Cirruslink AI
HomeCirrus TVToken FactoryGPUs

Cirruslink AI Privacy Policy

Last Updated: September 28, 2026

1. Collection of Personal Data

Cirruslink AI Privacy Policy

Cirruslink AI Privacy Policy

Last Updated: September 28, 2026

Cirruslink AI Pte. Ltd. (“Cirruslink,” “we,” “us,” or “our”) respects your privacy and is committed to protecting your personal data.

This Privacy Policy explains how we collect, use, disclose, store, transfer, and protect personal data when you access or use Cirruslink AI, including our websites at https://www.cirruslink.sg and https://www.cirruslink.sg/ai-apps, the model marketplace and the Cirruslink AI API, our AI applications, our creative canvas and other content creation tools, the public gallery (the “Gallery”), our creator program and our other related products and services (collectively, the “Services”).

This Privacy Policy is intended to provide the information required by the Personal Data Protection Act 2012 of Singapore (“PDPA”), the EU General Data Protection Regulation (“GDPR”), the UK GDPR, the California Consumer Privacy Act (“CCPA”) and other applicable data protection laws. Section 14 explains the rights you have under these laws.

This Privacy Policy is a notice of our practices and does not form part of any contract with you. Where applicable law requires your consent, we will ask for it before collecting, using, or disclosing your personal data for the relevant purpose, and you may withdraw it at any time.

1. About Cirruslink and This Privacy Policy

1.1 Who We Are

Cirruslink AI Pte. Ltd. (UEN 202508925H) is a company incorporated in Singapore with its registered office at 30 Pasir Panjang Road, #06-31, Mapletree Business City, Singapore 117440. Cirruslink is the controller responsible for the personal data described in this Privacy Policy, except where Section 1.3 explains that we act as a processor.

Cirruslink is a wholly-owned subsidiary of Cirruslink AI Technology Limited, a company incorporated in the British Virgin Islands whose shares are listed on the NASDAQ (ticker: SUPX) and whose principal operations are in Singapore. In this Privacy Policy, “Cirruslink Group” means Cirruslink AI Technology Limited and its subsidiaries.

You can contact our Data Protection Officer at privacy@cirruslink.sg. Where the law requires us to appoint a representative in the European Union or the United Kingdom under Article 27 of the GDPR or the UK GDPR, we will publish their contact details on this page (Section 20).

1.2 Scope of This Privacy Policy

This Privacy Policy applies to information collected through:

  • Our websites at https://www.cirruslink.sg and https://www.cirruslink.sg/ai-apps and our web applications;

  • Cirruslink AI accounts, including organization accounts;

  • The model marketplace, including model aggregation, the Cirruslink AI API, API keys and credits;

  • Content creation tools and AI applications, including video and story creation tools and agent workflows;

  • Model inference and AI generation services;

  • The Gallery and other sharing features;

  • Our creator program;

  • Customer support and communications;

  • Events, promotions, surveys, and other interactions with us.

This Privacy Policy does not apply to third-party websites, applications or services that we do not control, or to processing that third-party AI model providers carry out for their own purposes under their own terms and privacy policies (see Section 4.3).

Where a separate agreement, enterprise agreement, data processing agreement, or other contractual arrangement applies to your use of a particular Service, that agreement may supplement or, where expressly stated, take precedence over this Privacy Policy.

1.3 Our Role as Controller and Processor

Cirruslink is the controller of personal data relating to accounts, billing, support, security, marketing and our websites and, for individual users, of the User Content described in Section 2.4.

Where a business customer (for example, an organization that uses the Cirruslink AI API or an organization account under a business agreement) uses the Services to process personal data, Cirruslink processes that content on the customer's behalf as a processor (a “data intermediary” under the PDPA and a “service provider” under the CCPA) in accordance with our Data Processing Agreement (https://www.cirruslink.sg/privacy). In that case, the customer's own privacy notice applies and the customer is responsible for responding to your requests (see Section 18).

2. Information We Collect

We collect information that is reasonably necessary to provide, maintain, secure, and improve the Services.

The types of information we collect may include the following.

2.1 Account and Contact Information

When you create or use an account, we may collect:

  • Name;

  • Email address;

  • Phone number;

  • Username (which is shown publicly with any content you publish to the Gallery);

  • Account ID;

  • Password or authentication credentials;

  • Organization or company information;

  • Profile information;

  • Billing and account-related information;

  • Records of your acceptance of our terms, such as the version accepted, the date and time, your account ID and your IP address.

If you register or sign in through a third-party sign-in service, its provider shares with us your account identifier, name, email address and basic profile information (such as your profile picture), as permitted by your settings with that provider. We do not receive your password for that service. The provider's own processing is governed by its privacy policy.

2.2 Usage and Technical Information

When you access or use our Services, we may automatically collect certain technical and usage information, including:

  • IP address;

  • Browser type and version;

  • Operating system;

  • Device type and identifiers;

  • Network information;

  • Approximate location derived from IP address where reasonably necessary;

  • Pages, applications, and features accessed;

  • Date and time of access;

  • Session information;

  • Referring URLs;

  • Error logs;

  • Performance and diagnostic information;

  • Other technical information necessary to operate and secure the Services.

2.3 Token, API and Model Service Information

If you use our Token, API, model aggregation, or inference services, we may collect and process:

  • API account identifiers;

  • API keys and authentication credentials;

  • Selected models and providers, and your routing preferences and Custom Data Policy settings;

  • API request metadata;

  • Request timestamps;

  • Request and response status;

  • Token usage and consumption;

  • Input and output token counts;

  • Quota and rate-limit information;

  • Usage statistics;

  • Latency and performance metrics;

  • Error and retry information;

  • Billing and transaction information;

  • Other information reasonably necessary to operate, monitor, secure, and bill the API Services.

Where technically appropriate, API credentials may be encrypted, hashed, or otherwise securely stored.

2.4 User Content

Our Services may allow you to create, upload, submit, transmit, store, or otherwise process content.

This may include:

  • Text;

  • Prompts and instructions;

  • Images;

  • Videos;

  • Audio;

  • Documents;

  • Files;

  • Code;

  • Data provided to AI models;

  • AI-generated outputs;

  • Canvas content;

  • Workflows;

  • Agent configurations;

  • Node configurations;

  • Comments and collaboration content;

  • Other materials that you voluntarily provide or create through the Services.

We refer to this information collectively as “User Content.” User Content may include personal data about you or other people, including images, video or audio of people's faces or voices (see Section 4.5).

2.5 Content Creation Tools and AI Applications Data

When you use our content creation tools or AI applications, we may collect and process information associated with your projects, including:

  • Canvas names and project information;

  • Nodes and connections;

  • Prompts and instructions;

  • Uploaded assets;

  • Generated images, videos, audio, and text;

  • Workflow configurations;

  • AI model and tool selections;

  • Execution history;

  • Collaboration information;

  • Comments and shared content;

  • Project permissions and sharing settings;

  • Other information necessary to provide the relevant features.

2.6 Payment and Billing Information

If you purchase credits, Tokens, subscriptions, or other paid Services, we may collect information necessary to process and manage the transaction, such as:

  • Transaction records;

  • Subscription information;

  • Invoice information;

  • Payment status;

  • Billing address;

  • Purchase history.

Card and other payment details are collected and processed directly by our third-party payment service providers. We do not receive or store full card numbers or security codes. Our payment service providers act as independent controllers under their own privacy policies and may provide us with limited information, such as the card brand, the last four digits and the payment status. If you turn on auto-recharge, we keep your recharge threshold and amount.

2.7 Communications

If you contact us, we may collect information contained in your communications, including:

  • Your name and contact information;

  • Support requests;

  • Feedback;

  • Technical information;

  • Attachments;

  • Records of communications with us.

2.8 Information from Third Parties

We may receive information from third parties, including:

  • Authentication providers;

  • Payment service providers;

  • AI model providers (for example, error, safety or moderation signals relating to your requests);

  • Cloud infrastructure providers;

  • Analytics providers;

  • Business partners;

  • Organizations that administer your account;

  • Identity-verification and sanctions-screening providers and public sources, where we carry out compliance checks;

  • Other service providers that support the Services.

We will handle such information in accordance with applicable law and this Privacy Policy.

2.9 Gallery and Creator Program Information

If you publish content to the Gallery, we process the works, prompts, workflows and canvas projects you choose to publish, your username and profile, and engagement information (such as views, likes and clones). If you join the creator program, we also process the information you provide to apply and take part, such as your name, contact details and portfolio and, where the program offers payments, payout and tax information, as well as information about the performance of your works, canvas projects, reusable prompts, workflows and similar items.

2.10 Compliance Information

Where required for export-control, sanctions, anti-money laundering or fraud-prevention purposes (for example, for business customers, high-volume API use or payouts to creators), we may collect identity and business verification information, such as the information described in our Export Compliance Terms (https://www.cirruslink.sg/terms), and screen it against sanctions and restricted-party lists.

4. AI Services and User Content

Our Services include AI model aggregation, AI inference, content generation, and other AI-powered features.

When you use these Services, we may process your User Content in order to provide the requested functionality.

For example, when you submit a prompt and image to an AI model, we may process that information to:

  • Receive your request;

  • Determine the requested model or service;

  • Route the request to the applicable model provider or to Cirruslink-hosted infrastructure;

  • Process the request;

  • Return the resulting output to you;

  • Record necessary technical and usage information.

4.1 AI Inputs and Outputs

Depending on the Service you use, User Content may include prompts, uploaded files, model inputs, and AI-generated outputs.

We process such information only as reasonably necessary to provide, maintain and secure the Services, to moderate content and to comply with law, subject to any settings you choose (such as Custom Data Policies) and any additional terms applicable to the Service.

4.2 Use of User Content for AI Model Training

Cirruslink does not use your prompts, uploads or outputs to train or improve AI models, whether our own or those of third parties, unless you opt in. We may use aggregated and de-identified usage telemetry, such as token counts, latency and error rates, that does not include the content of your requests.

If we offer an opt-in for training or evaluation, we will explain it clearly when we ask, and you may withdraw your opt-in at any time for future use. Prompt logging, if offered, is off by default and applies only if you turn it on.

4.3 Model Providers, Routing and Processing Locations

The model marketplace and our AI applications give access to models from several third-party providers, which are listed on the Model Terms and Provider Disclosures page. Some models run on Cirruslink-hosted infrastructure; others are called through the provider's own API (“upstream API”).

When you use a model provided through an upstream API, your prompts, files and other inputs, the outputs and related request metadata are sent to the provider of the model you select or, only if you have turned on automatic routing or fallback, another provider that your Custom Data Policies permit. We do not move a request to a different hosting mode or to a processing location in another country unless you have allowed this in your settings. When you use a Cirruslink-hosted model, your request is processed on infrastructure operated by or for Cirruslink and is not sent to the model's developer. Where a model is available both Cirruslink-hosted and through an upstream API, we use the Cirruslink-hosted option unless your settings choose otherwise.

Each model's provider, hosting mode, processing location and retention and training practices are disclosed in the Model Terms and Provider Disclosures (https://www.cirruslink.sg/terms), to which our Sub-processor List (https://www.cirruslink.sg/privacy) refers. Where a provider offers settings that prevent training on, or limit retention of, customer content, we use commercially reasonable efforts to enable them where available. A provider may also process information under its own terms and privacy policy, as disclosed on that page.

Some providers process data in countries outside your own, whose laws may not provide a level of protection equivalent to that in your country and may permit government authorities to access data. You can use Custom Data Policies to restrict routing to the providers and locations you trust, and we encourage you to review the disclosures before submitting confidential, proprietary or sensitive information. For users in the EEA and the UK, we rely on the safeguards described in Section 13 and may restrict access to models whose providers do not support them.

4.4 Confidential Information

You are responsible for determining whether the information you submit to the Services is appropriate for processing through the selected AI model or third-party provider.

You should not submit highly sensitive personal information, confidential credentials, trade secrets, or other information that you are not authorized to disclose unless the relevant Service and contractual arrangements expressly support such use.

4.5 Faces, Voices and Likeness

Some features let you generate or edit images, video or audio that depict people, for example to create consistent characters or voices. You must not upload another person's face, voice or other likeness to clone, imitate or generate content depicting them unless you have their consent and any other permission required by law (see the Content and Community Policy).

We process such content only to provide the features you request, to moderate content and to comply with law. We do not use it to identify individuals. If a feature uses biometric identifiers or information, we will provide any notice and obtain any consent required by law (for example, under the Illinois Biometric Information Privacy Act) before using it.

5. Content Creation Tools, Collaboration and the Gallery

Our content creation tools allow users to create, organize, process, and share AI-generated and user-provided content.

If you choose to collaborate with others or share a canvas, certain information may become accessible to the people or organizations with whom you share it.

Depending on your sharing settings, this may include:

  • Canvas content;

  • Uploaded files;

  • AI-generated content;

  • Prompts;

  • Workflows;

  • Comments;

  • Project metadata;

  • Collaboration information.

You are responsible for configuring appropriate sharing and access permissions and for ensuring that you have the necessary rights to share the content.

5.1 Public Gallery and Sharing

If you publish content to the Gallery or otherwise make it public, the published content, including works, prompts, workflows and canvas projects, together with your username and profile information, will be visible to anyone, may be recommended to other users, may be cloned by other users to recreate it within Cirruslink AI, and may be indexed by search engines. Please do not publish personal data about yourself or others that you do not want to be public.

You can unpublish or delete your published content at any time through the Services, where available, or by contacting us. We will then stop displaying it, but we cannot recall copies or clones that other users have already made, and copies may remain in backups for a limited period (Section 10). Information about how we rank and recommend Gallery content is in the Content and Community Policy.

5.2 Creator Program

If you take part in the creator program, we use your information to administer your participation, display your works, canvas projects, reusable prompts, workflows and similar items, measure their performance and, where applicable, calculate and make payments and meet tax and compliance obligations. The Creator License Agreement (https://www.cirruslink.sg/terms) also applies.

5.3 Organization Accounts

If you use an organization account, the organization's administrators can see and manage information associated with your use of the organization's workspace, which may include your profile, usage, API keys, billing information and content in shared projects. See Section 18.

6. Token, API and Authentication Information

If you use our API or Token Services, you are responsible for protecting your API keys and authentication credentials.

You should:

  • Keep API keys confidential;

  • Avoid exposing API keys in publicly accessible code;

  • Rotate or revoke compromised credentials;

  • Notify us promptly if you believe an account or API key has been compromised.

We may temporarily suspend or restrict API access where reasonably necessary to protect the Services, your account, or other users.

We may retain API request metadata, usage information, and related technical records for security, billing, troubleshooting, compliance, and service operation, for the periods described in Section 10.

8. Cookies and Similar Technologies

We use cookies, local storage and similar technologies to operate the Services and remember your preferences. These include strictly necessary technologies, such as session and authentication cookies, and functional technologies, such as a cookie that remembers your language. Any analytics or marketing technologies are used only where the law allows and, where required, with your consent. Our Cookie Policy (https://www.cirruslink.sg/privacy) describes the technologies we use and explains your choices.

These technologies may include:

Essential Technologies

Used to:

  • Authenticate users;

  • Maintain sessions;

  • Secure accounts;

  • Remember essential settings;

  • Provide core functionality.

Analytics Technologies

If used, to:

  • Understand how users interact with the Services;

  • Measure performance;

  • Identify errors;

  • Improve products and user experience.

Marketing Technologies

If used and where permitted by law, to:

  • Measure marketing effectiveness;

  • Provide relevant promotional content;

  • Understand interactions with marketing communications.

You may manage cookies through your browser or device settings. Certain features may not function properly if essential cookies are disabled.

In the EEA, the United Kingdom and wherever else the law requires it, we will obtain your consent before using non-essential cookies and similar technologies. Where applicable, we treat Global Privacy Control signals as a request to opt out of any “sale” or “sharing” of personal information. We do not respond to Do Not Track signals.

18. Corporate and Enterprise Customers

If you access Cirruslink Services through an organization or enterprise account, the organization may control or administer your account and may have access to information associated with your use of the Services, such as your profile, usage and billing information, API keys and content in shared projects.

In such circumstances, the organization's privacy policy, contractual agreement, or data processing agreement with Cirruslink may also apply.

Where Cirruslink processes personal data on behalf of a business customer, we act as its processor under our Data Processing Agreement (https://www.cirruslink.sg/privacy) or the applicable agreement with that customer, and the customer is responsible for responding to your requests.

19. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect:

  • Changes to our Services;

  • Changes to our data processing practices;

  • Changes in applicable laws or regulations;

  • Changes to our business operations.

When we make changes, we will update the “Last Updated” date at the top of this Privacy Policy.

If we make material changes, we will notify you in advance by email or through the Services and, where applicable law requires your consent, we will ask for it.

We encourage you to review this Privacy Policy periodically.

Cookie Policy

COOKIE POLICY

Effective Date: September 28, 2026

1. INTRODUCTION

This Cookie Policy ("Policy") explains how Cirruslink AI Pte. Ltd. (UEN 202508925H) ("Cirruslink," "we," "us," or "our") uses cookies and similar technologies on the following websites (together, the "Sites"): https://www.cirruslink.sg and https://www.cirruslink.sg/ai-apps ("Cirruslink AI").

This Policy supplements the privacy policy for the Site you use: the Cirruslink AI Privacy Policy (https://www.cirruslink.sg/privacy) (each, the "Privacy Policy"). The Privacy Policy explains how we process personal data, your rights and how to contact us. Capitalized terms used but not defined in this Policy have the meanings given in the applicable Privacy Policy. This Policy is a notice and does not form part of any contract with you.

Strictly necessary cookies are used without consent because the Sites cannot work without them. For all other cookies, we will ask for your prior consent in the European Economic Area, the United Kingdom and wherever else the law requires it. Elsewhere, we rely on this notice, and you can opt out at any time as described in Section 5.

2. WHAT ARE COOKIES

Cookies are small text files that are stored on your device (computer, tablet, or mobile phone) when you visit a website or use a web-based application. Each cookie typically contains the name of the domain from which the cookie originated, a cookie value, and an expiration date.

Cookies serve several purposes:

Remembering information about you to make your experience more convenient

Understanding how you use our Services to improve their functionality and performance

Securing your account and protecting against fraud

Delivering personalized content and, where used, advertisements

Analyzing usage patterns to enhance user experience

Cookies can be classified into two main categories:

Session Cookies: These cookies are deleted when you close your browser. They are used to maintain your session and ensure continuity during your visit to our Services.

Persistent Cookies: These cookies remain on your device for a specified period or until you manually delete them. They are used to remember your preferences and information across multiple visits.

Additionally, cookies can be categorized as:

First-Party Cookies: These are set and controlled directly by Cirruslink on our domains. They are used to store information about your preferences and interactions with our Services.

Third-Party Cookies: These are set by third-party services (such as sign-in, analytics or advertising providers) that we allow to operate on our Sites. Some third-party cookies can be used to track your activity across multiple websites.

3. TYPES OF COOKIES WE USE

We group cookies into the following categories. Section 4 describes the types of cookies in each category.

3.1 Strictly Necessary Cookies

These cookies are essential for the operation of our Services and cannot be disabled without significantly impairing functionality. They include:

Authentication and session management (e.g., maintaining your login session)

Security features, including CSRF (Cross-Site Request Forgery) protection

Load balancing to ensure optimal server performance

Cookie consent preferences to remember your choices

Essential security and fraud prevention mechanisms

Third-party sign-in, where you choose to use a third-party sign-in service

Strictly necessary cookies do not require your consent. You can block them in your browser settings, but parts of the Sites, such as signing in, will then not work.

3.2 Functional Cookies

These cookies enhance the functionality of our Services by remembering your preferences and settings. They include:

Language and region preferences

Dashboard and interface customization settings

Remembered user preferences (e.g., theme selection)

Accessibility settings

Functional cookies remember choices you make, such as your language. Where the law allows, we set them without asking for consent because they provide a feature you have requested. You can delete or block them in your browser settings, but the Sites will then not remember your preferences.

3.3 Performance and Analytics Cookies

These cookies collect information about how you use our Services, helping us understand user behavior and improve performance. They include:

Page visit statistics and traffic patterns

Service usage and feature adoption metrics

Performance monitoring and error detection

User journey and interaction analysis

Load time and system performance metrics

Any analytics cookies, whether set by us or by our analytics providers, are used only where the law allows and, where the law requires it, with your consent, which you can withdraw at any time.

3.4 Advertising and Marketing Cookies

These cookies are used to deliver targeted advertisements and measure the effectiveness of our marketing campaigns. If we use advertising cookies on the Sites, they may include:

Cross-site tracking for targeted advertising

Retargeting and remarketing campaigns

Campaign effectiveness and conversion tracking

Audience segmentation and personalization

Social media integration and sharing

Where the law requires it, we will use advertising cookies only with your prior consent. Where advertising cookies involve a "sale" or "sharing" of personal information under US state privacy laws, you can opt out as described in Section 5.4.

4. COOKIES WE USE

The table below describes the types of cookies and similar technologies that we use, or may use, on the Sites:

TypeSet byPurposeCategoryDuration
Session and authentication cookies (all Sites)CirruslinkKeep you signed in, maintain your session and protect against cross-site request forgery and other attacksStrictly necessarySession or up to 12 months
Third-party sign-in cookies (where you choose to use a third-party sign-in service)The third-party sign-in providerEnable the third-party sign-in service you choose to work correctly, for example by recording the state of its sign-in promptStrictly necessarySession or as set by the provider
Consent preference cookies (all Sites, where we use a consent tool)CirruslinkRecord your cookie choicesStrictly necessary12 months
Preference cookies and local storage (all Sites)CirruslinkRemember your language and other preferencesFunctionalUp to 12 months or, for local storage, until you clear your browser storage
Analytics cookies (only if used)Cirruslink or our analytics providersDistinguish visitors and sessions to produce aggregated usage statistics and product analyticsAnalytics (consent where required)Up to 2 years
Advertising cookies (only if used)Our advertising partnersMeasure advertising conversions and build audiences for advertising on other websitesAdvertising (consent where required; may be "sharing" under US state privacy laws)Up to 3 months

We will update this table if we add or remove types of cookies. Durations are approximate; you can see the cookies set on your device in your browser settings.

5. HOW TO MANAGE COOKIES

5.1 Cookie Consent Tool

Where the law requires consent, we will provide a cookie consent tool and will not set non-essential cookies until you have made a choice. The tool will allow you to:

Accept all cookies

Reject non-essential cookies

Customize your cookie preferences

Access this Cookie Policy for more information

You will be able to change your choices at any time through the cookie settings link in the footer of the Sites. Withdrawing your consent does not affect the lawfulness of processing before withdrawal.

5.2 Browser Settings

You can also manage cookies through your browser. Most browsers let you view, block and delete cookies in their settings; see your browser's help pages.

Local storage: To clear information stored in local storage, clear the site data for the relevant Site in your browser settings.

Please note that disabling cookies may limit the functionality of our Services and your user experience.

5.3 Do Not Track Signals

Some browsers include a "Do Not Track" feature. Currently, there is no industry standard for recognizing and implementing Do Not Track signals, and Cirruslink does not respond to Do Not Track browser signals. However, you can use other cookie management tools described in this Policy to control our use of cookies.

5.4 Global Privacy Control

If your browser sends a Global Privacy Control (GPC) signal, we will treat it as a request to opt out of the "sale" or "sharing" of personal information (including for cross-context behavioral advertising) for that browser or device and, where we can associate the browser with your account, for your account, as required by applicable US state privacy laws. The Privacy Policy explains whether we sell or share personal information.

6. THIRD-PARTY COOKIES

Some cookies on the Sites are placed by third parties:

Third-party sign-in services: If you choose to sign in through a third-party sign-in service, its provider may set cookies needed for that service to work. The provider's own processing is governed by its privacy policy.

Analytics and Advertising Providers: If we use analytics providers or advertising partners, they may set the cookies described in Section 4 (only where the law allows and, where required, with your consent) and may process the information they collect under their own privacy policies.

Third parties' use of the information they collect is governed by their own privacy and cookie policies, which we encourage you to review.

7. SIMILAR TECHNOLOGIES

In addition to cookies, we may use other similar technologies to store information on your device and enhance your experience:

Web Beacons and Pixels: Our marketing emails may contain small image files (pixels) that tell us whether an email was opened. Where the law requires consent, we will ask for it, and you can block pixels by turning off automatic image loading in your email client.

Local Storage: We use browser local storage (such as HTML5 localStorage) to store certain preferences on your device, for example your language preference. You can clear local storage through your browser settings.

Device Fingerprinting: We do not use device fingerprinting to track you across websites. Our third-party payment service providers may collect device and browser information on payment pages to prevent fraud, as described in their privacy policies.

8. CHANGES TO THIS POLICY

Cirruslink may update this Cookie Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will post the updated version on the Sites and change the date at the top of this Policy. Where a change requires your consent, for example a new category of non-essential cookies, we will ask for it through the consent tool.

9. CONTACT US

If you have questions, concerns, or requests regarding this Cookie Policy or our cookie practices, please contact us:

Email: privacy@cirruslink.sg

Website: https://www.cirruslink.sg

Company: Cirruslink AI Pte. Ltd. (UEN 202508925H), 30 Pasir Panjang Road, #06-31, Mapletree Business City, Singapore 117440

We will respond to your inquiry in a timely manner and assist you with any cookie-related questions or concerns.

Data Processing Agreement

DATA PROCESSING AGREEMENT

Cirruslink AI

Effective Date: September 28, 2026

PREAMBLE

This Data Processing Agreement ("DPA") is entered into between Cirruslink AI Pte. Ltd. (UEN 202508925H), a company incorporated in Singapore with its registered office at 30 Pasir Panjang Road, #06-31, Mapletree Business City, Singapore 117440 ("Cirruslink" or "Processor"), and the customer that has entered into the Agreement with Cirruslink ("Customer" or "Controller"). It forms part of the agreement under which Cirruslink provides the Services to Customer, being the Cirruslink AI Terms of Use (https://www.cirruslink.sg/terms) together with any business or enterprise agreement, or any other written agreement between the parties that incorporates this DPA (the "Agreement"). This DPA is published at https://www.cirruslink.sg/privacy.

This DPA applies where, and to the extent that, Cirruslink processes Customer Personal Data on behalf of Customer in providing the Services, as a processor under the GDPR or the UK GDPR, a data intermediary under the PDPA, a service provider under the CCPA, or in an equivalent role under other Applicable Data Protection Laws. It does not apply to personal data that Cirruslink processes as a controller, such as account, billing, support, security, know-your-customer and export-compliance data, which is described in the applicable privacy policy. Where Customer acts as a processor on behalf of a third-party controller, Cirruslink acts as Customer's sub-processor, and references to Customer as "Controller" are to be read accordingly.

1. DEFINITIONS

Adequacy Decision: A decision of the European Commission, adequacy regulations of the United Kingdom, or a decision of the Swiss Federal Council, finding that a country provides an adequate level of data protection.

Applicable Data Protection Laws: All laws and regulations relating to data protection and privacy that apply to the processing of Customer Personal Data under this DPA, which may include the PDPA, European Data Protection Laws and the CCPA.

CCPA: The California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020, and its implementing regulations.

Customer Data: All data, content and materials, including prompts, inputs and outputs, that Customer or its users submit to, store in or process through the Services, as further described in the Agreement (in the Cirruslink AI Terms of Use, "User Content").

Customer Personal Data: Any personal data contained in Customer Data that Cirruslink processes on behalf of Customer in providing the Services.

Data Subject: The identified or identifiable individual to whom Customer Personal Data relates.

DPIA: A Data Protection Impact Assessment conducted in accordance with GDPR Article 35 or equivalent requirements under other Applicable Data Protection Laws.

European Data Protection Laws: The GDPR, the UK GDPR and the Swiss FADP, together with the laws implementing or supplementing them.

GDPR: Regulation (EU) 2016/679 (General Data Protection Regulation).

PDPA: The Personal Data Protection Act 2012 of Singapore and its subsidiary legislation.

Processor, Controller and process: Have the meanings given in the GDPR and include the equivalent concepts under other Applicable Data Protection Laws (such as "service provider" and "business" under the CCPA, and "data intermediary" and "organisation" under the PDPA).

Region: The data-center region selected by Customer for a Service, where the Service offers a choice of region.

Restricted Transfer: A transfer of Customer Personal Data that is subject to European Data Protection Laws to a country that is not covered by an Adequacy Decision.

Security Breach: A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data transmitted, stored or otherwise processed by Cirruslink or its Sub-processors.

Services: The services that Cirruslink provides to Customer under the Agreement, including Cirruslink AI, the model marketplace and the Cirruslink AI API (https://www.cirruslink.sg).

Standard Contractual Clauses (SCCs): The standard contractual clauses for the transfer of personal data to third countries set out in the Annex to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as completed in Annex 2.

Sub-processor: Any third party, including a Cirruslink Group company, that Cirruslink engages to process Customer Personal Data. A model provider is a Sub-processor where Customer Personal Data is sent to it through its upstream API to provide a model that Customer selects, directly or through its routing settings.

Sub-processor List: The list, published at https://www.cirruslink.sg/privacy, that describes the Sub-processors by category, as updated in accordance with Section 4.3.

Cirruslink Group: Cirruslink AI Technology Limited and its subsidiaries.

Swiss FADP: The Swiss Federal Act on Data Protection of 25 September 2020 and its ordinances.

UK Addendum: The International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (version B1.0) issued by the UK Information Commissioner under section 119A of the UK Data Protection Act 2018, as completed in Annex 2.

UK GDPR: The GDPR as it forms part of the law of the United Kingdom under the European Union (Withdrawal) Act 2018, read with the UK Data Protection Act 2018.

2. PROCESSING OF PERSONAL DATA

2.1 Scope and Roles

As between the parties, Customer is the Controller (or, where it acts for a third-party controller, a Processor) and Cirruslink is a Processor of Customer Personal Data. Where Customer is a Processor, Customer warrants that its instructions, including its appointment of Cirruslink as a sub-processor, are authorized by the relevant controller, and Customer shall be the single point of contact for Cirruslink; Cirruslink need not interact directly with that controller unless required by law. Each party shall comply with the Applicable Data Protection Laws that apply to it in connection with this DPA.

2.2 Cirruslink Processing Obligations

Cirruslink shall:

Process Customer Personal Data only on Customer's documented instructions (Section 2.5);

Ensure that persons authorized to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (Section 2.6);

Implement the technical and organizational measures described in Section 5.1 and Annex 3;

Engage Sub-processors only in accordance with Section 4;

Assist Customer, taking into account the nature of the processing, in responding to requests from Data Subjects (Section 3.1);

Assist Customer with DPIAs and prior consultations with supervisory authorities (Section 5.3), and with its security and breach-notification obligations (Sections 5.1 and 5.2);

Notify Customer of Security Breaches in accordance with Section 5.2;

Delete or return Customer Personal Data in accordance with Section 7;

Make available to Customer the information necessary to demonstrate compliance with this DPA (Section 5.4); and

Allow for and contribute to audits in accordance with Sections 5.4 and 5.5.

Cirruslink shall inform Customer without undue delay if, in its opinion, an instruction infringes European Data Protection Laws, and may suspend the processing concerned until the instruction is confirmed or modified.

2.3 Customer Processing Obligations

Customer shall:

Ensure that it has a lawful basis for, and has provided all notices and obtained all consents required for, the processing of Customer Personal Data under the Agreement, including where Customer or its users send Customer Personal Data to models that they select;

Ensure that its instructions comply with Applicable Data Protection Laws;

Comply with all Applicable Data Protection Laws regarding the collection and provision of Customer Personal Data, and determine whether the Services, including the Regions and models it selects, are appropriate for the Customer Personal Data it processes, including any special categories of personal data;

Promptly notify Cirruslink of any changes to processing instructions;

Provide accurate and complete information regarding the processing of personal data when requested.

2.4 Details of Processing

The details of the processing of Customer Personal Data are set out in Annex 1. The parties may update Annex 1 from time to time by mutual agreement to reflect any changes in the processing activities.

2.5 Instructions

The Agreement, this DPA and Customer's use and configuration of the Services (including its choice of Regions, models and routing settings such as Custom Data Policies) are Customer's complete documented instructions to Cirruslink. Any additional instructions require Cirruslink's written agreement and may be subject to additional fees. Cirruslink may process Customer Personal Data other than on Customer's instructions where required to do so by applicable law, in which case Cirruslink shall inform Customer of that legal requirement before processing, unless the law prohibits this on important grounds of public interest.

2.6 Confidentiality

Cirruslink shall treat Customer Personal Data as confidential and shall ensure that its personnel, and those of its Sub-processors, who are authorized to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and access Customer Personal Data only as needed to provide the Services.

2.7 No Training; Service Telemetry

Cirruslink shall not use Customer Personal Data to train or improve artificial intelligence models, or for any other purpose of its own, unless Customer opts in in writing or through a clearly identified setting in the Services. Cirruslink may generate service telemetry derived from the operation of the Services (such as utilization, performance and error metrics) that does not include the content of Customer Data and does not identify Customer or any Data Subject, and may use it to operate and improve the Services.

2.8 CCPA Service Provider Terms

Where the CCPA applies to Customer Personal Data, Cirruslink acts as a service provider (or, where applicable, a contractor) and processes Customer Personal Data only for the limited and specified business purposes of providing, securing and supporting the Services as described in the Agreement and Annex 1. Cirruslink shall not:

Sell or share Customer Personal Data (as "sell" and "share" are defined in the CCPA);

Retain, use or disclose Customer Personal Data for any purpose, including any commercial purpose, other than those business purposes, or outside the direct business relationship between Cirruslink and Customer, except as permitted by the CCPA; or

Combine Customer Personal Data with personal information that Cirruslink receives from or on behalf of another person, or collects from its own interactions with the consumer, except as permitted by the CCPA.

Cirruslink shall comply with the obligations that apply to it under the CCPA, provide the same level of privacy protection as the CCPA requires of Customer, assist Customer in responding to consumer requests in accordance with Section 3.1, and notify Customer if it determines that it can no longer meet its obligations under the CCPA. Customer may take reasonable and appropriate steps to ensure that Cirruslink uses Customer Personal Data consistently with Customer's obligations under the CCPA, including through the information and audit rights in Section 5, and, on notice, to stop and remediate any unauthorized use. Cirruslink certifies that it understands and will comply with the restrictions in this Section 2.8.

2.9 PDPA

Where the PDPA applies, Cirruslink processes Customer Personal Data as a data intermediary and shall, in respect of that data, make reasonable security arrangements to protect it (Section 5.1 and Annex 3), cease to retain it when retention is no longer necessary for the purposes of the Agreement (Section 7), and notify Customer of a data breach without undue delay (Section 5.2). Customer remains responsible for its own obligations under the PDPA, including any notification to the Personal Data Protection Commission and affected individuals.

3. ASSISTANCE OBLIGATIONS

3.1 Data Subject Requests

Taking into account the nature of the processing, Cirruslink shall assist Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling Customer's obligation to respond to requests from Data Subjects to exercise their rights under Applicable Data Protection Laws. Where the functionality of the Services allows, Customer can access, correct, export and delete Customer Personal Data itself. If Cirruslink receives a request directly from a Data Subject that identifies Customer, Cirruslink shall promptly forward it to Customer and shall not respond to it, except to direct the Data Subject to Customer, unless required by law. Cirruslink shall respond to Customer's reasonable requests for further assistance within 10 business days and may charge reasonable costs for assistance that goes beyond the functionality of the Services, except where the request results from Cirruslink's breach of this DPA.

3.2 Legal Requests

If Cirruslink receives a legally binding request from a public authority for disclosure of Customer Personal Data, Cirruslink shall, unless legally prohibited, promptly notify Customer so that Customer can seek a protective order or other remedy and, where appropriate, shall first seek to redirect the authority to Customer. Cirruslink shall review the legality of the request, challenge it where, after careful assessment, it concludes that there are reasonable grounds to consider it unlawful, and disclose only the minimum Customer Personal Data required. Subject to the SCCs where they apply, this Section does not restrict Cirruslink's compliance with export-control, sanctions and other laws that apply to it, as described in its Law Enforcement Policy (https://www.cirruslink.sg/privacy).

4. SUB-PROCESSORS

4.1 General Authorization

Customer grants Cirruslink general written authorization to engage Sub-processors, including Cirruslink Group companies, as described in the Sub-processor List, to process Customer Personal Data. Where Customer, directly or through its routing settings, selects a model that is provided through a third-party provider's upstream API, Customer authorizes Cirruslink to transmit the relevant Customer Personal Data to that provider, which acts as a Sub-processor for that data.

4.2 Sub-processor List

The authorized Sub-processors are described by category, with their functions and locations, in the Sub-processor List at:

https://www.cirruslink.sg/privacy

The Sub-processor List describes, by category, the Cirruslink Group companies, the infrastructure and service Sub-processors and the model providers that may process Customer Personal Data, and, for information only, recipients that act as independent controllers, such as payment service providers. The names of current Sub-processors are available to Customer on request to privacy@cirruslink.sg. Cirruslink is the Processor and is not listed as its own Sub-processor.

4.3 Sub-processor Changes

Cirruslink shall give Customer at least 14 days' notice before engaging a new Sub-processor, identifying the new Sub-processor and its function and location, by notifying customers who have subscribed to updates (customers can subscribe by emailing privacy@cirruslink.sg or, where available, through the console) and by updating the Sub-processor List and its "Last Updated" date. Customer may object in writing on reasonable grounds relating to data protection within that 14-day period, and the parties shall then discuss the objection in good faith. If they cannot resolve it within 14 days after the objection, Customer may, as its sole and exclusive remedy, terminate the affected Services by written notice, and Cirruslink shall refund any prepaid fees for the terminated Services covering the period after termination, on a pro-rata basis. Where the new Sub-processor is a model provider, Customer may instead stop using, or restrict routing to, the relevant model (for example, through Custom Data Policies).

Model providers. Cirruslink identifies each model provider on the Model Terms and Provider Disclosures page (to which the Sub-processor List refers for model providers) before its model is made available. A model provider processes Customer Personal Data only when Customer or its users select that provider's model, directly or through routing settings that Customer controls. If Customer enables or selects a newly listed model before the 14-day notice period has ended (for an organization account, through an administrator or a user whom the administrators allow to enable new models), that selection is Customer's specific authorization of the provider for those requests and waives the rest of the notice period for that provider (including for the purposes of Clause 9(a) of the SCCs); where the Services offer this option, Customer's administrators may prevent this by restricting new models in their Custom Data Policies. Cirruslink shall not replace the provider, or change the hosting mode, of a model that Customer has used in the preceding 90 days without giving at least 14 days' notice under this Section 4.3; where such a change is required by law or for security reasons, Cirruslink may instead suspend the model immediately and shall notify Customer as soon as practicable. Cirruslink shall update the Model Terms and Provider Disclosures page within a reasonable time after becoming aware of a material change to a model provider's processing locations or data practices, and Customer may stop using, or restrict routing to, the affected model.

4.4 Sub-processor Obligations

Cirruslink shall impose on each Sub-processor, by written contract, data protection obligations that offer at least the same level of protection for Customer Personal Data as this DPA, to the extent applicable to the services provided by that Sub-processor. Where a model provider's terms do not meet this requirement, Cirruslink shall identify the affected model on the Model Terms and Provider Disclosures page (https://www.cirruslink.sg/terms), and Customer shall not use that model to process Customer Personal Data; Cirruslink may restrict such use.

4.5 Liability

Cirruslink remains liable to Customer for the performance of each Sub-processor's obligations under this DPA as if they were its own, subject to Section 8.2.

5. SECURITY AND COMPLIANCE

5.1 Security Measures

Cirruslink shall implement and maintain the technical and organizational measures described in Annex 3, which are designed to protect Customer Personal Data against Security Breaches and to ensure a level of security appropriate to the risk. Cirruslink may update those measures from time to time, provided that the overall level of protection is not materially reduced. Security is a shared responsibility: Customer is responsible for securing its accounts, credentials, API keys and SSH keys, configuring its instances, networks and access controls, encrypting and backing up its Customer Data, and choosing Regions and models appropriate to its data.

5.2 Security Breaches

Cirruslink shall notify Customer without undue delay after becoming aware of a Security Breach. The notice shall describe, to the extent then known: (a) the nature of the Security Breach, including the categories and approximate number of Data Subjects and records concerned; (b) its likely consequences; (c) the measures taken or proposed to address it and to mitigate its possible adverse effects; and (d) a contact point for further information. Where information is not available at the time of the first notice, Cirruslink shall provide it in phases as it becomes available. Cirruslink shall take reasonable steps to contain and investigate the Security Breach and shall provide reasonable assistance to Customer in meeting Customer's obligations to notify supervisory authorities and Data Subjects, such as notifying the Personal Data Protection Commission within 3 calendar days after assessing a breach as notifiable or a supervisory authority within 72 hours. Notifying or responding to a Security Breach is not an acknowledgement of fault or liability by Cirruslink. Unsuccessful attempts or activities that do not compromise the security of Customer Personal Data, such as pings, port scans or failed log-in attempts, are not Security Breaches.

5.3 Data Protection Impact Assessments

Taking into account the nature of the processing and the information available to it, Cirruslink shall provide reasonable assistance to Customer in carrying out any DPIA required by Applicable Data Protection Laws and any related prior consultation with a supervisory authority, primarily by making available the documentation described in Section 5.4. Cirruslink shall respond to reasonable requests for further information within 10 business days and may charge reasonable costs for assistance beyond that documentation.

5.4 Security Documentation

On Customer's written request, no more than once in any 12-month period (or more often following a Security Breach or where a supervisory authority requires it), Cirruslink shall make available to Customer, subject to appropriate confidentiality obligations:

Summaries of any certifications or third-party audit reports relating to the Services that Cirruslink holds from time to time; or

Where Cirruslink does not hold a relevant certification or report, Cirruslink's written responses to a reasonable annual security questionnaire provided by Customer; and

Other information reasonably necessary to demonstrate Cirruslink's compliance with this DPA.

Customer shall exercise its audit and information rights under this DPA, the SCCs and Applicable Data Protection Laws by first requesting this documentation. Cirruslink does not commit to obtaining or maintaining any particular certification.

5.5 Customer Audits

If the documentation provided under Section 5.4 is not sufficient to demonstrate Cirruslink's compliance with this DPA, or there are indications of non-compliance, Customer may conduct an audit, which may include an inspection of the facilities and records of Cirruslink that are relevant to the processing of Customer Personal Data. Any such audit: (i) requires at least 30 days' written notice with a proposed scope, unless a supervisory authority requires a shorter period or the audit follows a Security Breach affecting Customer Personal Data; (ii) may take place no more than once in any 12-month period, unless a supervisory authority requires it, it follows a Security Breach affecting Customer Personal Data, or there are indications of non-compliance; (iii) shall be conducted during normal business hours without unreasonable disruption to Cirruslink's operations, by Customer or an independent auditor that is not a competitor of Cirruslink and is bound by confidentiality obligations; (iv) shall be at Customer's cost, including Cirruslink's reasonable costs of supporting it; and (v) shall not include access to the data of other customers, to Cirruslink's confidential information unrelated to the Services, or, except to the extent the SCCs require otherwise, to the facilities of Sub-processors or data-center operators, for which Cirruslink shall instead provide the relevant reports or certifications available to it. Information obtained in an audit is Cirruslink's confidential information.

6. TRANSFER OF PERSONAL DATA

6.1 Processing Locations

For Services that offer a choice of Region, Cirruslink shall store Customer Data at rest in the Region selected by Customer. Subject to that, Cirruslink and its Sub-processors may process Customer Personal Data globally, in any country where they operate, where needed to provide, support and secure the Services. The Sub-processor List describes current locations, which may change and be added to over time, and model providers process Customer Personal Data in the locations disclosed for each model on the Model Terms and Provider Disclosures page.

6.2 Cross-Border Transfers

Each party shall comply with the transfer requirements of Applicable Data Protection Laws. In particular:

EEA: to the extent that a transfer of Customer Personal Data from Customer to Cirruslink is a Restricted Transfer subject to the GDPR, the SCCs apply as completed in Annex 2 and are incorporated into this DPA;

United Kingdom: to the extent that the transfer is a Restricted Transfer subject to the UK GDPR, the SCCs as amended by the UK Addendum apply as set out in Annex 2;

Switzerland: to the extent that the transfer is subject to the Swiss FADP, the SCCs apply with the adaptations set out in Annex 2; and

Singapore: where Customer Personal Data subject to the PDPA is transferred outside Singapore, this DPA constitutes legally enforceable obligations requiring Cirruslink to provide a standard of protection comparable to that under the PDPA, and Cirruslink shall impose equivalent obligations on its Sub-processors.

Cirruslink shall make onward transfers of Customer Personal Data to Sub-processors, including model providers, only in accordance with Clauses 8.8 and 9 of the SCCs where they apply, and shall put in place with each Sub-processor that receives a Restricted Transfer the SCCs (Module 3) or another valid transfer mechanism.

6.3 Transfer Impact Assessments

Cirruslink shall provide Customer with the information reasonably requested to assess the laws and practices of the countries of destination relevant to the transfers under this DPA, including the countries where Customer selects models to be processed, and shall apply the supplementary measures described in Annex 3. Cirruslink is not certified under the EU-US Data Privacy Framework; where a Sub-processor is certified, Cirruslink may rely on that certification for onward transfers to it.

6.4 Alternative Transfer Mechanisms

If a transfer mechanism relied on under this DPA is invalidated, amended or replaced, Cirruslink may adopt an alternative mechanism that complies with Applicable Data Protection Laws, and Customer shall cooperate in executing any documents reasonably required for that purpose.

7. RETURN AND DELETION OF PERSONAL DATA

Upon termination or expiry of the Agreement, Cirruslink shall, within 30 days and at Customer's choice, return Customer Personal Data (by enabling Customer to retrieve it through the Services or in another commonly used format agreed by the parties) or delete it and, at the end of that period, shall delete all remaining Customer Personal Data, unless applicable law requires Cirruslink to retain it, in which case Cirruslink shall continue to protect it in accordance with this DPA and process it only for the purpose required by that law. Cirruslink shall certify the deletion in writing on Customer's request. Customer may make its choice in advance, including in an Order Form (for example, by instructing deletion at the end of a retention period stated there, subject to a right to request return). Customer Data on resources that Customer releases or deletes during the term is deleted immediately and cannot be recovered. Cirruslink does not back up Customer Data unless expressly agreed; any residual copies in backup or log systems are deleted in the ordinary course within 90 days and remain subject to this DPA until deleted. The return option does not apply to the extent that applicable law, including export control and sanctions laws, or an order of a competent authority prohibits return; in that case Cirruslink shall delete the Customer Personal Data, or retain it only as that law or order requires.

8. GENERAL PROVISIONS

8.1 Severability

If any provision of this DPA is found to be invalid or unenforceable by a court of competent jurisdiction, such provision shall be modified to the minimum extent necessary to make it valid and enforceable, or if such modification is not possible, the provision shall be severed and the remaining provisions shall continue in full force and effect.

8.2 Limitation of Liability

Each party's liability arising out of or in connection with this DPA, whether in contract, tort or otherwise, is subject to the exclusions and limitations of liability in the Agreement, to the extent they apply to that party, and any reference in the Agreement to a party's liability means its aggregate liability under the Agreement and this DPA together. Nothing in this Section limits either party's liability to Data Subjects under the third-party beneficiary provisions of the SCCs, or any liability that cannot be limited under Applicable Data Protection Laws.

8.3 Governing Law and Disputes

This DPA is governed by the laws of the Republic of Singapore, and disputes under it shall be resolved in accordance with the dispute resolution provisions of the Agreement. Only where, and to the extent that, the SCCs or the UK Addendum apply to a transfer, the SCCs are governed by the law of Ireland and are subject to the jurisdiction of the courts of Ireland, as set out in Annex 2, and the UK Addendum is governed by the law of England and Wales, as those instruments require.

8.4 Order of Precedence

In the event of any conflict or inconsistency, the following order of precedence applies: (a) the SCCs (including as amended by the UK Addendum or the Swiss adaptations in Annex 2); (b) this DPA; and (c) the rest of the Agreement. Nothing in this DPA or the Agreement is intended to modify or contradict the SCCs or to prejudice the fundamental rights or freedoms of Data Subjects. Subject to the SCCs, nothing in this DPA limits Cirruslink's compliance with export-control, sanctions and other laws that apply to it.

8.5 Amendment

Cirruslink may amend this DPA (a) where required to comply with Applicable Data Protection Laws or a decision of a competent authority, or to implement a new or updated transfer mechanism; or (b) in any other way that does not materially reduce the protection of Customer Personal Data. Cirruslink shall give at least 15 days' notice of any material amendment, unless a shorter period is required by law. If an amendment under (b) materially and adversely affects Customer, Customer may terminate the affected Services by written notice before the amendment takes effect, and Cirruslink shall refund any prepaid fees for the period after termination on a pro-rata basis.

ANNEX 1: DETAILS OF PROCESSING

This Annex sets out the details of the processing of Customer Personal Data required by Article 28(3) of the GDPR and similar provisions of other Applicable Data Protection Laws, and constitutes Annex I.A and I.B to the SCCs. Annex I.C is set out in Annex 2.

Processing ElementDetails
Data exporter (Controller)Customer, as identified in the Agreement or its account; contact details are those associated with Customer's account. Activities: use of the Services. Role: controller (or processor on behalf of a third-party controller). Customer's acceptance of the Agreement constitutes its signature of this Annex, dated the date of acceptance.
Data importer (Processor)Cirruslink AI Pte. Ltd. (UEN 202508925H), 30 Pasir Panjang Road, #06-31, Mapletree Business City, Singapore 117440. Contact: Data Protection Officer, privacy@cirruslink.sg. Activities: provision of the Services. Role: processor (or sub-processor where Customer is a processor). Cirruslink's acceptance of the Agreement constitutes its signature of this Annex.
Subject matterThe provision of the Services to Customer under the Agreement: access to models through the model marketplace and the Cirruslink AI API, AI applications, and creative canvas and other content creation tools.
Duration and retentionFor the term of the Agreement and until deletion in accordance with Section 7 of this DPA.
Nature and purpose of processingHosting, storage, computation, transmission (including to model providers selected by Customer or by its routing settings), retrieval and deletion of Customer Personal Data, solely to provide, maintain, secure and support the Services in accordance with the Agreement and Customer's instructions, and to comply with applicable law.
Categories of personal dataDetermined and controlled by Customer; may include identification and contact data, account and usage data of Customer's end users, and any personal data contained in files, databases, workloads, prompts, inputs and outputs that Customer or its users submit to or process through the Services.
Categories of data subjectsDetermined by Customer; may include Customer's employees, contractors, representatives and end users, and any individuals whose personal data is contained in Customer Data.
RecipientsCirruslink personnel with a need to know; Sub-processors described in the Sub-processor List (including model providers where Customer uses models provided through upstream APIs); and public authorities where required by law, in accordance with Section 3.2.
Frequency of transfer and locationsContinuous for the term of the Agreement. Customer Data is stored in the Region selected by Customer, where the Service offers a choice of Region; Cirruslink and its Sub-processors process it globally, in the locations described in the Sub-processor List and, for model providers, on the Model Terms and Provider Disclosures page.
Sensitive dataCirruslink does not require special categories of personal data or data relating to criminal convictions to provide the Services. If Customer chooses to include such data in Customer Data, the measures in Annex 3 apply and Customer is responsible for deciding whether additional safeguards are needed, such as encryption under Customer's control or restricting model routing.
Transfers to Sub-processorsSubject matter, nature and duration as set out above, limited to the services that each Sub-processor provides, as described in the Sub-processor List.
Competent supervisory authority (Annex I.C)As determined under Clause 13 of the SCCs, as set out in Annex 2.

The parties shall maintain and update Annex 1 to reflect any material changes to the processing activities.

ANNEX 2: STANDARD CONTRACTUAL CLAUSES

This Annex sets out how the SCCs, the UK Addendum and the Swiss adaptations apply to Restricted Transfers of Customer Personal Data under Section 6.2.

A. EU Standard Contractual Clauses

The SCCs are incorporated into this DPA by reference and completed as follows:

Modules: Module 2 (controller to processor) applies where Customer is a controller, and Module 3 (processor to processor) applies where Customer is a processor. Module 1 (controller to controller) applies to personal data that Customer transfers to Cirruslink where Cirruslink processes it as a controller, and Module 4 (processor to controller) applies where Customer, acting as a processor, transfers personal data to Cirruslink acting as a controller, in each case to the extent the transfer is a Restricted Transfer.

Data exporter: Customer, as described in Annex 1.

Data importer: Cirruslink AI Pte. Ltd., as described in Annex 1.

Clause 7 (Docking clause): The optional docking clause applies.

Clause 9(a) (Use of sub-processors): Option 2 (general written authorization) applies, and the time period for prior notice of changes to Sub-processors is 14 days, as set out in Section 4.3 of this DPA, including Customer's right to authorize a newly listed model provider before that period ends by enabling or selecting its model.

Clause 11(a) (Redress): The optional language does not apply.

Clause 13 (Supervision) and Annex I.C: Where Customer is established in an EU member state, the supervisory authority of that member state; where Customer is not established in the EU but falls within Article 3(2) of the GDPR and has appointed a representative under Article 27(1), the supervisory authority of the member state in which its representative is established; and where Customer is not required to appoint a representative, the supervisory authority of the member state in which the relevant Data Subjects are located, as designated by Customer (or, failing designation, the member state in which most of them are located).

Clause 17 (Governing law): Option 1 applies. The SCCs are governed by the law of Ireland.

Clause 18 (Choice of forum and jurisdiction): The courts of Ireland.

Annexes: Annex I.A and I.B of the SCCs are completed by Annex 1 of this DPA, Annex I.C by the Clause 13 designation above, and Annex II (technical and organizational measures) by Annex 3 of this DPA.

Related provisions: For Clause 8.1 of Modules 2 and 3, Customer's instructions are those described in Section 2.5. The audits described in Clause 8.9 shall be carried out in accordance with Sections 5.4 and 5.5, and the certification of deletion described in Clauses 8.5 and 16(d) shall be provided on request, in each case to the extent consistent with the SCCs.

The full text of the SCCs is available at: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj

B. UK Addendum

For Restricted Transfers subject to the UK GDPR, the UK Addendum is incorporated into this DPA and applies to the SCCs as completed in Part A, as follows: (a) Table 1: the parties, their details and their key contacts are as set out in Annex 1, and the start date is the date on which this DPA takes effect; (b) Table 2: the Addendum EU SCCs are the SCCs incorporated by Part A, with the Modules and options selected there; (c) Table 3: the Appendix Information is set out in Annex 1 (list of parties and description of the transfer), Annex 3 (technical and organizational measures) and the Sub-processor List; and (d) Table 4: the Importer may end the UK Addendum, as set out in Section 19 of the UK Addendum, when the Approved Addendum changes. The Mandatory Clauses of the UK Addendum apply.

C. Swiss Provisions

For Restricted Transfers subject to the Swiss FADP, the SCCs apply as completed in Part A with the following adaptations: (a) references to the GDPR are to be read as references to the Swiss FADP, as far as the transfers are subject to it; (b) the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority under Clause 13, as far as the transfers are governed by the Swiss FADP; (c) the term "member state" in Clause 18(c) shall not be interpreted so as to exclude Data Subjects in Switzerland from suing in their place of habitual residence; and (d) Clauses 17 and 18 otherwise apply as set out in Part A.

D. Adequacy Decisions

The SCCs do not apply to a transfer to the extent it is covered by an Adequacy Decision, for example where Customer Personal Data is stored in a country covered by an Adequacy Decision or the recipient is certified under a framework recognized by an Adequacy Decision, such as the EU-US Data Privacy Framework.

ANNEX 3: TECHNICAL AND ORGANIZATIONAL SECURITY MEASURES

This Annex describes the technical and organizational measures that Cirruslink implements to protect Customer Personal Data and constitutes Annex II to the SCCs. Taking into account the nature, scope, context and purposes of the processing and the risks to Data Subjects, Cirruslink maintains technical and organizational measures appropriate to the risk, including measures in the following areas. Customer remains responsible for the measures within its control, as described in Section 5.1.

1. ACCESS MANAGEMENT

Access Control: Access by Cirruslink personnel to production systems that process Customer Personal Data is limited to authorized personnel with a business need, based on their role, and is removed when no longer needed.

Authentication: Personnel access to production systems is subject to authentication measures appropriate to the risk, which may include individual accounts and multi-factor authentication for administrative access.

Least Privilege Principle: Cirruslink applies the principle of least privilege in granting access rights to personnel.

Access Logging: Administrative access to production systems is logged where technically feasible.

Segregation of Duties: Where practicable, Cirruslink segregates duties for sensitive operations.

Customer Isolation: Customer resources (such as virtual machines, bare-metal servers, storage volumes and networks) are designed to be logically isolated from those of other customers; bare-metal servers are dedicated to one customer while allocated, and Customer Data on released resources is deleted before they are reallocated.

Customer-Controlled Access: Customer controls access to its resources through the access controls available in the Services, such as the console, API keys, SSH key pairs and network settings. Cirruslink personnel do not log in to Customer instances except where Customer grants access or requests support, or as otherwise permitted by the Agreement.

2. ENCRYPTION

In-Transit Encryption: Connections to the console, websites and APIs are encrypted in transit using industry-standard protocols. Customer is responsible for encrypting its own traffic to and within its instances.

At-Rest Encryption: Cirruslink encrypts data at rest where appropriate to the risk, depending on the Service and system. Customer may apply its own encryption to Customer Data and keep the keys under its control.

Key Management: Where Cirruslink manages encryption keys, access to them is restricted to authorized personnel and systems.

3. NETWORK SECURITY

Firewalls: Cirruslink uses firewalls or other network access controls to restrict access to its management and production networks. Customers configure network settings, such as firewall rules, for their own resources.

Threat Protection: Cirruslink, or its data-center and network providers, use measures designed to detect, prevent or mitigate intrusions and denial-of-service attacks, as appropriate to the risk.

Network Segmentation: Cirruslink uses network segmentation, as appropriate to the risk, to separate its management networks from customer networks.

Vulnerability Management: Cirruslink addresses vulnerabilities in the systems it manages on a risk basis, including by applying security patches, and accepts vulnerability reports at security@cirruslink.sg under its Vulnerability Disclosure Policy.

4. PHYSICAL SECURITY

Data Center Facilities: Servers are hosted in data-center, colocation or cloud facilities with physical security measures, such as physical access controls, surveillance and visitor management. Where a facility is operated by a third party, Cirruslink relies on the operator's physical security controls and on the reports or certifications that the operator makes available.

Environmental Controls: Facility operators provide environmental controls, such as power, cooling and fire-suppression systems.

Equipment Disposal: Storage media that held Customer Data are securely wiped or destroyed before disposal or reuse.

5. LOGGING AND MONITORING

Logging: Cirruslink logs security-relevant events on the systems it manages, such as administrative access and console log-ins.

Log Retention: Access logs are kept for 90 days and security logs for up to 1 year, or longer where needed to investigate an incident or where required by law.

Log Protection: Access to logs is restricted to authorized personnel.

6. INCIDENT RESPONSE AND MANAGEMENT

Incident Response: Cirruslink maintains incident response procedures for detecting, assessing, containing and reporting security incidents, including notifying customers in accordance with Section 5.2.

Escalation Procedures: Incidents are escalated to management and, where required, notified to customers and authorities.

Investigation and Remediation: Incidents are investigated to determine their causes, and remediation measures are taken, as appropriate, to reduce the risk of recurrence.

Post-Incident Review: After significant incidents, Cirruslink reviews the incident and updates its measures where appropriate.

7. BACKUPS AND CONTINUITY

No Backup of Customer Data: Cirruslink does not back up Customer Data unless expressly agreed in writing, and Customer is responsible for backing up its Customer Data. Cirruslink maintains backups of its own account and configuration systems.

Redundancy: Where described in the Service documentation or the SLA, platform components are designed with redundancy.

8. PERSONNEL SECURITY

Screening: Personnel with access to production systems are screened before being granted access, as appropriate to their role and to the extent permitted by local law.

Data Protection Training: Personnel with access to Customer Personal Data receive data protection and security training appropriate to their role.

Confidentiality: Personnel authorized to process Customer Personal Data are bound by confidentiality obligations prohibiting unauthorized disclosure of personal data (Section 2.6).

Need-to-Know Basis: Personnel access personal data only on a need-to-know basis for the performance of their duties.

Termination Procedures: When personnel with access to personal data leave or change roles, their access is revoked promptly, and their confidentiality obligations continue to apply.

9. DATA SUBJECT REQUEST ASSISTANCE

Cirruslink maintains procedures to assist Customer in responding to data subject requests, including:

Receiving and forwarding data subject requests to Customer without undue delay;

Providing Customer, where available, with self-service tools in the Services to access, export and delete Customer Data;

Assisting in exporting personal data in a machine-readable format;

Keeping records of the data subject requests that Cirruslink receives and forwards to Customer;

Responding to Customer's requests for assistance within the timelines set out in Section 3.1.

10. MODEL PROVIDERS AND SUPPLEMENTARY MEASURES

Routing Controls: Customer can choose the models and providers to which its requests are sent and can restrict routing through Custom Data Policies; Cirruslink-hosted models can be used where Customer does not want data sent to upstream providers.

Provider Settings: Where upstream providers offer settings that disable training on, or limit retention of, API content, Cirruslink uses commercially reasonable efforts to enable them where they are available to Cirruslink.

Transparency: Cirruslink discloses the hosting mode, processing location and data practices of each model on the Model Terms and Provider Disclosures page and maintains the Sub-processor List.

Government Access Requests: Cirruslink handles requests from public authorities for Customer Personal Data in accordance with Section 3.2.

This DPA takes effect on the date the Agreement takes effect or, if later, the date on which Cirruslink first processes Customer Personal Data, and remains in effect for as long as Cirruslink processes Customer Personal Data on Customer's behalf.

2. How We Use Personal Data

Cirruslink AI Privacy Policy

3. How We Use Your Information

We may collect, use, and process personal data for the following purposes:

3.1 Providing the Services

We use information to:

  • Create and manage accounts;

  • Authenticate users;

  • Provide AI services;

  • Process API requests;

  • Route requests to the model you select or, only where you have turned on automatic routing or fallback, to another provider or endpoint that your Custom Data Policies permit (never to a different hosting mode or country unless you have allowed this in your settings);

  • Execute AI generation and inference tasks;

  • Store and retrieve canvas projects;

  • Execute workflows;

  • Enable collaboration and sharing;

  • Process subscriptions and payments;

  • Manage Token usage and quotas;

  • Provide customer support.

3.2 Operating and Improving the Services

We may use usage, technical and account information (but not the content of your prompts, uploads or outputs, except as described in Section 4.2) to:

  • Maintain and operate our infrastructure;

  • Monitor system performance;

  • Analyze usage patterns;

  • Improve reliability and performance;

  • Develop new features;

  • Troubleshoot technical problems;

  • Improve user experience;

  • Conduct product and service analytics.

3.3 Security and Abuse Prevention

We may process information to:

  • Detect and prevent fraud;

  • Detect unauthorized access;

  • Protect accounts and API credentials;

  • Prevent abuse of our Services;

  • Detect malicious activity;

  • Investigate security incidents;

  • Enforce usage limits;

  • Protect our infrastructure;

  • Enforce our Terms of Use, Content and Community Policy and other agreements.

3.4 Communications

We may use your contact information to send:

  • Service-related notifications;

  • Account and security notices;

  • Transactional communications;

  • Product updates;

  • Support communications;

  • Newsletters;

  • Promotional communications where permitted by applicable law.

You may opt out of promotional communications at any time (see Section 9).

3.5 Legal and Regulatory Compliance

We may process information where reasonably necessary to:

  • Comply with applicable laws and regulations;

  • Respond to lawful requests from authorities;

  • Establish, exercise, or defend legal claims;

  • Comply with export-control and sanctions laws, including by screening against restricted-party lists;

  • Protect our rights, property, or safety;

  • Prevent or investigate unlawful activity.

3.6 Other Purposes

We may use personal data for purposes notified to you at the time of collection, purposes compatible with the original purpose of collection, or other purposes where permitted or required by applicable law.

3.7 Content Moderation and Safety

To keep the Services safe and lawful, we use automated tools (which may include classifiers, hash-matching and keyword filters) and human review to detect, assess and act on content and activity that may breach the law, our Terms of Use or our Content and Community Policy (https://www.cirruslink.sg/terms), including in prompts, uploads, outputs and content published to the Gallery. Model providers may also apply their own safety filters.

Moderation may result in content being blocked, restricted or removed, or in accounts being restricted or suspended. Where the EU Digital Services Act requires it, we will give you a statement of reasons, and you may use our internal complaint process and the other redress options described in the Content and Community Policy. We keep records of reports, moderation decisions and appeals (Section 10).

We process notices from users and third parties, including requests under the US TAKE IT DOWN Act to remove non-consensual intimate images, which can be made without an account and which we act on within 48 hours of a valid request, and directions from authorities such as Singapore's Online Safety Commission. We may report child sexual abuse material and other serious illegal content to law-enforcement authorities and other organizations where required or permitted by law.

3.8 Automated Decision-Making

Some safety, fraud-prevention and sanctions-screening decisions are made with the help of automated tools. We do not make decisions that produce legal or similarly significant effects for you based solely on automated processing without human review. You may request human review of a decision, express your point of view and contest it by contacting privacy@cirruslink.sg or by using the appeal options in the Content and Community Policy.

3.9 Legal Bases (EEA and UK)

Where the GDPR or the UK GDPR applies, we rely on the following legal bases:

PurposeLegal basis (GDPR / UK GDPR)
Providing the Services (Section 3.1), including processing User Content to generate outputs and routing requests to model providersPerformance of our contract with you (Art. 6(1)(b)); where you use the Services for an organization, our legitimate interests in providing the Services to it (Art. 6(1)(f)).
Operating and improving the Services using usage and technical information (Section 3.2)Legitimate interests in running, securing and improving our Services (Art. 6(1)(f)).
Security, abuse prevention, content moderation and safety (Sections 3.3 and 3.7)Legitimate interests in keeping the Services and their users safe (Art. 6(1)(f)); compliance with legal obligations, such as under the EU Digital Services Act (Art. 6(1)(c)).
Service communications (Section 3.4)Performance of a contract (Art. 6(1)(b)); legitimate interests in communicating with our users (Art. 6(1)(f)).
Marketing (Section 9)Consent where required (Art. 6(1)(a)); otherwise legitimate interests in promoting our Services (Art. 6(1)(f)).
Publishing to the Gallery and taking part in the creator program (Section 5)Performance of a contract (Art. 6(1)(b)).
Legal, regulatory and compliance purposes, including tax records and export-control and sanctions screening (Section 3.5)Compliance with legal obligations (Art. 6(1)(c)); legitimate interests in complying with foreign laws that apply to our business and in establishing, exercising or defending legal claims (Art. 6(1)(f)).
Non-essential cookies and optional features that you turn on, such as prompt logging or a training opt-inConsent (Art. 6(1)(a)), which you may withdraw at any time.

Where we rely on legitimate interests, you may object (Section 14.3). Under the PDPA, we rely on your consent (including deemed consent) or on exceptions such as the legitimate interests and business improvement exceptions.

3. How We Share and Disclose Personal Data

Cirruslink AI Privacy Policy

7. Disclosure of Personal Data

We do not sell or rent your personal data, and we do not share it for cross-context behavioral advertising.

We may disclose or provide access to personal data where reasonably necessary to operate the Services or for the purposes described in this Privacy Policy.

7.1 Service Providers

We may use third-party service providers for:

  • Cloud infrastructure;

  • Data storage;

  • AI model inference;

  • Analytics;

  • Email delivery;

  • Authentication;

  • Payment processing;

  • Customer support;

  • Security monitoring;

  • Logging and observability;

  • Content processing;

  • Other business and technical services.

These providers process personal data on our behalf under contracts that require them to protect it and to use it only to provide their services to us. Our current sub-processors are listed in the Sub-processor List (https://www.cirruslink.sg/privacy).

7.2 AI Model Providers

Where you use a model provided through an upstream API, your prompts, inputs, outputs and related technical information are shared with the provider of that model to fulfill your request, as described in Section 4.3.

7.3 Affiliates

We may share information with Cirruslink Group companies that provide services to us, such as infrastructure, engineering, support or operations, and with our parent company for group governance, financial reporting, audit and compliance. Cirruslink remains responsible for the personal data it shares with its affiliates. Affiliates that act as our sub-processors are listed, with their functions, in the Sub-processor List.

7.4 Legal Requirements

We may disclose information where required or permitted by law, including in response to:

  • Court orders;

  • Legal processes;

  • Government requests;

  • Regulatory requirements;

  • Law enforcement requests.

We may also disclose information where we believe in good faith that it is necessary to comply with export-control or sanctions laws, to protect the rights, property or safety of Cirruslink, our users or others, or to report illegal content (Section 3.7). See our Law Enforcement Policy (https://www.cirruslink.sg/privacy).

7.5 Business Transactions

If Cirruslink is involved in a merger, acquisition, restructuring, financing, sale of assets, or similar corporate transaction, personal data may be transferred as part of that transaction, subject to applicable legal requirements.

7.6 Other Users and the Public

Content you share with collaborators is visible to them, and content you publish to the Gallery is public (Section 5).

7.7 Your Organization

If you use an organization account, we share information with the organization and its administrators (Section 18).

7.8 Payment Service Providers, Sign-in Providers and Advisers

Our payment service providers and the providers of third-party sign-in services that you choose to use receive personal data as independent controllers when they process payments or sign-ins. We also disclose personal data to our professional advisers, such as lawyers, auditors and insurers, under duties of confidentiality, and to other parties with your consent or at your direction.

Cirruslink Sub-processor List

Cirruslink Sub-processor List

Cirruslink AI Pte. Ltd.

Cirruslink AI (https://www.cirruslink.sg and https://www.cirruslink.sg/ai-apps)

Last Updated: September 28, 2026 | Version 1.0

1. Introduction

Cirruslink AI Pte. Ltd. (UEN 202508925H), a company incorporated in Singapore with its registered office at 30 Pasir Panjang Road, #06-31, Mapletree Business City, Singapore 117440 ("Cirruslink"), provides Cirruslink AI (the "Services"). This Sub-processor List describes, by category, the third parties, including other Cirruslink Group companies, that Cirruslink engages to process personal data on behalf of its customers ("Customer Personal Data") when Cirruslink acts as a processor under its Data Processing Agreement ("DPA"), published at https://www.cirruslink.sg/privacy. The names of current sub-processors are available to customers on request to privacy@cirruslink.sg.

This list is published at https://www.cirruslink.sg/privacy. "Cirruslink Group" means Cirruslink AI Technology Limited and its subsidiaries. Capitalized terms that are not defined in this list have the meanings given in the DPA.

Cirruslink remains responsible for its sub-processors as set out in the DPA and imposes on each of them written data protection obligations consistent with the DPA. Some of these providers also process personal data for which Cirruslink is the controller, such as account and billing data, as described in the Cirruslink AI Privacy Policy (https://www.cirruslink.sg/privacy).

For transparency, Section 6 also describes recipients that process personal data as independent controllers. They are not sub-processors.

Where a location is shown as "Global", the sub-processor may process Customer Personal Data in any country where it or its own service providers operate. Locations may change and be added over time, and this list describes the current position.

2. How We Notify Changes

At least 14 days before a new sub-processor begins to process Customer Personal Data, we will notify subscribed customers of its name, function and location, and update this list and its "Last Updated" date. To receive notice of updates, email privacy@cirruslink.sg with the subject line "Subscribe: sub-processor updates" or, where available, subscribe through the console. A customer may object to a new sub-processor on reasonable data protection grounds within that 14-day period, as described in the DPA. Model providers (Table C) are disclosed on the Model Terms and Provider Disclosures page before their models are made available. If you enable or select a newly listed model before the 14-day period ends, you authorize its provider for your requests, as described in Section 4.3 of the DPA. We will not replace the provider, or change the hosting mode, behind a model you have used in the preceding 90 days without giving 14 days’ notice; where such a change is required by law or for security reasons, we may instead suspend the model.

3. Table A – Cirruslink Group Affiliates

Cirruslink Group companies may process Customer Personal Data as sub-processors, in the roles shown below. Cirruslink AI Pte. Ltd. is the contracting entity and the processor under the DPA, and is not listed as its own sub-processor.

CategoryFunctionLocationServicesCustomer Personal Data processed
Cirruslink Group companies (our affiliates)Operations, engineering, infrastructure and support services provided to CirruslinkGlobalBothCustomer Personal Data needed to perform those services

4. Table B – Infrastructure and Service Sub-processors

CategoryFunctionLocationServicesCustomer Personal Data processed
Hosting, data-center and colocation providersCloud hosting for the websites, console, APIs and account systems, and data-center and colocation facilities (space, power, cooling, physical security and network connectivity) for servers operated by or for CirruslinkGlobalBothCustomer Personal Data stored on or processed by the servers and systems they host
Email delivery providersEmail delivery (verification codes and service notifications)GlobalBothNames, email addresses and message content
Customer support tooling providersCustomer support tooling (such as ticketing and chat)GlobalBothContact details and support communications, including any Customer Data shared in tickets
Logging and monitoring providersLogging and monitoringGlobalBothTechnical logs, IP addresses and account identifiers

5. Table C – Model Providers (Cirruslink AI API Content)

When a customer uses a model through the model marketplace, the Cirruslink AI API or our AI applications, the prompts, files and other inputs and the resulting outputs are processed either by the model's provider, where the model is accessed through the provider's upstream API, or on Cirruslink infrastructure, where the model is Cirruslink-hosted. A provider is a sub-processor only for the models accessed through its upstream API; where a model is Cirruslink-hosted, the model's developer does not receive customer content.

For each model, Cirruslink discloses the provider, hosting mode, processing location, retention and training practices and the applicable provider terms, as described on the Model Terms and Provider Disclosures page (https://www.cirruslink.sg/terms). Customers can restrict routing to particular providers or locations through Custom Data Policies.

CategoryFunctionLocationServices
Third-party model providers, as disclosed on the Model Terms and Provider Disclosures page (only for models accessed through the provider's upstream API)Generating responses to requests routed to their modelsGlobal (the location for each model is disclosed on the Model Terms and Provider Disclosures page)Cirruslink AI

6. Independent Recipients (Not Sub-processors)

The following categories of recipients process personal data as independent controllers under their own terms and privacy policies. They are described for transparency only and are not sub-processors.

RecipientRolePersonal dataPrivacy policy
Providers of third-party sign-in services that you choose to useIdentity provider for third-party sign-inAccount identifier, name, email address and basic profile information (such as profile picture), as permitted by your settings with that providerThe provider's own privacy policy
Third-party payment service providersPayment processing, refunds and fraud preventionPayment card and billing details, transaction data and device data collected on payment pagesThe provider's own privacy policy

7. Contact

For questions about this list, please contact our Data Protection Officer at privacy@cirruslink.sg, or write to Cirruslink AI Pte. Ltd., 30 Pasir Panjang Road, #06-31, Mapletree Business City, Singapore 117440.

Cirruslink Law Enforcement and Government Request Policy

Cirruslink Law Enforcement and Government Request Policy

Cirruslink AI Pte. Ltd.

Cirruslink AI (www.cirruslink.sg and the Cirruslink-AI app at www.cirruslink.sg/ai-apps)

Last Updated: September 28, 2026 | Version 1.0

Introduction

This Policy is issued by Cirruslink AI Pte. Ltd. (UEN 202508925H), a company incorporated in Singapore with its registered office at 30 Pasir Panjang Road, #06-31, Mapletree Business City, Singapore 117440 (“Cirruslink”, “we”, “us” or “our”).

It explains how we respond to requests about Cirruslink AI (www.cirruslink.sg and the Cirruslink-AI app at www.cirruslink.sg/ai-apps) (the “Services”). It covers requests from law enforcement agencies, regulators, courts and other government bodies (“Authorities”) for user data, and requests from Authorities to act on content or accounts.

1. Our principles

  • Valid legal process. We disclose user data only in response to valid legal process that binds Cirruslink under applicable law, or where the law otherwise permits disclosure. Examples of permitted disclosure are the emergencies described in Section 6 and reports we are required or permitted to make.

  • Narrow requests. Requests must identify the account or resource concerned and the specific data and time period sought. Identifiers include an account ID, email address, API key identifier, resource ID, or public IP address with date, time and time zone. We may ask for clarification of, seek to narrow, or object to requests that are overbroad, unclear or disproportionate. We disclose only what we are legally required to provide.

  • Legal review. Our legal team reviews every request for validity, jurisdiction and consistency with our obligations. Those obligations include data protection laws such as Singapore’s Personal Data Protection Act 2012 and, where it applies, the EU General Data Protection Regulation (including Article 48 on requests from authorities outside the EU).

  • User notice. We notify affected users unless we are prohibited from doing so or an exception applies (Section 7).

  • No direct access. We do not give Authorities direct or unsupervised access to our systems or to customer content. Disclosures are made by or under the control of Cirruslink in response to specific requests.

2. Who responds and where data is held

2.1 Cirruslink AI Pte. Ltd. provides both Services and responds to requests about them. Requests about the Services addressed to other Cirruslink Group companies should be sent to Cirruslink AI Pte. Ltd.

2.2 Service data may be stored and processed globally, in data centers and systems operated by or for Cirruslink in the countries where we and our service providers operate. Current locations are described in the Sub-processor List (https://www.cirruslink.sg/privacy) and on the Model Terms and Provider Disclosures page (https://www.cirruslink.sg/terms), and may change and be added to over time. Data processed by third-party AI model providers through a provider API is held by those providers (see the Model Terms and Provider Disclosures). Requests for that data should normally be made to the provider.

3. Types of data and what we require

3.1 We distinguish between:
  • account data: basic subscriber information, such as name, email address, account creation date and sign-in and IP logs. It also includes billing records (card details are held by our payment service providers) and identity verification (KYC) and export-compliance records;

  • usage data: for example, API request metadata, token and resource usage, resource provisioning records and network assignment records (such as public IP address assignments); and

  • customer content: for Cirruslink AI, prompts, Outputs, canvases, projects and uploaded files, to the extent we store them.

3.2 For account data and usage data, we require legal process that binds Cirruslink. In Singapore, that means, for example, an order to produce documents or other things under the Criminal Procedure Code 2010, a requirement under other written law, or a court order. For customer content, we require a court order, warrant or equivalent process that meets any higher standard the applicable law sets for content.

3.3 Where we process a business customer’s data as its processor, we will generally ask the Authority to seek the data from the customer first, unless the law prohibits this. We then inform the customer as described in the Data Processing Agreement.

4. Requests from Singapore Authorities

We respond to legal process issued under Singapore law. This includes orders under the Criminal Procedure Code 2010, statutory requests from regulators such as the Personal Data Protection Commission, the Monetary Authority of Singapore, Singapore Customs and the Online Safety Commission, and orders of the Singapore courts.

5. Requests from outside Singapore

5.1 Mutual legal assistance. Foreign Authorities should generally make requests through mutual legal assistance under Singapore’s Mutual Assistance in Criminal Matters Act 2000, or through other appropriate international channels. We may respond directly to foreign legal process where the law that applies to us requires it, for example for data held in that country, or in an emergency (Section 6).

5.2 United States. Cirruslink and its service providers may store or process data in the United States, among other countries. Under US law, including the Stored Communications Act as amended by the CLOUD Act, legal process may require a provider subject to US jurisdiction to disclose data within its possession, custody or control wherever the data is stored. We assess each such request, including whether Cirruslink is subject to the jurisdiction concerned and whether the request conflicts with other laws, such as Singapore or EU data protection law. Where appropriate, we seek to narrow or challenge it.

5.3 European Union. Where Regulation (EU) 2023/1543 applies to us, we handle European Production Orders and European Preservation Orders in accordance with it. Where the law requires us to designate an establishment or appoint a legal representative in the European Union for this purpose, we will publish its contact details on this page. Other requests from EU Authorities follow applicable EU and national law and mutual legal assistance.

6. Emergency requests

6.1 We may disclose information without legal process where we believe in good faith that this is necessary to prevent an imminent risk of death or serious physical injury to any person, and the law permits it. Examples are the emergency exceptions in the Personal Data Protection Act 2012, Article 6(1)(d) of the GDPR, and 18 U.S.C. §2702(b)(8) and (c)(4).

6.2 Send emergency requests to legal@cirruslink.sg with the subject “Emergency Law Enforcement Request”, from an official government email address. Describe the emergency and the person or persons at risk, explain why normal legal process would be too slow, and specify the information needed. We may verify the request and may require legal process afterwards.

6.3 Where we learn of a threat to someone’s life or safety on Cirruslink AI, we report it to the relevant authorities, as described in the Cirruslink AI Content and Community Policy (https://www.cirruslink.sg/terms).

7. User notice

7.1 Our policy is to notify affected users and customers of requests for their data before we disclose it, so that they can seek legal remedies. The exceptions are where:

  • the law or a court order prohibits notice, such as a non-disclosure order or a tipping-off prohibition;

  • notice would create a risk of harm to any person, or the case involves child sexual exploitation;

  • the matter is an emergency; or

  • notice would be futile or counterproductive, for example because the account has been compromised.

7.2 If a prohibition on notice later ends, we may give notice then. For business customers, we notify the customer as controller rather than its end users, as described in the Data Processing Agreement. For personal data that we process for a business customer under the Data Processing Agreement, we withhold notice only where the law prohibits it.

8. Preservation requests

When we receive a valid preservation request from an Authority, we preserve available records about the specified account or resource for 90 days while formal legal process is obtained. We extend this once, for a further 90 days, on a renewed request where the law requires it, and may otherwise do so. Preservation depends on technical feasibility.

9. Requests to remove content or restrict accounts

9.1 We assess requests to remove content, restrict access or suspend accounts against the law and our terms. For Cirruslink AI, these include orders under Article 9 of the EU Digital Services Act and directions of the Online Safety Commission under the Online Safety (Relief and Accountability) Act 2025. They also include directions under the Protection from Online Falsehoods and Manipulation Act 2019 and the Online Criminal Harms Act 2023. See the Content and Community Policy for how we handle them.

10. Export control and sanctions matters

10.1 Cirruslink provides advanced computing services. It cooperates with export control and sanctions authorities as required or appropriate. These include Singapore Customs, the Monetary Authority of Singapore, the US Department of Commerce’s Bureau of Industry and Security and the US Treasury Department’s Office of Foreign Assets Control.

10.2 We may provide KYC, end-use and usage records, which we keep for at least five years, and respond to end-use checks and license-condition reporting. We may also voluntarily report suspected violations.

10.3 We may be required to report suspicious transactions, for example to Singapore’s Suspicious Transaction Reporting Office, and prohibited from telling you that we have done so. Customers must cooperate as set out in the Export Compliance Terms (https://www.cirruslink.sg/terms).

11. Requests from private parties

We do not disclose user data to private parties, including civil litigants, without the user’s consent, except in response to legal process that binds Cirruslink (such as a Singapore court order) or where the law requires or permits it. Foreign civil litigants should use the appropriate international judicial assistance procedures. Rights holders should use the Copyright and Intellectual Property Policy. Individuals seeking their own data can use their account tools or contact privacy@cirruslink.sg.

12. How to submit a request

12.1 Send requests to legal@cirruslink.sg with the subject “Law Enforcement Request”, from an official government email address. Please include:

  • the issuing Authority and the officer’s name, title, badge or identification number, official email address and telephone number;

  • the legal basis for the request, with a copy of the legal process;

  • the identifiers of the account or resource, and the data and time period sought;

  • any deadline and the reason for it; and

  • whether a non-disclosure requirement applies, and its legal basis.

12.2 Formal service should be made at Cirruslink AI Pte. Ltd., 30 Pasir Panjang Road, #06-31, Mapletree Business City, Singapore 117440. We accept requests by email for convenience only. Doing so does not waive any objection, privilege or right, including as to jurisdiction or method of service.

12.3 We may verify any request. We may seek reimbursement of reasonable costs where the law permits. We do not answer non-law-enforcement inquiries sent to this address.

13. Transparency

We may publish information about the number and types of government requests we receive.

14. No guarantee and no rights created

This Policy describes our general practices. It creates no rights for any person, including users, customers and Authorities, and does not commit us to act in any particular way in a particular case, except to the extent that an agreement with a customer (such as the Data Processing Agreement) expressly provides otherwise. We may depart from it where the law or the circumstances require. Nothing in this Policy waives any objection, privilege or right of Cirruslink or its users. We may update this Policy at any time.

15. Contact

Law enforcement and government requests: legal@cirruslink.sg (subject: “Law Enforcement Request”; emergencies: “Emergency Law Enforcement Request”).

Cirruslink AI Pte. Ltd., 30 Pasir Panjang Road, #06-31, Mapletree Business City, Singapore 117440. Tel: +65 6493 0066.

4. Your Rights and Choices

Cirruslink AI Privacy Policy

9. Marketing Communications

We may send promotional communications where permitted by applicable law, including the Spam Control Act 2007 and the Do Not Call provisions of the PDPA in Singapore. We will not send marketing messages to a Singapore telephone number registered with the Do Not Call Registry unless you have given clear and unambiguous consent. In the EEA and the United Kingdom, we send electronic marketing only with your consent or, where the law permits, to existing customers about similar services.

You may unsubscribe from marketing emails by:

  • Clicking the unsubscribe link in the communication; or

  • Contacting us at privacy@cirruslink.sg.

We will continue to send essential service communications where necessary to operate your account or provide the Services.

14. Your Privacy Rights

Depending on your jurisdiction and applicable law, you may have rights regarding your personal data.

14.1 Singapore (PDPA)

Under the PDPA, you may:

  • Request access to your personal data in our possession or under our control;

  • Request information about how your personal data has been used or disclosed;

  • Request correction of inaccurate or incomplete personal data;

  • Withdraw consent, subject to legal or contractual restrictions;

  • Once the data portability obligation under the PDPA comes into force, request that we transmit certain personal data to another organization.

Where applicable, we will process requests in accordance with the timelines and requirements prescribed by law.

We may need to verify your identity before processing a request.

We may also charge a reasonable fee where permitted by applicable law, particularly where responding to an access request requires significant administrative or technical resources.

14.2 Withdrawal of Consent

You may withdraw consent by contacting us at:

privacy@cirruslink.sg

Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.

Depending on the nature of the request, withdrawal of consent may affect our ability to provide certain Services.

14.3 EEA and United Kingdom

If the GDPR or the UK GDPR applies, you have the right to access your personal data; to have it rectified or erased; to restrict or object to our processing (including, at any time, processing for direct marketing); to data portability; to withdraw consent at any time; and not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects (Section 3.8). We will respond within one month, which we may extend by two further months where necessary. These rights are subject to conditions and exceptions, for example where we must keep records to comply with law.

14.4 California

This Section applies to California residents and, together with the rest of this Privacy Policy, is our notice at collection under the CCPA. In the past 12 months, we have collected the following categories of personal information from the sources described in Section 2, for the purposes described in Section 3: identifiers (such as name, email address, username, account ID and IP address); personal information described in Cal. Civ. Code §1798.80(e) (such as phone number and billing information); commercial information (such as credit purchases and transaction history); internet or other electronic network activity information (such as usage and API metadata); approximate geolocation; audio, electronic and visual information contained in User Content (such as images, video and voice recordings you upload or generate); professional information (such as your organization); and sensitive personal information (account log-in credentials and, where collected for compliance checks, government identification numbers). We disclose these categories for business purposes to the recipients described in Section 7, and we keep them for the periods described in Section 10.

We do not sell personal information or share it for cross-context behavioral advertising, and we have not done so in the past 12 months. If that changes, we will update this Privacy Policy, provide a “Do Not Sell or Share My Personal Information” link and honor Global Privacy Control signals. We use sensitive personal information only for the purposes permitted by Cal. Code Regs. tit. 11, §7027(m), and not to infer characteristics about you.

You have the right to know and access the personal information we hold about you, to delete it, to correct it, to opt out of any sale or sharing, and not to be discriminated against for exercising these rights. You may use an authorized agent, who must provide your signed permission; we may ask you to verify your identity directly with us. We verify requests by matching the information you provide with information we hold, and we respond within 45 days, which we may extend by a further 45 days where reasonably necessary.

14.5 Other US States

If you live in another US state with a comprehensive privacy law (such as Colorado, Connecticut, Oregon, Texas or Virginia), you may, to the extent that law applies to us, have rights to confirm whether we process your personal data and to access, correct and delete it and obtain a portable copy of it, and to opt out of targeted advertising, the sale of personal data and profiling in furtherance of decisions that produce legal or similarly significant effects. We do not sell personal data or use it for targeted advertising or for such profiling. If we decline your request, you may appeal by replying to our decision or by emailing privacy@cirruslink.sg with “Appeal” in the subject line. We will respond within the period required by law and, if we deny your appeal, you may contact your state Attorney General.

14.6 How to Exercise Your Rights and Complain

To exercise your rights, contact privacy@cirruslink.sg or use your account settings, where available. If we decline a request, we will explain why where the law requires. If your request concerns content that a business customer processes through the Services, we will refer you to that customer.

We encourage you to contact us first so that we can try to resolve your concern. You may also complain to the Personal Data Protection Commission in Singapore (https://www.pdpc.gov.sg/complaints-and-reviews); to the supervisory authority in the EEA member state where you live or work or where an alleged infringement occurred (listed at https://www.edpb.europa.eu/about-edpb/our-members_en); to the UK Information Commissioner's Office (https://ico.org.uk/make-a-complaint/); or to the California Privacy Protection Agency (https://cppa.ca.gov/webapplications/complaint) or your state Attorney General.

5. Data Security

Cirruslink AI Privacy Policy

11. Data Security

We implement reasonable administrative, technical, and physical safeguards designed to protect personal data and User Content against:

  • Unauthorized access;

  • Unauthorized disclosure;

  • Loss;

  • Misuse;

  • Alteration;

  • Destruction;

  • Other unauthorized processing.

Depending on the applicable Service, security measures may include:

  • Encryption in transit;

  • Encryption at rest where appropriate;

  • Access controls;

  • Authentication mechanisms;

  • Credential protection;

  • Network security controls;

  • Logging and monitoring;

  • Security testing;

  • Backup and recovery procedures;

  • Internal access controls and policies.

However, no method of transmission or electronic storage is completely secure. We cannot guarantee absolute security.

You are also responsible for maintaining the security of your account credentials, devices, and API keys. Please report suspected vulnerabilities to security@cirruslink.sg in accordance with our Vulnerability Disclosure Policy (https://www.cirruslink.sg/terms).

12. Data Breach and Security Incidents

If we become aware of a personal data breach, we will assess the incident and take reasonable steps to contain, investigate, and remediate it.

Where required by applicable law, we will notify the relevant regulatory authorities and affected individuals within the applicable timeframes, for example the Personal Data Protection Commission (PDPC) within 3 calendar days after we assess that a breach is notifiable and, where the GDPR or the UK GDPR applies, the competent supervisory authority within 72 hours after becoming aware of it.

6. Third-Party Platforms and Integrations

Cirruslink AI Privacy Policy

17. Third-Party Services and Links

Our Services may contain links to or integrations with third-party services.

These may include:

  • AI model providers;

  • Authentication providers;

  • Payment service providers;

  • Cloud providers;

  • Analytics services;

  • Storage services;

  • Other third-party applications and platforms.

We are not responsible for the privacy practices, security, or content of third-party services.

Your interactions with third-party services are governed by their respective terms and privacy policies.

7. Data Retention

Cirruslink AI Privacy Policy

10. Data Retention

We retain personal data and User Content only for as long as reasonably necessary to:

  • Provide the Services;

  • Maintain your account;

  • Fulfill the purposes described in this Privacy Policy;

  • Meet contractual obligations;

  • Maintain business and transaction records;

  • Resolve disputes;

  • Prevent fraud and abuse;

  • Comply with legal or regulatory obligations;

  • Protect our legitimate interests.

Our main retention periods are:

CategoryRetention period
Account and profile informationFor the life of your account and 3 years after it is closed.
User Content saved in your projects and canvases (prompts, uploads, outputs and workflows)Until you delete it or close your account. Deleted content is removed from our active systems within 30 days and from backups in the ordinary backup cycle.
Content of API requests (prompts and outputs sent through the Cirruslink AI API)Not stored after the response is returned, unless you save it in a project or turn on prompt logging, or we need to keep it to investigate suspected abuse or illegal content or to comply with law. Model providers' retention is disclosed on the Model Terms and Provider Disclosures page.
Prompt logs (if prompt logging is offered and you turn it on)For the period shown in your settings, or until you turn the feature off and delete the logs.
API request metadata (such as timestamps, model, token counts, status and latency)90 days; billing records derived from it are kept as described below.
Content published to the GalleryUntil you unpublish or delete it, or your account is closed.
Billing, payment and tax recordsAt least 5 years after the end of the relevant financial year, as required by Singapore law, and up to 7 years where needed for group audit, tax or legal purposes.
Moderation, safety and legal-request records (including reports, notices, decisions and appeals)3 years after the decision, or longer where needed for legal claims or required by law.
KYC, export-control and sanctions screening records (where collected)At least 5 years after the later of the relevant transaction and the end of our relationship with you.
Support and communication records3 years after the inquiry is closed.
Security logsUp to 1 year, or longer where needed to investigate an incident.
BackupsOverwritten in the ordinary backup cycle, within 90 days.

When information is no longer reasonably required, we will take reasonable steps to delete, anonymize, or otherwise dispose of it in accordance with applicable law and our data retention practices.

Some technical logs, billing records, security records, or backup copies may remain for a limited period after account deletion where reasonably necessary for security, legal, or operational purposes.

8. Eligibility

Cirruslink AI Privacy Policy

15. Children's Privacy

The Services are not intended for, and may not be used by, anyone under 18.

We do not knowingly collect personal data from anyone under 18. If we learn that we have done so, we will delete it and close the account.

If you believe that a child has provided personal data to us in violation of applicable law, please contact us at:

privacy@cirruslink.sg

We will take reasonable steps to investigate and, where appropriate, delete such information.

16. User Responsibilities

You are responsible for ensuring that:

  • You have the necessary rights and permissions to provide User Content to us;

  • Your User Content does not unlawfully infringe the rights of others;

  • You do not submit personal data that you are not authorized to disclose;

  • You comply with applicable laws when using AI and API Services;

  • You appropriately configure canvas and project sharing permissions;

  • You do not upload another person's face, voice or likeness for cloning or generation without their consent;

  • You protect your account credentials and API keys.

If you process personal data belonging to other individuals through our Services, you are responsible for ensuring that your use of the Services complies with applicable privacy and data protection laws.

9. International Data Transfers

Cirruslink AI Privacy Policy

13. International Data Transfers

Cirruslink is based in Singapore. We, our affiliates, cloud providers, model providers and other service providers may store and process personal data globally, in the countries where we and our service providers operate. Current locations are described in the Sub-processor List and on the Model Terms and Provider Disclosures page, and may change and be added to over time.

As a result, personal data and User Content may be transferred to, stored in, or processed outside Singapore.

Where we transfer personal data outside Singapore, we take appropriate steps to ensure that the recipient is bound by legally enforceable obligations to provide a standard of protection comparable to that under the PDPA.

Depending on the circumstances, appropriate safeguards may include:

  • Contractual protections;

  • Data processing agreements;

  • For transfers from the EEA, the UK or Switzerland, the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914), the UK International Data Transfer Agreement or UK Addendum, or the Swiss-adapted clauses;

  • Technical and organizational safeguards;

  • Other legally recognized transfer mechanisms.

For users in the EEA and the UK, we rely on these safeguards (and, where available, adequacy decisions) for transfers to model providers and other recipients, and we may restrict access to models whose providers do not support them. You can request a copy of the relevant safeguards by contacting privacy@cirruslink.sg.

10. GDPR and U.S. State Supplemental Disclosures

Cirruslink AI Privacy Policy

21. Applicable Data Protection Laws

This Privacy Policy is intended to address the requirements of the PDPA, the GDPR, the UK GDPR, the CCPA and the other data protection laws that apply to us.

Where you access or use our Services from another jurisdiction, additional privacy rights or obligations may apply under the laws of that jurisdiction.

Nothing in this Privacy Policy is intended to limit any mandatory rights you may have under applicable data protection or privacy laws.

End of Privacy Policy

11. Contact Us

Cirruslink AI Privacy Policy

20. Contact Us

If you have questions, concerns, requests, or complaints regarding this Privacy Policy or our handling of personal data, please contact us:

Cirruslink AI Pte. Ltd. (UEN 202508925H), 30 Pasir Panjang Road, #06-31, Mapletree Business City, Singapore 117440

General support: support.ai@cirruslink.sg

Data Protection Officer (DPO):
privacy@cirruslink.sg

Telephone: +65 6493 0066

EU and UK representatives (Article 27 GDPR and UK GDPR): where the law requires us to appoint a representative in the European Union or the United Kingdom, we will publish their contact details on this page.

We will review and respond to privacy-related requests in accordance with applicable law.

If you are located in Singapore and are not satisfied with our response, you may contact the:

Personal Data Protection Commission (PDPC)
Website: https://www.pdpc.gov.sg/

If you are in Singapore, the EEA, the United Kingdom or the United States, you may contact the authorities listed in Section 14.6.

Back to HomeView Terms of Service
Start with one episode

Take the script on your desk
and cut an episode you can air

Call 100+ models through one account, render in the region you release to, and keep creation, assets and billing together.

Browse Token Factory
Cirruslink AINovels in, episodes out

CirrusLink wires compute, models and creative tools into one production line that short-drama and multimodal teams can switch on and start.

Singapore Global Hub| 99.99% SLA

Services

  • Cirrus TV
  • Token Factory unified API
  • Global render compute
  • Short-drama production support

Popular Models

  • Browse Token Factory

Contact Us

support.ai@cirruslink.sg

© 2025–2026 Cirruslink AI PTE. LTD. All rights reserved.

Cirruslink AI PTE. LTD. and Cirruslink INDUSTRIES PTE. LTD. are wholly-owned subsidiaries of Cirruslink AI Technology Limited

Privacy PolicyTerms of ServiceSLA Guarantee