Security and data protection for Klobbi Oracle
Your session, your data.
Oracle listens to your stage and writes down what is said. That means we hold your organisation’s words, and sometimes your attendees’ questions, for as long as your event needs them. This page sets out what we hold, where it goes, who can reach it and what we will put in writing for your procurement team.
ISO 27001 certified companyCSA Cyber Trust MarkBuilt for PDPASupport from Singapore
What Oracle holds
Three kinds of data, no more.
Everything Oracle keeps falls into one of three buckets. If a procurement questionnaire asks what personal data is processed, this is the answer.
Session audio
- What it is
- The feed from your venue’s sound desk while a session is running.
- Why we need it
- Captions and translation are generated from it. Without audio there is no product.
- How long we keep it
- Confirm with us for your event — we will put the retention period in your contract.
Transcripts and translations
- What it is
- The text of what was said, timestamped, plus the translated versions you ran.
- Why we need it
- It becomes the on-screen captions, the attendee recap and the record you keep.
- How long we keep it
- You set the retention period. At the end of it, the transcript is deleted.
Attendee interactions
- What it is
- Questions, votes and reactions. A name only if the attendee chose to attach one.
- Why we need it
- To run the Q&A and polls, and to give you the results afterwards.
- How long we keep it
- Kept with your event record and deleted with it.
Attendees don’t create an account. They scan a code and take part. Oracle doesn’t ask them for an email address, and an anonymous question carries no identity on the screen, in the recap or in the export you receive.
Where it goes, step by step
Follow one sentence through.
A speaker says something at 09:42. Here is everywhere those words exist afterwards, and for how long.
- What exists at this point
- Who can reach it
- How long
Tap a stage to follow the words through.
Certifications
Audited, with the paperwork to show.
Klobbi Pte Ltd holds both certificates below, issued by TÜV SÜD PSB Pte Ltd. We will send copies to your procurement team on request.
- Certificate
- IS27-2026-0346
- Issued by
- TÜV SÜD PSB Pte Ltd
- Scope
- Design, development and maintenance of event management system
- Valid
- 9 July 2026 to 22 April 2027
- Certificate
- CSA-Cyber Trust-Promoter-2026-0007
- Tier
- Promoter (Tier 3) · Classical Cybersecurity
- Issued by
- TÜV SÜD PSB Pte Ltd
- Valid
- 26 June 2026 to 25 June 2029
On scope, plainly: the certificates above are held by Klobbi Pte Ltd, and the ISO 27001 scope statement covers the design, development and maintenance of our event management system. Oracle is built and run by the same company, the same team and the same controls. If your procurement process needs a statement about Oracle specifically, ask us and we will put our position in writing rather than let a certificate logo answer for us.
PDPA and your role
The data is yours. We hold it for you.
Under Singapore’s Personal Data Protection Act, your organisation is the organisation collecting the personal data at your event. Klobbi processes it on your instructions, as a data intermediary, for the purposes you set out.
In practice that means the consent wording is yours, the retention period is yours, and the attendee list is yours. We don’t market to your attendees, and we don’t sell the data.
We will sign your data processing terms, or provide ours, whichever your legal team prefers.
- You decide what is collected, why, and how long it is kept.
- You write the consent and privacy wording your attendees see.
- We process only for your event, only on your instructions.
- We delete at the end of the retention period you set.
- Nobody markets to your attendees — not us, not anyone we work with.
Data Protection Officer · [email protected]
Who can reach your session
A named team, not a company.
Your event is worked on by the project manager assigned to it and the technical staff supporting that event. Not everyone at Klobbi can open your transcript, and the people who can are the people whose names are on your project.
Your moderators and organisers reach the session through their own logins, which you control and can revoke.
If an attendee asks a question anonymously, no name appears on the venue screen, in the recap, in your export or in our records of the session. There is no list of who asked what, because a town hall where people suspect otherwise is a town hall where nobody asks anything again.
What we will put in writing
Ask, and it goes in the contract.
Government agencies, universities, hospitals and banks have all put us through this process. These are the things we are used to confirming in writing before an event.
- Where your session data is processed and stored
- How long each type of data is kept, and when it is deleted
- Which of our staff can access your event, and how that is controlled
- Data processing terms, yours or ours
- Copies of both certificates, with scope statements
- Completed vendor security questionnaires
- Confidentiality undertakings for on-site crew
- Confirmation that recordings and transcripts are deleted on schedule
Frequently asked questions
Is Klobbi ISO 27001 certified?
Yes. Klobbi Pte Ltd holds ISO/IEC 27001:2022 certification, issued by TÜV SÜD PSB Pte Ltd, covering the design, development and maintenance of our event management system. We’ll send a copy of the certificate and the scope statement on request.
What is the Cyber Trust Mark?
It’s Singapore’s cybersecurity certification, run by the Cyber Security Agency. Klobbi holds it at the Promoter tier, which is the third of its five tiers, under the Classical Cybersecurity pillar.
Where is our session data stored?
Tell us your requirement and we’ll confirm our arrangement in writing for your procurement team.
How long do you keep recordings and transcripts?
For the retention period set in your contract, after which they’re deleted.
Who owns the transcript?
You do. It’s your session and your words. We don’t reuse your content, market to your attendees or sell the data.
Can attendees be identified from anonymous questions?
No. An anonymous question carries no name on the screen, in the recap or in the export you receive, and we don’t provide a list of who asked what.
Do attendees have to create an account?
No. They scan a code or open a link and take part. Oracle doesn’t collect an email address from them.
Will you complete our vendor security questionnaire?
Yes. Send it to [email protected] and we’ll complete it. We do this regularly for government, healthcare and university clients.
Can we sign our own data processing agreement?
Yes. We’ll work to your terms or provide ours, whichever your legal team prefers.
Who do we contact about a privacy concern?
Our Data Protection Officer, at [email protected].
Procurement · Legal · IT security
Send us the questionnaire.
We’d rather answer your security team’s questions now than discover them a week before your event. Send the form, or ask us anything on this page.
ISO 27001 certified companyCyber Trust Mark · Promoter tierMade in Singapore by Klobbi