Index · Privacy · PDPA notice · August 2026

Privacy notice

Feed Vault Drift Pte. Ltd. · Effective 13 August 2026

This notice explains how Feed Vault Drift Pte. Ltd. ("Feed Vault Drift", "we", "us") collects, uses, discloses, and protects personal data when you visit the Chalk Ledger website, correspond by email, or use the reading room at 358 Tanjong Katong Road. We comply with the Personal Data Protection Act 2012 (PDPA) of Singapore as amended, and apply the data minimisation habits we use at the physical desk to our digital operations.

1. Data controller

Feed Vault Drift Pte. Ltd. is the organisation responsible for personal data described here. Contact: [email protected] or 358 Tanjong Katong Road, #03-01, Singapore 437122. General desk enquiries may copy [email protected] for coordination.

2. Personal data we collect

Walk-in intake. When you use the reading room, we record your name, contact method, a description of your research thread, and desk officer initials. We do not collect national identification numbers unless required for institutional loan agreements covered by separate terms.

Email and telephone. If you email [email protected] or call the Drift Desk, we process your address, message content, and metadata necessary to reply in writing. Call logs are not recorded; officers may take brief handwritten notes for follow-up.

Website technical data. Our hosting provider processes server logs (IP address, browser type, requested URL, timestamp) for security and uptime. Essential cookies operate the consent banner; optional functional cookies load embedded maps; analytics cookies are off by default. See the cookie notice for details.

Community bulletins on shelves. Material filed on shelves may contain third-party personal data (names in neighbourhood letters, etc.). We redact direct identifiers where feasible before shelving and document redactions on request. Handling of third-party data in archived documents is governed by custodial purpose — we do not use bulletin names for marketing.

3. Purposes of use

We use personal data to: respond to research requests and issue written handovers; maintain intake and handover logs for accountability; operate and secure the website; comply with law; and improve desk procedures internally. We do not sell personal data, do not buy contact lists, and do not profile visitors for advertising.

Marketing communications are not sent without explicit opt-in. Service messages about your active handover (timing quotes, correction notices) are part of the archive service, not marketing.

4. Legal bases and consent

Under the PDPA, we rely on consent, contractual necessity, legitimate interests, and legal obligation as applicable. Website cookies use granular consent via the bottom banner (Reject all, Customise, Accept all). Essential cookies do not require consent because they are strictly necessary to remember your cookie choice and maintain basic session integrity.

Walk-in intake consent is obtained verbally and recorded on the intake slip — you may refuse non-essential uses such as anonymised procedure statistics; core intake logging is required to provide the service described in the Reading Room letter.

5. Disclosure to third parties

We disclose personal data only to: hosting and email providers under contract; professional advisers bound by confidentiality; and authorities when required by Singapore law. Maps are served by Google when you enable functional cookies; Google's processing is governed by their policies. We do not disclose intake logs to other visitors or to news outlets without your written direction or legal compulsion.

6. Cross-border transfer

Primary hosting is in Singapore. Some infrastructure providers may process data in other jurisdictions with comparable protection standards or contractual safeguards. We assess transfers against PDPA requirements before engaging vendors.

7. Retention

Intake logs and handover metadata are retained for seven years unless a longer period is required for ongoing disputes or legal holds. Email correspondence is retained while your request is active and for two years thereafter for correction audits. Server logs rotate on a ninety-day cycle unless security investigation requires longer retention. Cookie consent records follow the durations in the cookie notice.

8. Security

We apply access controls, encrypted transport (HTTPS), desk policies limiting folio access to assigned officers, and physical room controls at Tanjong Katong. No method is perfectly secure; we notify affected individuals and the PDPC where required if a breach likely causes significant harm.

9. Your rights

Subject to PDPA exceptions, you may request access, correction, withdrawal of consent, or information about how we used your data. Email [email protected] with sufficient detail to locate your record (name, approximate visit date, ref code if held). We respond within thirty days in most cases.

Withdrawal of consent for optional cookies can be exercised anytime via the cookie panel or the Manage cookies control on the cookie notice page. Withdrawal for essential intake logging may mean we cannot complete a handover.

10. Children

The reading room welcomes student researchers with adult supervision where appropriate. We do not knowingly collect marketing profiles of minors. Schools planning group visits should email the desk in advance so intake can be batched with guardian contact details.

11. Third-party links

Our pages link to official outlets cited on shelves. Those sites have their own privacy practices. Embedded maps load only with functional consent and are subject to Google's terms.

12. Automated decision-making

We do not use automated decision-making or profiling that produces legal or similarly significant effects. Register rows are maintained by desk officers, not algorithms ranking visitors.

13. Do Not Call / marketing registers

We do not operate telemarketing lists. Desk phone contact is inbound or follow-up to your written request, not cold outreach.

14. Updates to this notice

We publish material changes here with an updated effective date. Continued use after notice constitutes acceptance where permitted by law; active handovers follow the notice version in effect at intake unless law requires retrospective rights.

15. Complaints

Contact us first at [email protected]. If unresolved, you may lodge a complaint with the Personal Data Protection Commission (PDPC) of Singapore.

16. Specific processing activities

Handover stacks. Your name appears on folder labels only for collection at the desk; labels are destroyed or anonymised after collection plus retention period unless you request institutional citation copies that require attribution.

Correction challenges. If you challenge a register entry, we process your email and evidence copies solely to verify the folio and reply in writing.

Institutional agreements. Separate memos may specify data roles when universities or newsrooms engage recurring pulls; those memos prevail over this summary for the covered activities.

Photography in the room. Occasional room photography for archival documentation may include background visitors; we avoid identifiable faces where possible and do not use such images for advertising.

17. Access request procedure

To submit a PDPA access request, email [email protected] with your full name, preferred reply address, approximate intake or visit date, and any ref code from a handover label. We verify identity before releasing intake logs. Responses describe categories of data held, purposes, and retention — copies of logs may be redacted where third-party personal data appears in your thread description.

Correction requests should include the inaccurate field and supporting evidence. We do not alter archived outlet text; we correct our custodial metadata and desk notes when those are wrong.

18. International transfers

Primary hosting and desk systems are located in Singapore. If you email us from outside the city-state, your message transits networks we do not control. We do not routinely transfer intake logs overseas; institutional agreements that require cross-border processing will name the destination and safeguards in writing before data moves.

19. Data sharing with processors

We engage processors for secure hosting, transactional email delivery, and office equipment maintenance logs. Each processor is bound by contract to process data only on our instructions and to maintain confidentiality. We maintain a register of processors available on request to [email protected] for institutional due diligence.

We do not permit processors to use desk intake data for their own marketing or model training. Sub-processor changes are reviewed when contracts renew.

20. Data protection contact summary

Email: [email protected] · Postal: Feed Vault Drift Pte. Ltd., 358 Tanjong Katong Road, #03-01, Singapore 437122 · Telephone (orientation only): +65 6957 2814 · Hours: Mon–Fri 07:30–18:30 SGT.

Our data protection approach mirrors the reading room method: minimal collection, written replies, and no silent edits. If you believe we hold data beyond what this notice describes, ask — we prefer the question on record over assumptions.