Introduction
Persistence AI PTE. LTD., together with its subsidiaries and affiliates worldwide (collectively, “Persistence,” “we,” “us,” or “our”), provides AI-powered software, technology and software-as-a-service solutions through our websites, applications, platforms and related products and services, including www.persistence.dev (collectively, the “Services”).
Persistence AI PTE. LTD. is incorporated in Singapore and is the parent company of Utkarsh AI Labs Private Limited, an entity incorporated in India. Depending on your location, the nature of your relationship with us and the particular processing activity involved, Persistence AI PTE. LTD., Utkarsh AI Labs Private Limited, or another applicable Persistence group entity may be responsible for processing your Personal Data.
We are committed to respecting your privacy and protecting the Personal Data entrusted to us. This Privacy Policy (the “Policy”) explains how we collect, use, disclose, retain, transfer and protect Personal Data through our websites, Services, business operations and other interactions with you.
This Policy applies to individuals who visit our websites, create or use an account, use our Services, communicate with us, interact with us through marketing or business development activities, apply for employment, visit our premises, provide goods or services to us, or otherwise interact with Persistence.
Our Role When Processing Customer Data Persistence provides Services primarily to businesses and organizations. Where we process Personal Data on behalf of a customer in connection with the customer's use of our Services, Persistence may act as a processor, Data Processor, service provider, contractor or equivalent role under applicable data protection law.
In those circumstances, the customer may act as the controller, Data Fiduciary, business or equivalent entity, and our processing of the Personal Data will be governed primarily by the applicable customer agreement, Data Processing Agreement (“DPA”), Business Associate Agreement (“BAA”), where applicable, and the customer's documented instructions.
If your Personal Data is processed by Persistence on behalf of one of our customers, you may need to contact that customer directly to exercise your privacy rights. Persistence will assist its customers with such requests where required by applicable law or contract.
We encourage you to read this Policy together with any additional privacy notice, contractual terms, consent notice, product-specific disclosure, cookie notice or other information provided when Personal Data is collected or processed.
For purposes of this Policy, “Personal Data” or “Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or can reasonably be used to identify an individual, directly or indirectly, as determined under applicable law. Terminology and scope may differ depending on the jurisdiction.
This Policy is intended to apply globally. Additional provisions may apply depending on your location and the laws applicable to the processing of your Personal Data, including laws in Singapore, India, the European Economic Area (“EEA”), the United Kingdom (“UK”) and applicable jurisdictions in the United States.
1PERSONAL DATA WE COLLECT
The Personal Data we collect depends on how you interact with Persistence, the Services you use, the information provided to us by our customers and the applicable legal requirements.
Customers and Users of Our Services If you are a customer, prospective customer or authorized user of our Services, we may collect:
name; business or work email address; telephone number, where provided; company or organization; job title or professional role; account and user identifiers; customer identifiers; login and authentication information; device identifiers; IP address; subscription and account information; communications with us; and information relating to your access to and use of the Services. We may also collect technical and usage information such as logs, telemetry, diagnostic information, system information, security events, product interactions, features accessed, performance information and other information reasonably necessary to operate, secure, maintain and improve the Services.
End Users of Our Customers Where our Services are provided through one of our business customers, we may process Personal Data relating to employees, contractors, customers, users or other individuals of that customer.
Depending on the Services and the customer's use of them, such information may include:
name; business or other contact information; user or account identifiers; IP address; device and browser information; usage information; logs and telemetry; communications, content or information submitted to the Services; audio, recordings or other media, where applicable to the Service; and other information generated through or submitted to the Services. The nature and scope of this processing depends on the Services selected by the customer and the customer's instructions to Persistence.
Where Persistence processes such information solely on behalf of a customer, the customer is generally responsible for determining the purposes and means of processing, providing appropriate privacy notices, establishing an appropriate legal basis and responding to privacy-rights requests, subject to applicable law.
Account Information If you create an account, we may collect your:
name; email address; company or organization; job title; account credentials; authentication information; and other information necessary to create, secure and administer the account. Subscription, Billing and Transaction Information If you purchase or subscribe to our Services, we may collect information relating to your subscription, purchases, billing arrangements, invoices and transaction history.
Payment card information may be processed directly by third-party payment-service providers. Depending on the payment arrangement, Persistence may receive limited payment-related information such as transaction identifiers, payment status, billing details or the last digits of a payment method rather than complete payment-card information.
Website and Device Information When you visit our websites or interact with our online Services, we may automatically collect information such as:
IP address; browser type and version; operating system; device identifiers; language preferences; time zone; approximate location derived from IP address or similar information; referring and exit pages; pages or screens viewed; links or features used; interaction with website or Service content; and date, time and duration of activity. This information may be collected through cookies, logs, pixels, web beacons, SDKs, APIs, analytics technologies and similar tools.
Communications and Support If you communicate with us by email, website form, chat functionality, support channel, social media or other communication method, we may collect your contact information, the contents of the communication and any Personal Data you choose to provide.
Events, Surveys and Marketing Activities If you participate in a webinar, conference, survey, event, demonstration, promotional activity or other engagement organized or sponsored by Persistence, we may collect:
name; contact information; organization and role; preferences; survey or event responses; event registration details; and other information voluntarily provided. Where photographs, video recordings or other media are captured at an event, we will process such information in accordance with applicable law and applicable event-specific notices or consent requirements.
Recruitment and Employment-Related Information If you apply for a job, internship or other position with Persistence, we may collect information such as:
name and contact information; resume or curriculum vitae; employment history; educational and professional qualifications; skills and professional experience; interview and assessment information; references; work-authorization or immigration information, where required; compensation expectations or related information; background-verification information, where permitted by law; and other information provided during recruitment. Additional employment-related information may be collected if you become an employee or contractor.
Vendors, Suppliers and Business Partners If you represent or work for a vendor, supplier, professional adviser, business partner or other organization with which Persistence interacts, we may collect:
name; business contact details; organization; job title or designation; business address; tax or invoicing information; payment-related business information; information contained in contracts, quotations, proposals, purchase orders or invoices; and
other information necessary to establish and manage the business relationship. Office Visitors Where you visit a Persistence office or other controlled facility, we may collect information reasonably necessary for physical access, safety and security, including:
visitor name; contact information; organization; date and time of visit; purpose of visit; host; identification information where reasonably required; and photographs, CCTV footage or other physical-security information, where applicable.
2HOW WE COLLECT PERSONAL DATA
We may collect Personal Data from the following sources.
Directly From You We collect information that you provide when you:
create or manage an account; use the Services; enter into an agreement with us; subscribe to or purchase Services; request customer or technical support; communicate with us; submit a form; register for an event; complete a survey; apply for employment; visit our premises; engage with our marketing or social-media channels; or otherwise provide information to us. Automatically When you access our websites or Services, we may automatically collect technical, security, usage and device information through logs, cookies, SDKs, APIs, pixels, web beacons, analytics technologies and similar tools.
We may use this information to provide and secure the Services, authenticate users, understand usage, monitor performance, troubleshoot problems, maintain reliability, identify errors, detect fraud or security threats and improve our websites and Services.
From Customers Our customers may provide Personal Data to us or cause Personal Data to be processed through the Services.
For example, an organization may provide account information necessary to provision its employees' access to the Services or may submit Personal Data relating to its own users, customers or personnel.
From Third Parties Where permitted by applicable law, we may receive Personal Data from sources such as:
business partners; service providers; authentication or identity providers; analytics providers; event organizers; recruitment agencies; professional networks; publicly available sources; and other third parties with whom we have a legitimate business relationship.
3COOKIES AND SIMILAR TECHNOLOGIES
We may use cookies and similar technologies to operate our websites and Services, remember preferences, authenticate users, maintain security, understand website and product usage, measure performance and improve user experience.
Depending on applicable law, we may seek consent before placing or using certain categories of cookies or similar technologies.
You may be able to manage cookie preferences through your browser settings or cookiemanagement tools made available by Persistence.
Additional information about the categories of cookies and similar technologies we use, their purposes and available choices may be provided in our Cookie Policy or cookiemanagement interface.
Where applicable law requires an opt-out or consent mechanism relating to advertising, analytics or similar technologies, Persistence will provide the mechanism required by applicable law.
4CUSTOMER DATA
Our customers may submit, upload, transmit, generate or otherwise make Personal Data available to Persistence through their use of the Services (“Customer Data”).
Where Persistence processes Customer Data solely on behalf of a customer, we process that Personal Data:
according to the customer's documented instructions; for the purposes specified in the applicable agreement; subject to the applicable DPA or other data-protection terms; and in accordance with applicable data protection law. In those circumstances, the customer is generally responsible for determining the purpose of processing, establishing an appropriate legal basis, providing required notices to individuals and responding to applicable data-subject, data-principal or consumer requests.
Nothing in this section limits Persistence's obligations under applicable law or its contractual obligations to customers.
5HOW WE USE PERSONAL DATA
We process Personal Data for legitimate business, operational, contractual, security, compliance and other lawful purposes.
Where we act as a processor, Data Processor, service provider or equivalent role for a customer, the purposes of processing are determined primarily by that customer and the applicable agreement.
Where Persistence determines the purposes and means of processing, we may use Personal
Data for the following purposes Providing and Administering the Services We may use Personal Data to:
create and administer customer and user accounts; authenticate users and manage access; provide, operate, maintain and support the Services; enable product functionality; process subscriptions, orders, transactions and billing; provide customer, technical and product support; respond to enquiries and requests; monitor Service availability, performance and reliability; troubleshoot errors and service interruptions; provide documentation and other Service-related information; communicate about accounts, transactions, contractual matters, security, availability and material changes;
administer events, webinars and demonstrations; and fulfil our contractual obligations. Security, Fraud Prevention and Service Integrity We may use Personal Data to:
maintain network, application, information and cybersecurity; authenticate and verify users; detect suspicious, unauthorized or malicious activity; prevent and investigate fraud or abuse; detect, investigate and respond to security incidents; monitor vulnerabilities and system integrity; debug technical issues; maintain logs and security records; and protect the availability, confidentiality and integrity of the Services. Business Operations and Administration We may use Personal Data to:
conduct internal operations, planning and reporting; administer customer and vendor relationships; conduct audits and assessments; manage finance, accounting and taxation; maintain business and compliance records; administer contracts; enforce our agreements and policies; manage procurement and vendors; manage corporate governance; and otherwise operate and administer our business. Analytics, Research and Service Improvement We may use Personal Data, where permitted by applicable law, to:
understand how websites and Services are used; monitor and analyse product performance; conduct research, testing and quality assurance; improve and enhance existing Services; develop new products, features and functionality; identify usage trends and technical issues; and generate operational and business insights. Where Customer Data is involved, any use for these purposes will be subject to the applicable customer agreement, DPA and applicable law.
Marketing and Business Development Subject to applicable law and your preferences, we may use Personal Data to:
communicate about our products, Services and features; invite individuals to events, webinars and demonstrations; manage business leads and customer relationships; conduct promotional and business-development activities; measure the effectiveness of marketing communications; personalize marketing or website experiences where permitted; publish customer stories, testimonials or case studies with appropriate authorization; and
promote Persistence through appropriate business and digital channels. You may opt out of promotional communications by using the unsubscribe mechanism in the communication or contacting us as described in the Contact Us section.
Opting out of marketing communications does not prevent us from sending necessary transactional, contractual, account, security, privacy or service-related communications.
Recruitment and Employment We may process recruitment and employment-related Personal Data to:
evaluate candidates; communicate with applicants; conduct interviews and assessments; verify references or conduct background checks where permitted; administer offers; establish and administer employment or contractor relationships; manage payroll, benefits and personnel records; comply with employment, labour, tax, immigration and health-and-safety requirements; and
protect our personnel, systems, property and legal interests. Legal and Regulatory Compliance We may process Personal Data where reasonably necessary to:
comply with applicable laws and regulations; respond to valid court orders, subpoenas and legal process; respond to lawful requests from competent authorities; maintain records required by law; investigate suspected violations of law or our agreements; establish, exercise or defend legal claims; protect legal rights; and comply with tax, accounting, audit and reporting requirements. Other Lawful Purposes We may process Personal Data for other purposes:
disclosed at or before collection; authorized by you where consent is required; necessary to enter into or perform a contract; necessary for legitimate interests where recognized by applicable law and not overridden by applicable rights;
necessary to comply with legal obligations; or otherwise permitted or required by applicable law. Where we rely on consent, you may withdraw that consent subject to applicable law.
Withdrawal does not affect the lawfulness of processing undertaken before the withdrawal.
6LEGAL BASES FOR PROCESSING
The legal basis applicable to a particular activity depends on the jurisdiction, our relationship with you, the purpose of processing and whether Persistence is acting as a controller, Data Fiduciary, processor or service provider.
Where applicable, our legal bases may include:
Performance of a Contract. Processing necessary to enter into or perform a contract with you or your organization, or to take steps at your request before entering into a contract.
Consent. Processing based on valid consent where consent is required or otherwise appropriate under applicable law.
Legal Obligation. Processing necessary to comply with legal, regulatory, employment, tax, accounting, reporting or other obligations.
Legitimate Interests. Where recognized under applicable law, processing necessary for our legitimate interests or those of a third party, provided those interests are not overridden by applicable rights and interests.
Our legitimate interests may include providing and securing our Services, maintaining customer and business relationships, preventing fraud and misuse, improving our Services, administering our business and protecting our legal rights.
Protection of Rights and Safety. Processing necessary to establish, exercise or defend legal claims or protect the rights, security, property or safety of Persistence or others.
Other Lawful Bases. Any other basis permitted under the law applicable to the relevant processing.
7DE-IDENTIFIED, ANONYMIZED AND AGGREGATED INFORMATION
We may create, use and disclose information that has been de-identified, anonymized or aggregated so that it no longer identifies, or is not reasonably capable of identifying, an individual, to the extent permitted by applicable law.
Such information may be used for purposes including:
analytics; research and development; statistical analysis; security; benchmarking; reporting; Service improvement; and understanding trends relating to our Services. Where information is treated as de-identified or anonymized under applicable law, Persistence will not attempt to re-identify it except where permitted or required by law.
8HOW WE SHARE PERSONAL DATA
We may disclose Personal Data where reasonably necessary for the purposes described in this Policy or otherwise permitted or required by applicable law.
Service Providers and Subprocessors We may disclose Personal Data to third-party service providers, contractors and subprocessors that assist us with functions such as:
cloud hosting and infrastructure; data storage and databases; cybersecurity; authentication and identity management; system monitoring; communications; customer support; analytics; payment and billing administration; recruitment and background verification; professional services; legal, accounting and audit services; and other technology or business operations. Where applicable, we require such providers to be subject to contractual confidentiality, security and data-protection obligations appropriate to the services they provide.
Where Customer Data is involved, the use of subprocessors is subject to the applicable customer agreement, DPA and applicable data-protection requirements.
Affiliates We may share Personal Data among Persistence group entities where reasonably necessary for:
Service delivery; infrastructure and IT management; security; customer support; finance and accounting; legal and compliance; business administration; personnel administration; and other lawful business purposes. Business Partners and Integrations We may disclose Personal Data to business partners where necessary to provide an integration, functionality or service requested by you or your organization.
Our Services may also interact with third-party APIs, SDKs, software libraries, integrations and technology services. Where those providers process Personal Data on our behalf, applicable contractual, security and data-protection requirements will apply.
Where a third party processes information independently for its own purposes, its own privacy notice may apply.
Professional Advisers We may disclose Personal Data to lawyers, auditors, accountants, insurers, consultants and other professional advisers where reasonably necessary to obtain professional advice, administer our business, comply with law or protect our legal interests.
Legal Process, Rights, Security and Safety We may access, preserve, use or disclose Personal Data where we reasonably believe this is necessary or appropriate to:
comply with applicable law; respond to valid legal process or lawful government requests; establish, exercise or defend legal rights; enforce contracts or policies; protect Persistence, our customers, users, employees or other individuals; investigate or prevent fraud, abuse or unlawful activity; investigate or address security incidents; or protect the integrity and availability of our systems and Services. Where legally permitted, we will seek to limit disclosure to information reasonably necessary for the relevant purpose.
Corporate Transactions Personal Data may be disclosed or transferred in connection with an actual or proposed:
merger; acquisition; financing; investment; restructuring; reorganization; insolvency; sale or transfer of assets; change of ownership; or similar corporate transaction. Such disclosures will be subject to applicable law and contractual obligations At Your Direction or With Your Consent We may disclose Personal Data at your direction or where you provide authorization or consent, where required.
9SALE, SHARING AND TARGETED ADVERTISING
Persistence does not sell Personal Data for monetary consideration Certain privacy laws, including the CCPA/CPRA, define terms such as “sale,” “sharing” and “targeted advertising” more broadly than an exchange of Personal Data for money.
To the extent any activity undertaken by Persistence is considered a sale, sharing, targeted advertising or similar regulated activity under applicable law, Persistence will provide applicable notices and rights mechanisms, including opt-out mechanisms where required.
Where required by applicable law, Persistence will also recognize legally valid browserbased or other universal opt-out preference signals.
Our practices concerning cookies, advertising and similar technologies may be further described in our Cookie Policy or applicable cookie-preference mechanism.
10SECURITY OF PERSONAL DATA
Persistence maintains reasonable and appropriate administrative, technical, physical and organizational safeguards designed to protect Personal Data against unauthorized access, acquisition, use, alteration, disclosure, loss, destruction and other unlawful or accidental processing.
Depending on the Services and circumstances, these measures may include:
access controls; authentication mechanisms; encryption and other technical safeguards; logging and security monitoring; incident detection and response; vulnerability management and security testing; backup and recovery measures; business-continuity and disaster-recovery measures; confidentiality obligations for personnel and contractors; information-security and privacy policies; and due-diligence and contractual requirements for applicable service providers and subprocessors.
We take reasonable steps to require service providers processing Personal Data on our behalf to maintain appropriate confidentiality, security and data-protection safeguards.
However, no system, transmission method or electronic-storage method can be guaranteed to be completely secure. Accordingly, we cannot guarantee that Personal Data will never be accessed, disclosed, lost, altered or otherwise compromised.
Nothing in this section limits any rights or remedies available under applicable law.
11SECURITY INCIDENTS AND PRIVACY COMMUNICATIONS
Persistence may communicate with individuals regarding security, privacy, administrative, transactional, contractual and Service-related matters through electronic or other appropriate means.
If Persistence becomes aware of a security incident involving Personal Data that requires notification under applicable law, we will investigate the incident, take reasonable steps to contain and mitigate its effects and notify affected customers, individuals, regulators or other parties where and to the extent required by applicable law.
Where we process affected Personal Data on behalf of a customer, notification and cooperation obligations may also be governed by the applicable customer agreement or
DPA
12HIPAA AND PROTECTED HEALTH INFORMATION
Persistence may provide Services capable of supporting customers whose activities are subject to the U.S. Health Insurance Portability and Accountability Act of 1996 (“HIPAA”)
and its implementing regulations.
Where applicable, Persistence may process Protected Health Information (“PHI”) on behalf of a customer in accordance with the applicable Services, contractual requirements and law.
Where Persistence acts as a Business Associate under HIPAA, the processing of PHI will be governed by an applicable Business Associate Agreement (“BAA”), where required.
Customers that are covered entities or business associates under HIPAA should submit PHI to Persistence only where the applicable Services have been agreed and any required BAA or other applicable contractual documentation has been executed.
Where a BAA applies, Persistence's processing of PHI will be subject to that BAA, applicable HIPAA requirements and other applicable privacy and security laws. If this Policy conflicts with a BAA concerning PHI, the BAA will govern to the extent required by applicable law.
Persistence's ability to support HIPAA-related requirements does not itself constitute a certification or representation that any particular customer, product, configuration or use of the Services is compliant with HIPAA. Customers remain responsible for configuring and using the Services consistently with their own legal, regulatory, contractual and compliance obligations.
13INTERNATIONAL DATA TRANSFERS
Persistence AI PTE. LTD. is incorporated in Singapore and operates together with subsidiaries and affiliates, including Utkarsh AI Labs Private Limited in India.
Depending on the Services, the location of users, customers, personnel, affiliates, service providers and subprocessors, Personal Data may be accessed, transferred, processed or stored outside the country in which it was collected.
Where Personal Data is transferred internationally, Persistence will take appropriate steps required under applicable data-protection law.
Depending on the jurisdiction and circumstances, such measures may include:
adequacy decisions or adequacy regulations; standard contractual clauses; international data-transfer agreements or addenda; contractual data-protection provisions; Binding Corporate Rules, where applicable; recognized certification or code mechanisms, where legally available; transfer assessments; supplementary technical, contractual or organizational safeguards; applicable statutory derogations or exceptions; and other legally recognized transfer mechanisms. Where Persistence processes Personal Data on behalf of a customer, international-transfer arrangements may additionally be governed by the applicable customer agreement, DPA and customer instructions.
Persistence may disclose Personal Data to governmental, regulatory, law-enforcement or other public authorities where required or permitted by applicable law or valid legal process.
Where legally permitted and appropriate, Persistence will seek to limit such disclosure to
Personal Data reasonably necessary to comply with the relevant lawful request
14DATA RETENTION
Persistence retains Personal Data only for as long as reasonably necessary for the purposes for which it was collected or otherwise processed, including to:
provide and administer the Services; maintain customer, contractual and business relationships; comply with legal, regulatory, tax, accounting and reporting obligations; maintain security and business records; prevent fraud and abuse; investigate incidents; establish, exercise or defend legal claims; and enforce contractual rights. Retention periods may vary based on:
the nature and sensitivity of the Personal Data; the purpose of processing; the relationship with the individual or customer; contractual commitments; customer instructions; applicable legal requirements; limitation periods and potential disputes; security requirements; and legitimate business-record requirements. When Personal Data is no longer reasonably required, Persistence will take reasonable steps to delete, anonymize or securely dispose of it unless continued retention is required or permitted by applicable law.
Where Persistence processes Customer Data on behalf of a customer, retention, return and deletion will generally be governed by the customer agreement, DPA and documented customer instructions, subject to applicable law.
15YOUR PRIVACY RIGHTS
Depending on your jurisdiction, applicable law and Persistence's role in processing your
Personal Data, you may have one or more privacy rights These may include rights to:
obtain information about processing; access Personal Data; obtain a copy of Personal Data; correct or update inaccurate information; request deletion or erasure; request restriction of processing; object to particular processing; withdraw consent; obtain Personal Data in a portable format; opt out of certain sales, sharing, targeted advertising or profiling; limit specified uses of sensitive Personal Data; obtain information regarding certain automated decision-making; appeal certain decisions concerning privacy requests; nominate or appoint another person to exercise rights where provided by law; and lodge a complaint with an applicable regulatory or supervisory authority. These rights are not absolute and may be subject to statutory conditions, exceptions, limitations and verification requirements.
Exercising Your Rights To exercise an applicable privacy right, contact us using the details in the Contact Us section or use another privacy-request mechanism made available by Persistence.
We may take reasonable steps to verify your identity and authority before fulfilling a request.
Verification measures will depend on the nature of the request and sensitivity of the Personal
Data involved Where permitted by applicable law, you may authorize another person or agent to make a request on your behalf. We may require reasonable evidence of authorization and verification of the identities or authority involved.
We will respond to valid requests in accordance with the timelines and requirements prescribed by applicable law.
Customer-Controlled Data Where Persistence processes Personal Data solely on behalf of a customer, the customer may be the relevant controller, Data Fiduciary, business or other responsible entity.
In such circumstances, you may need to submit your request directly to that customer.
Persistence will assist the customer in responding where required by law or contract.
16INDIA
Digital Personal Data Protection Act, 2023 Where the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”), or relevant provisions thereof apply to the processing of your Personal Data, you may have rights and protections available under Indian law, subject to the applicability and commencement of the relevant provisions.
Depending on the circumstances and applicable provisions, these may include rights to:
obtain prescribed information about Personal Data being processed; request correction of inaccurate or misleading Personal Data; request completion or updating of Personal Data; request erasure where applicable; withdraw consent where processing is based on consent; access applicable grievance-redressal mechanisms; and nominate another individual to exercise applicable rights in the circumstances provided by law.
Where processing is based on consent, withdrawal of consent will be made reasonably accessible in accordance with applicable law. Withdrawal does not affect the lawfulness of processing undertaken before withdrawal.
Persistence will provide notices and rights mechanisms as required under applicable Indian law.
Where Persistence acts as a Data Processor on behalf of a customer acting as the Data Fiduciary, the customer may be primarily responsible for providing notices, establishing the applicable basis for processing and responding to Data Principal requests. Persistence will provide assistance as required under applicable law and contract.
Individuals may also have access to grievance-redressal and regulatory mechanisms available under applicable Indian law.
17SINGAPORE
Where the Personal Data Protection Act 2012 (“PDPA”) applies, Persistence will process Personal Data in accordance with applicable Singapore data-protection requirements.
Subject to statutory conditions and exceptions, individuals may have rights to:
request access to Personal Data in Persistence's possession or control; request prescribed information regarding the use or disclosure of Personal Data; request correction of errors or omissions in Personal Data; and withdraw consent for future collection, use or disclosure where processing is based on consent.
Withdrawal of consent may affect Persistence's ability to provide certain Services or continue a particular relationship where the relevant Personal Data is reasonably necessary for that purpose.
Persistence will take reasonable steps required under applicable Singapore law in relation to:
notification of purposes; consent and applicable exceptions; accuracy; protection; retention limitation; accountability; overseas transfers; and notifiable data breaches. Where Personal Data is transferred outside Singapore, Persistence will take steps required under the PDPA to ensure an appropriate standard of protection for the transferred Personal
Data Where Persistence processes Personal Data on behalf of another organization, that organization may be primarily responsible for the individual's request and Persistence will provide reasonable assistance where required.
Questions and complaints under the PDPA may be directed to our Data Protection Officer using the details provided in the Contact Us section.
18EUROPEAN ECONOMIC AREA
Where the EU General Data Protection Regulation (“EU GDPR”) applies, individuals may have rights including the:
right to be informed; right of access; right to rectification; right to erasure in circumstances provided by law; right to restriction of processing; right to data portability, where applicable; right to object to processing, including an absolute right to object to direct marketing; right to withdraw consent where processing is based on consent; and rights relating to certain automated decision-making and profiling. These rights are subject to the conditions and exceptions established under applicable law.
Where Persistence acts as a processor on behalf of a customer, that customer may be the relevant controller and individuals may need to direct requests to the customer.
Individuals may also lodge a complaint with a competent supervisory authority, including, as applicable, the authority in the country where they live or work or where they believe an infringement occurred.
International Transfers From the EEA Persistence AI PTE. LTD. is based in Singapore and operates with affiliates including Utkarsh AI Labs Private Limited in India. Personal Data may therefore be transferred to or accessed from countries outside the EEA.
Where Personal Data subject to the EU GDPR is transferred to a recipient outside the EEA and an applicable adequacy decision is unavailable, Persistence will use a legally recognized transfer mechanism where required.
Such safeguards may include:
the European Commission's Standard Contractual Clauses (“SCCs”); Binding Corporate Rules, where applicable; an approved code of conduct or certification mechanism, where legally available; another legally recognized safeguard; or a permitted derogation in circumstances provided by law. Where required, Persistence will undertake an appropriate transfer assessment and implement supplementary technical, contractual or organizational measures necessary for the relevant transfer.
Where Persistence processes Personal Data on behalf of a customer, transfer arrangements may additionally be governed by the applicable DPA and customer instructions.
19UNITED KINGDOM
Where the UK General Data Protection Regulation (“UK GDPR”) and Data Protection Act 2018 apply, individuals may have rights including the:
right to be informed; right of access; right to rectification; right to erasure in circumstances provided by law; right to restriction of processing; right to object, including to direct marketing; right to data portability, where applicable; right to withdraw consent where processing is based on consent; and rights relating to certain automated decision-making and profiling. These rights are subject to applicable statutory conditions and exemptions Individuals may lodge a complaint with the UK Information Commissioner's Office (“ICO”)
or another competent supervisory authority where applicable.
Where Persistence acts as a processor on behalf of a customer, that customer may be the relevant controller and requests may need to be directed to the customer.
International Transfers From the UK Personal Data subject to UK data-protection law may be transferred to, accessed from or processed in countries outside the UK.
Where a transfer constitutes a restricted transfer under applicable UK data-protection law, Persistence will use an applicable adequacy regulation, appropriate safeguard or other legally permitted transfer mechanism.
Where required, safeguards may include:
the UK International Data Transfer Agreement (“IDTA”); the International Data Transfer Addendum to the EU Standard Contractual Clauses (“UK Addendum”);
UK Binding Corporate Rules, where applicable; another legally recognized safeguard or mechanism; or a permitted statutory exception. Where required, Persistence will complete the applicable transfer risk assessment/data protection test and implement additional technical, contractual or organizational measures where necessary.
Where Persistence processes Personal Data on behalf of a customer, international-transfer requirements may additionally be governed by the applicable customer agreement, DPA and transfer mechanism.
20CALIFORNIA
This section applies only to the extent Persistence is subject to the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA/CPRA”), and the relevant Personal Information is within its scope.
California Privacy Rights Subject to applicable conditions and exceptions, California residents may have the:
Right to Know the categories and, where applicable, specific pieces of Personal Information collected about them and certain information regarding its collection, use and disclosure;
Right to Delete Personal Information, subject to applicable exceptions; Right to Correct inaccurate Personal Information; Right to Opt Out of Sale or Sharing where Persistence engages in activities constituting a sale or sharing under the CCPA/CPRA;
Right to Limit Use and Disclosure of Sensitive Personal Information where the statutory right applies;
Right to Non-Discrimination for exercising rights under applicable California privacy law; and
rights relating to certain uses of automated decisionmaking technology, where and to the extent applicable under California law.
Where applicable, Persistence will also process legally recognized opt-out preference signals in accordance with applicable California requirements.
Categories of Personal Information Depending on the Services used and nature of your interaction with Persistence, categories of Personal Information that may be processed include:
Category Examples Principal Purposes
Identifiers Name, email address, account identifier, online identifier, IP address Account administration, authentication, communications, security and Service delivery Customer or commercial information Organization, subscription information, transaction and billing information Service delivery, billing, customer support and business administration Internet or other electronic network activity Browser information, device information, logs and interactions with websites or Services Security, analytics, monitoring, troubleshooting and Service improvement Geolocation information Approximate location derived from IP address or similar information, where collected Security, analytics and Service functionality Audio or sensory information Audio, recordings or other media submitted to or processed through applicable Services Providing Services, customerdirected processing, security and troubleshooting Professional or employment-related information Job title, organization, employment history and recruitment information Customer relationships, recruitment and business administration
Inferences Preferences or other inferences derived from interactions or information, where applicable Analytics, personalization and
Service improvement Category Examples Principal Purposes Sensitive Personal
Information Account login credentials and other information falling within statutory sensitive-information categories, where collected Authentication, security, account administration or other disclosed purposes The actual categories collected will depend on the relevant Service, customer relationship and interaction with Persistence.
Sources Sources may include:
you directly; Persistence customers; your organization; automatic collection through our websites and Services; service providers; business partners; authentication providers; recruitment sources; and publicly available sources, where permitted. Business and Commercial Purposes We may process applicable Personal Information for purposes described in this Policy, including:
providing and administering the Services; authentication; customer support; billing; cybersecurity and fraud prevention; analytics; debugging; research and Service improvement; business administration; marketing where permitted; recruitment; compliance with law; and protection of rights and safety. Categories of Recipients Depending on the circumstances, Personal Information may be disclosed to categories of recipients including:
Persistence affiliates; service providers; subprocessors; business partners; integration providers; professional advisers; parties to corporate transactions; and governmental or regulatory authorities where legally required or permitted. Sale and Sharing Persistence does not sell Personal Information for monetary consideration If Persistence engages in an activity that constitutes a “sale” or “sharing” under applicable California law, Persistence will provide applicable disclosures and opt-out mechanisms required by law.
Persistence will not knowingly sell or share Personal Information of consumers under the applicable age threshold without any authorization required by California law.
Sensitive Personal Information Where Persistence processes Sensitive Personal Information, we will use and disclose it in accordance with applicable California law.
If Persistence uses or discloses Sensitive Personal Information for purposes that give rise to a statutory right to limit such processing, we will provide the legally required mechanism to exercise that right.
Authorized Agents and Verification California residents may use an authorized agent where permitted by law We may request evidence of the agent's authority and take reasonable steps to verify the identity or authority of the consumer and agent, subject to applicable law.
Non-Discrimination Persistence will not discriminate against an individual for exercising rights available under applicable California privacy law.
This does not prohibit legally permitted differences in prices, rates, levels of service or benefits that comply with applicable law.
Financial Incentives If Persistence offers a financial-incentive, price-difference, loyalty, referral or similar program that is subject to California privacy-law requirements, Persistence will provide any notice and information required by applicable law before or in connection with participation.
Participation in any such program will be voluntary where required by law California “Shine the Light” To the extent California's “Shine the Light” law applies to Persistence, California residents may submit applicable requests concerning disclosures of Personal Information to third parties for those third parties' own direct-marketing purposes using the contact information provided below.
21OTHER U.S. STATE PRIVACY RIGHTS
Residents of U.S. states with applicable comprehensive privacy laws may have additional rights depending on the state, applicable statutory thresholds and exemptions, the nature of the Personal Data and Persistence's role in processing it.
These rights may include:
confirming whether Personal Data is processed; accessing Personal Data; correcting Personal Data; deleting Personal Data; obtaining a portable copy; opting out of sale; opting out of targeted advertising; opting out of specified profiling or automated-decision activities; limiting or providing consent for processing sensitive Personal Data; withdrawing consent; appealing denial of a privacy request; and exercising rights without unlawful discrimination. Where applicable state law provides a right to appeal a decision concerning a privacy request, Persistence will provide an appropriate appeal mechanism.
Where a legally recognized universal opt-out mechanism is required to be honored,
Persistence will do so in accordance with applicable law Persistence will provide state-specific disclosures or mechanisms where required.
Nevada To the extent applicable, Nevada residents may have the right to opt out of the sale of certain covered information under Nevada law.
Persistence does not currently sell Personal Data for monetary consideration in the manner described above. If Nevada law provides an applicable opt-out right concerning a Persistence processing activity, the request may be submitted through the contact information below.
22AUTOMATED DECISION-MAKING AND ARTIFICIAL INTELLIGENCE
Persistence provides AI-powered technologies and Services. The role of Persistence in relation to Personal Data processed through AI functionality depends on the relevant
Service, customer configuration and processing context Where customers use Persistence Services to process Personal Data, including through automated or AI-enabled functionality, Persistence may process such information on behalf of the customer in accordance with the customer's instructions and applicable agreements.
Where Persistence itself uses automated processing involving Personal Data and applicable law imposes specific transparency, assessment, consent, access, opt-out or other requirements, Persistence will take steps required by that law.
Persistence does not represent through this Policy that all AI-enabled functionality constitutes automated decision-making producing legal or similarly significant effects.
Whether such requirements apply depends on the specific use case, purpose and applicable law.
Where applicable law provides rights concerning automated decision-making or profiling, individuals may exercise those rights using the mechanisms described in this Policy.
23RECRUITMENT AND EMPLOYMENT-RELATED PROCESSING
In addition to the information described elsewhere in this Policy, Persistence may process recruitment and employment-related Personal Data for:
evaluating qualifications and suitability; communicating with candidates; conducting interviews and assessments; conducting background and reference checks where permitted; administering offers; onboarding; administering employment or contractor relationships; payroll and benefits; workforce management; maintaining personnel records; complying with employment, labour, immigration, tax and other legal requirements; and
protecting Persistence's rights, systems, property, personnel and business. Depending on the jurisdiction, processing may be based on steps taken before entering into a contract, performance or administration of a contract, legal obligations, legitimate interests, consent where required, or another lawful basis.
Special categories of Personal Data or sensitive Personal Data will be processed only where permitted or required under applicable law and subject to any additional legal basis or safeguards required.
Recruitment and employment information may be accessed by appropriately authorized personnel and relevant service providers supporting recruitment, HR, payroll, benefits, background verification, technology, legal, accounting, audit or other legitimate business functions.
24OFFICE VISITORS AND PHYSICAL SECURITY
Persistence may process visitor Personal Data to:
manage and authorize access to facilities; protect employees, visitors and property; maintain physical and information security; investigate security incidents; maintain appropriate visitor and security records; and comply with applicable legal or regulatory obligations. Visitor Personal Data may be accessible to authorized Persistence personnel, facilitymanagement providers, security providers, technology providers, auditors and public authorities where required or permitted by law.
CCTV or similar security monitoring, where used, will be operated subject to applicable law and relevant notices.
25VENDORS AND BUSINESS PARTNERS
Persistence may process Personal Data relating to vendors, suppliers and business partners to:
conduct onboarding and due diligence; evaluate and manage relationships; negotiate and administer agreements; issue and manage purchase orders; process invoices and payments; manage procurement; communicate with business contacts; conduct audits and compliance activities; and comply with legal, tax, accounting and regulatory obligations. Depending on the jurisdiction, applicable legal bases may include performance of a contract, steps before entering into a contract, legal obligations, legitimate interests, consent where required, or another permitted basis.
26CHILDREN AND MINORS
The Services are primarily intended for businesses, organizations, professionals and other users authorized to enter into applicable business arrangements.
Unless expressly stated otherwise for a particular Service, our Services are not directed to children under 18.
Persistence does not knowingly collect Personal Data directly from children under 18 for the purpose of independently offering the Services to them.
However, where Persistence processes Personal Data on behalf of a customer, the nature of the Customer Data is determined by that customer. Customers are responsible for ensuring that their collection and submission of Personal Data relating to children or minors complies with applicable law and the applicable agreement with Persistence.
Where applicable law establishes a different age threshold or additional requirements concerning children's Personal Data, Persistence will comply with requirements applicable to its processing role.
If you are a parent or legal guardian and believe a child has provided Personal Data directly to Persistence in circumstances not permitted by applicable law, please contact us.
If Persistence determines that Personal Data was collected in violation of applicable children's privacy law, we will take appropriate steps, which may include deletion, subject to applicable legal requirements.
27INFORMATION YOU PROVIDE ABOUT OTHER INDIVIDUALS
Certain Services or business interactions may allow you to provide Personal Data relating to another individual.
If you provide such information, you are responsible for ensuring that you have appropriate authority, permission or another lawful basis to provide that Personal Data to Persistence.
You should not provide another person's Personal Data where doing so would violate applicable law or your obligations to that individual.
28THIRD-PARTY WEBSITES, APPLICATIONS AND SERVICES
Our websites, Services or communications may contain links to third-party websites, applications, platforms or services. Third parties may also link to or reference Persistence.
Third-party services not controlled by Persistence may have privacy practices, terms and security measures that differ from ours.
Persistence is not responsible for the privacy practices or content of third-party services that we do not control. We encourage you to review the applicable privacy notice and terms before providing Personal Data to an independent third party.
This section does not apply to a service provider or subprocessor processing Personal Data on Persistence's behalf, whose processing is subject to applicable contractual and dataprotection requirements.
29SUPERVISORY AND REGULATORY AUTHORITIES
Depending on your location and applicable law, you may have the right to lodge a complaint with a competent privacy, data-protection or regulatory authority.
For example:
individuals in the EEA may contact the competent data-protection supervisory authority;
individuals in the UK may contact the ICO; individuals in Singapore may have recourse to the Personal Data Protection Commission, where applicable;
individuals in India may have grievance and regulatory remedies available under applicable provisions of the DPDP framework as they come into force; and
U.S. residents may have rights to contact applicable state privacy regulators or attorneys general depending on applicable law.
We encourage individuals to contact Persistence so that we have an opportunity to address the concern. However, contacting Persistence first is not intended to restrict any statutory right to contact an applicable regulatory authority.
30ACCESSIBILITY
Persistence seeks to make this Privacy Policy reasonably accessible to individuals with disabilities and to use generally recognized accessibility practices for online content.
If you experience difficulty accessing this Policy or require it in another reasonably available format, please contact us using the information below.
31CHANGES TO THIS PRIVACY POLICY
Persistence may update this Policy from time to time to reflect changes in:
our Services; technologies; business practices; legal or regulatory requirements; or other relevant circumstances. When we update the Policy, we will revise the “Last Updated” date.
Where required by applicable law, we will provide additional notice of material changes through an appropriate method, which may include email, an in-product notice or a website notice.
Where consent to a material change is required by applicable law, we will obtain such consent as required.
We encourage you to review this Policy periodically.
32CONTACT US
If you have questions about this Privacy Policy or Persistence's privacy practices, wish to exercise an applicable privacy right, or wish to make a privacy complaint, please contact:
Data Protection Officer (DPO): Ankita Jha Entity: Persistence AI PTE. LTD. Email: privacy@persistence.dev
Where Persistence processes Personal Data on behalf of a customer, that customer may be the relevant controller, Data Fiduciary, business or equivalent entity. In such circumstances, you may need to direct your request to the relevant customer, and Persistence will provide reasonable assistance where required by applicable law or contract.
Nothing in this Privacy Policy is intended to limit any rights available to an individual under applicable privacy or data-protection law.
Questions?
Contact the Persistence team at contact@persistence.dev.






