Citely[1]

Privacy Policy

Last updated 1 August 2026

Draft template — review with Singapore legal counsel before this policy governs live customer data.

On The Ground (“Citely”, “we”, “us”) is committed to protecting personal data in accordance with Singapore’s Personal Data Protection Act 2012 (PDPA). This policy explains what we collect, why, and the rights you have over it.

1. What we collect

Account data (name, work email, company) when you sign up; billing data processed by our payment provider; product usage data (tracked prompts, domains, reports generated); and, where you contact support, the content of that correspondence. We do not require personal data to operate the core AI-visibility tracking, which principally concerns public AI engine responses rather than your customers’ personal data.

2. Consent Obligation

We collect, use, or disclose personal data only with consent, or where the PDPA permits collection without consent (for example, to manage the account relationship or comply with a legal obligation). Consent for non-essential cookies and marketing communications is collected separately and can be withdrawn at any time — see our Cookie Policy.

3. Purpose Limitation

Personal data is used only for the purposes notified at collection: operating your account, billing, providing support, and — where you have opted in — product updates and marketing. We do not sell personal data to third parties.

4. Access and Correction

You may request access to, or correction of, personal data we hold about you by writing to citely@ontheground.agency. We will respond within the timeframe required under the PDPA.

5. Protection Obligation

We apply reasonable technical and organisational safeguards — encryption in transit, access controls, and vendor due diligence — to protect personal data against unauthorised access, collection, use, disclosure, or disposal.

6. Retention Limitation

Personal data is retained only as long as necessary for the purposes it was collected for, or as required by law, after which it is securely deleted or anonymised.

7. Transfer Limitation

Where personal data is transferred outside Singapore — for example, to a sub-processor providing infrastructure or AI-engine query services — we require that recipient to provide a standard of protection comparable to the PDPA before the transfer occurs.

8. Data Breach Notification

In the event of a data breach that is likely to result in significant harm, we will notify the Personal Data Protection Commission (PDPC) and affected individuals as required under the PDPA’s mandatory breach notification regime.

9. Data Protection Officer

Questions about this policy or our data handling can be directed to our Data Protection Officer at citely@ontheground.agency.