RealRelay.ai Privacy Policy

Last Updated: [2026-09-01]

CWG INNOVATIONS PTE. LTD. ("RealRelay.ai", "we", "us" or the "Company") respects and values your privacy. This RealRelay.ai Privacy Policy (this "Policy") explains how we collect, use, store, share, transfer and protect data relating to an identified or identifiable individual ("Personal Data"), and the rights available to you, when we provide the RealRelay.ai website (the "Platform") and its related services (collectively, the "Services").

The Services are intended for individual users and persons using the Services on behalf of enterprises, government agencies or other organisations (collectively, "you"). If you use the Services on behalf of an organisation, you shall ensure that you have obtained all authorisations required to provide us with the relevant individuals' Personal Data and to process Interaction Data, and that those individuals have received all required notices. If you do not agree to this Policy, please cease using the Services. By using the Services, you acknowledge and agree that we will process your relevant information in accordance with this Policy.

Overview

  1. How We Use Your Personal Data
  2. Data Sharing
  3. Third-Party Platforms and Services
  4. Upstream Models
  5. Data Storage and Cross-Border Transfers
  6. How We Protect Personal Data
  7. Your Choices and Rights
  8. Minors
  9. Singapore-Specific Provisions
  10. Governing Law and Dispute Resolution
  11. Updates to this Policy and How to Contact Us

1. How We Use Your Personal Data

1.1 The following sets out in detail the types of Personal Data we collect from you, the purposes for which we process such data and the retention period applicable to each type of Personal Data.

Personal Data and How It Is CollectedProcessing Purposes and Applicable Legal BasesRetention Period
Account and organisation information (provided directly by you when you register, log in, create an organisation or use customer support, or provided by an organisational customer), such as username, email address, login verification information, organisation name, administrator information, job title and contact information. If you use an account from another platform to log in to the Platform, you authorise us to obtain relevant account and profile information from those third-party platforms (including Google and GitHub).To open accounts, verify identity, manage organisations, allocate permissions, manage API Credentials and provide customer support. Legal basis (only in relevant jurisdictions): performance of a contract with you or the organisation you represent.For the duration of the account and for a reasonable period after account deletion as necessary to resolve disputes, comply with legal obligations or maintain security safeguards.
Transaction and billing information (provided by you or a payment service provider), such as orders, subscriptions, invoices, payment status, usage, tax information and billing contact information. Full payment-card or account information is generally processed by the payment service provider in accordance with its own policy.To measure usage; manage orders and subscriptions; process payments and refunds; manage tax and reconciliation; and control transaction risk. Legal bases (only in relevant jurisdictions): performance of a contract, compliance with applicable accounting or tax obligations, and legitimate interests permitted by applicable law.Retained in accordance with applicable accounting, tax, payment-dispute and statutory retention requirements.
Interaction Data (submitted by you through our APIs to Upstream Providers, and outputs generated by Upstream Providers), such as prompts, input content (which may include multimodal data such as text, video and audio), model outputs, attachments and other conversation content.To route interaction requests to Upstream Providers selected by you or selected under the routing rules authorised by you, generate and return outputs, maintain security and provide the features you have enabled. Legal basis (only in relevant jurisdictions): performance of a contract with you or the organisation you represent.Retained only for the reasonable period necessary to complete the routing request, provide the features you have enabled, troubleshoot, maintain security safeguards or comply with legal obligations. The retention rules of Upstream Providers apply separately.
API data (provided or automatically generated when you make calls through the API), such as API request parameters, selected models, routing information, records related to use of API Credentials, request metadata, token usage, API response status and related technical information.To authenticate and manage API Credentials, execute API requests, route models, return API results, measure usage, bill, troubleshoot, audit and prevent misuse. Legal bases (only in relevant jurisdictions): performance of a contract, compliance with legal obligations and legitimate interests permitted by applicable law.Retained for the minimum reasonable period necessary to complete API calls, measure usage and bill, troubleshoot, maintain security safeguards, audit or comply with legal obligations.
Usage, access, behavioural and security logs (automatically generated when you use the Services), such as log-in and log-out events, pages accessed, time spent on pages, clicks, feature operations, API calls, tasks, exceptions, Cookies or similar identifiers, device, browser, operating-system and IP-address information, session identifiers, timestamps, request source, token usage, errors and security-event information.To operate the Services, provide and improve your experience, conduct statistical analysis, measure usage and bill, audit, troubleshoot, prevent misuse and maintain information security. Legal bases (only in relevant jurisdictions): performance of a contract, compliance with legal obligations and legitimate interests permitted by applicable law, including maintaining network and system security and improving the Services.Retained for the minimum reasonable period necessary for security, auditing, usage measurement and billing, troubleshooting and legal obligations. When the processing purpose no longer applies and we have no legal or business need to retain the data, we will delete or de-identify the data in accordance with our internal data-retention and deletion rules. For data collected through Cookies, you may withdraw consent at any time through Cookie settings.
Customer-support and communications information (provided by you through email, support tickets, online support, surveys or other means), such as contact information, descriptions of issues, feedback and communications records.To respond to enquiries, handle complaints, resolve disputes, improve customer support and retain necessary communications records. Legal bases (only in relevant jurisdictions): performance of a contract, responding to your request and legitimate interests permitted by applicable law.Retained for the period necessary to process the request, preserve communications evidence and comply with statutory obligations.
Marketing and event communications information (provided when you subscribe, participate in an event or permit us to contact you), such as name, contact information, subscription preferences and interaction records.To send you marketing or event information relating to the Services and manage unsubscribe requests. Legal bases (only in relevant jurisdictions): your consent or another direct-marketing basis permitted by applicable law. You may unsubscribe at any time using the method provided in the relevant email.Until you unsubscribe or withdraw your consent.
Identity, geographic and compliance information (provided directly by you or collected automatically), such as country or region of registration, corporate-entity or billing information, IP address, telephone-country code and information necessary to implement geographic controls.To determine available services, enforce geographic, export-control, sanctions and Upstream Provider restrictions, and prevent fraud and unlawful use. Legal bases (only in relevant jurisdictions): performance of a contract, compliance with legal obligations and legitimate interests permitted by applicable law.Retained for the minimum reasonable period necessary to provide the Services, implement the relevant restrictions and address risks.

1.2 In order to provide you with better and more personalised services, or to detect fraud and other reasons, our affiliates and partners may share your information with us as required by law, pursuant to agreements with you or with your consent.

1.3 We may process Personal Data in aggregated or anonymised form to analyse the effectiveness of our Services, study user behaviour and share such aggregated or anonymised information with business partners. For example, to improve user experience, we may analyse and aggregate users' general behavioural and usage data. Such information does not identify individual users. We may disclose input information in aggregated and anonymised form, which is not associated with your user ID, in order to develop commercial relationships with business partners.

1.4 In certain jurisdictions, certain types of Personal Data (such as information relating to your race, religion, political or philosophical views, sexual orientation or health) may be regarded as "sensitive information" and be subject to more stringent regulation than other types of Personal Data. We do not require you to provide sensitive Personal Data in order to use the Services. If you provide any sensitive Personal Data, you consent to our processing of that information within the scope of the privacy controls you select.

1.5 For information about our use of Cookies and similar technologies, please see our Cookie Policy.

2. Data Sharing

2.1 We may share your Personal Data with our affiliates so that we can provide the Services to you.

2.2 We engage service providers to provide various services that support and improve our Services. In addition to our affiliates, we use certain third-party service providers, such as Stripe (which provides payment card processing and verification services) and Alipay.

2.3 When you use third-party services, we may receive information about you from, and/or share information about you with, such third-party services. Third-party services may collect information (including Personal Data and log data) and place Cookies on your device. This Policy applies only to information we collect and does not apply to information collected by third parties.

2.4 If a third party or a relevant group company undergoes a merger, acquisition, reorganisation or sale, or where required by law or for other reasons, we will transfer your information to such entity so that it can continue to provide the Services to you.

2.5 When you submit Interaction Data through the Services, we process such data in order to fulfil your request, maintain security, measure usage or provide the features you have enabled, and transmit the necessary request content to the Upstream Providers selected by you or selected in accordance with routing rules authorised by you.

2.6 We may disclose your Personal Data to government, public-sector, regulatory, judicial and law-enforcement authorities. In certain circumstances, we are required by law to disclose your information, including to comply with legal obligations or requirements such as court orders, subpoenas or other legal processes; enforce our terms; or address security- or fraud-related matters.

2.7 We may share or disclose your Personal Data with our advisers, including auditors and lawyers, in the course of seeking professional advice.

2.8 We may publicly share aggregated and de-identified information (for example, aggregated trends concerning general use of our Services) and share it with our affiliates, subsidiaries and partners.

3. Third-Party Platforms and Services

3.1 The website may link to, rely on or integrate websites, applications, interfaces, services and platforms operated by other companies, including third-party services. We are not responsible for the privacy practices of any third-party websites, applications, interfaces, services and platforms this website links to, relies on and/or integrated with this website, or for the privacy practices of third-party advertising companies.

3.2 Once you leave this website through a link or access a third-party service, you should review the applicable privacy policy to determine how the relevant company handles any Personal Data it may collect about you.

4. Upstream Models

4.1 We do not use your input or output data to develop, train, or improve models. However, different Upstream Providers may apply different rules regarding data-storage locations, retention periods, training, evaluation, improvement or security review. Before using any model, you should read and comply with the applicable Upstream Terms. The relevant Upstream Terms may be found in the Upstream Model Provider Terms.

4.2 You understand and agree that you are responsible for storing your Interaction Data in accordance with your own needs. We provide data-storage services only where required by applicable laws and regulations or specified by particular service rules. Unless otherwise required by laws and regulations or agreed in service rules, we have no obligation to store your Interaction Data and assume no responsibility for your data-storage activities or results.

4.3 You shall ensure that you have the necessary rights, authorisations and lawful basis for processing the Interaction Data. Unless permitted by applicable law and you have fulfilled all necessary obligations, you shall not submit another person's sensitive Personal Data, information about minors, trade secrets, information subject to confidentiality obligations or other restricted data. You shall independently assess, in accordance with the rules of the selected model, whether it is appropriate to submit the relevant data.

5. Data Storage and Cross-Border Transfers

We store Personal Data collected from you on our servers located in Singapore. For technical-support purposes, we may access such data remotely from mainland China. Depending on the Upstream Provider you select, Interaction Data will be transferred to the applicable Upstream Provider. Please refer to the Upstream Model Provider Terms for the specific data-storage locations and processing rules of the relevant Upstream Provider.

6. How We Protect Personal Data

6.1 We will implement administrative, technical and physical measures appropriate to the nature of, and risks associated with, the information processed in order to prevent Personal Data from unauthorised access, collection, use, disclosure, copying, modification, loss or improper disposal. Such measures may include access controls, least-privilege controls, authentication, protections for data in transit and at rest, log monitoring and security-incident response.

6.2 Please understand, however, that no Internet transmission, electronic storage or security measure can guarantee absolute security. If you suspect any unauthorised use or security incident, please contact us promptly.

7. Your Choices and Rights

7.1 Please note that, in order to protect your information, we will need to verify your identity before responding to any request to exercise your rights.

7.2 You have the right to request access to the Personal Data we hold about you, to understand how we use that information and to know with whom we share it.

7.3 You also have the right to correct inaccurate or incomplete information. You may access and correct your Personal Data through your account.

7.4 You may log in to your account to delete your account or certain Personal Data. Account closure is irreversible. Upon completion of the closure, you will no longer be able to log in to or use that account, its API Credentials or functions associated with that account. By proceeding with account closure, you acknowledge that any remaining credits will be forfeited. We will process account closure only after you provide express confirmation. Following account closure, we will retain relevant data only for the period necessary to comply with legal obligations, tax or accounting requirements, preserve transaction records, prevent fraud and safeguard security, handle complaints or disputes, or establish, exercise or defend legal claims. Aggregated or irreversibly anonymised data that no longer identifies you may continue to be retained. For further account-closure terms, please see the Account Deletion Policy.

7.5 You may request that we erase the Personal Data we hold about you in the following circumstances: you believe we no longer need to hold your Personal Data; we processed your Personal Data on the basis of your consent and you withdraw that consent (and we have no other valid and lawful basis for processing the relevant Personal Data); or you were a minor when we collected the Personal Data and we can verify that fact. While we consider your erasure request, you may exercise your right to restrict our processing of your Personal Data. We may retain Personal Data where we have a sufficient legal basis to do so.

7.6 In certain circumstances, you have the right to require us to stop processing your Personal Data. However, where we have another valid legal basis to process your Personal Data, we may continue such processing.

7.7 You also have the right to request that we transfer your Personal Data to another party. If you ask us to transfer your Personal Data to a third party, please ensure that you provide the details of that third party. Please note that we can make such a transfer only where technically feasible. Once the third party receives the Personal Data, we will no longer be responsible for its security or processing.

7.8 If you do not want us to use your email address or other contact details to promote our Services, you may contact us to opt out. You may also choose to stop receiving promotional or marketing communications by following the "unsubscribe" instructions contained in those communications. We will, however, continue to send necessary non-promotional and non-marketing communications. Opt-out and unsubscribe requests may not take effect immediately as it takes time to be received, processed and implemented. Until such requests are implemented, your information will remain subject to your previous privacy settings. In addition, unless applicable law provides otherwise, any information provided to third parties before you opt out or unsubscribe will not be retrieved or withdrawn.

7.9 You may exercise your relevant rights by contacting us at legal@cwgsg.ai.

8. Minors

The Services are intended only for individual developers, enterprises and organisational users with the requisite legal capacity, and are not designed for minors (as determined by the age specified in the applicable jurisdiction). We do not knowingly collect Personal Data from minors. If you do not meet these requirements, you must not use the Services.

9. Singapore-Specific Provisions

9.1 This section applies if you are located in Singapore or if our collection, use or disclosure of your Personal Data is governed by Singapore's Personal Data Protection Act 2012 ("PDPA").

9.2 We will process your Interaction Data in accordance with this Policy and any written agreement entered into with you (if any), and in accordance with your instructions. We will act as a data intermediary in respect of such Interaction Data. You are responsible for providing necessary notices, obtaining consent or having another lawful basis for processing, and for handling data-subject requests that you are required to respond to directly. We will nevertheless fulfil our applicable obligations concerning information security, retention limitations, data-breach notification or assistance.

9.3 Where data processed by us constitutes business contact information under the PDPA (such as names, titles, business telephone numbers or business addresses), you are responsible for providing necessary notices, obtaining consent or having another lawful basis for processing, and for handling data-subject requests that you are required to respond to directly. We will nevertheless fulfil our applicable obligations concerning information security, retention limitations, data-breach notification or assistance.

9.4 We have appointed a Data Protection Officer as required under the PDPA. The Data Protection Officer may be contacted at legal@cwgsg.ai.

10. Governing Law and Dispute Resolution

10.1 This Policy and any dispute or claim arising out of or in connection with this Policy shall be governed by the laws of Singapore, without regard to its conflict of law principles. This Agreement is executed solely in English, and any translation into any other language shall not be binding on the parties.

10.2 To the maximum extent permitted by applicable law, any dispute, controversy or claim (whether in contract, tort, or otherwise) arising out of, relating to, or in connection with this Agreement, including its existence, validity, interpretation, performance, breach, or termination, shall be submitted to the Singapore International Arbitration Centre for arbitration and final resolution in accordance with the Arbitration Rules of the Singapore International Arbitration Centre in force when the Notice of Arbitration is submitted. The seat of the arbitration shall be Singapore. There shall be one arbitrator only. The arbitration proceedings shall be conducted in English.

10.3 You and we agree that, to the maximum extent permitted by applicable law, before either party initiates any legal proceedings, the parties shall first attempt to informally resolve their dispute. You shall notify us of your intent to initiate the informal dispute resolution process by emailing legal@cwgsg.ai. An informal dispute resolution conference shall be held within sixty (60) days of such notice, unless an extension is mutually agreed upon by the parties. Any statute of limitations shall be tolled while the parties attempt to resolve the issues through this informal process. The informal dispute resolution conferences shall be individualised; multiple individuals initiating claims shall not participate in the same informal dispute resolution conference unless mutually agreed to in writing by the parties. If a party is represented by counsel, the counsel may participate in the conference, but both parties shall attend and fully participate in the conference. If the parties cannot resolve the issue within 60 days of the notice, either party may initiate the arbitration process.

10.4 Completion of this informal dispute resolution process is a requirement that must be fulfilled before commencing arbitration or any other legal proceeding. An arbitration or any other legal proceeding shall be dismissed if it was filed without fully and completely complying with these informal dispute resolution procedures.

10.5 Nothing in this section shall exclude or limit any non-waivable rights granted to you by applicable law, including the right to file a complaint with a competent regulatory authority, or to bring claims in a local court (including a small claims court) where permitted by applicable law.

11. Updates to this Policy and How to Contact Us

11.1 We may update this Policy to reflect changes in the features of the Services, our data-processing activities, legal requirements or other legitimate needs. For material changes, we will provide prominent notice through a website announcement or other appropriate means before the changes take effect. Your continued access to or use of the Services constitutes your acceptance of the revised Policy.

11.2 If you have any questions, complaints or requests concerning this Policy, our processing of Personal Data or your rights, please contact us at legal@cwgsg.ai.