Arkiva’s Privacy Policy
1 – Introduction
Arkiva Pte Ltd ("Arkiva", "we", "us") is a Singapore company licensed by the National Environment Agency (NEA) to provide IT asset disposition (ITAD), secure data destruction, document shredding and e-waste recycling services.
This Policy explains how we collect, use, disclose, protect and retain personal data under the Personal Data Protection Act 2012 (PDPA) and its regulations. By using our website, contacting us or using our services, you acknowledge that you have read this Policy.
2 – Scope
This Policy covers personal data of:
- visitors to arkiva.com.sg and our online forms;
- representatives, employees and contact persons of our clients, prospects, suppliers and partners;
- individuals who visit our facility or are present at a collection site; and
- individuals who contact us by email, phone, WhatsApp or other channels.
This Policy does not cover:
- data stored on devices, media or documents you hand to us for destruction or recycling. This is governed by Section 8 and your service agreement;
- job applicants and employees, who are covered by our separate internal HR privacy notice; and
- third-party websites linked from our website.
3 – Key terms and precedence
Business contact information (such as name, job title, business phone, business email and business address) given for business purposes is not subject to most PDPA obligations. We may use it freely to deal with you and your organisation.
Client Media means any device, storage medium, document, paper record or equipment you provide to us for collection, destruction, data sanitisation, refurbishment, resale or recycling.
Service Agreement means any quotation, purchase order, service order, contract or terms and conditions agreed between Arkiva and a client.
Precedence. If this Policy conflicts with a Service Agreement, the Service Agreement prevails. This Policy is a notice under the PDPA. It does not create contractual rights or obligations beyond those required by law.
4 – Personal data we collect
We only collect what we need to deliver and document our services.
| Category | Examples |
|---|---|
| Contact details | Name, phone number, email, company, job title, address |
| Service and transaction records | Quotations, orders, invoices, payment records, collection addresses, delivery instructions |
| Chain of custody records | Name and signature of the person handing over or receiving items, date, time and location stamps, photos of items and seals at collection, serial numbers and asset tags |
| Facility and site records | CCTV footage at our facility, visitor log entries, images captured during on-site shredding or collection |
| Vehicle records | GPS location of our vehicles and drivers' job status updates |
| Website and device data | IP address, browser type, pages visited, cookie identifiers |
| Communications | Emails, call notes, WhatsApp and chat messages, enquiry form submissions, feedback |
We do not ask for NRIC, passport or other national ID numbers unless required by law, or needed to verify identity with a high degree of certainty (for example, an access request). We do not collect date of birth, gender, nationality, race or religion.
Photos taken at collection are meant to record the items and seals. Where an individual appears incidentally, the image is kept only as part of the chain of custody record.
5 – How we collect it
We collect personal data when you or your organisation:
- request a quotation, book a collection or sign a Service Agreement;
- fill in a form on our website or send us a message;
- hand over or receive items at a collection, delivery or on-site shredding job;
- visit our facility;
- subscribe to our newsletters or attend our events; or
- are referred to us by a client, partner or another person.
We may also collect business contact information from public sources such as company websites, ACRA records and LinkedIn.
6 – How we use it
We use personal data to:
- provide, schedule and carry out collection, transport, destruction, data sanitisation, refurbishment, resale and recycling services;
- keep chain of custody records and issue certificates of destruction, sanitisation or recycling;
- verify identity and authority at handover and prevent theft, fraud or loss of client items;
- issue quotations and invoices, collect payment and manage accounts;
- respond to enquiries, complaints and requests;
- secure our facility, vehicles and staff, including through CCTV and GPS tracking;
- meet our obligations to NEA, other regulators, auditors and certification bodies;
- defend or bring legal claims and handle disputes or investigations;
- improve our services, systems and website, and train our staff;
- send marketing and service updates, subject to Section 15; and
- carry out any merger, acquisition, sale or restructuring of our business.
7 – Legal basis
We rely on one or more of the following under the PDPA:
- Consent, including consent you give in writing, by email, verbally or through our website.
- Deemed consent, where you voluntarily provide personal data for a purpose, or where it is reasonably necessary to perform a contract with you or your organisation.
- Deemed consent by notification, where we have told you of a new purpose and given you a reasonable period to opt out.
- Legitimate interests, such as security, fraud prevention, chain of custody evidence and debt recovery. Questions about how we rely on legitimate interests can be sent to our DPO.
- Business improvement, for improving our services, operations and staff training.
- Other exceptions under the PDPA, including where data is publicly available, needed for an investigation or legal proceedings, required by law, or part of a business asset transaction.
8 – Data on Client Media
8.1 Our role. When you give us Client Media, any personal data stored on or in it remains under your control. We process it only to destroy, sanitise or recycle the media on your behalf. For that data, Arkiva acts as a data intermediary under the PDPA, and you remain the organisation responsible for it.
8.2 What we do with it. We do not access, read, copy, recover, analyse or use data on Client Media, except to the extent needed to sanitise it, verify that sanitisation succeeded, or comply with law. We do not sell or disclose that data.
8.3 What we do to protect it. While Client Media is in our custody, we:
- transport it in locked or sealed containers or vehicles;
- store it in access-controlled areas under CCTV;
- restrict handling to authorised, trained staff;
- destroy or sanitise it in line with the method agreed in the Service Agreement (for example, physical shredding, or data erasure to a recognised standard such as NIST SP 800-88); and
- notify you without undue delay if we believe a data breach involving your Client Media has occurred, so you can meet your own notification obligations.
8.4 When custody starts and ends. Our responsibility begins when Client Media is handed to our staff or appointed carrier, as shown by a signed or digitally recorded handover. It ends when the media is destroyed or sanitised and the certificate is issued. Sanitised devices may be resold or reused by us or by third-party vendors. For these items, our responsibility ends once sanitisation is complete and verified.
8.5 Your responsibilities. By giving us Client Media, you confirm and agree that:
- you own the Client Media, or have authority to dispose of it;
- you have the authority, and any consent required under the PDPA or other law, to pass the data on it to us for destruction;
- you have backed up any data you need. Destroyed or sanitised data cannot be recovered, and we are not responsible for any data you did not keep;
- you have removed any items not meant for disposal; and
- the inventory, quantities and descriptions you give us are accurate.
8.6 Limitation of liability. To the extent permitted by law, our liability for data on Client Media is limited to what is set out in the Service Agreement. We are not liable for any data loss, breach or unauthorised access that occurred before custody passed to us, or after it ended. Nothing in this Policy limits liability that cannot be limited under Singapore law.
8.7 Indemnity. You agree to indemnify Arkiva against claims, fines, losses and reasonable legal costs arising from a breach of your confirmations in Section 8.5.
9 – Who we share it with
We share personal data only where needed for the purposes in Section 6, and only with:
- our related companies and staff, on a need-to-know basis;
- logistics, transport and manpower contractors who help us collect and deliver items;
- licensed downstream recyclers and refiners in Singapore or overseas (sanitised or destroyed material only, never Client Media data);
- third-party resale vendors and buyers of refurbished equipment, only after sanitisation is complete;
- IT, cloud, software and communications providers, including our job management, asset tracking, email marketing (such as Brevo) and accounting systems;
- banks, payment processors, accountants, auditors, lawyers and insurers;
- certification bodies and client-appointed auditors checking our compliance;
- NEA, the PDPC, the Police and other government agencies where required or permitted by law; and
- a buyer or successor in any merger, acquisition or sale of our business.
We require service providers who process personal data for us to protect it to a standard comparable to the PDPA, by contract.
10 – Overseas transfers
Some of our staff and service providers are located outside Singapore, including in the Philippines, and our cloud providers may store data in other countries. Remote access from overseas counts as a transfer.
When we transfer personal data overseas, we make sure the recipient is bound by legally enforceable obligations, such as a contract or binding corporate rules, to protect it to a standard comparable to the PDPA. Client Media is collected and processed in Singapore. Data on Client Media is destroyed or sanitised in Singapore before any export. After processing, destroyed material, components and sanitised equipment may be exported to licensed overseas recycling or resale partners, in line with Singapore export laws and permits. No readable client data is sent overseas.
11 – How we protect it
We use reasonable security measures, including:
- access controls and role-based permissions on our systems;
- multi-factor authentication on key accounts;
- encryption for data in transit;
- CCTV, restricted entry and visitor logging at our facility;
- confidentiality undertakings and data protection training for staff and contractors; and
- regular review of our security practices.
No system is completely secure. We cannot guarantee that personal data sent over the internet, or held by third-party platforms you choose to use with us, will be free from unauthorised access.
12 – How long we keep it
We keep personal data only as long as needed for its purpose, or as required by law. Typical periods:
| Record | Retention |
|---|---|
| Certificates of destruction, sanitisation or recycling, and chain of custody records | As long as reasonably needed for business, audit or legal purposes |
| Invoices, payment and accounting records | At least 5 years, as required by Singapore tax and company law |
| Service Agreements and correspondence | 6 years after the relationship ends, to cover legal claims |
| CCTV footage | About 30 days, longer if needed for an incident or investigation |
| Vehicle GPS data | Up to 12 months |
| Marketing contacts | Until you unsubscribe, or 2 years without engagement |
| Website analytics | As set out in Section 14 |
After that, we securely destroy or anonymise the data, using the same methods we use for our clients.
13 – CCTV and vehicle tracking
Our facility, loading areas and some vehicles are monitored by CCTV, and our vehicles are GPS tracked. Signs are displayed where CCTV is in use. We use this footage and data for security, chain of custody evidence, staff safety, incident investigation and to protect client items. Footage is viewed only by authorised staff, and disclosed only to clients, insurers or authorities when needed for an incident.
14 – Cookies and website data
Our website uses:
- essential cookies, needed for the site and forms to work;
- analytics cookies (such as Google Analytics), to understand how the site is used; and
- marketing cookies or pixels, where enabled, to measure our advertising.
By using our website with cookies enabled in your browser, you agree to our use of cookies. You can block or delete cookies in your browser settings at any time, but some features may then not work. Questions about cookies can be sent to our DPO.
15 – Marketing
We may send you news, offers and updates about our services by email or other channels. You can unsubscribe at any time using the link in our emails or by contacting our DPO.
We will not send marketing messages to a Singapore phone number by call, SMS or WhatsApp unless we have your clear and unambiguous consent, or have checked the Do Not Call Registry, as required by the PDPA. Marketing emails follow the Spam Control Act. We do not sell your personal data.
16 – Your rights
Access. You may ask for the personal data we hold about you, and how it has been used or disclosed in the past 12 months.
Correction. You may ask us to correct personal data that is inaccurate or incomplete.
Withdrawal of consent. You may withdraw consent by giving us reasonable notice. We will tell you the likely consequences. For example, we may not be able to continue providing services or complete a pending job. Withdrawal does not affect data we are allowed or required by law to keep, such as chain of custody and accounting records.
How to make a request. Email our DPO with your name, contact details and request. We may verify your identity before acting. We will respond within 30 days, or tell you within that time when we can respond. We may charge a reasonable fee for access requests, and will give you an estimate first. We may refuse requests where the PDPA allows, for example where disclosure would reveal another person's data, prejudice an investigation, or reveal confidential commercial information.
Requests about data on Client Media should go to the client organisation that gave us the media. We will help that organisation respond where reasonable.
Data portability. When the PDPA data portability obligation comes into force, we will handle such requests as required by law.
17 – Data breaches
If we become aware of a possible data breach, we will assess it promptly, and within 30 days. If it is likely to cause significant harm to individuals, or affects 500 or more individuals, we will notify the PDPC within 3 calendar days of that assessment. We will notify affected individuals as soon as practicable where required. For Client Media, we will notify the client as set out in Section 8.3.
18 – Contact us
For any question, request or complaint about this Policy or your personal data, contact our Data Protection Officer:
Data Protection Officer
Arkiva Pte Ltd
1 Corporation Drive, #04-06 REVV, Singapore 619775
Email: dpo@arkiva.com.sg
Please include your full name, contact details and a short description of your request. We will handle it confidentially. If you are not satisfied with our response, you may contact the Personal Data Protection Commission.
19 – Changes and governing law
We may update this Policy at any time. The latest version will be posted on our website with its effective date, and takes effect when posted. Where a change materially affects how we use your personal data, we will take reasonable steps to notify you.
This Policy is governed by the laws of Singapore.
Last updated: 1 October 2026