Privacy Policy

How I collect, use and protect personal data on danielk.am and in client work.

Last updated: 25 September 2026

This policy explains how Alkamy Pte. Ltd. (UEN 201429706H, “we”, “us”) collects, uses and protects personal data through danielk.am and our services. We follow Singapore’s Personal Data Protection Act 2012 (PDPA). Where the EU or UK GDPR applies to you, this policy also explains your rights under those laws.

Who we are and how to contact us

  • Controller: Alkamy Pte. Ltd., Singapore.
  • Data Protection Officer: Daniel Kam, [email protected]

What we collect

  • Contact form and emails: name, email, company, website, your message, and anything else you choose to send.
  • Website chat: the messages you type into the chat assistant on our service pages, the page you were on, and a random session ID. The assistant is automated. It is not Daniel. Messages pass through our automation platform (n8n) and are sent to OpenAI to write the replies. Please do not share passwords, card numbers or private customer information in the chat.
  • Orders and billing (WooCommerce): name, email, billing address, company, tax ID if given, what you bought, and order history. Payments are handled by Stripe and PayPal. We do not see or store your full card number.
  • Project data: access details and information you share so we can do the work. This can include personal data of your own customers. See “Client data” below.
  • Website usage: IP address, browser and device type, pages viewed, referring site and similar data. This comes from server logs, cookies and analytics tools such as Google Analytics.
  • Newsletter (if you sign up): email and your subscription preferences.

We do not knowingly collect data from children under 13, or under 16 in the EU.

Why we use it, and our legal basis

PurposeGDPR legal basis
Replying to enquiries and sending quotesSteps before a contract, or legitimate interests
Delivering services and managing projectsPerformance of a contract
Taking payment, invoicing, keeping tax recordsContract and legal obligation
Running, securing and improving the websiteLegitimate interests
Analytics and non-essential cookiesConsent (where required)
Sending our newsletterConsent
Handling disputes and legal claimsLegitimate interests and legal obligation

Under the PDPA, we rely on your consent (including deemed consent when you give us data for an obvious purpose) or on an exception the PDPA allows.

Who we share it with

We share personal data only as needed with:

  • payment processors (Stripe, PayPal);
  • website hosting, email and backup providers;
  • analytics providers (Google Analytics, Google Search Console);
  • tools we use to run projects, such as project management, automation and AI services, including OpenAI, which writes the website chat replies;
  • professional advisers, such as accountants, lawyers and insurers; and
  • authorities, when the law requires it.

We do not sell your personal data.

International transfers

We are based in Singapore. Our service providers may store data in other countries, including the US and the EU. When we transfer data out of Singapore, we take steps to make sure it gets a comparable standard of protection, as the PDPA requires. For EU/UK data we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses offered by our providers, where these apply.

How long we keep it

  • Enquiries that do not become projects: up to 24 months.
  • Orders, invoices and business records: at least 5 years, to meet Singapore tax record-keeping rules.
  • Project access credentials: deleted when the project ends, or when you ask.
  • Client data we process for you: deleted or returned at the end of the project, unless you ask otherwise in writing.
  • Newsletter data: until you unsubscribe.

How we protect it

We use reasonable security measures. These include encrypted connections (HTTPS), strong passwords, two-factor authentication, a password manager, limited access and up-to-date software. No system is perfectly secure.

Data breaches

If a data breach may affect you, we will assess it promptly. We will notify the PDPC and you where the PDPA requires it. For EU/UK data we will follow the GDPR’s breach rules.

Your rights

Under the PDPA you can:

  • ask for access to your personal data and how we used it in the past year;
  • ask us to correct it; and
  • withdraw your consent. We will tell you what withdrawal means for any service you receive.

If the GDPR or UK GDPR applies, you can also ask us to erase your data, restrict or object to its use, or give you a portable copy. You can also complain to your local data protection authority.

To use any right, email [email protected]. We may need to check your identity. We aim to reply within 30 days. We may charge a reasonable fee for PDPA access requests, and we will tell you first.

If you are not happy with our reply, you can contact Singapore’s Personal Data Protection Commission (www.pdpc.gov.sg).

Client data (when we act for you)

When we work on your website or systems, we may handle personal data that belongs to your customers. We act on your behalf and follow your instructions and our Terms of Service. You remain responsible for your own privacy notice to your customers.

Cookies

We use strictly necessary cookies to keep the site secure and to make the cart, checkout and login work. If we add optional cookies, such as analytics, we will ask for your consent where the law requires it. You can also block cookies in your browser, but parts of the site may stop working.

Links and affiliate links

Our site links to other websites, some through affiliate links. Those sites have their own privacy policies. When you click an affiliate link, the other company may use cookies to record that you came from us.

Changes

We may update this policy. We will post the new version here with a new date.

Daniel Kam

Let’s work out the scope

Share your website address and what is going on. We agree the scope and the price before any work starts.

Ask about your projectA few taps, then I reply myself.
Prefer email? [email protected]. Please leave passwords and private customer information out.