Last updated: 12 August 2026.
This notice explains how PathIQ Pte. Ltd. handles personal data in two distinct contexts: (a) our website and business relationships, and (b) our data, identity, insight and risk products. Sections 3 onward deal mainly with (b), where most people whose data we process have never interacted with us directly.
PathIQ processes personal data relating to individuals in Singapore, the European Economic Area, the United Kingdom, the Republic of Korea and other Asia-Pacific markets. We do not knowingly process personal data relating to residents of California, Texas, Vermont, Oregon, Nevada, Connecticut, New Jersey or Vietnam, and we do not offer our data products in those jurisdictions.
PathIQ Pte. Ltd. is a company incorporated in Singapore with its registered office at 1 Raffles Place, #34-04, One Raffles Place, Singapore 048616.
Our role under data protection law depends on the product. Where we decide why and how personal data is processed, we are a controller (under the PDPA, an organisation) and this notice describes that processing. Where we process personal data solely on a customer's documented instructions, we are a processor (under the PDPA, a data intermediary), and the customer's own privacy notice governs.
| Product | Our role | Notes |
|---|---|---|
| Audience Logic | Controller / Processor | Segment creation and activation. |
| Insights IQ | Controller / Processor | Aggregated and derived analytics outputs. |
| Trust IQ | Controller / Processor | Identity verification and risk signals. |
| PathIQ Platform | Controller / Processor | Underlying identity graph and delivery infrastructure. |
| Website and marketing | Controller | Enquiries, business contacts, cookies and analytics. |
Our Data Protection Officer can be contacted at hello@path-iq.ai.
Individuals may contact our representative on any matter relating to the processing described in this notice.
The categories differ by product. We do not hold a single uniform record for every individual.
Most personal data we process is not collected from individuals directly. We obtain it from the following categories of source:
We require each supplier to confirm contractually that it has a valid legal basis for disclosing personal data to us and, where consent is the basis, that the consent obtained covers the purposes described in this notice. A list of our current data source categories is available on request from hello@path-iq.ai.
| Purpose | GDPR / UK GDPR basis | PDPA basis |
|---|---|---|
| Building and maintaining the identity graph; matching and resolving pseudonymous identifiers | Consent obtained by source | Consent |
| Creating audience segments and activating them for marketing | Consent obtained by source | Consent |
| Identity verification, fraud prevention and risk scoring (Trust IQ) | Legitimate interests — preventing fraud and verifying identity | Legitimate Interests exception; fraud prevention |
| Producing aggregated insights and campaign reporting | Legitimate interests — measuring and improving our services | Business improvement |
| Security, service integrity and platform monitoring | Legitimate interests — protecting our systems and customers | Legitimate Interests exception |
| Billing, contract administration and support | Performance of a contract; legal obligation | Contractual necessity; legal requirement |
| Marketing our services to business contacts | Legitimate interests, subject to your right to object at any time | Consent, or an applicable exception |
Where we rely on legitimate interests, we have carried out a balancing assessment weighing our interests against the rights and expectations of the individuals concerned.
Where we rely on consent obtained by a data source, that source is responsible for obtaining and evidencing it. We require evidence of consent to be available on request and for audits.
We do not knowingly build, hold or sell segments that reveal racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health, sex life or sexual orientation, or criminal offences. We do not knowingly process the personal data of children under 18 and our products are not directed at children.
We create profiles in the sense that we group pseudonymous records into interest and propensity segments, and we generate risk and confidence signals.
We do not make decisions producing legal effects concerning individuals, or similarly significant effects, based solely on automated processing. Our outputs are signals supplied to customers, who make their own decisions and are responsible for how those signals are used, including any requirement to provide human review.
| Category | Retention period |
|---|---|
| Identity graph records and pseudonymous identifiers | 3 months |
| Segment membership and inferred attributes | 3 months |
| Risk and verification signals | 3 months |
| Aggregated and anonymised reporting outputs | Retained indefinitely; no longer personal data |
| Suppression and opt-out records | Retained for as long as necessary to honour the request |
| Business contact and customer records | Length of the business relationship + 1 year |
| Billing and accounting records | 5 years |
Records that reach the end of their retention period are deleted or irreversibly anonymised. We do not retain personal data indefinitely on the basis that it may become useful.
We impose written contractual controls on every recipient, including purpose limitation, security requirements and restrictions on onward transfer.
PathIQ is established in Singapore and operates across multiple markets. Personal data may therefore be transferred outside the country in which the individual is located, unless specifically prohibited under the local jurisdiction's privacy laws and regulations.
Subject to your location and to applicable exemptions, you may have the right to:
You may request access to and correction of your personal data, and withdraw consent to its collection, use or disclosure using hello@path-iq.ai.
We apply technical and organisational measures appropriate to the risk, including encryption in transit and at rest, hashing and pseudonymisation of identifiers, role-based access control, logging and monitoring, vendor due diligence, and staff training.
If a data breach occurs that is likely to result in significant harm or risk to individuals, we will notify the Personal Data Protection Commission of Singapore, other competent supervisory authorities, and affected individuals, within the timeframes those laws require.
Our website uses cookies and similar technologies. See our Cookie Policy for details and to manage your preferences. Data collected through our website is handled as described in this notice and is kept separate from our data products.
Please contact hello@path-iq.ai first — we would rather resolve a concern directly. You also have the right to complain to a supervisory authority.
We review this notice at least annually. Where we make a material change to how we process personal data, we will update the date above and, where required, take reasonable steps to bring the change to the attention of affected individuals. Previous versions are available on request.
PathIQ Pte. Ltd.
1 Raffles Place, #34-04, One Raffles Place, Singapore 048616
Privacy and rights requests: hello@path-iq.ai