Privacy
Privacy Policy
PDPA-compliant notice for LawSpark Pte. Ltd. — last updated 21 July 2026.
1. Introduction
LawSpark Pte. Ltd. (UEN 202451273M) respects your privacy and complies with the Personal Data Protection Act 2012 (PDPA) of Singapore. This Privacy Policy explains how we collect, use, disclose and protect personal data when you visit lawspark.life, submit enquiries, engage our legal services or interact with us as a client. By using this website you acknowledge this policy; separate consent may be required for specific processing activities.
2. Organisation identity
Data controller: LawSpark Pte. Ltd., 17 Mohamed Sultan Road, #02-04, Singapore 238969. Privacy Officer: [email protected]. We are a Singapore law practice providing commercial counsel, contract review, corporate matters support, employment law advice and compliance briefings.
3. Personal data we collect
We may collect: identity and contact data (name, email, phone, company); enquiry and client matter data (instructions, documents, correspondence); technical data (IP address, browser type, cookie identifiers where consented); billing and engagement data (fees, payment references). We do not knowingly collect data from children.
4. Purposes of collection
We use personal data to: respond to enquiries and conduct conflict checks; provide legal services under engagement letters; manage retainer counsel relationships; issue invoices and comply with legal obligations; improve website security and, where consented, analytics; send service communications relevant to active client matters.
5. Legal bases and consent
Processing is based on consent (enquiry forms, marketing where applicable), contractual necessity (engaged legal services), legitimate interests (security, firm administration) and legal obligation (record-keeping, regulatory requests). Consent may be withdrawn subject to contractual and legal limits — contact [email protected].
6. Client and matter data
Client matter files may include commercial contracts, corporate documents, employment records, advisory opinions and negotiation correspondence. Access is restricted to assigned members of our legal team and permitted processors. We apply need-to-know principles and document handling procedures aligned with professional confidentiality.
7. Disclosure
We may disclose data to: engaged co-counsel or specialist advisers with client consent; IT and hosting providers under contract; professional insurers; regulators or courts when required by law. We do not sell personal data.
8. Retention
Enquiry records: up to 24 months unless an engagement follows. Client matter files: for the duration of engagement plus periods required by law and professional practice (typically 7 years or longer where litigation is possible). Cookie consent records: 6 months. Financial records: as required by Singapore law.
9. Individual rights
Under the PDPA you may request access to, correction of, or withdrawal of consent for your personal data. Submit requests to [email protected]. We respond within reasonable timeframes prescribed by law. You may contact the Personal Data Protection Commission (PDPC) if concerns remain unresolved.
10. Cross-border transfers
Data may be processed on servers outside Singapore where our hosting or tooling providers operate. We require appropriate safeguards and contractual protections consistent with PDPA requirements.
11. Sub-processors
We use contracted providers for hosting, email, document storage and analytics (where consented). Sub-processors are bound by confidentiality and data protection terms. A list is available on request to [email protected].
12. Security
We implement access controls, encryption in transit, secure backups and staff training. No method is completely secure; report suspected incidents to [email protected] promptly.
13. Cookies
See our Cookie Policy at /cookies.php for categories, durations and consent controls.
14. Changes
We may update this policy. Material changes will be reflected with a new Last updated date. Continued use after changes constitutes acknowledgement where permitted by law.
15. Contact
Privacy Officer — [email protected] · LawSpark Pte. Ltd., 17 Mohamed Sultan Road, #02-04, Singapore 238969 · +65 6285 4728
16. Scope of this policy
This Privacy Policy applies to personal data processed through lawspark.life, email correspondence with our firm, clarity-session intake, engagement letters, retainer counsel arrangements and related client matter workflows. It does not replace bespoke data-processing clauses in engagement letters where those clauses address matter-specific confidentiality, privilege or regulatory obligations. Where this policy and an engagement letter differ on an active client matter, the engagement letter prevails for that matter.
17. Website enquiries and forms
When you submit the contact form, we collect the fields you provide — name, email, optional phone, subject selection and message text — together with the consent_pdpa checkbox confirmation. We also operate a honeypot field (website) that should remain empty; if populated, the submission is silently discarded as likely automated spam. Enquiry data is used solely to respond, conduct preliminary conflict checks and, if appropriate, propose an engagement letter. We do not add enquiry contacts to unrelated marketing lists without separate consent.
18. Data minimisation and accuracy
We collect only personal data reasonably necessary for the stated purposes. You are responsible for ensuring information you provide is accurate. Clients should notify us promptly of changes to contact details or corporate representatives so matter files and invoices remain current. We may request verification documents where required for conflict checks or billing compliance.
19. Marketing and newsletters
LawSpark does not operate aggressive marketing funnels, income-course funnels or unrelated product promotions. Occasional firm updates about legal services, compliance briefings or regulatory changes may be sent to contacts who have opted in or who remain active clients under engagement terms. You may unsubscribe from non-essential communications by contacting [email protected]; service messages relating to active matters may still be sent where necessary.
20. Automated decision-making
We do not use automated decision-making or profiling that produces legal or similarly significant effects without human review. Website analytics, where enabled with consent, aggregate visit patterns and do not determine whether we accept a client matter. Conflict checks and engagement decisions are made by qualified members of our legal team.
21. Breach notification
If we become aware of a personal data breach likely to result in significant harm or required notification under Singapore law, we will assess the incident promptly, take containment steps, document the event and notify affected individuals and/or the PDPC where required. Report suspected security issues to [email protected] without delay so we can investigate.
22. Employee and applicant data
If you apply for a role with LawSpark or interact with us as a supplier, separate privacy notices or contract terms may apply. Employment and HR records are handled under applicable employment law and PDPA principles, with access restricted to authorised personnel. This website policy focuses on visitor, enquiry and client matter data.
23. Professional privilege and confidentiality
Client legal advice and matter communications may be subject to legal professional privilege in addition to PDPA protections. Privilege is distinct from data-protection rights and may limit what can be disclosed even upon access requests. We will explain applicable limits when responding to PDPA access or correction requests involving privileged material.
24. Third-party websites and embeds
Our site may link to external resources such as regulatory guidance or professional bodies. Those sites have their own privacy practices. We do not control third-party tracking on external pages. Before following outbound links, review the destination site's notices. We do not embed unrelated advertising networks or social-login widgets that profile visitors across unrelated services.
25. Your responsibilities
Do not submit special categories of personal data through the public contact form unless necessary and lawful. Avoid uploading confidential third-party documents without authority. For sensitive client matter documents, use channels agreed in your engagement letter rather than unsecured email where alternatives are provided.
26. Policy review
We review this Privacy Policy periodically to reflect changes in our services, technology and legal requirements. The Last updated date at the top of this page indicates the most recent revision. Archived versions may be available on request for regulatory or client audit purposes. Contact [email protected] for copies.