Paprel · Legal
Privacy Policy
How Paprel handles website, account and customer-service personal data.
Last updated: 9 September 2026
1. Who handles your data
Nexara Global Pte. Ltd. operates Paprel. We determine the purposes of website enquiries, account administration, billing, security and our own business communications. For personal data in customer accounting records, we generally process under the business customer’s documented instructions as its processor/data intermediary, or as a subprocessor where that customer acts for another organisation. Roles depend on the actual processing, not only its label.
This notice explains processing; using the site is not blanket consent to every purpose. Customer-controlled records are also subject to that customer’s notice and the Data Processing Addendum. Contact dpo@paprel.com for privacy questions.
2. Data and sources
We receive account and business contact details, billing/subscription information, support messages and form submissions from you; customer records and attachments from authorised users and integrations; and technical data such as IP address, browser/device information, page activity and security logs from use of the Service.
Customer records may include counterparties, employees, invoices, receipts, bank transaction information and other accounting data. OAuth/app metadata may include client identifiers, scopes, consent decisions, status and timestamps. Integration activity may include requested actions, account identifiers, results and diagnostic information; avoid including unnecessary personal information or secrets in requests and support messages.
Payment providers handle payment credentials under their own arrangements. The exact payment information available to Paprel depends on the enabled billing or payment integration.
3. Purposes and legal grounds
We use necessary account and contact data to provide services, manage the relationship, respond to enquiries, bill, secure systems, investigate misuse and meet legal obligations. Website analytics and advertising are controlled through optional cookie choices. Marketing communications use consent where required and provide a way to opt out.
Where GDPR applies, contractual necessity applies to processing necessary for a contract with the individual; business contacts and proportionate service/security administration may rely on legitimate interests, subject to balancing and applicable rights. Legal obligations support required records/disclosures; optional tracking and consent-based marketing rely on consent. Contracting with a company does not automatically make every employee’s processing necessary for a contract with that individual.
Under Singapore PDPA, we use consent, applicable deemed-consent provisions or statutory exceptions only where their conditions are met. Legitimate interests is an exception with its own conditions and assessment requirements; GDPR terminology alone does not establish a Singapore basis. Customer-record processing follows documented lawful instructions and applicable data-protection duties.
4. Recipients and service providers
Our website contact form sends your name, email, subject and message to Web3Forms to deliver the enquiry. Our website uses Google Analytics and Google Ads subject to cookie choices. Hosting, communications, billing and support providers may receive data needed for their functions. See Provider Information for the distinction between website providers and customer-service subprocessors.
Authorised connected apps receive the data and functions covered by their permissions. Their own terms, retention and AI practices apply to subsequent handling. Revoking access cannot retrieve copies already received. We may disclose necessary information to advisers, for legal obligations and rights protection, or during a business transfer subject to applicable safeguards. We do not sell personal data.
5. Cookies, analytics and advertising
The site stores essential settings, including a cookie-consent preference currently retained for 30 days. Optional categories cover analytics, marketing and advertising. Google tags are configured for optional consent and can process online identifiers, device/browser details, visited URLs and attribution information. These identifiers can be personal data; analytics should not be assumed anonymous.
Use the site’s Cookie Preferences control to accept, reject or change optional choices. You can also manage browser storage. Withdrawal affects future consent-based activity and does not invalidate earlier lawful processing; data already sent is subject to the recipient’s retention and applicable rights. Browser blocking alone may not delete existing provider data. Do not put sensitive accounting information in website URLs.
6. International processing
Providers and authorised support access may involve countries outside your own. Hosting location, support access and onward processing are not necessarily the same. A regional deployment does not by itself guarantee all logs, backups and support remain in that region.
Where required, transfers must use applicable safeguards, including comparable protection under Singapore PDPA and, for relevant GDPR transfers, an adequacy decision or appropriate safeguards such as applicable executed standard contractual clauses. We do not represent that SCCs cover every transfer merely by referring to them here. Ask dpo@paprel.com about the locations and safeguards applicable to your service and how to obtain relevant information.
7. Retention, deletion and security
We retain personal data for the purposes for which it is needed, considering the service relationship, legal recordkeeping, security investigations, disputes and applicable instructions. Account/billing records, enquiry messages, operational logs and customer accounting data may have different schedules. A business’s statutory retention duty is not a promise of indefinite Paprel hosting.
Cancelling or allowing a subscription to expire does not itself delete the company workspace or its records. Company deletion is a separate action and initially marks the workspace for deletion. Under the current standard automated process, permanent cleanup becomes eligible seven years after that action. Backup copies follow separate lifecycles. These timings describe the automated process; they do not establish a universal legal requirement to retain data or override an applicable earlier deletion obligation.
Customer Data return and deletion are governed by the Terms of Service and Data Processing Addendum. Contact dpo@paprel.com for retention information or an authorised request. We verify authority, relevant customer instructions and applicable duties, including any requirement for earlier deletion. Retention must remain necessary for its justified purpose; cancellation or the automated schedule alone is not a basis to keep personal data indefinitely. Retained records remain protected and restricted to justified purposes.
We apply appropriate technical and organisational measures for applicable processing and contractual commitments. No service can guarantee perfect security. Our Security page explains scope, customer responsibilities and how to request deployment-specific information.
8. Your rights and requests
Depending on applicable law and circumstances, you may have rights of access, correction, deletion, restriction, portability, objection and withdrawal of consent. These rights have conditions and exceptions and are not identical under GDPR and Singapore PDPA. For consent-based processing you may withdraw consent; we will explain relevant consequences. You can object to direct marketing.
Contact dpo@paprel.com. We may verify identity and authority before responding within applicable legal timeframes, including lawful extensions. For customer-controlled accounting data, contact the business that supplied the data; we will route or assist requests as appropriate rather than act contrary to its lawful instructions. You may complain to Singapore’s PDPC or the competent supervisory authority where applicable.
9. Age and changes
Paprel business accounts are for adults aged 18 or over. This is account eligibility, not a claim that customer records never contain children’s or other minors’ data. Customers must have authority and a lawful basis for such records. If unauthorised child account use or collection is identified, we will assess, restrict and coordinate appropriate handling under law and customer instructions rather than automatically deleting lawful records.
We update this notice when processing changes and provide additional notice where required. A notice update does not itself establish consent to new optional processing. The date above identifies this version.