PRIVACY POLICY
EFFECTIVE DATE: [2026-06-13]
ARETEUP PTE. LTD. (hereinafter referred to as "we", "us" or "our") formulates this Privacy Policy (hereafter referred to as the “Privacy Policy” or “Policy”) in accordance with the Personal Data Protection Act 2012 of Singapore (hereinafter referred to as the “PDPA”) , which was amended in 2021. This Policy applies to our mobile application (hereinafter referred to as the "App") and related services through which we provide online courses and educational services to adults (collectively referred to as the "Services"). This Policy sets out how we collect, use, disclose, store, protect and process your personal data, as well as your rights under the PDPA.
1. DEFINITIONS
Personal Data: Information that can directly or indirectly identify your identity, regardless of its authenticity. It includes all information voluntarily provided by you, automatically collected by us or collected via third-party SDKs.
Sensitive Personal Data: Including biometric information such as portraits and facial features. The PDPA imposes strict protection rules on such data. Platforms are prohibited from automated collection; the collection or use of such data must be based on the user’s separate explicit consent.
Data Protection Officer (DPO): The Person responsible for supervising the implementation of this Policy, responding to all requests from data subjects, and liaising with the Personal Data Protection Commission (PDPC) of Singapore.
Third-Party SDKs: Refers to software development kits integrated into our platform, including Alibaba Cloud Player SDK, Cloud Live Streaming Pusher SDK, and Firebase Analytical Suite. The Firebase Suite consists of analytical service, crash monitoring service and message push service. These SDKs are mainly used to support platform functions such as video playback, live streaming push, data analysis, fault troubleshooting and message push.
2. PERSONAL DATA WE COLLECT
2.1 INFORMATION YOU VOLUNTARILY PROVIDE AND CORRESPONDING USAGE SCENARIOS
All such information is filled in, submitted or authorized by you during your use of the platform’s educational services. It is essential to ensure the normal operation of the platform’s core educational services, transaction services and account services. The specific collection and usage scenarios of each type of information are as follows.
We may collect your full name mainly to complete real-name authentication for your platform account, register student files and file course enrollment information. It is also used for certificate production, admission notice labeling, invoice issuance and verification of order transaction information, so as to ensure the authenticity, validity and one-to-one correspondence of your personal educational records and transaction data.
We may collect your email address and corresponding verification codes for account registration and login authentication to secure your account access. Your email will serve as an official primary communication channel for delivering course commencement notifications, student status review results, certificate issuance reminders, transaction receipts, invoice documents and announcements regarding platform service changes.
We may collect your passport details, nationality and country of residence information, primarily for cross-border course enrollment, overseas student status registration, international education qualification review and filing for cross-border certificate delivery. This complies with the qualification verification and information registration requirements for international online education services and ensures the lawful provision of cross-border educational services.
We may collect your educational and professional background information to complete your student profile. Based on your learning and work experience, the platform will match you with suitable course resources, study plans and advanced training services. Such information also serves as the review basis for enrollment in premium courses and special research programs.
We may collect your frequently used college enrollment information to streamline the registration process for various courses, research programs and qualification training. It also helps file enrollment credentials, verify the validity of enrollment qualifications and standardize the entire course enrollment procedure.
We may collect your residential address and delivery address. The residential address is used to complete basic student profile information and file student status documents. The delivery address is exclusively for dispatching paper admission notices, completion certificates, degree certificates, official learning materials and physical teaching aids to ensure accurate delivery of all paper documents.
We may collect your portrait and facial feature data, which qualify as sensitive personal information. We will only collect and use such data upon obtaining your separate explicit consent. It is mainly applied to verify your identity authenticity, register and file online student status documents, and review course enrollment qualifications. It also supports document archiving and verification for official certificates and admission notices, preventing fake enrollment and identity fraud in learning activities, and safeguarding the authenticity and security of educational services.
We may collect your social media accounts including WhatsApp, Instagram and Facebook solely to provide quick login services and simplify account registration and login procedures. You may choose whether to authorize account binding. Once authorized, you can log in to the platform via the corresponding social media accounts, and such accounts will not be used for any unauthorized purposes.
We may collect your gender and date of birth to complete your student profile, cater to the course service demands of different age groups and user groups, and optimize personalized learning plans. The data is also used for compliant statistics on the platform’s user structure to support the improvement and upgrading of educational services.
Nicknames and avatars are non-mandatory information. You may voluntarily fill in and upload them in your personal account center. They are used to display your public account identity and facilitate interactions in course communities and study groups. You can modify or delete them at any time, and this will not affect your access to basic courses and core platform services.
Access to permissions for camera, photo album and microphone is only granted after you confirm pop-up authorizations, and no data will be collected automatically. Camera and photo album permissions allow you to upload ID photos, portrait materials, enrollment documents and assignments for student status registration, qualification review and homework submission. Microphone permission enables interactive live courses, online Q&A and voice assignment submission. You may disable these permissions anytime in your device system settings.
We may collect your bank card number, transaction bills and invoice information only when you purchase paid courses, research services, physical teaching aids and other products on the platform. Such data supports online self-ordering, manual order creation, payment and settlement, and retention of transaction records. It is also used to issue electronic or paper invoices in compliance with regulations and keep transaction vouchers, protecting your consumer rights and ensuring compliant platform transactions.
2.2 INFORMATION AUTOMATICALLY COLLECTED BY THE APP AND CORRESPONDING USAGE SCENARIOS
Such information is device or service data which is automatically collected by the system for the purpose specified in this section in compliance with the requirement under PDPA during your usage of the APP. All collected data will only be used to guarantee stable APP operation, optimize user experience and protect account and service security, and will not be applied to irrelevant scenarios.
We may automatically collect your device model, operating system version and device configuration information to adapt to diverse operating environments, optimize the performance of course video playback, live streaming and page loading, resolve device compatibility issues, and ensure all users can use the platform’s educational services smoothly.
We may automatically collect unique device identifiers and Android ID only for the purpose for identifying individual devices, completing device binding for accounts, detecting logins from abnormal devices and conducting risk control verification. This effectively prevents account theft, unauthorized logins and malicious batch course viewing, protecting your account security and maintaining normal platform service order.
We may automatically collect browser type, telecom service provider, system language and device time zone information to adapt service display modes to different network environments and usage habits. It optimizes page language display, network adaptation and time synchronization to enhance overall user experience, and supports accurate statistics on user behavior across different access channels.
We may automatically collect device sensor data to support basic interactive functions such as gesture control, screen rotation and adaptive playback, ensuring responsive operation and improving daily usability.
We may automatically collect IP address, accessed service URLs and network status information to monitor network connection quality, dynamically adjust video definition and live streaming bitrate, and avoid stuttering and loading failures. The data also helps troubleshoot network anomalies, identify malicious access and safeguard platform network security.
We may automatically collect product usage statistics, download and installation records, operation logs, access time and usage duration. These data are used to analyze the usage frequency and effect of platform courses and functions, study user learning habits and service demands, and provide data support for course iteration, function optimization and service upgrading.
We may automatically collect APP crash logs and fault diagnosis information to monitor operational malfunctions in real time, quickly locate crashes, functional errors and stuttering issues. This enables the technical team to fix bugs promptly and continuously improve APP stability and service quality.
We may automatically collect communication app data solely for platform risk control and security verification. It helps detect malicious diversion, illegal promotion and abnormal interactions to maintain a pure learning environment. We will not read, store or use your private communication content.
2.3 INFORMATION COLLECTED BY THIRD-PARTY SDKs
We integrate the following third-party software development kits (SDKs) to deliver required service functions. All information collected by these SDKs is strictly limited to what is necessary for their intended functions. Details are set out below:

2.3.1 Alibaba Cloud Player SDK Developer: Alibaba Group
Core function: Provide on-demand playback for course videos on the platform. Collected information: Network status, Wi-Fi status, MAC address, and information related to device read-write storage permissions.
Privacy Policy Link: http://terms.aliyun.com/legal-agreement/terms/suit_bu1_ali_cloud/suit_bu1_ali_cloud201902141711_54837.html?spm=a2c4g.11186623.2.14.1be61192lkxDR9
2.3.2 Cloud Live Streaming Pusher SDK Developer: Chuangsheng Shilian Digital Technology (Beijing) Co., Ltd. (创盛视联数码科技(北京)有限公司)
Core function: Conduct online video network scheduling and fully optimize users’ video playback experience. This SDK will collect Unique device identifier (Android ID).
Purposes of use: Perform network scheduling and optimization based on device information, and deliver usage prompts for different network types to ensure smooth and stable video playback. It also provides tailored network services for users based on network type and IP address.
Privacy Policy Link: https://admin.bokecc.com/privacy.bo
2.3.3 Firebase Service Provider: Google LLC
This SDK consists of analytical service, crash monitoring service and message push service, with the respective core functions as follows:
Analytical service - Collect statistics on app usage and user behavior data to support product experience optimization.
Crash monitoring service - Gather app crash information and exception logs to identify and resolve operational issues, and improve app stability.
Message push service - Deliver system notifications, service reminders and various service messages to users, so as to boost message delivery efficiency and overall service quality.
This SDK may collect various device identifiers (such as Android ID, IDFA, Firebase Installation ID, push token, etc.), app usage data, basic device information (such as device model, device name, operating system version, application version, etc.), network information (such as IP address, network type, etc.), crash log diagnostic data and exclusive identifiers for message push.
Privacy Policy Links: https://firebase.google.com/support/privacy https://policies.google.com/privacy


2.4 INFORMATION NOT CURRENTLY COLLECTED BUT MAY BE COLLECTED BY US IN THE FUTURE
We do not currently collect your real-time check-in data, dynamic location, continuous positioning records, activity trajectories and other relevant information. If we need to collect such information for service upgrades in the future, we will notify you separately in advance by updating this Policy, pop-up reminders or in-app messages, and obtain your explicit consent prior to formal collection. You have the right to refuse the relevant authorization, and such refusal will not affect your normal use of the existing basic services on the platform.
2.5 INFORMATION OF CHILDREN
The Services are not intended for children under the age of 13. We do not knowingly collect,process or retain any personal data or non-personally-identifiable information from anyone under the age of 13 nor is any part of our platform or other Services directed to children under the age of 13. As a parent or legal guardian, please do not allow such children under your care to submit personal data to us. In the event that personal data of a child under the age of 13 in your care is disclosed to us, you hereby consent to the processing of the child’s personal data and accept and agree to be bound by this Policy on behalf of such child. 
3. PURPOSES OF COLLECTION AND USE
We process Personal Data only for necessary, reasonable and foreseeable purposes for users, and strictly adhere to the principle of data minimization throughout the process.
1.To ensure the smooth delivery of educational services, including providing course services, student status registration, qualification document verification, delivery of admission notices and degree certificates, and unified management of student enrollment information.
2.To safeguard account and service security, including user identity verification, secure account login, anti-fraud risk control, abnormal activity detection and security protection.
3.To handle transactions and after-sales services, including course order processing, payment and settlement, transaction bill management, invoice issuance and response to user after-sales inquiries.
4.To implement core platform functions, such as on-demand video playback, live streaming, quick login via social media accounts, message push reminders and live interactive features. The live streaming interaction function is only available after you grant access to your camera and microphone.
5.To facilitate product iteration and optimization, including statistical calculation on app usage data, troubleshooting of application crashes, performance optimization and user behavior analysis. All analytical data will be anonymized or de-identified.
6.To fulfill compliance obligations, including complying with local laws and regulations of Singapore, responding to regulatory requirements of the Personal Data Protection Commission (PDPC), cooperating with judicial procedures, and protecting the legitimate rights and interests of the platform, users and the public in accordance with the law.
7.To provide optional marketing and promotion services such as customized course recommendations and platform event notifications. Such services will only be provided upon your explicit consent, and you may unsubscribe from relevant push notifications at any time.
We will not collect or use your personal data for any other purpose or general commercial purposes, and will fully abide by the purpose limitation principle.
4. CONSENT RULES
For general personal data, we obtain your explicit consent through your voluntary submission of information, ticking service agreements, authorizing quick login, confirming pop-up windows and other means. In compliance with the PDPA, your continued use of platform services shall be deemed as implied consent.
For sensitive personal data such as portraits and facial features, we apply strict rules for separate explicit consent. We will clearly inform you of the purposes of data use via dedicated pop-up windows, and no pre-checked authorization will be set. You may withdraw such consent and authorization at any time.
Data collection performed by third-party SDKs is based on your overall consent to this Privacy Policy. Data processing by third-party tools is subject to their respective privacy policies. We will not share your core identity information and transaction data with third-party SDKs.
You may withdraw granted consent at any time via multiple approaches, including in-app settings, contacting the Data Protection Officer (DPO), or disabling device permissions. Withdrawal of consent will not affect data processing activities lawfully performed prior to the withdrawal, nor will it impact your access to basic platform services that do not require authorization, such as browsing basic courses.
5. DATA DISCLOSURE AND SHARING
We will not sell, rent or trade any of your personal data. We only disclose user data under compliant scenarios and strictly abide by the purpose limitation principle stipulated in the PDPA at all times:
1.Compliant disclosure with your explicit consent. For instance, when you authorize login via social media accounts, relevant account information will be shared in compliance with rules.
2.Entrusting compliant third-party service providers with data processing. We only engage qualified third-party organizations providing cloud services, payment services, customer support and technical support to process user data. We will sign formal data processing agreements with partners, requiring them to fully comply with PDPA provisions, process data solely in accordance with our legitimate instructions, and prohibit any secondary disclosure of user information.
3.Responding to legal and regulatory requirements. We may disclose relevant data in accordance with applicable laws to comply with local laws and regulations of Singapore, respond to official investigations by the PDPC, judicial orders and litigation proceedings, or protect the legitimate rights and interests of the platform, users and the general public as well as prevent fraud risks.
4.Data processing in the event of corporate restructuring. In case of corporate merger, acquisition, asset transfer or other business changes, we will notify you in advance to ensure your data protection rights remain fully effective. Data processing after such changes will still be governed strictly by this Privacy Policy.
5.Data shared with third-party SDKs. We only provide SDK operators with a small amount of non-essential data necessary for functional operation, such as device identifiers and network information. Under no circumstances will we share your core personal data including name, passport details, bank card information or portraits.
6. CROSS-BORDER DATA TRANSFERS
As the servers of some third-party SDKs are located outside Singapore, your personal data may be transferred overseas during the operation of our services. We will conduct such activities in strict compliance with the PDPA rules governing cross-border data transfers.
We will conduct prior assessments on the data protection capabilities and compliance status of overseas data recipients to ensure their protection standards meet the relevant requirements of PDPA.
We will sign standard contractual clauses with all overseas partners to bind them to data protection obligations via legally binding agreements and safeguard the security of your personal data.
For cross-border transfers of sensitive personal data such as portraits, we will obtain your separate written explicit consent. No such transfer will be performed without your authorization.
You may contact our Data Protection Officer at any time to enquire about detailed information and compliance documents regarding the cross-border transfer of your personal data.

7. DATA STORAGE AND SECURITY
We strictly control the retention period of user data, and only keep data for the shortest duration necessary to fulfill the purposes of collection, including the term of course services, after-sales support period, and retention periods mandated by applicable laws and regulations. Upon the expiration of the service period, we will anonymize or securely destroy and delete your data, except where retention is explicitly required by law.
We have established a comprehensive data security protection system. We adopt industry-standard encryption technologies for data transmission and storage, enforce strict internal access control, conduct regular security audits as well as vulnerability detection and remediation, and formulate complete emergency response procedures for data breaches, so as to fully prevent risks of data leakage, loss, tampering and unauthorized access.
In the event of a data breach that may impair your legitimate rights and interests, we will proactively notify Singapore's Personal Data Protection Commission (PDPC) within three(3) calendar days. Meanwhile, we will duly inform the affected users in a timely manner in accordance with the law, and truthfully disclose the scope of the breach, potential impacts and official response measures.
8. YOUR RIGHTS UNDER THE PDPA
You may exercise the following data subject rights at any time. We will respond to and handle your requests in strict compliance with the statutory time limits stipulated under the PDPA. Please note that a reasonable fee may be charged for processing your requests. We will inform you in advance if any fee is applicable.
Right to Access. You may request to access a copy of your personal data retained by us and full details of all data processing activities.
Right of Rectification. You may request us to rectify inaccurate or incomplete personal data held on the platform, such as your name and residential address. However, we reserve the right to decline your rectification request if applicable laws explicitly permit or require us to do so under specific circumstances.
Right to Erasure and Restriction of Processing. You may request account cancellation, deletion of all your personal data, or restriction on the processing of specific personal data. We will promptly process your request if it complies with the requirements of the PDPA as well as other applicable laws.
Right to Portability. Where technically feasible, you may request the transfer of your non-sensitive personal data to another service provider.
Right to Object to Marketing. You may opt out of receiving marketing SMS, emails, in-app notifications and other promotional content from us at any time.
Right to Withdraw Consent. You may withdraw all previously granted authorizations for data processing at any time, including authorizations for the collection of sensitive personal data and the use of third-party tools and services.
You may contact the Data Protection Officer via the contact information specified below to exercise the above rights. Upon receiving such request, we will first verify your identity in order to protect user’s data security and legitimate rights and interests.
9. DATA PROTECTION OFFICER (DPO) & CONTACT INFORMATION
Should you have any questions or objections regarding this Privacy Policy, or need to exercise your rights related to personal data or file a complaint, please contact us via the methods below.
Data Protection Officer Name: Yiwen Zhang (张怡文)
Email: privacy@areteup.com
Address: 15 BEACH ROAD
#05-08
BEACH CENTRE
SINGAPORE (189677)
Complaint Channel: You may submit a complaint to the Personal Data Protection Commission of Singapore via its official website: www.pdpc.gov.sg.
10. POLICY UPDATES
We may update this Privacy Policy from time to time in light of changes to laws and regulations, platform service upgrades and function iterations.
After an update, we will notify you through in-app pop-up windows, in-app messages and official announcement channels. In the event of material changes, including addition of new types of sensitive personal data collected and revision of cross-border data transfer rules, we will obtain your explicit consent again.
Your continued use of the platform services shall be deemed as your acceptance of the updated Privacy Policy.
You may view the latest version of this Privacy Policy within the APP at any time.