Privacy Policy

Effective 24 September 2026

This policy explains how Toda Labs Pte. Ltd., Singapore ("we"), handles personal data across todalabs.io, MeshLite demos, the customer console and related services. Customer agreements may provide additional terms for business use.

1. Information we process

2. How we use information

We use this information to provide and administer services, respond to enquiries, maintain security, troubleshoot issues and understand service performance. We handle personal data under Singapore’s Personal Data Protection Act 2012 (PDPA), relying on consent or other grounds permitted by applicable law. Before using data for a new purpose, we provide notice and obtain consent where required by law.

When processing personal data on a business customer’s behalf, we follow its lawful instructions and our agreement, while retaining our own applicable legal obligations. Customers are responsible for appropriate notices to their users and any permissions required for their use of the service.

3. Cookies and microphone access

We use cookies and browser storage for language, authentication, service controls and first-party analytics. On todalabs.io, the analytics cookie lasts up to 90 days and is renewed when you visit. Global Privacy Control prevents this website identifier; other operational data may still be processed. Our website does not load Google Analytics or advertising cookies. You can manage storage and microphone permission in your browser.

4. Service providers and sharing

We use hosting and storage providers, including Netlify and Microsoft Azure, as well as AI, speech, voice and email services. They receive the data needed for their services. Google Fonts receives your IP address when delivering fonts. Providers may process data outside Singapore. We remain responsible for meeting applicable PDPA requirements for comparable protection when transferring data overseas.

We may disclose information as required by law or, where legally permitted, to protect legal rights or prevent abuse. We do not sell personal data or share it for advertising.

5. Retention and security

We retain personal data for as long as reasonably needed to provide services, manage our business relationship, maintain security or meet legal obligations. Retention varies by data type, purpose and applicable agreement, including for backups and provider records. Data that is no longer needed is deleted or anonymised. We use reasonable safeguards and restrict access to people who need it for their work.

6. Your choices and contact

You can browse without starting the Demo and can deny or revoke microphone access. For privacy questions, access or correction requests, withdrawal of consent, or deletion requests, contact hello@todalabs.io.

We handle requests under applicable law, may verify your identity, and will explain any relevant service limitations or retention requirements. For services operated by a business customer, please contact that customer first about its processing of your data.

7. Children and policy updates

Our website and public demos are not directed at children. We update the effective date when this policy changes and provide additional notice where required.