Privacy notice
How ClickBloom Forge Pte. Ltd. handles personal data under Singapore PDPA.

Data controller
ClickBloom Forge Pte. Ltd., 20 Kandahar Street, #03-02, Singapore 198885.
Contact for privacy matters
[email protected]
This notice explains what personal data we collect when you visit clickbloomforge.life, why we collect it, how long we keep it, and what rights you have. We operate as a campaign creative studio serving business clients; this site is a brochure, not a consumer platform.
What we collect
When you email us, we process your email address, name, and message content to respond. We do not operate contact forms on this site. When you telephone the studio, we do not record calls unless you are an existing client and recording was agreed in your engagement letter.
When you browse the site, our hosting provider processes server logs including IP address, browser type, pages requested, and timestamps. These logs are used for security and diagnostics.
When you interact with the cookie banner, we store your consent choice in a cookie named cbf_consent and, as backup, in localStorage under cookie_consent_v1. The stored value is JSON describing which optional categories you allowed.
Google Maps embeds on every page may set cookies or collect usage data according to Google's policies when you interact with the map or when maps consent is enabled. See our cookie notice for detail.
Purpose and legal basis
We process enquiry emails to take steps prior to a potential contract at your request. We process server logs for legitimate interests in security and reliable operation. We process consent records to comply with PDPA and ePrivacy expectations for optional cookies.
Retention
Enquiry emails are kept for up to twenty-four months unless an engagement begins, in which case they are filed with client records under the engagement terms. Server logs rotate within ninety days. Consent records persist for one hundred eighty days in the cookie and until cleared in localStorage.
Sharing
We do not sell personal data. Hosting infrastructure is located in Singapore. Google receives data when Maps embeds load according to your cookie preferences. We do not use social advertising pixels on this site.
Your rights
You may request access, correction, or withdrawal of consent by writing to [email protected]. We will verify identity before responding. You may complain to the Personal Data Protection Commission if you believe processing is unlawful.
Security
We use HTTPS, restrict server access, and train staff who handle enquiries. No method of transmission is perfectly secure; we respond to incidents according to PDPA breach-notification requirements.
Children
This site is directed at business professionals. We do not knowingly collect data from individuals under eighteen.
Changes
We update this notice when practices change. Material changes will adjust the last updated date below. Continued use after an update constitutes acknowledgement for non-material edits.
International transfers
Primary processing occurs in Singapore. Google Maps and Google Fonts may process data in the United States or other countries where Google operates infrastructure. Where required, we rely on standard contractual clauses or equivalent mechanisms provided by vendors.
Automated decision-making
We do not use automated decision-making or profiling that produces legal or similarly significant effects on individuals visiting this site.
Data minimisation
We collect only what is needed to respond to enquiries, secure the site, and honour cookie choices. We do not ask for NRIC, payment card numbers, or government identifiers through this site because no payment or account registration exists here.
Marketing communications
We do not send unsolicited marketing email to persons who only browsed the site. If you email us, we may reply with service information relevant to your enquiry. You may ask us to delete your address after a enquiry concludes.
Processor relationships
Hosting providers act as data intermediaries under contract. They may access server logs for maintenance. We select providers with security practices appropriate to a small business brochure site.
Cookies and similar technologies
Detailed cookie categories appear on the cookie notice. Essential storage holds consent JSON only unless you enable optional categories. You may clear cookies in browser settings; the banner will reappear.
Access procedure
Write to [email protected] describing your request. We verify identity using reasonable means — typically by replying to the email address in question or confirming details only the requester would know. We respond within thirty days unless complexity requires extension under PDPA.
Record keeping
Privacy requests and our responses are logged in a restricted file retained for three years for accountability. Logs contain dates and summary of action, not unnecessary copies of identity documents.
Categories of individuals
Visitors: persons browsing the site whose IP addresses appear in server logs. Correspondents: persons who email us. Client contacts: persons named in enquiry mail who may later enter contractual relationships governed by separate privacy terms in engagement letters. We do not knowingly process data about visitors under eighteen.
Sources of personal data
Directly from you when you email; automatically from your browser when you request pages; from your organisation when a colleague copies you on correspondence. We do not purchase marketing lists or enrich emails from brokers.
Consequences of not providing data
You may browse without emailing. If you withhold your email address, we cannot respond to service enquiries. If you block essential cookies, your consent choice may not persist between pages.
PDPA consent and withdrawal
Where consent is the basis for optional cookies, you may withdraw through the cookie panel or by clearing storage. Withdrawal does not affect prior processing that was lawful at the time. Essential cookies remain because they store the withdrawal itself.
Data breach notification
If a breach likely to cause significant harm occurs, we will notify affected individuals and the Personal Data Protection Commission as required, describing nature of the breach, likely consequences, and measures taken.
Third-party links
Mailto links open your email client. Google Maps links load Google content. We are not responsible for privacy practices of services outside our control; review their notices separately.
Retention schedule summary
Enquiry mail: twenty-four months unless superseded by client file. Server logs: ninety days rotation. Consent JSON: one hundred eighty days in cookie storage. Privacy request log: thirty-six months. Client project files follow engagement terms not repeated here.
Access correction and portability
Access requests receive a summary of categories held and copies of correspondence we can reasonably retrieve. Correction requests are honoured when data is inaccurate. Portability applies where technically feasible and where data was provided by you in structured form.
Officer responsible
The studio director oversees privacy compliance for this site. Operational queries may be delegated to staff trained on PDPA basics. Regulatory correspondence is handled at director level.
Technical and organisational measures
HTTPS is enforced where hosting configuration allows. Access to mailboxes is password-protected and limited to staff who respond to enquiries. Workstations use disk encryption where supported. We review access lists when staff roles change.
Anonymisation and aggregation
We do not publish analytics from this site in a form that identifies individuals. If aggregate statistics are ever used internally, they are rounded and thresholded to avoid re-identification.
Complaints
If you believe we processed your data unlawfully, contact [email protected] first. You may escalate to the Personal Data Protection Commission if unresolved. We document complaint handling for accountability.
Updates to processing
New tools that process personal data will be reflected in this notice before or at deployment. Material expansions of processing require renewed consent where consent is the basis.
Definitions
Personal data means data about an identifiable individual. Processing includes collection, use, disclosure, and storage. Client engagement data may include additional categories defined in project letters.
Last updated: 13 August 2026.
Cross-border clients should note that enquiry mail may be stored on Singapore-hosted infrastructure even if they write from elsewhere.
We do not respond to bulk data subject requests that appear automated. Genuine requests receive human review.
Deletion requests are honoured unless retention is required for legal claims or ongoing contracts initiated through the enquiry.
Where processing is based on legitimate interests, you may object by explaining your particular situation. We will balance interests as PDPA requires.
We do not use personal data for automated credit decisions or employment screening from website visits alone.
Data protection questions about active client projects should reference the project name in your mail.
Cross-border clients should note that enquiry mail may be stored on Singapore-hosted infrastructure even if they write from elsewhere.
We do not respond to bulk data subject requests that appear automated. Genuine requests receive human review.
Deletion requests are honoured unless retention is required for legal claims or ongoing contracts initiated through the enquiry.
Where processing is based on legitimate interests, you may object by explaining your particular situation. We will balance interests as PDPA requires.
We do not use personal data for automated credit decisions or employment screening from website visits alone.
Data protection questions about active client projects should reference the project name in your mail.
Cross-border clients should note that enquiry mail may be stored on Singapore-hosted infrastructure even if they write from elsewhere.
We do not respond to bulk data subject requests that appear automated. Genuine requests receive human review.