This data protection policy (“Policy”) applies to Paddi Pte Ltd (UEN No,: 202122533K), which is established in Singapore and who manages and operates the website under the domain name: https://chakrabypiya.com (the “Website”).
We are committed to protecting and respecting your privacy while complying with the provisions of the Personal Data Protection Act 2012 of Singapore (“PDPA”). If you are a European Economic Area (“EEA”) resident, we comply with the General Data Protection Regulation (EU) 2016/679 (hereinafter the “GDPR”) insofar as it is applicable to you.
As a Singapore entity, we will comply with the PDPA and any applicable Singapore laws. As for personal data of EEA residents, where there are no applicable Singapore laws, EUPD will be processed in accordance with the GDPR where applicable. We will ensure that complying with the GDPR does not conflict with the PDPA and the applicable Singapore laws.
This Policy is part of the Terms of Service of our Website and unless otherwise defined below, capitalised terms and expressions used in this Policy have the meanings given to them in the Terms of Service.
This Policy describes how Paddi Pte Ltd ("we", "us", or "our")collects, uses, and discloses your personal data when you use our Website, place an order or make a purchase on our Website or otherwise communicate with us regarding the Website. For purposes of this Policy, "you" and "your" means you as the user of the Website, whether you are a Buyer, User, or another individual whose personal data we have collected through our Website, or any other website or service or App, used or operated by us which hyperlinks to our website or this Policy.
By providing your personal data to us, you acknowledge and agree that you have fully read and understood this Policy, and are consenting to the collection, use, processing and disclosure of your personal data as described in this Policy.
Changes to This Policy
We may update this Policy from time to time, including to reflect changes to our practices or for other operational, legal, or regulatory reasons. We will post the revised Policy on the Website, update the "Last updated" date and take any other steps required by applicable law.
Collection and Use of Personal Data
WHAT PERSONAL DATA WE COLLECT
The types of personal data we collect, use or disclose depends on how you interact with and use our Website. The PDPA defines “personal data”, as data, whether true or not, about an individual who can be identified from that data or from that data and other information to which we have or are likely to have access.
The GDPR defines personal data as any information relating to an identified or identifiable natural person (“data subject”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
(above shall be collectively referred to as “personal data” in this Policy).
The following sections describe the categories and specific types of personal data we collect, use and disclose, and the purposes for such collection, use and disclosure.
INFORMATION AND/OR PERSONAL DATA WE COLLECT DIRECTLY FROM YOU
Information and/or personal data that you directly submit to us through our Website may include:
• Contact details including your name, address, phone number, and email.
• Order information including your name, billing address, shipping address, payment confirmation, email address, and phone number.
• Account information including your username, password, selected products, Find Your Chakra Focus results, security questions, and other information collected under your Account and used for account security purposes.
• Customer service information including the information you choose to include in communications with us, for example, when sending a message through the Website, emailing us, or contacting us through WhatsApp or other messaging or social media services.
• Date of birth
Some features of the Website may require you to directly provide us with certain information about yourself which may include personal data. You may elect not to provide this information, but doing so may prevent you from using or accessing these features.
SENSITIVE PERSONAL DATA
We do not generally collect sensitive personal data. While the PDPA does not define sensitive data, the GDPR defines the following as special categories of personal data: racial or ethnic origin; political opinions; religious or philosophical beliefs; trade-union membership; genetic data; biometric data for the purpose of uniquely identifying a natural person; data concerning one’s health or sex life; and sexual orientation.
Where applicable under the GDPR, and only in the event that we process sensitive data, we will only process special categories of data upon obtaining your explicit consent, except under certain circumstances listed in Article 9 of the GDPR such as matters relating to social protection, protection of vital interests, personal data made public by you, for legal claims or for reasons of substantial public interest.
INFORMATION WE COLLECT ABOUT USE
We may also automatically collect certain information about your interaction with the Website ("Usage Data"), for which we may use cookies, pixels and similar technologies ("Cookies"). Usage Data may include information about how you use our Website and your Account, including device information, browser information, information about your network connection, your IP address and other information regarding your interaction with the Website.
INFORMATION FROM THIRD PARTIES
We may obtain personal data about you from third parties, including from vendors and service providers who may collect and process data on our behalf, such as:
• Companies who support our Website, such as Shopify and various social media platforms.
• Our payment processors, who collect payment data (e.g., bank account, credit or debit card information, billing address) to process your payment in order to fulfil your orders and provide you with products or services you have requested, in order to perform our contract(s) with you.
• When you visit our Website, open or click on emails we send you, communicate with us through WhatsApp or other messaging or social media services, or interact with our Website or advertisements, we, or third parties we work with, may automatically collect certain information using online tracking technologies such as pixels, web beacons, software developer kits, third-party libraries, and cookies.
Any personal data we obtain from third parties will be treated in accordance with this Privacy Policy.
Also see the section below titled Third-Party Websites and Links.
HOW WE USE PERSONAL DATA
In addition to the specific uses set out below, we may use personal data we collect about you to communicate with you, provide or improve the Website, comply with any applicable legal obligations, enforce any applicable terms of service, and to protect or defend the Website, our rights, and the rights of Users or others. We may use your personal data that we collect for any or all of the following purposes:
• Providing Products. We use your personal data to provide you with the Website and to perform our contract(s) with you under our Terms of Service, including on the sale and purchase of Products, to process your payments, fulfil your orders, to send notifications to you related to your Account, purchases, returns, exchanges or other transactions, to create, maintain and otherwise manage your Account, to arrange for shipping, facilitate any returns and exchanges and other features and functionalities related to your Account. If you are an EEA resident , the legal basis for these data processing activities is for the performance of our contract(s) with you, according to Art. 6 (1) (b) of the GDPR.
• Marketing and Advertising. If you opt-in to receiving from us marketing, advertising and promotional communications, we may use your personal data for marketing and promotional purposes, and to send to you marketing communications by email, text message or postal mail, and to show you advertisements for products or services (including through social media platforms). This may include using your personal data to better tailor our marketing communications and advertising on our Website and other websites. If you are an EEA resident, the legal basis for these data processing activities is our legitimate interest in promoting and/or selling our products in accordance with Art. 6 (1) (f) of the GDPR and your consent in accordance with Art. 6(1) (a) of the GDPR. You may opt out of receiving marketing communications from us at any time by using the unsubscribe option displayed in our emails to you. If you opt out, we may still send you non-promotional emails, such as those about your Account or orders that you have made on our Website.
• Legal Compliance, Security and Fraud Prevention. We use your personal data to detect, investigate or take action regarding possible fraudulent, illegal or malicious activity. We may also use your personal data to comply with any international, federal, provincial or state regulations, rules, laws, local ordinances or investigations thereunder. If you choose to use the Website and register an Account, you are responsible for keeping your Account credentials safe. We highly recommend that you do not share your username, password, or other access details with anyone else. If you believe your Account has been compromised, please contact us immediately. If you are an EEA resident, the legal basis for these data processing activities is our legitimate interest in keeping our Website secure for you and other customers, according to Art. 6 (1) (f) of the GDPR and for compliance with our legal obligations under Art. 6 (1) (c) of the GDPR.
• Communicating with You and Service Improvement. We use your personal data to provide you with customer support and improve our Website and Products. If you are an EEA resident, this is in our legitimate interests in answering any queries to provide effective services to you, and to maintain our business relationship with you according to Art. 6 (1) (f) of the GDPR. In cases where communication relates to an order, the lawful basis for processing of your personal data is the performance of our contract with you according to Art. 6 (1) (b) of the GDPR.
• Other Purposes: We may also use your personal data for any other purposes for which you have provided the personal data and for any other incidental purposes related to or in connection with the above purposes that we consider to be in our legitimate interest.
• If your personal data is used for different purposes and/or shared with a third party in a situation not mentioned in this Policy, we will seek your consent before proceeding to use and/or share your personal data.
Disclosure of Personal Data
DISCLOSURE TO THIRD PARTIES
In certain circumstances, we may disclose your personal data to third parties for contract fulfilment purposes, legitimate purposes and other reasons subject to this Policy. Such circumstances may include the disclosure of personal data
• With vendors, service providers, suppliers, and other third parties who perform services on our behalf (e.g., IT management, payment processing, data analytics, customer support, cloud storage, order fulfilment, shipping, marketing and promotion).
• When you direct, request us or otherwise consent to our disclosure of certain information to third parties, such as to ship your products or through your use of social media widgets or login integrations, with your consent.
• With our affiliates or otherwise with our corporate group, for the legitimate conduct of the group’s business.
• In connection with a business transaction such as a merger or bankruptcy, to comply with any applicable legal obligations (including to respond to subpoenas, search warrants and similar requests), to enforce any applicable terms of service, and to protect or defend the Website, our rights, and the rights of our users or others.
CATEGORIES OF PERSONAL DATA AND RECIPIENTS
We may disclose the following categories of personal data about you to the following categories of recipients (“Recipients”) for the purposes set out above::
| Categories of Personal Data | Categories of Recipients |
| • Identifiers such as basic contact details and certain order and account information • Personal data categories l such as basic contact details and certain order and account information • Commercial information such as order information, shopping information and customer support information • Internet or other similar network activity, such as Usage Data • Geolocation data such as locations determined by an IP address or other technical measures |
• Vendors, service providers, suppliers, and third parties who perform services on our behalf (such as Internet service providers, payment processors, fulfilment partners, customer support partners, data analytics providers, cloud storage providers, shipping partners, marketing and promotion partners) • Business and marketing partners • Affiliates |
We shall endeavour to ensure that recipients only use the above personal data for the purposes for which it was provided to them and to the extent necessary for such purposes and will observe and adhere to the terms of this Policy.
We do not use or disclose sensitive personal data without your explicit consent or for the purposes of inferring characteristics about you.
Transfer of personal data outside Singapore
We will take all necessary steps to ensure that the standard of protection in the recipient country is comparable to that of the PDPA, or if applicable the GDPR.
Third-Party Websites and Links
Our Website may provide links to websites or other online platforms operated by third parties. If you follow links to sites not affiliated or controlled by us, you should review their privacy and security policies and other terms and conditions. We do not guarantee and are not responsible for the privacy or security of such sites, including the accuracy, completeness, or reliability of information found on these sites. Information you provide on public or semi-public venues, including information you share on third-party social networking platforms may also be viewable by other users of the Website and/or users of those third-party platforms without limitation as to its use by us or by a third-party. Our inclusion of such links does not, by itself, imply any endorsement of the content on such platforms or of their owners or operators, except as disclosed on the Website. These third-party websites and platforms are responsible for ensuring that they apply appropriate safeguards and give you options in relation to the collection, use and disclosure of your personal data.
Cookies
Like many websites, we use Cookies on our Website. For specific information about the Cookies that we use related to powering our store with Shopify, see https://www.shopify.com/legal/cookies. We use Cookies to power and improve our Website (including to remember your actions and preferences), to run analytics and better understand user interaction with the Website (in our legitimate interests to administer, improve and optimize the Website). We may also permit third parties, services providers and other Recipients to use Cookies on our Website to better tailor the services, products and advertising on our Website and other websites.
Most browsers automatically accept Cookies by default, but you can choose to set your browser to remove or reject Cookies through your browser controls. Please keep in mind that removing or blocking Cookies can negatively impact your user experience and may cause some parts of the Website, including certain features and general functionality, to work incorrectly or no longer be available. Additionally, blocking Cookies may not completely prevent how we share information with third parties such as our advertising partners.
Please note that while your browser may allow you to transmit a “do not track” signal, like many websites, our Website is not designed to respond to such signals. To learn more about “do not track” signals, you can visit http://www.allaboutdnt.com/.
Data of Underaged Persons
The Website is not intended to be used by any individual aged below 18 years, and we do not knowingly collect any personal data about such underaged individuals. We do not claim any responsibility or actual knowledge that we “collect”, “use”, “disclose”, “retain”, “share” or “sell” (as those terms are defined in applicable law) personal data of individuals under 18 years of age.
If you are aged below 18 years, and have provided us your personal data, please contact us or seek the assistance of your parent or guardian to contact us using the contact details set out below to request that it be deleted.
Security and Protection of Personal Data
SECURITY MEASURES
We have implemented the appropriate security and technical measures to protect your personal data that is under our care and control to prevent loss, modification, collection, unauthorised access, misuse, copying, alteration, disclosure and/or destruction.
If we engage external data intermediaries to process and maintain your personal data on our behalf, they will be bound by contractual data protection arrangements we have with them.
Do note that the transmission of data over the internet is never completely secure. While we endeavour to protect your personal data, we cannot guarantee the security of data transmitted to us or by us.
RETENTION
We will retain your personal data for as long as such data is necessary to fulfil the purposes of collection, use and disclosure as set out in this Policy, or as required or permitted by all applicable laws.
Your personal information will also be retained by us for marketing purposes until you opt out of receiving or notify us that you no longer wish to receive marketing communications from us by following the steps set out below under the paragraph titled “Your Consent and Rights”.
International Users
By using our Website, you agree that we may transfer, store and process your personal data outside the country you live in and that your personal data may be processed by staff and third-party service providers and partners in these countries so that we may make the Website available for your use. If you do not consent to your personal data being transferred, stored in or processed outside the country you live in, you must discontinue all use of and cease all interaction with the Website immediately.
Your Consent and Rights
By using our Website, you consent to the collection, use and disclosure of your personal data and other activities as outlined in this Policy.
Your consent will remain valid until it is withdrawn by you. You may at any time withdraw your consent and request for us to stop collecting, using and/or disclosing your personal data for any or all of the purposes listed above by writing to us or via email to our Data Protection Officer at the contact details provided below.
Under the PDPA, you have the following rights:
• Right to Access: You have a right to request access to your personal data that we hold.
• Right to Know: You have a right to know the ways in which we have used and shared your personal data over the preceding 12 months.
• Right to Correct: You have a right to request us to correct or update any of your personal data that we hold.
For EEA residents, you are also granted the right to request the erasure of your personal data, the right to object to the processing of your personal data in specific circumstances and the right to restrict processing.
If you wish to exercise any of your rights, you may submit your request in writing or via email to our Data Protection Officer at the contact details provided below.
Withdrawing consent
If you wish to withdraw consent, you should give us reasonable advance notice in writing. While we respect your right and decision, please note that the withdrawal of consent amongst other things, will affect the quality of services rendered to you. Upon your withdrawal of consent, we will cease (and cause our intermediaries and agents to cease) collecting, using or disclosing the personal data unless it is authorised or required under applicable laws.
Accessing and making corrections to your personal data
You may write to us, based on reasonable grounds, to find out how we have been using or disclosing your personal data and / or to request a copy of your personal data.
Before we accede to your request, we will need you to verify your identity. Thereafter, we will let you have an estimate of the time required to retrieve all the relevant personal data and the fee that we will charge for processing your request (our costs in administering your request). Upon confirmation of your acceptance of the aforesaid fee, we shall respond to your written request within 30 days. You will also be informed in the event that we are unable to accede to your request. We may choose to deny you access to, and/or correction of, your personal data in accordance with the exceptions under the PDPA, such as when we are satisfied on reasonable grounds that the correction should not be made or that the request for access is frivolous or vexatious or the information requested is trivial.
Governing Law and Jurisdiction
Nothing in this Policy shall limit the rights of the data subject under any applicable law. This Policy shall be governed by the laws of Singapore. You agree to submit to the exclusive jurisdiction of the Singapore courts.
Language
The Website is currently available only in English. In case of discrepancies between the English version and (if available) any other language versions of the Policy and contents of this Website, the English version shall prevail.
Data Protection Officer
If you have any queries regarding this Privacy Policy, you may contact our Data Protection Officer by email at: office@chakrabypiya.com.
Last updated: 20 November 2025