Legal
Privacy Policy
Last updated 7 September 2026
Aurum Wealth Analytics Pte. Ltd. (“Aurum”, “we”, “us”) is a company registered in Singapore. This policy explains what personal data this website — aurumwa.io — collects, why we collect it, who else ever sees it, and how to have it corrected or removed.
It is written to Singapore’s Personal Data Protection Act 2012 (the PDPA). It covers these public pages — the ones you can reach from the menu at the top — and the reports published on them.
It does not cover the client surfaces this domain also serves, each of which collects more than these pages do and is governed by the notice given to you when you are let into it: the adviser dashboard, the financial health check, the referral partner portal, and a shared deck link. If you have arrived at one of those from a link somebody sent you, the notice that applies is the one shown to you there, not this one.
What we collect
Three things, and only three.
- What you type into a form. There are three. The consultation request takes your name, your email address, your company if you give it, the interest you select and your message. The Brief takes your email address, and which page you subscribed from. The application for membership takes your name, your email address and your mobile number, which we need to give you a membership and reach you about it; the membership you are asking for and, where it covers more than one person, how many; and, only if you choose to give them, your date of birth, gender, occupation and country, the subjects you would like watched and how you prefer to be contacted. Those last ones you may leave blank without it counting against your application. It also takes an invitation code if you were given one. Nothing on this site asks for a financial detail, an identification number, or a password.
- What your browser sends when it asks for a page. Our hosting provider records ordinary server logs — the address requested, the time, your IP address and your browser’s user agent string — which is how any web server works and how we see that something is broken or under attack.
- One cookie, and only if you sign in as a member. Signing in sets a single cookie holding a random session reference — not your email, not your name, nothing readable. It is marked
HttpOnly, so no script on the page can read it, and it is discarded 24 hours after you last use the site, or immediately when you sign out. It exists only to keep you signed in; it is not used for analytics, preferences or tracking, and it is not read on any page you visit signed out. If you never sign in, this site sets no cookies at all and writes nothing to your browser’s local or session storage. There is no consent banner because there is nothing to consent to beyond the sign-in you chose to make.
We use no analytics, no advertising pixels, no tag managers, no session recorders and no third-party trackers of any kind. Loading any page of this site causes your browser to contact exactly one host — aurumwa.io. Typefaces are served from our own domain rather than a font network, and the published reports under /r/ are self-contained bundles that make no external request at all, so reading one tells nobody but our own server that you did.
Why we collect it, and your consent
We use what you send us to do the thing you asked for: to answer your enquiry, to send you the Brief, or to consider and administer your membership and let you sign in to it. Where you chose to give a date of birth, gender, occupation or country, we use those to understand the readership we write for, and for nothing else — they are not needed to grant a membership and are never used to decide one. We use server logs to keep the site available and secure. That is the whole list of purposes.
By submitting a form you consent to us using your details for that purpose. You can withdraw that consent at any time by writing to contact@aurumwa.io, and every Brief carries a one-click unsubscribe. Withdrawal takes effect as soon as we can act on it, and we will tell you if it means we can no longer do something you had asked for.
Who else sees it
We do not sell personal data, we do not share it with advertisers or data brokers, and we do not pass it to a product provider so that somebody can call you.
Two service providers necessarily handle it on our behalf, under contract and only on our instructions: the platform that hosts this site, and the provider that carries our email. Beyond those, personal data leaves this house only where the law requires it — for example a court order or a regulatory demand — and we will tell you if that happens unless we are prohibited from doing so.
Where it is processed
Those providers operate infrastructure outside Singapore, so your data may be processed overseas. Where that happens we take reasonable steps to ensure a standard of protection comparable to the PDPA, as section 26 requires — by contract with the provider, and by keeping the amount of personal data involved to the minimum the purpose needs.
How long we keep it
Enquiries are kept while we are dealing with them and for as long afterwards as we need a record of what was discussed — typically no more than three years for a conversation that did not become an engagement. Brief subscriptions are kept until you unsubscribe. Server logs are kept for a short operational period by our host.
When personal data is no longer needed for the purpose it was collected for, and no legal or business purpose requires keeping it, we dispose of it.
Seeing it, correcting it, deleting it
Under the PDPA you may ask what personal data we hold about you and how we have used it, ask us to correct anything inaccurate, and ask us to delete it. Write to contact@aurumwa.io and we will respond within 30 days, or tell you within that time when we can respond if it will take longer.
Members do not have to write to us to correct most of it. Signing in and opening your account shows the name, mobile number, date of birth, gender, occupation and country we hold, and every one of them can be changed or emptied there. The address you sign in with can be changed too; because it is also how we confirm it is you, we send a code to the new address first and change nothing until it comes back.
We may need to confirm who you are before answering, and we may charge a reasonable fee for an access request that takes substantial work — if so we will tell you the fee before doing anything.
How it is protected
The site is served over HTTPS and asks browsers to refuse plain HTTP for two years afterwards. Form submissions are transmitted to a single mailbox over an authenticated, encrypted connection, and are never written to a database on this website. Every page is served with a policy forbidding it from being framed by another site, along with content-type, referrer and permissions restrictions.
No system is perfect, and we do not claim otherwise. What we can say is that the amount of personal data this website holds is deliberately, structurally small.
Changes to this policy
If we change how this site handles personal data, we change this page in the same breath and move the date at the top. Material changes are also noted in the Brief.
The terms of use govern the rest of your use of this site.
Questions about anything on this page can go to contact@aurumwa.io, and a person will answer them.