Privacy
Lumen Data Charter — Privacy Notice
This Charter explains how GrowthBlaze collects, uses, discloses, and protects personal data in connection with growthblaze.life and our growth programmes. It is written for Singapore’s Personal Data Protection Act 2012 (PDPA) and related advisory guidelines. It is not a marketing brochure and it is not a wellness or coaching privacy pamphlet — it covers a full-funnel growth marketing agency.
Atrium A — Who holds the light
The organisation responsible for personal data processed through this website and related client work is GrowthBlaze Pte. Ltd., 38 Amoy Street, #02-04, Singapore 069903. You may contact us at [email protected] or +65 6832 3856 (Mon–Fri 09:00–18:00 SGT). For data protection matters specifically, write to [email protected]. We aim to acknowledge privacy requests within seven business days and to complete straightforward access or correction requests within a reasonable period under the PDPA.
Where we process personal data as a data intermediary for a client (for example, operating a lifecycle marketing sequence on the client’s CRM), the client remains the primary organisation for that dataset. Our statement of work and any data processing addendum will describe roles, permitted purposes, and deletion or return instructions. This Charter still describes how we handle website enquiry data and our own business contact records.
Atrium B — What personal data we may hold
Depending on how you interact with GrowthBlaze, we may process: identity and contact details (name, job title, company, email, phone); enquiry content from a growth blaze brief (including programme interest and descriptions of funnel issues); billing and contract details for clients; technical logs such as IP address, browser type, approximate location derived from IP, pages viewed, and referral source; cookie identifiers as described in our Cookie Notice; workshop attendance records; and correspondence history. We do not seek sensitive personal data for wellness, health coaching, or income-course profiling. If you voluntarily include such information in a free-text message, we will treat it carefully and ask you not to send unnecessary sensitive details.
We may also process business contact data obtained from referrals, professional events in Singapore, or publicly available professional profiles when exploring a legitimate business relationship. In those cases we limit use to relevant outreach about growth programmes and honour opt-out requests promptly.
Atrium C — Purposes on the lumen ladder
We organise purposes the way we organise growth work — by stage — so you can see why a data point exists.
Attract (awareness & enquiry). To operate growthblaze.life, respond to contact forms, schedule atelier visits, and understand which funnel topics draw interest. Form consent is collected via an unticked consent_pdpa checkbox. Submissions are routed with a [GrowthBlaze] subject prefix to our intake address for handling.
Convert (engagement & contracting). To prepare proposals, statements of work, NDAs, invoices, and onboarding questionnaires for programmes such as Acquisition Campaign Programme, Conversion Path & Landing Optimisation, Retention & Lifecycle Marketing Layer, Growth Analytics & Learning Cycle, or Always-On Growth Blaze Retainer.
Retain (service delivery). To deliver growth programmes, facilitate workshops, maintain project communication, grant tool access where agreed, and measure delivery against scoped blaze rungs. Client-supplied customer lists remain under client instruction.
Learn (improvement & compliance). To improve our website and services, secure systems, keep financial and legal records, respond to regulators, and analyse aggregated patterns (for example, which programme pages are read most). Analytics cookies, if any, run only with consent as set out in the Cookie Notice.
Atrium D — Legal bases and consent practice
Under the PDPA, we rely on consent where required (notably for website enquiry processing and optional analytics cookies), and on other permitted purposes where applicable for existing contractual relationships, business asset transactions, investigations, and legal obligations. Consent for contact forms is affirmative and specific: the checkbox is not pre-checked; submitting without consent is blocked by the form design and by our send.php validation.
You may withdraw consent for marketing messages at any time by emailing [email protected] or using unsubscribe mechanisms in emails we send. Withdrawal does not affect processing required to complete an active contract or to meet legal duties. If withdrawal prevents us from delivering a programme, we will explain the impact before stopping related processing.
Atrium E — How we collect
Directly from you via forms, email, phone, video calls, and atelier visits; automatically via essential site logs and optional cookies; from your colleagues when they include you on a brief; from publicly available professional sources for B2B outreach; and from service providers who process data on our behalf (hosting, email, productivity suites). We do not buy consumer marketing lists for wellness or lifestyle coaching purposes because that is not our business.
Atrium F — Disclosure and transfers
We may disclose personal data to: employees and contractors under confidentiality; hosting and email providers; professional advisers (legal, accounting); payment processors for invoices; and regulators or law enforcement when legally required. If a client engagement requires tools hosted outside Singapore, we will assess transfer safeguards and reflect them in the engagement documents. We do not sell personal data.
Form intake may be received at an operational mailbox used for triage (including [email protected] as configured for website forms). That mailbox is part of our processing pipeline for enquiries and is protected with access controls appropriate to client intake.
Atrium G — Retention
Enquiry records that do not become clients are typically retained for up to twenty-four months unless a longer period is needed for dispute handling. Client contractual and billing records are retained for periods required by Singapore law and ordinary commercial practice (often at least five years for accounting artefacts). Website server logs are rotated on shorter cycles. Cookie lifetimes are described in the Cookie Notice. When retention ends, we delete or irreversibly anonymise data where feasible.
Atrium H — Security of the atrium
We apply administrative, technical, and physical measures appropriate to a small Singapore marketing agency: access limitation, credential hygiene, device protections, and vendor due diligence. No method of transmission over the internet is perfectly secure; we work to reduce risk rather than claim impossibility of incidents. If a notifiable data breach occurs, we will assess and notify the Personal Data Protection Commission and affected individuals as required by law.
Atrium I — Your PDPA rights
Subject to PDPA exceptions, you may request access to personal data we hold about you, request correction of inaccurate data, withdraw consent, and ask questions about our policies. For client datasets where we act as intermediary, we may redirect you to the client organisation. To exercise rights, email [email protected] with enough detail to verify your identity and locate the records. We may charge a reasonable fee for access requests where permitted.
Atrium J — Children
Our website and programmes are directed at business professionals. We do not knowingly collect personal data from children for growth programmes. If you believe a minor has submitted data, contact [email protected] and we will delete it where appropriate.
Atrium K — AI-assisted growth workflows
When we use AI-assisted tools inside a client engagement, we follow the statement of work: confidential client materials are not used to train public models unless expressly agreed; drafts remain subject to human review; and personal data minimisation principles apply. Website visitors are not automatically enrolled into experimental AI profiling beyond ordinary analytics (if consented).
Atrium L — Third-party links
growthblaze.life may link to external sites. Their privacy practices are their own. Review those notices before providing data to third parties.
Atrium M — Changes to this Charter
We may update this Privacy Notice to reflect legal, technical, or business changes. The “Last updated” date at the top will change when we do. Material changes will be highlighted on this page. Continued use of the website after updates constitutes awareness of the revised Charter for website processing; client contracts may require separate notice.
Atrium N — Contact for privacy light
If you have questions about how a growth programme will handle customer lists, CRM exports, or experiment instrumentation, raise them during the growth blaze brief so we can document instructions before Attract or Retain work begins. Clarity early keeps the atrium light steady for both parties.
Where a programme requires shared dashboards, tag managers, or CRM segments, we record which party administers access, who may export lists, and how long temporary credentials remain active. Those operational notes sit alongside the statement of work so privacy practice is not left to hallway memory. If your internal security team needs a short questionnaire completed before kickoff, send it to [email protected] and we will respond with accurate descriptions of our hosting, form intake, and AI draft boundaries.
GrowthBlaze Pte. Ltd.
38 Amoy Street, #02-04, Singapore 069903
Email: [email protected]
General: [email protected] · Tel: +65 6832 3856
UEN 203062958D · Mon–Fri 09:00–18:00 SGT
If you are unsatisfied with our response, you may contact the Personal Data Protection Commission (PDPC) of Singapore. We encourage you to write to us first so we can illuminate and resolve the issue inside the atrium.
Related documents: Cookie Notice, Terms of Engagement, Legal hub.