Skip to content

Legal

Hoshiro Labs Privacy Policy

For Hoshiro Labs and Hoshiro ARC — AI Reach & Capability

Effective date: 21 August 2026

1. Who we are

Hoshiro Labs is operated by LY TECHNOLOGY PTE. LTD. (UEN 201901898K), with registered office at 3 Phillip Street, #14-05, Royal Group Building, Singapore 048693. For the purposes of applicable privacy law, LY TECHNOLOGY PTE. LTD. is the organisation responsible for the personal data described in this Policy unless another notice states otherwise. Privacy enquiries and requests may be sent toprivacy@hoshirolabs.com. General support enquiries may be sent to support@hoshirolabs.com.

2. Scope

This Privacy Policy explains how we collect, use, disclose, protect and retain personal data when you visit Hoshiro Labs, use Hoshiro ARC, create an account, purchase a report, subscribe to a monitoring plan, request remediation or advisory services, contact us, or otherwise interact with our services.

3. Personal data we may collect

  • Account and contact data: Name, business email, organisation, account identifiers, verification status, support/contact information.
  • Authentication and security data: Session identifiers, login timestamps, security events, IP address, device/browser information, anti-abuse identifiers and related technical logs.
  • Scan and report data: Domains and URLs submitted for scanning, pages sampled, public technical evidence, scores, findings, report history, methodology versions and remediation selections.
  • Transaction data: Product or plan purchased, order/reference numbers, amount, currency, payment status, refund status and billing-related information. Full payment-card details are generally handled by the payment provider rather than Hoshiro.
  • Subscription and advisory data: Plan, tracked domains, competitor names/domains, prompt or market-monitoring configurations, reports, alerts, meeting details and advisory notes where applicable.
  • Communications: Support requests, legal/privacy requests, feedback, survey responses and other messages you send us.
  • Usage and analytics data: Page views, feature usage, referral/source information, approximate location derived from IP, cookie or analytics identifiers, and interaction data where analytics is enabled.
  • Customer-provided implementation data: Information reasonably necessary to deliver remediation, such as platform/CMS type, access method, technical contacts, staging details and non-secret configuration information.

Please do not submit passwords, private keys, payment-card details or other secrets in free-text forms, reports or ordinary support messages unless we specifically provide a secure method for that purpose.

4. Sources of personal data

  • Directly from you when you register, buy, subscribe, configure monitoring, contact support or request services.
  • Automatically from your browser, device and use of the website, including security and anti-abuse controls.
  • From payment, calendar, email, hosting, analytics and other service providers used to operate the service.
  • From publicly accessible websites and technical resources when ARC analyses a submitted domain.
  • From your employer, colleague or authorised representative where they create or manage a business account on your behalf.

5. How we use personal data

  • Create and administer accounts and authenticate users.
  • Provide ARC scans, reports, historical comparisons, monitoring, alerts, remediation proposals and advisory services.
  • Process purchases, subscriptions, refunds, invoices and related accounting records.
  • Enforce free-scan limits, detect abuse, prevent fraud, protect accounts and secure the service.
  • Communicate service messages, report availability, security notices, product updates and support responses.
  • Improve ARC methodology, product performance and customer experience using aggregated, de-identified or appropriately controlled data where possible.
  • Measure website and funnel performance where analytics is enabled.
  • Comply with legal, regulatory, tax, accounting and dispute-resolution obligations.
  • Protect our rights, customers, systems and third parties.

6. Legal bases where applicable

Depending on the law that applies to a particular individual, we process personal data on one or more of the following grounds: performance of a contract or steps requested before entering a contract; legitimate business interests such as service security, product improvement and B2B operations; consent where required; and compliance with legal obligations. Where Singapore's Personal Data Protection Act applies, we collect, use and disclose personal data in accordance with applicable consent, notification and other statutory exceptions or requirements.

7. Website scanning and public data

ARC primarily evaluates publicly accessible website material and technical conditions associated with a domain submitted for assessment. Public website content may incidentally contain personal data, such as staff names or business contact details. We process such information only as reasonably necessary to provide the requested assessment, evidence and related services. Customers are required to submit sites they are authorised to assess. ARC is not intended to collect private-account content, bypass access controls or conduct covert surveillance.

8. Automated analysis

ARC uses automated rules, software and, where appropriate, AI-assisted processing to analyse website conditions, produce scores, identify findings, prioritise recommendations and support monitoring. ARC does not guarantee the behaviour of third-party AI systems and is not designed to make legally or similarly significant decisions about individual people. Where applicable law gives you rights relating to automated decision-making or profiling, you may contact us using the details below.

9. Cookies, device identifiers and analytics

We use strictly necessary cookies or similar technologies for authentication, security, session management and fair-use/scan-limit controls. We may use Cloudflare Turnstile and related security technology to distinguish legitimate users from abusive traffic. Analytics technologies such as Google Analytics may be used where enabled and, where required, subject to consent controls. More information appears in the Hoshiro Labs Cookie Notice.

10. Service providers and disclosures

We may disclose personal data to service providers that process data for us where reasonably necessary to operate Hoshiro Labs. These may include:

  • Cloud hosting, content delivery, security and anti-bot providers, including Cloudflare where used.
  • Payment providers, including Stripe where used.
  • Email delivery and customer-communications providers.
  • Analytics providers, including Google Analytics where enabled.
  • Scheduling providers, including Calendly where enabled.
  • Database, logging, monitoring, document-generation and file-storage providers.
  • AI and automation infrastructure providers used to perform or support ARC services, subject to appropriate contractual and security controls.
  • Professional advisers, auditors, insurers and authorities where required for legitimate business or legal purposes.

We do not sell personal data as a standalone business. If our practices ever constitute a "sale" or "sharing" under a privacy law that uses those defined terms, we will provide the notices and choices required by that law.

11. International transfers

Hoshiro operates from Singapore and may use providers or infrastructure in other countries. Where personal data is transferred outside Singapore or another relevant jurisdiction, we take steps required by applicable law to ensure an appropriate or comparable level of protection, including contractual safeguards where necessary.

12. Retention

We retain personal data only for as long as reasonably required for the purpose for which it was collected, for legitimate business needs, or to meet legal obligations.

  • Accounts: For the life of the account and a reasonable period after closure for security, support, dispute and legal purposes, unless earlier deletion is appropriate.
  • ARC scans and reports: Historical scan/report records are retained as part of the customer account unless deleted in accordance with applicable rights or account policy. A report becoming Outdated after 30 days is a technical freshness status and does not cause deletion.
  • Security and anti-abuse logs: Normally up to 12 months, or longer where reasonably needed to investigate abuse, fraud, security incidents or legal claims.
  • Payments, invoices and commercial records: For the period required by applicable tax, accounting and company law. Singapore business records may need to be retained for at least five years.
  • Marketing preferences: Until you opt out or the information is no longer needed, while retaining sufficient suppression information to honour an opt-out where appropriate.
  • Support and legal correspondence: For as long as reasonably needed to resolve the matter and preserve relevant business or legal records.

13. Data security

We use reasonable administrative, technical and organisational safeguards designed to protect personal data against unauthorised access, disclosure, alteration, loss or misuse. No internet service can guarantee absolute security. If a personal-data breach occurs, we will assess and notify affected individuals and regulators where required by applicable law.

14. Your privacy rights

Your rights depend on where you live and which privacy law applies. Subject to applicable exceptions, you may have rights to request access to or correction of personal data, withdraw consent, request deletion, restrict or object to processing, request portability, or opt out of certain uses. For Singapore PDPA access, correction or consent-related requests, contactprivacy@hoshirolabs.com. We may need to verify your identity before acting on a request.

If the EU or UK GDPR applies to your data, you may also have rights of erasure, restriction, portability, objection, withdrawal of consent and complaint to a competent data-protection authority. If California privacy law applies to Hoshiro and to you, you may have rights to know, access, correct or delete personal information and to opt out of certain sale/sharing or automated-decision uses where applicable, without unlawful discrimination for exercising those rights.

15. Marketing communications

You may opt out of non-essential marketing email using the unsubscribe mechanism provided or by contacting us. We may still send transactional or service messages necessary for your account, purchase, subscription, report, security or support relationship. Telephone or text marketing, if ever used, will be handled in accordance with applicable Singapore Do Not Call and other marketing requirements.

16. Children

Hoshiro ARC is a business service and is not directed to children. We do not knowingly seek to create accounts for children under 18.

17. Changes to this Policy

We may update this Privacy Policy to reflect changes in law, providers, technology or our services. The effective date at the top shows when this version took effect. Material changes will be communicated where required.

18. Contact and complaints

Privacy enquiries, requests or complaints: privacy@hoshirolabs.com. General support: support@hoshirolabs.com. Legal notices:legal@hoshirolabs.com. Registered office: 3 Phillip Street, #14-05, Royal Group Building, Singapore 048693.