Privacy Policy

Last updated: September 17, 2026

PRIVACY POLICY

SABAI ECOVERSE PTE. LTD.

Version 1.0

Effective: 01 October 2025

1. WHO WE ARE AND WHAT THIS POLICY COVERS

1.1. This Privacy Policy (the "Policy") explains how SABAI ECOVERSE PTE. LTD., a private limited company incorporated in Singapore, UEN 202346091R, with its registered office at 531 Upper Cross Street, #02-11, Hong Lim Complex, Singapore 050531, operating under the "Sabai Protocol" brand at https://sabaiprotocol.com (the "Company", "we", "us"), collects, uses, discloses and protects personal data.

1.2. The Company decides why and how the personal data described in this Policy is processed and is responsible for it.

1.3. This Policy applies to personal data of: (a) visitors of our website; (b) persons who contact us or request a consultation; (c) our clients and prospective clients, their representatives, beneficial owners and persons paying on their behalf; and (d) our suppliers, partners and their contact persons.

1.4. This Policy does not apply to personal data that we process on behalf of our clients inside software, platforms or services that we develop, configure or support for them. In that case the client decides how that data is used, and our processing is governed by our agreement with the client and by the client's own privacy notice.

1.5. We process personal data in accordance with the Personal Data Protection Act 2012 of Singapore (the "PDPA") and, where they apply to our activities, the General Data Protection Regulation (EU) 2016/679 (the "GDPR"), the UK GDPR and other applicable data protection laws.

1.6. Our services are provided under our Terms of Service (Public Offer) published at https://sabaiprotocol.com/terms-of-service (the "Terms"). This Policy supplements the Terms in all matters relating to personal data.

2. DATA PROTECTION OFFICER

2.1. We have designated a Data Protection Officer who is responsible for our compliance with data protection laws. You can contact the Data Protection Officer with any question, request or complaint about your personal data:

Data Protection Officer, SABAI ECOVERSE PTE. LTD.

Email: it@sabaifriends.com

Address: 531 Upper Cross Street, #02-11, Hong Lim Complex, Singapore 050531

2.2. Individuals located in the European Union, the European Economic Area or the United Kingdom may use the same contact details.

3. PERSONAL DATA WE COLLECT

3.1. Data you give us:

(a) request data: your name, email address, phone number, the channel through which you prefer to be contacted (email, Telegram or WhatsApp) and the content of your message, submitted through the request form on our website or otherwise;

(b) business contact data: company name, position and professional contact details;

(c) correspondence and meeting data: the content of emails, messages, calls and video meetings with us, and documents you share with us. If a call or meeting is recorded, participants are informed in advance;

(d) engagement data: information about the services ordered, scope of work, invoices, deliverables and feedback;

(e) payment data: details of the bank account, payment method or digital-asset address used for payment, transaction identifiers and amounts;

(f) verification data: where we carry out know-your-client checks under Section 7 of the Terms, identity documents, date of birth, nationality, residential address, information on beneficial owners, directors and authorised persons, information on the source of funds, and the results of sanctions and other screening;

(g) third-party payer and collection agent data: where a payment is made by another person under Section 5.6 of the Terms, the identification data of that person.

3.2. Data collected automatically when you visit our website: IP address, browser and device type, operating system, pages visited, date and time of the visit, referring page, language preference and security signals used to protect the website against attacks and automated traffic. Details on cookies are set out in our Cookie Policy published at https://sabaiprotocol.com/cookie-policy.

3.3. Data from other sources: public registers and databases, sanctions and watch lists, results of screening of incoming payments carried out by our payment and digital-asset service providers, public professional profiles, and persons who recommend us to you or you to us.

3.4. We do not ask for data revealing health, religious or philosophical beliefs, political opinions, trade union membership, sexual life or orientation, or genetic or biometric data. Identity documents provided for verification may incidentally contain other information, such as a photograph or nationality; we use such information only for verification. Please do not send us such data through the request form.

3.5. Our services are not intended for persons under 18 years of age, and we do not knowingly collect their personal data.

3.6. You are not obliged to provide personal data. However, without contact data we cannot answer your request, and without the data required for the agreement or for verification we may be unable to provide the services or may decline or suspend an engagement as described in the Terms.

4. WHY WE USE PERSONAL DATA

4.1. We use personal data for the following purposes. For individuals to whom the GDPR applies, the legal basis for each purpose is indicated in brackets.

(a) To answer your request, arrange and hold a consultation and prepare a proposal (steps taken at your request before entering into an agreement; our legitimate interest in responding to business enquiries).

(b) To enter into and perform the agreement under the Terms, including communication, scheduling, delivery of the services, invoicing and receipt of payments (performance of the agreement).

(c) To verify clients and payers, screen payments and prevent money laundering, terrorist financing, sanctions evasion and fraud (compliance with legal obligations; our legitimate interest in preventing financial crime and protecting our business).

(d) To keep accounting, tax and corporate records (compliance with legal obligations).

(e) To operate, secure and improve our website, including protection against attacks and automated traffic (our legitimate interest in running a secure and functional website).

(f) To send business clients and business contacts information about our services, events and publications that may interest them (our legitimate interest in developing our business, or your consent where required by law). You can object to such messages at any time, free of charge.

(g) To establish, exercise or defend legal claims and to respond to lawful requests of courts and public authorities (our legitimate interest; compliance with legal obligations).

4.2. Where we rely on legitimate interests, we have balanced them against your rights and interests. You may ask us for more information on this balancing.

4.3. Under the PDPA, we process personal data with your consent, including consent that is deemed to be given when you voluntarily provide data for a purpose or enter into an agreement with us, or without consent where the PDPA permits it, including for legitimate interests, business asset transactions, investigations and compliance with law. When you submit a request through our website, you consent to our use of your data for the purposes described in paragraph 4.1(a).

4.4. We do not use personal data for decisions based solely on automated processing that produce legal effects for you or similarly significantly affect you. Screening tools may flag a payment or a person; the final decision is made by our staff.

4.5. We do not sell personal data.

5. WHO RECEIVES PERSONAL DATA

5.1. We disclose personal data only to the extent necessary for the purposes described in Section 4, to the following categories of recipients:

(a) service providers acting on our instructions: website hosting (ScalaHosting; the website servers are located in Singapore); content delivery, website security and traffic analytics without cookies (Cloudflare); email, document storage and video meetings (Google Workspace); tag management on the website (Google Tag Manager); project management and client relationship management (ClickUp);

(b) banks, payment institutions and digital-asset service providers that process payments to us and screen them;

(c) our subcontractors and professional advisers, including lawyers, accountants and auditors, who are bound by confidentiality;

(d) providers of messaging and communication services that you choose to use with us, such as Telegram or WhatsApp; these providers process data under their own terms and privacy policies;

(e) courts, regulators, law enforcement and other public authorities, where we are required or permitted to do so by law;

(f) a successor or acquirer of all or part of our business, subject to confidentiality;

(g) any other person with your consent or at your request.

5.2. Our service providers may use personal data only to provide services to us and must protect it.

6. TRANSFERS OUTSIDE SINGAPORE AND THE EUROPEAN UNION

6.1. The Company and our website servers are located in Singapore. Some of our service providers are located in, or process data in, other countries, including the United States, and our staff and subcontractors may access personal data from other countries.

6.2. When we transfer personal data outside Singapore, we ensure that the recipient provides a standard of protection comparable to that under the PDPA, in particular through contractual obligations.

6.3. Where the GDPR applies to our processing and personal data is transferred to a country that the European Commission has not recognised as providing adequate protection, we rely on the Standard Contractual Clauses approved by the European Commission, which are included in the terms of our service providers, or on the certification of the recipient under the EU-U.S. Data Privacy Framework. You may request information about these safeguards from our Data Protection Officer.

7. YOUR RIGHTS

7.1. Everyone whose personal data we process may:

(a) ask whether we hold your personal data, obtain access to it and receive information about the ways in which it has been used or disclosed by us within the past year;

(b) ask us to correct inaccurate or incomplete personal data;

(c) withdraw your consent at any time, with effect for the future. We will explain the likely consequences, for example that we may be unable to continue an engagement;

(d) complain to us, and, if you are not satisfied with our answer, to the Personal Data Protection Commission of Singapore (www.pdpc.gov.sg).

7.2. If the GDPR or the UK GDPR applies to the processing of your personal data, you also have the right to: request erasure of your data; request restriction of processing; receive the data you provided to us in a structured, commonly used and machine-readable format and have it transmitted to another organisation; object at any time to processing based on our legitimate interests; object at any time to the use of your data for direct marketing; and lodge a complaint with the data protection supervisory authority of the country where you live or work or where the alleged infringement took place.

7.3. To exercise your rights, write to our Data Protection Officer at it@sabaifriends.com. We may ask you to confirm your identity before acting on your request.

7.4. We respond as soon as reasonably possible. Where the PDPA applies and we cannot respond to an access or correction request within 30 days, we will inform you in writing within that period of the time by which we will respond. Where the GDPR applies, we respond within one month, which may be extended by up to two further months for complex or numerous requests, in which case we will inform you of the extension within the first month.

7.5. Exercising your rights is free of charge. Where the PDPA permits it, we may charge a reasonable fee for providing access to personal data; we will tell you the amount in advance. We may refuse or charge for requests that are manifestly unfounded or excessive, as permitted by law.

7.6. Some rights are subject to exceptions under the law, for example where we must keep data to comply with a legal obligation or to defend legal claims. If we refuse a request, we will tell you why.

8. HOW LONG WE KEEP PERSONAL DATA

8.1. We keep personal data only as long as needed for the purposes for which it was collected or as required by law, in particular:

(a) requests that did not lead to an engagement: up to 24 months after our last contact with you;

(b) agreements, invoices, payment and accounting records: at least five years after the end of the financial year to which they relate, as required by Singapore accounting and tax laws;

(c) verification and screening records: five years after the end of the business relationship or after the relevant transaction;

(d) website technical and security logs: for a limited period, generally not exceeding 12 months, unless they are needed to investigate an incident;

(e) correspondence and deliverables: for the term of the engagement and five years after its end.

8.2. We may keep data longer where it is necessary to establish, exercise or defend legal claims, or where a longer period is required by law. After the retention period, we delete or anonymise the data.

9. HOW WE PROTECT PERSONAL DATA

9.1. We use reasonable technical and organisational measures to protect personal data against unauthorised access, collection, use, disclosure, copying, modification, disposal and loss, including encrypted connections to our website, access control and two-step authentication for our systems, access on a need-to-know basis and confidentiality obligations of our staff and subcontractors.

9.2. No method of transmission over the internet or of storage is completely secure. If a data breach occurs, we will assess it promptly and, where the law requires it, notify the Personal Data Protection Commission of Singapore, other competent authorities and the affected individuals within the time limits set by law.

10. COOKIES

10.1. Our website uses cookies and similar technologies as described in our Cookie Policy published at https://sabaiprotocol.com/cookie-policy.

11. LINKS TO OTHER WEBSITES

11.1. Our website contains links to websites and pages of third parties, including social networks. We are not responsible for the privacy practices of those third parties. Please read their privacy policies.

12. CHANGES TO THIS POLICY

12.1. This Policy is identified by the version number and effective date stated at the head of this document. We may amend this Policy by publishing a new version with a new effective date. Where the changes are significant, we will take reasonable steps to inform the persons concerned. Previous versions are retained by the Company.

12.2. Translations of this Policy are provided for convenience; the English version prevails.

13. CONTACT

SABAI ECOVERSE PTE. LTD.

UEN 202346091R

531 Upper Cross Street, #02-11, Hong Lim Complex, Singapore 050531

Data Protection Officer: it@sabaifriends.com

Website: https://sabaiprotocol.com