Privacy & Data Protection Policy

Last Updated: October 2025

1. Purpose

This Privacy & Data Protection Policy (“Policy”) explains how NextBoss.ai (“we”, “us”, or “our”) collects, uses, discloses, and protects your personal data in compliance with the Personal Data Protection Act 2012 of Singapore (PDPA) and other applicable laws. By using our Platform, you consent to our data practices as described below.

2. Scope

This Policy applies to all users of NextBoss.ai, including buyers, sellers, startup founders, investors, and visitors using our website, Telegram bot, or related services (collectively, the “Platform”).

3. Data We Collect

  • Account Data: name, email address, Telegram username or ID, and authentication details.
  • Business Listing Data: information you voluntarily provide when creating listings or Launchpad entries (e.g., business description, price, location, documents, media).
  • Transaction Data: credits, payments (via Telegram Stars or other gateways), and transaction history.
  • Usage Data: IP address, browser type, device data, referring URLs, and interaction logs for security and analytics.
  • AI Interaction Data: chat messages, prompts, and extracted fields used to process and improve AI accuracy.
  • Communication Data: messages sent via our forms or chatbots, including support or dispute communications.

4. How We Use Your Data

  • To operate, maintain, and improve the Platform and AI features.
  • To enable user authentication, listings, payments, and credits.
  • To connect buyers, sellers, and Launchpad participants.
  • To communicate service updates, support, and compliance notices.
  • To detect, investigate, and prevent fraud or policy violations.
  • To comply with applicable laws, regulations, or lawful government requests.

5. Use of AI and Automation

NextBoss.ai uses artificial intelligence models to extract, summarize, and format information from text inputs or uploaded data. These systems may process your input content to generate responses or assist in listing creation. We do not use AI for automated decision-making that produces legal or similarly significant effects without human review.

AI data processing occurs under strict access control, and no personal identifiers are used for model training outside the Platform’s own internal improvements.

6. Launchpad Data & Investor Protection

Launchpad submissions and investor interactions are entirely user-driven. We do not verify or endorse any project, nor do we store financial documents or investment commitments. Users must not submit any sensitive financial data or personal identification numbers (e.g., NRIC, FIN, or passport numbers) on public listings.

Any communication or transaction that proceeds off-platform is at your sole discretion and risk. You are encouraged to conduct independent verification, and never share private banking credentials or personal information through our chatbots.

7. Data Disclosure

We may share your data with:

  • Service providers supporting our operations (hosting, AI, payments, analytics).
  • Regulatory or law enforcement authorities, where required by law.
  • Parties involved in a merger, acquisition, or business transfer, under confidentiality obligations.

We do not sell or rent personal data to third parties for marketing purposes.

8. International Transfers

Some of our data processors or servers may be located outside Singapore. When personal data is transferred overseas, we ensure that the receiving party provides a comparable standard of protection as required under the PDPA.

9. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes outlined in this Policy or as required by law. When data is no longer needed, it will be securely deleted or anonymized.

10. Security Measures

We implement reasonable administrative, physical, and technical safeguards to protect data against unauthorized access, loss, misuse, or alteration. However, no online transmission or storage system is completely secure, and we cannot guarantee absolute security.

11. Your Rights

Under the PDPA, you have the right to:

  • Request access to personal data we hold about you;
  • Request correction of inaccurate or incomplete data;
  • Withdraw consent for specific uses of your data (subject to legal and contractual limitations).

Requests can be submitted via our contact form. We may require proof of identity and a reasonable processing time to respond.

12. Cookies & Tracking

Our website may use cookies and analytics tools to enhance user experience and measure traffic. You may disable cookies in your browser, but some features may not function properly.

13. Children’s Data

The Platform is not intended for individuals under 18 years old. We do not knowingly collect personal data from minors. If we discover that data has been submitted by a minor without parental consent, it will be deleted promptly.

14. Data Breach Notification

In the event of a data breach that may result in significant harm, we will notify affected individuals and the Personal Data Protection Commission (PDPC) in accordance with PDPA requirements.

15. Updates to This Policy

We may update this Policy periodically to reflect changes in our practices or legal requirements. Updated versions will be posted with a new “Last Updated” date, and your continued use of the Platform constitutes acceptance of the revised Policy.

16. Contact Us

For any questions, feedback, or data-related requests, please contact our Data Protection Officer (DPO) via the contact form on our website. We aim to respond within a reasonable time frame in accordance with PDPA standards.