Who is responsible

In this notice, “we”, “us” and “our” mean Evernex Academy Pte Ltd, a sister company to Evernet. Each company is a separate legal entity. This notice covers our company’s handling of personal data, not only visits to the EverX website. It does not cover Evernet’s independent business activities or other organisations’ own handling of personal data.

For privacy enquiries, requests or complaints, contact our data protection contact at dpo@evernex.com.sg. For programme enquiries, use hello@everx.com.sg.

You can also write to: Data Protection Contact, Evernex Academy Pte Ltd, 140 Paya Lebar Road, #06-22, Singapore 409015. Our general telephone number is +65 6513 0889; for a confidential privacy request, please use the privacy email or postal address directly.

Personal data means information about an individual who can be identified from that information, or from it together with other information we have or are likely to access. This notice applies subject to Singapore’s Personal Data Protection Act 2012 (PDPA), including its applicable exclusions and exceptions.

Who and what this notice covers

This notice applies to prospective and existing customers, corporate client representatives, learners and other programme participants, event attendees, website visitors, suppliers, partners, trainers, contractors, job applicants and employees, as applicable to their dealings with us. It covers personal data in electronic and paper records, whether received online, in person, by telephone, through correspondence or through an authorised third party.

Specific collection notices may supplement this notice for a programme, event, recruitment process or employment arrangement. We will explain relevant purposes and recipients at the appropriate point of collection. Describing a possible activity here does not mean that we currently carry it out or collect every category of information listed.

Personal data we may collect and how we receive it

Depending on your relationship with us and the relevant service, information may include:

We may receive information directly from you or, where authorised or otherwise permitted by law, from your employer or sponsor, an organising partner, a recruitment agency, a referee or a provider supporting our services. We collect only what is relevant to the notified purpose.

Please do not send NRIC numbers, passwords, identifiable customer records or confidential files in an initial enquiry. National identification numbers or copies of identity documents will only be requested where permitted by applicable law and guidance, with the purpose explained. If you provide another person’s details, ensure you are authorised to do so and that the relevant collection purposes have been communicated to them.

Why we collect, use and disclose personal data

Consent and purpose limitations

Where consent is required, we will seek it for the relevant purpose. We may also collect, use or disclose data where permitted or required by law. Sending a service enquiry, attending training or entering a contract does not automatically subscribe you to marketing or authorise unrelated uses of your personal data.

We limit collection, use and disclosure to purposes a reasonable person would consider appropriate in the circumstances. We do not require consent to uses beyond what is reasonable to provide the relevant product or service. Where a different purpose requires further notification or consent, we will address that before proceeding. Marketing communications will provide a way to opt out, and we will comply with applicable consent and Do Not Call requirements.

Training, employer-sponsored programmes and AI tools

For employer-sponsored programmes, we will explain any reporting arrangements, such as confirmation of attendance, completion or agreed learning outcomes, before collecting or sharing the relevant participant information. An employer’s sponsorship does not by itself authorise unrestricted access to a participant’s personal data.

Our approach is to use fictional, anonymised or suitably redacted information for learning exercises wherever practical. Participants should not enter personal data or confidential business information into an AI tool merely because it is used in a class. Where an engagement requires such information, the purpose, authorised users, relevant tool or provider and applicable handling arrangements must be established first. Participation does not by itself authorise use of your personal data to train a general-purpose AI model.

Where we process personal data solely on a corporate client’s behalf as a data intermediary, the client’s instructions, applicable service agreement and relevant data protection responsibilities also apply. We will coordinate requests concerning those records with the responsible client where appropriate; our own PDPA obligations remain applicable.

Photographs, recordings and testimonials

We will notify participants if a session or event is to be photographed or recorded and explain the intended use. Where consent is required, we will obtain it. Publicity uses, including identifiable testimonials, will be addressed separately from participation in a programme. Please tell the organiser or our data protection contact if you have concerns or wish to withdraw consent; we will explain the available arrangements and any practical or legal limitations.

Recruitment and employment

Applicant information is used to assess suitability, communicate about an application and conduct relevant checks where authorised or otherwise permitted by law. Employment-related information is used for the applicable employment and statutory purposes described above. Additional recruitment or employee notices will explain specific processing where needed. Any consent exception for evaluating an application or managing employment is not a blanket permission for unrelated use.

Who may receive personal data

Depending on the engagement, relevant recipients may include authorised staff and trainers; an employer or sponsor under the notified reporting arrangements; providers of communications, IT, learning delivery, event administration, accounting or payment services; professional advisers; and authorities where disclosure is required or permitted by law. Disclosure is limited to the relevant purpose and information, with appropriate arrangements for providers processing data on our behalf.

The sister-company relationship does not by itself authorise unrestricted sharing of personal data with Evernet. The general telephone number is shared with Evernet, so the person answering may receive details needed to route an enquiry. If a referral to Evernet’s services is proposed, we will explain it and obtain consent where required.

Website and digital services

This website currently has no online registration, payment or account facility. Where a service uses a separate platform, the relevant collection information will be provided for that service.

This site uses Vercel for hosting and Sanity for published content and assets. The homepage loads fonts from Google Fonts. These providers may process technical information when delivering their services. Our email provider processes correspondence that you send us.

The homepage includes a Google Maps embed that loads automatically when you open the page. This connects your browser to Google, which may receive technical information such as your IP address and browser details and may use cookies or similar technologies under its own privacy practices. Opening the directions link also takes you to Google Maps. See Google’s Privacy Policy for more information.

Cookies, sharing links and AI demonstrations

We have not added advertising pixels, visitor analytics scripts or newsletter tracking to this website. Infrastructure providers may use technical mechanisms necessary for delivery and security. Your browser settings allow you to manage cookies.

Sharing buttons are ordinary links. A third-party platform receives information when you choose to open it, subject to its own policies. Our animations and sample work are educational illustrations, not a live AI assistant: they do not submit your enquiry or other input to an AI model.

The “Copy a brief” feature copies a template to your device’s clipboard; it does not send an enquiry to us. Please review what you include before sending an email. For external services, see the privacy information from Vercel, Sanity and Google.

Protection, retention and overseas processing

Our policy is to apply reasonable security arrangements, retain personal data only while needed for business or legal purposes, and then delete it or remove identifying information. Where providers process personal data outside Singapore, we must ensure the applicable PDPA transfer requirements are met, including comparable protection. No internet service can promise absolute security.

Retention depends on the purpose and circumstances, including whether an enquiry remains active and whether records are needed for contractual, accounting, dispute-resolution or legal obligations. Withdrawal of consent does not necessarily require immediate deletion of records that must lawfully be retained.

Keeping information accurate

We will make reasonable efforts to keep personal data accurate and complete where it is likely to be used to make a decision affecting you or disclosed to another organisation. Please tell us if information you have provided changes or is incorrect.

Your requests and choices

You may contact us to request access to or correction of personal data, withdraw consent, or raise a concern. Requests are subject to applicable PDPA requirements and exceptions. We may ask for information reasonably needed to verify your identity and locate the relevant records; please do not send identity documents unless requested through an agreed channel.

Privacy concerns and complaints

Email dpo@evernex.com.sg with a description of your concern, relevant dates and a way to contact you. We will review the matter, seek clarification where necessary and communicate the outcome or next steps. You may also request information about our applicable data protection policies and complaints process through this channel.

If you remain concerned, you may contact the Personal Data Protection Commission. This does not limit any rights or remedies available under the PDPA.

Personal data breaches

If we become aware of a suspected personal data breach, we will assess it and take appropriate steps to contain and address it. Where notification is required under the PDPA, we will notify the PDPC as soon as practicable and no later than three calendar days after determining that the breach is notifiable. We will notify affected individuals as soon as practicable where required by law, subject to applicable exceptions.

Changes to this notice

We will update this notice when our business activities or data handling changes and show the revised date above. Where a new purpose requires notification or consent, we will address that separately rather than treating publication of an updated notice as consent.