1. Introduction
LawDrive Pte. Ltd. ("LawDrive", "we", "us", or "our") is committed to protecting personal data in accordance with the Personal Data Protection Act 2012 of Singapore ("PDPA") and related subsidiary legislation. This Privacy Policy explains how we collect, use, disclose, store, and protect personal data when you visit lawdrive.life, communicate with us, or engage our legal advisory services.
By using our website or providing personal data to us, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use our website or submit personal data through our channels.
This policy applies to visitors, enquiry contacts, prospective clients, current clients, correspondents, and suppliers whose personal data we process in connection with the statute atelier and our legal practice.
2. Data controller
LawDrive Pte. Ltd., UEN 202559374M, registered at 5 Shenton Way, #16-08 UIC Building, Singapore 068808, is the organisation responsible for personal data collected through this website and in connection with our legal practice, unless otherwise stated in an engagement letter or separate controller agreement.
For privacy-related enquiries, contact our Data Protection Officer at [email protected] or write to the registered address above. We aim to acknowledge privacy correspondence within five business days.
3. Personal data we collect
We may collect the following categories of personal data depending on your interaction with us:
- Identity and contact data: name, email address, telephone number, job title, department, company name, and postal address.
- Enquiry data: information you provide in contact forms, emails, or consultations, including descriptions of legal questions, statute references, and supporting documents you choose to share.
- Technical data: IP address, browser type, device identifiers, operating system, pages visited, session duration, and referral URLs collected through cookies and similar technologies where permitted.
- Engagement data: billing information, bank details where relevant, correspondence, meeting notes, folio maps, instructions, and documents provided when you become a client.
- Marketing preferences: your choices regarding newsletters, statute update alerts, or event invitations where applicable.
- Recorded communications: where you consent or where permitted by law, notes from video or telephone conferences related to your brief.
We do not intentionally collect sensitive personal data through our website contact form unless you voluntarily include it in your message. If you are submitting information about health, criminal records, biometric data, or other sensitive categories in connection with a legal brief, please do so only through secure channels we designate after engagement.
4. How we collect personal data
We collect personal data through several channels:
- Direct submission via our contact form at lawdrive.life/contact.php, which posts to our secure processing endpoint send.php.
- Email, telephone, or in-person communication during office hours (Monday to Friday, 09:00–18:00 SGT).
- Automated technologies such as essential and optional cookies described in our Cookie Policy.
- Referrals from existing clients, correspondent firms, accountants, or professional networks, where the referrer has authority to share your contact details.
- Publicly available sources including ACRA filings, regulatory registers, court lists, and media reports relevant to legal due diligence or conflict checks.
- Events, webinars, or roundtables hosted or sponsored by LawDrive where you register or provide business cards.
5. Purposes of collection, use, and disclosure
We collect and use personal data for purposes that a reasonable person would consider appropriate in the circumstances, including:
- Responding to enquiries and assessing whether we can act for you.
- Performing conflict checks, anti-money laundering screening, and client onboarding procedures required by law and professional conduct rules.
- Delivering legal advisory services, maintaining folio files, and communicating about your briefs.
- Issuing invoices, processing payments, managing credit, and fulfilling accounting and tax obligations.
- Complying with statutory and regulatory requirements, including obligations under the Legal Profession Act, PDPA, and countering the financing of terrorism rules.
- Improving our website, analysing aggregate usage trends, testing accessibility, and maintaining information security.
- Sending updates about legal developments, regulator consultations, or firm events where you have consented or where permitted by law.
- Establishing, exercising, or defending legal claims and managing complaints or disputes.
- Managing vendor relationships, IT support, and professional indemnity matters.
We may disclose personal data to third parties where necessary for these purposes, including IT service providers, cloud hosting providers, document management platforms, e-signature vendors, professional indemnity insurers, auditors, correspondent law firms, expert witnesses, courts and tribunals, and regulatory authorities. We require processors to protect personal data through contractual safeguards commensurate with the sensitivity of the information and the nature of processing.
6. Legal basis and consent
Under the PDPA, we rely on consent, contractual necessity, legal obligation, and legitimate interests as appropriate. When you submit our contact form, you must tick the consent checkbox (consent_pdpa) confirming that you agree to our collection and use of your data to respond to your enquiry. You may withdraw consent for marketing communications at any time without affecting the lawfulness of processing before withdrawal.
Where we process personal data of employees or representatives of corporate clients, we rely on legitimate interests and contractual necessity in addition to any consent obtained from the individual or authorised by their organisation.
Where consent is withdrawn for processing essential to an ongoing engagement, we will explain the impact on our ability to continue acting and discuss alternative arrangements where possible.
7. Cookies and similar technologies
Our website uses cookies to enable core functionality and, with your consent, analytics and marketing cookies. Details of each cookie category, retention periods, and management options are set out in our Cookie Policy. You may accept all cookies, reject non-essential cookies, or customise preferences through the banner displayed on first visit. Rejecting analytics cookies does not affect your ability to submit enquiries.
8. Retention
We retain personal data only as long as necessary for the purposes described in this policy or as required by law. Enquiry records from non-clients are typically retained for up to twenty-four months unless a longer period is needed to resolve a dispute or demonstrate how an enquiry was handled. Client files are retained in accordance with Law Society practice directions and limitation periods applicable to legal claims, which may extend to seven years or more after matter closure.
When personal data is no longer required, we securely delete or anonymise it using methods appropriate to the medium of storage, including shredding physical documents and cryptographic erasure of electronic records where feasible.
9. Cross-border transfers
Some of our service providers may store or process personal data outside Singapore, including in the United States, European Union, or other ASEAN jurisdictions where correspondent firms or cloud regions operate. Where we transfer personal data overseas, we ensure that the recipient jurisdiction provides a comparable standard of protection or we implement contractual clauses, binding corporate rules, and technical measures required under the PDPA to protect your data.
Clients with restrictions on offshore processing should raise this during onboarding so we can discuss Singapore-hosted alternatives where available.
10. Security measures
We implement administrative, technical, and physical safeguards to protect personal data against unauthorised access, collection, use, disclosure, copying, modification, disposal, or similar risks. Measures include role-based access controls, encrypted transmission where supported, password policies, staff training, vendor due diligence, and incident response procedures tested periodically.
No method of transmission over the internet is completely secure; we encourage you to use strong passwords and avoid sending highly confidential documents through unencrypted email before engagement. We will provide secure upload channels after a solicitor–client relationship is established where volume or sensitivity warrants.
11. Your rights under the PDPA
Subject to exceptions under the PDPA, you may:
- Request access to personal data we hold about you.
- Request correction of inaccurate or incomplete personal data.
- Withdraw consent for processing that relies on consent, understanding that this may limit our ability to continue certain services.
- Request information about how your personal data has been used or disclosed within the past year.
To exercise these rights, email [email protected] with sufficient detail to identify you and your request. We respond within thirty days unless an extension is permitted. A reasonable fee may apply for manifestly unfounded or excessive access requests.
12. Accuracy
We take reasonable steps to ensure personal data is accurate and complete. Please notify us promptly if your contact details change or if you believe information we hold is incorrect so folio records and billing remain reliable.
13. Third-party links
Our website may contain links to external sites operated by regulators, courts, correspondents, or other third parties. We are not responsible for the privacy practices of those sites and encourage you to review their policies before providing personal data.
14. Children
Our website and services are directed at business clients and adults. We do not knowingly collect personal data from individuals under eighteen without appropriate parental or guardian involvement and a legitimate legal purpose.
15. Data breach notification
In the event of a data breach likely to result in significant harm or affect a significant number of individuals, we will notify the Personal Data Protection Commission and affected individuals as required by the PDPA, and take remedial steps to mitigate harm, including password resets, vendor remediation, and client communication where privileged matters may be affected.
16. Automated decision-making
We do not use solely automated decision-making, including profiling, that produces legal or similarly significant effects without human review. Conflict-check and AML screening tools may flag matches for manual assessment by our team.
17. Updates to this policy
We may update this Privacy Policy to reflect changes in law, technology, or our practices. The effective date at the top of this page indicates the latest revision. Material changes will be highlighted on our website where practicable.
18. Contact
LawDrive Pte. Ltd.
5 Shenton Way, #16-08 UIC Building, Singapore 068808
Email: [email protected]
Phone: +65 6593 2761
19. Complaints
If you believe we have handled your personal data in breach of the PDPA, you may lodge a complaint with us at the contact details above. We investigate complaints promptly and aim to resolve them within fourteen business days. You also have the right to refer unresolved complaints to the Personal Data Protection Commission of Singapore.
20. Definitions
In this Privacy Policy, "personal data" means data about an individual who can be identified from that data or from that data and other information to which we have or are likely to have access. "Processing" includes collecting, recording, holding, organising, adapting, altering, retrieving, using, disclosing, or destroying personal data.