ATOLLIER
Legal

Privacy Policy

Last updated · 5 August 2026

We ask for very little, and we treat what you share with care. This Privacy Policy explains what personal data Atollier collects, why we collect it, how we handle and protect it, and the rights and choices available to you under Singapore’s Personal Data Protection Act 2012 (the "PDPA") and, where they apply to you, other data protection laws such as the EU and UK GDPR.

1. Who we are

1.1 This website and the Atollier travel club are operated by Atollier Pte. Ltd. ("Atollier", "we", "us" or "our"), a company incorporated in Singapore with its registered office at 10 Anson Road, #28-01, International Plaza, Singapore 079903.

1.2 Atollier is the organisation responsible for the personal data described in this policy and determines the purposes for which it is processed.

2. Personal data we collect

2.1 "Personal data" means data, whether true or not, about an individual who can be identified from that data, or from that data and other information to which we have or are likely to have access. We collect the following, in each case only what you choose to provide:

  • When you introduce yourself: your name, email address, and the details you decide to share about the journey you have in mind — such as destinations, approximate dates, who is travelling, interests, and any notes you send us.
  • When you subscribe to Atollier: your first name and email address, so we can send you our occasional letters.
  • When you request an expedition dossier: your first name and email address, and the expedition you are interested in.
  • When you contact us directly: the contents of your message and your contact details, whether you reach us by email, Calendly or WhatsApp.
  • Technical data: limited, largely anonymous information recorded by our hosting and analytics providers, such as pages visited, approximate region, browser type and access times, used to keep the site secure and understand what resonates. We do not use this data to identify you.

2.2 We do not knowingly collect special categories of data such as health information, and we ask that you do not send us more personal data than we need.

3. Passport and identification data

3.1 Where arranging your journey requires it — for example to book flights, accommodation or in-country travel, or to meet a destination’s entry requirements — we may ask for passport details or similar travel-identification information for you and those travelling with you. We collect this only for that purpose.

3.2 We share such information only with the travel providers who need it to fulfil your booking, and we retain it only for as long as needed for your trip and for any related legal or accounting obligation, after which we securely delete it.

3.3 We do not use NRIC or FIN numbers, or copies of NRIC cards, to identify or authenticate you, and we ask that you do not send them to us.

4. Personal data about other people

4.1 If you give us personal data about anyone other than yourself — for example a partner, family member or friend travelling with you, or an emergency contact — you confirm that you have their permission to share it with us for the purposes set out in this policy, and that you have made them aware of this policy.

5. How we use your personal data

5.1 We use your personal data to:

  • respond to your enquiry and plan, discuss and arrange the journey you have in mind;
  • send you newsletters or marketing material, where you have asked to receive it;
  • provide an expedition dossier you have requested and follow up about it;
  • keep our own records and manage our relationship with you;
  • operate, secure, maintain and improve this website and our services, including preventing and investigating fraud or misuse; and
  • comply with applicable law and respond to lawful requests from authorities.

6. Photography and filming at events and on expeditions

6.1 From time to time we may take photographs or short films at Atollier events, gatherings or on expeditions, in which you may appear. We may use these to share the experience and to represent Atollier — for example on our website, in Soundings, or on our social channels.

6.2 If you would prefer not to be photographed or filmed, or would like an image of you removed after the event, please let our team know at the event or write to us (clause 17), and we will do our best to accommodate you. Where required, we will seek your consent before using an image in which you are clearly identifiable.

7. Our legal bases

7.1 Under the PDPA we rely on your consent for sending you marketing communications such as newsletters and expedition dossiers. For responding to your enquiries, arranging your journey, keeping records and running and securing our service, we rely on your consent and, where applicable, the legitimate interests basis permitted under the PDPA. Where the GDPR applies to you, the corresponding bases are your consent and our legitimate interests.

7.2 We will never sell your personal data, and we do not use it for automated decision-making or profiling that produces legal or similarly significant effects.

8. Marketing communications and your choices

8.1 We send marketing communications only to people who have asked to receive them. You can withdraw your consent or unsubscribe at any time, using the link in any Soundings letter or by writing to us (clause 17). We will action your request promptly; please allow a reasonable period, and in any event no more than 30 days, for it to take full effect across our systems, during which you may still receive messages already in progress.

8.2 Where we send marketing messages to a Singapore telephone number, including by WhatsApp, we do so in accordance with the Do Not Call provisions of the PDPA and will respect any registration on the Do Not Call Registry.

9. Who we share your personal data with

9.1 We keep your circle small. We use a small number of trusted service providers to run the essentials, and we share only what each needs to do its job:

  • Supabase — secure database hosting for our enquiries and contacts;
  • Resend — sending the emails you receive from us;
  • Vercel — website hosting and privacy-respecting analytics;
  • Slack — internal notifications so we see your message promptly;
  • Calendly — if you choose to book a conversation with us;
  • WhatsApp — if you choose to message us there directly.

9.2 We may also disclose personal data to our professional advisers (such as lawyers, accountants and auditors), and to regulators, authorities or law enforcement where we are required or permitted to do so by law, or to establish, exercise or defend legal rights. Our service providers are required to use your personal data only to provide their services to us and to keep it confidential.

10. International transfers

10.1 Some of our service providers are located outside Singapore, so your personal data may be processed abroad. Where we transfer personal data overseas, we take reasonable steps to ensure it receives a standard of protection comparable to that under the PDPA — for example through the provider’s contractual commitments and their own data protection safeguards — in line with our Transfer Limitation obligation under the PDPA.

11. How long we keep your personal data

11.1 We keep your personal data for as long as needed to help with your journey and our relationship with you, and thereafter only for as long as we have a genuine legal or business reason to do so — for example, to honour a marketing preference or to meet a legal or accounting obligation. When personal data is no longer required for any such purpose, we will cease to retain it or remove the means by which it can be associated with you.

12. Your rights

12.1 Subject to the PDPA and any other law that applies to you, you may ask us to:

  • access the personal data we hold about you and information about how it has been used or disclosed;
  • correct any personal data that is inaccurate or incomplete;
  • withdraw your consent, including unsubscribing from marketing at any time; and
  • where a corresponding right applies to you under the GDPR, delete your personal data or restrict its processing, where there is no overriding reason for us to keep it.

12.2 To make a request, please contact us using the details in clause 17. We will respond as soon as reasonably possible, and in any event within 30 days; if we need longer, we will tell you why. A reasonable fee may apply to an access request, as permitted by the PDPA, and we will tell you in advance if so. If withdrawing your consent means we can no longer provide part of our service, we will let you know.

13. Data breach notification

13.1 We maintain measures to detect and respond to data breaches. If a data breach occurs that is likely to result in significant harm to affected individuals, or that affects 500 or more individuals, we will notify the Personal Data Protection Commission ("PDPC") within three calendar days of determining that the breach is notifiable, and we will notify affected individuals where the PDPA requires us to do so.

14. Cookies and analytics

14.1 We use only the cookies and similar technologies needed for the site to function and to understand aggregate usage. We do not use advertising cookies, and we do not track you across other websites. You can set your browser to refuse some or all cookies, though parts of the site may then not work as intended.

15. Security

15.1 We take reasonable technical and organisational measures to protect your personal data against unauthorised access, use, disclosure, alteration or loss, and we limit access to those who need it. No method of transmission or storage is entirely secure, but we work only with reputable providers and review our practices from time to time.

16. Children

16.1 This website and our services are intended for adults. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with personal data, please contact us and we will delete it.

17. Data Protection Officer and how to contact us

17.1 We have designated a Data Protection Officer who is responsible for overseeing our compliance with this policy and the PDPA. For any question about this policy or your personal data, or to make any request under clause 12, please write to:

Data Protection Officer, Atollier Pte. Ltd.

Email: adam@atollier.club

17.2 If you are not satisfied with how we have handled your personal data or your request, you may raise the matter with the Personal Data Protection Commission of Singapore (www.pdpc.gov.sg).

18. Business transfers

18.1 If Atollier is involved in a merger, acquisition, reorganisation or sale of assets, your personal data may be transferred as part of that transaction. We will require the recipient to protect your personal data consistently with this policy, and we will notify you of any material change to who controls your personal data or how it is used.

19. Changes to this policy

19.1 We may update this policy from time to time. When we do, we will revise the date above and, where changes are significant, take reasonable steps to bring them to your attention. Please check back occasionally so you stay informed.

20. Governing law

20.1 This policy is governed by and construed in accordance with the laws of Singapore.