Privacy Policy

This Privacy Policy (this "Policy") explains how ExchangeToken (as used in this Policy, "ExchangeToken", "we" or "us" refer to SATORISYS PTE. LTD. and its affiliates) collects, uses, discloses, and otherwise processes personal data in connection with your use of the ExchangeToken services (including available models and features, collectively, the "Services"). Please carefully read this Policy before providing your personal data to ExchangeToken. By browsing our website or using our Services, you agree to the processing of your personal data in accordance with this Policy.

We explicitly commit that the Services covered by this Privacy Policy do not collect any data considered highly sensitive under Singapore's Personal Data Protection Act (PDPA), such as financial information, health records, national identification (NRIC) numbers, etc.

ExchangeToken functions primarily as a service provider for businesses. In the course of providing Services, we may collect your personal data on behalf of our business customers who are the data "controllers". This Privacy Policy does not apply to such processing where we act as a data processor for our customers.

1. WHAT IS PERSONAL DATA

When we use the term "personal data" in this Privacy Policy, we mean any data or information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular natural person or household.

2. HOW WE COLLECT PERSONAL DATA

Personal Data Collected from You

  • Account Information

    including company name, email address, user ID and password. We use this information to administer your account and provide customer support.

  • Inquiry and Communications Information

    such as user ID, and any information provided through "Contact" forms, chat messages, or emails.

  • Services Usage Information (User Content)

    including any files, documents, videos, images, data, or information you choose to transmit to us. ExchangeToken acts strictly as a technical transmission gateway. We do not proactively access, monitor, or analyze the substance of the "User Content". This information is temporarily processed in real-time solely for the purpose of routing prompts to your selected third-party model provider and returning outputs, it is not retained or archived by us after the request is completed.

  • Business Representative Contact Information

    including name, company contact information (e.g. email, address), job title, and any other information for the performance of the applicable service agreement.

  • Bring-Your-Own-Key (BYOK) Credential Information

    If you use the BYOK feature, we will collect the API Keys and credentials information for third-party model supplier that you provide to us.

Personal Data Obtained from Third Parties

We may also obtain personal data from third parties, which we often combine with personal data we collect automatically or directly. We may receive the same categories of personal data as described above from the following sources:

  • Your Employer / Company

    If you interact with our Services through your employer or company, we may receive your information from them or their representatives, including your name, contact details, and company information. We use this information to operate and maintain the features and functionality of the Services.

  • Other Sources

    We may also obtain your personal data that we do not otherwise have from, for example, publicly available sources, or through transactions such as mergers and acquisitions. We use this information to operate, maintain, and provide the Service to you.

Through the provision of our Services, we may also process deidentified information that cannot reasonably be used to infer information about, or otherwise be linked to, a particular individual or household. ExchangeToken will maintain and use the information in deidentified form and will not attempt to reidentify the information, except in instances where necessary for determining whether the deidentification process used by ExchangeToken satisfies the requirements under applicable laws.

3. HOW WE USE PERSONAL DATA

We use collected personal data to:

  • perform contractual obligations and route requests to third-party models;
  • verify identity, and display usage data in your console;
  • Provide customer support and respond to inquiries;
  • test, enhance, update and monitor the Services, or diagnose and fix technology problems;
  • enforce our Terms of Service to resolve disputes, to carry out our obligations and enforce our rights, and to protect our business interests and the interests and rights of third parties;
  • prevent and investigate fraud, unlawful behaviour or criminal activity;
  • For any other lawful purposes, or other purposes that you consent to.

4. HOW WE SHARE PERSONAL DATA

We may also share, transmit, disclose, grant access to, make available, and provide personal data with and to third parties, as follows:

  • Third-Party Service Supplier and Overseas Transfer

    Our Services require sharing necessary information with third-party model suppliers. You acknowledge and agree that any personal data embedded within the User Content will be transmitted in real-time to these providers. These providers may be located in Singapore or overseas jurisdictions (including but not limited to the United States and Europe).

  • ExchangeToken Entities

    We may share personal data with other companies owned or controlled by ExchangeToken, and other companies owned by or under common ownership as ExchangeToken, which also includes our subsidiaries (i.e., any organization we own or control) or our ultimate holding company (i.e., any organization that owns or controls us) and any subsidiaries it owns, particularly when we collaborate in providing the Services.

  • Business Transaction or Reorganization

    We may take part in or be involved with a corporate business transaction, such as a merger, acquisition, joint venture, or financing or sale of company assets. We may disclose personal data to a third party during negotiation of, in connection with or as an asset in such a corporate business transaction. Personal data may also be disclosed in the event of insolvency, bankruptcy, or receivership.

  • Legal Obligations and Rights:

    We may disclose personal data to third parties, such as legal advisors and law enforcement:

    • in connection with the establishment, exercise, or defence of legal claims;
    • to comply with laws or to respond to lawful requests and legal process;
    • to protect our rights, property, and safety.
    • as otherwise required by applicable laws.
  • With Your Consent or Direction:

    We may disclose your personal data to certain other third parties or publicly with your consent or direction.

5. HOW WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES

We use tracking technologies, including (i) cookies or small data files that are stored on your device and (ii) other, related technologies, such as web beacons, pixels, embedded scripts, mobile SDKs, location-identifying technologies and logging technologies (collectively, "tracking technologies"), to collect information about how you access and use our Services when you visit our Services, read our emails, or otherwise engage with us. We may use third-party partners or technologies to collect this information and this information may be combined with other personal data we collect directly from you or receive from other sources. We and our third-party partners may use tracking technologies to collect the following types of information:

  • Device and Usage Information

    such as your IP address, browser type, Internet service provider, device type/model/manufacturer, operating system, date and time stamp, and a unique ID that allows us to uniquely identify your browser, mobile device, or your account, and other such information. We may also work with third-party partners to employ technologies, including the application of statistical modelling tools, which permit us to recognize and contact you across multiple devices.

  • Service Interaction Information

    for example, the site from which you came and the site to which you are going when you leave our Services, how frequently you access the Service, whether you open emails or click the links contained in emails, whether you access the Services from multiple devices, and other browsing behaviour and actions you take on the Sites.

  • Activity Information

    such as the pages you visit, the links you click, and other similar actions. We may also use third-party tools to collect information you provide to us or information about how you use the Services and these tools may record information you enter when you interact with our Services or engage in chat features through our Service.

  • Analytics Information

    We may collect analytics data or use third-party analytics tools to help us measure traffic and usage trends for the Services and to understand aggregated, non-identifiable user patterns.

All of the information collected automatically through these tools allows us to improve our customer experience. Specifically, we use this data to:

  • Enhance Services: Monitor and improve our website and Services.
  • Cross-Device Identification: Recognize and identify you across multiple devices.
  • Measure Effectiveness: Assess the performance of our Services and monitor metrics such as visitor counts, traffic, usage, and demographic patterns.
  • Troubleshoot Issues: Diagnose and resolve technology problems.
  • Plan and Enhance Services: Use insights to plan improvements and future enhancements to our Services.

If you would prefer not to accept cookies, most browsers will allow you to: (i) change your browser settings to notify you when you receive a cookie, which lets you choose whether or not to accept it; (ii) disable existing cookies; or (iii) set your browser to automatically reject cookies; however, doing so may negatively impact your experience using the Services, as some features and Services may not work properly.

6. HOW WE PROTECT DATA SUBJECT RIGHTS

ExchangeToken fully respects individuals' privacy and recognizes individuals' data protection rights.

Scope of Rights: Depending on your jurisdiction or on where you live, you may have the right to request access to and correction or erasure of personal data, or restriction of processing and to object to processing as well as the right to data portability or other rights as provided by applicable laws. You also have the right to withdraw your consent previously given for the processing of your personal data.

Exercise of Rights: You may also at any time request the modification or deletion of your information by contacting us directly using the information provided in the "Contact" section below. We will respond within 30 days upon our receipt of your request.

Verification and Limitations: Before we are able to provide you with any access to information, correct any inaccuracies, or delete your personal data, we may ask you to verify your identity and may seek other details from you to help us to respond to your request. Please note that we may not be able to fulfil all modification or deletion requests, for example, where we are obligated to retain your personal data under regulatory requirements.

If you use the BYOK service, you may terminate this service at any time by removing your API keys from the ExchangeToken platform. Upon termination or expiration of the applicable service agreement, you must actively delete all credentials stored in the platform without undue delay. ExchangeToken reserves the right to permanently delete any Credentials remaining in your Account upon termination without further notice. Under the BYOK model, the User acts as the sole controller of the personal data associated with their third-party credentials, and ExchangeToken provides only the routing infrastructure.

7. PERSONAL DATA OF CHILDREN AND MINORS

ExchangeToken's website and Services are not intended for children or minors. The definition and minimum age of children and minors is set forth in applicable laws. Children and minors should not use our Services or otherwise provide us with any personal data either directly or by other means. In very rare cases, our Services are not directed to, and we do not intend to, or knowingly, collect or solicit personal data from children and minors, however, they may actively interact with us. If we learn that any personal data we have collected has been provided by a child or minor, we will promptly delete that personal data.

8. CHANGES TO THIS PRIVACY POLICY

ExchangeToken reserves the right to update or modify this Privacy Policy from time to time at our sole discretion, with changes taking effect immediately upon posting on our website. We recommend that you check this Policy regularly to familiarize yourself with ExchangeToken's privacy practice. When we do change this Privacy Policy, we will also revise the "Last Updated" date.

9. CONTACT

If you have any questions about this Privacy Policy or any of our Services, or wish to exercise your rights, please email us at: support@exchangetoken.ai