Privacy Policy
Effective date: 21 July 2026 · Last updated: 21 July 2026
1. Introduction
LawPoint Pte. Ltd. ("LawPoint", "we", "us", or "our") is committed to protecting personal data in accordance with the Personal Data Protection Act 2012 of Singapore ("PDPA") and related subsidiary legislation. This Privacy Policy explains how we collect, use, disclose, store, and protect personal data when you visit lawpoint.life, communicate with us, or engage our legal services.
By using our website or providing personal data to us, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use our website or submit personal data through our channels.
2. Data controller
LawPoint Pte. Ltd., UEN 202628351M, registered at 7 Straits View #16-05, Marina One East Tower, Singapore 018936, is the organisation responsible for personal data collected through this website and in connection with our legal practice, unless otherwise stated in an engagement letter.
For privacy-related enquiries, contact our Data Protection Officer at [email protected] or write to the registered address above.
3. Personal data we collect
We may collect the following categories of personal data depending on your interaction with us:
- Identity and contact data: name, email address, telephone number, job title, company name, and postal address.
- Enquiry data: information you provide in contact forms, emails, or consultations, including descriptions of legal matters.
- Technical data: IP address, browser type, device identifiers, pages visited, and referral URLs collected through cookies and similar technologies where permitted.
- Engagement data: billing information, correspondence, documents, and instructions provided when you become a client.
- Marketing preferences: your choices regarding newsletters or event invitations where applicable.
We do not intentionally collect sensitive personal data through our website contact form unless you voluntarily include it in your message. If you are submitting information about health, criminal records, or other sensitive categories in connection with a legal matter, please do so only through secure channels we designate after engagement.
4. How we collect personal data
We collect personal data through several channels:
- Direct submission via our contact form at lawpoint.life/contact.php, which posts to our secure processing endpoint.
- Email, telephone, or in-person communication during office hours (Monday to Friday, 09:30–18:30 SGT).
- Automated technologies such as essential and optional cookies described in our Cookie Policy.
- Referrals from existing clients, correspondent firms, or professional networks, where the referrer has authority to share your contact details.
- Publicly available sources including corporate registries and regulatory filings relevant to legal due diligence.
5. Purposes of collection, use, and disclosure
We collect and use personal data for purposes that a reasonable person would consider appropriate in the circumstances, including:
- Responding to enquiries and assessing whether we can act for you.
- Performing conflict checks and client onboarding procedures required by law and professional conduct rules.
- Delivering legal services, maintaining files, and communicating about your matters.
- Issuing invoices, processing payments, and fulfilling accounting obligations.
- Complying with statutory and regulatory requirements, including anti-money laundering and countering the financing of terrorism obligations.
- Improving our website, analysing aggregate usage trends, and maintaining security.
- Sending updates about legal developments or firm events where you have consented or where permitted by law.
- Establishing, exercising, or defending legal claims.
We may disclose personal data to third parties where necessary for these purposes, including IT service providers, cloud hosting providers, professional indemnity insurers, auditors, correspondent law firms, courts and tribunals, and regulatory authorities. We require processors to protect personal data through contractual safeguards commensurate with the sensitivity of the information.
6. Legal basis and consent
Under the PDPA, we rely on consent, contractual necessity, legal obligation, and legitimate interests as appropriate. When you submit our contact form, you must tick the consent checkbox (consent_pdpa) confirming that you agree to our collection and use of your data to respond to your enquiry. You may withdraw consent for marketing communications at any time without affecting the lawfulness of processing before withdrawal.
Where we process personal data of employees or representatives of corporate clients, we rely on legitimate interests and contractual necessity in addition to any consent obtained from the individual or authorised by their organisation.
7. Cookies and similar technologies
Our website uses cookies to enable core functionality and, with your consent, analytics and marketing cookies. Details of each cookie category, retention periods, and management options are set out in our Cookie Policy. You may accept all cookies, reject non-essential cookies, or customise preferences through the banner displayed on first visit.
8. Retention
We retain personal data only as long as necessary for the purposes described in this policy or as required by law. Enquiry records from non-clients are typically retained for up to twenty-four months unless a longer period is needed to resolve a dispute. Client files are retained in accordance with Law Society practice directions and limitation periods applicable to legal claims, which may extend to seven years or more after matter closure.
When personal data is no longer required, we securely delete or anonymise it using methods appropriate to the medium of storage.
9. Cross-border transfers
Some of our service providers may store or process personal data outside Singapore. Where we transfer personal data overseas, we ensure that the recipient jurisdiction provides a comparable standard of protection or we implement contractual clauses and technical measures required under the PDPA to protect your data.
10. Security measures
We implement administrative, technical, and physical safeguards to protect personal data against unauthorised access, collection, use, disclosure, copying, modification, disposal, or similar risks. Measures include access controls, encrypted transmission where supported, staff training, and incident response procedures. No method of transmission over the internet is completely secure; we encourage you to use strong passwords and avoid sending highly confidential documents through unencrypted email before engagement.
11. Your rights under the PDPA
Subject to exceptions under the PDPA, you may:
- Request access to personal data we hold about you.
- Request correction of inaccurate or incomplete personal data.
- Withdraw consent for processing that relies on consent, understanding that this may limit our ability to continue certain services.
- Request information about how your personal data has been used or disclosed within the past year.
To exercise these rights, email [email protected] with sufficient detail to identify you and your request. We respond within thirty days unless an extension is permitted. A reasonable fee may apply for manifestly unfounded or excessive access requests.
12. Accuracy
We take reasonable steps to ensure personal data is accurate and complete. Please notify us promptly if your contact details change or if you believe information we hold is incorrect.
13. Third-party links
Our website may contain links to external sites operated by third parties. We are not responsible for the privacy practices of those sites and encourage you to review their policies before providing personal data.
14. Children
Our website and services are directed at business clients and adults. We do not knowingly collect personal data from individuals under eighteen without appropriate parental or guardian involvement.
15. Data breach notification
In the event of a data breach likely to result in significant harm or affect a significant number of individuals, we will notify the Personal Data Protection Commission and affected individuals as required by the PDPA, and take remedial steps to mitigate harm.
16. Updates to this policy
We may update this Privacy Policy to reflect changes in law, technology, or our practices. The effective date at the top of this page indicates the latest revision. Material changes will be highlighted on our website where practicable.
17. Contact
LawPoint Pte. Ltd.
7 Straits View #16-05, Marina One East Tower, Singapore 018936
Email: [email protected]
Phone: +65 6918 3752
18. Complaints
If you believe we have handled your personal data in breach of the PDPA, you may lodge a complaint with us at the contact details above. We investigate complaints promptly and aim to resolve them within fourteen business days. You also have the right to refer unresolved complaints to the Personal Data Protection Commission of Singapore.
19. Definitions
In this Privacy Policy, "personal data" means data about an individual who can be identified from that data or from that data and other information to which we have or are likely to have access. "Processing" includes collecting, recording, holding, organising, adapting, altering, retrieving, using, disclosing, or destroying personal data.