Legal
Information Security & AI Ethics Policy
Last updated: August 2026
Enfactum handles client data, campaign data and business information as part of our work, and this policy sets out how we protect that information under Singapore's Personal Data Protection Act 2012 and Cybersecurity Act 2018, and how we use artificial intelligence responsibly, in line with the principles set out in IMDA's Model AI Governance Framework.
Client and campaign data is accessible only to team members who need it for active engagements, and access is reviewed and revoked promptly when engagements end or team members change roles. We use industry standard tools for storage, transfer and backup of client data, with encryption applied in transit and at rest wherever the platform supports it. Third party tools and platforms used in client work, including analytics, CRM, ad platforms and cloud infrastructure, are chosen with data protection and platform reputation as selection criteria. In the event of a data breach affecting client information, we assess the incident promptly, notify affected clients without undue delay, and where the breach is notifiable under the PDPA, report it to the Personal Data Protection Commission within the required timeframe. Team members handling client data are briefed on data handling expectations as part of onboarding and ongoing account management.
Enfactum's AI Ecosystems capability means artificial intelligence is part of how we plan, build and execute for clients, and we hold ourselves to a set of principles around that use. AI tools support our strategists and creative teams, but they do not replace human judgment on client recommendations, brand decisions or final deliverables, and a qualified team member reviews AI assisted output before it reaches a client. Where AI plays a material role in a deliverable, such as content generation, data modelling or creative concepting, we disclose this to the client as part of our process. We do not input confidential client data into public or unvetted AI tools, and where AI platforms are used on client data, we confirm the platform's data retention and training policies beforehand. Client data is never used to train third party AI models without the client's explicit written consent. We also review AI generated creative, copy and targeting recommendations for bias before they go live, particularly given the diverse markets our campaigns often reach.
For questions about this policy or to report a concern, contact info@enfactum.com.