Security and data protection for Klobbi Oracle

Your session, your data.

Oracle listens to your stage and writes down what is said. That means we hold your organisation’s words, and sometimes your attendees’ questions, for as long as your event needs them. This page sets out what we hold, where it goes, who can reach it and what we will put in writing for your procurement team.

ISO 27001 certified companyCSA Cyber Trust MarkBuilt for PDPASupport from Singapore

What Oracle holds

Three kinds of data, no more.

Everything Oracle keeps falls into one of three buckets. If a procurement questionnaire asks what personal data is processed, this is the answer.

  • Session audio

    What it is
    The feed from your venue’s sound desk while a session is running.
    Why we need it
    Captions and translation are generated from it. Without audio there is no product.
    How long we keep it
    Confirm with us for your event — we will put the retention period in your contract.
  • Transcripts and translations

    What it is
    The text of what was said, timestamped, plus the translated versions you ran.
    Why we need it
    It becomes the on-screen captions, the attendee recap and the record you keep.
    How long we keep it
    You set the retention period. At the end of it, the transcript is deleted.
  • Attendee interactions

    What it is
    Questions, votes and reactions. A name only if the attendee chose to attach one.
    Why we need it
    To run the Q&A and polls, and to give you the results afterwards.
    How long we keep it
    Kept with your event record and deleted with it.

Attendees don’t create an account. They scan a code and take part. Oracle doesn’t ask them for an email address, and an anonymous question carries no identity on the screen, in the recap or in the export you receive.

Where it goes, step by step

Follow one sentence through.

A speaker says something at 09:42. Here is everywhere those words exist afterwards, and for how long.

What exists at this point
Who can reach it
How long

Tap a stage to follow the words through.

Certifications

Audited, with the paperwork to show.

Klobbi Pte Ltd holds both certificates below, issued by TÜV SÜD PSB Pte Ltd. We will send copies to your procurement team on request.

ISO/IEC 27001:2022
Certificate
IS27-2026-0346
Issued by
TÜV SÜD PSB Pte Ltd
Scope
Design, development and maintenance of event management system
Valid
9 July 2026 to 22 April 2027
CSA Cyber Trust Mark
Certificate
CSA-Cyber Trust-Promoter-2026-0007
Tier
Promoter (Tier 3) · Classical Cybersecurity
Issued by
TÜV SÜD PSB Pte Ltd
Valid
26 June 2026 to 25 June 2029

On scope, plainly: the certificates above are held by Klobbi Pte Ltd, and the ISO 27001 scope statement covers the design, development and maintenance of our event management system. Oracle is built and run by the same company, the same team and the same controls. If your procurement process needs a statement about Oracle specifically, ask us and we will put our position in writing rather than let a certificate logo answer for us.

PDPA and your role

The data is yours. We hold it for you.

Under Singapore’s Personal Data Protection Act, your organisation is the organisation collecting the personal data at your event. Klobbi processes it on your instructions, as a data intermediary, for the purposes you set out.

In practice that means the consent wording is yours, the retention period is yours, and the attendee list is yours. We don’t market to your attendees, and we don’t sell the data.

We will sign your data processing terms, or provide ours, whichever your legal team prefers.

Who does whatUnder PDPA
  • You decide what is collected, why, and how long it is kept.
  • You write the consent and privacy wording your attendees see.
  • We process only for your event, only on your instructions.
  • We delete at the end of the retention period you set.
  • Nobody markets to your attendees — not us, not anyone we work with.

Data Protection Officer · [email protected]

Who can reach your session

A named team, not a company.

Your event is worked on by the project manager assigned to it and the technical staff supporting that event. Not everyone at Klobbi can open your transcript, and the people who can are the people whose names are on your project.

Your moderators and organisers reach the session through their own logins, which you control and can revoke.

Anonymous stays anonymousQ&A

If an attendee asks a question anonymously, no name appears on the venue screen, in the recap, in your export or in our records of the session. There is no list of who asked what, because a town hall where people suspect otherwise is a town hall where nobody asks anything again.

What we will put in writing

Ask, and it goes in the contract.

Government agencies, universities, hospitals and banks have all put us through this process. These are the things we are used to confirming in writing before an event.

  • Where your session data is processed and stored
  • How long each type of data is kept, and when it is deleted
  • Which of our staff can access your event, and how that is controlled
  • Data processing terms, yours or ours
  • Copies of both certificates, with scope statements
  • Completed vendor security questionnaires
  • Confidentiality undertakings for on-site crew
  • Confirmation that recordings and transcripts are deleted on schedule

Frequently asked questions

Is Klobbi ISO 27001 certified?

Yes. Klobbi Pte Ltd holds ISO/IEC 27001:2022 certification, issued by TÜV SÜD PSB Pte Ltd, covering the design, development and maintenance of our event management system. We’ll send a copy of the certificate and the scope statement on request.

What is the Cyber Trust Mark?

It’s Singapore’s cybersecurity certification, run by the Cyber Security Agency. Klobbi holds it at the Promoter tier, which is the third of its five tiers, under the Classical Cybersecurity pillar.

Where is our session data stored?

Tell us your requirement and we’ll confirm our arrangement in writing for your procurement team.

How long do you keep recordings and transcripts?

For the retention period set in your contract, after which they’re deleted.

Who owns the transcript?

You do. It’s your session and your words. We don’t reuse your content, market to your attendees or sell the data.

Can attendees be identified from anonymous questions?

No. An anonymous question carries no name on the screen, in the recap or in the export you receive, and we don’t provide a list of who asked what.

Do attendees have to create an account?

No. They scan a code or open a link and take part. Oracle doesn’t collect an email address from them.

Will you complete our vendor security questionnaire?

Yes. Send it to [email protected] and we’ll complete it. We do this regularly for government, healthcare and university clients.

Can we sign our own data processing agreement?

Yes. We’ll work to your terms or provide ours, whichever your legal team prefers.

Who do we contact about a privacy concern?

Our Data Protection Officer, at [email protected].

Procurement · Legal · IT security

Send us the questionnaire.

We’d rather answer your security team’s questions now than discover them a week before your event. Send the form, or ask us anything on this page.

ISO 27001 certified companyCyber Trust Mark · Promoter tierMade in Singapore by Klobbi

WhatsApp us