Version 1.2 · Updated 2026-08-18 · Operator: AcctTen (acctten.com)
To provide our intelligent payroll services, we utilise state-of-the-art AI technologies, including Google Cloud's Vertex AI, alongside deterministic statutory calculation engines. Payroll processing and storage are performed within our Supabase Southeast Asia region (Singapore); specific AI inference steps are routed to global endpoints as described below.
While we prioritise local data residency where possible, some processing of your personal data occurs at locations outside Singapore (Global Endpoints for AI providers and regional processing for payment, telemetry, and authentication providers). We ensure that any cross-border data processing is conducted in strict accordance with the Singapore Personal Data Protection Act (PDPA).
We do not collect medical diagnosis or condition data. Sick-leave records contain only the leave-type classifier and an optional certificate file reference — no illness description.
| Component | Region | Purpose |
|---|---|---|
| Supabase (Postgres, Auth, Storage) | ap-southeast-1 (Singapore) | Primary data store — tenants, employees, payroll records, audit logs, authentication |
| Vercel | Global edge network | Application compute, static hosting, edge functions |
| Stripe | United States | Subscription billing + card payment processing (card data stays on Stripe — we never receive the card number) |
| Google Vertex AI | Global endpoint | Agentic payroll assistance — zero-retention inference, no model training on customer data |
| Sentry (Functional Software, Inc.) | Configurable (default United States) | Error telemetry only — a scrubbing hook removes NRIC, bank, salary and email fields before data leaves our servers |
| OneMap (Singapore Land Authority) | Singapore | Postal code to address lookup at signup (no personal data in the query) |
| ACRA Open Data | Singapore | UEN to entity lookup at signup (Singapore Open Data Licence, attribution displayed) |
| Google OAuth | United States | Optional social sign-in, for users who choose to sign in with Google |
| Resend (Plus Five Five, Inc.) | United States | Outbound email delivery — sign-in links, one-time codes, employee invitations, leave notifications, and accounting documents sent to a customer. Receives the recipient address and whatever the message itself names (for a leave notification, the employee name and leave type). For an accounting document it also receives the rendered PDF as an attachment, which carries the customer name and address, the supplier GST registration number, the line descriptions and the amounts |
Full sub-processor register available at /privacy-policy/subprocessors.
| Data class | Retention | Basis |
|---|---|---|
| Payroll records (pay runs, CPF filings) | 2 years minimum | Employment Act §96 |
| Income tax records (IR8A, IR21) | 5 years minimum | Income Tax Act §67 |
| Audit logs | 7 years | Regulatory defensibility |
| Session + auth state | 30 days | Supabase Auth default |
| Account (on erasure request) | 7-day grace + purge of non-statutory rows | PDPA §25 balanced against §96/§67 |
Statutory retention obligations (MOM §96, IRAS §67) override individual erasure requests for the specified data classes.
Email dpo@acctten.com to exercise any of these rights. We aim to respond within 30 calendar days.
We maintain security arrangements appropriate to the sensitivity of payroll data, as required by PDPA §24. These include encryption of your data both in storage and in transit, access controls that keep each organisation's records separate and limit staff access by role, and audit logging of actions taken in the system. Customers evaluating us may request further detail under a confidentiality agreement: dpo@acctten.com.
In the event of a notifiable data breach (as defined by PDPA §26D), we will notify the PDPC within 72 hours of assessment, and affected individuals as soon as practicable.
Data Protection Officer: dpo@acctten.com
We may update this policy as our processing practices evolve. The version pinned at your organisation's signup is retained for your reference. Material changes will be communicated via in-app notification and email to registered OWNER/ADMIN contacts.
Version 1.2 (18 August 2026): added Resend to the sub-processor register. Resend has delivered our sign-in links, one-time codes and invitations since our email was first configured in May 2026, and our leave notifications since July 2026. It was missing from this disclosure, so this entry corrects the record rather than announcing a new transfer of your data.
If you submit a request via the /early-access waitlist form, AcctTen Pte Ltd (UEN 202616044C) collects and processes the following personal data:
Purpose: Early-access communications, design-partner outreach, and product development. We will not use your data for any other purpose without your explicit consent.
Legal basis: Your freely given, specific, informed, and unambiguous consent under PDPA §13, collected via the consent checkbox on the form.
Retention: We retain waitlist data until the product reaches general availability, and for up to 90 days thereafter. You may request deletion at any time (see the withdrawal paragraph at the end of this section).
Data controller: AcctTen Pte Ltd (UEN 202616044C). Contact: dpo@acctten.com.
§26D notification: In the event of a notifiable data breach affecting waitlist data, we will notify the PDPC within 72 hours of assessment and affected individuals as soon as practicable.
Withdrawal of consent (PDPA §16): You may withdraw consent at any time by emailing dpo@acctten.comwith subject line "Waitlist consent withdrawal." We will process your request within 30 calendar days and delete your data subject to any lawful retention obligations.