Privacy Policy
Effective date: June 3, 2026
SecureOTP Systems Inc. ("SecureOTP", "we", "us", or "our") is committed to protecting your personal information. This Privacy Policy explains what data we collect, how we use it, and the rights you have over it.
1. Information We Collect
Account Information
When you register for a SecureOTP account, we collect your name, email address, company name, and billing details necessary to provision your account and process payments.
Usage Data
We automatically collect data about how you interact with our services, including API call logs (timestamps, originating IP addresses, request payloads excluding message content), dashboard activity, and feature usage patterns. This data is used solely to operate and improve the service.
End-User Phone Numbers
To deliver OTP messages on your behalf, we process the phone numbers you submit via our API. We act as a data processor with respect to your end users' phone numbers. We do not use these numbers for any purpose other than fulfilling your delivery requests.
Device and Browser Data
When you access our console or website, we collect standard browser information including IP address, browser type, operating system, referring URLs, and session duration for security and analytics purposes.
2. How We Use Your Information
Service Delivery
We use your information to operate and maintain your account, process API requests, send OTP messages to your end users, generate invoices, and provide technical support.
Service Improvement
Aggregated, de-identified usage data is analysed to improve routing algorithms, delivery reliability, and product features. No personally identifiable information is used in this analysis.
Communications
We may contact you about your account status, billing matters, security notices, and — with your consent — product updates or promotional content. You may opt out of marketing communications at any time.
Legal Obligations
We process data where required by applicable law, regulation, or court order, including fraud prevention and abuse detection.
4. Data Sharing and Disclosure
Sub-processors
To deliver our service we engage vetted sub-processors (cloud infrastructure, telecom carriers, payment processors) under data processing agreements that impose equivalent privacy obligations. A current list of sub-processors is available on request.
No Sale of Data
We do not sell, rent, or trade your personal information or your end users' phone numbers to any third party for marketing or any other commercial purpose.
Legal Requirements
We may disclose information if required by law, subpoena, or to protect the rights, property, or safety of SecureOTP, our customers, or the public. We will notify you of such requests where legally permitted.
5. Data Security
Technical Safeguards
All data in transit is encrypted using TLS 1.3. Data at rest is encrypted using AES-256. API keys are stored as salted hashes and never returned in plaintext after initial issuance.
Access Controls
Access to production systems is restricted to authorised personnel on a least-privilege basis, protected by multi-factor authentication and regularly audited.
Incident Response
In the event of a data breach that is likely to affect your rights or freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the incident.
6. Data Retention
Account Data
Account data is retained for the duration of your active account and for up to 90 days after account closure to allow for dispute resolution, after which it is securely deleted.
Message Logs
API request logs (excluding message content) are retained for 90 days for debugging and billing reconciliation, then purged. OTP message content (the code itself) is never stored after delivery.
Billing Records
Financial transaction records are retained for seven years as required by applicable accounting and tax regulations.
7. Your Rights
Access and Portability
You may request a copy of all personal data we hold about you at any time. We will provide it in a structured, machine-readable format within 30 days.
Correction and Deletion
You may request correction of inaccurate data or deletion of your account and associated data. Requests will be fulfilled within 30 days subject to legal retention obligations.
Restriction and Objection
You have the right to restrict or object to certain processing activities. Where we rely on legitimate interests as a legal basis, you may object and we will cease processing unless we can demonstrate compelling grounds.
How to Exercise Your Rights
Submit requests to [email protected]. We may require identity verification before fulfilling sensitive requests.
8. International Data Transfers
Transfer Mechanisms
SecureOTP operates globally. When we transfer personal data outside your jurisdiction, we rely on appropriate safeguards such as Standard Contractual Clauses approved by the European Commission, or equivalent mechanisms required by applicable law.
9. Children's Privacy
Our services are not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If you believe we have inadvertently collected data from a minor, please contact us immediately and we will delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email to your registered address or via a prominent notice in the console at least 14 days before taking effect. Continued use of the service after the effective date constitutes acceptance of the revised policy.
11. Contact Us
For privacy inquiries, data subject requests, or to reach our Data Protection Officer, please contact us at [email protected] or write to: SecureOTP Systems Inc., 1 Harbour Front Avenue, Suite 1400, Singapore 098632.