Effective 3 February 2026
Privacy policy.
The short version
We hold three kinds of personal data: details of people who contact us or book a call, business contact details we use to approach other businesses, and data that belongs to our clients which we only touch in order to run the systems we built for them. We do not sell personal data, we do not share it with advertisers, and we do not use client or patient data to train AI models. To ask what we hold about you, correct it, or have it deleted, email privacy@autolabclick.com. We answer within 30 days.
Who we are.
autolabclick is the trading name of Loophole LLP (UEN T21LL1039K), a limited liability partnership registered in Singapore. We build custom AI and automation systems for clinics and service businesses, mostly in Singapore, Malaysia and Australia.
This policy explains what personal data we collect, why we collect it, who else sees it, how long we keep it and how you get it removed. It is written to meet our obligations under the Personal Data Protection Act 2012 of Singapore (the PDPA).
Our data protection contact is privacy@autolabclick.com. Write to that address for any question about your data, including access, correction and deletion requests. We aim to respond within 30 days, and we will tell you if a request will take longer.
1. Visitors to this website.
There is no enquiry form anywhere on this site. The only action the site asks for is booking a call, and that runs through Calendly.
- Server logs. Our host, Vercel, records the usual technical detail of a page request: IP address, browser and device type, the pages requested and the time. It is used to keep the site running and to spot abuse, and it is deleted on our host's own short retention cycle.
- Meta Pixel (advertising cookies). This site runs the Meta Pixel. It sets a cookie, records which pages you viewed and whether you clicked a booking button, and sends that to Meta Platforms so we can measure our ads and show ads later to people who visited. You can stop it: block cookies in your browser, use a tracker-blocking extension, or change your ad preferences inside Facebook and Instagram. The site works normally with the pixel blocked.
- Booking a call. When you book, Calendly collects your name, email address, your phone number if you give one, your time zone, and your answers to the booking questions, including how you found us. We also tag the link with the page you booked from, so we know which page earned the call. The booking lands in our Google Calendar and Gmail.
Please do not send medical details, or anyone else's personal details, through a booking form. A booking only needs enough to hold the slot.
2. Clients and people who contact us.
- What we hold. Your name, work email, phone number, company, role, what we discussed, and the proposals, invoices and payment records that follow from it.
- Calls are recorded and transcribed. We use Fathom on video calls to take notes. Everyone on the call sees the recording notice before it starts, and we turn it off if you ask. Recordings and transcripts are used for our own notes, for the follow-up we owe you, and to improve how we run calls. They are not published and not shared outside our team.
- Where it sits. Google Workspace for email, calendar and files, Notion as our CRM, and Slack for internal notifications.
- Payments. We take payment by PayNow bank transfer and through HitPay. We see the amount, the reference and whether it cleared. We never see or store your full card number.
- How long we keep it. For as long as we are working together, and for five years after the last transaction, because Singapore business and tax records have to be kept for five years. After that it is deleted.
3. Data we handle for our clients.
This is the section that matters if you are a patient or a customer of a business we built a system for.
When we build a booking assistant, a reminder system or an integration between a clinic's tools, that system runs on the client's own accounts and handles their customers' data. The client decides what the system does with it. We only act on their instructions. Under the PDPA that makes us a data intermediary, and we carry the Protection and Retention Limitation obligations directly, along with a duty to tell the client about a breach.
- What that data can include. Names, phone numbers, email addresses, appointment dates and the service booked, messages sent to the business, and invoice or payment status. In a healthcare setting it can include the reason for a visit. We ask clients to keep clinical notes out of the parts of the system we operate wherever their workflow allows.
- What we do with it, and what we never do. We use it to run the system, to fix it when it breaks, and to report on it to the client. We do not sell it, we do not use it for our own marketing, and we do not use it to train AI models. Where the system sends message text to an AI provider to draft a reply, we use business API terms under which the provider does not train its models on that content.
- If you are a patient or customer of one of our clients. Contact the business directly, because they hold your record and they decide what happens to it. If you write to us instead, we will pass your request to them and help them answer it.
- How long we keep it. For as long as we operate the system. When an engagement ends we return or delete whatever sits in our own accounts within 30 days, unless the client asks us to do otherwise or the law requires it to be kept. Data held inside the client's own platforms stays with the client, and their retention rules apply to it.
- If something goes wrong. We tell the client without undue delay, so they can meet their own notification duties under the PDPA.
4. WhatsApp messages.
We build and operate WhatsApp Business API numbers on behalf of client businesses, through a WhatsApp Business Solution Provider approved by Meta. This section describes what happens when you message one of those numbers.
- What we receive. Your WhatsApp phone number, the profile name you show on WhatsApp, the content of the messages you send including any files or images, the time each message was sent, and delivery and read status.
- Why. Only to handle the conversation you started: answer your enquiry, book, reschedule or cancel an appointment, confirm it, remind you before it, and send information you asked for. Nothing else.
- How a business is allowed to message you first. Template messages go only to people who have contacted the business or given it permission to message them, for example when booking. We do not buy phone number lists and we do not message people who never dealt with the business.
- Who else sees it. The business you messaged, Meta as the operator of WhatsApp, our Business Solution Provider, the booking or CRM system that business runs, and the AI provider that helps draft a reply. That is the whole list. Your number is never sold, never shared with advertisers, and never added to another business's list.
- Stopping messages. Reply STOP at any time and automated messages to your number stop. You can also just tell the business.
- How long it is kept. The conversation stays in the business's system for as long as they need it as a customer record. In the parts we operate, message logs are kept for up to 12 months and then deleted.
- Deleting your WhatsApp data. Email privacy@autolabclick.com from any address, tell us the WhatsApp number and which business you messaged, and we will delete the message record held in the systems we operate and ask that business to delete it in theirs. We respond within 30 days.
5. Business contacts we approach.
We approach businesses that we think can use what we build. If you received an email from us and did not ask for it, this is the section that explains where your address came from.
- What we collect. The company name, website, business phone number, business address and a general business email address. Sometimes also the name, work email address, job title and public LinkedIn profile of the person who would make this kind of decision.
- Where it comes from. Public sources such as company websites, business listings, public directories and public professional profiles, and from licensed business data providers who supply work email addresses.
- Why we may do this. Business contact information used for a business purpose sits outside the PDPA's consent requirement. We only write to work addresses about work matters, never to personal ones. We honour every removal request regardless.
- How to stop it. Click the unsubscribe link in the email, reply and say stop, or email privacy@autolabclick.com. We remove you from the campaign the same working day where we can.
- One record we keep on purpose. After a removal request we keep your email address on a suppression list. That single record is what stops a later campaign from contacting you again. If we deleted it entirely we would have no way of knowing you had asked us to stop.
6. Job applicants.
- What we collect. Your name, email address, phone number, your CV and any links you share, your answers to the application questions, and the notes we make while assessing your application. The application form is hosted on Netlify and submissions reach our email.
- Why. To assess your application and to contact you about it. Nothing else, and never for marketing.
- How long we keep it. Twelve months from your application, so we can come back to you if a suitable role opens. Ask us and we delete it sooner.
- A human decides. We do not use automated screening to reject an application without a person reading it.
7. Who else touches the data.
We use third-party services to run the business. Each one gets only what its job needs, and each is bound by its own contract and data protection terms. This list changes as our tools change, and we update it here when it does.
- Website and forms: Vercel (site hosting and server logs), Netlify (job application form).
- Calls and scheduling: Calendly (bookings), Google Workspace (email, calendar, files), Fathom (call recording and transcripts).
- Business records: Notion (our CRM), Google Sheets, Slack.
- Outreach email: Instantly (sending), Anymail Finder and MillionVerifier (finding and checking business email addresses).
- Payments: HitPay, and PayNow bank transfer through our bank.
- Running the systems we build: Modal and n8n (automation and hosting), and the client's own platforms such as their practice management system, WhatsApp Business account and accounting software.
- AI providers: OpenAI and Anthropic, on business terms under which the content we send is not used to train their models.
- Advertising: Meta Platforms, through the pixel described in section 1.
8. Data that leaves Singapore.
Most of the services above store data outside Singapore, usually in the United States or the European Union. Section 26 of the PDPA allows a transfer overseas only where the receiving party is bound to a standard of protection comparable to the PDPA. We rely on the data processing terms and contractual commitments of the providers we use, and we check this before putting a new tool anywhere near client data.
If you are a client and you need to know exactly where a particular system sends data, ask us and we will tell you for that system. It is a fair question and it usually has to be answered before a clinic can sign anything.
9. How we protect it.
- Accounts are protected with two-factor authentication wherever the service supports it.
- Access is limited to the people who need it to do the work, and it is removed when they no longer do.
- API keys and credentials live in secret stores and environment files, never in shared documents, spreadsheets or chat messages.
- The machines we work on use full-disk encryption.
- Wherever possible a client's system runs on the client's own accounts rather than ours, so our access ends when the engagement does. This is deliberate. Nothing important should sit behind a login only we hold.
No system is perfectly secure and we will not pretend otherwise. If a breach affects your data we act on it immediately and follow the notification duties the PDPA places on us, including telling the affected organisation without undue delay.
10. Your rights, and how to delete your data.
Under the PDPA you can ask us to:
- Tell you what personal data we hold about you and how we have used it in the past year.
- Correct anything that is wrong.
- Delete it, where we are not required to keep it.
- Withdraw consent to any use you previously agreed to.
Send the request to privacy@autolabclick.com. We may need to check who you are before we act, so that we are not handing your data to someone else. We respond within 30 days, and we will tell you if a request needs longer. The PDPA allows a reasonable fee for an access request. If one applies we will tell you the amount before doing the work, and for an ordinary request there is no fee.
If you think we have handled your data badly, tell us first and we will try to put it right. You can also complain to the Personal Data Protection Commission of Singapore at pdpc.gov.sg.
11. Children.
This website and our outreach are aimed at businesses, not at children. Where a system we build for a client handles data about a minor, for example a clinic booking an appointment for a child, that client is responsible for obtaining consent from the parent or guardian, and for the clinical and record-keeping rules that apply to it.
12. Changes to this policy.
When this policy changes we publish the new version on this page and update the effective date at the top. Where a change materially affects how we handle a client's data, we tell that client directly rather than relying on them noticing this page. This version is effective 3 February 2026.
Contact
Data protection contact: privacy@autolabclick.com
Loophole LLP, trading as autolabclick. UEN T21LL1039K. Singapore.