WiBiz Data Protection and Privacy Summary
Version: v1.0
Published: 6 August 2026
Owner: WiBiz Data Protection
Classification: Public
Status: Current public summary
1. Purpose
This summary describes the organisation-wide privacy and personal-data handling commitments of Digital Benefits Pte Ltd, trading as WiBiz. The applicable contract and Build Security and Data Annex identify the roles, purposes, data, locations, providers, retention, and rights process for a specific service.
2. Commitments
WiBiz requires personal data to be:
- collected and used for documented, lawful purposes;
- limited to what is reasonably needed for those purposes;
- kept accurate where accuracy affects the service or an individual;
- protected through risk-appropriate technical and organisational measures;
- retained only for a documented business, contractual, or legal need;
- returned, exported, deleted, or placed under legal hold through a defined process;
- transferred outside its originating jurisdiction only with the applicable safeguards;
- handled by approved personnel and providers within the permitted scope.
3. Roles and instructions
WiBiz may act as an organisation, controller, processor, data intermediary, or independent controller depending on the purpose and contract. The role is assessed per processing activity. Where WiBiz processes personal data for a client, the signed data-processing terms and documented instructions govern that activity.
4. Data rights and requests
WiBiz maintains a public data-protection contact. Requests involving access, correction, deletion, objection, export, or another applicable right are authenticated, scoped, recorded, assessed, and answered according to the applicable role, law, and contract.
5. International transfers and service providers
The applicable build record identifies storage, processing, backup, support-access, and transfer locations. It also records the provider role, service, data, purpose, safeguard, and review status. WiBiz does not make one universal residency claim for every service.
6. Retention and deletion
There is no one public retention period that safely applies to every data category and contract. Each build must define retention triggers, active-service retention, termination handling, export, production deletion, backup handling, provider deletion, legal holds, and the evidence available at closure.
7. Security incidents
Potential personal-data breaches are assessed through the incident process. Regulatory and client notifications follow the applicable law, processing role, and signed agreement. Public wording does not replace a client-specific notification commitment.
8. Advanced processing
Where a build uses specialised processing services, the build-specific schedule identifies the provider, data sent, purpose, retention, account settings, training or service-improvement position, transfer path, human control, and client choices. An unverified provider setting is not presented as a universal fact.
9. Contact
Data-protection enquiries: dpo@wibiz.ai
Security enquiries: security@wibiz.ai
WiBiz Data Protection and Privacy Summary v1.0, 6 August 2026.