Laaffic Legal & Privacy
Introduction
Clear rules are the foundation of reliable partnerships. Laaffic provides communications and marketing services globally. Our maintained legal, privacy, and security documents explain each party's responsibilities, how data is handled, and the boundaries for using our services.
Review our Terms of Service, Acceptable Use Policy, Service and Country-Specific Requirements, and Data Processing Addendum.
Learn how we process personal data, use cookies, manage subprocessors, and support individuals in exercising their data rights.
Learn about the technical and organisational measures we use to protect accounts, platforms, and data, and the scope of service availability commitments.
Review the rules for using Laaffic trademarks, copyrights, and website content, and how to submit an infringement notice.
Law enforcement, regulators, and parties making lawful civil requests can review our submission requirements.
Customer & Partner Agreements
The following documents jointly govern the commercial relationship, acceptable-use boundaries, and communications compliance responsibilities for business customers using Laaffic Services.
Laaffic Terms of Service
1. Scope and Acceptance
These Terms govern the use of Laaffic products and services by you or the business you represent and form an agreement with LAAFFIC PTE. LTD. By creating an account, signing an Order Form, clicking to accept, or using the Services, you confirm that you have authority to bind that business. A separately signed Order Form, master agreement, or addendum prevails over these Terms in the event of conflict.
2. Services and Accounts
Laaffic provides the Services described in the applicable Order and documentation. You must provide accurate and complete account and business information and keep it current. You are responsible for protecting accounts, passwords, API keys, and credentials and for all activity under your account. Notify Laaffic immediately of unauthorised access or use.
3. Customer Responsibilities
You are responsible for determining whether the Services are suitable for your business and for recipients, content, timing, numbers, and list sources. You must obtain legally required consent or another lawful basis, give required notices, identify the sender, provide effective opt-out methods, and promptly honour opt-outs. Your personnel, agents, contractors, and End Users must comply with these Terms, the AUP, and applicable law.
4. Fees, Taxes, and Payment
You must pay the fees stated in an Order, quote, or account. Unless an Order states otherwise, prepaid balances are not redeemable for cash and consumed fees are non-refundable. You are responsible for applicable taxes, carrier surcharges, and third-party network charges, other than taxes based on Laaffic's net income. Billing disputes must be raised in writing within 30 days after the invoice date, except where law provides otherwise.
5. Lawful Use and Abuse Prevention
You may not use the Services for fraudulent, phishing, malicious, harmful, infringing, harassing, or unsolicited communications, or evade identity, rate, filtering, billing, or security controls. Laaffic may investigate suspected unlawful activity, fraud, spam, abnormal traffic, or security risk and may reasonably restrict traffic, suspend Services, request evidence, or terminate accounts.
6. Suspension
We may suspend affected Services if we reasonably believe your use breaches these Terms or the AUP, creates fraudulent or abnormal traffic, threatens security or stability, violates law or carrier rules, involves overdue amounts, or relies on inaccurate account information. Except for urgent action or where notice is prohibited, we will use reasonable efforts to notify you and explain restoration conditions.
7. Customer Data
You retain rights in Customer Data. You authorise Laaffic and its subprocessors to process Customer Data only to provide, secure, maintain, and support the Services, comply with law, and as otherwise agreed in writing. You warrant that required notices, consents, permissions, and authorisations have been obtained. The DPA also applies to personal data processing.
8. Confidentiality
The receiving party may use Confidential Information only to perform the Agreement and disclose it only to personnel, Affiliates, advisers, and contractors with a need to know and confidentiality duties. Confidential Information excludes information demonstrably known lawfully, public without breach, lawfully received from an authorised third party, or independently developed. For compelled disclosure, the receiving party will give advance notice where lawful and reasonable assistance.
9. Intellectual Property
Laaffic and its licensors retain all rights in the Services, software, APIs, documentation, marks, and improvements. You retain rights in Customer Data, Customer Applications, and your content. No IP rights are granted except as necessary to use the Services. Neither party may publicly use the other's name or marks or imply endorsement without written consent.
10. Third-Party Services and Networks
The Services may rely on carriers, aggregators, networks, devices, app stores, and platforms such as WhatsApp, which may apply separate rules and technical limits. Laaffic does not control public communications networks or recipient devices and does not guarantee that every communication will be delivered, delivered on time, opened, or produce a particular result.
11. Service Changes
We may improve, update, or modify the Services. If a change materially reduces a core function of a purchased Service, we will give reasonable advance notice, except for changes required immediately for security, law, or urgent third-party network requirements.
12. Warranties and Disclaimers
Laaffic will provide the Services with reasonable professional skill and care. Except as expressly stated, the Services are provided “as is” and “as available.” To the maximum extent permitted by law, implied warranties of merchantability, fitness for purpose, non-infringement, or successful communication are disclaimed. Non-excludable statutory rights remain unaffected.
13. Limitation of Liability
To the maximum extent permitted by law, neither party is liable for indirect, incidental, special, punitive, or consequential loss, or loss of profit, revenue, goodwill, opportunity, or data, under any theory of liability, even if advised of the possibility.
14. Indemnity
You will defend and indemnify Laaffic, its Affiliates, directors, officers, and employees against third-party claims arising from Customer Data, communications content, missing consent, breach of applicable law, or End User conduct. Laaffic will promptly notify you and allow reasonable control of the defence and settlement. A settlement admitting Laaffic liability or imposing non-monetary obligations requires Laaffic's prior written consent.
15. Term and Termination
These Terms begin when accepted and continue until all Orders and accounts end. Either party may terminate an affected Order for a material breach not cured within 30 days after written notice; an incurable material breach may be terminated immediately. Termination does not affect accrued rights or payment obligations.
16. Data After Termination
After termination, you may export available Customer Data during the account's export period. Laaffic will then delete or anonymise Customer Data under the DPA and law, except for legally required retention, dispute needs, or protected backup rotation.
17. Compliance
Each party will comply with applicable anti-bribery, AML, sanctions, export control, data protection, and communications laws. You may not serve sanctioned parties or evade carrier registration, identity, or content approval requirements.
18. Governing Law and Disputes
These Terms are governed by Singapore law, without its conflict-of-laws rules. The parties will first attempt in good faith to resolve disputes. If unresolved within 30 days after negotiations begin, either party may bring proceedings in the courts of Singapore, subject to mandatory law.
19. General
Neither party is liable for delay caused by events beyond reasonable control, except payment obligations. Neither party may assign the Agreement without consent, except to a successor in a merger, reorganisation, or sale of substantially all relevant assets. These Terms and incorporated documents are the entire agreement for the Services. If a provision is invalid, the remainder continues.
Acceptable Use Policy
1. Core Principle
Use the Services only lawfully, transparently, and with respect for recipient choice. You are responsible for accounts, personnel, agents, contractors, and End Users.
2. Prohibited Content and Activity
Do not use the Services for fraud, phishing, identity theft, malware, unlawful gambling, trafficking, child sexual abuse material, threats, harassment, hate, privacy violations, infringement, or other unlawful conduct. Do not impersonate others, falsify sender identity, or deliberately mislead recipients.
3. Unsolicited Communications
Before marketing, obtain legally required consent or another lawful basis and retain evidence. Clearly identify the sender and provide an effective opt-out. Promptly honour opt-outs, complaints, and suppression lists.
4. Platform Integrity
Do not access systems without authorisation, scan or exploit vulnerabilities, conduct denial-of-service attacks, distribute malicious code, share credentials, or bypass rate, filtering, verification, billing, or security controls.
5. Regulated Uses
Finance, gambling, health, political, cryptoasset, lending, and other regulated uses are allowed only where lawful, licensed, and compliant with Laaffic and carrier requirements. We may require licences, consent records, business-model details, templates, and source-of-funds evidence.
6. Investigation and Enforcement
We may investigate complaints, anomalous traffic, carrier notices, and reasonable risk signals. You must cooperate and provide evidence. We may limit traffic, reject content, suspend or terminate Services, and report to carriers or authorities where required.
7. Reporting
Report suspected abuse to legal@laaffic.com with the subject “Abuse Report” and provide numbers, timestamps, content, screenshots, and other available evidence.
8. Updates
We may update this Policy for law, carrier rules, security threats, or new abuse patterns. Material changes will be posted in the Legal Center with reasonable notice.
Service and Country-Specific Requirements
1. General
Customers must comply with laws, regulation, industry codes, carrier rules, and third-party platform policies applicable where the sender, recipient, and communication are located. Account or template review by Laaffic is not legal approval.
2. SMS, MMS, and RCS
Use authorised numbers, sender IDs, short codes, or long codes and complete required registration. Marketing messages must identify the sender and include required opt-out information. Do not disguise content to evade review. Carriers may filter, delay, or reject messages.
3. Voice, SIP, and AI Voice
Use accurate, authorised caller IDs and comply with autodialling, telemarketing, recording, quiet-hour, and do-not-call rules. No harassment, spoofing, or unauthorised recording. Unless expressly stated, the Services are not for emergency calling.
4. WhatsApp
WhatsApp Services are also subject to applicable Meta and WhatsApp terms, business policies, templates, and account restrictions. Customers are responsible for valid recipient consent and opt-outs. Third-party platforms may reject templates, restrict accounts, or change rules.
5. OTP and Authentication
Authentication messages are for lawful, authorised verification, security notice, or account recovery only. No OTP bombing, credential phishing, number enumeration, or unauthorised account access.
6. Contact Centre
Customers are responsible for agent access, recording notice, quality review, retention, and local employment and monitoring law. Provide required notice before transfers and minimise disclosure.
7. Advertising and Performance Marketing
Creative, landing pages, tracking, audience sources, and conversion practices must comply with platform rules and law. Do not promote unlawful products, false returns, deceptive financial opportunities, or prohibited content.
8. Regional Restrictions
Countries may impose additional sender ID, template, registration, localisation, consent, quiet-hour, and industry rules. Use of a region means acceptance of applicable requirements shown in the account, Order, or Legal Center.
Privacy & Data Protection
This section explains how Laaffic handles personal data, uses website technologies, processes data for business customers, and manages subprocessors. Personal data refers to any information that directly identifies you, or that indirectly identifies or relates to you.
Privacy Statement
1. Scope
LAAFFIC PTE. LTD., together with its affiliates ("Laaffic" or "we"), is a Singapore-based cloud communications service provider that delivers SMS, Voice, WhatsApp, RCS, MMS, contact centre, and authentication solutions to business customers through our products, platforms, and services.
Laaffic takes the protection of personal data seriously. We also believe that our data practices should be explained clearly and in a way that people can understand. This Privacy Policy (“This Policy”) describes how we collect, use, disclose, retain, and protect personal data when you visit a Laaffic website, register for or use our products and services, contact us, attend an event, or otherwise interact with us. It also explains the choices and rights that may be available to you.
This Policy applies where Laaffic acts as a controller and determines why and how personal data is processed, including in connection with our websites, account and customer relationship management, sales enquiries, marketing activities, and corporate operations.
When a customer uses Laaffic's SMS, Voice, WhatsApp, RCS, MMS, contact centre, authentication, or other communications services to process its end users' data, the customer generally determines the purposes and means of that processing, and Laaffic provides the services on the customer's instructions. In those circumstances, the customer is generally the controller and Laaffic generally acts as a processor or data intermediary. Such instructions are set out in the customer agreement, Data Processing Agreement (DPA), service-specific terms, or the customer's use or configuration of product features. This Policy does not replace the privacy notice that a customer must provide to its end users, and it does not change the allocation of responsibilities in our contract or data processing agreement.
If you are an end user of a Laaffic customer, the controller-related provisions of this Policy do not apply to you. Your personal information is controlled by the enterprise customer with whom you directly interact. Please refer to that customer's privacy policy first. Laaffic will assist our customer with your request as required by our contract and applicable law.
This Policy does not apply to independently operated third-party websites, products, or services, or to job applicants, for whom a separate notice may be provided.
2. Personal Data We Process
The information we process depends on your relationship with Laaffic and the services you use, and may include the following:
- Information you voluntarily provide to us
- Contact and professional information: name, company, job title, industry, business email address, phone number, country or region of residence, and social media details;
- Account information: username, account ID, login credentials and security verification data;
- Business and transaction information: consultation records, product preferences, contract and order details, billing and payment histories, purchase history, and bank account information. Full payment card information shall in principle be processed directly by authorized payment service providers;
- Compliance and qualification verification information: company registration documents, authorized representative details, identity credentials or operational purpose certification materials required for activating specific communication services, complying with operator regulations, fraud prevention, customer identity verification or statutory requirements;
- Customer support and feedback content: service tickets, emails, online chats, call recordings, troubleshooting logs, questionnaires and feedback submissions;
- Event and marketing information: registration data, event participation records, subscription preferences and marketing setting configurations.
- Information automatically generated or collected by the system when you access the website and services
- Device and network information: IP address, browser and operating system type, device model, language, time zone and approximate geographic location;
- Website browsing behavior data: pages visited, click records, referral pages, search records, browsing duration, session information and error logs;
- Account and service usage history: login activities, configuration settings, API requests, operation logs, usage volume, service status and error details;
- Communication metadata: sender and recipient identifiers, transmission routing, timestamps, communication type, call duration, send/delivery/failure status, as well as information related to unsubscription and complaints;
- Data generated by cookies and similar technologies, see Clause 8 for detailed provisions.
- Materials transmitted or uploaded by customers via the services
Such materials may include phone numbers, communication content, templates, audio recordings or video files, verification requests, communication records, and other data uploaded at the customer’s discretion. The actual scope is determined by the products used, system configurations and operational instructions selected by the customer.
Such data is not actively collected by Laaffic, but is provided by enterprise customers or generated through customers' use of the services. Laaffic processes such data solely to fulfill the communication services instructed by customers, and only to the extent technically and operationally necessary. Laaffic does not use such data for its own marketing, profiling, sale, or sharing.
Customers shall ensure they possess valid legal grounds for collecting, using and submitting the aforementioned data to Laaffic, and fulfill statutory obligations of notification and right of choice toward end users in accordance with applicable laws.
- Information obtained from third parties
Sources may include affiliated enterprises, channel partners, event organizers, public information platforms, identity verification and anti-fraud service providers, payment service vendors, telecommunications operators, data aggregators and other communication service providers.
Please only submit information necessary to fulfill relevant purposes. Unless required for service activation, identity verification, payment processing or explicitly stipulated by law, do not proactively submit identity documents, financial account details, health records, biometric data or other sensitive personal information via general consultation forms, emails or online chats.
| Role | Types of Data Processed |
|---|---|
| Controller | Information you voluntarily provide to us: contact and professional information, account information, business and transaction information, compliance and qualification information, customer support and feedback, event and marketing information |
| Information we automatically generate or collect when you use our websites and services: device and network information, website activity information, account and service usage information, communication metadata, information generated by cookies and similar technologies | |
| Information from third parties (where Laaffic determines the purposes and means of processing such information): from affiliates, channel or business partners, event organizers, public sources, identity and anti-fraud service providers, payment service providers, telecommunications operators, aggregators and other communication service providers | |
| Processor | Data submitted or transmitted by customers through the services: phone numbers, communication content, templates, recordings or media files, authentication requests, communication logs and other data the customer chooses to upload |
3. How and Why We Use Personal Data
We only process necessary personal data for legitimate, specific and business-related purposes, including:
- Providing, configuring, routing, maintaining and supporting products and services;
- Creating and managing accounts, fulfilling contracts, orders, billing, settlement and customer relationship management;
- Handling sales inquiries, demos, trials, event registrations and cooperation requests;
- Verifying identities or enterprise qualifications to meet requirements from operators, communication ecosystem partners and legal compliance obligations;
- Safeguarding the security of accounts, networks, platforms and communications, as well as detecting, investigating and preventing fraud, spam, abuse and unauthorized access;
- Monitoring service performance, troubleshooting faults, analyzing usage patterns, and improving products, services and user experience;
- Sending mandatory notifications regarding services, transactions, security or policy updates;
- Sending marketing communications where consent has been obtained or permitted by applicable laws, and managing your subscriptions and preferences;
- Complying with valid requirements from laws, regulatory authorities, courts, law enforcement agencies or government bodies, asserting legal rights and resolving disputes;
- Conducting corporate audits, financial operations, governance, business continuity planning, mergers and acquisitions, or other lawful business activities.
Where applicable laws require us to specify the legal bases for processing, we will rely on one or more of the following depending on the circumstances: performance of a contract or pre-contractual measures taken at your request; your consent; compliance with legal obligations; protection of vital interests of you or another individual; and legitimate interests pursued by us or a third party, provided such interests do not override your rights and freedoms in an undue manner. You may withdraw your consent at any time, but such withdrawal shall not affect the lawfulness of processing carried out prior to the withdrawal based on your consent.
4. How We Disclose Personal Data
Selling personal data is not part of our business model. We disclose personal data only as needed to provide services, operate our business, or comply with law, including to the following categories of recipients:
- Communications ecosystem providers, such as mobile network operators, aggregators, number or voice providers, OTT communications platforms, and other providers needed to route and deliver communications;
- Service providers, such as cloud hosting, content delivery, security, identity verification, payment, customer support, analytics, marketing, audit, and professional advisory providers;
- Affiliates and authorised personnel, where needed for coordinated operations, customer support, finance, compliance, and security, subject to appropriate access controls and confidentiality obligations;
- Customers and their authorised parties, as needed to provide services, reports, or support in accordance with customer configurations and instructions;
- Transaction parties, including actual or prospective parties and advisers involved in a merger, acquisition, financing, restructuring, asset transfer, or similar transaction, subject to confidentiality and applicable law; and
- Public authorities or other necessary recipients, where required by law or valid legal process, or where necessary to protect rights and safety, investigate fraud, or prevent abuse.
Where a vendor processes personal data on our behalf, we apply contractual, confidentiality, security, and access restrictions appropriate to the risk. Certain communications ecosystem providers may independently determine how they process particular metadata for their own legal obligations, network operations, or billing.
We do not sell mobile numbers or SMS consent information submitted through our website contact forms, and we do not provide that information to third parties for their own marketing purposes unless you separately and expressly agree.
5. International Transfers
Laaffic is headquartered in Singapore and operates across multiple countries and regions. To provide global communications, customer support, and corporate operations, personal data may be accessed, processed, or stored outside your country or region, where data protection laws may differ.
For international transfers, we use safeguards appropriate to applicable law and transfer risk. These may include data protection terms with recipients, access restrictions, security measures, and, where applicable, recognised standard contractual clauses or other lawful transfer mechanisms. For transfers subject to Singapore's Personal Data Protection Act, we take steps designed to ensure that recipients provide a standard of protection comparable to that under the Act. Data location and transfer arrangements for a particular service may depend on the product, routing, carrier network, and customer configuration and may be further addressed in a contract or data processing agreement.
6. Information Security
We use reasonable technical and organisational measures appropriate to the nature, context, and risk of processing to protect personal data from unauthorised access, collection, use, disclosure, copying, modification, loss, or disposal. These measures may include access controls, authentication, encryption in transit, logging and monitoring, vulnerability and incident management, backups, and employee confidentiality requirements.
No network, system, or method of transmission can be guaranteed to be completely secure. If a personal data breach occurs, we will investigate, contain its impact, and notify relevant customers, individuals, and regulators where required by applicable law.
7. Retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, to perform our contracts, comply with legal and carrier requirements, resolve disputes, and protect legitimate interests. In setting retention periods, we consider the amount, nature, and sensitivity of the data, the potential risk of unauthorised use or disclosure, the processing purpose, whether that purpose can be achieved by other means, and applicable legal, accounting, tax, and contractual requirements.
Data processed by customers through the Services is retained according to customer configurations, applicable product rules, and our contract or data processing agreement. At the end of the applicable period, we delete, anonymise, or securely isolate the data in accordance with our processes. Data in backups may remain until the relevant backup cycle expires, during which time it remains protected and is not used for other purposes.
8. Cookies and Similar Technologies
We may use cookies, pixels, web beacons, local storage, and similar technologies to:
- operate and secure our websites, logins, and forms;
- remember language, region, and other preferences;
- understand website use and improve performance and experience; and
- measure marketing and provide relevant content or advertising where we have consent or another basis permitted by law.
Except for strictly necessary technologies, we obtain your choice or consent before use where required by law. You can manage non-essential technologies through our website cookie settings tool or your browser settings. Rejecting some technologies may affect certain features. Cookie names, providers, purposes, and durations are displayed in the website cookie settings.
9. Your Choices and Rights
Depending on your location and applicable law, you may have the right to:
- receive information about how we process your personal data;
- request access to or a copy of your personal data;
- correct inaccurate or incomplete data;
- request deletion;
- restrict or object to certain processing, including direct marketing;
- withdraw consent;
- request data portability where applicable;
- challenge significant decisions based solely on automated processing; and
- complain to a data protection authority with jurisdiction.
You may stop receiving marketing emails by using the unsubscribe link in the message. Opting out of marketing does not prevent us from sending necessary service, security, transaction, or legal notices.
To exercise a right, email legal@laaffic.com and identify your name, relationship with Laaffic, the request, and the information reasonably needed to locate relevant records. To protect personal data, we may verify your identity and authority. We will respond within the time required by applicable law. Some rights are subject to legal exceptions.
If Laaffic processes your data only on behalf of a customer, we will generally refer or route your request to that customer.
10. Children's Privacy
Our products, services, and websites are intended for business customers and professionals. They are not directed to children and are not intended for children to register for or use independently. We do not knowingly collect personal data directly through our website from a child below the applicable legal age in their location. If you believe a child has provided personal data to us, contact legal@laaffic.com so that we can investigate and take appropriate action.
Customers must not use the Laaffic Services to collect or process children's data unlawfully and are responsible for obtaining any required parent or guardian authorisation.
11. Third-Party Links and Services
Our websites or services may link to or connect with third-party websites, platforms, or services. Where a third party independently determines its processing, its own privacy policy governs. We encourage you to review that policy before providing personal data.
12. Changes to This Policy
We may update this Policy to reflect changes in our products, business, technology, or law. We will publish the revised version on this page and update the “Last updated” date. If a change materially affects your rights or how we process personal data, we will provide advance or timely notice through a prominent website notice, email, or another appropriate method.
Contact and Complaints
For questions, requests, or complaints about this Policy or Laaffic's privacy practices, contact:
LAAFFIC PTE. LTD.
Privacy email: legal@laaffic.com
Address: 108 Keng Lee Road, #03-01, Keng Lee View, Singapore 219268
We will review your request carefully and respond within the period required by applicable law. If you are not satisfied with our response, you may complain to a data protection authority with jurisdiction or seek another remedy available under applicable law.
Last updated: 26 August 2026
Cookie Policy
1. Technologie
Laaffic websites may use cookies, pixels, web beacons, local storage, and similar technologies to operate and secure websites, remember preferences, analyse performance, and measure marketing where required consent is obtained.
2. Categories
Strictly necessary cookies support login, security, load balancing, and forms. Functional cookies remember language and region. Analytics cookies help us understand website use. Advertising cookies measure marketing or provide relevant content and are used only where permitted or consented to.
3. Third Parties
Some technologies are set by providers of analytics, content, support, or advertising. They act under contract for us or under their own privacy policies where they independently determine processing.
4. Choices
Manage non-essential cookies through website settings or your browser. Choices are browser- and device-specific and may reset when cookies are cleared. Rejecting non-essential cookies does not prevent basic browsing but may limit features.
5. Retention
Session cookies expire when a browser session ends. Persistent cookies expire at their stated duration or when deleted. Names, providers, purposes, and durations appear in website cookie settings.
6. Contact
Questions: legal@laaffic.com.
Data Processing Addendum
This DPA forms part of the Services agreement between Customer and LAAFFIC PTE. LTD. and applies when Laaffic processes Customer Personal Data on Customer's behalf.
1. Roles and Instructions
Customer is a controller or processor acting for a controller; Laaffic is a processor or subprocessor. Laaffic processes Customer Personal Data only under the Agreement, Orders, configurations, and documented instructions, unless law requires otherwise.
2. Customer Duties
Customer is responsible for lawfulness, accuracy, necessity, notice, consent, and other legal basis. A Customer acting as processor confirms that its controller authorised Laaffic as subprocessor.
3. Processing Details
Processing supports provision, protection, maintenance, and support of purchased Services for the Agreement term and lawful retention period. Data may include contact details, telephone numbers, communications content, authentication data, metadata, device/network data, and other submitted data. Data subjects may include Customer personnel, contacts, End Users, and recipients.
4. Confidentiality
Authorised personnel are subject to confidentiality and receive access only as needed
5. Security
Laaffic will maintain risk-appropriate measures including access control, authentication, transmission protection, logging, monitoring, vulnerability management, backups, incident response, and workforce security.
6. Subprocessors
Customer generally authorises subprocessors. Laaffic will impose equivalent protection and remains responsible for their processing on its behalf. Changes will be posted or notified. Customer may object in writing on reasonable data-protection grounds.
7. Transfers
Laaffic will use lawful transfer safeguards, including contractual protection, access restrictions, and standard contractual clauses where applicable. Customer authorises transfers necessary for global communications.
8. Data Subject Requests
Laaffic will reasonably assist Customer with access, correction, deletion, restriction, objection, and portability. Direct requests may be referred to Customer.
9. Security Incidents
After confirming an incident affecting Customer Personal Data, Laaffic will notify Customer without undue delay and provide available details on nature, effects, mitigation, and contacts, and reasonably assist required notification.
10. Assessments and Consultation
Where information is otherwise unavailable, Laaffic will reasonably assist with impact assessments and prior regulatory consultation.
11. Audit Information
Laaffic will provide reasonably necessary compliance information. If insufficient, Customer may conduct one scoped audit annually on notice, under confidentiality, without operational disruption, and at its cost, except for regulator requirements or a material incident.
12. Return and Deletion
After termination, Laaffic will return or delete Customer Personal Data at Customer's choice, except for legal retention or protected backup rotation. Retained data will not be used for another purpose.
13. Conflict
This DPA prevails over the Terms for personal data processing. The Terms govern other matters.
Subprocessors
Laaffic uses assessed providers for infrastructure, communications routing, security, support, analytics, payment, and necessary operations. Subprocessors processing Customer Personal Data for Laaffic are subject to appropriate confidentiality, security, and data protection duties. The list identifies legal name, function, processing location, and applicable products. Email legal@laaffic.com to subscribe to changes. A Customer may object on reasonable data-protection grounds within 10 days after notice. The parties will seek a solution in good faith. If unresolved and inseparable from the affected Service, Customer may discontinue and terminate that affected Service.
Privacy Rights Requests
Depending on applicable law, you may request access, correction, or deletion, withdraw consent, object to direct marketing, restrict certain processing, or request portability where applicable. Email legal@laaffic.com with the subject “Privacy Request” and provide your name, relationship with Laaffic, the specific request, and information needed to locate relevant records. We may verify identity and authority to protect personal data. If Laaffic processes your information only for a business customer, we will refer or route the request to that customer.
Additional Notice for California Residents
This section applies to you if you are a resident of California. References to “Personal Data” shall include “personal information” and “sensitive personal information,” as these terms are defined under the California Consumer Privacy Act (“CCPA”) as amended by the CPRA.
In the preceding 12 months, we collected the following categories of Personal Data and sensitive personal information:
- Identifiers: such as real name, address, unique personal identifiers, email address.
- Personal information categories listed in the California Customer Records statute: such as name, telephone number, email address, company name, job title, and financial information. In the provision of our services we may also process (a) the content of communications, such as message bodies, call recordings (if applicable), and images or files sent via our platform; and (b) service usage data, including call detail records, from/to phone numbers, device location data (inferred from IP), and IP addresses.
- Commercial information: such as records of products or services purchased, obtained, or considered.
- Internet or other similar network activity information: browsing history, search history, and other information regarding your interaction with our sites, applications, or advertisements.
- Inferences drawn from other Personal Data: such as inferences reflecting preferences, characteristics, behavior, or attitudes.
- Geolocation data: we may gain access to the approximate location of the device or equipment you are using if you interact with us online or use our services (e.g., through IP address).
- Sensory data: such as audio, electronic, or similar information when you contact us (e.g., call recordings with our support team, if any).
The categories of sources from which we collect your Personal Data, the recipients of your Personal Data, and the specific business or commercial purposes for which we collect and disclose your Personal Data are described in the main body of our Privacy Policy (see “How We Use Your Personal Data” and accompanying tables). The criteria we use to determine how long to retain your Personal Data are also described in our Privacy Policy.
We do not “sell” or “share” (as those terms are defined under the CCPA) your Personal Data with third parties for crosscontext behavioral advertising or any other purpose that constitutes a “sale” or “share”. However, we may disclose Personal Data to our telecommunications partners, service providers, and affiliates solely to deliver the services you request. We do not have actual knowledge that we have sold or shared Personal Data of individuals under 16 years of age.
Your Privacy Rights
In addition to the rights described in the “Your Rights and Choices About Your Data” section of our Privacy Policy, California law provides you with the following rights, subject to certain exceptions:
- Right to Know: You have the right to request that we disclose the categories and specific pieces of Personal Data we have collected about you, the categories of sources, the business purpose, and the categories of third parties with whom we share it.
- Right to Delete: You have the right to request deletion of your Personal Data, subject to legal exceptions.
- Right to Correct: You have the right to request correction of inaccurate Personal Data.
- Right to OptOut: You have the right to opt out of the “sale” or “sharing” of your Personal Data (though we do not engage in such activities).
- Right to Limit Use of Sensitive Personal Data: You have the right to limit our use of your sensitive Personal Data to that which is necessary to provide the services, if applicable.
- Right to NonDiscrimination: We will not discriminate against you for exercising any of these rights.
To exercise any of these rights, please submit your request through one of the following methods:
- Email us at legal@laaffic.com; or
- Write to us at 108 Keng Lee Road, #03-01, Keng Lee View, Singapore 219268.
For requests submitted via an authorized agent, we may require written proof of your authorization and verify both your and the agent’s identity.
We will respond to verifiable requests within the timeframes required by California law. If we cannot fulfill your request, we will explain the reason. If you wish to appeal a decision, you may contact us using the same contact information above.
Security & Reliability
Security Overview
Laaffic uses reasonable technical and organisational measures appropriate to the nature, context, and risk of processing to protect accounts, platforms, and data against unauthorised access, use, disclosure, alteration, loss, or destruction.
Access security: account permissions, authentication, least privilege, and access reviews restrict system and data access. Customers are responsible for passwords, API keys, and endpoint environments.
Data protection: appropriate transmission protection, logging, monitoring, backup, and disposal measures are used, and unnecessary access to production data is restricted.
System security: secure development, change management, vulnerability and patch management, anomaly monitoring, and vendor management support the security of the Services.
Incident response: after confirming an incident involving Customer Data, we investigate, contain, and remediate its effects and notify relevant customers or authorities as required by the DPA and applicable law.
Service Reliability
Laaffic monitors service operation and takes reasonable measures to maintain availability and recoverability. Communications depend on carriers, aggregators, the internet, third-party platforms, and recipient devices; successful submission does not guarantee final delivery, opening, or conversion. Specific availability commitments, support levels, and service credits apply only where expressly stated in an Order or SLA.
Security concerns may be sent to legal@laaffic.com with the subject “Security Report.” Do not access, test, or disrupt Laaffic systems without authorisation.
Intellectual Property
Laaffic names, logos, marks, website design, software, APIs, documentation, graphics, images, audiovisual material, and original content belong to Laaffic or their owners. Except as permitted by law or in writing, do not copy, modify, distribute, sell, mirror, reverse engineer, or use them to build a competing product.
Do not use Laaffic branding to imply partnership, certification, sponsorship, or endorsement; modify logos; or register confusing marks, domains, or social names without permission. Necessary, non-prominent nominative use to accurately describe compatibility or a factual relationship is allowed.
Send infringement notices to legal@laaffic.com with subject “IP Notice,” identifying the owner, protected work, location, contact details, good-faith statement, and authority. We may request information, remove or restrict content, and notify the relevant Customer after review.
Government & Legal Requests
These Guidelines are for law enforcement, regulators, court-authorised persons, and lawful civil requesters. Do not use this process for support or privacy rights requests.
Send requests to legal@laaffic.com from a verifiable official or professional domain. Identify the requester, legal authority, jurisdiction, enforceable process, target account or number, record categories, timeframe, and response contact.
Laaffic discloses data only where applicable law requires and the request is valid, binding, and within proper jurisdiction. We may reject or seek narrowing of requests that are overbroad, vague, unverifiable, or unsupported. International requests may require judicial-assistance or recognised court procedures.
Where lawful and non-prejudicial, we will use reasonable efforts to notify the affected Customer. A prohibition on notice should cite express legal authority. Emergency disclosure is limited to preventing imminent death or serious physical injury and requires sufficient verification.
Preservation requests must be specific, lawful, and time-limited. Laaffic preserves only identifiable data that exists when the request is received and does not create records that do not exist. Submission does not guarantee that data is held or waive any rights or objections.