Privacy Policy
This policy explains what personal data TheBullseye collects, why we collect it, who we share it with, how long we keep it, and what you can require us to do about it. It is written to meet our obligations under Singapore’s Personal Data Protection Act 2012 (the “PDPA”).
1. Who we are
TheBullseye is a video production and creative studio registered in Singapore.
- Registered address: 10 Anson Road, #28-068 International Plaza, Singapore 079903
- UEN: 202635288E
- Contact: hello@thebullseye.sg
In this policy, “personal data” has the meaning given to it in the PDPA: data, whether true or not, about an individual who can be identified from that data, or from that data together with other information we have or are likely to have access to.
2. Our Data Protection Officer
As required by the Accountability Obligation under the PDPA, we have designated a Data Protection Officer responsible for ensuring our compliance. You can reach our DPO at:
hello@thebullseye.sg — please put “DPO” in the subject line so it is routed correctly.
Postal enquiries may be addressed to the Data Protection Officer at our registered address above.
3. What we collect
3.1 Data you give us directly
Almost all the personal data we hold comes from our contact form or from correspondence you start. Through the contact form we collect:
- Your name
- Your work email address
- Your company name and website, where you choose to provide them
- The service you are enquiring about
- Whatever you write in the message field
Only your name, work email and message are required. The remaining fields are optional and the form works without them.
If you go on to become a client, we will also hold the business contact details, project information and billing information needed to deliver and invoice the work.
3.2 Data collected automatically
Our web server records standard technical information when a page is requested, including IP address, browser and device type, the page requested and the time of the request. This is ordinary server logging, used for security and to keep the site working.
3.3 What we do not collect
We do not knowingly collect special categories of sensitive personal data, we do not collect NRIC, FIN or passport numbers through this website, and we do not buy personal data from list brokers.
Please do not send confidential or sensitive information through the contact form. It is a first-contact channel. If your enquiry involves confidential material, say so in the message and we will arrange a secure route.
4. Why we use it, and on what basis
Under the Purpose Limitation and Notification Obligations, we may only use your personal data for purposes a reasonable person would consider appropriate, and which we have told you about. Those purposes are:
- To reply to your enquiry. This is the reason the contact form exists.
- To prepare a proposal or quotation where you have asked for one.
- To deliver, manage and invoice work you have engaged us for.
- To keep records required for accounting, tax and corporate compliance in Singapore.
- To keep the website secure and to investigate misuse.
When you submit the contact form having been shown this policy, we rely on your consent, and on deemed consent where you voluntarily provide data for a purpose that is obvious from the circumstances — you cannot ask us for a quote without us using your email to send it.
We do not sell or rent your personal data. We do not use your enquiry to add you to a marketing list. If we ever want to send you marketing that you did not ask for, we will ask first.
5. Withdrawing consent
You may withdraw consent for us to collect, use or disclose your personal data at any time, on reasonable notice, by writing to our DPO. We will act on the request and tell you the likely consequences — which, if a project is live, may include our being unable to continue delivering it.
Withdrawal does not affect anything done before you withdrew, and it does not override records we are legally required to keep.
6. Marketing and the Do Not Call Registry
We do not send unsolicited marketing messages to Singapore telephone numbers. Should that ever change, we will check numbers against the Do Not Call Registry as required under Part 9 of the PDPA before sending, unless there is a valid ongoing relationship exemption and the message falls within it. Every marketing message will identify us and give you a way to opt out.
7. Who we share it with
We disclose personal data only where it is necessary, and only to:
- Service providers who host this website, deliver our email, or process payments, acting on our instructions.
- Professional advisers — accountants, auditors and lawyers — where they need it to advise us.
- Authorities, where disclosure is required or authorised by Singapore law or a court order.
We do not disclose your enquiry to other clients, and we do not disclose one client’s project information to another.
8. Transfers outside Singapore
Some of the services we use to run this site and our email may store or process data outside Singapore. Under the Transfer Limitation Obligation, we will only transfer personal data overseas where the recipient is bound by legally enforceable obligations to provide a standard of protection comparable to that under the PDPA — normally through contractual terms with the provider.
9. How we protect it
Under the Protection Obligation we make reasonable security arrangements to prevent unauthorised access, collection, use, disclosure, copying, modification or disposal. In practice that means encryption in transit (HTTPS across the whole site), access limited to the people who need it, and accounts secured with strong authentication.
No method of transmission or storage is completely secure, and we do not claim otherwise. What we can commit to is that we will tell you when it matters — see the next section.
10. If there is a data breach
The PDPA has required notification of certain data breaches since February 2021. If we have reason to believe a breach has occurred, we will assess without undue delay whether it is notifiable.
A breach is notifiable if it:
- results in, or is likely to result in, significant harm to affected individuals — which includes financial loss, identity theft, physical harm or damage to reputation; or
- affects 500 or more individuals, whether or not significant harm is likely.
Where a breach is notifiable, we will notify the Personal Data Protection Commission as soon as practicable and in any case no later than 3 calendar days after determining that it is notifiable. Where the breach is likely to result in significant harm to you, we will notify you as well, at the same time or after notifying the Commission.
11. How long we keep it
Under the Retention Limitation Obligation we must stop keeping personal data once the purpose has ended and retention is no longer necessary for legal or business purposes. Our practice is:
| What | How long |
|---|---|
| Enquiries that do not become projects | 24 months from last contact, then deleted |
| Client project records | Duration of engagement plus 5 years |
| Accounting and tax records | 5 years, as required by Singapore law |
| Web server logs | Up to 12 months |
12. Your rights, and how to use them
The PDPA gives you two rights in particular, and we will honour both.
12.1 Access
You may ask us for the personal data we hold about you, and for information about how it has been used or disclosed in the year before your request. Write to our DPO. We will respond as soon as reasonably possible; if we cannot respond within 30 days we will tell you when we will.
A small fee may apply to cover the cost of responding to an access request. If so, we will tell you the amount before we do the work, and you may withdraw the request.
12.2 Correction
If anything we hold about you is inaccurate or incomplete, tell us and we will correct it, and send the correction to organisations we disclosed it to in the previous year unless they no longer need it.
12.3 Making a complaint
If you are not satisfied with how we have handled your personal data, please raise it with our DPO first — we would rather fix it. If we cannot resolve it between us, you may lodge a complaint with the Personal Data Protection Commission at pdpc.gov.sg.
13. Cookies
This website is a static site. It does not set advertising cookies, it does not run third-party tracking pixels, and it does not build a profile of you across other websites.
The showreel on our homepage is served by Vimeo, and is embedded with Vimeo’s Do Not Track parameter enabled so that it does not set tracking cookies. If we add analytics or other cookies in future, we will update this section and, where required, ask for your consent before setting them.
You can block or delete cookies in your browser settings. Nothing on this site depends on them.
14. Other websites
We link to other websites — client work, published research, government resources. We are not responsible for their content or their privacy practices, and this policy does not apply to them.
15. Children
Our services are directed at businesses. We do not knowingly collect personal data from anyone under 18. If you believe a minor has given us personal data, contact our DPO and we will delete it.
16. Changes to this policy
We may update this policy. The version in force is the one on this page, and the date at the top tells you when it last changed. Where a change materially affects how we use data you have already given us, we will take reasonable steps to tell you rather than relying on you noticing.
17. Contact
Data Protection Officer, TheBullseye
10 Anson Road, #28-068 International Plaza, Singapore 079903
hello@thebullseye.sg
A note on this document
This policy is written to reflect the obligations under Singapore’s Personal Data Protection Act 2012 as they apply to how this website actually works. It is not legal advice, and it is not a substitute for review by a Singapore-qualified lawyer before you rely on it in a contract or a regulatory response.