SUMMIT/FORGE Back to site

Privacy Policy

Effective Date: September 03, 2026

This Website Privacy Policy explains how SUMMIT FORGE PTE. LTD., a company registered in Singapore (“SUMMIT FORGE”, “Company”, “we”, “us” or “our”), processes personal data collected through our website.

We provide services on performance-based user acquisition, curated partner sourcing, campaign distribution and exclusivity, tracking and attribution infrastructure, creative and funnel optimization, compliance and quality assurance.

This Privacy Policy applies only to personal data processed by us as a controller in connection with this website. Where we process personal data on behalf of our clients as a processor in the course of providing services, that processing is governed by the relevant client agreement and data processing agreement.

1. Controller and contact details

The controller of your personal data is:

SUMMIT FORGE PTE. LTD
202608415G
Address: 216 Joo Chiat Road, #02-16, Soho Life, Singapore, 427483
Email: info@summitforge.marketing

2. Applicable legal framework and geographic scope

Singapore — PDPA

The Company is established in Singapore. Processing falling within the territorial scope of the Singapore’s Law on Personal Data Protection Act 2012 (hereinafter referred to as the “PDPA”) of Singapore and its subsidiary legislation, including, but not limited to, the Personal Data Protection (Notification of Data Breaches) Regulations 2021.

European Union and European Economic Area — GDPR

The EU General Data Protection Regulation, Regulation (EU) 2016/679 (“GDPR”), applies where the relevant processing falls within its territorial scope. This may include processing carried out in the context of an establishment in the EU/EEA, or processing by a non-EU controller that is related to intentionally offering goods or services to individuals in the EU/EEA or monitoring their behavior there. Mere accessibility of the Website in the EU/EEA does not, by itself, determine that the GDPR applies.

We do not use Website analytics, behavioral advertising, profiling or other tools intended to monitor visitors’ behavior. Where the GDPR does not legally apply to a particular Website interaction, we nevertheless aim to apply substantially equivalent transparency, security and rights-handling standards to individuals in the EU/EEA.

The operational parts of this Policy apply generally. Where a legal basis or right must be identified under a specific law, the relevant GDPR and PDPA provisions are stated separately.

3. Personal Data We Collect

3.1 Data You Provide Directly

When you interact with our website or contact us, we may collect the following categories of personal data:

3.2 Data Collected Automatically

When you visit our website, we may automatically collect:

3.3 Sensitive Personal Data

We do not intentionally collect sensitive personal data (e.g., NRIC/FIN numbers, health information, racial or ethnic origin, religious beliefs) through our website.

4. Purposes of Collection and how this is permitted under the PDPA and GDPR

We process personal data collected through the website for the following purposes:

PurposePersonal dataHow this is permitted under the PDPAGDPR legal basis
Responding to enquiries Inquiry form data: full name, company name, contact email and message content We collect and use the personal data you voluntarily submit to us, such as your full name, company name, contact email and message content, to respond to your enquiry and communicate with you about it. Where required under the PDPA, we will rely on your consent or deemed consent for this purpose.

We do not use personal data submitted through the contact form to send marketing communications unless we have separately notified you of that purpose and, where required, obtained your consent.
Art. 6(1)(f): legitimate interests in responding to professional and business inquiries.
Legal and regulatory compliance Relevant inquiry, technical and communication records. We may collect, use or disclose personal data where this is required or authorized by applicable law, regulation, court order or regulatory requirement, or where another applicable exception under the PDPA applies. Art. 6(1)(c): processing when it is necessary to comply with a legal obligation.
Operating, troubleshooting and securing the Website; preventing spam, fraud, misuse and cyber incidents. Strictly necessary cookie data and basic technical data required for website operation We may collect, use and where necessary disclose personal data to protect our Website, systems, users and business, including for fraud prevention, misuse detection, incident response and investigations, where permitted under the PDPA, including under applicable exceptions, and where required or authorized by law. Art. 6(1)(f): legitimate interests in a secure, reliable Website.

5. Disclosure of Personal Data

5.1 Third-Party Service Providers

We may disclose personal data to third-party service providers, including data intermediaries, that process personal data on our behalf and for our purposes, such as IT and hosting providers, business systems providers, professional advisers and other operational support providers.

Where a service provider acts as our data intermediary, we require it to process personal data in accordance with a written contract and to implement appropriate security and retention measures. We remain responsible for complying with the PDPA in relation to processing carried out on our behalf and for our purposes.

5.2 Regulatory and Legal Authorities

We may disclose personal data to government agencies, regulators, law enforcement bodies, or courts where required by law, including under the PDPA and/or GDPR, or applicable anti-money laundering legislation. Such disclosures are made only to the extent required and permitted by law.

5.3 Business Transfers

In the event of a merger, acquisition, or sale of all or part of our business assets, personal data held by us may be transferred to the successor entity, subject to equivalent data protection obligations.

5.4 No Sale of Personal Data

We do not sell, rent, or trade your personal data to third parties for their own marketing purposes.

6. Transfer of Personal Data Outside Singapore

The Company is established in Singapore. Personal data submitted through the Website may therefore be received, stored or otherwise processed in Singapore. Singapore is outside the EEA and, as of the last update of this Policy, is not a country covered by an adequacy decision of the European Commission. Where the GDPR’s international-transfer rules apply to a transfer of personal data to Singapore or another country outside the EEA, we rely on an available lawful transfer mechanism, such as an applicable adequacy decision, the European Commission’s Standard Contractual Clauses, together with supplementary measures where required, or another mechanism permitted under Chapter V GDPR. Derogations under Article 49 GDPR are used only where the applicable legal conditions are met.

Where Singapore’s Personal Data Protection Act 2012 (PDPA) and its transfer rules apply to a transfer of personal data from Singapore to a country or territory outside Singapore, we take appropriate steps to ensure that the recipient is subject to legally enforceable obligations providing a standard of protection that is at least comparable to the protection under the PDPA, or we rely on another basis or exception permitted by applicable law. Such safeguards may include contractual obligations, binding corporate rules, applicable law or recognized certification mechanisms. You may contact us for information about the safeguards relevant to your personal data, subject to applicable confidentiality restrictions.

7. Retention of Personal Data

We retain personal data only for as long as necessary for the relevant purpose, taking into account applicable legal obligations, statutory limitation periods, security needs and the principle of data minimization.

Inquiry-form submissions and related correspondence are retained for up to six months after the inquiry is closed or after the last substantive communication. If an inquiry leads to pre-contractual negotiations or a contractual relationship, the relevant records may be transferred to separate business or client files and retained in accordance with the applicable contract, a separate privacy notice, applicable legal retention requirements and statutory limitation periods.

Routine server, security and error logs are normally retained for up to 90 days. Such logs may be retained for a longer period where necessary to investigate a security incident, prevent or address abuse, comply with applicable law, or establish, exercise or defend legal claims.

Data contained in strictly necessary technical cookies are retained only for the duration of the relevant session or for the limited technical period required for the relevant Website function. Such data may be retained for a longer period only where this is necessary for security, troubleshooting or the establishment, exercise or defense of legal claims.

8. Your Rights Under the PDPA and/or GDPR

Subject to the conditions and limitations under applicable data protection law, you may have the right to:

Rights and complaint under the PDPA

To exercise any of the above rights, please submit a written request to our DPO at info@summitforge.marketing. We may require you to verify your identity before processing your request. We reserve the right to charge a reasonable fee for access requests in accordance with the PDPA. We will respond to all verified requests as soon as reasonably possible.

EU/EEA — rights and complaint under the GDPR

To exercise any of the above rights, please submit a written request to our DPO at info@summitforge.marketing.

Where the GDPR applies, you may lodge a complaint with a supervisory authority in the EU/EEA Member State of your habitual residence, place of work or the place of the alleged infringement. A list of EU/EEA supervisory authorities is available from the European Data Protection Board.

9. Cookies and technical information

Our website uses only strictly necessary technical cookies and similar technologies that are required for the website to function properly, maintain security, remember essential settings, and support basic website operations.

We do not use analytics cookies, advertising cookies, marketing cookies, tracking pixels or behavioral profiling technologies on this website.

Strictly necessary cookies may collect limited technical information, such as:

These cookies cannot be switched off through our website because they are necessary for the website to operate. You may be able to block or delete cookies through your browser settings, but doing so may affect the functionality or security of the website.

10. Security of Personal Data

SUMMIT FORGE implements appropriate technical and organizational security measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Our security measures include:

In the event of a personal data breach, we will comply with applicable notification requirements under the PDPA and, where applicable, the GDPR. Where required by applicable law, this may include notifying the PDPC, the competent EU/EEA data protection supervisory authority or authorities, and affected individuals within the applicable statutory timeframes and subject to the relevant legal thresholds and exceptions.

11. Children’s Privacy

Our Website is not intended for individuals under the age of 16, and we do not knowingly collect, use, or disclose personal data from minors.

We request that individuals under the age of 16 do not submit any personal data through the Website or contact forms. If we become aware that personal data has been provided by a minor without verifiable parental or guardian consent, we will take reasonable steps to delete such data as soon as practicable, in accordance with the Protection Obligation and Retention Limitation Obligation under the PDPA.

If you believe that a minor has provided personal data to us, please contact so that appropriate action may be taken.

12. Changes to This Policy

We reserve the right to update or amend this Privacy Policy at any time. Material changes will be notified to you via our website or, where we hold your email address, by email. The “Effective Date” at the top of this Policy indicates when the current version was last updated. We encourage you to review this Policy periodically.

13. Contact Us & Complaints

For any questions, concerns, or requests relating to this Privacy Policy or our data protection practices, please contact our Data Protection Officer:

Name / TitleData Protection Officer
OrganizationSUMMIT FORGE PTE. LTD
Emailinfo@summitforge.marketing
Postal Address216 Joo Chiat Road, #02-16, Soho Life, Singapore, 427483