← All legal documents · Privacy Policy · Children's Privacy Notice

Balance — Singapore Country Annex

Effective date: 28 June 2026 Last updated: 28 June 2026

Owner: , Director, BabaYaga Program, TOO — Privacy Officer and Designated Child Safety Officer for every Singapore resident covered by this Annex; the Data Protection Officer ("DPO") under s 11(3) of the Personal Data Protection Act 2012 (Singapore) (No. 26 of 2012) ("PDPA"), with business contact published as the publicly-accessible DPO contact required by s 11(5) PDPA read with the Personal Data Protection Regulations 2014 and the Personal Data Protection Regulations 2021; the designated contact point for the Personal Data Protection Commission ("PDPC"), the Infocomm Media Development Authority ("IMDA"), the Council for Estate Agencies (n/a), the Singapore Police Force ("SPF") National Cyber Crime Unit, and the Ministry of Social and Family Development ("MSF") under their respective intake protocols. Reviewed: at least once a year, by 9 June. Re-opened immediately on (a) any amendment to the Personal Data Protection Act 2012 (Singapore) — including the bringing into force of any provision of the Personal Data Protection (Amendment) Act 2020 (No. 40 of 2020) that is not yet operationally in force at the Effective date (in particular the data portability provisions at PDPA Part VIB (ss 26H–26P) which require subsidiary regulations to be made under s 26P before they are operationally in force; the s 26P regulations had not been made at the Effective date — § 18 versioning protocol provides for an immediate off-cycle update on their making and the consequential commencement of Part VIB); (b) any amendment to the Personal Data Protection Regulations 2014, the Personal Data Protection (Notification of Data Breaches) Regulations 2021, the Personal Data Protection (Composition of Offences) Regulations 2021, the Personal Data Protection (Composition of Offences) Regulations 2022, the Personal Data Protection (Enforcement) Regulations 2021, the Personal Data Protection (Do Not Call Registry) Regulations 2013, or to any successor PDPA subsidiary regulation; (c) any Advisory Guideline or PDPC Decision issued by the Personal Data Protection Commission under PDPA s 49 — including the Advisory Guidelines on the PDPA for Children's Personal Data, the Advisory Guidelines on Key Concepts in the PDPA, the Advisory Guidelines on the PDPA for NRIC and Other National Identification Numbers, the Advisory Guidelines on the PDPA for Selected Topics, the Guide to Active Enforcement, the Guide to Managing Data Breaches 2.0, the Guide to Data Protection Practices for ICT Systems, the Guide to Notification, and the body of PDPC decisions published at https://www.pdpc.gov.sg/Commissions-Decisions/Data-Protection-Enforcement-Cases; (d) any decision of the Data Protection Appeal Panel (constituted under PDPA s 47) or of any Singapore court under PDPA Part IX; (e) any amendment to the Spam Control Act 2007 (Singapore) or its associated regulations; (f) any amendment to the Cybersecurity Act 2018 (Singapore) (only relevant if Balance were ever designated a Critical Information Infrastructure ("CII") — not in scope at the Effective date); (g) any amendment to the Online Criminal Harms Act 2023 (Singapore) ("OCHA") (in force from 1 February 2024) or to any Direction issued by the Minister for Home Affairs or the Commissioner of Police thereunder; (h) any amendment to the Broadcasting Act 1994 (Singapore) including its Code of Practice for Online Safety (in force from 18 July 2023 for "Designated Online Communications Services") or to any Direction under the Online Safety (Miscellaneous Amendments) Act 2022; (i) any amendment to the Protection from Online Falsehoods and Manipulation Act 2019 (Singapore) ("POFMA") (relevant only contextually — Balance does not generate or host online falsehoods); (j) any amendment to the Penal Code 1871 (Singapore, revised), in particular ss 354 (outrage of modesty), 376–376E (sexual offences against minors and sexual grooming), 376EB (sexual exposure to minor under 16), 376G (sexual penetration of a person under 18 by trust), ss 377BA–377BJ (offences relating to child sexual exploitation including sexual communication with minors, CSAM-related offences), s 377BG (causing minor under 16 to be a recipient of sexual material), s 377BH (production/distribution/possession of CSAM), s 416A (cheating by personation); (k) any amendment to the Children and Young Persons Act 1993 (Singapore) ("CYPA") including the Children and Young Persons (Amendment) Act 2019 which strengthened protection of children and young persons; (l) any amendment to the Computer Misuse Act 1993 (Singapore) ("CMA"), the Criminal Procedure Code 2010 (Singapore) ("CPC"), or the Mutual Assistance in Criminal Matters Act 2000 (Singapore) ("MACMA"); (m) any amendment to the Films Act 1981 (Singapore), the Undesirable Publications Act 1967 (Singapore), or the Broadcasting Act 1994 (Singapore) on undesirable / restricted content; (n) any amendment to the Consumer Protection (Fair Trading) Act 2003 (Singapore) ("CPFTA"), the Sale of Goods Act 1979 (Singapore, as adopted), the Unfair Contract Terms Act 1977 (Singapore, as adopted), the Lemon Law amendments at CPFTA Part III, or any subsidiary regulation; (o) any amendment to a sub-processor's Singapore data-handling posture under our sub-processor register; (p) the bringing into force of any post-Effective-date Singapore regulation governing automated processing or related techniques (covered by the deliberate-silence carve-out in § 2 of this Annex). Classification: Public legal annex. This document is published at Privacy Policy alongside the global Privacy Policy (H1) and at Children's Privacy Notice alongside the Children's Privacy Notice (H2), and is incorporated by reference into both. It is one of the country annexes that travel with the global documents under the "global policy + per-country annex" architecture documented in our internal compliance plan § 6.3.

This Annex discharges the country-annex obligations referenced in:

This Annex is the canonical Singapore-resident extension of the global Privacy Policy and Children's Privacy Notice. Where this Annex grants a Singapore resident a right that the global Policy does not, this Annex governs. Where the global Policy grants a Singapore resident a right that this Annex does not, the global Policy governs. The two are read together.

This Annex is drafted in English. Singapore's four official languages are English, Malay, Mandarin Chinese, and Tamil (Constitution of the Republic of Singapore Art 153A). English is the working language of the Singapore Government, the language of the courts, and the language in which all Singapore statutes are authoritative. Localised translations into Malay, Mandarin Chinese, and Tamil are queued for the Phase-2 locale rollout per our internal compliance tracker. No translation is statutorily required at the Effective date for the English-language privacy notice to a Singapore resident (PDPA does not require multilingual notification).


1. Scope and applicability

This Annex applies to every Balance user (parent or kid) whose country of residence is the Republic of Singapore — the city-state with no internal subdivision beyond the five Community Development Councils (CDCs) and the planning regions of the Urban Redevelopment Authority. There is no provincial or territorial overlay.

We determine country of residence at install/sign-up time by (a) the country the parent self-declares in the in-app onboarding flow, (b) the IP-geolocation read at sign-up (which we discard immediately after the residence decision — our internal data-flow map § 2.1 stores no IP after the authentication request closes), and (c) the Play Store account locale that Google Play passes to us at install. The residence determination is reviewable at any time by the parent at Settings → Account → Region.

Where any of the three signals identifies Singapore as the country of residence, this Annex applies, even if the other signals are non-Singaporean. The most-protective-for-the-data-subject reading is the controlling reading per our internal compliance plan § 6.3.

The PDPA has extraterritorial effect under s 2(1) — the Act applies to organisations whether they are formed or recognised under the law of Singapore, resident or located in Singapore, or operating from outside Singapore. The PDPC's Advisory Guidelines on Key Concepts in the PDPA Chapter 7 + the body of PDPC decisions confirm that an organisation outside Singapore is subject to the PDPA in respect of its collection, use, or disclosure of personal data of individuals in Singapore where the organisation directs activities towards Singapore. Balance squarely targets Singapore residents through Google Play Singapore, through publication of this Annex at balance.babayagaprogram.com, and through delivery of the parental-control service to Singapore-resident parents and kids; the PDPA applies in full.


2. Statutory framework — what applies

The Singapore personal-data-protection regime is dominated by the Personal Data Protection Act 2012, as modernised by the Personal Data Protection (Amendment) Act 2020 (No. 40 of 2020) (substantively in force in tranches from 1 February 2021), supplemented by the suite of subsidiary regulations and the Personal Data Protection Commission's binding Advisory Guidelines. The PDPA is the principal layer. Adjacent layers: the Spam Control Act 2007; the Online Criminal Harms Act 2023 and the Code of Practice for Online Safety under the Broadcasting Act 1994; the Penal Code 1871; the Children and Young Persons Act 1993; the Consumer Protection (Fair Trading) Act 2003; the Cybersecurity Act 2018 (only for CII designation — not engaged); the Computer Misuse Act 1993; the Criminal Procedure Code 2010; and the Mutual Assistance in Criminal Matters Act 2000.

Instrument Short cite What it does Balance's posture
Constitution of the Republic of Singapore Constitution — Part IV (Fundamental Liberties — Art 9 right to life and personal liberty; Art 12 equal protection; Art 14 freedom of speech, assembly and association); Art 152 (minorities and special position of Malays); Art 153A (official languages — Malay, Mandarin, Tamil, English). Privacy is not explicitly enumerated; Re Wong Sin Yee [2014] 4 SLR 532 and Public Prosecutor v Mas Swan bin Adnan [2012] 3 SLR 527 acknowledge but do not entrench a constitutional privacy right. The constitutional anchor. Privacy in Singapore is statutory (PDPA) rather than constitutional. Applies as the constitutional layer. Treatment in §§ 3, 6, 13 below.
Personal Data Protection Act 2012 (Singapore) PDPA — No. 26 of 2012, in force 2 January 2013 (institutional provisions) + 2 January 2014 (DNC Registry) + 2 July 2014 (Data Protection provisions); as substantively amended by the Personal Data Protection (Amendment) Act 2020 (No. 40 of 2020) in force in tranches from 1 February 2021. Substantive sections: Part I preliminaries; Part II (s 11 — accountability + mandatory DPO at s 11(3) + public availability of DPO contact at s 11(5)); Part III — Collection, Use and Disclosure of Personal Data (s 13–17 consent obligation + deemed consent + s 18 purpose obligation + s 20 notification obligation + s 21 access obligation + s 22 correction obligation + s 23 accuracy obligation + s 24 protection obligation + s 25 retention obligation + s 26 transfer-limitation obligation + s 26A right of withdrawal of consent + ss 26B–26E Part VIA mandatory data breach notification in force 1 February 2021 + ss 26F–26G PDPC deemed-consent-for-contractual-necessity + deemed-consent-for-legitimate-interests new bases + ss 26H–26P Part VIB data portability framework provisions only — operationally in force on the making of subsidiary regulations under s 26P which have not been made at the Effective date); Part IV (Care of Personal Data — s 24 protection / s 25 retention); Part V (s 26A right of withdrawal); Part VI (collection, use, disclosure carve-outs for business-asset transactions, employment, research, etc.); Part VIA — Notification of Data Breaches (s 26A–26E in force 1 February 2021; s 26B definition of notifiable data breach — significant-harm-to-individual or significant-scale ≥ 500 individuals test + ss 26C–26D PDPC notification within 3 calendar days + affected-individual notification at the same time unless prohibited by law enforcement or where the data has been rendered unintelligible); Part VIB — Data Portability (ss 26H–26P — framework not yet operationally in force); Part VII (the Do Not Call Registry + s 36–48); Part VIII (Administration — s 49 Advisory Guidelines power + s 50–55 PDPC powers); Part IX (Enforcement — s 56–62 investigations + s 60 financial penalties up to the greater of 10% of annual turnover in Singapore or SGD 1 million for organisations with annual turnover in Singapore exceeding SGD 10 million / up to SGD 1 million for smaller organisations); Part X (Appeals — Data Protection Appeal Panel + appeals to the General Division of the High Court); Part XI (Miscellaneous — Right of Private Action at s 48O** — individuals may commence a private civil action in the District Court / General Division of the High Court for loss or damage suffered by reason of a contravention of Part IV/V/VI). The principal statute. Applies in full to Balance as an organisation operating from outside Singapore directing activities to Singapore residents (per PDPC Advisory Guidelines on Key Concepts Chapter 7). Treatment in §§ 3, 4, 6, 7, 8, 11, 13 below.
Personal Data Protection Regulations 2014 (Singapore) PDPR 2014 — the principal subsidiary regulation. Sets the operational details for the PDPA (definitions; access procedures; transfer-limitation conditions; etc.). Regulation 9–11 sets out the prescribed mechanisms for cross-border transfer comparable to PDPA s 26 — including (i) the data subject's consent; (ii) the transfer is necessary for the performance of a contract between the organisation and the individual; (iii) the recipient is bound by legally enforceable obligations to provide a standard of protection comparable to the PDPA (typically via written contract, binding corporate rules ("BCRs"), or certification under an approved cross-border privacy scheme such as the APEC Cross-Border Privacy Rules ("CBPR")). Applies in full. Treatment in § 8 below.
Personal Data Protection (Notification of Data Breaches) Regulations 2021 PDPR-NDB 2021 — subsidiary regulation operationalising PDPA Part VIA. Applies in full. Treatment in § 11 below.
Personal Data Protection (Do Not Call Registry) Regulations 2013 PDPR-DNC 2013 — subsidiary regulation operationalising PDPA Part VII (DNC Registry). Applies. Balance does not place telemarketing calls; the DNC Registry is not engaged.
Personal Data Protection (Enforcement) Regulations 2021 PDPR-Enforcement 2021 — subsidiary regulation operationalising PDPA Part IX. Applies in full as the PDPC enforcement-procedure layer.
PDPC Advisory Guidelines PDPC's binding interpretive guidance, issued under PDPA s 49 — including the Advisory Guidelines on Key Concepts in the PDPA (most recent revision), the Advisory Guidelines on the PDPA for Children's Personal Data (the principal children's-data interpretive instrument), the Advisory Guidelines on the PDPA for NRIC and Other National Identification Numbers, the Advisory Guidelines on the PDPA for Selected Topics, the Guide to Active Enforcement, the Guide to Managing Data Breaches 2.0, the Guide to Data Protection Practices for ICT Systems, the Guide to Notification, and the body of PDPC decisions published at https://www.pdpc.gov.sg/Commissions-Decisions/Data-Protection-Enforcement-Cases. Sets the PDPC's binding interpretive layer on the PDPA. Applies. Balance's posture is operationalised consistently with the Advisory Guidelines on the PDPA for Children's Personal Data in particular.
Spam Control Act 2007 (Singapore) SCA — regulates unsolicited commercial electronic messages with a Singapore-link computer. Schedule I requires identification + unsubscribe; Schedule II requires unsubscribe facility. Civil penalties for non-compliance enforced via the District Court (s 13). Applies. Balance does not send commercial electronic messages to Singapore residents; the only email Balance sends is transactional. Treatment in § 12.3 below.
Cybersecurity Act 2018 (Singapore) Cybersecurity Act — establishes the Cyber Security Agency of Singapore ("CSA"); designates Critical Information Infrastructure ("CII") under s 7; imposes incident-reporting + protection obligations on CII owners. Applies only to organisations designated as CII operators. Balance is not designated as a CII operator at the Effective date; therefore the Cybersecurity Act's substantive obligations do not engage Balance directly. Applies as a context-setting fact.
Online Criminal Harms Act 2023 (Singapore) OCHA — in force 1 February 2024. Empowers the Minister for Home Affairs and the Commissioner of Police to issue Directions to online service providers (including content-removal, access-restriction, app-removal, and account-restriction Directions) where there is reasonable suspicion that an offence is being committed using an online service. Regulates online services that may be used to facilitate criminal harms (scams, malicious cyber activity, etc.). Balance's posture: Balance is best characterised as a private parental-control client that does not host third-party content publicly, does not enable user-to-user communication outside the parent-kid pairing of a single household, and does not provide a service in the sense engaged by the OCHA Directions regime; Balance nevertheless will cooperate with any properly-issued Direction served on Balance under the routes in § 13 + § 14 below.
Broadcasting Act 1994 (Singapore) + Code of Practice for Online Safety The Online Safety (Miscellaneous Amendments) Act 2022 (in force 1 February 2023) amended the Broadcasting Act to establish the Code of Practice for Online Safety applicable to Designated Online Communications Services ("DOCS"). The Code came into operation on 18 July 2023 for DOCS designated by IMDA. Designated services (DOCS — at the Effective date, the IMDA has designated a small number of social-media services including Facebook, Instagram, TikTok, X, HardwareZone, YouTube — none being Balance) must implement child-safety measures, content-moderation systems, and reporting tools. Balance has not been designated as a DOCS and the IMDA Designation Order at the Effective date does not extend to parental-control services. Applies as a context-setting fact.
Protection from Online Falsehoods and Manipulation Act 2019 (Singapore) POFMA Applies to online communications of falsehoods. Balance does not generate or host online communications of falsehoods. Not engaged.
Penal Code 1871 (Singapore, revised) Penal Code — s 354 (outrage of modesty); s 376 (rape); s 376A (sexual penetration of a minor under 16); s 376AA (sexual communication with a minor under 16 — sexting offence introduced by the Criminal Law Reform Act 2019); s 376B (commercial sex with a minor under 18); s 376C (commercial sex with a minor under 18 outside Singapore — extraterritorial); s 376E (sexual grooming of a minor under 16 — grooming offence introduced by the Penal Code (Amendment) Act 2007); s 376EB (sexual exposure to a minor under 16); s 376G (sexual penetration of a person under 18 by a person in a position of trust); ss 377BA–377BJ (offences relating to child sexual exploitation including sexual communication with minors and possession/production/distribution of CSAM — introduced by the Criminal Law Reform Act 2019 in force 1 January 2020); s 416A (cheating by personation — relevant for grooming-by-impersonation scenarios). The principal Singapore criminal statute for CSAE, online-grooming, intimate-image, and CSAM offences. Applies. Cross-reference in Child Safety Standards § 8.1 + § 14 below.
Children and Young Persons Act 1993 (Singapore) CYPA — as amended by the Children and Young Persons (Amendment) Act 2019. Definitionschild means a person under 14 years; young person means a person 14 years or above and under 16 years (s 2). Establishes the framework for protection of children and young persons; mandatory reporting of child abuse (s 14); offences (Part II); MSF / Child Protective Service ("CPS") cooperation. The principal child-welfare statute. Applies. Treatment in § 5 + § 14 below.
Computer Misuse Act 1993 (Singapore) CMA — the principal cybercrime statute. s 3 (unauthorised access to computer material); s 4 (access with intent to commit or facilitate commission of offence); s 5 (unauthorised modification of computer material); s 6 (unauthorised use or interception of computer service); s 7 (unauthorised obstruction of use of computer); s 8 (unauthorised disclosure of access code). Applies. Treatment in § 13 below.
Criminal Procedure Code 2010 (Singapore) CPC — sets the procedural rules for police powers including production orders + search warrants under Part IV. The lawful-access framework for criminal investigations. Applies. Treatment in § 13 below.
Mutual Assistance in Criminal Matters Act 2000 (Singapore) MACMA — Singapore's framework for assisting foreign states with criminal-justice cooperation. The mutual-assistance framework. Applies. Treatment in § 13 below.
Films Act 1981 + Undesirable Publications Act 1967 (Singapore) Films Act + UPA — IMDA-administered classification of films + prohibition of undesirable publications including CSAM. The principal undesirable-content classification statutes. Applies as a context-setting fact.
Consumer Protection (Fair Trading) Act 2003 (Singapore) CPFTA — Singapore's principal consumer-protection statute. s 4 (unfair practices — false claims, misleading representations, exploitative conduct); Part III (the Lemon Law amendments in force 1 September 2012 — implied terms of quality and fitness for purpose; the consumer's right to repair, replacement, reduction in price, or rescission; the 6-month presumption of defect rule); s 6 (consumer's right to commence civil action). Enforced by Competition and Consumer Commission of Singapore ("CCCS") and the Consumers Association of Singapore ("CASE"). The principal consumer-protection statute. Applies in full. Treatment in § 16 below.
Sale of Goods Act 1979 (Singapore, adopted) + Unfair Contract Terms Act 1977 (Singapore, adopted) English statutes received into Singapore law via the Application of English Law Act 1993, with subsequent local amendments. SGA Part III implied terms; UCTA s 11 reasonableness requirement. Apply as additional consumer-protection layers. Apply. Treatment in § 16 below.
EU adequacy None. Singapore does not hold an EU adequacy decision under GDPR Art 45 at the Effective date. EU/EEA → Singapore transfers are governed by EU SCCs + Transfer Impact Assessment. Cross-reference in EU / EEA annex § 8. The absence of EU adequacy does not affect Balance's posture because Balance has no Singapore data residency (the backend is in the US — see § 9 below).
APEC Cross-Border Privacy Rules (CBPR) Singapore is a participating economy in the APEC Cross-Border Privacy Rules (APEC CBPR) system since 2018 + the APEC Privacy Recognition for Processors (PRP) system since 2018. The Singapore Accountability Agent under the APEC CBPR is IMDA (with PDPC supporting). The APEC CBPR is one of the lawful-cross-border-transfer mechanisms recognised under PDPR 2014 Reg 10. Applies as a context-setting fact (Balance relies on the PDPR 2014 Reg 10 contract-based route rather than APEC CBPR certification at the Effective date).
Convention 108 / Convention 108+ Not applicable. Singapore is not a party to the Council of Europe Convention 108 or Convention 108+. Applies as a context-setting fact. The Council-of-Europe layer is not engaged.

(Any prospective Singapore regulation governing automated processing, algorithmic decisions, or related techniques — including any post-Effective-date PDPC Advisory Guideline in that area, the IMDA's voluntary Model AI Governance Framework (2024 edition, voluntary and applies to government and industry by adoption only), the Model AI Governance Framework for Generative AI (May 2024, voluntary), the AI Verify framework (voluntary testing toolkit), any future Singapore AI Act or Model AI Bill before the Singapore Parliament, and any successor instrument — is intentionally omitted from this Annex on the principle that this Annex makes no affirmative or negative statement about whether Balance does or does not process personal data using techniques within the scope of any such Singapore regulation. Balance's substantive product posture is described elsewhere in the policy bundle and is the controlling reference; this Annex's silence on the topic is deliberate and is not to be read as an implicit statement either way.)


3. Supervisory authorities

3.1 PDPC — Personal Data Protection Commission

The principal supervisory authority is the Personal Data Protection Commission ("PDPC"), established as a statutory body under PDPA s 5 + the Personal Data Protection Commission Act 2012 (Singapore). The PDPC is administratively part of the Infocomm Media Development Authority ("IMDA") + the Ministry of Communications and Information ("MCI") (now the Ministry of Digital Development and Information ("MDDI") since the 2024 restructure).

Field Value
Name Personal Data Protection Commission (PDPC)
Headquarters 10 Pasir Panjang Road, #03-01 Mapletree Business City, Singapore 117438
Website https://www.pdpc.gov.sg/
Complaint channel PDPC online complaint form at https://www.pdpc.gov.sg/lodge-a-complaint, or via the PDPC's Personal Data Protection (Notice and Complaint Form); email info@pdpc.gov.sg
Phone +65 6377 3131
Mandatory-Breach-Notification channel PDPC online Data Breach Notification (Section 26D) form per PDPA Part VIA + PDPR-NDB 2021 — at https://eservice.pdpc.gov.sg/case/db — submission within 3 calendar days of the organisation determining that the breach is a notifiable data breach
Commissioner At the Effective date — Lew Chuen Hong (in his capacity as Chief Executive of IMDA) and the PDPC Commissioner as published at the PDPC website

The PDPC is the first-line forum for any PDPA-grounded complaint from any Singapore resident. A Singapore resident may petition the PDPC after first raising the matter with Balance (PDPC's published Guide to Complaints Process recommends this sequencing, but the PDPC also accepts direct complaints). We accept all DSAR / privacy enquiries at (named individual: , in his capacity as the DPO under PDPA s 11(3)) and respond within the PDPA timelines (see § 6 below).

A Singapore resident may also pursue private remedies against Balance via the Right of Private Action at PDPA s 48O (District Court / General Division of the High Court — loss or damage from a Part IV/V/VI contravention).

3.2 IMDA — Infocomm Media Development Authority

The Infocomm Media Development Authority ("IMDA") administers the Broadcasting Act 1994, the Films Act 1981, the Telecommunications Act 1999, the Spam Control Act 2007 (in part), and other digital-infrastructure statutes; the IMDA is also the Singapore Accountability Agent for the APEC CBPR.

Field Value
Name Infocomm Media Development Authority (IMDA)
Headquarters 10 Pasir Panjang Road, Mapletree Business City, Singapore 117438
Website https://www.imda.gov.sg/
Phone +65 6377 3800

3.3 Other regulatory bodies

Body Subject matter URL
Ministry of Home Affairs (MHA) OCHA Directions; cybercrime policy https://www.mha.gov.sg/
Singapore Police Force (SPF) — Police Cybercrime Command CMA + Penal Code cybercrime investigation https://www.police.gov.sg/
Ministry of Social and Family Development (MSF) — Child Protective Service (CPS) CYPA — child protection https://www.msf.gov.sg/ + https://www.msf.gov.sg/our-services/Pages/Child-Protective-Service.aspx
Competition and Consumer Commission of Singapore (CCCS) CPFTA + competition law https://www.cccs.gov.sg/
Consumers Association of Singapore (CASE) CPFTA consumer-protection advocacy https://www.case.org.sg/
National Council of Social Service (NCSS) Children-related social-service coordination https://www.ncss.gov.sg/
TOUCH Cyber Wellness Children's online-safety education and counselling https://www.touch.org.sg/
Singapore Children's Society Children's welfare NGO https://www.childrensociety.org.sg/

3.4 The DPO

PDPA s 11(3) requires every organisation to designate one or more individuals (whose responsibility is the policy and operational implementation of the PDPA — the Data Protection Officer — "DPO") to be responsible for ensuring that the organisation complies with the PDPA. PDPA s 11(5) requires that the business contact information of at least one DPO be made publicly available (typically on the organisation's website).

The Balance DPO is:

The DPO's business contact is published in this Annex, in the global Privacy Policy (Privacy Policy § 1), and at balance.babayagaprogram.com — satisfying PDPA s 11(5). The DPO is the contact point for the PDPC on any regulatory matter and for data subjects on rights-exercise matters. The DPO need not be located in Singapore (PDPC Advisory Guidelines on Key Concepts Chapter 11.2).


The PDPA is a consent-based regime modulated by deemed-consent provisions (introduced by the 2020 Amendment Act) and limited statutory carve-outs. Balance processes personal data of Singapore residents on the following PDPA mapping:

Processing purpose PDPA basis Cross-reference
Run the parental-control service the parent signed up for (account creation, family configuration, kid profile, limits, schedules, tasks, earned-time ledger, end-to-end-encrypted proof media) PDPA s 13(a) consent obligation (the parent's express consent at sign-up) + PDPA s 15(1) deemed consent by conduct (where the individual voluntarily provides personal data for a purpose, the individual is deemed to consent to the collection use or disclosure for that purpose) + PDPA s 15A deemed consent by contractual necessity (in force 1 February 2021 — where collection use or disclosure of personal data about an individual is reasonably necessary for the conclusion or performance of a contract or transaction to which the individual is a party) + PDPA s 18 purpose obligation + PDPA s 20 notification obligation H1 § 4; H7 PA-01 through PA-08; § 7 of this Annex
Process the kid's personal data PDPA s 13(a) + PDPA s 14 — the parent's consent on behalf of the kid + PDPC Advisory Guidelines on the PDPA for Children's Personal Data (which provides that an organisation should obtain consent of the parent/guardian for children under 13) § 7 of this Annex; our Data Protection Impact Assessment § 6
Deliver operational alerts PDPA s 13(a) + s 18 (primary purpose) H1 § 4; H7 PA-09; M3
Detect, prevent, and respond to security incidents, abuse, fraud, and unauthorised access PDPA s 17(1) read with First Schedule paragraphs 1(b)(i) and 1(b)(ii) (collection use or disclosure necessary for any investigation or proceedings + necessary for evaluation suitable for an emergency that threatens the life health or safety of any individual) + PDPA s 24 protection obligation H7 PA-15; § 13 below
Comply with legal, regulatory, and supervisory obligations PDPA s 17(1) read with First Schedule paragraph 1(d) (collection use or disclosure required or authorised by any written law) § 13 below; M1; § 14 below
Process Verifiable Parental Consent for the kid's data PDPA s 13(a) — collection of the parent's personal data for the primary purpose of obtaining VPC § 7 of this Annex; A-US § 5
Process the parent's billing / subscription data PDPA s 15A deemed consent by contractual necessity — necessary for the performance of the subscription contract; CPFTA + Lemon Law overlay in § 16 below H4; § 16 below

Balance does not rely on deemed consent by legitimate interests at PDPA s 15B (in force 1 February 2021) for any kid-side processing, even though the s 15B basis is theoretically available, because the express consent + deemed consent by contractual necessity bases are sufficient and more parent-aligned.

Balance does not collect any NRIC (National Registration Identity Card) number or other national identification number of any Singapore resident. The PDPC's Advisory Guidelines on the PDPA for NRIC and Other National Identification Numbers (issued 31 August 2018, in force from 1 September 2019) restrict the collection use or disclosure of an individual's NRIC number (and FIN — Foreign Identification Number, or BC number — Birth Certificate number, or other national identification numbers) except in specific permitted scenarios. Balance's posture aligns: no NRIC / FIN / BC number is collected.


5. Children's rights overlay

Singapore does not have a children-specific data-protection statute equivalent to COPPA (US), GDPR Art 8, or Quebec Private Sector Act s 8.1, at the Effective date. The children's regime is built up from (i) the PDPA + the PDPC's binding Advisory Guidelines on the PDPA for Children's Personal Data (issued under PDPA s 49); (ii) the Children and Young Persons Act 1993 (CYPA); (iii) the Penal Code 1871 age-of-consent provisions (16 for general consent; 18 for commercial sex); (iv) the common-law doctrine of parental authority and the Guardianship of Infants Act 1934 (Singapore — provides for joint parental responsibility); (v) the UN Convention on the Rights of the Child (Singapore acceded 5 October 1995, with reservations).

5.1 Definitions

For the purposes of this Annex:

Balance applies the most-protective reading and obtains Verifiable Parental Consent for every Singapore kid regardless of age, using the VPC mechanism in United States annex § 5 (email-verified parent account creation + payment-method capture at subscription time + parent's affirmative in-app action of creating the kid profile and pairing the kid's device). The VPC screen for Singapore residents itemises the categories of personal data being authorised, the purposes for which it is being processed, the third parties to whom it may be disclosed (sub-processors), and the data subject's rights under the PDPA.

Balance does not provide a kid-self-serve consent path inside the app. The parent always consents on behalf of the kid; the kid app's UI is designed for the kid to see their own limits, schedules, tasks, and earned-time ledger, and to request changes through the in-app "request change" affordance, which is forwarded to the parent device for the parent's decision. This is the most-protective reading of the PDPA + the PDPC Advisory Guidelines on the PDPA for Children's Personal Data + the CYPA's protection framework.

5.4 No advertising directed at children

Balance does not display advertising to any user (parent or kid), does not allow any third party to display advertising in Balance, and does not build a behavioural-advertising profile of any user. This is consistent with: (i) the PDPC's interpretive position on advertising to children; (ii) the Singapore Code of Advertising Practice by the Advertising Standards Authority of Singapore ("ASAS"); (iii) IMDA's Code of Practice for Online Safety (although Balance is not a designated DOCS). Cross-references: the Play Console Data Safety form § 2 (Contains ads: No); the Play Console Child Safety Standards declaration § 3 ATTESTATION-D.

5.5 Cooperation routes

The principal Singapore child-protection bodies are: (i) the Ministry of Social and Family Development (MSF) — Child Protective Service (CPS) — the principal child-welfare agency under the CYPA; (ii) the Singapore Police Force (SPF) — Anti-Scam Centre + Police Cybercrime Command — the principal law-enforcement nodes for cyber-CSAE; (iii) the National Council of Social Service (NCSS); (iv) TOUCH Cyber Wellness — children's online-safety education and counselling; (v) Singapore Children's Society; (vi) Tinkle Friend — Singapore Children's Society's helpline for children aged 7–12 (1800-274-4788); (vii) National CARE Hotline (1800-202-6868) — government 24/7 helpline. Balance cooperates with each on incidents involving Singapore kids — see § 14 below.


6. PDPA rights catalogue

6.1 The rights catalogue

A Singapore resident has the following rights under the PDPA + PDPR as in force at the Effective date.

6.2 Timeline

Where the request would be vexatious or where the access carve-outs at PDPA s 21(3) / s 21(4) / Fifth Schedule apply, Balance may decline to provide access and explain the reasons.

6.3 Identity verification

Where there is reasonable doubt about the identity of the natural person making the request, Balance may request additional information necessary to confirm the identity. The identity-verification protocol uses the parent's existing authentication credential.

6.4 Fees

Under PDPA s 28(2) + PDPR 2014 Reg 7, an organisation may charge a reasonable fee for processing an access request, provided the fee does not exceed the reasonable costs incurred. Balance does not charge for access in practice.

6.5 Language

A request may be submitted in English. The PDPC accepts complaints in English.


7. Children's data — PDPA + Advisory Guidelines on the PDPA for Children's Personal Data + CYPA

Balance processes personal data of Singapore kids under the following layered framework:

For Balance:

A parent may revoke consent at any time at Settings → Family → [kid name] → "Delete this kid" (or by email to ). Revocation triggers the cascade documented in Data Retention & Deletion Policy § 7. Revocation does not affect the lawfulness of processing carried out before the revocation.


8. International data transfers from Singapore — PDPA s 26 + PDPR 2014 Reg 9–11

The controller (BabaYaga Program, TOO) is established in Kazakhstan. The backend (Emergent Labs Inc.) is hosted in the United States. Proof-media storage (Google Cloud Storage) is in the United States. Push (Firebase Cloud Messaging), sign-in (Google Sign-In), and billing (Google Play Billing) are operated by Google LLC and dispatched from the United States. Transactional email (Resend) is dispatched from the United States. Accordingly, every Singapore resident's personal data leaves Singapore at the point of being uploaded to the Balance backend.

8.1 The Singapore-to-US transfer mechanism — PDPA s 26

PDPA s 26 is the transfer-limitation obligation: an organisation must not transfer any personal data to a country or territory outside Singapore except in accordance with requirements prescribed under the Act, to ensure that organisations provide a standard of protection to personal data so transferred that is comparable to the protection under the PDPA. PDPR 2014 Reg 9–11 sets out the prescribed conditions:

Balance relies on the following stack to satisfy PDPA s 26 + Reg 10 for the Singapore → US transfer:

8.2 The Singapore-to-KZ axis (controller administrative access)

The controller's personnel in Kazakhstan have administrative access to the US-hosted backend for operational purposes. Because Kazakhstan is a third country, the Singapore-KZ axis is covered by the Reg 10(2)(ii) contract route + Reg 10(1)(b) consent route — written processor agreements signed between Emergent Labs (as processor) and BabaYaga Program, TOO (as controller) in inverse, with EU-SCC substance preserved. The transfer-impact analysis for the KZ leg is in our international-transfer pack § 7.


9. Data residency for Singapore residents

Question Answer
Where is the backend hosted? United States. Emergent Labs Inc. (Delaware) on US infrastructure.
Where is the MongoDB database located? United States.
Where is the proof-media storage located? United States — Google Cloud Storage us multi-region.
Where are push notifications dispatched from? United States — Firebase Cloud Messaging.
Is any Singapore resident's personal data held in Singapore? No. Every Singapore resident's personal data is held in the United States. The PDPA s 26 + Reg 10 transfer mechanism in § 8 above is the legal basis for the transfer.
Where is the controller? Kazakhstan (BabaYaga Program, TOO). The controller has administrative access to the US-hosted backend via written processor agreements.
Is there a Singapore establishment? No. Balance has no permanent establishment in Singapore. The PDPA's extraterritorial reach (s 2(1) + PDPC Advisory Guidelines on Key Concepts Chapter 7) is the basis for Balance's PDPA compliance.
Where is the supervisory authority? Singapore — PDPC + IMDA + the regulatory bodies in § 3.3 above.

The decision to centralise on a US-only backend is documented in our internal compliance plan § 6. Singapore does not impose a comprehensive data-localisation mandate on parental-control services at the Effective date, with the exception of certain sector-specific regimes (e.g., the Cybersecurity Act 2018 in respect of CII operators — not applicable to Balance) and the Banking Act 1970 in respect of banking services (not applicable to Balance).


10. Sub-processors touching Singapore-resident data

Sub-processor Role Location of processing Singapore transfer paperwork
Emergent Labs Inc. (Delaware, USA) — using MongoDB Atlas (MongoDB, Inc., US) for the production database; relationship governed by Emergent ToS (22 Dec 2025) + Privacy Policy (28 May 2026) as the GDPR Art 28(3) "other legal act" (no standalone DPA available outside Enterprise per Emergent final position 2026-06-10; full handling in our internal vendor-handling plan); MongoDB Atlas Customer DPA + EU SCCs Module 2 + UK IDTA Addendum at https://www.mongodb.com/legal/dpa cover the storage layer Hosts the FastAPI backend + MongoDB cluster United States PDPR 2014 Reg 10(2)(ii) contract — written processor agreement with PDPA-comparable-protection clauses + Reg 10(1)(b) parent's consent on file per our international-transfer pack § 6; E2EE supplementary measure for proof media.
Google LLC — Google Cloud Storage (USA) Stores end-to-end-encrypted proof-media ciphertext United States (us multi-region) Reg 10(2)(ii) contract (Google Cloud Data Processing Addendum) + Reg 10(1)(b) consent; ciphertext-only handling.
Google LLC via Google Cloud (USA) Periodic (daily) backups of our operational database United States (us multi-region) Reg 10(2)(ii) contract (Google Cloud Data Processing Addendum) + Reg 10(1)(b) consent; the backup archive holds the operational data we hold about the resident (account, family, kid profile, usage totals, tasks, earned-time ledger, device identifiers, push tokens), other than the items that never reach our backend in readable form (the kid's proof media and the media-encryption keys); retained on a 30-day rolling window, then automatically deleted.
Google LLC — Firebase Cloud Messaging Delivers push notifications to Singapore kid + parent devices United States Reg 10(2)(ii) + Reg 10(1)(b) as above; push body deliberately free of sensitive content (cross-reference: the just-in-time permission disclosures).
Google LLC — Google Sign-In Authenticates parent Google identity (when used) United States Reg 10(2)(ii) + Reg 10(1)(b) as above.
Google LLC — Google Play Billing Processes subscription purchases United States Reg 10(2)(ii) + Reg 10(1)(b) + Google Play Developer Distribution Agreement.
Resend, Inc. (San Francisco, CA, USA) Delivers transactional email to Singapore parent users United States Reg 10(2)(ii) + Reg 10(1)(b).

Every sub-processor is bound by a written data-processing agreement that forbids processing of any data we transmit for any purpose other than performing the service we engaged them for, and that incorporates the security and confidentiality controls in our Records of Processing Activities (Article 30) § 7 + PDPA s 24 protection obligation. The full sub-processor list, with each row's processor-agreement status, is at our sub-processor register.


11. Breach notification — PDPA Part VIA (Mandatory Data Breach Notification scheme)

PDPA Part VIA (ss 26A–26E, in force since 1 February 2021 + PDPR-NDB 2021) is the strictest breach-notification regime in the landing-country set, with a hard 3-calendar-day deadline for PDPC notification:

Audience Trigger Deadline Channel
PDPC A notifiable data breach has occurred — defined at PDPA s 26B + PDPR-NDB 2021 Reg 3 as a data breach that (i) results in or is likely to result in significant harm to an affected individual (the significant-harm test, with Reg 3 specifying significant-harm categories) OR (ii) is of significant scale (a data breach affecting 500 or more individuals — PDPR-NDB 2021 Reg 3(2)). Within 3 calendar days of the organisation determining (after assessment) that the breach is a notifiable data breach. The organisation must conduct the assessment in a reasonable and expeditious manner (PDPA s 26C + PDPR-NDB 2021 Reg 4). Balance internal anchor: as soon as practicable but no later than 72 hours from initial discovery (matched to the GDPR Art 33 benchmark), with the formal PDPC notification submitted on the assessment-completion timestamp within the statutory 3-calendar-day window. PDPC online Data Breach Notification form per PDPA Part VIA + PDPR-NDB 2021 at https://eservice.pdpc.gov.sg/case/db
Affected individuals A notifiable data breach that meets the significant-harm-to-individual limb at PDPA s 26D(1)(a) — i.e., the breach results in or is likely to result in significant harm to an affected individual. No notification to individuals is required where the notification only meets the significant-scale limb at s 26B(1)(b) and where Reg 8 carve-outs apply (significant-scale-only breach without significant harm). At the same time or as soon as practicable after notifying the PDPC (PDPA s 26D + PDPR-NDB 2021 Reg 7). Direct email to the affected parent on file; in-app banner where the parent is logged in; out-of-app contact via the public-website incident page if email is no longer deliverable. The notification is in English.
CSAE-specific An incident with a CSAE component. Per § 14 below + the internal runbook (M1). SPF + MSF CPS + TOUCH Cyber Wellness.

The internal breach-decision SLA is at our breach-notification runbook § 5.4 + § 9: preliminary classification within one business day, formal assessment under PDPA s 26C completed within 72 hours of discovery, PDPC notification within the statutory 3-calendar-day deadline (the strictest deadline in the landing-country set), affected-individual notification at the same point unless one of the s 26D(5) / Reg 8 carve-outs applies (notification likely to compromise an ongoing investigation; the organisation has taken effective remedial action that renders significant harm to the individual no longer likely; etc.).

11.1 Minimum content of the PDPC notification (PDPA s 26C + PDPR-NDB 2021 Reg 5)

The PDPC notification states: - the date and circumstances of the notifiable data breach; - the personal data and categories of personal data involved; - the number of affected individuals (or the best estimate); - the manner in which the personal data was affected (including whether the data has been rendered unintelligible or whether the data has been retrieved or remains under unauthorised access); - the steps taken or proposed to be taken by the organisation in response to the breach (including any steps to remedy the breach + steps to contain the breach + steps to notify affected individuals); - the contact information of the DPO (, named individual: ).

The English-language template lives in our breach-notification runbook § 8.1.

11.2 Non-compliance — PDPA s 26E

Failure to notify the PDPC of a notifiable data breach is an offence and on conviction the organisation is liable to a fine not exceeding SGD 100,000 under PDPA s 26E. The PDPC may also impose financial penalties under PDPA s 60 for the underlying contravention of the protection obligation.


12. Cookies, spam, and electronic direct marketing

Singapore does not have a dedicated ePrivacy / cookies statute. The substantive position on cookies and electronic direct marketing is derived from: (i) PDPA s 13 + s 18 + s 20 for any cookie that processes personal data; (ii) the PDPC's Advisory Guidelines on the PDPA for Selected Topics Chapter on cookies; (iii) the Spam Control Act 2007 for commercial electronic messages; (iv) the PDPA Part VII Do Not Call Registry for telemarketing voice calls + SMS / faxes (s 36–48).

12.1 In-app — strictly-necessary storage only

The Balance app (parent and kid) does not deploy any cookie-equivalent storage that is not strictly necessary for the service. The strictly-necessary storage Balance uses (authentication tokens in Android SecureStore; the device-pairing key wrap; the kid app's earned-time cache) is operationally necessary and is covered by the parent's sign-up consent.

The public legal-documents site (balance.babayagaprogram.com) uses only strictly-necessary cookies; no analytics cookies; no advertising cookies; no third-party trackers; no fingerprinting; no embedded social plugins.

12.3 Electronic direct marketing — not sent

Balance does not send commercial electronic messages within the meaning of Spam Control Act 2007 s 2(1) to Singapore residents. The only email Balance sends to Singapore parent users is transactional — account creation, password reset, subscription receipts, security alerts, and parent-action notifications. The SCA's "commercial electronic message" definition requires the message to promote or solicit the supply of goods or services; transactional messages are outside the definition. If Balance ever introduces a marketing channel, we will comply with SCA Schedule I (sender identification + valid unsubscribe + accurate message subject) and Schedule II (unsubscribe facility), and we will check the PDPA Part VII Do Not Call Registry for any number we intend to call before placing a telemarketing call.

12.4 No telemarketing

Balance does not place telemarketing voice calls, SMS, or faxes to Singapore residents. The PDPA Part VII Do Not Call Registry obligations are not engaged.


13. Lawful-access requests and the encryption posture

Singapore authorities may serve a lawful-access request on Balance via:

The Balance architectural posture interacts with these mechanisms as follows:

The full encryption posture is in our encryption-posture record.


14. CSAE reporting routes — Singapore

A Singapore resident (parent, kid, or third party) who wishes to report a CSAE concern about Balance, about a third party encountered outside Balance, or about a Balance user, may use any of the following routes:

The full CSAE Country Routing Table is in Child Safety Standards § 8.6.


15. Complaint routes (summary)

A Singapore resident who is dissatisfied with Balance's handling of a privacy enquiry or a child-safety concern may complain to any of the following authorities:

Authority Subject matter Address / URL
Personal Data Protection Commission (PDPC) PDPA 10 Pasir Panjang Road, #03-01, Mapletree Business City, Singapore 117438; https://www.pdpc.gov.sg/; +65 6377 3131
Infocomm Media Development Authority (IMDA) Broadcasting Act + Films Act + Code of Practice for Online Safety + APEC CBPR Accountability Agent 10 Pasir Panjang Road, Mapletree Business City, Singapore 117438; https://www.imda.gov.sg/; +65 6377 3800
Singapore Police Force (SPF) — Police Cybercrime Command CMA + Penal Code https://www.police.gov.sg/; emergency 999; non-emergency 1800-255-0000
Ministry of Social and Family Development (MSF) — CPS CYPA https://www.msf.gov.sg/; 1800-777-0000
Competition and Consumer Commission of Singapore (CCCS) CPFTA + competition law https://www.cccs.gov.sg/; +65 6325 8255
Consumers Association of Singapore (CASE) CPFTA consumer-protection advocacy https://www.case.org.sg/; +65 6100 0315
Data Protection Appeal Panel Appeals from PDPC decisions under PDPA Part X via PDPC
District Court of Singapore PDPA s 48O private right of action + CPFTA s 6 civil action https://www.judiciary.gov.sg/
General Division of the High Court of Singapore PDPA s 48O above District Court limits; appeals from Data Protection Appeal Panel https://www.judiciary.gov.sg/

A Singapore resident may always first raise the matter with us at (DSAR; named individual: , in his capacity as the DPO under PDPA s 11(3)). We will respond within the PDPA timelines. Raising the matter with us first is recommended by the PDPC but is not a precondition to complaining to the PDPC.


16. Consumer rights — the CPFTA + Lemon Law + Sale of Goods Act + Unfair Contract Terms Act overlay

The Consumer Protection (Fair Trading) Act 2003 (Singapore) ("CPFTA"), as substantively amended to include the Lemon Law provisions at CPFTA Part III (in force 1 September 2012), applies to Balance's subscription flow as a consumer transaction — the parent is a consumer within CPFTA s 2 (not engaged in trade or business in the transaction). The Sale of Goods Act 1979 (Singapore, as adopted) and the Unfair Contract Terms Act 1977 (Singapore, as adopted) layer additional implied terms. Treatment is implemented in Subscription Terms § 20.

16.1 Unfair practices (CPFTA s 4)

CPFTA s 4 prohibits unfair practices — false claims, misleading representations, exploitative conduct, accepting payment when there are reasonable grounds to believe the supplier will not be able to supply, taking advantage of a consumer's inability to protect his or her own interests, etc. The Specified Acts under the Second Schedule include over 20 categories of prohibited conduct. The Balance Terms of Service (Terms of Service) and the in-app subscription flow are drafted to avoid each CPFTA s 4 risk.

16.2 Lemon Law — CPFTA Part III (in force 1 September 2012)

The CPFTA Part III "Lemon Law" extends implied consumer guarantees and remedies. The principal Lemon Law rules:

The Lemon Law applies in modified form to subscription services where the service is supplied as a discrete continuing supply (i.e., Balance subscription).

16.3 Sale of Goods Act + Unfair Contract Terms Act

The Sale of Goods Act 1979 implied terms include: SGA s 13 description; SGA s 14 satisfactory quality + fitness for purpose. The Unfair Contract Terms Act 1977 s 11 requires that any term restricting liability satisfy the reasonableness test, having regard to the resources of the parties + the bargaining position + whether the consumer received an inducement.

16.4 Forum and choice of law

The Balance Terms of Service preserve the consumer's domicile forum (see Terms of Service § 19); choice-of-law clauses that would displace the CPFTA, Lemon Law, Sale of Goods Act, or Unfair Contract Terms Act to the prejudice of the Singapore consumer are subject to the reasonableness test under the UCTA s 11 + the public policy doctrine. The CCCS may seek injunctive relief under CPFTA s 9A in respect of unfair practices.

16.5 Refunds and the Singapore subscription posture

Balance honors a voluntary 14-day no-questions refund window via Google Play Billing, exceeding the CPFTA + Lemon Law minimum standards for a subscription-service supply. The 14-day refund window is documented at Subscription Terms § 20.


17. Cross-references


18. Versioning and review

This Annex follows the same strict versioning protocol as the rest of the Phase-1 bundle:


End of Singapore Country Annex.

← Back to Privacy Policy · Children's Privacy Notice