Compliance and privacy

Southeast Asia compliance, platform connectivity and privacy protection

Deep-Insights AI runs live warehouse, transport and freight operations across Singapore, Malaysia, Indonesia, Thailand, Vietnam and the Philippines. This page sets out how the platform meets regional data protection law, which industry platforms it connects to, and what safeguards apply when AI agents act on operational data.

Regional data protection coverage

Obligations we design for in each Southeast Asian market where customers operate.

Singapore

PDPA (Personal Data Protection Act)

Consent, purpose limitation, access and correction rights, breach notification to PDPC within 3 calendar days of assessing a notifiable breach. Deployments can be hosted in Singapore with data residency pinned in-region.

Malaysia

PDPA 2010 (as amended 2024)

Data-user obligations for disclosure, security and retention, mandatory breach notification and data protection officer appointment for covered processing.

Indonesia

PDP Law No. 27/2022

Lawful basis and consent records, controller/processor responsibilities, 3x24-hour breach notification, and cross-border transfer safeguards.

Thailand

PDPA B.E. 2562

Consent management, data subject rights handling, records of processing activity and transfer adequacy assessments.

Vietnam

Decree 13/2023/ND-CP

Data processing impact assessment filings, local storage considerations, and documented cross-border transfer dossiers.

Philippines

Data Privacy Act of 2012

Registration where thresholds apply, security measures, breach notification to the NPC, and data sharing agreements.

Platform connectivity

SHAPE, customs, terminal and e-invoicing integrations

SHAPE (Singapore Harmonised Air Cargo Platform Exchange)

Air cargo booking, capacity and status message exchange with participating carriers and ground handlers, so bookings and milestones flow into the platform without re-keying.

Singapore Customs / TradeNet-linked declarations

Permit data preparation and validation against shipment records before submission through your declaring agent or broker interface.

PSA and terminal systems

Container gate, yard and vessel event data ingested for container operations, demurrage and detention calculation.

Carrier and NVOCC portals

Rate, booking and tracking exchange with major ocean and air carriers plus intra-Asia regional operators, via API, EDI or agent-driven portal handling.

ASEAN e-invoicing and tax platforms

Settlement documents formatted to local e-invoicing requirements including Singapore InvoiceNow (Peppol) and Malaysia MyInvois.

Enterprise systems

SAP, Oracle, Microsoft Dynamics and regional ERP/WMS integration, with reconciliation back to the system of record.

Privacy and security safeguards

Encryption and key management

TLS 1.2+ in transit and AES-256 at rest. Secrets and credentials are stored in a managed vault, never in application code or logs.

Regional data residency

Production data can be pinned to Singapore or another regional data centre. Cross-border transfer is contractual and documented, not incidental.

Auditability by default

Every automated action an AI agent performs is logged with the input it read, the rule it applied, the approval it received and the record it changed.

Access control

Role-based access, least-privilege service accounts, SSO/SAML for enterprise identity providers, and periodic access reviews.

Customer operational data is never used to train shared or third-party models. Model providers are contracted on zero-retention terms, and prompts containing personal data can be masked before they leave your tenant. Read the privacy policy and cookie notice for how we handle data on this website.

Compliance FAQ

Where is our data stored if we operate in Southeast Asia?

Production data can be hosted in Singapore or another regional data centre of your choice, with data residency stated in the contract. Cross-border transfers, where required, are covered by documented transfer mechanisms.

Is Deep-Insights AI compliant with Singapore's PDPA?

The platform is built to support PDPA obligations: consent and purpose records, access and correction handling, retention limits, breach detection and notification workflows, and a data protection officer contact for customers. Compliance is a shared responsibility — we provide the controls, you define the processing purposes.

Can we connect to SHAPE and other Singapore logistics platforms?

Yes. Deep-Insights AI supports message exchange with SHAPE for air cargo, terminal and PSA container event feeds, customs permit preparation and Peppol-based e-invoicing, alongside direct carrier API and EDI connections.

How do AI agents handle personal data?

Agents process only the fields needed for the workflow, operate inside your tenant, and never use your operational data to train shared models. Personal data in documents can be masked in agent prompts and logs.

What certifications do you hold or align with?

The platform is operated to ISO 27001-aligned controls with SOC 2-style logging, change management and vendor review practices. Customer-specific audit and due-diligence packs are available on request.

Who is accountable if an AI agent makes a mistake?

Agents operate within configured approval thresholds. Actions above a threshold require human sign-off, and every action is reversible and traceable, so accountability stays with the documented approval chain.

Need our due-diligence pack?

We provide security architecture documentation, data flow diagrams, sub-processor lists and regional hosting details for procurement and legal review.

Contact us