Version 1.0 · Updated 2026-04-21 · Operator: AcctTen (acctten.com)
To provide our intelligent payroll services, we utilise state-of-the-art AI technologies, including Google Cloud's Vertex AI, alongside deterministic statutory calculation engines. Payroll processing and storage are performed within our Supabase Southeast Asia region (Singapore); specific AI inference steps are routed to global endpoints as described below.
While we prioritise local data residency where possible, some processing of your personal data occurs at locations outside Singapore (Global Endpoints for AI providers and regional processing for payment, telemetry, and authentication providers). We ensure that any cross-border data processing is conducted in strict accordance with the Singapore Personal Data Protection Act (PDPA).
We do not collect medical diagnosis or condition data. Sick-leave records contain only the leave-type classifier and an optional certificate file reference — no illness description.
| Component | Region | Purpose |
|---|---|---|
| Supabase (Postgres + Auth + Storage) | ap-southeast-1 (Singapore) | Primary data store — employees, payroll, audit logs |
| Vercel (edge + serverless) | Global edge network | Application compute, rendered pages |
| Stripe (payment processing) | United States | Subscription + billing (card data stays on Stripe) |
| Google Vertex AI | Global Endpoint | Agentic payroll assistance (zero-retention) |
| Anthropic API (via Vertex router) | United States | Backup model for high-tier agent calls (zero-retention) |
| Sentry (error monitoring) | Configurable (default US) | Diagnostic telemetry — PII scrubbing hook applied |
| OneMap (SG Land Authority) | Singapore | Postal-code → address lookup (non-PII) |
| ACRA Open Data | Singapore | UEN → entity lookup (SG Open Data Licence, attribution displayed) |
| Google OAuth | United States | Optional social sign-in |
Full sub-processor register available at /privacy-policy/subprocessors.
| Data class | Retention | Basis |
|---|---|---|
| Payroll records (pay runs, CPF filings) | 2 years minimum | Employment Act §96 |
| Income tax records (IR8A, IR21) | 5 years minimum | Income Tax Act §67 |
| Audit logs | 7 years | Regulatory defensibility |
| Session + auth state | 30 days | Supabase Auth default |
| Account (on erasure request) | 7-day grace + purge of non-statutory rows | PDPA §25 balanced against §96/§67 |
Statutory retention obligations (MOM §96, IRAS §67) override individual erasure requests for the specified data classes.
Email dpo@acctten.com to exercise any of these rights. We aim to respond within 30 calendar days.
In the event of a notifiable data breach (as defined by PDPA §26D), we will notify the PDPC within 72 hours of assessment, and affected individuals as soon as practicable. Our internal breach runbook details detection, assessment, notification, and post-incident review procedures.
Data Protection Officer: dpo@acctten.com
We may update this policy as our processing practices evolve. The version pinned at your organisation's signup is retained for your reference. Material changes will be communicated via in-app notification and email to registered OWNER/ADMIN contacts.
If you submit a request via the /early-access waitlist form, AcctTen Pte Ltd (UEN 202616044C) collects and processes the following personal data:
Purpose: Early-access communications, design-partner outreach, and product development. We will not use your data for any other purpose without your explicit consent.
Legal basis: Your freely given, specific, informed, and unambiguous consent under PDPA §13, collected via the consent checkbox on the form.
Retention: We retain waitlist data until the product reaches general availability, and for up to 90 days thereafter. You may request deletion at any time (see §16 below).
Data controller: AcctTen Pte Ltd (UEN 202616044C). Contact: dpo@acctten.com.
§26D notification: In the event of a notifiable data breach affecting waitlist data, we will notify the PDPC within 72 hours of assessment and affected individuals as soon as practicable.
Withdrawal of consent (PDPA §16): You may withdraw consent at any time by emailing dpo@acctten.comwith subject line "Waitlist consent withdrawal." We will process your request within 30 calendar days and delete your data subject to any lawful retention obligations.