
GDPR stands for General Data Protection Regulation. It is a data protection and security regulation written in EU law to protect all citizens in the European Union (EU) and European Economic Area (EU) from data breaches and misuse or exploitation of information. However, GDPR regulations should be applied worldwise, which means it protects any individual that has shared personal information or data with any organisation including outside the EU. Organisations that do not comply to the strict GDPR conditions will face severe penalties.
Control
We ensure that you have full control over your personal information. Under GDPR laws, you have the right to withdraw and limit access to personal information and data.
Consent
We will not use any of your personal information or data without your consent. We also request for your consent in a clear and reliable manner.
Privacy
Your right to privacy is our priority. We will only use your data and information within and only within the purposes stated in our privacy policy.
Compliance
As you trust us to use your data to administer your employee surveys, we make it our responsibility to keep your data safe and secure. This makes you GDPR compliant as well.
Awareness
EngageRocket provides easy access to a variety of our resources and policy information to ensure that you are aware of how and why we use your personal information and data.
Confidentiality
With the option of conducting confidential surveys, we ensure high data integrity and protect your employees by ensuring their personal information stays confidential.
This Privacy Policy outlines how we collect, use, disclose, and protect personal data in accordance with applicable privacy laws, including Singapore’s Personal Data Protection Act (PDPA), the California Consumer Privacy Act (CCPA/CPRA), and the European Union General Data Protection Regulation (GDPR), as well as the UK GDPR and the Swiss Federal Act on Data Protection (FADP).
We are committed to protecting the privacy and security of your personal data. This Policy explains our practices when acting as a Data Controller or Data Processor under applicable laws, including GDPR, PDPA, and CCPA. We process personal data only for legitimate business purposes and in accordance with the principles of lawfulness, fairness, transparency, data minimization, accuracy, storage limitation, integrity, confidentiality, and accountability.
Under GDPR, we may act as either a Data Controller or Data Processor, depending on the context of processing. As a Data Controller, we determine the purposes and means of processing personal data. As a Data Processor, we process personal data on behalf of our clients in accordance with their documented instructions.
We have appointed a Data Protection Officer (DPO) to oversee our data protection compliance and to serve as the primary contact point for data protection inquiries. DPO contact details can be found at the bottom of this page.
We collect personal data such as names, contact information, login credentials, and usage data to deliver our SaaS services, support users, and comply with contractual and legal obligations.
We use essential technical mechanisms to support core functionalities and continued service delivery, such as enabling users to resume their survey responses or activities, troubleshooting, and platform optimisation where applicable. These mechanisms are strictly for operational continuity and not used for advertising, profiling, or analytics for commercial purposes.
Under GDPR, our lawful bases for processing may include consent, performance of a contract, compliance with legal obligations, protection of vital interests, performance of a task carried out in the public interest, and legitimate interests.
Depending on your location, you may have the following rights under applicable privacy laws:
- Access your personal data and receive a copy
- Correct or update inaccurate data
- Request erasure of your data ('right to be forgotten')
- Restrict or object to data processing - Withdraw consent at any time (without affecting prior lawful processing)
- Request data portability
- Lodge a complaint with a relevant data protection authority
We operate globally and may transfer personal data outside your country of residence. Where personal data is transferred internationally, we use transfer mechanisms such as Standard Contractual Clauses (SCCs) or other approved safeguards to ensure appropriate protection.
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, loss, misuse, or disclosure. Our information security program follows internationally recognized frameworks including ISO 27001, Soc 2 and is regularly audited by independent assessors to verify the effectiveness of our controls for security, availability, and confidentiality.
Personal data is retained only as long as necessary to fulfill the purposes outlined in this Policy, unless a longer retention period is required or permitted by law.
We may update this Policy periodically to reflect changes in legal or operational requirements. Updates will be posted on our website with the revised effective date.
For any questions about this Privacy Policy or your data protection rights, please contact us at compliance@engagerocket.co

Copyright © 2024 EngageRocket Pte Ltd. All rights reserved unless otherwise stated.