SolveCube

Data Protection Policy

How SolveCube collects, uses, protects and deletes your personal data


Applies to

All users of the SolveCube platform (solvecube.com)

Entity

SolveCube Pte Ltd (UEN: 201101982W)  |  36 Robinson Rd, #20-01 City House, Singapore 068877

Contact

talktous@solvecube.com  |  dpo@solvecube.com


1.  Who we are

SolveCube Pte Ltd (formerly I-Cube Consortium Pte Ltd, UEN: 201101982W) is a Singapore-registered company operating the SolveCube AI Talent Intelligence Platform at solvecube.com and related mobile and API services. References to 'SolveCube', 'we', 'us' or 'our' in this policy refer to SolveCube Pte Ltd and, where relevant, SolveCube Talent Solutions LLP (our India-registered affiliate).

This policy governs all personal data processed through our platform. It applies to candidates, experts, clients, recruiters, and any other person whose data we hold. It is compliant with Singapore's Personal Data Protection Act 2012 (as amended 2021), the EU/UK General Data Protection Regulation, India's Digital Personal Data Protection Act 2023, the UAE Personal Data Protection Law, and the Saudi Personal Data Protection Law.


2.  What data we collect

From candidates and talent pool members

  • Identity and contact: name, email, phone number, location, nationality, photo.

  • Professional: work history, skills, qualifications, LinkedIn profile, CV/resume, assessments voluntarily completed.

  • Compliance data: where required by local hiring regulations (e.g. nationality for Emiratisation/Nitaqat), collected only with a clear legal basis.

  • Platform signals: how you interact with the platform — search activity, profile views, response rates, availability signals.

  • AI-generated data (new in v2.0): match scores, availability scores, skill inferences, and AI-generated summaries produced by our models. These are treated as personal data and subject to the same protections as data you submit directly.


From clients and their users

  • Account and billing: company name, registration number, contact details, billing address, payment information.

  • Usage data: feature usage, search queries, session data, hiring mandate details, shortlist decisions.

  • Communications: calls, emails, and messages between you and SolveCube recorded for service delivery and dispute resolution purposes.


Technical data — all users

  • Device and connection: IP address, device type, browser, operating system.

  • Cookies and tracking: session cookies, analytics cookies, functional cookies. See Section 5.


AI and agent processing data 

Our platform uses AI models, large language models (LLMs), and autonomous agents (including Aspira AI, Flash Search, Talent Torch, and Conversational AI). When these features process your data, we record:

  • Prompt inputs submitted to AI features (retained for up to 90 days for quality and security review).

  • Model input/output logs (retained for 3 years for audit and accountability).

  • Agent action logs — what our autonomous agents did and on whose instruction (retained for 3 years).

We do not use individual candidate personal data to train AI models without explicit written consent. Anonymised, aggregated platform signals may be used to improve matching algorithms — in a form that cannot be traced to any individual.


3.  Why we collect it — legal ground for processing

Processing activity

Legal ground

Providing platform services to clients and users

Contractual necessity

AI-powered talent matching and shortlisting

Legitimate interests (talent acquisition services); consent where local law requires it

Candidate profile storage and pool management

Legitimate interests; consent for direct marketing

Compliance with employment quotas (Emiratisation, Nitaqat, Singapore FCF)

Legal obligation

Platform analytics and improvement

Legitimate interests

Marketing communications

Consent — unsubscribe at any time via talktous@solvecube.com

Dispute resolution and legal proceedings

Legitimate interests; legal obligation

Retention for audit and regulatory purposes

Legal obligation and legitimate interests


4.  How we use your data

  • To deliver and improve our platform services and AI features.

  • To match candidates to roles and generate shortlists, rankings, and talent insights.

  • To process payments and manage billing.

  • To communicate with you about your account, our services, and (with consent) our products.

  • To comply with applicable law — including Singapore MOM, IRAS, CPF, and employment regulations in other jurisdictions where we operate.

  • To investigate fraud, security incidents, and disputes.

  • For research and analytics — always in anonymised or aggregated form; never in a way that identifies you.

We do not sell your personal data to any third party. We do not use your data for advertising on behalf of third parties.


5.  Cookies

We use cookies on the SolveCube platform. You can accept or decline non-essential cookies via your browser settings or our cookie banner. Declining non-essential cookies may affect some platform features.

Cookie type

Purpose

Essential / Authentication

Required for login and secure access. Cannot be disabled.

Functional

Remembers your preferences and settings.

Analytics

Helps us understand how the platform is used (Google Analytics and similar). Data is anonymised.

AI feature cookies

Session context for AI features like CAI — cleared at session end.

Third-party cookies (Google Analytics) may transfer data to servers outside Singapore. Google's privacy policy applies to that processing. We encourage you to review it at policies.google.com.


6.  AI features — what this means for you 

SolveCube's platform uses AI to help recruiters and clients find and evaluate talent. This includes automated scoring, ranking, shortlisting, and AI-generated profile summaries. Here is what you need to know:

  • AI outputs about you (match scores, availability scores, summaries) are based on your profile data and platform signals. They are advisory — a human reviews them before any hiring decision is made.

  • We will tell you when AI has been used to process your data or generate outputs about you, through platform notices and this policy.

  • You can ask us to explain how an AI output about you was generated. Email dpo@solvecube.com — we'll respond within 10 business days.

  • You can opt out of automated scoring. If you do, your profile will be flagged for manual review only.

  • No hiring or rejection decision will be made about you based solely on an AI output without a human reviewer.


7.  Who we share your data with

We share personal data only where necessary and under appropriate safeguards:

Recipient

What and why

Client organisations (recruiters, employers)

Candidate profiles shared when a client searches for or is matched to a candidate. Clients are data controllers for their use of your data.

Data enrichment providers 

Professional profile data — to verify or supplement your profile. Contractual restrictions on further use apply.

AI/LLM API providers

Query context for AI features. DPA in place. No training on your data. Inputs not retained beyond session.

Assessment platforms 

Name, email, role — where assessments are activated. Their privacy policy governs further processing.

Payment processors (Stripe, Razorpay)

Billing and payment data only. PCI-DSS compliant. DPA in place.

Cloud infrastructure (AWS/GCP)

Platform hosting. Data processing agreement in place. Data residency per customer requirements.

Law enforcement / regulatory authorities

Where required by law, court order, or to protect rights and safety.

SolveCube Talent Solutions LLP (India affiliate)

Where your engagement involves India-based delivery. Covered by intra-group data sharing agreement.


8.  International transfers

SolveCube operates across Singapore, India, and the GCC region. Your data may be transferred between these jurisdictions as part of our normal operations. We protect all international transfers through:

  • Intra-group data sharing agreements aligned to PDPA and GDPR standards.

  • Standard Contractual Clauses (SCCs) for transfers to countries without an adequacy decision.

  • Contractual commitments from third-party providers to maintain equivalent data protection standards.

Customers with specific data residency requirements (common in UAE and Saudi Arabia) should specify this at contract stage. Contact dpo@solvecube.com for information about the transfer mechanisms applicable to your data.


9.  What you can ask us to do

You have the following rights over your personal data. To exercise any of them, email dpo@solvecube.com from your registered email address. We respond within 30 calendar days (10 business days for AI-specific requests).

Right

What it means

Access

Request a copy of the personal data we hold about you.

Correction

Ask us to correct inaccurate or incomplete data.

Erasure

Ask us to delete your data. We'll comply unless we have a legal obligation to retain it.

Portability

Request your data in a machine-readable format.

Restriction

Ask us to stop processing your data in certain circumstances while a dispute is resolved.

Objection

Object to processing based on legitimate interests.

Withdraw consent

Withdraw consent at any time where consent is the legal ground. This doesn't affect processing that has already taken place.

Explanation of AI output (new)

Ask how an AI-generated score, ranking, or summary about you was produced. Response within 10 business days.

Opt out of AI scoring (new)

Ask that your profile not be subject to automated scoring — manual review only.

Human review of AI decision (new)

Request that a human re-examines an AI output that affected a decision about you.

Correct AI input data (new)

If the data feeding an AI output is wrong, we'll correct it and update affected outputs where feasible.

Data breach notification

Notify us at dpo@solvecube.com if you suspect your data has been compromised.

A reasonable fee may apply to access requests to cover administrative costs. We'll inform you before processing if so. Requests will not affect your ability to use the platform.


10.  How we protect your data

  • Encryption at rest (AES-256) and in transit (TLS 1.2 minimum).

  • Multi-factor authentication for all platform access.

  • Role-based access controls — only personnel who need your data for their role can access it.

  • API keys for third-party integrations stored in a secrets management system, rotated regularly.

  • Annual penetration testing by a qualified third party.

  • Clean desk policy and physical access controls for any physical records.

  • Regular staff training on data protection and information security.

  • Data Protection Impact Assessments (DPIAs) before any new high-risk processing activity.

No system is completely secure. If you suspect your account has been compromised, contact us immediately at talktous@solvecube.com.


11.  How long we keep your data

Data type

Retention period

Active candidate / expert profiles

Duration of relationship + 3 years

Inactive profiles (no activity)

2 years from last activity, then deleted

Client account and mandate records

7 years (contractual and legal obligations)

AI inference logs (model inputs/outputs)

3 years

LLM prompt logs

90 days

Agent action logs

3 years

Financial records (invoices, payments)

7 years (IRAS/MCA requirements)

Communications (calls, emails, chat)

Duration of relationship + 2 years

Data breach and incident records

7 years

When data reaches the end of its retention period it is securely deleted. You can request earlier deletion at any time — we'll comply unless a legal basis for retention applies.


12.  Cookies and consent withdrawal

To withdraw cookie consent: adjust your browser settings or use our cookie preference centre on the platform. To withdraw consent for marketing communications: click unsubscribe in any email, or contact talktous@solvecube.com. We process withdrawals within 30 calendar days.


13.  Data breach response

If we become aware of a breach affecting your personal data, we will notify you without undue delay — and within 72 hours where required by law (PDPC Singapore; relevant data protection authorities in other jurisdictions). Our Data Breach Management Plan:

Step

Action

A

Report breach to DPO by email: date/time, person reporting, brief description.

B

DPO meets with reporter to gather evidence: source, nature, and persons affected. Records in Data Breach Incident Form.

C

DPO assesses risk level, proposes corrective and preventive actions, presents to Senior Management. Updates DBMP activity log.

D

Upon approval: carry out corrective/preventive action. Notify PDPC, affected individuals, data controllers, and intermediaries as required.

E

Post-incident review: root cause analysis, policy and procedure improvements.

14.  Policy changes

We update this policy when our practices change or when laws require it. We'll notify you of material changes via email or platform notice at least 14 days before they take effect. The current version is always at solvecube.com/data-protection-policy. Your continued use of the platform after a change constitutes acceptance.

15.  Contact us

Contact

Details

Email

dpo@solvecube.com

Address

36 Robinson Rd, #20-01 City House, Singapore 068877

General enquiries

talktous@solvecube.com