Skip to content
Little Red Bot AI automation for Singapore SMEs

Privacy & PDPA.

The short version: we collect almost nothing, we say exactly what the little we collect is for, and you can see it, fix it, or delete it by asking. Written to comply with Singapore's Personal Data Protection Act 2012 — and to be readable.

Last updated 12 July 2026

What we collect

If you just read the site: nothing. No analytics scripts, no advertising pixels, no fingerprinting, no cookies set by us. Our web server keeps standard technical logs (IP address, requested page, timestamp) for security and capacity purposes only, rotated on a short schedule. To see whether the site is useful at all we read aggregate, cookieless signals only: Google Search Console (what queries found us), our email provider's list statistics once the newsletter is wired, and — if we ever add on-site counting — a self-hosted, cookieless counter, which we'd name here first. Still no third-party trackers, ever.

If you subscribe to the newsletter: your email address, the consent you gave, and the date you gave it. That's the whole record.

Why we collect it (purpose limitation, PDPA ss 18–20)

Your email is used for exactly one purpose, stated at the point you give it to us: sending you The Red Dot Report, our newsletter about AI tools, grants and workflow templates for Singapore SMEs. We don't sell, rent, or share the list, and we don't use it for anything else without asking you first.

Consent, and taking it back (ss 13–16)

We only add you to the list when you explicitly ask (unticked checkbox + subscribe action). Before regular sends begin we will confirm your address by email — no confirmation, no sends. You can withdraw consent at any time: every issue carries a one-click unsubscribe, or email us and we'll remove you within a week and say so.

Access and correction (ss 21–22)

Ask us what personal data we hold about you (it will be: your email address and your consent record) and we'll show you, correct it, or delete it. Requests go to the contact below; we respond within 30 days.

Protection and retention (ss 24–25)

The subscriber list lives in access-controlled storage on our own infrastructure today; when an email provider goes live (before issue #1 is sent), this line will name it. It is not exported to spreadsheets that wander around laptops. If you unsubscribe, we keep only the minimal suppression record needed to make sure we don't email you again. If we ever suffer a notifiable data breach, we'll follow the PDPA's breach-notification duty (s 26D) and tell you plainly what happened.

Third parties and links

Articles link to external sites (government pages, tool vendors). Some tool links are affiliate links or placeholders — see How we make money. External sites have their own privacy practices; a link is not an endorsement of them.

Who to talk to

Data questions, access/correction requests, or complaints: hello@aiautomations.sg (attention: Data Protection Officer). This mailbox is the accountability contact required by PDPA s 11. If we ever fail you, the Personal Data Protection Commission (pdpc.gov.sg) is the regulator.

Reference: Personal Data Protection Act 2012 (Singapore), especially ss 11–26D — consent, purpose limitation, notification, access & correction, protection, retention and breach notification. Read the Act at sso.agc.gov.sg/Act/PDPA2012.