Privacy notice

Last updated: 12 August 2026. AdVault Craft Pte. Ltd. ("we", "us") respects your privacy under the Personal Data Protection Act 2012 (PDPA).

This privacy notice applies only to advaultcraft.life and studio correspondence related to AdVault Craft. It does not govern client campaign materials processed under separate contractual terms.

When you telephone the studio, we may note your number and the substance of the call in our CRM for follow-up. Call recordings are not made unless you request a recorded briefing and we agree in writing.

Marketing lists are not purchased. We do not enrich enquiry emails with third-party data brokers. If you receive mail from us, you wrote to us first or are an existing client with a legitimate ongoing relationship.

Client project files may contain personal data about your customers if you supply it in briefs. We process that data only to perform contracted services and delete or return it per the statement of work.

Sub-processors for client work — translation, print, regional review — are named in client contracts when they touch personal data. This public notice covers the studio website and enquiry handling only.

If you withdraw consent for functional cookies, maps on every page show placeholders until you load them or accept functional storage again. Essential consent cookie remains to remember that choice.

Data protection enquiries should email [email protected] with enough detail to locate your record. We may ask for verification before disclosing or deleting data to prevent fraudulent requests.

This notice was reviewed for PDPA alignment on the last updated date shown in the header. Material changes will be flagged here; immaterial clarifications may be made without changing the date.

We do not operate loyalty programmes or sale of personal data. Analytics cookies remain off unless you enable them in the customise panel — and we currently use no third-party analytics scripts even when enabled.

Employees with access to enquiry mailboxes receive confidentiality training annually. Access is revoked on departure; shared passwords are not used for client file storage.

Personal data collected through hello@ mail is stored in Singapore-hosted mailboxes with two-factor authentication on administrator accounts. Backups are encrypted at rest.

We retain enquiry records to avoid asking repeat visitors the same intake questions. You may request deletion of enquiry-only records if no contract was signed.

Cookie consent records contain no name or email — only boolean flags and a timestamp. They cannot be used to identify you without combining other logs we do not merge for profiling.

If you are a client, your signed contract describes project-file retention, return of materials, and destruction timelines that override generic statements on this page where they differ.

PDPA access requests should include full name, email used to contact us, and approximate date of enquiry so we can locate records without excessive search.

Correction requests for client project files go through your account lead, not only privacy@ mail, so strategists can verify context before amending working documents.

Deletion after contract completion follows retention schedules in your statement of work. Public website data and client project data follow different timelines.

Server logs may include IP address and user agent for security monitoring. Logs are not used to build advertising profiles or sold to brokers.

Google Maps functional consent is separate from analytics consent. You may load maps without enabling analytics on this site.

Children’s data is not knowingly collected from website browsing. Business enquiry mail from minors is deleted when discovered unless a guardian contract exists.

Cross-border APAC collaborators access files under contractual confidentiality when you approve regional review. Data location is named in client contracts.

Breach notification procedures follow PDPC guidance: assess, contain, notify commission and affected individuals when required by severity.

Data portability for enquiry mail is available as forward or export on request. Client deliverables portability follows handover clauses in statements of work.

Automated decision-making is not used on enquiry data. Cookie consent flags are manual choices stored for convenience, not profiling scores.

Marketing unsubscribes for existing clients are honoured within reasonable time. We do not send newsletter blasts from this domain without explicit opt-in.

Third-party processors for hosting are selected for Singapore or comparable protection standards. Sub-processor list for website hosting is available on request to privacy@.

Retention of cookie consent is one hundred eighty days; after expiry the banner returns so you may reconsider map loading preferences.

Complaints unresolved with us may be escalated to the Personal Data Protection Commission Singapore per PDPA complaint pathways.

Sensitive personal data should not be sent unsolicited in enquiry mail. If you must share regulated data, wait for secure transfer instructions in our reply.

We do not combine website logs with client CRM records to profile visitors who never emailed the studio.

Retention schedules for mail attachments follow enquiry versus client rules described in separate contract schedules.

Data minimisation: we ask only for information needed to read your brief — extra fields in email are ignored unless relevant.

Processor agreements with hosting providers are reviewed annually for Singapore adequacy expectations.

Your duty to accurate data: please update us when contact details change so correspondence reaches the right owner.

Anonymised analytics, if enabled in future, would use aggregated counts without persistent user IDs — current build loads no analytics scripts.

Public privacy notice does not list client names as examples. Case references stay anonymised in all studio publications.