Privacy Policy for Virelith
This Privacy Policy describes how Virelith collects, uses, discloses and protects personal data in connection with our real estate deal registration and transaction support services. We operate from Singapore and handle data necessary to register deals, coordinate transactions and communicate with parties involved in property transactions. Our approach focuses on minimizing friction in the transaction lifecycle while respecting applicable data protection laws.
Definitions
The following terms are used throughout this policy to clarify the types of data and processing activities related to our service offering for real estate deal registration and transaction support.
Data We Collect
We collect data directly from users, automatically through our systems, and from third-party partners when necessary to deliver and improve our services. The volume and type of data depend on the specific transaction and features used.
Data You Provide
When you register a deal, contact support or set up an account, we collect information you supply to enable registration, verification and transaction coordination.
- Contact details: full name, email address, phone number and business contact information
- Property and deal details: address, contract terms, asking/offer prices and timelines
- Company details: agency name, license numbers and representative roles
- Transaction documents: contracts, proof of funds, identification documents and signed forms when necessary
- Communications: messages, attachments and notes platform with Virelith support or counterparties
- Consent and preferences: marketing choices, communication preferences and consent records
Data Collected Automatically
When you visit our website or use our platform, we automatically collect technical and usage data to operate the service securely and improve functionality.
- Technical data such as IP address, browser type and operating system
- Device identifiers and session information for platform access
- Usage data including pages visited, time on site and feature interactions
- Cookies and tracking identifiers used to remember preferences and measure performance
- Referring site or campaign source that led you to our site
- Aggregated analytics and anonymized performance metrics
Third-Party Data Sources
We may receive personal data about you from third parties to verify information, expedite transactions, or comply with legal obligations related to real estate dealings.
- Payment processors and banking partners for transaction-related information
- Identity verification and background check providers
- Public records and property registries when verifying ownership and title information
How We Use Your Data
We use personal data to operate the platform, manage registrations and support transaction workflows. Processing is limited to purposes that enable efficient and compliant deal management.
- To register and process real estate deals and coordinate transaction steps between parties
- To verify identities and supporting documents where required for compliance and risk management
- To communicate with users, provide support and share status updates during transactions
- To store and manage transaction documents securely for the duration required by law or business needs
- To detect and prevent fraud, misuse or unauthorized activity related to deals
- To analyze service usage and improve platform functionality and user experience
- To carry out legal or regulatory obligations and respond to lawful requests from authorities
- To send marketing communications if you have opted in, subject to your preferences and the ability to opt out
Legal Basis for Processing
Where applicable, we rely on established legal bases such as contractual necessity, compliance with legal obligations, legitimate interests and consent for certain activities like marketing.
- Performance of a contract: processing necessary to provide deal registration and transaction services
- Legal obligation: processing to comply with statutory and regulatory requirements
- Legitimate interests: processing to operate, secure and improve our services in ways that do not override individual rights
- Consent: when you opt in to receive marketing communications or other optional features
Data Protection Rights (GDPR & PDPA)
If you are located in the European Economic Area or the UK, you may have rights under local data protection laws. In Singapore, the Personal Data Protection Act (PDPA) provides related protections. Exercising rights may require identity verification and is subject to legal exceptions.
- Right to access: you may request copies of personal data we hold about you
- Right to rectification: you can ask us to correct inaccurate or incomplete information
- Right to erasure: you may request deletion of data where there is no overriding legal reason to retain it
- Right to restriction: you may request limits on how we process your data in certain situations
- Right to data portability: where applicable, you can request a machine-readable copy of data provided by you
- Right to object: you can object to certain processing activities based on legitimate interests, subject to review
Sharing of Personal Data
We share personal data with third parties when necessary to support transactions, comply with law, or provide platform features. Sharing is limited to the minimum required and controlled through contracts.
- Transaction counterparties and their agents to facilitate deal completion
- Service providers such as payment processors, identity verification and document storage vendors
- Regulatory authorities, law enforcement or courts when required by law
- Professional advisors, including legal or tax advisors engaged to support a transaction
- Analytics and hosting providers that process data on our behalf
- Third-party platforms and partners with your consent or as part of agreed transaction workflows
International Data Transfers
Because we operate internationally and work with global service providers, personal data may be transferred to and processed in jurisdictions outside Singapore. Transfers are conducted in accordance with applicable law and with appropriate safeguards.
Safeguards include contractual data protection clauses, data processing agreements, technical security measures such as encryption, and vendor assessments to ensure an adequate level of protection.
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes described, to comply with legal obligations, and to resolve disputes or enforce agreements.
Account information and identity verification records are retained for the duration of the business relationship and typically for up to 7 years after account closure to meet regulatory and record-keeping requirements.
Communications and message history related to transactions are retained for up to 2 years unless a longer period is required for compliance or dispute resolution.
System logs and diagnostic data are retained for operational and security purposes, generally up to 1 year before archival or deletion.
When data is no longer required, we will securely delete or anonymize it subject to any legal retention obligations. Requests for deletion will be assessed in light of regulatory and contractual duties.
Security Measures
Virelith maintains technical and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration and destruction. Security is implemented based on risk assessments and industry-standard practices.
- Encryption in transit and at rest for sensitive data and documents
- Access controls, role-based permissions and regular access reviews
- Incident response procedures, staff training and periodic security assessments
Your Rights
You can exercise your privacy rights by contacting our data protection contact. Requests will be handled in a reasonable timeframe and may require verification to protect privacy and security.
- Request access or correction of personal data we hold about you by contacting us with sufficient detail to locate the records
- Submit requests to object to processing, request restriction or request deletion, which will be reviewed against legal and contractual obligations
- Request data portability for personal data you provided to us when technically feasible
- Right to restriction of processing: You may request that we limit how we use your personal data while a dispute about accuracy or lawfulness is resolved.
- Right to data portability: Where applicable, you can request a machine-readable copy of data you provided to Virelith to transfer it to another provider.
- Right to object: You can object to our processing of your personal data for direct marketing or profiling where your interests outweigh ours.
- Right to withdraw consent: If you previously gave consent for a specific purpose, you can withdraw it at any time; withdrawal affects future processing only.
- Right to lodge a complaint: If you believe your data rights have been breached, you may contact Virelith or escalate to the Personal Data Protection Commission (PDPC) in Singapore.
Exercising Your Data Rights
To exercise any of the rights listed above, submit a written request to our privacy team. Provide enough detail to identify the data and the specific action you want us to take. We will verify your identity before processing requests to protect your information and that of others.
We aim to respond to valid requests promptly and typically provide a substantive response within 30 days of verification. Complex requests may take longer; we will inform you if additional time is necessary.
Marketing Communications
Virelith may use your contact information to send relevant updates about services, industry insights, and offers related to real estate deal registration and transaction support. We tailor communications to be practical and actionable so you receive value in every message.
You can opt out of marketing emails at any time by using the unsubscribe link at the bottom of our messages or by contacting our privacy team. Opting out will stop promotional messages but will not affect transactional messages necessary for service delivery.
Children's Data
Virelith's services are intended for adults and professional users. We do not knowingly collect personal data from children under 18. If we become aware that we have collected information from a child without appropriate consent, we will take steps to delete it.
Third-Party Links
Our site and communications may contain links to third-party sites and services. These third parties operate under their own privacy practices. Virelith is not responsible for the content or privacy practices of those third parties; review their policies before sharing personal data.
Policy Updates
We may update this privacy policy to reflect changes in law, technology, or our services. Material changes will be posted on our website with an updated effective date. Continued use of Virelith services after updates indicates acceptance of the revised policy.