LLMSource Pte. Ltd.
Privacy Policy
Effective May 2026
Last updated: August 17, 2026
This is the Privacy Policy of LLMSource Pte. Ltd. (“LLMSource”; “we”).
LLMSource is a company incorporated in Singapore, with Singapore UEN 202615639N and registered office at 750D Chai Chee Road, #06-01 ESR BizPark @ Chai Chee, Singapore 469004.
1. Introduction and scope
This Privacy Policy explains how we collect, use, disclose and otherwise process personal data, and the rights available to individuals whose personal data we handle. We provide a software-as-a-service platform (“Service”) that helps businesses understand and improve how they are described and recommended by AI systems, including by scanning a business’s website and structured data, testing AI-generated outputs about the business, and providing analysis, scoring and monitoring based on the results. This Policy applies to personal data we process in connection with the Service, our websites, and our sales, marketing, support and business communications. It does not apply to third-party websites, products or services that we do not control, including the websites we scan on our customers’ instructions and the AI systems we query.
2. Our role
Data protection law distinguishes between the party that determines the purposes and means of processing (a “controller”; the responsible “organisation” under the Singapore PDPA; a “business” under California law) and the party that processes personal data on that party’s behalf (a “processor”; a “data intermediary” under the Singapore PDPA; a “service provider” under California law). We act in either capacity, depending on the activity.
Where we are the controller. We are the controller of personal data relating to the administration of our business. For example, account registration and authentication data, billing and transaction data, the personal data of individuals who correspond with us, marketing contacts, website visitor data, and the security and operational logs generated by the Service.
Where we are the processor. When we process content relating to a customer’s website or business on the customer’s instructions in the course of delivering the Service, the customer is the controller and we are the processor. Our processing in that capacity is governed by the SaaS agreement and the data processing addendum entered into with the customer, and any request from an individual concerning such content should ordinarily be directed to the relevant customer as the controller.
A customer who is an individual is our contracting counterparty and a data subject: we are the controller of their account, billing and communications data, and their processor in respect of the personal data contained in the website content and other materials we process on their instruction. Where a conflict arises, the SaaS agreement and data processing addendum govern the processor relationship, and this Policy governs our controller processing.
3. Personal data we collect
The categories of personal data we process, whether as controller or on a customer’s behalf, are set out below. Not every category is processed for every individual, and much of the data we handle relates to businesses rather than to identifiable individuals.
| Category | Description and typical data elements | |
|---|---|---|
| i | Account and profile data | Name, business email address, job title, username, password, account settings and preferences, and the organisation to which a user belongs. |
| ii | Billing and transaction data | Billing contact, business address, subscription plan, and transaction records. Card details go directly to our payment processor and are not collected or stored by us. |
| iii | Business profile and entity data | Information about the customer’s business, brands, locations and entities, which may contain the names, roles and business contact details of individuals associated with the business. |
| iv | Website scan and structured data | Content and structured data from the website URLs a customer submits or authorises us to scan. Where the customer is a natural person, this content will ordinarily include that person’s own personal data. It may also include the personal data about business owners, staff, and third parties referenced on the site, such as names, contact details, biographies or images. |
| v | Claims and evidence data | Claims, certifications, documents and other evidence uploaded or submitted by a customer, which may contain personal data depending on what the customer chooses to provide. |
| vi | AI monitoring and testing data | Prompts and queries we send to AI systems and the responses we receive concerning the customer’s business. |
| vii | Usage, device and technical data | IP address, device and browser type, operating system, pages viewed, features used, timestamps, and similar technical data collected when the Service or our website is used. |
| viii | Communications and support data | The content of your correspondence with us, including support tickets, enquiries, survey responses and records of meetings or calls. |
| ix | Marketing data | Contact details, marketing preferences and engagement data (such as whether an email was opened) used to send and measure communications, where permitted. |
Sensitive data. The Service is not designed to process special categories of personal data (as defined by the GDPR) or sensitive personal information (as defined by California law), and we ask customers not to submit such data through claims, evidence or scanned content unless strictly necessary and lawful. The authentication credentials used to secure an account may constitute sensitive personal information under California law, we use them only to authenticate access and secure the Service. Although we ask customers not to submit special categories of personal data (as defined by the GDPR) or sensitive personal information through claims, evidence or scanned content, such data may occasionally appear in that content. Where we process it on a customer’s instruction, the customer is responsible for establishing a lawful basis and any additional condition required for such data. Where we act as a controller, we process it only where the conditions under applicable law are met.
4. How we collect personal data
We collect personal data:
Personal data we obtain indirectly. Some personal data we process are not obtained from you directly but from the websites we scan, the AI systems we query, and public sources such as registries and directories. Where we process such data as a processor on a customer’s instruction, the customer, as controller, is responsible for providing any notice required to the individuals concerned. Where we act as a controller of such data, we provide the information required by applicable law, including Article 14 of the GDPR, unless an exemption applies.
5. Purposes for which we use personal data and our legal bases
We process personal data only where a lawful basis applies. Where the GDPR governs the processing, we rely on the legal bases identified below. Where another data protection law applies, we rely on the equivalent lawful basis available under that law, such as your consent or the necessity of the processing to perform a contract to which you are a party, as described in the regional provisions in section 16.
| Purpose | Data used | Legal basis (GDPR) | |
|---|---|---|---|
| i | To create and administer accounts, authenticate users and provide the Service | Account, business profile, usage and technical data | Performance of a contract; our legitimate interests in operating and securing the Service |
| ii | To deliver the scanning, scoring, verification, monitoring and reporting features | Website scan and structured data, business profile, claims and evidence, AI monitoring data | Performance of a contract; processing on behalf of, and on the instructions of, the customer controller |
| iii | To take payment and manage billing | Billing and transaction data | Performance of a contract; compliance with a legal obligation |
| iv | To provide support and communicate with you | Communications, account and usage data | Performance of a contract; our legitimate interests in responding to enquiries |
| v | To maintain security, prevent fraud and abuse, and ensure availability | Usage, device, technical and log data | Our legitimate interests in protecting the Service; compliance with a legal obligation |
| vi | To improve, develop and analyse the Service | Usage and technical data, aggregated and anonymised data | Our legitimate interests in improving our products |
| vii | To send marketing and measure its effectiveness | Marketing and contact data | Consent, where required; otherwise, our legitimate interests, subject to your right to object |
| viii | To comply with law and to establish, exercise or defend legal claims | Any relevant category | Compliance with a legal obligation; our legitimate interests in protecting our rights |
Where we rely on legitimate interest, we assess that those interests are not overridden by your interests or fundamental rights and freedoms. You may ask us for further information about that assessment. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal. The withdrawal will take effect as soon as practicable after we receive your withdrawal notification.
6. Artificial intelligence, scoring and automated processing
The Service uses automated and AI-based analysis to help businesses understand how they are described online. This analysis is directed at businesses and their online presence; it is not designed to evaluate identifiable individuals, and it does not produce legal effects concerning an individual or similarly significantly affect an individual within the meaning of Article 22 of the GDPR. Where any feature would involve a decision about an individual based solely on automated processing and producing such effects, we will implement the safeguards required by applicable law, including the right to obtain human intervention, to express a point of view and to contest the decision.
Third-party AI systems. The Service queries third-party AI systems to assess and monitor how they describe and respond to queries about a business. These AI systems operate as independent products, are not under our instruction or control, and act as independent controllers in respect of any data contained in our queries to them, in accordance with their own privacy terms. We do not control, and are not responsible for, how these AI systems process, retain or use that data, including whether they use it to train or improve their own models. The responses returned by these systems reflect the third-party AI system and not us, and may be inaccurate, including in relation to individuals. An individual who wishes to correct information that an AI system produces about them should contact the operator of that system.
Model training. We do not use customer content or the personal data contained in it to train, fine-tune or develop AI or machine learning models, whether our own or those of any third party. Where we use machine learning to maintain and improve the Service, we utilize aggregated or anonymised data that does not identify any individual. If we change this position, we will update this Policy and, where required by law, obtain your consent or offer you a means to opt out.
Inferences. Any inferences we draw relate to a business’s online presence and not to the evaluation of an identifiable individual.
7. How we disclose personal data
We disclose personal data only as described in this Policy. We disclose personal data to:
Payments. We use a third-party payment processor to process payments. Your card and payment details are provided directly to our payment processor and are not collected or stored by us. Our payment processor processes payment data as an independent controller for its own purposes, including processing the transaction, preventing fraud, and complying with legal and payment network obligations, in accordance with its own privacy policy. We receive from our payment processor only limited transaction details needed to administer billing. We do not sell personal data, and we do not share personal data for cross-context behavioural advertising as those terms are defined under California law. Where we act as a processor, we disclose the personal data contained in customer content only as instructed by the customer and as permitted by the applicable data processing addendum in the SaaS agreement.
8. Cross-border transfers of personal data
We are established in Singapore and use service providers located in various countries. As a result, personal data may be transferred to, stored in, or accessed from countries other than the one in which you are located, including countries that may not provide the same level of data protection as your home jurisdiction. Where we transfer personal data across borders, we implement a transfer mechanism recognised under applicable law. For transfers from the European Economic Area, we rely on the European Commission’s Standard Contractual Clauses or on the Commission’s adequacy decision. For transfers from other jurisdictions, we rely on the mechanism required by the applicable law, such as the recipient’s provision of an adequate level of protection, appropriate contractual safeguards, or your consent, as described in the regional provisions in section 16. You may request a copy of the relevant safeguards.
9. How long we keep personal data
We keep personal data for as long as necessary to fulfil the purposes for which it was collected, including to provide the Service, to comply with our legal, accounting and reporting obligations, and to establish, exercise or defend legal claims. To determine the appropriate retention period, we consider the nature and sensitivity of the data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process it, and applicable legal requirements.
In general, we retain:
When personal data is no longer required, we delete it or irreversibly anonymise it.
Anonymised and aggregated data. Where we anonymise or aggregate personal data, we maintain it only in anonymised or aggregated form, do not attempt to re-identify it except as necessary to test the effectiveness of our anonymisation, and require any recipient to be bound by the same restrictions. We do not treat such data as personal data for so long as it is maintained in that form.
10. How we protect personal data
We maintain technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These measures include access controls and encryption, security controls for our systems and software, logging and monitoring, staff confidentiality obligations and training, and governance and audit trails. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security. Where the law requires it, we will notify the relevant supervisory authority and affected individuals of a personal data breach within the applicable timeframes.
11. Cookies and similar technologies
We and our providers use cookies and similar technologies on our websites and within the Service to enable core functionality, remember your preferences, maintain security, and measure and improve performance. Where required by law, we obtain consent before setting non-essential cookies and provide a means to manage your preferences. Further detail is set out in our Cookie Policy, which forms part of this Policy.
12. Your rights
Depending on where you are located or the law that applies to you, you may have rights in respect of your personal data, including the rights to access, correct, delete, port, restrict or object to processing, and to withdraw consent. The specific rights available to you, and how to exercise them, are described in the regional provisions in section 16. Where we process personal data as a processor on a customer’s behalf, please direct your request to that customer as controller; we will assist the customer in responding as required by our agreement with it. To exercise a right in respect of personal data for which we are the controller, contact us. We will respond within the period required by applicable law. We may need to verify your identity before acting on a request, and we will not discriminate against you for exercising your rights.
13. Children’s personal data
The Service is intended for business and professional use and is not directed to children. We do not knowingly collect personal data directly from children. “Child” is understood in accordance with the applicable regional law described in section 16, including individuals under 16 in the European Economic Area (subject to Member State law) and in the United States for the purposes of the relevant rules. If you believe a child has provided personal data to us, please contact us so that we can take appropriate action.
14. Third-party sites and services
The Service and our websites may link to, or interoperate with, third-party websites and services, including the websites we scan and the AI systems we query. We are not responsible for the privacy practices of those third parties, and we encourage you to review their privacy notices.
15. Changes to this Policy
We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements or other factors. When we make a material change, we will update the “Last updated” date above and, where required by law, provide a more prominent notice or seek your consent. Please review this Policy periodically.
16. Regional provisions
This section sets out additional information and rights that apply to individuals in particular jurisdictions. In the event of a conflict between this section and the rest of the Policy, this section governs for the individuals to whom it applies. Where a jurisdiction below is a Member State of the European Union or the EEA, the European Union and EEA provisions in section 16.4 also apply.
16.1 Australia
Where the Privacy Act 1988 (Cth) applies, we handle personal information in accordance with the Australian Privacy Principles (APPs). You may request access to, and correction of, your personal information. Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure the recipient handles it consistently with the APPs, and we conduct direct marketing in accordance with APP 7. We will notify you and the Office of the Australian Information Commissioner (OAIC) of an eligible data breach under the Notifiable Data Breaches scheme. You may complain to us and, if unresolved, to the OAIC.
16.2 Brazil
Where the Lei Geral de Proteção de Dados, Law No. 13.709/2018 (“LGPD”) applies, we process personal data on a legal basis set out in the LGPD, such as the performance of a contract, our legitimate interests, or your consent. You have the right to confirm the existence of processing; to access your data; to correct incomplete or inaccurate data; to anonymise, block or delete unnecessary or excessive data; to data portability; to information about the parties with whom we share your data; to delete data processed on the basis of consent; and to withdraw consent. Where we transfer personal data outside Brazil, we use a mechanism permitted by the LGPD. You may contact us or the National Data Protection Authority.
16.3 Colombia
Where the Statutory Law 1581 of 2012 and its implementing decrees apply, we process personal data with your authorisation or on another permitted basis. You have the right to know, update and rectify your personal data; to request proof of the authorisation you gave; to be informed of how your data is used; to revoke your authorisation and request deletion where the law permits; and to lodge a complaint with the Superintendence of Industry and Commerce. We process sensitive data only with your explicit authorisation and appropriate safeguards, and we make international transfers only to jurisdictions providing an adequate level of protection or on another basis permitted by law.
16.4 European Union and European Economic Area
This part applies where the General Data Protection Regulation (“GDPR”) governs our processing of your personal data. The controller is LLMSource Pte. Ltd., and our legal bases for processing are set out in section 5.
Subject to the conditions and exceptions in the GDPR, you have the following rights:
You may exercise these rights by contacting us. You also have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or the place of an alleged infringement. International transfers are made using the safeguards described in section 8, and you may request a copy of those safeguards. Providing personal data necessary to enter into and perform our contract is a requirement of using the Service. If you do not provide it, we may be unable to provide the Service.
16.5 India
Where the Digital Personal Data Protection Act, 2023 (“DPDP”) applies, we process personal data on the basis of your consent or for a legitimate use permitted by the DPDP, after giving you the required notice. You have the right to access a summary of your personal data, to correct and update it, to erasure, to grievance redressal, and to nominate another individual to exercise your rights in the event of death or incapacity. You may raise a grievance with us before approaching the Data Protection Board of India.
16.6 Japan
Where the Act on the Protection of Personal Information (“APPI”) applies, we handle personal information for the purposes of use notified or published to you. Subject to the conditions in the APPI, you may request disclosure, correction, addition, deletion, the cessation of use, and the cessation of third-party provision of your personal information. Before providing personal data to a third party outside Japan, we provide the information required by the APPI and obtain your consent where required. You may contact the Personal Information Protection Commission.
16.7 Malaysia
Where the Personal Data Protection Act 2010 (“Malaysia PDPA”) applies, we process personal data in the course of commercial transactions in accordance with its principles. You have the right to access and correct your personal data, to withdraw consent, and to require us to stop processing your personal data for direct marketing. Where we transfer personal data outside Malaysia, we take steps to ensure an adequate level of protection or rely on another permitted basis. We handle data breach notification and appoint a data protection officer as required by the Malaysia PDPA and its amendments. You may contact the Personal Data Protection Commissioner.
16.8 Philippines
Where the Data Privacy Act of 2012, Republic Act No. 10173 applies, we process personal data on the basis of consent or another criterion for lawful processing. You have the right to be informed; to access your personal data; to object to processing; to rectification; to erasure or blocking; to data portability; to damages; and to file a complaint. We notify the National Privacy Commission (NPC) and affected individuals of a personal data breach as required. You may contact the NPC.
16.9 Singapore
This part applies where the Personal Data Protection Act 2012 (“Singapore PDPA”) governs our processing. We collect, use and disclose personal data for the purposes described in this Policy, and we rely on your consent (including deemed consent), or on another lawful basis under the Singapore PDPA such as the legitimate interests or business improvement exceptions, where applicable. We will notify you of the purposes for which we collect, use and disclose your personal data at or before the time of collection, unless an exception applies. Subject to the Singapore PDPA, you may request access to, and correction of, the personal data we hold about you, and you may withdraw your consent to our continued collection, use or disclosure of your personal data by contacting our Data Protection Officer. Withdrawing consent may affect our ability to provide the Service to you. Where we transfer personal data outside Singapore, we take reasonable steps to ensure a comparable standard of protection as required by the Singapore PDPA. We will notify the Personal Data Protection Commission and affected individuals of a notifiable data breach as required by law.
16.10 South Korea
Where the Personal Information Protection Act (“PIPA”) applies, we process personal information on the basis of your consent or another basis permitted by the PIPA, and we obtain separate consent where required, including for sensitive information and unique identifiers. You have the right to access, correct, delete and suspend the processing of your personal information and to withdraw consent; and, in respect of a decision made solely by automated means that significantly affects you, to request an explanation of or to refuse the decision. Cross-border transfers are made with your consent or on another basis permitted by the PIPA. You may contact the Personal Information Protection Commission.
16.11 Thailand
Where the Personal Data Protection Act B.E. 2562 (2019) (“Act”) applies, we process personal data on a lawful basis under the Act, such as the performance of a contract, our legitimate interests, or your consent. You have the right to access, rectify, erase, restrict and object to the processing of your personal data, to data portability, and to withdraw consent. Where we transfer personal data outside Thailand, we do so to recipients providing adequate protection or on another basis permitted by the Act. You may contact the Personal Data Protection Committee.
16.12 United Kingdom
This part applies where the UK GDPR and the Data Protection Act 2018 govern our processing of your personal data. The controller is LLMSource Pte. Ltd., and our legal bases for processing are set out in section 5. Your rights mirror those described in the European Union and EEA provisions above — access, rectification, erasure, restriction, portability, objection (including to direct marketing at any time), and withdrawal of consent — subject to the conditions and exceptions in the UK GDPR. You may exercise these rights by contacting us, and you have the right to lodge a complaint with the Information Commissioner’s Office. For transfers of personal data out of the United Kingdom, we rely on UK adequacy regulations or on the UK International Data Transfer Agreement or the UK Addendum to the European Commission’s Standard Contractual Clauses, and you may request a copy of the relevant safeguards.
16.13 United States of America
Several states have enacted comprehensive consumer privacy laws that give their residents rights to access, correct, delete and obtain a portable copy of their personal information, and to opt out of the sale of personal information, targeted advertising and certain profiling. Where such a law applies to you, you may exercise these rights by contacting us. We do not sell personal information, and we do not use it for cross-context behavioural advertising or targeted advertising, as those terms are defined under those laws. California residents have the additional rights and disclosures set out below.
California. This part supplements the Policy with the disclosures required by the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (together, the “CCPA”). Our customers may be individuals as well as businesses, and this part applies to any California resident whose personal information we process as a business. It does not govern personal information that we process only as a service provider on a customer’s behalf, which is handled under our agreement with that customer.
The table below sets out the statutory categories of personal information we have collected in the preceding twelve months, and to whom we disclose each category for a business purpose. We do not sell personal information and we do not “share” personal information for cross-context behavioural advertising.
| Category (Cal. Civ. Code § 1798.140) | Collected (examples) | Disclosed for a business purpose to |
|---|---|---|
| Identifiers | Name, email, username, IP address, account identifiers | Service providers and sub-processors |
| Customer records | Business contact details, billing contact | Service providers |
| Commercial information | Subscription and transaction records | Service providers |
| Internet or network activity | Usage, log and device data; interactions with the Service and our sites | Hosting, analytics and security providers |
| Geolocation data | Approximate location inferred from IP address | Hosting, analytics and security providers |
| Professional or employment information | Job title and business role | Service providers |
| Sensitive personal information | Account log-in credentials | Service providers, to authenticate and secure access only |
| Inferences | Preferences derived from usage of the Service | Service providers |
Sources of this personal information are described in section 4, and the business and commercial purposes for which we use it are described in section 5. We retain each category for the period described in section 9.
Sensitive personal information. We collect account log-in credentials, which are sensitive personal information, and use them only to authenticate users and secure the Service. We do not use or disclose sensitive personal information for the purpose of inferring characteristics. Accordingly, the right to limit the use of sensitive personal information does not apply to our processing.
Subject to the CCPA’s conditions and exceptions, California residents have the right to know and access the personal information we have collected, used, disclosed and sold or shared; to delete personal information; to correct inaccurate personal information; to opt out of the sale or sharing of personal information (which we do not do); to limit the use and disclosure of sensitive personal information (which, as noted, does not apply to us); and not to receive discriminatory treatment for exercising these rights.
How to exercise your rights. You may submit a request by contacting us. We will verify your request by matching the information you provide against our records, and we may request further information where necessary. You may use an authorised agent, provided the agent presents proof of authorisation and we can verify your identity. We will respond within the timeframes required by the CCPA. If we decline to act on your request, in whole or in part, we will explain why, and you may appeal that decision by contacting us. We will respond to your appeal within the timeframe required by law. California Civil Code section 1798.83 permits California residents to request information about disclosures to third parties for their direct marketing – we do not make such disclosures. Our websites do not respond to “Do Not Track” signals, but we treat recognised opt-out preference signals as valid opt-out requests where applicable.
16.14 Vietnam
Where the Law on Personal Data Protection (Law No. 91/2025/QH15) and its implementing decree apply, we process personal data on the basis of your consent or another basis permitted by the Decree, and we obtain consent for sensitive personal data where required. You have the right to be informed; to access, correct and delete your personal data; to withdraw consent; to object to and restrict processing; and to complain. Where we transfer personal data outside Vietnam, we prepare and retain a transfer impact assessment dossier and comply with the notification requirements under the Decree. A comprehensive personal data protection law may in future supplement or replace the Decree, and we will update this Policy as required. You may contact us.
16.15 Other jurisdictions
Our Service is available in many countries, and this section does not list every data protection law that may apply. Where the data protection law of your country or region governs our processing of your personal data and grants you rights not otherwise described in this Policy, we will honour those rights to the extent required by that law. You may make any such request or raise any concern about how we handle your personal data, by contacting us, and we may need to verify your identity before we respond. Where local law requires a specific basis or mechanism for international transfers, breach notification, or any other measure, we will comply with that requirement to the extent it applies to us.
17. How to contact us
If you have any questions about this Policy or wish to exercise your rights, you may contact us as follows:
Data controller: LLMSource Pte. Ltd., 750D Chai Chee Road, #06-01 ESR BizPark @ Chai Chee, Singapore 469004.
Data Protection Officer: [email protected].