Scope and who controls personal data
This Privacy Policy explains how DAVIS MATERIALWORKS, trading as Supercharge Interactive, collects, uses, discloses, protects and retains personal data for this website, enquiry forms, demo requests and demonstrations where we decide the purposes and means of processing. In those circumstances, we are the organisation responsible for the personal data under Singapore's Personal Data Protection Act 2012 (PDPA).
A demonstration may instead be configured for or controlled by a client. The client controls its accounts, content, instructions and any personal data it chooses to process there, and we may act as its service provider or data intermediary. The client's privacy notice governs its purposes and decisions. This Policy still applies to personal data we independently control, such as our access-request, security and legal acceptance records.
Personal data we collect
Our current and legacy enquiry forms may collect your name, work contact details, organisation, role, selected service or topic, project information, message and consent or acceptance choices. The legacy enquiry form may also record a telephone country code and country or approximate location inferred from information such as an IP address through a configured geolocation provider.
For a demo request or authorised demo, we may collect your name, business email, organisation, role, intended purpose, request decision, demo credentials issuance and status, sign-in times, pages or functions used, commands or submissions, and security or administrative activity. Do not place real personal, confidential or production data in a demo unless expressly authorised.
Website, application and security logs may include IP address, user agent, requested path, timestamps, referrer, session identifiers, device or browser information, security and error events, blacklist results, rate-limit events and actions taken. We also collect correspondence, attachments and records of calls or meetings you choose to have with us.
Why we use personal data
We use personal data to receive and answer enquiries; understand a proposed project; assess, approve and administer demo access; issue and manage credentials; operate, troubleshoot and improve the website and authorised demonstrations; authenticate users; prevent spam, fraud, misuse and security incidents; enforce access rules; maintain legal acceptance and business records; communicate service or security notices; establish, exercise or defend legal claims; comply with law; and produce aggregated or anonymised service insights.
Where analytics or optional tools are deployed, we use their data to understand site performance and journeys, measure communications and diagnose faults, subject to applicable notice and consent choices.
Consent and other permitted processing
Where the PDPA requires consent, we seek express consent or rely on deemed consent by conduct or deemed consent by contractual necessity only after providing appropriate notice. Browsing a public page does not by itself give automatic consent to unrelated analytics, marketing or future uses.
We may process personal data without consent where the PDPA or another law permits or requires it, including applicable exceptions for legitimate interests, business improvement, investigations, emergencies, legal claims and compliance. Before relying on legitimate interests, we assess the likely benefit and adverse effect, implement reasonable safeguards and consider what a reasonable person would expect. You may withdraw consent on reasonable notice, but withdrawal operates prospectively and does not invalidate prior lawful processing or processing that remains permitted or required without consent.
Evidence of legal acceptance
Where an enquiry, access request or demo process records your acknowledgement or acceptance of legal terms, we may keep proportionate evidence of it. Depending on the relevant process, this may include the statement and document version presented, your affirmative choice, date and time, the information submitted with the request, the source page, and ordinary request metadata such as IP address and user agent. An IP address is supporting technical evidence and is not by itself conclusive proof of identity or acceptance. We use these records to administer access, demonstrate what was presented, resolve disputes and comply with legal obligations.
When we disclose personal data
We disclose only what is reasonably necessary to providers performing a defined function for us, such as website and database hosting, content delivery, email delivery, form handling, credential administration, security and abuse prevention, logging, error monitoring, analytics, font delivery, geolocation and professional support. A client may receive records relating to its client-controlled demo. Providers are expected to protect the data and use it only for the contracted function.
We may also disclose data to professional advisers, insurers, auditors, a buyer or successor involved in a genuine business transaction, affected persons, or police, regulators, cybersecurity authorities and courts where permitted or required by law or reasonably necessary to investigate and respond to a threat or claim.
We do not sell personal data for payment.
Overseas transfers
Some infrastructure, communications, analytics, security or support providers may process data outside Singapore. Before transferring personal data overseas, we use measures appropriate to the circumstances, such as vendor due diligence, data-minimisation, access controls and contractual obligations requiring a standard of protection comparable to the PDPA, or another transfer basis the PDPA permits. No safeguard removes every jurisdictional or security risk.
Security and data breaches
We use reasonable administrative, technical and physical measures appropriate to the nature of the data, including role-based access, authentication, environment separation, logging, updates, backups and encryption in transit where supported. No internet transmission, storage system or security control provides absolute security, and we cannot guarantee that an incident will never occur.
We assess suspected breaches, contain and remediate them where practicable, and determine whether notification is required under the PDPA. If a breach is notifiable, we will notify the Personal Data Protection Commission as soon as practicable and no later than three calendar days after determining that it is notifiable. Where notification to affected individuals is required, we will notify them as soon as practicable at the same time as, or after, notifying the Commission, subject to lawful exceptions or directions.
Retention
We keep personal data only while its business or legal purpose continues. The period depends on the nature and sensitivity of the data, the enquiry or demo lifecycle, security and backup needs, limitation periods, an active dispute or investigation, and accounting, regulatory or other legal requirements. Enquiry, operational, analytics, correspondence, acceptance and security records therefore do not all have one fixed retention period.
We delete, securely destroy or anonymise records when their purposes cease and retention is no longer necessary for a legal or business reason, subject to proportionate backup cycles and lawful holds.
Access, correction, withdrawal and other requests
You may ask for access to personal data we control about you and information about how it was used or disclosed during the period required by the PDPA, or ask us to correct an error or omission. You may withdraw consent on reasonable notice. You may also request deletion or restriction, but those are not absolute PDPA rights and we may retain or continue using data where a purpose remains lawful, necessary or exempt. If a client controls the relevant demo data, we may direct the request to that client or assist it under our agreement.
We may verify your identity, authority and the scope of a request. We will respond as soon as reasonably possible. If we cannot respond within 30 calendar days, we will give you a written update and the time by which we expect to respond. Where the PDPA permits a reasonable access fee, we will first provide a written estimate and will not charge a correction fee. You may withdraw an access request if you do not accept the estimate.
Marketing and Do Not Call choices
An enquiry, demo request or legal acceptance does not automatically subscribe you to marketing. We send marketing only where you have chosen it or another lawful basis applies, and each applicable message provides a way to opt out. We honour withdrawal and unsubscribe requests within a reasonable period and comply with applicable Do Not Call requirements for marketing sent to Singapore telephone numbers.
Children
The website and demonstrations are intended for adults and business users and are not directed to children. We do not knowingly invite a child to request demo credentials or submit personal data. A parent or guardian who believes a child supplied data should contact us through the channel below so we can assess and take appropriate action.
Changes and how to contact us
We may update this Policy prospectively when our practices, providers or legal obligations change. The effective date identifies the current version. We will provide proportionate notice of a material change and seek a fresh acknowledgement where required; a change does not retrospectively make an earlier use lawful.
For questions, access or correction requests, withdrawal of consent, complaints, or concerns about a possible privacy incident, use the channel labelled Privacy / Data Protection in the site footer. Using that labelled channel helps route the request to the people responsible for handling it without placing contact details inside this article.