Legal

Privacy Policy

Last updated: 17 August 2026

Regulatory Passport respects your privacy and is committed to protecting personal data.

Regulatory Passport is a brand operated by Mentogram Pte. Ltd., a company incorporated in Singapore ("Mentogram", "Regulatory Passport", "we", "us" or "our").

This Privacy Policy explains how we collect, use, disclose, store and protect personal data when you visit our website, contact us, purchase or use our services, interact with our platform or otherwise engage with Regulatory Passport.

1. Personal Data We May Collect

Depending on how you interact with us, we may collect information including:

Identity and Contact Information

  • name;
  • job title;
  • company or organisation;
  • email address;
  • telephone number;
  • country or location; and
  • business contact details.

Account Information

Where platform or account functionality is provided, we may collect:

  • login information;
  • account preferences;
  • organisation details;
  • account activity; and
  • service history.

Project and Regulatory Information

When you engage Regulatory Passport, we may receive information relating to:

  • your organisation;
  • products;
  • regulatory status;
  • target markets;
  • regulatory submissions;
  • product documentation;
  • technical files;
  • dossiers;
  • certificates;
  • manufacturers and suppliers;
  • project requirements; and
  • other information required to provide our services.

Some project information may be commercially confidential but may not constitute personal data unless it identifies or relates to an identifiable individual.

Payment and Transaction Information

We may collect information about:

  • services purchased;
  • invoices;
  • billing details;
  • transaction status; and
  • payment history.

Payment-card information may be processed directly by third-party payment providers rather than stored by us.

Website and Technical Information

We may automatically collect information such as:

  • IP address;
  • browser type;
  • device information;
  • operating system;
  • pages visited;
  • referral source;
  • approximate location;
  • website interactions; and
  • cookie or analytics identifiers.

Communications

We may retain communications with you, including:

  • emails;
  • contact-form submissions;
  • meeting information;
  • customer-support communications;
  • enquiries; and
  • feedback.

2. How We Collect Personal Data

We may collect personal data:

  • directly from you;
  • from your employer or organisation;
  • when you submit an enquiry;
  • when you purchase or request a service;
  • when you create or use an account;
  • during regulatory projects;
  • through meetings and correspondence;
  • through our website and cookies;
  • from service providers;
  • from business partners;
  • from publicly available professional or business sources; and
  • where otherwise permitted by applicable law.

3. How We Use Personal Data

We may use personal data to:

  • provide Regulatory Passport services;
  • respond to enquiries;
  • prepare proposals and quotations;
  • manage client relationships;
  • assess project requirements;
  • coordinate experts and consultants;
  • perform conflict checks;
  • deliver regulatory and market-entry projects;
  • process payments and invoices;
  • administer accounts;
  • operate and improve our website and platform;
  • maintain security;
  • prevent fraud or misuse;
  • analyse service performance;
  • communicate service updates;
  • maintain business records;
  • comply with legal and regulatory obligations;
  • establish, exercise or defend legal claims; and
  • conduct other activities reasonably necessary for operating Regulatory Passport.

Where required by applicable law, we will obtain appropriate consent before using personal data for a particular purpose.

4. Marketing Communications

Where permitted by applicable law, we may use business contact information to communicate information about Regulatory Passport services, insights, events or relevant offerings.

You may unsubscribe from marketing communications at any time using the unsubscribe mechanism provided or by contacting us.

We may continue sending non-marketing communications necessary for an existing client relationship or service.

5. Cookies and Analytics

Our website may use cookies and similar technologies to:

  • operate essential website functionality;
  • remember preferences;
  • understand website usage;
  • measure performance;
  • improve user experience; and
  • support marketing activities where permitted.

Where required by applicable law, we will obtain consent before placing non-essential cookies.

You may also control certain cookies through your browser settings.

6. How We Share Personal Data

We may disclose personal data where reasonably necessary to:

  • employees and authorised personnel;
  • regulatory experts and consultants;
  • professional advisers;
  • technology and cloud-service providers;
  • payment processors;
  • analytics providers;
  • communications providers;
  • regulatory or governmental authorities where required;
  • laboratories, representatives or other project partners where relevant to an engagement; and
  • other service providers supporting our operations.

We seek to limit disclosure to information reasonably necessary for the relevant purpose.

We do not sell personal data to third parties.

7. International Data Transfers

Regulatory Passport may operate internationally and may work with clients, experts and service providers located in different countries.

Accordingly, personal data may be transferred outside Singapore or outside the country in which it was originally collected.

Where required by applicable law, we take appropriate steps to ensure that overseas transfers of personal data are subject to an appropriate standard of protection.

8. Data Security

We use reasonable administrative, organisational and technical safeguards designed to protect personal data against risks including:

  • unauthorised access;
  • unauthorised disclosure;
  • misuse;
  • alteration;
  • loss; and
  • destruction.

However, no electronic system or method of transmission can be guaranteed to be completely secure.

9. Data Retention

We retain personal data only for as long as reasonably necessary for:

  • providing services;
  • maintaining business and regulatory records;
  • fulfilling contractual obligations;
  • resolving disputes;
  • complying with legal obligations; and
  • establishing or defending legal claims.

When personal data is no longer required for legitimate business or legal purposes, we will take reasonable steps to delete, anonymise or otherwise cease retaining it.

10. Access and Correction

Subject to applicable law, you may request access to personal data we hold about you and request correction of inaccurate or incomplete personal data.

Certain exceptions may apply where permitted by law.

Requests may be submitted using the contact information below.

11. Withdrawal of Consent

Where we process personal data based on consent, you may withdraw your consent by providing reasonable notice.

Withdrawal of consent may affect our ability to provide services where the relevant information is necessary for delivering those services or fulfilling legal obligations.

12. Data Breaches

Where a personal-data breach occurs, we will assess the incident and take appropriate steps in accordance with applicable data-protection requirements.

Where notification to individuals or a regulatory authority is legally required, we will make the required notifications in accordance with applicable law.

13. Third-Party Websites and Services

Our website or services may contain links to third-party websites, regulatory authorities, partner organisations or other external services.

Their privacy practices are governed by their own policies, and Regulatory Passport is not responsible for the privacy practices of independent third parties.

14. Business Clients

Much of Regulatory Passport's work involves organisations rather than individual consumers.

Where a client provides personal data relating to its employees, contractors, customers or other individuals, the client is responsible for ensuring that it has an appropriate basis for providing that information to us.

We will process such information in accordance with applicable law and the relevant contractual arrangements.

15. Children

Regulatory Passport provides professional and business services and is not intended for children.

We do not knowingly seek to collect personal data from children through our services.

16. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our services, technology, business operations or legal requirements.

The latest version will be published on our website with the updated effective date.

17. Contact and Data Protection Enquiries

Regulatory Passport is operated by:

Mentogram Pte. Ltd.
Singapore

Data Protection / Privacy Email: hello@regulatorypassport.com

You may contact us using the above details regarding:

  • access or correction requests;
  • withdrawal of consent;
  • privacy questions;
  • complaints; or
  • other personal-data matters.

Where required under applicable law, requests will be handled within the applicable statutory timeframe.

18. Singapore Personal Data Protection Act

Mentogram Pte. Ltd. handles personal data in accordance with applicable requirements of Singapore's Personal Data Protection Act 2012 ("PDPA") and other applicable data-protection laws.

Where individuals located outside Singapore interact with Regulatory Passport, additional rights or requirements may apply under the laws of their jurisdiction.