Skip to content

Run your CRM in line with Singapore's PDPA

HelloGrowthCRM is a sales CRM built by Soor LLC. If your team sells into Singapore, the Personal Data Protection Act 2012 applies to the contact records, call notes and marketing lists you keep in it. This page sets out what the PDPA asks of an organisation, which duties stay with you, and which controls the platform provides. It is written for procurement and security reviewers who want specifics. It is not legal advice, so check your own position with counsel or your Data Protection Officer.

What the PDPA asks of a sales team

The PDPA governs the collection, use and disclosure of personal data by private-sector organisations in Singapore, and it is enforced by the Personal Data Protection Commission. A CRM sits directly in scope: names, work and mobile numbers, email addresses, job titles, meeting notes and call summaries are all personal data when they identify someone. The Act sets out obligations that run across the data lifecycle, including consent, notification, purpose limitation, accuracy, protection, retention limitation, transfer limitation, access and correction, openness, accountability, and data breach notification. Separate provisions cover telemarketing through the Do Not Call Registry. Most of these duties land on you as the organisation, not on the software vendor.

That split matters during procurement. Under the PDPA, an organisation processing data on behalf of another is a data intermediary, and it carries a narrower set of duties, mainly protection and retention limitation, while the instructing organisation stays answerable for the rest. HelloGrowthCRM processes your CRM records on your instructions. You decide what to collect, why, how long to keep it and who inside your company can see it. Our job is to give you controls that make those decisions enforceable, and to be clear about how the service is built, where it runs and which third parties we rely on to run it.

So the useful question is not whether a CRM is PDPA certified. There is no such certification, and any vendor claiming one is describing something that does not exist. The useful questions are narrower and testable. Can you show what personal data is held and export it on demand? Can you restrict who sees which records? Can you delete a person's data when a request arrives? Can you evidence who reached production systems if the Commission asks? Those are things a reviewer can check inside a trial account, and the rest of this page answers them one at a time.

Consent, notification and the Do Not Call Registry

The Consent Obligation requires you to obtain consent before collecting, using or disclosing personal data, unless an exception applies, with deemed consent, legitimate interests and business improvement among the recognised exceptions. The Notification Obligation requires you to state the purposes at or before collection. In a sales context that means a clear notice on web forms, event sign-up sheets and outbound sequences. Individuals can withdraw consent at any time, and you must act on the withdrawal and stop the relevant processing. Practically, your CRM has to record where a contact came from and what they were told, so that consent is evidenced rather than asserted after the fact.

The Do Not Call provisions sit alongside consent and are what most often catches sales teams out. Before sending a specified message, meaning a marketing voice call, text message or fax to a Singapore telephone number, you must check the number against the relevant register unless you hold clear and unambiguous consent in writing or an exemption applies. A check result is valid for 21 days, so lists must be re-checked rather than screened once. Messages to a subscriber with an ongoing relationship, market research and certain service messages are treated differently. Custom fields and tags let you store check dates and consent evidence against each contact record.

Where you capture data matters as much as what you capture. If a website form feeds the CRM through an integration, the notice on that form is the notice governing the record. Keep the wording consistent between your privacy policy, the form and the CRM field that stores the source. If you buy or import a list, you inherit the problem of proving consent for every row in it. Import with a source field populated, keep the original file, and be ready to show how each contact entered your system. Reconstructing that history later is far harder than recording it at the point of import.

Access, correction, accuracy and retention

The Access and Correction Obligation lets individuals ask what personal data you hold about them, how it has been used or disclosed in the past year, and to have errors corrected. You must respond as soon as reasonably possible, and if you cannot respond within 30 days you must tell the individual when you will. A CRM makes this manageable or painful depending on how its search and export behave. Administrators in HelloGrowthCRM can search across contact records, open the full activity history and export account data at any time, so assembling a response does not depend on a support ticket or an engineering request.

Correction requests carry a follow-on duty. When you correct data, you generally have to send the correction to organisations you disclosed it to in the previous year, unless they no longer need it. That is far easier to satisfy if you know which integrations received the record. Our subprocessor list at /subprocessors sets out the third parties involved in running the service, and your own integration settings show where records flow outward from your account. Keep that map current. It is one of the first things a reviewer asks for, and the first thing you will reach for during an incident.

Retention Limitation requires you to stop keeping personal data once the business or legal purpose has ended. We do not publish a fixed number of days, because the right period depends on your industry, contracts and statutory obligations rather than ours. What we provide is the mechanism: deletion requests are honoured, administrators can remove records, and the data rights process is documented at /legal/data-rights. Set a retention schedule, write it down, and review lapsed leads on a cycle rather than letting dormant contact records pile up. An unreviewed CRM full of five-year-old leads is a liability, not an asset.

The Protection Obligation and how the platform is built

The Protection Obligation asks for reasonable security arrangements to prevent unauthorised access, collection, use, disclosure, copying, modification or disposal. Reasonable is judged against the sensitivity of the data and the size and nature of the organisation, so the Commission expects proportionate controls rather than a fixed checklist. HelloGrowthCRM protects data in transit with TLS and encrypts data at rest. Customer data sits in Supabase-managed Postgres running on AWS, with row-level security enforcing tenant isolation so records belonging to one account are not reachable from another. That isolation is enforced at the database layer, not only in application code paths.

Access is controlled on two fronts. Inside your account, role-based access control decides which users see which records and which actions they can take, so a new representative does not need the same reach as an administrator. On our side, production access is least-privilege, gated behind multi-factor authentication, logged, and reviewed periodically. Soor LLC also completed a SOC 2 Type II examination covering a February to June 2025 observation window, and the report is available under NDA by writing to sales@hellogrowthcrm.com. A SOC 2 Type II report tells a reviewer more than any badge, because it describes the controls and how they were tested.

Availability and recovery form part of the Protection Obligation too, because losing data is a way of failing to protect it. Automated backups run with point-in-time recovery, so a database can be restored to a chosen moment rather than only to the most recent snapshot. We maintain a documented incident-response workflow covering triage, containment and customer communication. Security researchers can report issues through the process published at /legal/vulnerability-disclosure. If you need any of this mapped to your own control framework or security questionnaire, raise it during the security review and we will answer in writing.

Breach notification, transfers and your DPO

The PDPA requires organisations to notify the Commission of a notifiable data breach within three calendar days of assessing that it is notifiable. A breach is notifiable if it results in, or is likely to result in, significant harm to affected individuals, or if it affects 500 or more individuals. Where significant harm is likely, affected individuals must also be told as soon as practicable. The assessment itself must be prompt, and the Commission expects organisations to move quickly rather than let an investigation drift. A data intermediary must notify the organisation it processes for without undue delay once it becomes aware of a breach.

For that chain to work you need to know how you will hear from us and who you will tell next. Our incident-response workflow includes customer notification, and a Data Processing Agreement is available setting out the commitments in writing. Separately, the Transfer Limitation Obligation applies when personal data leaves Singapore: you must take steps to ensure the recipient provides a comparable standard of protection, usually through contract terms. The DPA and the subprocessor list are the documents that support that assessment, and the hosting region that applies to your account is confirmed during onboarding or the security review.

Finally, the Openness and Accountability Obligations require you to appoint at least one Data Protection Officer, make their business contact information available, and keep written policies and practices. The DPO can be an existing employee and does not have to be based in Singapore, but somebody must own the role. Publish the contact details, train the sales team on what they can and cannot do with contact data, and keep a record of that training. The Commission looks for evidence when something goes wrong, and clean access records make that evidence much easier to produce.

Controls and capabilities at a glance

  • TLS protects data in transit and stored data is encrypted at rest across the HelloGrowthCRM platform and its managed database.
  • Row-level security in Supabase-managed Postgres on AWS enforces tenant isolation, so one account cannot reach another account's records.
  • Role-based access control limits which users see which contacts, deals and activity history, supporting the PDPA protection obligation.
  • Production access at Soor LLC is least-privilege, multi-factor gated, logged and reviewed periodically rather than granted permanently.
  • Soor LLC completed a SOC 2 Type II examination covering a February to June 2025 observation window; the report is available under NDA.
  • Administrators can export account data at any time, which supports PDPA access requests without depending on a vendor support ticket.
  • Deletion requests are honoured, and the process for individuals and customers is documented publicly at /legal/data-rights.
  • A documented incident-response workflow covers triage, containment and customer notification so you can meet the three-day PDPC window.
  • Automated backups with point-in-time recovery let a database be restored to a chosen moment, not only to the last nightly snapshot.
  • The subprocessor list at /subprocessors and an available Data Processing Agreement support transfer limitation and vendor due diligence.

Questions reviewers ask

Is HelloGrowthCRM PDPA certified?
No, and neither is any other CRM. The PDPA is a law you comply with, not a certification scheme, so there is no certificate to hold or display. What we offer instead is evidence. Soor LLC completed a SOC 2 Type II examination covering a February to June 2025 observation window, available under NDA from sales@hellogrowthcrm.com, plus a Data Processing Agreement, a published subprocessor list and a documented data rights process. Treat any vendor advertising PDPA certification with caution.
Are you the data intermediary or the organisation under the PDPA?
For the customer records you load into your account, you are the organisation and we process on your instructions as a data intermediary. That means consent, notification, purpose limitation, access and correction, and retention decisions stay with you. Our duties centre on protecting the data and not keeping it longer than needed for the service. The practical consequence is that you should configure roles, retention and integrations deliberately, because those choices are the ones a regulator will examine first.
Will you sign a Data Processing Agreement?
Yes. A DPA is available covering processing instructions, confidentiality, security measures, subprocessor handling, assistance with data subject requests and breach notification. Ask for it during evaluation rather than after go-live, and read it against your own transfer limitation assessment. Our subprocessor list at /subprocessors names the third parties involved in running the service, so you can see who is in the chain before you sign. If your legal team needs specific wording reviewed, raise it during the security review.
Where is my CRM data hosted?
HelloGrowthCRM runs on Supabase-managed Postgres hosted on AWS. The specific region that applies to your account is confirmed during onboarding or a security review, so ask for it in writing and record the answer in your transfer assessment. If a particular location is a hard requirement for your organisation, raise it before signing rather than after migration. Do not infer a hosting location from a local phone number, a domain suffix or a regional sales presence.
How do I handle a PDPA access request using the CRM?
Search the contact record, open its activity history, and export what relates to the individual. Administrators can export account data at any time without vendor involvement, which is what makes the 30-day response expectation workable. Decide in advance whether free-text notes are in scope of your responses, because notes often contain opinions that are still personal data. Document your process once and follow it consistently. Our own data rights process is published at /legal/data-rights for reference.
What happens if there is a security incident?
Soor LLC maintains a documented incident-response workflow covering triage, containment, remediation and customer notification. Because you must notify the Commission within three calendar days of assessing a breach as notifiable, define internally who receives our notification and what they do first. A notification sitting unread in a shared inbox is the common failure. We also publish a vulnerability disclosure process at /legal/vulnerability-disclosure so researchers can report issues to us through a defined route.
Does the CRM check numbers against the Do Not Call Registry for me?
Checking numbers against the register is your obligation as the sender of the message, and results are valid for 21 days, so screening has to be repeated rather than done once. HelloGrowthCRM gives you the place to record it: use custom fields and tags to store the check date, the register checked and the consent evidence, then segment lists on those fields. That way a reviewer can see why a given number was contacted, which is the part that matters when a complaint arrives.
Do we still need a Data Protection Officer if the CRM is secure?
Yes. The Openness and Accountability Obligations require an organisation to appoint at least one DPO and make their business contact information available, regardless of which software you use. The DPO can be an existing employee and does not need to be in Singapore. Vendor security controls reduce risk, but they do not transfer the obligation. Give the DPO visibility of your CRM configuration, retention schedule and integration list so the role has something concrete to oversee.

Get the security pack before you commit

Ask sales@hellogrowthcrm.com for the SOC 2 Type II report under NDA, the Data Processing Agreement and confirmation of the hosting region for your account. The subprocessor list is at /subprocessors and the data rights process is at /legal/data-rights. If a question here is not answered, put it in the security review and we will respond in writing.