Okidex

Privacy Policy

Last Updated: 30 June 2026

At Okidex, we are committed to connecting founders with private investors and talent in a secure, transparent, and respectful manner. This Privacy Policy ("Policy") describes how Okidex, Inc. ("Okidex," "we," "us," or "our") collects, uses, shares, and protects your personal information when you use our mobile application, website (okidex.com), and related services (collectively, the "Services"). We respect your privacy and are dedicated to protecting your data in accordance with applicable laws, including Singapore’s Personal Data Protection Act 2012 (PDPA), as amended by the Personal Data Protection (Amendment) Act 2020, the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other relevant privacy regulations. In Singapore, we comply with the guidelines issued by the Personal Data Protection Commission (PDPC).

By using our Services, you consent to the practices described in this Policy. If you do not agree, please do not access or use the Services. We may update this Policy from time to time, and we will notify you of material changes via email, in-app notification, or by posting the updated Policy on our website with the new effective date. Your continued use of the Services after such changes constitutes your acceptance of the revised Policy.

1. Information We Collect

We collect information to provide, improve, and personalize our Services, facilitate matchmaking between founders, investors, and talent, and ensure a safe environment. Under the PDPA, personal data is defined as data about an individual who can be identified from that data or in combination with other information we have or are likely to have access to. We act as the data controller for your personal data under applicable laws like the PDPA and GDPR.

Information You Provide to Us

  • Registration and Profile Data: When you create an account, we collect your name, email address, phone number, professional title, location, and other details you provide, such as your role (e.g., founder, investor, or talent). For verification purposes, we may collect government-issued ID, selfies, or other identity documents through third-party providers to confirm your identity and prevent fraud. You are responsible for the accuracy and appropriateness of the data you choose to share or publish on your profile, including any personal or sensitive information you make publicly visible. Under the PDPA, we ensure you are notified of the purposes for collecting this data and obtain your consent where required.
  • Professional and Business Information: Founders may upload business plans, pitch decks, financial projections, resumes, or other business-related documents. Investors and talent may provide investment criteria, professional experience, skills, endorsements, or financial preferences. You can choose to include sensitive information, but we advise against posting unnecessary personal details publicly. You are responsible for any data, including business plans or financial details, that you choose to share or publish on your profile or with other users. We obtain explicit consent for processing sensitive personal data, such as financial details, as required by the PDPA.
  • Financial Information: If you link payment methods for premium features or transactions (e.g., subscription fees), we collect payment details such as credit/debit card numbers, bank account information, billing address, and transaction history. For matchmaking involving investments, we may collect or infer financial data with your explicit consent, such as investment history or funding requirements, in compliance with the PDPA’s Consent Obligation.
  • Communications and Content: Messages, connection requests, feedback, and any content you post or share through the Services, including in matches, chats, or forums. You are responsible for the content you share or publish in these interactions.
  • Linked Accounts: If you connect third-party accounts (e.g., LinkedIn, Google, or financial apps), we collect data like profile information, contacts, or professional networks, subject to your authorization and PDPA’s Notification Obligation.

Information We Collect Automatically

  • Usage Data: Device information (e.g., IP address, browser type, operating system), log data (e.g., pages viewed, time spent), and interaction data (e.g., matches made, searches performed).
  • Location Data: Approximate or precise location (via GPS, IP, or device settings) to facilitate local matchmaking, with options to control this in your device settings. Under the PDPA, we notify you of location data collection purposes and obtain consent where required.
  • Cookies and Similar Technologies: We use cookies, pixels, web beacons, and other tracking technologies to recognize you across devices, analyze usage, and personalize content. For details, see our Cookie Policy below, which complies with the PDPA’s transparency requirements.

Information from Others

  • Data from matches or connections (e.g., endorsements, referrals, or shared business plans).
  • Aggregated or anonymized data from partners for analytics, ensuring compliance with the PDPA’s Protection Obligation.

We do not collect information from children under 18, and our Services are not intended for them (see Section 8). The PDPA does not apply to business contact information (e.g., name, business title, business email) or data of deceased individuals (for over 10 years), and we align our practices accordingly.

2. How We Use Your Information

We use your information to operate and enhance our Services, based on legal grounds such as your consent, contractual necessity, legitimate interests (e.g., fraud prevention), or legal obligations, as permitted under the PDPA, GDPR, and other laws.

  • Providing and Personalizing Services: To create profiles, suggest matches (e.g., connecting founders with compatible investors or talent based on profiles, location, and algorithms), facilitate communications, and enable features like virtual meetings or document sharing, in line with the PDPA’s Purpose Limitation Obligation.
  • Matchmaking and Networking: Analyze professional data, business plans, and financial preferences to predict compatibility and recommend opportunities, with your explicit consent for sharing sensitive details like financial information or business plans during matches, as required by the PDPA’s Consent Obligation.
  • Safety and Security: Verify identities, monitor for violations of our terms, detect fraud (e.g., using transaction patterns or automated systems), and prevent unauthorized access, fulfilling the PDPA’s Protection Obligation.
  • Payments and Financial Services: Process transactions, manage subscriptions, and, with explicit consent, facilitate investment-related disclosures (e.g., sharing funding needs with investors).
  • Communications: Send service updates, security alerts, and promotional messages (e.g., about new features or events), with opt-out options for marketing in compliance with the PDPA’s Do Not Call (DNC) Registry provisions.
  • Analytics and Improvement: Conduct research, develop insights (e.g., workforce trends in startups), and improve algorithms, using aggregated data where possible, as permitted under the PDPA’s Accountability Obligation.
  • Advertising and Marketing: Target ads based on your interests and usage, without sharing personal data with advertisers except in hashed form or with consent, ensuring compliance with the PDPA’s Notification Obligation.
  • Compliance and Legal Purposes: Fulfill legal requirements, such as anti-money laundering (AML) checks, tax reporting, or responding to authorities, as required by the PDPA and other laws.

For sensitive data like financial information or business plans, we require your explicit consent before processing or sharing, which you can withdraw at any time via account settings, as supported by the PDPA’s consent withdrawal provisions.

3. Sharing Your Information

We share your information only as necessary and with safeguards in place, such as contracts requiring data protection, in compliance with the PDPA’s Transfer Limitation Obligation.

  • With Other Users: In matches, we share profile details, business plans, or financial information you consent to disclose (e.g., a founder sharing a pitch deck with an investor). You control visibility through privacy settings. You are responsible for the data you choose to share with other users, including in profiles, messages, or matchmaking interactions. We ensure compliance with the PDPA’s Consent and Notification Obligations before sharing.
  • Service Providers: With third-party vendors (data intermediaries under the PDPA) for functions like payment processing (e.g., Stripe), identity verification, cloud storage, analytics, or customer support. These providers are bound by strict confidentiality and data protection agreements, meeting the PDPA’s requirements for data intermediaries.
  • Affiliates and Partners: Within our corporate group or with financial partners for fraud prevention or service enhancement, ensuring equivalent privacy protections as required by the PDPA.
  • For Legal Reasons: To comply with laws, prevent harm, enforce terms, or in response to subpoenas, with discretion to disclose if we believe it’s necessary, as permitted under the PDPA.
  • Business Transfers: In mergers, acquisitions, or asset sales, your data may be transferred, with notice provided, in line with PDPA guidelines.
  • Aggregated Data: Non-identifiable insights shared for research or marketing, ensuring no personal data is disclosed.

We do not sell your personal data. We will never share, sell, rent, lease, or distribute your business' legal, financial, or personal information directly or indirectly through third parties, without your explicit prior consent. Under ordinary trading circumstances, Okidex will not share the original incorporation articles or verification documents provided by founders with investors, even upon request, as doing so would infringe on our privacy agreement with founders. It is solely up to the founders to transmit these articles or documents to investors on their own accord. For financial information, sharing requires your explicit consent, and we use mechanisms like standard contractual clauses for international transfers to ensure a comparable level of protection as required by the PDPA’s Transfer Limitation Obligation.

Data Room Sharing & NDA Consent

For startup profiles utilizing Data Room privacy controls (Oki+ Premium), the collection, usage, and sharing of sensitive financial and capitalization table information are subject to the following privacy rules:

  • Data Sharing Controls & Expiration: Founders have complete control over who views their financials and cap table, and can approve investor requests for live updates or time-boxed periods of 30, 60, or 90 days. Access can be withdrawn (revoked) instantly at the founder's discretion.
  • 24-Hour Cooling-Off Period: If access is revoked, investors are locked out immediately. To prevent spamming, a 24-hour cooling-off period is enforced before an investor can re-request access to that startup's Data Room.
  • NDA Acceptance Signature Log: When an investor accepts a Standard NDA, Custom NDA, or acknowledges an external arrangement to unlock access, we record the investor's identity, the text of the NDA accepted, and the timestamp. This serves as an audit trail for the founder.
  • Access and View Audit Trail: We track investor interactions with your Data Room, recording the last time they viewed your financials or capitalization table (`lastAccessedAt`) to provide founders with complete transparency on who is auditing their records.

OkiDojo and Pitch Deck Parser Privacy

For startup founders participating in OkiDojo (Oki+ Premium), the uploading and parsing of pitch decks and financial spreadsheets are protected by strict privacy policies:

  • In-Memory Processing: Any pitch deck (PDF) or financial spreadsheet (.xlsx/.xls) uploaded to OkiDojo is parsed and analyzed strictly in-memory within the client's browser session. The original files and extracted raw contents are never sent to, stored on, or cached on Okidex's servers, databases, or Firebase storage buckets.
  • Read and Disposal Policy: The parser reads the information available on your PDF or spreadsheet and immediately disposes of the file after extraction. If you make any updates or changes to your business details, you will need to re-upload your deck/file to regenerate the comparative analysis.
  • Temporary AI Context: The extracted text is processed solely during the active session to generate competitive landscape metrics, news matches, and 60-second elevator pitches. Once the session is closed or refreshed, the temporary data is purged.
  • Mock Social and Publication Feeds: The live-listener feeds (e.g. from TechCrunch, VentureBeat, social platforms) correspond to generic public trends in the startup's sub-sector and geography. They are compiled based on aggregate topics and do not index, search, or associate any of the user's private data or uploaded deck content.

4. Cookie Policy

We use cookies and similar technologies (e.g., web beacons, pixels, and device identifiers) to enhance your experience, analyze usage, and deliver personalized content. This Cookie Policy, aligned with PDPA guidelines, explains how we use these technologies and your choices.

Types of Cookies We Use

  • Essential Cookies: Necessary for the Services to function, such as maintaining your login session, securing your account, and enabling core features like matchmaking. These cannot be disabled, as they are critical to service delivery.
  • Performance Cookies: Collect anonymized data on how you use our Services (e.g., pages visited, time spent) to improve performance and user experience. Examples include Google Analytics cookies.
  • Functionality Cookies: Enable enhanced features, like remembering your preferences (e.g., language or location settings) or customizing your interface.
  • Advertising Cookies: Used to deliver relevant ads and track ad performance. We may share hashed, non-identifiable data with ad partners to personalize ads across devices, with your consent.
  • Social Media Cookies: Allow integration with platforms like LinkedIn for account linking or sharing, subject to your consent and the third party’s privacy policy.

How We Use Cookies

  • Authentication: Recognize you when you log in and ensure secure access.
  • Personalization: Tailor match suggestions and content based on your interactions and profile.
  • Analytics: Measure traffic, identify popular features, and optimize Services.
  • Advertising: Show targeted ads on and off our Services, ensuring relevance without sharing personal data directly with advertisers.

Managing Cookies

Under the PDPA, we notify you of cookie usage purposes and obtain consent for non-essential cookies. You can control cookies through:

  • Cookie Consent Banner: On your first visit, choose which non-essential cookies to allow. Update preferences anytime via the "Manage Cookies" link at okidex.com/cookies.
  • Browser Settings: Block or delete cookies, though this may affect functionality (e.g., logging you out). Instructions are available for browsers like Chrome, Firefox, or Safari.
  • Device Settings: Adjust tracking settings (e.g., “Limit Ad Tracking” on iOS or “Opt Out of Ads Personalization” on Android).
  • Third-Party Opt-Outs: Visit sites like youronlinechoices.eu (EU) or optout.networkadvertising.org (US) for ad network opt-outs.

Third-Party Cookies

Some cookies are set by partners (e.g., analytics or ad providers). These are governed by their privacy policies, and we ensure they meet PDPA standards. For example, Google Analytics uses anonymized data, and we do not share identifiable information with ad partners without consent.

We retain cookie data for up to 13 months, unless required for legal purposes or deleted earlier at your request, in line with the PDPA’s Retention Limitation Obligation. For more details, contact us at wilfred@okidex.com.

5. Data Security and Retention

We implement reasonable security measures to protect your data, fulfilling the PDPA’s Protection Obligation. All Okidex servers are private, isolated, and secure, utilizing state-of-the-art administrative, physical, and technical safeguards. This includes SSL/TLS encryption for all data in transit and AES-256 encryption at rest. Access controls restrict server and database access to authorized personnel only. However, no system is completely secure, so we cannot guarantee absolute security.

Manual and AI-Assisted Verification Auditing Consent: During the verification process for startup profiles (including business email verification, financial log checks, or legal incorporation document audits), submitting documents or files implies that the founder explicitly consents to and allows the OkiAgent AI system and authorized Okidex compliance staff to parse, scan, and manually review all submitted files. This processing is performed with the sole intent of cross-checking the documents against the founder's stated details on their profile. Auditing files are stored in secure, private storage buckets with strict IAM policies. Under ordinary trading circumstances, Okidex will not share the original incorporation articles or verification documents provided by founders with investors, even upon request, as doing so would infringe on our privacy agreement with founders. It is solely up to the founders to transmit these articles or documents to investors on their own accord.

Recourse for Data and File Deletion: Any user (especially founders) who has previously submitted business registry papers, financial logs, cap table details, or personal data retains the right to formally request the complete, permanent deletion of these files and articles from Okidex's secure servers and databases at any time. To request deletion, contact our Data Protection Officer at wilfred@okidex.com. We will purge the files from our systems and provide confirmation of deletion.

We retain data as needed for the purposes described, in compliance with the PDPA’s Retention Limitation Obligation:

  • Profile data: Until account deletion, plus up to 28 days for restoration.
  • Financial and transaction data: For audit, tax, or legal purposes (e.g., 7 years).
  • Verification data: Up to 3 years for fraud prevention (unless deleted earlier upon user request, as detailed above).
  • Cookie data: Up to 13 months, as noted above.

Upon account deletion, we anonymize or delete data, though shared content may remain visible to others. You can request deletion via settings, as supported by the PDPA’s Access and Correction Obligation.

In the event of a data breach likely to result in significant harm or affecting a significant number of individuals, we will notify the PDPC and affected individuals within 3 calendar days of assessment, as required by the PDPA’s Data Breach Notification Obligation.

6. Your Rights and Choices

We empower you to control your data, in line with the PDPA, GDPR, and CCPA:

  • Access and Correction: View, edit, or export your information via account settings. Under the PDPA, you can request access to your personal data and information about its use or disclosure within the past year, and request corrections to errors or omissions.
  • Deletion: Request data deletion, subject to legal retention requirements, as supported by the PDPA.
  • Opt-Outs: Withdraw consent for marketing, location sharing, cookies, or data processing (e.g., for matching algorithms) at any time, with notification of consequences as required by the PDPA.
  • Do Not Sell/Share: Under CCPA, opt out of data sales (though we do not sell data).
  • GDPR and PDPA Rights: If in the EU/EEA/UK or Singapore, exercise rights to access, rectify, erase, restrict, or object to processing, or data portability. For Singapore residents, contact the PDPC for complaints about data misuse.
  • Cookie Controls: Manage via the Cookie Consent Banner, browser settings, or our Cookie Policy page.
  • Financial Consent: Specifically revoke consent for sharing financial info or business plans.
  • DNC Registry: Opt out of telemarketing by registering your Singapore telephone number with the PDPA’s Do Not Call Registry.

To exercise rights, contact our Data Protection Officer (DPO), as required by the PDPA’s Accountability Obligation, at wilfred@okidex.com. We respond within applicable timeframes (e.g., 30 days under CCPA and PDPA). For complaints, Singapore residents can contact the PDPC at 10 Pasir Panjang Road, #03-01, Mapletree Business City, Singapore 117438.

7. International Data Transfers

We operate globally and may transfer data to countries outside your residence, including the US. For transfers outside Singapore, we ensure the recipient provides a comparable level of protection as required by the PDPA’s Transfer Limitation Obligation, using mechanisms like standard contractual clauses or binding corporate rules, which also align with GDPR requirements.

8. Children's Privacy

Our Services are for users 18 and older. We do not knowingly collect data from children under 18. If we learn of such collection, we will delete it promptly, in line with the PDPA. Parents can contact us for assistance.

9. Changes to This Policy

We may update this Policy to reflect changes in our practices or laws. We will notify you of significant changes via email, in-app notification, or by posting the updated Policy, as required by the PDPA’s Accountability Obligation.

10. Contact Us

For questions or concerns, contact our Data Protection Officer, as mandated by the PDPA, at:

  • Email: wilfred@okidex.com
  • Registered Address: 37 Pasir Panjang Close, Singapore 118980

For Singapore residents, you may also contact the Personal Data Protection Commission at:

  • Address: 10 Pasir Panjang Road, #03-01, Mapletree Business City, Singapore 117438
  • Website: www.pdpc.gov.sg

Thank you for trusting Okidex with your information. We are committed to your privacy as we build meaningful connections in the startup ecosystem, in full compliance with the PDPA and other applicable laws.