Legal
Privacy Policy
01About us
MILEO LLP (UEN T26LL0601G) is a Singapore-registered marketing studio. This policy explains what personal data we collect, how we use and protect it, and the choices you have. We follow Singapore's Personal Data Protection Act 2012 (the "PDPA") and other applicable laws.
02Our two roles
Depending on the work, we act as one of two things. As a data controller we're responsible for the full set of PDPA obligations. As a data intermediary we only process data on a client's instructions, and just sections 24, 25 and 26C(3) of the PDPA apply to us. When we're acting as an intermediary, it's the client's own privacy policy that governs your rights, not this one.
| Activity | MILEO's role |
|---|---|
| mileo.sg visitors and enquiries | Data controller. This policy applies. |
| Vendor and contractor records | Data controller. This policy applies. |
| Client CRM data, Klaviyo campaigns for clients | Data intermediary. The client's policy applies. |
| Meta Lead Ads naming the client as controller | Data intermediary. The client's policy applies. |
03What we collect, and why
Website visitors and enquiries
- Your name, email, company, how you heard about us, and your message, when you fill in our enquiry form. We use these only to reply to you.
- Basic server logs, including IP address, kept by our host for security and to keep the site running. We don't run any analytics or tracking on the site.
Vendors and contractors
- Name, email, phone and bank details, from contracts. We use these to run the working relationship and to pay you.
04Our legal bases
We rely on one of these, depending on the situation:
- Express consent. For example, when you send us an enquiry.
- Deemed consent by conduct (s.15 PDPA). When you hand over data as part of a transaction.
- Deemed consent by notification (s.15A PDPA). When we tell you the purpose and you don't object within a reasonable time.
- Legal obligation. Such as keeping tax and accounting records.
05Third parties and overseas transfers
We only share your data with the service providers below. Each is bound by terms that give your data a standard of protection comparable to the PDPA (s.26).
| Recipient | Location | Purpose |
|---|---|---|
| Netlify, Inc. | USA | Website hosting |
| Klaviyo Inc. | USA | Email marketing platform |
| Meta Platforms Ireland Ltd | Ireland / USA | Ad delivery, Lead Ads, Custom Audiences |
| Google LLC | USA | Ads (client campaigns), Google Workspace |
| Xero Ltd | New Zealand | Invoicing and accounting |
We don't sell your personal data, and we won't share it beyond this list without your consent, unless the law requires it.
06Cookies
We keep cookies to a minimum. The site uses only strictly necessary cookies that keep it working, and those don't need your consent. We don't use analytics or advertising cookies, and there's no tracking pixel on the site. If that ever changes, we'll update this policy and ask for your consent first.
07AI and automated processing
We use AI features inside Klaviyo (predictive analytics) and Meta Advantage+ (campaign optimisation). These can tailor what you see based on how you behave. If any of this ever has a significant effect on you, we'll tell you specifically and ask for your consent, in line with the PDPC's Advisory Guidelines on AI Recommendation and Decision Systems (March 2024).
08How long we keep it
- Website enquiries: 2 years from your last contact with us.
- Vendor and contractor records: for the length of the relationship, plus 7 years.
- Financial records: 5 years (Income Tax Act 1947).
09How we protect it
We protect personal data with multi-factor authentication on every system that holds it, encryption in transit and at rest, access limited to people who need it, and immediate removal of access when someone leaves.
10Your rights
You can ask us to do any of the following, at any time:
| Right | What it means | How to exercise it |
|---|---|---|
| Access | Ask for a copy of your data, and how we've used it over the past 12 months | Email dpo@mileo.sg |
| Correction | Ask us to fix data that's wrong or incomplete | Email dpo@mileo.sg |
| Withdraw consent | Withdraw your consent for any or all purposes | Email dpo@mileo.sg |
We'll respond to access and correction requests within 30 calendar days.
11Do Not Call Registry
If we ever run SMS or telemarketing, we check Singapore's Do Not Call Registry (dnc.gov.sg) before each campaign, and we won't message registered numbers without your clear, specific consent. You can add your number at dnc.gov.sg.
12Data breaches
If a breach is serious enough to be notifiable, meaning it causes significant harm or affects 500 or more people, we'll report it to the PDPC within 3 calendar days of our assessment, and tell the people affected where Part 6A of the PDPA requires it.
13Children
Our site isn't aimed at children under 13. If we find we've collected their data, we'll delete it. Anyone aged 13 to 17 can give valid consent if they understand what they're agreeing to, in line with the PDPC's Children's Personal Data Advisory Guidelines (March 2024).
14Contact our DPO
For any question, to access or correct your data, to withdraw consent, or to make a complaint, get in touch with our DPO:
15Updates to this policy
We may update this policy from time to time. If we make a material change, we'll let you know by email or with a banner on the site.
| Version | Date | Summary |
|---|---|---|
| 1.0 | 26 May 2026 | Initial publication |