Privacy Policy
Last updated 21 August 2026
Governance Row Pte. Ltd. (UEN 202635495N) ("Governance Row", "we") is a Singapore company. This policy explains how we collect, use, and protect personal data in accordance with the Singapore Personal Data Protection Act 2012 (PDPA). It covers our website (governancerow.com) and our platform (app.governancerow.com).
What we collect
Website. When you download a resource, request a demonstration, or contact us, we collect the information you provide: typically your name, work email address, and firm. Our site may also collect standard technical data such as browser type and pages visited.
Platform. When your firm uses the Governance Row platform, we collect account information for each user: name, work email address, role, and authentication data.
Platform content. The governance records your firm creates in the platform (AI inventories, assessments, controls, evidence) are your firm's business data. We process it on your firm's behalf under our Data Processing Agreement, which governs that data. This policy covers personal data; the DPA covers your firm's content.
How we use it
We use personal data to provide the services you ask for: delivering resources you request, responding to enquiries, operating platform accounts, sending service communications, and, where you have provided a work email in a business context, telling you about Governance Row's products and relevant regulatory developments. You can opt out of non-service communications at any time using the unsubscribe link in any email or by writing to dpo@governancerow.com.
Consent
By providing your personal data through our forms or platform, you consent to its collection, use, and disclosure as described in this policy. You may withdraw consent at any time by contacting dpo@governancerow.com; we will explain the consequences of withdrawal, such as no longer being able to provide a service that depends on the data.
Who we share it with
We do not sell personal data. We share it only with the service providers that run our infrastructure: Vercel (application hosting), Supabase (database and authentication, hosted in Singapore), and Resend (email delivery). Each processes data only to provide its service to us. Where a provider processes data outside Singapore, we ensure a standard of protection comparable to the PDPA through the provider's contractual commitments and certifications. We may also disclose personal data where required by law.
Analytics and cookies
Our website uses analytics to understand how the site is used, which may set cookies and collect technical identifiers. You can control cookies through your browser settings.
Retention
We keep personal data only as long as needed for the purposes above or as required by law. Platform account data is deleted in accordance with our Data Export and Exit Guarantee when a subscription ends. You may ask us to delete your data at any time, subject to legal retention requirements.
Access and correction
You may request access to the personal data we hold about you, or ask us to correct it, by writing to dpo@governancerow.com. We respond to access requests within the timeframes the PDPA prescribes.
Security
Personal data is protected by encryption in transit and at rest, mandatory multi-factor authentication on platform accounts, and role-based access controls. Details are set out in our security documentation, available on request.
Children
Our services are for businesses and are not directed at children.
Changes
We may update this policy from time to time. The date above reflects the latest version, and material changes will be noted on this page.
Contact
Data protection queries: dpo@governancerow.com
Governance Row Pte. Ltd., Singapore.