Skip to content

Trust / Security and data handling

Operational trust, explained plainly.

These are the current, documented boundaries around application data, customer-site delivery, authenticated operations, and payment integrations.

01

Where your data is hosted

EasyBiz Cloud runs on Google Cloud, in Singapore. Your published customer website is delivered separately over a global content network, so public web traffic is served independently of the systems holding your business records.

02

Encrypted in transit

Every EasyBiz Cloud website and service endpoint is served over HTTPS. The keys that publish your customer site stay on our servers — never in the browser or the Console.

03

Access is enforced, not just hidden

Every request is checked against your authenticated account before it can touch your records. Access is enforced by the system itself, not by hiding a button in the interface.

04

Tenant isolation

Each business's records are stored under its own isolated account scope, and published website files under theirs. One tenant's request cannot reach another tenant's data.

05

Payments stay with the payment provider

When you connect Stripe, card payments are handled by Stripe with signed confirmations. We keep only the payment references your books need — full card details are never stored by EasyBiz.

06

Privacy and data handling

Our Privacy Policy explains the information we collect, why we process it, how cross-border transfers are handled, and the rights available over personal information.

Personal data / PDPA

Personal data, handled under the Singapore PDPA.

EasyBiz Cloud is built and operated in Singapore. When your business stores customer records in EasyBiz Cloud, your business remains the owner of that data — we process it to run the service you configured, in line with the Personal Data Protection Act.

Where data lives

Core application services run in Google Cloud's Singapore region. Your published customer website is delivered from a global content network with a Singapore point of presence. Our Privacy Policy sets out how cross-border transfers are handled.

Your customers' rights

We support access, correction, and deletion of personal data on verified request — for your business's own records, initiated by you as the data owner. We do not sell personal data held on behalf of tenants.

Access and accountability

Staff access inside your workspace is controlled by seats and permissions that you assign. On our side, production access is restricted to authorised operators, and privileged operations are authenticated and logged.

If something goes wrong

If we become aware of a data breach affecting your records, we will notify affected businesses without undue delay and support the assessments the PDPA requires. Data-protection enquiries reach us at the contact below.

Security contact / direct enquiry

Questions about security or data handling?

Send us the product surface and control you want to understand. You can also review the current Privacy Policy for information-handling terms.