PDPA 2012
How LegalRush Pte. Ltd. collects, uses, and protects your personal data.
Effective date: 21 July 2026 · Last updated: 21 July 2026
LegalRush Pte. Ltd. (“LegalRush,” “we,” “us,” or “our”) is a Singapore law practice registered under UEN 202439182K, operating from 16 Circular Road, #03-02, Singapore 049368, and the website legalrush.pro (the “Site”). We are committed to protecting personal data in accordance with the Personal Data Protection Act 2012 of Singapore (“PDPA”) and applicable subsidiary legislation.
This Privacy Policy explains what personal data we collect, why we collect it, how we use and disclose it, how long we retain it, and what rights you have. By using the Site, submitting a rush intake form, visiting our chamber, engaging us for legal services, or otherwise interacting with us, you acknowledge that you have read this Privacy Policy. Where consent is required under the PDPA, we obtain it before collecting or using personal data for the stated purpose.
LegalRush Pte. Ltd. is the organisation responsible for personal data described in this policy. For data protection enquiries, contact us at [email protected] with subject line “PDPA enquiry” or write to LegalRush Pte. Ltd., 16 Circular Road, #03-02, Singapore 049368. General chamber enquiries may be directed to the same email or +65 6284 3916.
We collect personal data only where necessary for defined purposes. Categories include:
We do not intentionally collect sensitive personal data through the Site contact form beyond what you voluntarily attach. Please avoid submitting NRIC numbers, medical records, or unrelated third-party personal data via the public form. Secure document transfer instructions are provided after scope confirmation for active matters.
Personal data is collected through:
We collect and use personal data for purposes including:
We may disclose personal data to:
We do not sell personal data. We do not use client matter data to train public AI models. Transfers outside Singapore occur only where necessary for hosting or specialist support, with contractual safeguards or consent as required.
Under the PDPA, we rely on:
You may withdraw consent by emailing [email protected]. Withdrawal does not affect lawfulness of prior processing. We may continue processing where another legal basis applies, including ongoing matters requiring retention under professional rules.
We retain personal data only as long as necessary:
| Data type | Retention period |
|---|---|
| Rush intake enquiries not converted to matters | 24 months from last correspondence |
| Client matter files | Minimum 7 years after matter closure unless longer required by law or agreement |
| Financial and trust records | 7 years (statutory requirement) |
| Server logs | 90 days |
| Cookie consent records | 6 months (browser local storage) |
| CCTV footage | 30 days rolling unless incident investigation requires longer |
When data is no longer needed, we delete or anonymise it securely subject to legal hold requirements.
Subject to PDPA exceptions, you have the right to:
To exercise these rights, email [email protected] with sufficient detail to identify you and your request. We respond within thirty days unless an extension is permitted. A reasonable fee may apply for manifestly unfounded or excessive access requests as allowed under the PDPA.
Access requests relating to active client matters may require identity verification and could be limited where disclosure would affect another person’s rights or legal professional privilege. Correction requests should specify inaccurate fields and proposed corrections. We notify relevant third parties of corrections where required.
If you believe we have not handled personal data properly, you may contact the Personal Data Protection Commission (PDPC) of Singapore after giving us an opportunity to resolve your concern.
In the event of a data breach likely to result in significant harm or affect a significant number of individuals, we will notify the PDPC and affected individuals as required under the PDPA. Our breach response includes containment, assessment, documentation, and remediation. Staff are trained to escalate suspected breaches immediately. If you suspect unauthorised access to personal data held by LegalRush, contact [email protected] without delay.
We implement administrative, technical, and physical safeguards including HTTPS on the Site, encrypted storage for matter documents, role-based access controls, staff confidentiality training, and secure disposal of physical records. Client portals and email channels use authentication appropriate to sensitivity. No transmission over the internet is completely secure; we advise against sending highly confidential attachments via the public rush intake form before secure channels are established.
The Site may link to external sites such as ACRA, maps, or professional bodies. We are not responsible for their privacy practices. Review their policies before submitting personal data.
The Site is not directed at children under thirteen. We do not knowingly collect personal data from children through the Site. Contact us to delete such data if discovered.
We may update this Privacy Policy to reflect legal, operational, or Site changes. Material updates will be posted here with a revised “Last updated” date. Significant changes affecting consent-based processing may require renewed consent.
LegalRush Pte. Ltd.
16 Circular Road, #03-02, Singapore 049368
Email: [email protected]
Phone: +65 6284 3916
UEN: 202439182K