PDPA Compliance
Singapore Personal Data Protection Act
PDPA Compliance (Singapore)
Last updated: May 2026
Overview
PDPAThe Singapore Personal Data Protection Act 2012 (PDPA) establishes a data protection framework for Singapore that recognises both the rights of individuals to protect their personal data and the needs of organisations to collect, use, or disclose personal data for legitimate purposes.
Anoman AI is designed to support PDPA compliance for Singapore-based organisations and individuals. This page describes how Anoman AI collects, uses, and protects personal data in accordance with the PDPA obligations.
Note: Our Singapore region is planned for Q3 2026. Until that region is available, all customer data is processed in our Jakarta (Indonesia) cluster in compliance with Indonesian data protection law (UU PDP). Singapore customers will be migrated to the Singapore cluster automatically upon its launch.
Data Controller
PDPAThe data controller responsible for personal data collected through the Anoman AI platform is:
PT Anoman Artifisial Informasi
Jakarta, Indonesia
Email: [email protected]
As the data controller, PT Anoman Artifisial Informasi determines the purposes and means of processing personal data submitted through the Anoman LLM gateway. Customers who use the Anoman API to process end-user data act as independent data controllers for their own users' data, subject to their own PDPA obligations.
Purposes of Collection
PDPAAnoman AI collects and processes personal data only for specific, notified purposes. We collect personal data for the following purposes:
- Account creation and authentication — name, email address, and credentials required to create and manage your Anoman AI account.
- Providing the Anoman LLM gateway service — API request metadata, usage logs, and configuration data necessary to operate and improve the service.
- Billing and subscription management — payment information and transaction history required to process payments and manage your subscription.
- Security monitoring and guardrail enforcement — request metadata used to detect anomalies, enforce content policies, and protect the platform from abuse.
- Sending service-related notifications — email communications regarding account activity, billing alerts, and important service updates.
We do not collect personal data beyond what is necessary for these stated purposes. Where you provide personal data in the content of LLM requests, our PII detection guardrails can be configured to detect and redact such data before it is forwarded to LLM providers.
Your Rights
PDPAUnder the PDPA, you have the following rights with respect to your personal data held by Anoman AI:
- Access — you may request a copy of the personal data we hold about you, together with information about how that data is being used.
- Correction — you may request that we correct any personal data that is inaccurate or incomplete.
- Withdrawal of consent — you may withdraw consent for non-essential processing at any time. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal, and may mean that certain features of the service become unavailable.
- Data portability — you may request to receive your personal data in a structured, machine-readable format suitable for transfer to another service provider.
We will respond to all rights requests within 30 days of receipt. To exercise any of these rights, contact our Data Protection Officer at [email protected].
Cross-Border Data Transfers
PDPAThe PDPA imposes obligations on organisations that transfer personal data outside Singapore. This section explains how Anoman AI manages cross-border data transfers.
Current processing location: All customer data is currently processed in our Jakarta, Indonesia cluster pending the launch of our Singapore region (planned Q3 2026). Upon Singapore region launch, Singapore customer data will be stored and processed exclusively within the Singapore cluster.
Sub-processor transfers: When API requests are forwarded to upstream LLM services, the content of those requests is transferred to the service operating the chosen model. Each upstream service operates under its own Data Processing Agreement (DPA) that governs how it handles transferred data. Every model in our catalog declares its data processing region (visible on the model detail page) so customers can route by residency before any data leaves our infrastructure.
Singapore region launch: Upon launch of the Singapore cluster, Singapore customer data will remain within Singapore for storage and primary processing. Transfers to LLM sub-processors will continue to be governed by the relevant provider DPAs.
Contact & DPO
If you have any questions about this PDPA compliance statement or about how Anoman AI processes your personal data, please contact our Data Protection Officer:
Data Protection Officer
PT Anoman Artifisial Informasi
Email: [email protected]
You may also contact us for any of the following matters:
- Submitting a data access or correction request
- Withdrawing consent for non-essential processing
- Requesting data portability
- Raising a complaint about how your personal data is handled
If you are not satisfied with our response, you have the right to lodge a complaint with the Personal Data Protection Commission (PDPC) of Singapore at www.pdpc.gov.sg.