Privacy Policy
Last updated 20 September 2026
This Privacy Notice explains how Alora Technologies Pte. Ltd. ('Alora', 'we', 'us' or 'our') accesses, collects, stores, uses and shares ('processes') personal information when you:
- visit our website at https://alorawork.com or any other website of ours that links to this Privacy Notice;
- use the Alora application or any other application of ours that links to this Privacy Notice;
- receive custom software, forward-deployed engineering, workflow or AI services from us under a written agreement; or
- contact us or engage with us in other related ways, including marketing, scheduling a meeting, messaging us or attending events.
The two roles we act in. Please read this section first, because the rest of this notice depends on it.
- When we decide why and how information is processed, we are the controller (in Singapore terms, the organisation responsible for the data). This covers website visitors, people who contact us, our own account holders, prospective customers and the business contacts of our customers.
- When we process information inside a system we build, host or operate for a business customer, that customer decides why and how it is processed. We act as their processor (a data intermediary under the PDPA). In that case the customer's own privacy notice applies to the individuals concerned, and our handling of that information is governed by our agreement with that customer rather than by this notice. Section 6 explains what we do and do not do with customer content. If you are an employee, client or contact of one of our customers and you want to exercise privacy rights over information held in their system, please contact that organisation first; we will support them in responding.
Questions or concerns? If you do not agree with our policies and practices, please do not use our Services. If you have questions, contact us at contact@alorawork.com.
SUMMARY OF KEY POINTS
What personal information do we process? Contact and account details you give us, information we collect automatically when you use our website and applications, information from the messaging and scheduling tools you use to reach us, and information contained in accounts or files a customer connects to a system we operate for them. Learn more in Section 1.
Do we process sensitive personal information? We do not ask for sensitive personal information, for example racial or ethnic origin, health, sexual orientation or religious beliefs, and we ask customers not to place it in systems we operate unless we have agreed to it in writing in advance.
Do we collect information from third parties? Yes, in limited cases: from a business customer who gives us the contact details of their staff, from systems a customer authorises us to connect to on their behalf, and from the providers we use to receive messages and book meetings. We do not buy personal information from data brokers.
How do we process your information? To provide, secure, improve and administer our Services, to perform our contracts, to communicate with you, for security and fraud prevention, and to comply with the law. Learn more in Section 2.
When do we share personal information? With the service providers that help us run the Services, with a customer's own organisation where the information belongs to that customer, in connection with a business transfer, and where the law requires it. We do not sell personal information and we do not share it for advertising. Learn more in Section 4.
Do we use your information to train AI models? No. We do not use customer content or personal information to train our own or any third party's general-purpose AI models. Learn more in Section 6.
How do we keep your information safe? Through the organisational and technical measures described in Section 8. No system can be guaranteed to be completely secure.
What are your rights and how do you exercise them? Depending on where you live, you may have rights of access, correction, deletion, portability, objection and withdrawal of consent. Email contact@alorawork.com to exercise them. Learn more in Section 10.
TABLE OF CONTENTS
- What information do we collect?
- How do we process your information?
- What legal bases do we rely on?
- When and with whom do we share your personal information?
- Connected accounts and integrations
- Customer content, AI processing and our role as a processor
- How long do we keep your information?
- How do we keep your information safe?
- Do we collect information from minors?
- What are your privacy rights?
- Controls for do-not-track features
- United States residents
- Do we make updates to this notice?
- How can you contact us about this notice?
- How can you review, update or delete the data we collect from you?
- Language of this notice
1. WHAT INFORMATION DO WE COLLECT?
Personal information you disclose to us
In short: we collect the personal information you provide to us.
We collect personal information that you give us when you register for an account, ask about our products and services, take part in activities on the Services, or contact us. What we collect depends on how you interact with us, and may include:
- names;
- email addresses;
- telephone numbers, where you give them to us or contact us by phone or messaging;
- job titles and employer;
- usernames and authentication data, including the password you set;
- contact preferences;
- the content of your messages to us; and
- billing information, where you buy a paid plan or subscription.
Payment information. Card payments are handled by our payment providers. Card details are collected and processed by those providers in accordance with applicable law and card-scheme rules, and we receive only the information we need to identify and manage the transaction, such as the payment reference, the amount and the outcome.
All personal information you provide must be true, complete and accurate, and you must tell us if it changes.
Sensitive information. We do not ask for sensitive personal information and we ask you not to send it to us.
Information we collect automatically
In short: some information, such as your IP address and browser or device characteristics, is collected automatically when you use our Services.
- Log and usage data. Service-related, diagnostic, usage and performance information our servers record in log files. This may include your IP address, device information, browser type and settings, date and time stamps, pages and files viewed, searches, features used, and error reports.
- Device data. Information about the computer, phone, tablet or other device you use, which may include device and application identifiers, hardware model, operating system, internet service provider or mobile carrier, browser type and system configuration.
- Approximate location. We derive an approximate location, usually at city or country level, from your IP address. This is not precise location data. Where a service we build or operate for a business customer requires precise device location, for example to confirm that a vehicle or a field worker is at an agreed site, we will make that clear in advance and it will only work with the permission of the person using the device, which can be withdrawn at any time in the device settings.
- Cookies and similar technologies. We use cookies and similar technologies to operate the website, keep you signed in and remember your preferences.
Application data
If you use our application(s), we may also collect the device information described above and, if you choose to enable them, push notifications. You can turn push notifications off in your device settings.
Information we receive from others
- From our business customers. A customer may give us the names, business email addresses, job titles and phone numbers of the staff who will use a system we build or support for them.
- From connected accounts. Where a customer authorises us to connect a system we operate to their tools, we receive information from those accounts. See Sections 5 and 6.
- From messaging and scheduling tools. If you message us through WhatsApp or book a meeting through our Google Calendar appointment link, we receive the information you provide through that channel, such as your name, phone number, email address, the meeting details and the content of your message. Those providers process that information under their own terms and privacy policies, which we do not control.
- Meetings. We do not record meetings by default. If we propose to record a meeting or to use a note-taking tool, we will tell you before the meeting starts.
2. HOW DO WE PROCESS YOUR INFORMATION?
In short: we process your information to provide, improve, secure and administer our Services, to perform our contracts, to communicate with you and to comply with the law.
- To create and administer accounts, including authentication and keeping accounts in working order.
- To deliver the services you or your organisation have engaged us for, including building, operating, supporting and improving systems for business customers.
- To respond to enquiries and provide support, including messages sent through our contact channels.
- To arrange and hold meetings that you book with us.
- To take payment and manage billing for paid plans and engagements.
- To send administrative and service messages about changes, security issues and support.
- To send marketing communications where you have asked for them or where we are otherwise permitted to send them, with an opt-out in every message.
- To keep the Services secure, to detect, prevent and investigate fraud, abuse and security incidents, and to enforce our terms.
- To comply with legal obligations and to establish, exercise or defend legal claims.
- To protect an individual's vital interests, such as to prevent harm.
We do not use personal information for advertising, for profiling, or to build products unrelated to the service you or your organisation have asked us for.
3. WHAT LEGAL BASES DO WE RELY ON?
In short: we process personal information only when we have a valid legal reason to do so.
Singapore. We are established in Singapore, and the Personal Data Protection Act 2012 ('PDPA') applies to our processing. We collect, use and disclose personal data with consent, on the basis of deemed consent, or on another basis permitted by the PDPA. You may withdraw consent by contacting us, subject to legal or contractual consequences that we will explain to you.
EU, UK and Switzerland. Where we offer services to, or monitor, people in the EEA, the UK or Switzerland, the GDPR, UK GDPR or Swiss data protection law may also apply to that processing. In those cases we rely on:
- Performance of a contract — to provide the Services to you or to the organisation you act for, and to take steps at your request before entering a contract.
- Legitimate interests — to operate, secure and improve our Services, to market to business contacts, and to protect against fraud and abuse, having considered your rights and interests.
- Consent — where we ask for it, for example for certain marketing. You can withdraw consent at any time.
- Legal obligations — to comply with the law and to defend legal claims.
- Vital interests — in an emergency involving a risk to someone's life or safety.
Canada. We rely on your express consent, or on implied consent where the circumstances allow it, and you may withdraw consent at any time. In the limited cases permitted by Canadian law we may process information without consent, including for fraud detection and prevention, for investigations, in an emergency where consent cannot be obtained in time, or where disclosure is required by a subpoena, warrant or court order.
4. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?
In short: we share information with the providers that help us run the Services, with the organisation the information belongs to, and where the law requires it. We do not sell personal information.
- Service providers. We use third parties to host our infrastructure, store files, send email, process payments, provide security, and supply AI model services. They act on our instructions under written contracts and may not use the information for their own purposes. A business customer can ask us for a current list of the providers used in their deployment.
- Within your organisation. Where you use a system we operate for a business customer, administrators and other authorised people at that organisation can see information in it, according to the permissions that organisation sets.
- Professional advisers. Lawyers, accountants, auditors and insurers, where necessary and under duties of confidence.
- Legal and safety. Where we believe disclosure is required by law, legal process or a government request, or is necessary to investigate potential violations, protect our rights or property, or protect the safety of any person.
- Business transfers. In connection with a merger, financing, acquisition or sale of all or part of our business. We will tell affected customers if this changes who controls their information.
- With your direction. Where you ask us to share information, for example with a partner or an integration you enable.
We do not sell personal information, and we do not share it for advertising purposes.
International transfers. We are based in Singapore. Personal information may be stored or processed on infrastructure located outside Singapore, including that of our hosting and AI providers. Where personal information is transferred out of Singapore, we take steps to ensure it receives protection comparable to that required by the PDPA. Where a transfer is subject to EU or UK law, we rely on an adequacy decision or on standard contractual clauses. You can ask us for details of the safeguards that apply to your information.
5. CONNECTED ACCOUNTS AND INTEGRATIONS
In short: we access third-party accounts only when you or your organisation connects them, and only for the purposes you authorise.
Where you or your organisation connects a third-party account to a system we provide, for example email, calendar, file storage, messaging or a CRM, we access and process information from that account to provide the features you have asked for. We use that information only for the purposes described in this notice, in our agreement with your organisation, or as otherwise made clear to you when you connect the account. You can disconnect an integration at any time, which stops further access but does not by itself delete information already processed. We do not control how those providers handle your information; please review their privacy notices.
Social logins. We do not offer registration or sign-in through a social media account. You create an account with your own email address and a password you set.
6. CUSTOMER CONTENT, AI PROCESSING AND OUR ROLE AS A PROCESSOR
In short: content that a business customer puts into a system we build or operate belongs to that customer. We process it on their instructions, we do not use it to train AI models, and we delete or return it when the engagement ends.
What customer content is. Documents, records, messages, contacts, transactions and other material that a customer, or a person acting for a customer, uploads to or connects to a system we build, host or operate for them, together with the information our systems generate about how that content is used.
Our role. The customer decides why and how customer content is processed. We process it only:
- to provide, support, secure and improve the system we have agreed to provide to them;
- on their documented instructions, including through the settings and permissions they choose; and
- as required by law, in which case we will tell them unless the law prevents us.
AI processing. Where a system uses AI to read, summarise, extract from or act on customer content, that processing happens through the model providers named in our agreement with the customer. We contract with those providers so that customer content is not used to train their models and is retained by them only as long as needed to return a result, subject to their published abuse-monitoring periods.
We do not use customer content or personal information to train our own or any third party's general-purpose AI models, and we do not use one customer's content for another customer.
Who can see customer content. Content in a system we operate is visible to the people that the customer's own administrators authorise, according to the permissions they set, and to the Alora personnel described below. We do not make it public.
Staff access. Access to customer content is limited to the named people who need it to deliver or support the engagement, under confidentiality obligations, with access logged. Whether any Alora person may see a customer's live records, and on what basis, is decided expressly with that customer and recorded in our agreement with them.
Sensitive and regulated data. We ask customers not to put special-category data, health records, payment-card data, government identifiers or other regulated data into systems we operate unless this has been agreed in writing in advance and appropriate additional measures are in place.
Retention and deletion. Customer content is retained for the period agreed with the customer. On request or at the end of an engagement, we return or delete it in accordance with our agreement and our exit checklist, with backups expiring on their normal cycle. See Section 7.
Your rights. If you are an individual whose information appears in customer content, contact the organisation that holds it. If you contact us instead at contact@alorawork.com, we will pass your request to them and help them respond.
7. HOW LONG DO WE KEEP YOUR INFORMATION?
In short: we keep information only as long as we need it for the purposes described in this notice, or for as long as the law requires.
- Account information is kept while the account is open. After an account is closed, we delete or anonymise it within 30 days, except where we need to keep certain records as described below.
- Customer content is kept for the period agreed with the customer concerned.
- Billing and tax records are kept for as long as accounting and tax law requires, generally five years in Singapore.
- Security, incident and audit logs are kept for 12 months.
- Marketing contact details are kept until you unsubscribe, and we then keep a minimal record so that we do not contact you again.
- Records needed to prevent fraud, handle disputes, investigate incidents, enforce our terms or comply with legal obligations are kept for as long as that purpose or the relevant limitation period requires.
When we no longer have a legitimate need to process personal information, we delete or anonymise it. Where deletion is not immediately possible because the information is held in backup archives, we isolate it from further processing and delete it when the backup expires on its normal cycle.
8. HOW DO WE KEEP YOUR INFORMATION SAFE?
In short: we use organisational and technical measures designed to protect personal information, but no system is completely secure.
Our measures include named individual accounts with multi-factor authentication for privileged access, least-privilege access grants that are reviewed and removed when no longer needed, encryption in transit and at rest using our providers' managed encryption, secrets held in approved secret storage rather than in code or tickets, separation between development and production environments, logging and monitoring, and regular backups with tested restoration. Despite these efforts, no transmission over the internet or method of storage can be guaranteed to be completely secure, so we cannot guarantee that unauthorised third parties will never defeat our security. You should access the Services in a secure environment.
If a data breach affects your personal information, we will notify you and the relevant regulator where the law requires it, and we will notify affected business customers in line with our agreement with them.
9. DO WE COLLECT INFORMATION FROM MINORS?
In short: our Services are for adults and organisations, not for children.
The Services are intended for business use by people aged 18 or over. We do not knowingly collect, solicit information from, or market to children under 18, or the equivalent age specified by the law of their jurisdiction, and we do not sell such information. By using the Services, you represent that you are at least 18 or the equivalent age in your jurisdiction. If we learn that we have collected personal information from a person under that age, we will deactivate the account and take reasonable steps to delete the information promptly. If you believe we hold information about a child, contact us at contact@alorawork.com.
10. WHAT ARE YOUR PRIVACY RIGHTS?
In short: depending on where you live, you have rights over your personal information, and you can exercise them by emailing us.
Everyone. You can ask us at any time what personal information we hold about you, ask us to correct it, ask us to delete it, or ask us to stop sending marketing.
Singapore. Under the PDPA you may request access to personal data in our possession or control, information about how it has been used or disclosed in the past year, and correction of inaccurate or incomplete personal data, subject to the exceptions in the Act.
EEA, UK, Switzerland and Canada. Where those laws apply, you may also have the right to restrict or object to processing, to request portability, and not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. If we ever make such a decision, we will tell you, explain the main factors, and offer a simple way to ask for human review.
How to exercise your rights. Email contact@alorawork.com with "privacy request" in the subject line, or write to us at the postal address in Section 14. We will acknowledge your request and respond within the period required by the applicable law, generally within 30 days, and we will tell you if we need more time. We may ask you for information to verify your identity, and we will use that information only for verification.
Withdrawing consent. Where we rely on consent, you may withdraw it at any time by contacting us or updating your preferences. This does not affect the lawfulness of processing before withdrawal, or processing that relies on another legal basis.
Marketing. You can unsubscribe at any time using the link in any marketing message or by contacting us. We may still send service messages about your account.
Complaints. We would appreciate the chance to address your concerns first. You may also complain to your data protection authority: in Singapore, the Personal Data Protection Commission; in the EEA or UK, your national authority; in Switzerland, the Federal Data Protection and Information Commissioner.
Account information
You can review or change your account information by logging in to your account settings, or by asking us. If you ask us to close your account, we will deactivate or delete it and remove your information from our active databases, subject to the retention periods in Section 7.
11. CONTROLS FOR DO-NOT-TRACK FEATURES
Most browsers and some mobile operating systems offer a Do-Not-Track ('DNT') setting. No uniform standard for recognising and implementing DNT signals has been finalised, so we do not currently respond to DNT signals or similar mechanisms. If a standard is adopted that we must follow, we will describe our practice in an updated version of this notice.
12. UNITED STATES RESIDENTS
Several US states give residents rights over their personal information, including the right to know what we process, to access it, to correct inaccuracies, to request deletion, to obtain a copy, to be free from discrimination for exercising those rights, and to opt out of the sale of personal data, targeted advertising and certain profiling.
We do not sell personal information, we do not share it for targeted advertising, and we do not use it for profiling that produces legal or similarly significant effects.
If you are a US resident and you want to exercise any of these rights, email contact@alorawork.com and we will respond as the applicable law requires, whether or not that law applies to us by its own terms. You may use an authorised agent, who must provide proof of their authority. We will verify your identity before acting. If we decline to act on your request, you may appeal by replying to our decision, and we will respond in writing with our reasons.
13. DO WE MAKE UPDATES TO THIS NOTICE?
In short: yes, we update this notice as needed.
We may update this notice from time to time. The updated version will be shown by a new 'Last updated' date at the top. If we make material changes, we will post a prominent notice or contact you directly. We encourage you to review this notice periodically.
14. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?
For questions, comments or privacy requests, contact us by email at contact@alorawork.com or by post at:
Alora Technologies Pte. Ltd.
221 Henderson Road, #08-18
Henderson Building
Singapore 159557
UEN: 202614913K
15. HOW CAN YOU REVIEW, UPDATE OR DELETE THE DATA WE COLLECT FROM YOU?
To request access to, correction of, a copy of, or deletion of your personal information, or to withdraw consent, email contact@alorawork.com with "privacy request" in the subject line, or write to the address in Section 14. These rights may be limited in some circumstances by applicable law.
16. LANGUAGE OF THIS NOTICE
This notice is published in English. Any translation is provided for convenience only and is machine-assisted unless stated otherwise. If there is any conflict or difference in meaning between the English version and a translation, the English version prevails, except where the law of your country requires otherwise.