Vibedata Privacy Policy
Version 1.0 · Effective 1 August 2026
1. Who we are
Accelerate Data Pte. Ltd. (UEN 202551619M) is the organisation responsible for
the personal data described in this policy. We are a company incorporated in
Singapore. Our registered office is 68 Circular Road, #02-01, Singapore 049422.
In this policy, "we", "us", and "our" mean Accelerate Data Pte. Ltd. "You"
means a visitor to our website or a user of the Vibedata sandbox.
We handle personal data in accordance with the Personal Data Protection Act
2012 of Singapore (the "PDPA").
How to reach us about personal data
Email: hello@acceleratedata.ai
Post: Data Protection Officer, Accelerate Data Pte. Ltd., 68 Circular Road,
#02-01, Singapore 049422
A Data Protection Officer has been designated under PDPA section 11(3). We
publish the role rather than an individual's name, so the contact stays valid
as the holder changes. Write to the Data Protection Officer at the address
above and it will reach the right person.
2. What this policy covers
This policy covers:
- our website at
acceleratedata.ai, including the blog and all forms on it; - the Vibedata sandbox, our shared evaluation environment; and
- email and other correspondence between you and us.
This policy does not cover customer production deployments of Vibedata.
Vibedata runs in the customer's own tenant. In those deployments the customer
is responsible for the personal data in their own systems, and the terms of
their agreement with us apply instead of this policy.
Your use of the sandbox is also governed by the
sandbox terms of use. If those terms and this policy
disagree about personal data, this policy applies.
3. What personal data we collect
3.1 Your sandbox access request
When you request sandbox access, we collect:
| What | Required? |
|---|---|
| First name and last name | Required |
| Work email address | Required |
| GitHub username | Required |
| What you want to try in the sandbox (free text) | Required |
| The data platform you run today | Required |
| Company | Optional |
| Job title | Optional |
| Tools in your stack today | Optional |
| Size of your data team | Optional |
| How you heard about us | Optional |
We also record the date and time of your request, the status of your request,
and the date you were last active in the sandbox.
We do not ask for a phone number. We do not ask for a password or any other
credential. GitHub is the identity we use for sandbox access.
3.2 Your consent choices
We record which consent boxes you ticked, and when. There are two, and they
are separate:
- acceptance of the sandbox terms of use, which is required to request access;
- consent to product and community updates by email, which is optional and is
never pre-ticked.
3.3 Website analytics and cookies
Our website runs on HubSpot. When you visit it, we collect:
- the country, region, city, and timezone that HubSpot derives from your IP
address; - the page you landed on, the page you came from, and the pages you view;
- campaign parameters in the link you followed (UTM source, medium, campaign,
content, and term); - a HubSpot tracking cookie (
hutk) that lets us recognise a returning
browser and connect it to a form submission.
Section 12 explains the cookies in more detail and how to refuse them.
3.4 Your use of the sandbox
While you use the sandbox we collect operational data, including sign-in
records, session activity, and execution traces of the work the agents do in
your session. We use this to run the environment, keep it secure, support you,
and understand which parts of the product work.
3.5 Correspondence
If you email us, or we email you about your access request, we keep that
correspondence and the email address it came from.
3.6 Information from other sources
When you give us a work email address, HubSpot may add company information
associated with that email domain — for example company name, industry, and
approximate size — from its own business database. We do not control the
contents of that database.
3.7 What you put into the sandbox
The sandbox terms tell you not to put personal data into the sandbox. If
you do so anyway, we hold it, and we cannot always separate it from the rest
of the environment. In that situation:
- you remain responsible for that personal data under the data protection law
that applies to you; - we process it only to operate the sandbox;
- we may delete it at any time, without notice; and
- you should tell us immediately at hello@acceleratedata.ai so we can remove
it from the live environment. Copies may persist for a period in backups,
logs, and telemetry, and we cannot guarantee complete or immediate erasure.
4. Why we collect it
We collect personal data for these purposes, and no others:
| Purpose | Data used |
|---|---|
| To review your access request and decide whether to grant it | Section 3.1, section 3.6 |
| To provision and administer your sandbox access | Name, email, GitHub username |
| To write the starting-path guidance we send you | Your free-text answer, your data platform, your tooling |
| To contact you about your access, the sandbox, or changes to our terms | Name, email |
| To keep the sandbox and the website secure and working correctly | Section 3.4, IP-derived location, reCAPTCHA data |
| To understand which content brings people to us | Section 3.3 |
| To send you product and community updates, if you asked for them | Name, email |
| To improve our products and services | Section 3.4, and section 3.1 in aggregate |
For the last purpose, we prefer not to use your personal data at all. Where
product improvement can be done with aggregated or anonymised data, that is
what we use.
Where improving the product genuinely requires personal data we already hold,
and the conditions in Part 5 of the First Schedule to the PDPA are met — in
particular that the purpose cannot reasonably be achieved without identifiable
data, and that a reasonable person would consider the use appropriate — we rely
on the business improvement purposes in that Part. Where those conditions
are not met, we rely on your consent instead. We do not use this basis to make
decisions that affect you.
We do not sell your personal data. We do not share it with anyone for
their own marketing.
5. Consent, and how to withdraw it
We collect most of this data because you gave it to us and consented when you
submitted the form. Where we rely on an exception in the PDPA rather than on
your consent, this policy says so.
You can withdraw your consent at any time. Email hello@acceleratedata.ai and
tell us what you want to withdraw. We will act on it within a reasonable
period and confirm when it is done.
Please understand the consequence before you withdraw. We need your name,
email address, and GitHub username to run your sandbox access. If you withdraw
consent to those, your sandbox access will end. Withdrawing consent to
marketing email has no effect on your access.
Withdrawing consent does not make our earlier use of your data unlawful, and
it does not require us to delete records we are required to keep by law.
6. Marketing email
Product and community updates are separate from your sandbox access.
- The consent box is optional and unticked. We never pre-tick it.
- Your access request is not judged on whether you ticked it.
- Every marketing email carries an unsubscribe link. It works immediately.
- You can also unsubscribe by emailing hello@acceleratedata.ai.
Email about your access request, your sandbox account, or a change to our
terms is service email, not marketing. You cannot unsubscribe from it while
you hold sandbox access, because we need a way to reach you.
We do not collect phone numbers and we do not make marketing calls or send
marketing text messages, so the Do Not Call provisions of the PDPA do not
arise.
7. Who else handles your data
We use a small number of service providers. They act on our instructions and
only for the purposes in section 4.
| Provider | What it does | What it receives |
|---|---|---|
| HubSpot | Our CRM, forms, website CMS, and email | Everything in sections 3.1, 3.2, 3.3, 3.5, 3.6 |
| GitHub | The identity we grant sandbox access to | Your GitHub username. We never receive your GitHub password. We may look at the public profile for the username you give us, to confirm it exists. |
| Google reCAPTCHA | Stops automated spam on our forms | Your IP address and how you interacted with the page. Google's own privacy policy applies to what Google does with it. |
| Microsoft Azure | Runs the sandbox | Everything in section 3.4 and 3.7. The sandbox runs in Azure's Singapore region, though not every supporting component is necessarily located there. |
| AI model provider | Powers the agents in the sandbox | Content from your sandbox session, including what you type to the agents and what they generate. We contract with these providers on commercial terms that bar them from training their models on that content, and require deletion within 30 days. Processing is outside Singapore. We describe the providers generically rather than naming them, because which model handles a given step changes. If you need the current list for a security review, ask us at hello@acceleratedata.ai. |
We may also disclose personal data where the law requires it, where a
regulator or court directs it, or to establish or defend a legal claim.
If we sell or transfer our business, personal data may transfer with it. We
will tell you if that happens and this policy will continue to apply until we
publish a replacement.
8. Where we hold your data, and transfers out of Singapore
The sandbox runs in Microsoft Azure's Singapore region. Not every
supporting component is necessarily located there.
Your personal data does leave Singapore. Our HubSpot portal is hosted in
HubSpot's North America region. GitHub and Google are established in the United
States. The AI model providers our agents call may process content outside
Singapore. So while the sandbox itself is Singapore-hosted, the systems around
it are not.
Where we transfer your personal data outside Singapore, we take steps to
ensure it receives a standard of protection at least comparable to the PDPA,
as section 26 of the PDPA and regulation 10 of the Personal Data Protection
Regulations 2021 require.
For HubSpot, Google, and GitHub we rely on those providers' standard
data processing terms, which bind them to a comparable standard.
For our cloud host and the AI model providers our agents call, we are
completing the equivalent contractual review. Until it is complete, we describe
that work honestly here rather than claiming it is done.
[[TO CONFIRM: close this out and replace this paragraph with a positive
statement once the cloud-host and model-provider terms are verified against the
regulation 10 standard. This is publish-blocking only if you prefer not to ship
the honest interim wording.]]
Training. Content from a sandbox session is sent to third-party AI model
providers so the agents can run. We use those providers under commercial API
terms that prohibit them from training their models on that content, and
under which content is deleted within 30 days. That is a contractual
commitment, not a setting we rely on.
This does not make the sandbox a safe place for confidential material. It is a
shared environment, other users may be able to see what you put in, and
processing happens outside Singapore. The sandbox terms still tell you to treat
anything you put in as published, and you must not put production or personal
data into it.
9. How long we keep it
We keep personal data only for as long as we need it for the purposes in
section 4, or for as long as the law requires.
| What | How long |
|---|---|
| Sandbox access request and account records | While your access is active, plus 24 months |
| Sandbox operational telemetry | While your access is active, plus 24 months |
| Website analytics and cookie data | 24 months |
| Email correspondence | 24 months |
| Marketing subscription records | Until you unsubscribe, plus a record of the unsubscribe so we do not email you again |
| Backups | Deleted on the same schedule as the systems they belong to, within the 24-month window |
After those periods we delete the data or anonymise it so it can no longer
identify you.
Sandbox access has no fixed end date. That does not mean we keep your data
forever. If your access is withdrawn or you stop using the sandbox, the
retention periods above start running.
10. How we protect it, and what we do if something goes wrong
We take reasonable steps to protect personal data against unauthorised access,
collection, use, disclosure, copying, modification, and disposal, as section
24 of the PDPA requires. Those steps include access controls on our systems,
encryption in transit, and limiting access to the people who need it.
The sandbox is a shared environment. Content you put into it may be
visible to our staff and, depending on configuration, to other users. This is
why the sandbox terms tell you not to put personal data or production data
into it. Treat everything you put into the sandbox as non-confidential.
If there is a data breach. We will assess any suspected breach as soon as
practicable. Where a breach is notifiable under Part 6A of the PDPA — because
it is likely to cause significant harm to affected individuals, or is of
significant scale — we will notify the Personal Data Protection Commission,
and we will notify affected individuals where the law requires us to. We
notify the Commission within the statutory deadline, which is no later than 3
calendar days after we determine that a breach is notifiable.
We will tell you by email at the address in your access request.
11. Your rights
Under the PDPA you can ask us to:
Give you access. You can ask what personal data we hold about you, and how
we have used or disclosed it in the past year.
Correct it. If something we hold is wrong or incomplete, you can ask us to
correct it. We will correct it unless we are satisfied on reasonable grounds
that the correction should not be made, and we will tell you either way.
Stop using it. You can withdraw your consent as described in section 5.
How to ask. Email hello@acceleratedata.ai with what you want. Put "Data
request" in the subject line. We may need to confirm who you are before we
act, so that we do not disclose your data to someone else.
How long we take. We will respond as soon as reasonably possible. If we
cannot respond within 30 days, we will tell you within those 30 days when we
will respond.
Cost. We do not charge for a correction request or for withdrawing
consent. We do not normally charge for an access request. If a request is
unusually large or repetitive we may charge a reasonable fee, and we will tell
you the amount and get your agreement before we do any work.
Limits. The PDPA allows us to refuse some requests — for example where
giving access would reveal someone else's personal data, or would reveal
confidential commercial information. If we refuse, we will tell you why.
If you are not satisfied. Write to us first at hello@acceleratedata.ai and
tell us what is wrong. If we cannot resolve it, you can complain to the
Personal Data Protection Commission of Singapore at pdpc.gov.sg.
12. Cookies
Our website uses cookies. A cookie is a small file a website stores in your
browser.
| Cookie | Set by | What it does |
|---|---|---|
hutk |
HubSpot | Recognises a returning browser and connects it to a form submission, so we can see which content led to a request |
| reCAPTCHA cookies | Distinguishes people from automated traffic on our forms |
This table covers the cookies we set deliberately. HubSpot's CMS and tracking
script may set further session and analytics cookies depending on which
features are enabled. If you want the current complete list, ask us at
hello@acceleratedata.ai.
You can block or delete cookies in your browser settings. If you block them,
the website will still work, but forms may behave less predictably and we will
not be able to connect your request to the content that brought you here.
We do not use advertising cookies and we do not run retargeting.
13. If you are in the European Union or the United Kingdom
We are a Singapore company and the PDPA is the law we work to. The EU General
Data Protection Regulation and the UK GDPR can still apply to us where we
offer the sandbox to people in those territories or monitor their behaviour on
our website.
Where the GDPR applies to you, in practice this means:
- Our legal bases. We rely on your consent for marketing email and for
non-essential cookies, on the performance of a contract to provision and
run your sandbox access, and on our legitimate interests in securing our
systems, understanding which content works, and improving our product. You
can object to processing based on legitimate interests. - Extra rights. As well as access and correction, you can ask us to erase
your data, restrict how we use it, or send you a portable copy. You can
object to processing and withdraw consent at any time. - How to use them. The same route as section 11: hello@acceleratedata.ai.
The GDPR deadline is one month, and we work to whichever deadline is shorter. - Complaints. You can complain to the data protection authority in your
country, as well as to us. - Transfers. Your data will be transferred to and stored outside the EEA
and the UK. See section 8.
14. Age
The sandbox and this website are for people working in a professional
capacity. You must be at least 18 years old to request sandbox access. We do
not knowingly collect personal data from children. If you believe a child has
given us personal data, tell us at hello@acceleratedata.ai and we will delete
it.
15. Changes to this policy
We may update this policy. Each version carries a version number and an
effective date at the top of this page.
If we make a material change — for example a new purpose, a new category of
data, or a new provider that receives your data — we will email the address in
your access request at least 14 days before the change takes effect.
Changes that are not material take effect when we publish them.
16. Contact
Questions, requests, or complaints about personal data:
Email: hello@acceleratedata.ai
Post: Data Protection Officer, Accelerate Data Pte. Ltd., 68 Circular Road,
#02-01, Singapore 049422