Legal

Privacy Policy

Last updated: 13 July 2026

Setubase Ltd (“Setubase”, “we”, “us”, or “our”) is committed to handling personal information responsibly and transparently. This policy explains what information we collect, how we use it, how we safeguard it, and your rights in relation to it. It applies to visitors, users, and customers worldwide. By using our platform or contacting us, you agree to this policy. If you do not agree, you must not use the Service.

1. Who we are

Setubase Ltd is incorporated in Singapore and is the data controller for personal information collected through setubase.com and our platform. We provide collaboration, document-control, and project management tools for construction project teams. Where we process personal data on behalf of a customer within their workspace, that customer is the controller and we act as data processor on their documented instructions. Each customer is responsible for having a lawful basis for any personal data they upload or process using the Service, and for providing any notices required to be given to data subjects under applicable law. If you have questions about this policy or how we handle your data, contact us at hello@setubase.com.

2. What information we collect

We collect information you provide directly — such as your name, work email address, organisation, job title, and account and billing details. We collect Customer Data that you and your team upload to the platform (documents, project records, communications, and related metadata). We collect information about how you interact with the Service through standard server logs, security logs, device and browser data, and analytics (page views, session duration, referring URLs, feature usage, and IP address). If you use AI-powered features (Intelligence), we process queries and relevant Customer Data you submit to those features. We do not sell personal data and we do not use tracking cookies for advertising.

3. How we use your information

We use the information we collect to provide, operate, secure, and improve the Service; to authenticate users and prevent fraud and abuse; to process payments and manage subscriptions; to respond to enquiries and provide customer support; to monitor platform performance and diagnose technical issues; to comply with legal obligations; and to send you service communications and, where you have agreed, marketing communications. We do not sell your personal data to third parties. We do not use your Customer Data to train or fine-tune foundation AI models without your explicit prior written consent.

4. AI and Intelligence Features — Data Processing

If you use the Intelligence add-on or other AI-powered features, queries and relevant Customer Data you submit are processed by our AI layer and may be transmitted to third-party AI model inference providers (which may be located in the United States or other countries) to generate responses. We take reasonable steps to select providers that: (a) process data only to deliver the requested output; (b) do not use your data to train their general-purpose models; and (c) are subject to appropriate data-processing agreements or equivalent commitments. AI query inputs and outputs are stored in your workspace as part of your project record. They are not used to improve our models or shared with other customers. AI outputs may be inaccurate and must be independently verified before being relied upon — see Section 4 of our Terms of Service. AI features produce algorithmic outputs that may surface risks or flag project issues; however, Setubase does not make automated decisions that produce legal or similarly significant effects about individuals without human review, and all outputs are presented to a human user for their own assessment and decision. On the Custom plan, data residency and model selection options may be available; contact hello@setubase.com for details.

5. Legal basis for processing

Where the UK GDPR, EU GDPR, Singapore PDPA, or similar laws apply, we process personal data on the basis of: performance of a contract (providing the Service you have requested); legitimate interests (operating, securing, and improving the Service and preventing fraud and abuse); consent (for optional marketing communications and for any AI model training that requires consent); and compliance with legal obligations. You may withdraw consent at any time by contacting hello@setubase.com or updating your notification preferences. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.

6. How we store, protect, and retain your data

We use reasonable technical and organisational measures designed to protect personal data, including encryption in transit and at rest, role-based access controls, audit logging, and the use of reputable cloud providers bound by data-processing agreements. However, no method of transmission or storage over the internet is completely secure. While we work hard to protect your information, we cannot guarantee its absolute security, and any transmission is at your own risk. We retain personal data only as long as necessary for the purposes described in this policy or as required by applicable law. Upon account closure or termination, we will delete or anonymise personal data within a reasonable period, unless we are required to retain it for legal, regulatory, audit, or dispute-resolution purposes. Customer Data (project files, documents, and records) is retained for the duration of your active subscription and for a reasonable grace period after termination, during which you may request an export by contacting hello@setubase.com. After that grace period, Customer Data will be removed from live systems in accordance with our standard data lifecycle processes; residual copies in backups are overwritten as part of our normal backup rotation. Financial, billing, and transactional records may be retained for longer periods as required by applicable accounting, tax, or regulatory law. We are not liable for any loss of Customer Data that occurs after account termination or where an export was not requested before data removal.

7. Data breaches and security incidents

Despite our safeguards, no system is immune to unauthorised access, hacking, malware, or other criminal activity. In the event of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and affected individuals where and as required by applicable law, and within the timeframes it prescribes. To the maximum extent permitted by law, Setubase is not liable for any loss or damage arising from a security incident, cyberattack, or unauthorised access that occurs despite our having taken commercially reasonable measures. You are responsible for keeping your credentials and access controls secure and for maintaining your own independent backups of critical data.

8. International data transfers

We are incorporated in Singapore and operate globally. We may store and process personal data in Singapore, the United Kingdom, the European Economic Area, the United States, Australia, and other countries where we or our service providers operate. These countries may have data-protection laws that differ from those in your jurisdiction. Where we transfer personal data across borders, we rely on appropriate safeguards such as adequacy decisions, the UK International Data Transfer Agreement, EU Standard Contractual Clauses, and equivalent mechanisms required under applicable law. Singapore users: transfers of personal data outside Singapore are conducted in accordance with the Personal Data Protection Act 2012 (“PDPA”), and we take contractual steps to ensure overseas recipients apply comparable standards of protection. Australia users: transfers outside Australia are conducted in accordance with the Australian Privacy Act 1988 (Cth), and we take reasonable steps to ensure overseas recipients handle personal information in a manner consistent with the Australian Privacy Principles. By using the Service, you acknowledge that your information may be transferred to and processed in these locations.

9. Sharing your information

We do not sell or rent your personal information. We may share it with trusted service providers (“sub-processors”) who help us operate the platform — including cloud hosting, payment processing, analytics, email delivery, customer support tooling, and AI model inference — subject to confidentiality obligations and data-processing agreements that: (a) restrict their use of your data to the services they provide to us; (b) require them to process personal data only on our documented instructions; and (c) require them to implement security measures at least as protective as those we apply. A list of our current sub-processors is available on request by emailing hello@setubase.com. We may also disclose data when required by law, regulation, legal process, or governmental request; where necessary to protect the rights, property, or safety of Setubase, our users, or the public; and in connection with a merger, acquisition, restructuring, or sale of assets (in which case we will provide reasonable notice of any change in the data controller where required by law).

10. Your rights

Depending on your location, you may have the right to: access the personal data we hold about you; request correction of inaccurate data; request deletion of your data (subject to legal retention obligations); object to or restrict our processing; withdraw consent; receive a portable copy of your data; and lodge a complaint with a supervisory authority. California residents: you may have rights under the CCPA/CPRA, including the right to know what personal information we collect, the right to delete, the right to correct, and the right not to be discriminated against for exercising these rights; we do not sell or share personal information as those terms are defined under that law. UK and EEA residents: you may raise concerns with your local data protection authority; UK residents may contact the Information Commissioner's Office (“ICO”) at ico.org.uk. Singapore residents: you have rights under the PDPA to access and correct personal data we hold about you and to withdraw consent, subject to legal exceptions; you may contact the Personal Data Protection Commission of Singapore to raise concerns. Australian residents: you have rights under the Privacy Act 1988 (Cth) to access and seek correction of personal information we hold about you, and to complain to the Office of the Australian Information Commissioner (“OAIC”) if you believe we have breached the Australian Privacy Principles. UAE residents: where the UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection (“UAE PDPL”) applies, you may have rights to access, correct, and request deletion of your personal data; contact hello@setubase.com to exercise these rights. If you require a Data Processing Addendum (“DPA”) for GDPR, Singapore PDPA, or other compliance purposes, please contact hello@setubase.com. To exercise any right, contact hello@setubase.com. We will respond within the timeframe required by applicable law, though complex or high-volume requests may take longer as permitted under that law.

11. Cookies

Our website uses essential cookies required for basic functionality such as session management and security. We do not use advertising or behavioural tracking cookies. Our Service does not currently respond to Do Not Track (“DNT”) signals from browsers. If we introduce optional analytics or preference cookies in future, we will request your consent where required by applicable law and provide clear opt-out mechanisms.

12. Children's privacy

The Service is intended for business use and is not directed to individuals under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will endeavour to delete it as soon as reasonably practicable.

13. Third-party links and integrations

Our website and platform may contain links to third-party websites or integrate with third-party services, including AI model providers, project management tools, and document platforms. We are not responsible for the privacy practices, security, or content of those parties. We encourage you to review their privacy policies before sharing any personal information with them.

14. Limitation of our liability in relation to privacy

To the maximum extent permitted by applicable law, Setubase's liability for any loss, damage, or harm arising from the collection, use, disclosure, or protection of personal data — including any data breach, security incident, or failure to comply with a data subject's request — is subject to the limitations set out in the Terms of Service. We are not responsible for any personal data that you or your users choose to include in Customer Data uploaded to the Service, for any misuse of personal data by your organisation or your users, or for any regulatory penalty imposed on you as a result of your own data-processing activities.

15. Changes to this policy

We may update this policy from time to time to reflect changes in our practices, the Service, or applicable law. When we do, we will revise the “Last updated” date at the top. For material changes — those that meaningfully affect how we collect or use your personal data or that reduce your rights — we will provide additional notice by email or in-product notification before the change takes effect, where required by applicable law. Continued use of the Service after changes take effect constitutes your acceptance of the updated policy.

16. Contact us

If you have any questions or concerns about this Privacy Policy, wish to exercise your rights, or wish to request our sub-processor list, please contact us at hello@setubase.com. We will endeavour to respond to privacy enquiries in a timely manner. If you are not satisfied with our response, you may be entitled to complain to a supervisory authority in your jurisdiction.