Privacy Policy
Last update: Aug/2026
Your Privacy is Important to Us
In this Policy, "we", "us", "our" or "Epsilo" means BuffaloTechnology Pte. Ltd. and/or its affiliates and related companies (as the case may be), and "you", "your" or "yours" means the persons to whom this Policy applies.
The security of your personal data is important to us. Epsilo has in place safeguards to protect the personal data stored with us. This Policy describes how we may collect, use, disclose, process and manage your personal data which is subject to the Personal Data Protection Act (No. 26 of 2012) of Singapore ("PDPA").
By interacting with us and/or engaging our services, using our website or submitting information to us, you agree and consent to us collecting, using and disclosing your personal data in the manner set forth in this Policy. This Policy supplements but does not supersede nor replace any other consents you may have previously provided to us in respect of your personal data, and your consents herein are additional to any rights which we may have at law to collect, use or disclose your personal data.
What Personal Data We Collect
Personal data is data that can be used to identify a natural person but excludes "business contact information" as defined in the PDPA. If you provide us with any personal data relating to a third party, by submitting such personal data to us, you also represent to us and must ensure that you have notified the third party of the terms of this Policy and obtained his/her consent thereto.
As a parent or legal guardian, please do not allow minors under your care to submit personal data to us. In the event that such personal data of a minor is disclosed to us, you hereby consent to the processing of the minor’s personal data and accept and agree to be bound by this Policy and take responsibility for his or her actions.
Some examples of personal data that we may collect are:
- (a)personal particulars (e.g. name, contact details, residential address, date of birth and/or identity card/passport details);
- (b)banking information (e.g. credit card details and banking transactions);
- (c)transaction information (such as payment method, locations and distance travelled); and/or
- (d)personal opinions made known to us (e.g. feedback or responses to surveys).
Usage of Your Personal Data
We may use your personal data for our core business purposes, such as:
- (a)providing our services;
- (b)creating, administering and updating your account;
- (c)responding to, processing and handling your queries, feedback, suggestions, etc;
- (d)verifying your identity, processing payments as well as managing our administrative, business operations (including the processing, storage, monitoring and backup of data) and complying with internal policies and procedures;
- (e)communicating with you, including providing you with updates on changes to products and services (whether made available by us or through us) including any additions, expansions, suspensions and replacements of or to such products and services and their terms and conditions;
- (f)complying with all applicable laws, regulations, rules, directives, orders, instructions and requests from any authorities, including regulatory, governmental, tax and law enforcement authorities or other authorities;
- (g)financial reporting, regulatory reporting, management reporting, risk management, audit and record keeping purposes;
- (h)enforcing obligations owed to us;
- (i)seeking professional advice, including legal advice; and/or
- (j)any other purpose relating to any of the above.
In your interactions with us, we may also have specifically notified you of other purposes for which we collect, use or disclose your personal data. If so, we will collect, use and disclose your personal data for these additional purposes as well, unless we have specifically notified you otherwise.
Use of Personal Data for Marketing Purposes
We may use your personal data to offer you products or services, including special offers or entitlements that may be of interest to you or for which you may be eligible. Such marketing messages may be sent to you in various modes including but not limited to electronic mail, short message service, telephone calls and other mobile messaging services. In doing so, we will comply with the PDPA and other applicable data protection and privacy laws.
If we have an ongoing relationship with you and you have not indicated to us that you do not wish to receive telemarketing messages sent to your Singapore telephone number, we may send you telemarketing messages to your Singapore telephone number related to the subject of our ongoing relationship via short message service and other mobile messaging services (other than a voice or video call).
You may at any time request that we stop contacting you for marketing purposes via selected or all modes.
To find out more on how you can change the way we use your personal data for marketing purposes, or to request that we stop contacting you for marketing purposes, please contact us (please see the "How to contact us" section below).
Nothing in this section shall vary or supersede the terms and conditions that govern our relationship with you.
Disclosure and Sharing of Personal Data
We may from time to time and in compliance with all applicable laws on data privacy, disclose your personal data to any personnel of Epsilo or to third parties, whether located in Singapore or elsewhere, in order to carry out the purposes set out above. Please be assured that when we disclose your personal data to such parties, we require them to ensure that any personal data disclosed to them are kept confidential and secure.
We wish to emphasise that we do not sell personal data to any third parties and we shall remain fully compliant of any duty or obligation of confidentiality imposed on us under the applicable agreement(s) and/or terms and conditions that govern our relationship with you or any applicable law.
We may transfer, store, process and/or deal with your personal data outside Singapore. In doing so, we will comply with the PDPA and other applicable data protection and privacy laws.
Other Websites
Our website may contain links to other websites and resources which are not maintained by us. We have no control over and do not take any responsibility for these third-party websites and their personal data handling practices, and you are encouraged to review the personal data policies of such websites.
Retention of Personal Data
Your personal data is retained as long as the purpose for which it was collected remains and until it is no longer necessary for any other legal or business purposes.
How We Protect Your Data
We apply technical and organisational safeguards to protect all personal data, with heightened controls for sensitive data such as authentication credentials and data accessed from third-party accounts you connect to Epsilo:
- (a)Encryption in transit: all data exchanged with our services and with third-party APIs is encrypted using TLS 1.2 or higher.
- (b)Encryption at rest: personal data and access credentials (including OAuth tokens) are stored encrypted using industry-standard encryption (AES-256); credentials are never stored in plaintext.
- (c)Access controls: access to production systems and sensitive data is restricted to authorised personnel on a least-privilege, need-to-know basis, protected by multi-factor authentication and logged for audit.
- (d)Infrastructure security: our services run in access-controlled cloud environments with network isolation, firewalling and continuous monitoring.
- (e)Incident response: we maintain procedures to detect, investigate and remediate security incidents, and will notify affected users and authorities of any personal data breach where required by applicable law.
- (f)Review and testing: our security safeguards are reviewed regularly and updated as threats and technology evolve.
Google User Data
Certain Epsilo features let you connect your own Google account (for example, to send reports or notifications from your own Gmail address, or to export data to your own Google Sheets). When you choose to connect a Google account, we access only the data covered by the Google permission scopes you explicitly grant on the Google consent screen:
- (a)Gmail (send only): used solely to send email messages that you explicitly configure or trigger, from your own address. We do not read, modify or delete your email, and we do not request any read access to your mailbox.
- (b)Google Drive / Sheets (per-file): used solely to create, or access with your selection, the specific spreadsheet files you choose to use with Epsilo. We have no access to other files in your Drive.
- (c)Basic profile information (email address, name): used solely to identify which Google account you connected.
We store only the OAuth tokens needed to act on your behalf, encrypted at rest as described above. We do not store the content of messages sent through your account. Google user data is never sold, never used for advertising, and never used for any purpose other than providing the features you configure. It is not transferred to third parties except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition with prior notice to you.
Epsilo's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We do not use Google user data, including any data obtained through Google Workspace APIs, to develop, improve or train generalised artificial intelligence or machine learning models.
You can disconnect your Google account from Epsilo at any time, which deletes the stored tokens, or revoke Epsilo's access from your Google Account security settings. You may also request deletion of any Google user data we hold by contacting us at [email protected]; we honour such requests within 30 days.
AI Features and Sub-processors
The Epsilo Console includes an AI assistant. It is powered by Claude, a large language model provided by Anthropic PBC, which acts as our sub-processor for this feature. When you send a message to the assistant, the content of that message, any files you attach to it, and the advertising data needed to answer it are transmitted to Anthropic through Epsilo's backend so that a response can be generated and returned to you.
We do not send your name, email address, account identifier or workspace identity to Anthropic. Anthropic processes this data solely to generate the response and does not use data submitted through its API to train its models. We do not use your conversations to train any generalised artificial intelligence or machine learning model, our own or anyone else's.
AI features are opt-in. In the Epsilo mobile app the assistant is disabled until you accept the in-app AI disclosure, and you may withdraw that consent at any time from Account settings, which disables the assistant again. Where AI features are enabled, you can simply choose not to use the assistant.
The other sub-processors we rely on to operate the service are:
- (a)Anthropic PBC (United States) — AI assistant responses, as described above.
- (b)Okta, Inc. (Auth0) (United States) — authentication and identity. Processes your email address and login identifiers so you can sign in.
- (c)Functional Software, Inc. (Sentry) (United States) — crash and performance diagnostics. Receives error and performance telemetry, not the content of your conversations.
- (d)Apple Inc. (United States) — speech recognition, only where you use voice input on a device or language that does not support on-device recognition. Where on-device recognition is available, your audio never leaves your device.
None of these sub-processors is permitted to use your personal data for their own purposes, to sell it, or to use it for advertising. If we engage a new sub-processor for a materially different purpose, we will update this section.
You may delete your Epsilo account at any time, including from within the mobile app, which removes your account and its associated personal data as described in "Retention of Personal Data" above.
Access, Correction and Withdrawal
You may request access or make corrections to or withdraw your consent to any use of your personal data held by us. If you withdraw your consent to any or all use of your personal data, depending on the nature of your request, we may not be in a position to continue to provide our services to you.
Please contact us for details on how you may request access, correction to or withdrawal of your personal data.
How to Contact Us
To contact us on any aspect of this Policy or your personal data or to provide any feedback that you may have, please get in touch with our Data Protection Officer as follows:
Email: [email protected]
Amendments and Updates of Epsilo Privacy Policy
We may amend this Policy from time to time to ensure that this Policy is consistent with any developments to the way we use your personal data or any changes to the laws and regulations applicable to us. We will make available the updated policy on our website (https://epsilo.ai). All communications, transactions and dealings with us shall be subject to the latest version of this Policy in force at the time.
We may from time to time update this Policy. Updates will be posted on our website. By continuing to interact with us, subject to applicable law, you agree to be bound by the prevailing terms of the policy as so updated from time to time. Without prejudice to the foregoing, by accessing and using our website in any way, you represent and warrant that you have read, understand and consent to the collection, use and disclosure of your personal data as set out above.