HelloGrowthCRM is a sales CRM built by Soor LLC. If your team sells into Singapore, the Personal Data Protection Act 2012 applies to the contact records, call notes and marketing lists you keep in it. This page sets out what the PDPA asks of an organisation, which duties stay with you, and which controls the platform provides. It is written for procurement and security reviewers who want specifics. It is not legal advice, so check your own position with counsel or your Data Protection Officer.
The PDPA governs the collection, use and disclosure of personal data by private-sector organisations in Singapore, and it is enforced by the Personal Data Protection Commission. A CRM sits directly in scope: names, work and mobile numbers, email addresses, job titles, meeting notes and call summaries are all personal data when they identify someone. The Act sets out obligations that run across the data lifecycle, including consent, notification, purpose limitation, accuracy, protection, retention limitation, transfer limitation, access and correction, openness, accountability, and data breach notification. Separate provisions cover telemarketing through the Do Not Call Registry. Most of these duties land on you as the organisation, not on the software vendor.
That split matters during procurement. Under the PDPA, an organisation processing data on behalf of another is a data intermediary, and it carries a narrower set of duties, mainly protection and retention limitation, while the instructing organisation stays answerable for the rest. HelloGrowthCRM processes your CRM records on your instructions. You decide what to collect, why, how long to keep it and who inside your company can see it. Our job is to give you controls that make those decisions enforceable, and to be clear about how the service is built, where it runs and which third parties we rely on to run it.
So the useful question is not whether a CRM is PDPA certified. There is no such certification, and any vendor claiming one is describing something that does not exist. The useful questions are narrower and testable. Can you show what personal data is held and export it on demand? Can you restrict who sees which records? Can you delete a person's data when a request arrives? Can you evidence who reached production systems if the Commission asks? Those are things a reviewer can check inside a trial account, and the rest of this page answers them one at a time.
The Consent Obligation requires you to obtain consent before collecting, using or disclosing personal data, unless an exception applies, with deemed consent, legitimate interests and business improvement among the recognised exceptions. The Notification Obligation requires you to state the purposes at or before collection. In a sales context that means a clear notice on web forms, event sign-up sheets and outbound sequences. Individuals can withdraw consent at any time, and you must act on the withdrawal and stop the relevant processing. Practically, your CRM has to record where a contact came from and what they were told, so that consent is evidenced rather than asserted after the fact.
The Do Not Call provisions sit alongside consent and are what most often catches sales teams out. Before sending a specified message, meaning a marketing voice call, text message or fax to a Singapore telephone number, you must check the number against the relevant register unless you hold clear and unambiguous consent in writing or an exemption applies. A check result is valid for 21 days, so lists must be re-checked rather than screened once. Messages to a subscriber with an ongoing relationship, market research and certain service messages are treated differently. Custom fields and tags let you store check dates and consent evidence against each contact record.
Where you capture data matters as much as what you capture. If a website form feeds the CRM through an integration, the notice on that form is the notice governing the record. Keep the wording consistent between your privacy policy, the form and the CRM field that stores the source. If you buy or import a list, you inherit the problem of proving consent for every row in it. Import with a source field populated, keep the original file, and be ready to show how each contact entered your system. Reconstructing that history later is far harder than recording it at the point of import.
The Access and Correction Obligation lets individuals ask what personal data you hold about them, how it has been used or disclosed in the past year, and to have errors corrected. You must respond as soon as reasonably possible, and if you cannot respond within 30 days you must tell the individual when you will. A CRM makes this manageable or painful depending on how its search and export behave. Administrators in HelloGrowthCRM can search across contact records, open the full activity history and export account data at any time, so assembling a response does not depend on a support ticket or an engineering request.
Correction requests carry a follow-on duty. When you correct data, you generally have to send the correction to organisations you disclosed it to in the previous year, unless they no longer need it. That is far easier to satisfy if you know which integrations received the record. Our subprocessor list at /subprocessors sets out the third parties involved in running the service, and your own integration settings show where records flow outward from your account. Keep that map current. It is one of the first things a reviewer asks for, and the first thing you will reach for during an incident.
Retention Limitation requires you to stop keeping personal data once the business or legal purpose has ended. We do not publish a fixed number of days, because the right period depends on your industry, contracts and statutory obligations rather than ours. What we provide is the mechanism: deletion requests are honoured, administrators can remove records, and the data rights process is documented at /legal/data-rights. Set a retention schedule, write it down, and review lapsed leads on a cycle rather than letting dormant contact records pile up. An unreviewed CRM full of five-year-old leads is a liability, not an asset.
The Protection Obligation asks for reasonable security arrangements to prevent unauthorised access, collection, use, disclosure, copying, modification or disposal. Reasonable is judged against the sensitivity of the data and the size and nature of the organisation, so the Commission expects proportionate controls rather than a fixed checklist. HelloGrowthCRM protects data in transit with TLS and encrypts data at rest. Customer data sits in Supabase-managed Postgres running on AWS, with row-level security enforcing tenant isolation so records belonging to one account are not reachable from another. That isolation is enforced at the database layer, not only in application code paths.
Access is controlled on two fronts. Inside your account, role-based access control decides which users see which records and which actions they can take, so a new representative does not need the same reach as an administrator. On our side, production access is least-privilege, gated behind multi-factor authentication, logged, and reviewed periodically. Soor LLC also completed a SOC 2 Type II examination covering a February to June 2025 observation window, and the report is available under NDA by writing to sales@hellogrowthcrm.com. A SOC 2 Type II report tells a reviewer more than any badge, because it describes the controls and how they were tested.
Availability and recovery form part of the Protection Obligation too, because losing data is a way of failing to protect it. Automated backups run with point-in-time recovery, so a database can be restored to a chosen moment rather than only to the most recent snapshot. We maintain a documented incident-response workflow covering triage, containment and customer communication. Security researchers can report issues through the process published at /legal/vulnerability-disclosure. If you need any of this mapped to your own control framework or security questionnaire, raise it during the security review and we will answer in writing.
The PDPA requires organisations to notify the Commission of a notifiable data breach within three calendar days of assessing that it is notifiable. A breach is notifiable if it results in, or is likely to result in, significant harm to affected individuals, or if it affects 500 or more individuals. Where significant harm is likely, affected individuals must also be told as soon as practicable. The assessment itself must be prompt, and the Commission expects organisations to move quickly rather than let an investigation drift. A data intermediary must notify the organisation it processes for without undue delay once it becomes aware of a breach.
For that chain to work you need to know how you will hear from us and who you will tell next. Our incident-response workflow includes customer notification, and a Data Processing Agreement is available setting out the commitments in writing. Separately, the Transfer Limitation Obligation applies when personal data leaves Singapore: you must take steps to ensure the recipient provides a comparable standard of protection, usually through contract terms. The DPA and the subprocessor list are the documents that support that assessment, and the hosting region that applies to your account is confirmed during onboarding or the security review.
Finally, the Openness and Accountability Obligations require you to appoint at least one Data Protection Officer, make their business contact information available, and keep written policies and practices. The DPO can be an existing employee and does not have to be based in Singapore, but somebody must own the role. Publish the contact details, train the sales team on what they can and cannot do with contact data, and keep a record of that training. The Commission looks for evidence when something goes wrong, and clean access records make that evidence much easier to produce.
Ask sales@hellogrowthcrm.com for the SOC 2 Type II report under NDA, the Data Processing Agreement and confirmation of the hosting region for your account. The subprocessor list is at /subprocessors and the data rights process is at /legal/data-rights. If a question here is not answered, put it in the security review and we will respond in writing.