Legal
Privacy Policy
Effective date: 1 January 2026
Caspr Holding Pte Ltd(“Caspr,” “we,” “our,” or “us”), a company incorporated in the Republic of Singapore (UEN: 202530032C), operates the website at caspr.ai and the Caspr platform (the “Platform”). This Privacy Policy describes how we collect, use, store, disclose, and protect personal data when you access or use the Platform.
Caspr Research Private Limited, our wholly owned subsidiary incorporated in India, provides operational and technical support and processes personal data on our behalf as a data processor, under a binding data processing agreement.
1. Scope
This Policy applies to all individuals who interact with the Platform globally, including:
- Visitors to caspr.ai
- Registered users of the Platform
- Subscribers to any Caspr plan or service
- Individuals who contact us for support or information
2. Personal Data We Collect
2.1 Data you provide directly
- Account data: Name, email address, company name, job title, and password
- Payment data: Billing name and address (collected via Stripe; we do not store card numbers or payment credentials)
- Input content: Prompts, queries, and documents you submit to generate analyses
- Communications: Emails, messages, or feedback you send to us
2.2 Data collected automatically
- Usage data: Pages visited, features used, analyses generated, session duration, clicks, and navigation paths
- Device and technical data: IP address, browser type and version, operating system, device identifiers, referrer URLs
- Log data: Server logs, error reports, and timestamps
- Cookie and tracking data: See Section 8
2.3 Data received from third parties
- Stripe: Payment confirmation signals and fraud detection data
- Analytics providers: Aggregated behavioural signals
3. How We Use Your Personal Data
| Purpose | Legal Basis (GDPR) | Legal Basis (PDPA / Singapore) |
|---|---|---|
| Providing and operating the Platform | Performance of contract | Contractual necessity |
| Processing payments via Stripe | Performance of contract | Contractual necessity |
| Sending transactional communications | Performance of contract | Contractual necessity |
| Improving the Platform and developing features | Legitimate interests | Legitimate interests |
| Sending marketing and product communications | Consent or legitimate interests | Consent |
| Fraud prevention, abuse detection, and security | Legitimate interests | Legitimate interests |
| Legal and regulatory compliance | Legal obligation | Legal obligation |
| Analytics and Platform performance monitoring | Legitimate interests | Legitimate interests |
Where we rely on legitimate interests, we have assessed that those interests are not overridden by your rights and freedoms. You may object to processing based on legitimate interests at any time (see Section 7).
4. Data Sharing and Disclosure
We do not sell your personal data. We share personal data only in the following circumstances:
4.1 Service providers and sub-processors
| Sub-processor | Role | Location |
|---|---|---|
| Stripe, Inc. | Payment processing | USA |
| Caspr Research Private Limited | Operational support, infrastructure, report generation | India |
| Amazon Web Services (AWS) | Cloud hosting and data storage | USA |
| Google LLC (Google Analytics) | Usage analytics | USA |
| Google LLC (Google Workspace / Gmail) | Transactional and marketing email delivery | USA |
All sub-processors are bound by contractual obligations that require them to protect your personal data and process it only on our documented instructions.
4.2 Legal requirements
We may disclose personal data where required by law, court order, regulatory authority, or to protect the rights, property, or safety of Caspr, our users, or the public.
4.3 Business transfers
In the event of a merger, acquisition, restructuring, or sale of assets, your personal data may be transferred to the successor entity. We will provide notice before any such transfer becomes effective.
5. International Data Transfers
Caspr Holding Pte Ltd is incorporated in Singapore and stores and processes data in accordance with Singapore’s Personal Data Protection Act 2012 (as amended, “PDPA”). We may transfer personal data to countries outside your jurisdiction, including Singapore, India, and the United States, where our service providers operate.
For users in the European Economic Area (EEA) and United Kingdom: Where we transfer your personal data outside the EEA or UK, we do so on the basis of Standard Contractual Clauses (SCCs) approved by the European Commission, or the UK International Data Transfer Agreement (IDTA), where applicable.
For users in Singapore:Transfers of personal data outside Singapore are subject to contractual protections consistent with the PDPA’s transfer limitation obligations.
For users in India: Transfers involving personal data of Indian residents are subject to applicable requirements under the Digital Personal Data Protection Act 2023 (DPDPA) and any rules or regulations issued thereunder.
6. Data Retention
We retain personal data for as long as your account is active or as necessary to deliver our services and meet legal obligations.
| Data category | Retention period |
|---|---|
| Account data | Deleted within 90 days of account closure, subject to legal hold |
| Payment and billing records | 7 years (tax and audit compliance) |
| Usage and access logs | 12 months |
| Input content and generated reports | Deleted within 90 days of account closure |
| Backup and disaster recovery systems | Purged within 30 days of scheduled deletion |
7. Your Rights
7.1 GDPR rights (EU/EEA and UK users)
You have the right to: access, rectify, erase, restrict processing of, and port your personal data; object to processing; withdraw consent; and lodge a complaint with your national supervisory authority.
7.2 PDPA rights (Singapore users)
You have the right to access personal data held about you, correct inaccurate data, and withdraw consent, subject to reasonable notice and legal or contractual consequences.
7.3 DPDPA rights (Indian users)
You have the right to obtain a summary of personal data being processed, request correction and erasure, and access grievance redressal through our designated Grievance Officer (see Section 12).
7.4 CCPA/CPRA rights (California users)
We do not sell personal information and do not share it for cross-context behavioural advertising. California residents have the right to know, delete, correct, and opt out of sale or sharing of personal information. We do not engage in the sale or sharing of personal information.
To exercise any of the above rights, contact us at legal@caspr.ai. We will respond within the timeframes required by applicable law. We may need to verify your identity before processing your request.
8. Cookies and Tracking Technologies
We use cookies and similar tracking technologies on caspr.ai:
| Category | Purpose | Can you opt out? |
|---|---|---|
| Essential | Authentication, session management, security. Required for the Platform to function. | No |
| Analytics | Understanding how users navigate and use the Platform. Data is aggregated. | Yes |
| Marketing | Measuring the effectiveness of marketing campaigns. Applied only where consent is given. | Yes |
You may manage your preferences via the cookie consent banner displayed on your first visit to caspr.ai.
9. Security
We implement industry-standard technical and organisational security measures, including encryption of data in transit (TLS) and at rest, access controls, regular security reviews, and contractual security obligations on all sub-processors. In the event of a personal data breach, we will notify you and the relevant regulatory authorities as required by applicable law.
10. Children’s Privacy
The Platform is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us at legal@caspr.ai.
11. Changes to This Policy
We may update this Privacy Policy periodically. Where changes are material, we will notify you by email or by prominent notice on the Platform no less than 14 days before the changes take effect.
12. Contact and Grievance Redressal
Data Controller: Caspr Holding Pte Ltd, 160 Robinson Road, #14-04, Singapore Business Federation Center, Singapore 068914. Email: legal@caspr.ai
For Indian users — Grievance Officer: Jayant Jha, Caspr Research Private Limited, 501, Imperia Mindspace, Sector 62, Gurugram, Haryana, India 122102. Email: legal@caspr.ai. Response time: within 30 days.
This document was last updated on 01 January 2026. The governing language of this Policy is English.