Governance Row
PRIVACY

Privacy Policy

Last updated 21 August 2026

Governance Row Pte. Ltd. (UEN 202635495N) ("Governance Row", "we") is a Singapore company. This policy explains how we collect, use, and protect personal data in accordance with the Singapore Personal Data Protection Act 2012 (PDPA). It covers our website (governancerow.com) and our platform (app.governancerow.com).

What we collect

Website. When you download a resource, request a demonstration, or contact us, we collect the information you provide: typically your name, work email address, and firm. Our site may also collect standard technical data such as browser type and pages visited.

Platform. When your firm uses the Governance Row platform, we collect account information for each user: name, work email address, role, and authentication data.

Platform content. The governance records your firm creates in the platform (AI inventories, assessments, controls, evidence) are your firm's business data. We process it on your firm's behalf under our Data Processing Agreement, which governs that data. This policy covers personal data; the DPA covers your firm's content.

How we use it

We use personal data to provide the services you ask for: delivering resources you request, responding to enquiries, operating platform accounts, sending service communications, and, where you have provided a work email in a business context, telling you about Governance Row's products and relevant regulatory developments. You can opt out of non-service communications at any time using the unsubscribe link in any email or by writing to dpo@governancerow.com.

Consent

By providing your personal data through our forms or platform, you consent to its collection, use, and disclosure as described in this policy. You may withdraw consent at any time by contacting dpo@governancerow.com; we will explain the consequences of withdrawal, such as no longer being able to provide a service that depends on the data.

Who we share it with

We do not sell personal data. We share it only with the service providers that run our infrastructure: Vercel (application hosting), Supabase (database and authentication, hosted in Singapore), and Resend (email delivery). Each processes data only to provide its service to us. Where a provider processes data outside Singapore, we ensure a standard of protection comparable to the PDPA through the provider's contractual commitments and certifications. We may also disclose personal data where required by law.

Analytics and cookies

Our website uses analytics to understand how the site is used, which may set cookies and collect technical identifiers. You can control cookies through your browser settings.

Retention

We keep personal data only as long as needed for the purposes above or as required by law. Platform account data is deleted in accordance with our Data Export and Exit Guarantee when a subscription ends. You may ask us to delete your data at any time, subject to legal retention requirements.

Access and correction

You may request access to the personal data we hold about you, or ask us to correct it, by writing to dpo@governancerow.com. We respond to access requests within the timeframes the PDPA prescribes.

Security

Personal data is protected by encryption in transit and at rest, mandatory multi-factor authentication on platform accounts, and role-based access controls. Details are set out in our security documentation, available on request.

Children

Our services are for businesses and are not directed at children.

Changes

We may update this policy from time to time. The date above reflects the latest version, and material changes will be noted on this page.

Contact

Data protection queries: dpo@governancerow.com

Governance Row Pte. Ltd., Singapore.