Personal Data Protection Commission (PDPC).