1, who we are
WIDTH Pte. Ltd. ("WIDTH", "we", "us") operates width.com and provides AI-native compliance software to regulated financial institutions. We are the data controller of personal information we collect through this website. Our registered office is 1 Raffles Place, #50-00, One Raffles Place Office Tower 1, Singapore 048616.
2, information we collect
- Contact data — name, business email, company, and role, when you request a demo or subscribe to updates.
- Usage data — pages viewed, referring URL, approximate location (country/region), browser and device information.
- Cookies and similar technologies — described in Section 6.
3, how we use it
- To respond to your enquiries and arrange demonstrations.
- To send service updates and product information you have opted into.
- To operate, secure, and improve our website.
- To comply with applicable law, including anti-money-laundering and sanctions obligations.
4, legal basis
WIDTH processes personal data under GDPR Article 6 lawful bases: (a) consent (Art. 6(1)(a)) for marketing communications; (b) legitimate interests (Art. 6(1)(f)) for website operation and security; and (c) legal obligation (Art. 6(1)(c)) for anti-money-laundering and sanctions screening. For Singapore residents, processing aligns with PDPA Purpose Limitation and Notification Obligations.
5, who we share it with
WIDTH shares personal data only with processors operating under written Data Processing Agreements that meet GDPR Article 28 requirements: cloud infrastructure, analytics, CRM, and email delivery providers. WIDTH does not sell personal data to third parties. Disclosure to law-enforcement or regulatory authorities occurs only where legally required, with notice to the data subject where permitted by law.
6, cookies
This site uses cookies and similar technologies — pixels, tags and local storage — to operate, to understand aggregate usage, and (with your consent) to measure and improve our marketing.
Your choices. Non-essential cookies (analytics and marketing) are off by default and load only after you accept them; you can accept all, reject all, or choose by category, and change your choice at any time via the Cookie Settings link in the footer. Declining non-essential cookies does not affect your access to the site.
We group cookies into three categories:
- Strictly necessary (always on) — required for the site to function and to remember your cookie choices; these do not track you and cannot be switched off.
- Analytics / performance (consent required) — help us understand how the site is used, aggregated and where possible anonymised.
- Marketing / advertising (consent required) — measure campaigns and show relevant WIDTH content on other platforms.
| Cookie | Provider | Purpose | Category | Retention |
|---|---|---|---|---|
| width_consent | WIDTH | Stores your cookie-consent choices and the policy version | Necessary | 12 months |
| _ga, _ga_<id> | Google Analytics 4 | Distinguishes visitors and sessions for aggregated usage analytics | Analytics | Up to 24 months |
| _clck, _clsk | Microsoft Clarity | Session and usage analytics (heatmaps, aggregated behaviour) | Analytics | Session – 12 months |
| _gcl_au | Google Ads | Measures advertising conversions | Marketing | 90 days |
| bcookie, lidc, li_sugr | Campaign measurement and audience insights | Marketing | Session – 12 months |
You can withdraw consent at any time via Cookie Settings, control cookies in your browser, and opt out of certain advertising via the "Do Not Sell or Share My Personal Information" link. The live list in the Cookie Settings panel is authoritative; the table above summarises the main cookies in use.
7, international transfers
Personal data transferred outside the EEA or Singapore is protected by Standard Contractual Clauses (SCCs, European Commission 2021/914), Binding Corporate Rules (BCR) where applicable, or adequacy decisions under GDPR Articles 44–50. WIDTH maintains transfer impact assessments for all third-country transfers. Singapore-originating transfers comply with PDPA's Third Schedule conditions.
8, retention
Website contact and enquiry data is retained for 24 months from last interaction, then securely deleted or anonymised. KYC/AML records processed on behalf of institutional clients are retained for 5–7 years per applicable jurisdiction (e.g., 5 years under MAS Notice 626; 6 years under the UK Money Laundering Regulations 2017; 7 years under FinCEN BSA requirements), after which records are cryptographically purged from all storage tiers.
9, your rights
The rights you can exercise depend on where you are and which data-protection law applies to you. Whichever applies, contact us at privacy@width.com to exercise any right below.
Rights we honour across our principal markets (Singapore, Hong Kong, the UAE):
- Access — you may ask whether we hold personal data about you and request a copy, together with information about how we have used or disclosed it.
- Correction — you may ask us to correct inaccurate or incomplete personal data about you.
- Withdraw consent — where we rely on your consent (for example, marketing emails), you may withdraw it at any time; withdrawal does not affect processing already carried out beforehand. In Singapore and the UAE this is a standalone statutory right; in Hong Kong you may at any time require us to stop using your data for direct marketing.
- Stop direct marketing — you may require us, free of charge, to stop using your personal data for direct marketing and to stop providing it to others for their direct marketing; you can also use the unsubscribe link in any message.
- Erasure / restriction (where the law provides) — for example, under the UAE Personal Data Protection Law you may request erasure or restriction of processing in the circumstances that law allows.
We respond within the period the applicable law requires — for example, within 40 days in Hong Kong, and without undue delay in Singapore and the UAE.
How to complain. If you are unhappy with how we have handled your personal data, please contact us first at privacy@width.com. You also have the right to complain to the data-protection authority where you are:
- Singapore — the Personal Data Protection Commission (PDPC). You may also have a right of private action in court if you have suffered loss or damage.
- Hong Kong — the Office of the Privacy Commissioner for Personal Data (PCPD).
- United Arab Emirates — the UAE Data Office. If we process your data within the DIFC or ADGM financial free zones, the relevant regulator is the DIFC Commissioner of Data Protection or the ADGM Commissioner of Data Protection.
Other regions. If you are in the EEA or the UK, you also have rights of erasure, restriction, portability and objection under the GDPR / UK GDPR, and may complain to your local supervisory authority (in the UK, the Information Commissioner's Office). If you are a California resident, you hold rights under the CCPA/CPRA, including the right to opt out of the sale or sharing of your personal information via the "Do Not Sell or Share My Personal Information" link.
10, contact
For privacy questions, complaints, or data-subject requests: privacy@width.com.