Privacy Policy

Effective Date: 1 September 2026

YYForce Inc. (“YYForce”, “we”, “us” or “our”), formerly known as YY Group Holding Limited, respects the privacy of individuals who visit www.yyforce.ai (the “Website”), submit information through the Website or otherwise communicate with us in connection with the Website.

This Privacy Policy explains how we may collect, use, disclose, retain and otherwise handle personal data in connection with the Website.

1. Scope of This Policy

This Policy applies to personal data collected through or in connection with this corporate Website.

YYForce subsidiaries, affiliates, applications, platforms, products or services may maintain separate privacy notices or policies.

Where a separate privacy notice applies to a particular product, service, platform or application, that notice will govern the processing described in it.

This Policy does not govern third-party websites or services that may be linked from the Website.

2. Personal Data We May Collect

The personal data we collect depends on how you interact with us and the Website.

2.1 Information You Provide to Us

We may collect information that you voluntarily provide when you:

  • contact us or submit an enquiry;
  • communicate with our business, corporate or investor relations teams;
  • subscribe to newsletters, updates or other communications, where available;
  • provide feedback; or
  • otherwise communicate with us through the Website.

This information may include:

  • your name;
  • email address;
  • telephone number;
  • company or organisation;
  • job title, where provided;
  • communication preferences;
  • the contents of your enquiry or correspondence; and
  • other information you choose to provide.

Please avoid providing personal data that is not reasonably necessary for your enquiry or communication with us.

2.2 Information Generated Through Use of the Website

When you access the Website, certain technical information may be generated or collected through our web infrastructure, cookies or similar technologies.

Depending on the Website’s configuration and technologies in use, this information may include:

  • Internet Protocol (IP) address;
  • browser type;
  • device or operating-system information;
  • pages accessed;
  • referring or exit pages;
  • dates and times of access; and
  • cookie or similar technical identifiers.

The types of technical information collected may change as the Website and its technical configuration change.

We do not represent in this Policy that the Website collects specific categories of information, such as precise GPS location, purchasing histories or detailed behavioural profiles, unless such processing actually forms part of the Website and this Policy is updated accordingly.

3. Cookies and Similar Technologies

The Website may use cookies and similar technologies to provide Website functionality and, where applicable, understand Website performance or user interactions.

The particular cookies and technologies used depend on the Website’s technical configuration at the relevant time.

Where cookies or similar technologies require consent or another form of user choice under applicable law, appropriate choices will be made available through the Website’s cookie banner, cookie notice or cookie settings.

You may also be able to control cookies through your browser settings.

Disabling certain cookies may affect the functionality of the Website.

4. How We Use Personal Data

We may collect, use or disclose personal data for purposes including:

  • responding to enquiries and communications;
  • providing information that you request;
  • administering newsletter or communication subscriptions, where applicable;
  • maintaining, operating and improving the Website;
  • diagnosing technical or security issues;
  • protecting the Website, our systems, our users and our organisation;
  • managing business, corporate, investor and stakeholder communications;
  • maintaining appropriate business and correspondence records;
  • complying with applicable laws, regulations, court orders, regulatory requirements and lawful requests;
  • preventing or investigating suspected misuse, fraud or unlawful activity;
  • establishing, exercising or defending legal rights; and
  • other purposes notified to you at the time the information is collected or otherwise permitted by applicable law.

We will not use personal data for a materially different purpose without taking any steps required by applicable law.

5. Consent and Other Permitted Processing

Where the Singapore Personal Data Protection Act 2012 (“PDPA”) applies, we will collect, use and disclose personal data in accordance with the PDPA, including applicable requirements concerning notification, consent and permitted exceptions.

Where consent is required, we may obtain it through the relevant interaction or point of collection.

In circumstances permitted by applicable law, personal data may also be collected, used or disclosed without consent.

Where privacy or data-protection laws of another jurisdiction apply to particular processing activities, we will handle the relevant personal data in accordance with the requirements applicable to that processing.

This Privacy Policy is intended to explain our privacy practices.

Mere access to the Website is not intended, by itself, to constitute consent to processing for which express consent is required by applicable law.

6. Communications

If you subscribe to or otherwise request communications from us, we may use the contact details you provide to send those communications.

You may unsubscribe from marketing or promotional email communications using any unsubscribe mechanism provided in the communication or by contacting us.

Where communications to Singapore telephone numbers are subject to the Do Not Call provisions of the PDPA, such communications will be handled in accordance with applicable requirements.

Administrative, transactional, corporate, regulatory or other non-marketing communications may not be affected by a marketing opt-out where there is an appropriate basis for sending them.

7. Disclosure of Personal Data

We may disclose personal data where reasonably necessary for the purposes described in this Policy.

Recipients may include:

7.1 YYForce Companies

Subsidiaries or affiliated companies within the YYForce group where access to the information is reasonably necessary for a relevant business, operational or administrative purpose.

7.2 Service Providers

Third parties providing services that support our Website or operations, including technology, website, communications or other service providers where applicable.

Where service providers process personal data on our behalf, we seek to require them to handle the information appropriately and for authorised purposes, subject to applicable law and contractual arrangements.

7.3 Professional Advisers

Legal advisers, accountants, auditors, insurers, financial advisers and other professional advisers where disclosure is reasonably necessary.

7.4 Authorities and Legal Requirements

Government authorities, regulators, law-enforcement agencies, courts or other persons where disclosure:

  • is required or permitted by applicable law;
  • is necessary to comply with legal or regulatory obligations; or
  • is reasonably necessary to establish, exercise or defend legal rights.

7.5 Corporate Transactions

Relevant parties, potential counterparties and advisers in connection with an actual or proposed:

  • merger;
  • acquisition;
  • disposal;
  • restructuring;
  • financing;
  • investment;
  • reorganisation; or
  • other corporate transaction.

Appropriate confidentiality or data-protection measures will be applied where required.

We do not state that YYForce sells Website visitors’ personal data or shares it with third parties for targeted advertising unless such a practice is actually implemented and appropriately disclosed.

8. International Transfers

YYForce operates internationally, and personal data may in appropriate circumstances be processed or accessed outside Singapore.

Where the PDPA applies to a transfer of personal data outside Singapore, we will take steps required under applicable law to ensure that the transferred personal data receives a standard of protection comparable to that required under the PDPA, unless an applicable exception applies.

Where other applicable data-protection laws govern an international transfer, we will implement measures required by those laws where applicable.

9. Data Retention

We retain personal data only for as long as reasonably necessary for:

  • the purposes for which the information was collected;
  • legitimate operational or business requirements;
  • compliance with legal or regulatory obligations;
  • dispute resolution; or
  • the establishment, exercise or defence of legal rights.

When personal data is no longer required for such purposes, we will cease retaining it or remove the means by which the data can be associated with particular individuals where required by applicable law and reasonably practicable.

Different categories of information may be retained for different periods depending on their purpose and applicable legal, regulatory or business requirements.

10. Data Security

We take reasonable measures designed to protect personal data in our possession or under our control against risks such as unauthorised access, collection, use, disclosure, copying, modification, disposal or loss, in accordance with applicable legal requirements.

No website, electronic transmission or information-storage system can be guaranteed to be completely secure.

Accordingly, we cannot guarantee the absolute security of information transmitted to or through the Website.

Where a personal-data breach occurs, we will assess and address the incident in accordance with applicable legal requirements, including applicable notification requirements.

11. Accuracy of Personal Data

Where required by applicable law, we may take reasonable steps to ensure that personal data in our possession or under our control is accurate and complete where that data is likely to be:

  • used to make a decision affecting an individual; or
  • disclosed to another organisation.

You may contact us if you believe personal data we hold about you contains an error or omission.

12. Your Rights and Choices

Your rights concerning personal data depend on the laws applicable to the relevant processing.

Singapore

Subject to the PDPA and applicable exceptions, you may request:

  • access to personal data about you that is in our possession or under our control;
  • information concerning the ways in which such personal data has been used or disclosed within the applicable period; and
  • correction of an error or omission in personal data about you that is in our possession or under our control.

Where we rely on your consent to collect, use or disclose personal data, you may withdraw that consent by giving reasonable notice.

Where applicable, we may inform you of the likely consequences of withdrawing consent.

Withdrawal of consent does not affect processing that is otherwise permitted or required by applicable law.

Other Jurisdictions

If privacy or data-protection laws in another jurisdiction apply to our processing of your personal data, you may have additional rights under those laws.

We will consider requests in accordance with the law applicable to the relevant processing and any applicable exemptions, limitations, procedures and identity-verification requirements.

13. Third-Party Links

The Website may contain links to websites, platforms or services operated by third parties.

This Privacy Policy does not govern the privacy practices of those third parties.

We encourage you to review the privacy policies of third-party websites and services before providing personal data to them.

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in:

  • our business or practices;
  • the Website;
  • technology;
  • applicable legal or regulatory requirements; or
  • other relevant circumstances.

When we update the Policy, we will publish the revised version on this page and update the effective or last-updated date.

Where required by applicable law, we will provide additional notice or obtain consent in relation to material changes.

15. Contact and Data Protection Officer

If you have questions about this Privacy Policy, wish to make an applicable data-protection request or wish to raise a privacy concern, you may contact our Data Protection Officer using the contact details published by the Company.

YYForce Inc.
Attn: Data Protection Officer
Email: dpo@hongyegroup.com.sg
Email: dpo@yycircle.com
Telephone: +65 6604 6896 / +65 6604 6919

We may request information reasonably necessary to verify your identity and process your request.

For general corporate enquiries:

Email: enquiries@yyforce.ai

If you remain dissatisfied with our handling of a privacy concern, you may have the right to contact the competent data-protection authority applicable to your circumstances, including the Personal Data Protection Commission in Singapore where appropriate.