Privacy Notice
Last updated 10 October 2026
This notice explains how Cloudswired Technologies ("we"), which operates SkillPass, handles personal data, in line with the Personal Data Protection Act 2010 (PDPA). It covers two groups of people: training providers who use SkillPass, and participants who register with those providers.
1. Training providers and their staff
When you create an account we collect your name, email, phone number, organisation details and your activity in the dashboard. For billing we keep invoices and payment records.
We use this to run your account, bill you, support you, keep the service secure and tell you about important changes. We are the data user for this data.
2. Participants
When you register for a programme on a provider's SkillPass site, the provider is the data user of your data and decides how it is used. Their privacy notice is linked on their site. We process your data on the provider's behalf to run registrations, payments, attendance and certificates.
Your IC or passport number is encrypted when stored and shown masked to staff; each time a provider's staff member views the full number it is logged.
To use or change your data, please contact the provider first. If you can't reach them, contact us and we will pass your request on.
3. Certificate verification
Anyone with a certificate's verification code (for example from its QR code) can see that the certificate is genuine: the holder's name, programme, dates, issuing provider and status. IC numbers are never shown in full on verification pages.
Certificate records are kept for as long as the certificate may need to be verified, including after a provider stops using SkillPass.
4. Who we share data with
We use service providers to run SkillPass: hosting (Vultr, Singapore), database and file storage (Supabase, Singapore), network and security (Cloudflare), email delivery (Zoho ZeptoMail) and payments (CHIP). They process data only to provide their service to us.
We don't sell personal data. We disclose it to authorities only when the law requires.
5. Security and retention
Data is encrypted in transit, access is limited by role, sensitive identifiers are encrypted at rest, and databases are backed up daily.
Provider account data is kept while the account is active and for up to 7 years after for accounting and legal purposes. Participant data is kept as the provider instructs, except minimal certificate records as described above.
6. Your rights
You may request access to or correction of your personal data, withdraw consent, or ask us to limit its processing, subject to the PDPA. Some data must be kept to meet legal obligations or to keep issued certificates verifiable.
Contact: [email protected]. We aim to reply within 21 days.
7. Changes
We may update this notice. The date at the top shows the latest version.