Privacy Policy
Effective Date: 1 May 2026 · Version 1.0
Introduction
WMG Pte Ltd (“WMG”, “Wavelink”, “World Wavelink”, “we”, “our”, or “us”), a company incorporated in Singapore (Company Registration No. 200007060H), operates the World Wavelink platform, including the websites at worldwavelink.com, worldwavelink.net, together with associated APIs and services (collectively, the “Platform”).
This Privacy Policy explains how we collect, use, disclose, and protect personal data in connection with your use of the Platform. It applies to:
- Customer organisations and their authorised users accessing the customer portal or client API;
- Government agencies and their authorised analysts accessing the government data portal or government API;
- Visitors to our public-facing websites;
- Business contacts and prospective partners who communicate with us.
By accessing or using the Platform, you acknowledge that you have read and understood this Privacy Policy. If you are accessing the Platform as an authorised user on behalf of an organisation, you represent that your organisation has authorised you to do so and has agreed to our Terms of Use.
This Privacy Policy should be read alongside our Terms of Use, which govern your use of the Platform.
Definitions
In this Privacy Policy, the following terms have the meanings given below:
Personal Data We Collect
We collect personal data only where necessary for the operation of the Platform and the delivery of our Services. The categories of personal data we collect depend on how you interact with the Platform.
3.1 Account and Identity Data
When Portal Users are registered on the Platform (by their organisation's administrator or by WMG), we collect:
- Full name
- Work email address
- Job title and department (optional)
- Organisation name and role on the Platform (administrator or member)
- Authentication credentials (passwords stored as cryptographic hashes; we do not store plaintext passwords)
- Multi-factor authentication settings and recovery information
3.2 Usage and Activity Data
When you use the Platform, we automatically collect:
- Login timestamps, session duration, and session identifiers
- Pages visited, features accessed, and actions performed within the Platform
- IP address and approximate geographic region at login
- Browser type, operating system, and device type
- API request logs, including endpoint called, timestamp, HTTP method, and response code (but not request or response payload content unless required for debugging with your consent)
3.3 Shipment and Transaction Data
In the course of providing logistics coordination services, we process data relating to shipments managed through the Platform. This data is provided by Customers and may include personal data of individuals involved in shipment transactions, including:
- Shipper and consignee names and contact details
- Names and contact details of notify parties
- Customs declarant names and identifiers where required by applicable trade regulations
Where this data relates to identified or identifiable individuals (as opposed to corporate entities), it is treated as personal data under this Privacy Policy.
3.4 Communications Data
If you contact us directly (by email, through a contact form, or otherwise), we collect:
- Your name and contact details
- The content of your communication
- Any attachments or supporting documents you send to us
3.5 Government Portal Data
Authorised analysts from Government Agencies accessing the government data portal are identified by their organisational login credentials (processed via SAML SSO through their agency's own identity provider, or via OAuth credentials issued by WMG). We log every query made through the government portal, including the query parameters and result metadata, for audit and transparency purposes. Query results are aggregated and do not contain individual-level personal data.
3.6 Data We Do Not Collect
We do not collect, and you must not provide to us through the Platform:
- Payment card numbers or banking credentials (payment processing, where applicable, is handled by regulated third-party processors outside the Platform)
- Sensitive personal data such as national identification numbers, passport numbers, or biometric data, except where required by applicable customs or trade regulations and handled in accordance with those regulations
- Personal data of individuals under 18 years of age
How We Use Personal Data
We use personal data for the following purposes, each of which has a corresponding legal basis:
4.1 Providing and Operating the Platform
Legal basis: Performance of a contract / Legitimate interests
- Creating and managing user accounts
- Authenticating users and maintaining session security
- Processing and tracking shipments
- Generating and delivering reports and notifications
- Providing customer support
4.2 Platform Security and Integrity
Legal basis: Legitimate interests / Legal obligation
- Detecting, investigating, and preventing unauthorised access, fraud, and abuse
- Maintaining audit logs of user actions for security and compliance purposes
- Monitoring system performance, uptime, and reliability
- Enforcing our Terms of Use and acceptable use policies
4.3 Service Improvement
Legal basis: Legitimate interests
- Analysing usage patterns to improve Platform features and user experience
- Identifying and resolving technical issues
- Developing new features and services
Where we use personal data for service improvement purposes, we use aggregated or anonymised data wherever possible. We do not sell usage data to third parties or use it for behavioural advertising.
4.4 Legal and Regulatory Compliance
Legal basis: Legal obligation
- Complying with applicable laws and regulations in Singapore and jurisdictions in which we operate
- Responding to lawful requests from courts, regulators, and law enforcement authorities
- Maintaining records required by applicable financial, trade, and corporate law
4.5 Communications
Legal basis: Legitimate interests / Consent (where required)
- Responding to your enquiries and providing support
- Sending service-related notices, including security alerts, policy updates, and maintenance notifications
- Sending marketing and promotional communications, where you have opted in to receive them
You may opt out of marketing communications at any time by using the unsubscribe link in any such communication or by contacting us at the address in Section 12.
Disclosure of Personal Data
We do not sell personal data. We disclose personal data only in the following circumstances:
5.1 Within the Platform Ecosystem
Personal data relating to shipments may be shared with other parties involved in the shipment transaction, including freight vendors, carriers, and customs agents, to the extent necessary to coordinate the shipment. This sharing is disclosed to and authorised by the Customer at the point of order.
5.2 Service Providers
We engage third-party service providers to assist in operating the Platform. These providers act as data processors under our instruction and are bound by confidentiality obligations and data processing agreements. They include:
- Cloud infrastructure providers (server hosting, storage, and networking)
- Email delivery providers
- Authentication services
- Monitoring and alerting services
- Professional services providers (legal, audit, and compliance advisers)
We do not permit service providers to use personal data for their own purposes.
5.3 Government and Regulatory Authorities
We may disclose personal data to government bodies, regulators, courts, and law enforcement authorities where required to do so by applicable law, or where we believe in good faith that disclosure is necessary to:
- Comply with a legal obligation or court order
- Protect the rights, property, or safety of WMG, our customers, or the public
- Detect, prevent, or address fraud, security breaches, or technical issues
5.4 Business Transfers
In the event of a merger, acquisition, reorganisation, or sale of all or substantially all of WMG's assets, personal data held by WMG may be transferred to the acquiring entity as part of that transaction. We will notify affected individuals in accordance with applicable law if such a transfer involves a material change in how their personal data is used.
5.5 Aggregated and Anonymised Data
We may share aggregated, anonymised, or de-identified data that cannot reasonably be used to identify individuals, including with government partners for trade analytics purposes. Such data is not personal data and is not subject to the restrictions in this Privacy Policy.
International Data Transfers
WMG is incorporated and headquartered in Singapore. The Platform is operated from Singapore, with cloud infrastructure hosted with providers operating in Singapore and, where required for performance, in other regions.
Where personal data is transferred outside Singapore to countries that may not offer the same level of data protection as Singapore, we ensure that appropriate safeguards are in place, including:
- Standard contractual clauses or equivalent data transfer mechanisms recognised under the PDPA and applicable international frameworks
- Adequacy decisions or binding corporate rules where applicable
- Contractual obligations on recipients to maintain standards of protection comparable to those under the PDPA
Customers whose operations involve cross-border shipments should be aware that shipment-related data may need to be processed by customs authorities, carriers, and freight agents in the origin, transit, and destination jurisdictions of each shipment. This processing is an inherent feature of cross-border trade and is not within WMG's control. Customers are responsible for ensuring their own compliance with applicable data protection laws in relation to data they submit to the Platform.
Data Retention
We retain personal data for as long as necessary to fulfil the purposes for which it was collected, subject to our legal and contractual obligations. Our standard retention periods are:
- Account and identity data: retained for the duration of the account and for 5 years following account closure, to comply with corporate record-keeping requirements
- Shipment and transaction data: retained for 7 years from the date of the last transaction, to comply with trade, customs, and tax record-keeping requirements in applicable jurisdictions
- Audit and security logs: retained for 3 years from the date of the logged event
- Communications data: retained for 2 years from the date of the communication, unless the subject matter requires longer retention
- Marketing consent records: retained for 5 years from the date of consent, or until consent is withdrawn, whichever is earlier
Where retention beyond these periods is required by law or regulation (for example, by customs authorities or tax authorities), we retain data for the period required by that law or regulation.
When personal data is no longer required, we delete or anonymise it in a manner appropriate to the sensitivity of the data.
Security
We implement technical and organisational measures designed to protect personal data against unauthorised access, disclosure, alteration, or destruction. These measures include:
- Encryption of data in transit using TLS 1.2 or higher
- Encryption of data at rest
- Access controls limiting data access to authorised personnel on a need-to-know basis
- Role-based access controls within the Platform
- Multi-factor authentication for administrative access
- Comprehensive audit logging of access to and modifications of personal data
- Regular security assessments and penetration testing
- Incident response procedures
No method of transmission or storage is completely secure. In the event of a data breach that is likely to result in significant harm to affected individuals, we will notify affected parties and relevant regulatory authorities as required by applicable law.
Cookies and Tracking
The Platform uses cookies and similar tracking technologies. The types of cookies we use are:
Essential Cookies
These cookies are necessary for the Platform to function. They include session authentication cookies and CSRF protection tokens. You cannot opt out of essential cookies without ceasing to use the Platform.
Functional Cookies
These cookies remember your preferences (such as theme settings) and improve your experience. They can be disabled without affecting core Platform functionality.
Analytics Cookies
We use limited analytics to understand how the Platform is used and to improve it. Where we use third-party analytics tools, these are configured to anonymise IP addresses and not to share data with third parties for advertising purposes. You may opt out of analytics cookies via your browser settings.
We do not use advertising cookies or third-party behavioural tracking on the Platform.
Your browser settings allow you to control which cookies are accepted. Restricting essential cookies may prevent some or all Platform functions from working correctly.
Your Rights
Subject to applicable law, you have the following rights in relation to your personal data:
Right to Access
You have the right to request a copy of the personal data we hold about you and information about how we use it.
Right to Correction
You have the right to request that we correct inaccurate or incomplete personal data about you.
Right to Withdrawal of Consent
Where we process your personal data on the basis of consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
Right to Data Portability
Where technically feasible and required by applicable law, you may request that we provide your personal data in a structured, commonly used, machine-readable format.
Right to Erasure
You may request that we delete your personal data in certain circumstances, subject to our legal obligations to retain data for regulatory, audit, and dispute-resolution purposes.
Right to Object
You may object to our processing of your personal data for direct marketing purposes at any time. You may also object to other processing based on legitimate interests, subject to our demonstrating compelling legitimate grounds for the processing.
Portal Users who are accessing the Platform as an employee or representative of a Customer organisation should note that certain rights (such as correction or deletion of shipment records) may be subject to the agreement between WMG and that Customer organisation.
To exercise any of these rights, please contact our Data Protection Officer at the address in Section 12. We will respond to requests within 30 days, or such other period as required by applicable law.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or Platform features. We will provide notice of material changes by:
- Publishing the updated Privacy Policy on this page with a revised Effective Date
- Sending a notification to registered Portal Users via in-app notification or email, at least 30 days before the changes take effect for material changes
Your continued use of the Platform after the effective date of any updated Privacy Policy constitutes acceptance of the changes. If you do not agree to the updated Privacy Policy, you should discontinue use of the Platform and contact your organisation's administrator or WMG to discuss your options.
Contact and Data Protection Officer
WMG has appointed a Data Protection Officer (DPO) as required under the PDPA. If you have questions about this Privacy Policy, wish to exercise your rights, or wish to raise a concern about our handling of your personal data, please contact:
Data Protection Officer
KK Leong
Data Protection Officer
WMG Pte Ltd
60 Paya Lebar Rd, #06-20
Singapore 409051
admin@worldwavelink.com
We will acknowledge receipt of your request and aim to provide a substantive response within 30 days. Where a request is complex or numerous, we may extend this period by up to a further 30 days, and will notify you accordingly.
If you are not satisfied with our response, you have the right to lodge a complaint with the Personal Data Protection Commission of Singapore (pdpc.gov.sg) or the data protection authority in your jurisdiction.
Governing Law
This Privacy Policy is governed by and construed in accordance with the laws of the Republic of Singapore. Any dispute relating to this Privacy Policy shall be subject to the exclusive jurisdiction of the Singapore courts, without prejudice to your right to lodge a complaint with the relevant data protection authority in your jurisdiction.
World Wavelink is a product of WMG Pte Ltd, Singapore. Company Registration No. 200007060H.