Privacy Policy
1. Introduction
MeetingRoomTablet is a meeting room display and booking platform operated by Skynapse Business Technology Pte. Ltd. ("Skynapse", "we", "us", or "our"). We are committed to protecting your personal data in accordance with the Singapore Personal Data Protection Act 2012 (PDPA) and the guidelines of the Personal Data Protection Commission ("PDPC").
This Privacy Policy explains what personal data we collect through our website (meetingroomtablet.com) and platform, how we use and protect it, and the rights available to you. It should be read together with our Cookie Policy and, for customers, the applicable Data Processing Addendum, which governs the detailed terms on which we process data on your behalf.
2. Our Two Roles
As a business-to-business (B2B) Software-as-a-Service provider, we handle personal data in two distinct capacities:
As an organisation (data controller): in respect of the personal data of our own website visitors, prospects, account administrators and business contacts.
As a data intermediary (data processor): in respect of the booking and calendar data our customers process through the MeetingRoomTablet platform. That data remains the customer's property and is processed strictly for the purpose of operating the software for its intended purpose.
3. Personal Data We Collect
Depending on how you interact with us, we may collect:
Business contact information — name, job title, company, work email and phone number of customers, administrators and prospects. This is used for operational, billing, and support related activities.
Account and authentication data — usernames, sign-in identity from Microsoft or Google, login history and IP addresses. We use Microsoft and Google sign-in; we do not store your Microsoft or Google password.
Billing and transaction data — billing contact name, billing country and invoicing details. Card payments are processed by our payment provider (Stripe); we do not store any card information in the platform.
Customer platform data — room, device, booking and calendar information created within the platform, processed on behalf of the relevant customer.
Technical and usage data — device information, log files, cookies and analytics events collected via the website and platform.
We do not collect NRIC, FIN, National Identification, or passport numbers in the course of providing the service.
4. How We Use Personal Data
We collect, use and disclose personal data only for purposes a reasonable person would consider appropriate, including to:
-
provide, operate, maintain and support the MeetingRoomTablet platform and website;
-
create and administer accounts, authenticate access, and manage subscriptions and billing;
-
communicate about service updates, support requests and contractual matters;
-
secure and troubleshoot the platform, including monitoring for fraud, abuse and security incidents;
-
send marketing communications to business contacts, where permitted under the PDPA's B2B and legitimate-interests provisions or with consent; and
-
comply with legal, regulatory, tax and accounting obligations.
We do not use customer platform data for our own independent purposes, and we do not use it to train or improve AI/ML models except where the data has first been de-identified so it cannot reasonably be attributed to any individual or customer, as described in our full Data Protection/Security Policy.
5. Consent and Legal Basis
We collect personal data with consent, or where an exception under the PDPA applies (such as contractual necessity, legitimate interests, or the B2B contact/deemed-consent provisions). Where we rely on such a basis, we document it internally. You may withdraw consent at any time (see Section 9).
6. Cookies and Similar Technologies
Our website and platform use cookies and similar technologies to support authentication, essential functionality and analytics. You can manage your preferences as described in our separate Cookie Policy, which forms part of this Privacy Policy.
7. How We Protect Your Data
We apply a layered set of technical, administrative and physical safeguards, including:
-
Hosting on Microsoft Azure, with production data residing in the Singapore region and our Disaster Recovery site in USA.
-
ISO/IEC 27001:2022 certification for our information security management system.
-
Encryption of personal data in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent).
-
Multi-tenant isolation so one customer cannot access another customer's data, tested at least annually.
-
Role-based access control and least-privilege access, with multi-factor authentication for administrative access.
-
Continuous monitoring, regular patching, and annual independent penetration testing
-
Daily backups with encrypted storage and a documented disaster-recovery process.
No method of transmission or storage is completely secure, but we maintain security arrangements that are reasonable and appropriate to the sensitivity of the data.
8. Data Retention
We retain personal data only as long as necessary for the purposes described above or as required by law. In particular, production customer data is deleted within 30 days of contract termination, following an export window, after which it ages out of encrypted backups on a rolling schedule. Operational and security logs are retained for defined periods to support monitoring and investigations. Full details are set out in our Data Protection/Security Policy.
9. Your Rights
Subject to the PDPA, you may:
-
access the personal data we hold about you;
-
correct inaccurate or incomplete personal data; and
-
withdraw consent to our collection, use or disclosure of your personal data.
To make a request, contact our Data Protection Officer (Section 13). We will verify your identity and respond as soon as reasonably possible, generally within 30 days. Where a request relates to data we process on behalf of a customer (as a data intermediary), we will refer you to that customer as the data controller and assist them in responding.
10. Disclosure and Sub-processors
We do not sell personal data. We share it only with trusted service providers (sub-processors) that help us operate the service, each bound by data-protection obligations no less protective than this Policy and the PDPA. Our sub-processors include, among others:
-
Microsoft Azure — cloud hosting and infrastructure
-
Stripe — payment processing
-
SendGrid/Amazon Simple Email Service (SES) — transactional email delivery
-
Microsoft 365 / Google Workspace — calendar and sign-in integration you connect
-
Freshdesk / Freshsales — customer support and CRM
-
Microsoft Outlook — business communications
We may also disclose personal data where required by law or a valid legal request, as described in our full policy.
11. Overseas Transfers
Where personal data is transferred outside Singapore, we ensure it is given a standard of protection comparable to the PDPA through appropriate legal mechanisms, such as standard contractual clauses or recognised cross-border privacy frameworks.
12. Data Breach Notification
We maintain a documented breach-response process. Where a data breach is assessed to be notifiable under the PDPA, we will notify the PDPC and, where required, affected individuals within statutory timelines. Where we process affected data as a data intermediary, we will notify the relevant customer without undue delay.
13. Contact Us / Data Protection Officer
For any questions, requests or complaints about this Policy or your personal data, contact our Data Protection Officer:
Data Protection Officer
Skynapse Business Technology Pte. Ltd.
Email: legal@meetingroomtablet.com
Address: 5008 Ang Mo Kio Avenue 5, #04-09/16 Techplace II, Singapore 569874
If you are not satisfied with our response, you may lodge a complaint with the Personal Data Protection Commission (PDPC) at [www.pdpc.gov.sg].
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology or legal obligations. Material changes will be posted on this page with an updated effective date.
