This Privacy Policy (“Policy”) sets out the basis which Fixonal Pte. Ltd. (UEN 202005987Z) (“Fixonal”, “us” or “we”) and the individual who or entity that (“you” and “your”) collects, uses, discloses, stores and protects personal data when you access or use https://fixonal.com/, https://keppt.me/ or any other related websites (“Websites”), and the Keppt mobile application together with its various features and functionalities (“Application”) (collectively, the “Platforms”).
This Policy applies to personal data in our possession or under our control, including personal data in the possession of organisations which we have engaged to collect, use, disclose or process personal data for our purposes.
Please also read the terms of use (“Terms”) carefully before using the Platforms, which can be accessed here: https://keppt.me/terms.
The Platforms are software solutions offering customers access to an AI-powered document intelligence platform that enables you to scan, upload and store documents, categorise document content and delivers analytics, insights, reminders and summaries derived from those documents through features like family plans, commenting, sharing, searching, image thumbnails, document previews, optical character recognition (OCR), easy sorting and organisation, and personalisation (“Services”).
This Privacy Policy is intended to comply with:
Our Privacy Policy explains how we collect and use your personal data while our Acceptable Use Policy outlines your responsibilities when using our Services. By using the Platforms, you agree to be bound by the Terms, and all other terms and policies that appear on the Platforms (including FAQs, our Terms of Use and Acceptable Use Policy). In the event of any inconsistency between this Policy and other terms and policies that appear on the Platforms on matters of data protection, this Policy prevails.
1.1. Fixonal is a company incorporated in Singapore, with its registered office at 160 Robinson Road, #14-04, Singapore Business Federation Center, Singapore 068914.
1.2. For the purpose of this Policy, Fixonal is the data controller (as defined under the EU/UK GDPR) and the organisation (as defined under the PDPA) in respect of personal data processed through the Platforms, except where this Policy states otherwise (for example, in relation to the “Unlimited Family” subscription plan).
1.3. Fixonal’s Data Protection Officer can be contacted by submitting your request via email to our Data Protection Officer at dpo@fixonal.com for any question, concern or request relating to this Policy or your personal data or information.
2.1. This Policy applies to personal data processed through the Platforms.
2.2. This Policy does not apply to third party websites, applications or services that may be linked from the Services (including the Apple App Store, Google Play Store, and any authentication or payment services provider), which are governed by their own privacy policies.
3.1. Because Keppt is a personal document vault, the personal data we process includes personal data and, routinely, special category / sensitive personal data. This is a core feature of the Services and we have designed our data handling accordingly.
3.2. Information you provide to us. Depending upon the context in which you interact with us, personal information you may provide to us through the Services includes:
(a) Contact data, such as your first and last name, salutation, email address, billing and mailing addresses, professional title and company name, and phone number;
(b) Account data, such as the username and password that you may set to establish an online account with the Services, any “Unlimited Family” subscription plan you are a part of and your role within the “Unlimited Family” subscription plan (e.g., owner (“Owner”), invitees of the Owner (“Invitee(s)”)), and any other information that you add to your account profile;
(c) Communications data, based on our exchanges with you, including when you contact us through the Services, social media, or otherwise;
(d) Transactional data, such as information relating to or needed to complete your subscriptions on or through the Services, including subscription type and transaction history;
(e) Marketing data, such as your preferences for receiving our marketing communications and details about your engagement with them;
(f) Inputs, prompts and user-generated content, such as images, documents, data, feedback, works of authorship and other content or information that you upload/use as an input or prompt to, generate, transmit or otherwise make available on the Services, as well as associated metadata (e.g., how, when, where content was collected or edited, keywords or location information);
(g) Financial data, such as receipts, bills, invoices, bank statements, tax documents, insurance policies;
(h) Identification data, such as passports, national identity documents, driving licences, residency permits, and extracted fields such as full name, document number and expiry date;
(i) Health data, such as medical records, prescriptions, test results, vaccination certificates, health insurance documents;
(j) Household or lifestyle data, such as utility bills, vehicle paperwork, travel documents, subscription confirmations, warranties;
(k) Derived data, if you use certain features of the Services, such as to convert images or documents to generate or propose reminders, currency exchange, translation or data analytics, we may derive certain information from images or documents to provide those features;
(l) Payment data, needed to complete transactions is collected and processed directly by our payment processors, such as RevenueCat, as further described below in the “How We Share Your Information” and “Third Party Links and Content” sections; and
(m) Other data, not specifically listed here, which we will use as described in this Privacy Policy or as otherwise disclosed at the time of collection.
3.3. We do not collect audio or video files, and the Services do not support them. We do not ask you for, and you should not upload, categories of information unrelated to your own personal document management (for example, documents belonging to, or containing personal data of, other individuals, except as permitted under the paid “Unlimited Family” subscription plan).
3.4. If you upload a document containing sensitive data belonging to another person (for example, a family member’s medical record within a family plan), you confirm that you have the appropriate basis (such as their consent, or another lawful basis available to you) to do so, and that you are responsible for that upload as set out in the Terms.
3.5. Where you are subject to the EU/UK GDPR, we rely on your explicit consent to process special category data, which you provide when you choose to upload a document of that kind. You may decline to upload any sensitive data; doing so will simply mean those documents are not stored on the Platforms.
3.6. Third party sources. We may combine personal information we receive from you with personal information that we obtain from other sources, such as:
(a) Public sources, such as public records, social media platforms and other publicly available sources;
(b) Third Party AI Provider. Parts of the Services are integrated with a third party AI provider (“Third Party AI Provider”) that generate outputs (i.e., responses, reminders, currency exchange, translation or data analytics) to your inputs and prompts. The Third Party AI Provider may infer information about you and share information with us as part of their processing of your inputs and prompts to the Platforms;
(c) Third party service providers that provide services on our behalf or help us operate the Services or our business;
(d) Third party login/linked services, such as the Google or Apple account that you use to log into, or otherwise link to, your account, including when you utilise or direct the Services to utilise your third-party accounts. This data may include your username and other information associated with your account on that third party service that is made available to us based on your account settings on that service; and
(e) At your direction. Where you consent or direct us to interact with a third party, we may receive only the information needed to carry out the actions you request and consistent with the permissions you grant. We only access the images, documents and data you authorise, and we follow the applicable third party service provider policies. For example, when you connect Google services, we comply with the Google API Services User Data Policy, including the Limited Use requirements.
3.7. Cookies and similar technologies. We, our service providers, and our business partners may automatically log information about you, your computer or mobile device, and your interaction over time with the Services, our communications and other online services as facilitated by cookies and other technologies. For more information, see our Cookie Policy at fixonal.com.
4.1. We may use your personal information for the following purposes or as otherwise described at the time of collection:
(a) To provide the Services. To create and administer your account; store and organise your images and documents; and enable core features (capture, upload, search, provide data analytics on your instructions, and provide related hosting and support);
(b) To provide the Services (where the paid “Unlimited Family” subscription plan is used). To facilitate data sharing, including managing Invitees’ access permissions, synchronising session data among authorised Invitees, and monitoring resource and data usage of the Invitees;
(c) AI classification and extraction. To transmit your inputs to our Third Party AI Provider for processing and to receive outputs, as necessary to fulfil your requests; to classify uploaded documents and extract structured fields, which power search, reminders, organisation and insights (see Section 7); to execute tasks asynchronously in the cloud, including background operations that continue running even when you close your browser or device, with task execution logs retained to enable replay and debugging;
(d) Reminders and insights. To generate service personalisation based on your instructions such as to understand your needs and interests; personalise your experience with the Services and our Services-related communications; remember your selections and preferences as you navigate webpages; send reminders (for example, an expiring deadline in a document) and simple aggregations derived from your uploaded images or documents;
(e) Subscription and billing. To manage your subscription tier, entitlements and renewal state. Card payment details are handled entirely by Apple, Google or our payment processors, such as RevenueCat, and are never received or stored by Fixonal;
(f) Customer support. To provide support for the Services, and respond to your requests, questions and feedback; to respond to enquiries sent to support@fixonal.com; communicate with you about the Services, including by sending Services-related announcements, updates, security alerts, and support and administrative messages;
(g) Service integrity and security. To enable security features of the Services; prevent, identify, investigate and deter fraudulent, harmful, unauthorised, unethical or illegal activity, including cyberattacks and identity theft, abuse, security incidents, and violations of the Terms, Acceptable Use Policy and all other terms and policies that appear on the Platforms;
(h) Legal and regulatory compliance. To comply with applicable laws, lawful requests, and legal process, such as to respond to subpoenas, investigations or requests from government authorities; protect our, your or others’ rights, privacy, safety or property (including by making and defending legal claims); audit our internal processes for compliance with legal and contractual requirements or our internal policies; and enforce the terms and conditions that govern the Services;
(i) To create aggregated, de-identified and/or anonymised data. We may create aggregated, de-identified and/or anonymised data from your personal information and that of other individuals whose personal information we collect. We may convert your personal information into de-identified and/or anonymised data by removing information that could identify you. We may use this aggregated, de-identified and/or anonymised data and share it with third parties for our lawful business purposes, including to analyse and improve the Services and promote our business;
(j) Marketing (opt-in only). We, our service providers and our third party marketing partners, may collect and use your information for marketing and advertising purposes to send you product updates or marketing communications, communicate with you about events or contests in which you participate, but only where you have opted in, and you may withdraw consent i.e. opt-out at any time. Where permitted by law and with your permission where required, we process certain online identifiers to (i) show you more relevant ads, (ii) measure ad performance, and (iii) build or refine audiences;
(k) Unlimited Family subscription plan. Where you, as the Owner (through the family plan), engage us through the Services to process personal information of your Invitees, you act as the data controller (or organisation) for those processing activities and we act as your data processor, handling such personal information only on your documented instructions, Platform settings or inputs; and
(l) Additional uses, in some cases, we may use your personal information for additional uses or further purposes, in which case we will ask for your consent to use your personal information for those additional uses or further purposes as required under applicable laws.
4.2. We do not sell your personal data and we do not use your document content to train, fine-tune or otherwise improve any AI model.
4.3. Under the PDPA, our processing is based on your consent (deemed or express, as applicable) at the point you upload a document or take an action within the Services, or, where permitted, on the "legitimate interests" and other exceptions to consent set out in the PDPA (for example, for fraud prevention and business improvement activities that do not have an adverse effect on you).
5.1. We may share your personal information with the following parties and as otherwise described in this Privacy Policy, in other applicable notices, or at the time of collection:
(a) Related entities. Our subsidiaries, related entities and affiliates.
(b) Service providers. Third parties that provide services on our behalf or help us operate or promote the Services or our business (such as hosting, information technology, customer support, email delivery, marketing, consumer research and website analytics).
(c) Third party AI provider. We use a third party AI provider to power certain aspects of the Platforms, such as extracting fields from images or documents, processing user inputs/prompt features, data analytics, reminders, summaries and recommendations. You may also activate and use a third party AI Integration with the Services.
(d) Linked third party services. If you log into the Services with, or otherwise link your account to, a social media or other third party service, we may share your personal information with that third party service. The third party’s use of the shared information will be governed by its privacy policy and the settings associated with your account with the third party service.
(e) Payment processors. Any payment card information you use to make a purchase through the Platforms or for the Services is collected and processed directly by our payment processors, such as RevenueCat. Our payment processors may use your payment data in accordance with their privacy policy located at: https://www.revenuecat.com/privacy/.
(f) Marketing and measurement vendors and service providers. We share information about you with our marketing and measurement vendors and service providers and partners to help us promote the Services to you on apps and websites, and to measure the effectiveness of those promotions.
(g) Third parties designated by you. We may share your personal information with third parties where you have instructed us or provided your consent to do so.
(h) Professional advisors. Professional advisors, such as lawyers, auditors, bankers and insurers, where necessary in the course of the professional services that they render to us.
(i) Authorities and others. Law enforcement, government authorities and private parties, as we believe in good faith to be necessary or appropriate for the compliance and protection purposes described above.
(j) Business transferees. We may disclose personal information in the context of actual or prospective business transactions (e.g., investments and financing of Fixonal and its affiliates, public stock offerings, or the sale, transfer or merger of all or part of our business, assets or shares), for example, we may need to share certain personal information with prospective counterparties and their advisers. We may also disclose your personal information to an acquirer, successor or assignee of Fixonal as part of any merger, acquisition, sale of assets or similar transaction, and/or in the event of an insolvency, bankruptcy or receivership in which personal information is transferred to one or more third parties as one of our business assets.
(k) Other users and the public. At your election, user-generated content data may be visible to other users of the Platforms and the public. For example, other users of the Platforms or the public may have access to your information if you choose to make information available to them, such as when you share content. In addition, we offer users the ability to join a family plan, and certain of their information may be visible to other Invitees based on role permissions.
(l) “Unlimited Family” subscription plan. if you, as an Invitee, join a paid “Unlimited Family” subscription plan through an invitation by its Owner, the Owner of such plan may access certain data of its Invitees, monitor and manage Invitees’ usage, export session data, and view shared information, images and documents, but cannot view personal account details or detailed individual session information.
6.1. In this section, we describe the rights and choices available to all users. Users who are located in Europe can find additional information about their rights below at “Notice to European Users” (Section 14).
(a) Access, correct or update your information. If you have registered for an account with us through the Services, you may review and update certain account information by logging into the account.
If you wish to make an access request for access to a copy of the personal data which we hold about you or information about the ways in which we use or disclose your personal data, please note that a reasonable fee may be charged for an access request. If so, we will inform you of the fee before processing your request.
We will respond to your request as soon as reasonably possible. In general, our response will be within thirty (30) business days. Should we not be able to respond to your request within thirty (30) days after receiving your request, we will inform you in writing within thirty (30) days of the time by which we will be able to respond to your request. If we are unable to provide you with any personal data or to make a correction requested by you, we shall generally inform you of the reasons why we are unable to do so (except where we are not required to do so under the PDPA).
(b) Linked third party platforms. If you choose to connect to the Services through your Google, or Apple account, or other third party platform, you may be able to use your settings in your account with that platform to limit the information we receive from it. If you revoke our ability to access information from a third party platform, that choice will not apply to information that we have already received from that third party.
(c) Delete your content or close your account. If you are an individual user, you can choose to delete certain content through your account. If you wish to request to close your account by submitting your request via email to our Data Protection Officer at dpo@fixonal.com.
(d) “Unlimited Family” subscription plan privacy controls. As an Invitee of a paid “Unlimited Family” subscription plan, you have the ability to manage your privacy settings through the Platforms’ features, such as restricting the sharing of certain information, images or documents with other Invitees or the Owner of a paid “Unlimited Family” subscription plan. However, certain information (e.g., aggregate usage) may still be accessible to the Owner as required to carry out its obligations under the Terms or this Privacy Policy and comply with applicable laws.
(e) Withdrawing your consent i.e. opt-out of marketing communications. After opting in, you may opt out of marketing-related emails by following the opt-out or unsubscribe instructions at the bottom of the email, or by submitting your request via email to our Data Protection Officer at dpo@fixonal.com. Please note that if you choose to opt-out of marketing-related emails, you may continue to receive service-related and other non-marketing emails.
(f) Declining to provide information. We need to collect personal information to provide certain services. If you do not provide the information we identify as required or mandatory, we may not be able to provide those services.
(g) Withdrawing your consent. The consent that you provide for the collection, use and disclosure of your personal data will remain valid until such time it is being withdrawn by you in writing. You may withdraw consent and request us to stop collecting, using and/or disclosing your personal data for any or all of the purposes listed above by submitting your request in writing or via email to our Data Protection Officer at dpo@fixonal.com.
Upon receipt of your written request to withdraw your consent, we may require reasonable time (depending on the complexity of the request and its impact on our relationship with you) for your request to be processed and for us to notify you of the consequences of us acceding to the same, including any legal consequences which may affect your rights and liabilities to us. In general, we shall seek to process your request within ten (10) business days of receiving it.
Whilst we respect your decision to withdraw your consent, please note that depending on the nature and scope of your request, we may not be in a position to continue providing the Services to you and we shall, in such circumstances, notify you before completing the processing of your request. Should you decide to cancel your withdrawal of consent, you may submit your request in writing or via email to our Data Protection Officer at dpo@fixonal.com.
Please note that withdrawing consent does not affect our right to continue to collect, use and disclose personal data where such collection, use and disclose without consent is permitted or required under applicable laws.
6.2. For information about cookies and other technologies employed by the Services and how to control them, see our Cookie Policy, here: https://keppt.me/cookies.
7.1. The Platforms contains AI features and AI integrations which process the following information you provide and generate outputs (including responses, translations, reminders, translation, currency conversion and data analytics) based on the accuracy of:
(a) Your inputs (information, text, images, documents, prompts and questions); and
(b) Context required to provide the feature (e.g., language settings, reminders, translation, currency conversion, data analytics).
7.2. Controls and limitations:
(a) We apply access controls and technical safeguards to reduce exposure of Personal Data.
(b) We may use de-identification, aggregation or redaction techniques where practicable.
(c) Where any Sensitive Information or Special Categories of Data is uploaded to the Platforms, such data extracted from your documents is used solely to power the features you use it for (search, organisation, reminders, insights) and is not used for any secondary purpose, including marketing or model training. “Special Categories of Data” or “Sensitive Information” means any of the following types of Personal Information: (i) social security number, taxpayer identification number, passport number, driver’s license number or other government-issued identification number; or (ii) credit or debit card details or financial account number, with or without any code or password that would permit access to the account, credit history, or (iii) information on race, religion, ethnicity, sex life or practices, medical or health information, genetic or biometric information, biometric templates, political or philosophical beliefs, political party or trade union membership, background check information, judicial data such as criminal records or information on other judicial or administrative proceedings, or any other category of Personal Information identified as special or sensitive under applicable laws.
(d) We do not use identity or health document content to build inferred profiles about you beyond the features described in this Policy.
7.3. Automated decision-making and profiling:
(a) We do not use your information to train, fine-tune, or otherwise improve any AI model, whether ours, our sub-processors’, or any third party’s.
(b) Vertex AI is used under Google Cloud’s terms, which provide that customer data submitted to the service is not used to train Google’s foundation models.
7.4. Where our AI processing constitutes use of personal data in a recommendation or decision system for PDPA purposes, we have had regard to the Personal Data Protection Commission's Advisory Guidelines on the Use of Personal Data in AI Recommendation and Decision Systems in designing this feature.
7.5. Document classification, field extraction, and reminders are automated processes, but they do not produce legal or similarly significant effects concerning you, and we do not use them to make decisions about you. Nonetheless, you should be aware that AI outputs are best-effort and may be inaccurate or incomplete. Known risk categories include OCR misreads, document misclassification, incorrect extraction of personal data, amounts, dates, vendor names or document numbers, missed reminders and the model inferring fields that are not actually present in a document. These are inherent characteristics of AI systems, not defects specific to our implementation.
8.1. In addition to the individual “Free”, “Basic” and “Unlimited” subscription plan, the Platforms allow the Owner of the group “Unlimited Family” subscription plan to invite a small number of Invitees (for example, a spouse, family member or trusted advisor) to view the images, documents and data that you explicitly add to that family plan.
8.2. Without limitation to the “Notice to European users”, if you are the Owner of the family plan and you or your Invitees add images, documents or data containing another person’s personal data to it (for example, a joint account statement, or a family member’s medical record), the Owner may act as the data controller in relation to that data as between you and your Invitees, and we may act as a processor providing the hosting and organisational infrastructure for that sharing. You (as the Owner) are responsible for complying with all applicable laws, including ensuring you have an appropriate lawful basis to upload and/or share such documents, for respecting any data subject rights requests from individuals represented in those documents, and for managing your Invitees’ access.
8.3. Invitees to a family plan and other individuals are data subjects of Fixonal in their own right only to the extent these individuals can be identified from the images, documents and data, or in respect of their own account and usage data. Requests by any Invitee to access, correct or delete personal data contained within a family plan should generally be directed to the Owner of the “Unlimited Family” subscription plan in the first instance; Fixonal will support the Owner in fulfilling such requests through the Platform’s export and deletion tools, or by submitting the request via email to our Data Protection Officer at dpo@fixonal.com.
8.4. The Owner of the “Unlimited Family” subscription plan controls access permissions (to access, view, comment or download) and may revoke any Invitee’s access at any time, after which such Invitee can no longer view the shared information, images and documents in the family plan on subsequent access to the Services. We are not responsible for any actions taken by the Owner of the “Unlimited Family” subscription plan.
9.1. To safeguard your personal data from unauthorised access, collection, use, disclosure, copying, modification, disposal or similar risks, we have introduced appropriate administrative, physical and technical measures such as through:
(a) minimised collection of personal data,
(b) authentication and access controls (such as good password practices, need-to-know basis for data disclosure, etc.),
(c) encryption of data,
(d) data anonymisation,
(e) up-to-date antivirus protection,
(f) regular patching of operating system and other software,
(g) securely erase storage media in devices before disposal,
(h) web security measures against risks,
(i) usage of one-time password (OTP) / 2 factor authentication (2FA) / multi-factor authentication (MFA) to secure access, and
(j) security review and testing performed regularly.
9.2. You should be aware, however, that no method of transmission over the Internet or method of electronic storage is completely secure. While security cannot be guaranteed, we strive to protect the security of your information and are constantly reviewing and enhancing our information security measures. No system is completely secure and you must notify us immediately of suspected unauthorised access.
9.3. Please submit your personal data or personal information at your own discretion; we accept no liability for any unauthorised circumvention of the Services’ or third party privacy or security measures.
10.1. We maintain incident response procedures to assess, contain, investigate and remediate suspected or confirmed data breaches. Where a data breach meets the PDPA threshold for notification (e.g., results in, or is likely to result in, significant harm to individuals or is of a significant scale), we will:
(a) Notify the Singapore Personal Data Protection Commission (PDPC) as required; and
(b) Notify affected individuals (or school, where applicable) as required under applicable laws or pursuant to any direction or decision by a competent court or authority.
11.1. We may retain your personal data for as long as it is necessary to fulfil the purpose for which it was collected or as required or permitted by applicable laws.
11.2. We generally retain personal information to fulfil the purposes for which we collected it, and for the purposes of satisfying any legal, accounting, tax or other compliance or regulatory requirements, to establish or defend legal claims, or for fraud prevention purposes.
11.3. To determine the appropriate retention period for personal information, we may consider factors such as the amount, nature, and sensitivity of the personal information, the potential risk of harm from unauthorised use or disclosure of your personal information, the purposes for which we process your personal information and whether we can achieve those purposes through other means, and the applicable legal requirements.
11.4. When no longer needed, we will securely delete or anonymise the data, subject to technical and legal constraints.
11.5. We will cease to retain your personal data, or remove the means by which the data can be associated with you, as soon as it is reasonable to assume that such retention no longer serves the purpose for which the personal data was collected, and is no longer necessary for legal or business purposes.
12.1. We, and our sub-processors, may store/process data in: Singapore, Iowa, USA and the Netherlands.
12.2. For transfers subject to the PDPA’s transfer limitation obligation, we take steps to ensure that overseas recipients of personal data are bound by legally enforceable obligations to provide a standard of protection comparable to the PDPA.
12.3. Where personal data is transferred from the European Economic Area, the United Kingdom or Singapore to a jurisdiction that has not been determined to provide an adequate level of protection, we rely on appropriate safeguards required by applicable law, which may include the European Commission’s Standard Contractual Clauses, the UK’s International Data Transfer Addendum, and/or our sub-processors’ own certifications and contractual commitments (for example, under Google Cloud’s data processing terms).
12.4. A copy of the relevant transfer safeguards is available by submitting your request via email to our Data Protection Officer at dpo@fixonal.com.
13.1. The Platforms may contain links to websites, mobile applications, AI integrations and other services operated by third parties. In addition, our content may be integrated into web pages or other online services that are not associated with us. These links and integrations are not an endorsement of, or representation that we are affiliated with, any third party.
13.2. We do not control websites, mobile applications, AI integrations or other services operated by third parties, and we are not responsible for their actions. We encourage you to read the privacy policies of the other websites, mobile applications, AI integrations and online services you use.
13.3. You should review the relevant third party licensors, service providers and integrated services where privacy policies and terms of use, including but not limited to:
(a) Google Play Store: If you use the Google Play Store, Google will process certain data under its own privacy policies and terms;
(b) Google Firebase Authenticator: If you use Google sign-in or related security features, Google will process certain data under its own privacy policies and terms;
(c) Apple App Store: If you use the Apple App Store, Apple will process certain data under its own privacy policies and terms;
(d) Apple Authenticator App: If you use Apple sign-in or related security features, Apple will process certain data under its own privacy policies and terms;
(e) Google Cloud Platform (GCP): Provides data warehouse services used to store, manage, and process personal data in a secure environment; Provides cloud infrastructure and hosting services used by Fixonal to store and process data; GCP will process certain data under its own privacy policies and terms;
(f) Google Vertex AI (now known as the Gemini Enterprise Agent Platform): Artificial intelligence enabled functionality for Google Gemini. Google will process certain data under its own privacy policies and terms;
(g) RevenueCat: If you make any payment, RevenueCat will process certain data under its own privacy policies and terms;
(h) Sentry: Provides application error tracking and monitoring services; Sentry will process certain data under its own privacy policies and terms;
(i) Anthropic: Provider for backend support of AI-enabled functionality. If you activate any AI Integration, Anthorpic will process certain data under its own privacy policies and terms; and
(j) OpenAI: Provider for evaluating the effectiveness of our Large Language Models (LLM). If you activate any AI Integration, OpenAI will process certain data under its own privacy policies and terms.
13.4. These third party service providers (or sub-processors) are required for us to host, distribute and bill for the Service through those channels; if you do not wish your data to be processed by them, you may be unable to use the corresponding distribution channel (for example, in-app subscription billing on iOS or Android) or we may not be able to provide you the Services.
13.5. We may update this list as our sub-processors change. We will reflect additions or replacements by updating this Policy and, where the change is material, providing notice as described in “Changes to this Policy”.
14.1. The terms set out below applies only to individuals in the United Kingdom and the European Economic Area.
(a) Personal information. References to “personal information” in this Privacy Policy should be understood to include a reference to “personal data” (as defined in the GDPR) – i.e., information about individuals from they are either directly identified or can be identified.
(b) Controller. Fixonal is the controller in respect of the processing of your personal information covered by this Privacy Policy for purposes of European data protection legislation (i.e., the EU GDPR and UK GDPR (collectively, the “GDPR”)).
(c) Processor. For personal data that we process on behalf of the Owner of the “Unlimited Family” subscription plan, the Owner is the controller and we are their processor under the GDPR. Invitees should direct data subject requests to the respective Owner in the first instance.
(d) Our GDPR Representatives and Data Protection Officer. We have appointed a Data Protection Officer (DPO) who also serves as the GDPR Representatives. The DPO independently performs their duties in compliance with the GDPR (as applicable). The DPO’s contact details are provided in the “Contact Us” section.
(e) Our legal bases for processing. Our legal bases for processing your personal information described in this Policy are listed below, generally:
(i) Consent. We process information for certain purposes as described below only when you have given us your consent to do so, and where we have your specific consent to carry out the processing for the Purpose in question
(ii) Contractual Necessity. Where we need to perform a contract, we are about to enter into or have entered into with you.
(iii) Legitimate Interests. Where it is necessary for our legitimate interests and your interests and fundamental rights do not override those interests.
(iv) Compliance with Law. Where we need to comply with a legal or regulatory obligation.
| Purpose | Legal Basis |
|---|---|
| Providing the Services, account administration, AI analytics, classification/extraction, reminders, subscription management and operations | Contractual Necessity |
| Service integrity, security, fraud prevention | Compliance with Law Legitimate Interests. We have a legitimate interest in ensuring the ongoing security and proper operation of the Services and associated IT services, systems, and networks. |
| Service improvement and analytics | Legitimate Interests. We have a legitimate interest in providing you with a good service, which is personalised to you and that remembers your selections and preferences. Consent, in respect of any optional cookies used for this purpose. |
| Legal and regulatory compliance | Compliance with Law. Legitimate interest. Where Compliance with Law is not applicable, we and any relevant third parties have a legitimate interest in participating in, supporting, and following legal process and requests, including through co-operation with authorities. We and any relevant third parties may also have a legitimate interest of ensuring the protection, maintenance, and enforcement of our and their rights, property, and/or safety. |
| Marketing communications | Legitimate Interests. We have a legitimate interest in promoting our operations and goals as an organisation and sending marketing communications for that purpose. You have the choice to withdraw consent i.e. opt-out of receiving marketing communications at any time. |
| Research and development /To create aggregated, de-identified and/or anonymised data | Legitimate interest. We have legitimate interest, and believe it is also in your interests, that we are able to take steps to ensure that the Services operate as intended. |
| Processing of special category document content (financial, identity documents, health, household/lifestyle, payment data) | Consent, if the relevant further use is not compatible with the initial purpose for which the personal information was collected. |
| Additional uses | The original legal basis relied upon, if the relevant further use is compatible with the initial purpose for which the Personal Information was collected. Consent, if the relevant further use is not compatible with the initial purpose for which the personal information was collected. |
(f) Your rights. European data protection laws give you certain rights regarding your personal information. If you are located in Europe, you may ask us to take the following actions in relation to your personal information that we hold:
(i) Access. Provide you with information about our processing of your personal information and give you access to your personal information.
(ii) Correct. Update or correct inaccuracies in your personal information.
(iii) Delete. Delete your personal information where there is no good reason for us continuing to process it.
(iv) Transfer. Transfer a machine-readable copy of your personal information to you or a third party of your choice.
(v) Restrict. Restrict the processing of your personal information, for example if you want us to establish its accuracy or the reason for processing it.
(vi) Object. Object to our processing of your personal information where we are relying on Legitimate Interests; also object to direct marketing at any time.
(vii) Withdraw Consent. When we use your personal information based on your consent, you may withdraw that consent at any time.
(g) Exercising these rights. You may submit requests by email to dpo@fixonal.com. We may request specific information from you to help confirm your identity and process your request. Whether or not we are required to fulfill any request you make will depend on several factors (e.g., why and how we are processing your personal information). If we reject any request you may make (whether in whole or in part) we will let you know our grounds for doing so at the time, subject to any legal restrictions.
(h) Your Right to Lodge a Complaint with your Supervisory Authority. In addition to your rights outlined above, if you are not satisfied with our response to a request you make, or how we process your personal information, you can make a complaint to the data protection regulator in your habitual place of residence as set out in “Contact Us”.
(i) Data Processing outside Europe.
(i) We may share your personal information with third parties who are based outside Europe.
(ii) Where we share your personal information with third parties who are based outside Europe, we try to ensure a similar degree of protection is afforded to it by implementing one of the following mechanisms:
(iii) Transfers to territories with an adequacy decision. We may transfer your personal information to countries or territories whose laws have been deemed to provide an adequate level of protection for personal information by the European Commission or UK Government (as and where applicable) (from time to time) or under specific adequacy frameworks approved by the European Commission or UK Government (as and where applicable) (from time to time).
(iv) Transfers to territories without an adequacy decision. We may transfer your personal information to countries or territories whose laws have not been deemed to provide such an adequate level of protection (e.g. the United States, Australia or Singapore).
(v) However, in these cases:
(A) we may use specific appropriate safeguards, which are designed to give personal information effectively the same protection it has in Europe – for example, standard-form contracts approved by relevant authorities for this purpose; or in limited circumstances, we may rely on an exception, or ‘derogation’, which permits us to transfer your personal information to such country despite the absence of an ‘adequacy decision’ or ‘appropriate safeguards’ – for example, reliance on your explicit consent to that transfer.
(vi) You may contact us if you want further information on the specific mechanism used by us when transferring your personal information out of Europe. You may have the right to receive a copy of the appropriate safeguards under which your personal information is transferred by contacting us at dpo@fixonal.com.
(j) Data Breach Notification.
(i) Where we are the data controller, in the case of a personal data breach, we shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay.
(ii) Where we are the data processor, we shall notify the data controller without undue delay after becoming aware of a personal data breach.
(iii) Where you are the data processor, you shall notify us without undue delay after becoming aware of a personal data breach.
15.1. This Policy applies in conjunction with any other terms, agreements or contracts and consent clauses that apply in relation to the collection, use and disclosure of your personal data by us.
15.2. We may revise this Policy from time to time without any prior notice. If changes are material, we will provide notice via the Platforms or other appropriate means, and, where required by applicable law, we will seek your consent. You may determine if any such revision has taken place by referring to the date on which this Policy was last updated. Your continued access of the Platforms and/or use of the Services constitutes your acknowledgement and acceptance of such changes.
15.3. We encourage you to review this Policy periodically. The “Last Updated” date of this Policy indicates when it was last revised.
16.1. If you have any questions about this Privacy Policy, you may contact our Data Protection Officer if you have any enquiries or feedback on our personal data protection policies and procedures, or if you wish to make any request, in the following manner:
Address to: Data Protection Officer
Contact Number: [please provide]
Email Address: dpo@fixonal.com
16.2. We may need to verify your identity before fulfilling requests and may charge an administrative fee to assist with certain requests. For accounts on the “Unlimited Family” subscription plan, we may route requests of any Invitees through the Owner, where appropriate.
16.3. If you have a concern about how we handle your personal data, we encourage you to contact us first so that we can try to resolve it. You also have the right to lodge a complaint with a supervisory authority, including:
(a) Singapore: the Personal Data Protection Commission (PDPC), www.pdpc.gov.sg.
(b) United Kingdom: the Information Commissioner's Office (ICO), www.ico.org.uk.
(c) European Union: the data protection authority of your EU member state of habitual residence, place of work, or the place of the alleged infringement.
(d) Other jurisdictions: the applicable data protection or privacy authority in your country of residence.
16.4. We aim to respond within a reasonable time and in any event in accordance with applicable laws.
Last Updated: 1 September 2026
Effective Date: 5 September 2026