Legal

Privacy Policy

Effective Date: 1 May 2026  ·  Version 1.0

01

Introduction

WMG Pte Ltd (“WMG”, “Wavelink”, “World Wavelink”, “we”, “our”, or “us”), a company incorporated in Singapore (Company Registration No. 200007060H), operates the World Wavelink platform, including the websites at worldwavelink.com, worldwavelink.net, together with associated APIs and services (collectively, the “Platform”).

This Privacy Policy explains how we collect, use, disclose, and protect personal data in connection with your use of the Platform. It applies to:

  • Customer organisations and their authorised users accessing the customer portal or client API;
  • Government agencies and their authorised analysts accessing the government data portal or government API;
  • Visitors to our public-facing websites;
  • Business contacts and prospective partners who communicate with us.

By accessing or using the Platform, you acknowledge that you have read and understood this Privacy Policy. If you are accessing the Platform as an authorised user on behalf of an organisation, you represent that your organisation has authorised you to do so and has agreed to our Terms of Use.

This Privacy Policy should be read alongside our Terms of Use, which govern your use of the Platform.

02

Definitions

In this Privacy Policy, the following terms have the meanings given below:

Personal Datameans any data, whether true or not, about an individual who can be identified from that data, or from that data and other information to which we have or are likely to have access.
Platformmeans the World Wavelink cross-border logistics coordination platform, including all websites, web applications, APIs, and associated services operated by WMG.
Customermeans a business organisation that has entered into a service agreement with WMG and uses the Platform to manage cross-border shipments.
Portal Usermeans an individual authorised by a Customer or Government Agency to access the Platform on their behalf.
Government Agencymeans a government body or regulatory authority that has entered into a data access agreement with WMG to access aggregated trade data through the government API or portal.
Servicesmeans all services provided through the Platform, including shipment coordination, documentation management, freight tracking, and data analytics.
PDPAmeans the Personal Data Protection Act 2012 of Singapore, as amended from time to time.
03

Personal Data We Collect

We collect personal data only where necessary for the operation of the Platform and the delivery of our Services. The categories of personal data we collect depend on how you interact with the Platform.

3.1 Account and Identity Data

When Portal Users are registered on the Platform (by their organisation's administrator or by WMG), we collect:

  • Full name
  • Work email address
  • Job title and department (optional)
  • Organisation name and role on the Platform (administrator or member)
  • Authentication credentials (passwords stored as cryptographic hashes; we do not store plaintext passwords)
  • Multi-factor authentication settings and recovery information

3.2 Usage and Activity Data

When you use the Platform, we automatically collect:

  • Login timestamps, session duration, and session identifiers
  • Pages visited, features accessed, and actions performed within the Platform
  • IP address and approximate geographic region at login
  • Browser type, operating system, and device type
  • API request logs, including endpoint called, timestamp, HTTP method, and response code (but not request or response payload content unless required for debugging with your consent)

3.3 Shipment and Transaction Data

In the course of providing logistics coordination services, we process data relating to shipments managed through the Platform. This data is provided by Customers and may include personal data of individuals involved in shipment transactions, including:

  • Shipper and consignee names and contact details
  • Names and contact details of notify parties
  • Customs declarant names and identifiers where required by applicable trade regulations

Where this data relates to identified or identifiable individuals (as opposed to corporate entities), it is treated as personal data under this Privacy Policy.

3.4 Communications Data

If you contact us directly (by email, through a contact form, or otherwise), we collect:

  • Your name and contact details
  • The content of your communication
  • Any attachments or supporting documents you send to us

3.5 Government Portal Data

Authorised analysts from Government Agencies accessing the government data portal are identified by their organisational login credentials (processed via SAML SSO through their agency's own identity provider, or via OAuth credentials issued by WMG). We log every query made through the government portal, including the query parameters and result metadata, for audit and transparency purposes. Query results are aggregated and do not contain individual-level personal data.

3.6 Data We Do Not Collect

We do not collect, and you must not provide to us through the Platform:

  • Payment card numbers or banking credentials (payment processing, where applicable, is handled by regulated third-party processors outside the Platform)
  • Sensitive personal data such as national identification numbers, passport numbers, or biometric data, except where required by applicable customs or trade regulations and handled in accordance with those regulations
  • Personal data of individuals under 18 years of age
04

How We Use Personal Data

We use personal data for the following purposes, each of which has a corresponding legal basis:

4.1 Providing and Operating the Platform

Legal basis: Performance of a contract / Legitimate interests

  • Creating and managing user accounts
  • Authenticating users and maintaining session security
  • Processing and tracking shipments
  • Generating and delivering reports and notifications
  • Providing customer support

4.2 Platform Security and Integrity

Legal basis: Legitimate interests / Legal obligation

  • Detecting, investigating, and preventing unauthorised access, fraud, and abuse
  • Maintaining audit logs of user actions for security and compliance purposes
  • Monitoring system performance, uptime, and reliability
  • Enforcing our Terms of Use and acceptable use policies

4.3 Service Improvement

Legal basis: Legitimate interests

  • Analysing usage patterns to improve Platform features and user experience
  • Identifying and resolving technical issues
  • Developing new features and services

Where we use personal data for service improvement purposes, we use aggregated or anonymised data wherever possible. We do not sell usage data to third parties or use it for behavioural advertising.

4.4 Legal and Regulatory Compliance

Legal basis: Legal obligation

  • Complying with applicable laws and regulations in Singapore and jurisdictions in which we operate
  • Responding to lawful requests from courts, regulators, and law enforcement authorities
  • Maintaining records required by applicable financial, trade, and corporate law

4.5 Communications

Legal basis: Legitimate interests / Consent (where required)

  • Responding to your enquiries and providing support
  • Sending service-related notices, including security alerts, policy updates, and maintenance notifications
  • Sending marketing and promotional communications, where you have opted in to receive them

You may opt out of marketing communications at any time by using the unsubscribe link in any such communication or by contacting us at the address in Section 12.

05

Disclosure of Personal Data

We do not sell personal data. We disclose personal data only in the following circumstances:

5.1 Within the Platform Ecosystem

Personal data relating to shipments may be shared with other parties involved in the shipment transaction, including freight vendors, carriers, and customs agents, to the extent necessary to coordinate the shipment. This sharing is disclosed to and authorised by the Customer at the point of order.

5.2 Service Providers

We engage third-party service providers to assist in operating the Platform. These providers act as data processors under our instruction and are bound by confidentiality obligations and data processing agreements. They include:

  • Cloud infrastructure providers (server hosting, storage, and networking)
  • Email delivery providers
  • Authentication services
  • Monitoring and alerting services
  • Professional services providers (legal, audit, and compliance advisers)

We do not permit service providers to use personal data for their own purposes.

5.3 Government and Regulatory Authorities

We may disclose personal data to government bodies, regulators, courts, and law enforcement authorities where required to do so by applicable law, or where we believe in good faith that disclosure is necessary to:

  • Comply with a legal obligation or court order
  • Protect the rights, property, or safety of WMG, our customers, or the public
  • Detect, prevent, or address fraud, security breaches, or technical issues

5.4 Business Transfers

In the event of a merger, acquisition, reorganisation, or sale of all or substantially all of WMG's assets, personal data held by WMG may be transferred to the acquiring entity as part of that transaction. We will notify affected individuals in accordance with applicable law if such a transfer involves a material change in how their personal data is used.

5.5 Aggregated and Anonymised Data

We may share aggregated, anonymised, or de-identified data that cannot reasonably be used to identify individuals, including with government partners for trade analytics purposes. Such data is not personal data and is not subject to the restrictions in this Privacy Policy.

06

International Data Transfers

WMG is incorporated and headquartered in Singapore. The Platform is operated from Singapore, with cloud infrastructure hosted with providers operating in Singapore and, where required for performance, in other regions.

Where personal data is transferred outside Singapore to countries that may not offer the same level of data protection as Singapore, we ensure that appropriate safeguards are in place, including:

  • Standard contractual clauses or equivalent data transfer mechanisms recognised under the PDPA and applicable international frameworks
  • Adequacy decisions or binding corporate rules where applicable
  • Contractual obligations on recipients to maintain standards of protection comparable to those under the PDPA

Customers whose operations involve cross-border shipments should be aware that shipment-related data may need to be processed by customs authorities, carriers, and freight agents in the origin, transit, and destination jurisdictions of each shipment. This processing is an inherent feature of cross-border trade and is not within WMG's control. Customers are responsible for ensuring their own compliance with applicable data protection laws in relation to data they submit to the Platform.

07

Data Retention

We retain personal data for as long as necessary to fulfil the purposes for which it was collected, subject to our legal and contractual obligations. Our standard retention periods are:

  • Account and identity data: retained for the duration of the account and for 5 years following account closure, to comply with corporate record-keeping requirements
  • Shipment and transaction data: retained for 7 years from the date of the last transaction, to comply with trade, customs, and tax record-keeping requirements in applicable jurisdictions
  • Audit and security logs: retained for 3 years from the date of the logged event
  • Communications data: retained for 2 years from the date of the communication, unless the subject matter requires longer retention
  • Marketing consent records: retained for 5 years from the date of consent, or until consent is withdrawn, whichever is earlier

Where retention beyond these periods is required by law or regulation (for example, by customs authorities or tax authorities), we retain data for the period required by that law or regulation.

When personal data is no longer required, we delete or anonymise it in a manner appropriate to the sensitivity of the data.

08

Security

We implement technical and organisational measures designed to protect personal data against unauthorised access, disclosure, alteration, or destruction. These measures include:

  • Encryption of data in transit using TLS 1.2 or higher
  • Encryption of data at rest
  • Access controls limiting data access to authorised personnel on a need-to-know basis
  • Role-based access controls within the Platform
  • Multi-factor authentication for administrative access
  • Comprehensive audit logging of access to and modifications of personal data
  • Regular security assessments and penetration testing
  • Incident response procedures

No method of transmission or storage is completely secure. In the event of a data breach that is likely to result in significant harm to affected individuals, we will notify affected parties and relevant regulatory authorities as required by applicable law.

09

Cookies and Tracking

The Platform uses cookies and similar tracking technologies. The types of cookies we use are:

Essential Cookies

These cookies are necessary for the Platform to function. They include session authentication cookies and CSRF protection tokens. You cannot opt out of essential cookies without ceasing to use the Platform.

Functional Cookies

These cookies remember your preferences (such as theme settings) and improve your experience. They can be disabled without affecting core Platform functionality.

Analytics Cookies

We use limited analytics to understand how the Platform is used and to improve it. Where we use third-party analytics tools, these are configured to anonymise IP addresses and not to share data with third parties for advertising purposes. You may opt out of analytics cookies via your browser settings.

We do not use advertising cookies or third-party behavioural tracking on the Platform.

Your browser settings allow you to control which cookies are accepted. Restricting essential cookies may prevent some or all Platform functions from working correctly.

10

Your Rights

Subject to applicable law, you have the following rights in relation to your personal data:

Right to Access

You have the right to request a copy of the personal data we hold about you and information about how we use it.

Right to Correction

You have the right to request that we correct inaccurate or incomplete personal data about you.

Right to Withdrawal of Consent

Where we process your personal data on the basis of consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

Right to Data Portability

Where technically feasible and required by applicable law, you may request that we provide your personal data in a structured, commonly used, machine-readable format.

Right to Erasure

You may request that we delete your personal data in certain circumstances, subject to our legal obligations to retain data for regulatory, audit, and dispute-resolution purposes.

Right to Object

You may object to our processing of your personal data for direct marketing purposes at any time. You may also object to other processing based on legitimate interests, subject to our demonstrating compelling legitimate grounds for the processing.

Portal Users who are accessing the Platform as an employee or representative of a Customer organisation should note that certain rights (such as correction or deletion of shipment records) may be subject to the agreement between WMG and that Customer organisation.

To exercise any of these rights, please contact our Data Protection Officer at the address in Section 12. We will respond to requests within 30 days, or such other period as required by applicable law.

11

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or Platform features. We will provide notice of material changes by:

  • Publishing the updated Privacy Policy on this page with a revised Effective Date
  • Sending a notification to registered Portal Users via in-app notification or email, at least 30 days before the changes take effect for material changes

Your continued use of the Platform after the effective date of any updated Privacy Policy constitutes acceptance of the changes. If you do not agree to the updated Privacy Policy, you should discontinue use of the Platform and contact your organisation's administrator or WMG to discuss your options.

12

Contact and Data Protection Officer

WMG has appointed a Data Protection Officer (DPO) as required under the PDPA. If you have questions about this Privacy Policy, wish to exercise your rights, or wish to raise a concern about our handling of your personal data, please contact:

Data Protection Officer

KK Leong
Data Protection Officer
WMG Pte Ltd
60 Paya Lebar Rd, #06-20
Singapore 409051
admin@worldwavelink.com

We will acknowledge receipt of your request and aim to provide a substantive response within 30 days. Where a request is complex or numerous, we may extend this period by up to a further 30 days, and will notify you accordingly.

If you are not satisfied with our response, you have the right to lodge a complaint with the Personal Data Protection Commission of Singapore (pdpc.gov.sg) or the data protection authority in your jurisdiction.

13

Governing Law

This Privacy Policy is governed by and construed in accordance with the laws of the Republic of Singapore. Any dispute relating to this Privacy Policy shall be subject to the exclusive jurisdiction of the Singapore courts, without prejudice to your right to lodge a complaint with the relevant data protection authority in your jurisdiction.

World Wavelink is a product of WMG Pte Ltd, Singapore. Company Registration No. 200007060H.