Privacy Policy
How Midnight Brewlab collects, uses, and protects the limited personal data you share with us through the Built to Renew website.
This Privacy Policy explains how Midnight Brewlab Pte. Ltd. ("Midnight Brewlab", "we", "us", or "our"), the operator of the Built to Renew program and this website, handles personal data collected through the site. This is a marketing and information site for a professional executive program. It is directed to business professionals. It is not intended for consumers or children, and we do not sell products or process payments through it.
1. Who is responsible for your data
The party responsible for personal data collected through this website is Midnight Brewlab Pte. Ltd. (UEN 202439998W), a private company limited by shares registered in Singapore. Built to Renew is delivered by Midnight Brewlab as a joint program with Prof. Dr. Wim Vanhaverbeke and Dr. Bert Grobben.
For any privacy matter, contact us at hello@midnightbrewlab.com. Our registered office address is available on request.
2. What personal data we collect
We practise data minimisation and collect only what we need. When you use this website, we may collect:
- Registration and enquiry data: your name, business email address, role and organisation, your preferred participation tier, and any message you choose to send us when you register your interest.
- Email correspondence: the contents of any message you send us and the contact details you provide.
- Technical and server log data: limited information automatically recorded by our hosting infrastructure, such as IP address, browser type, and timestamps, used for security, diagnostics, and to keep the website running reliably.
The registration form on this website opens your own email application with the details prefilled, so your message reaches us by email. We do not collect special categories of data (such as health data) through this website, we do not run advertising, and we do not carry out automated decision-making or profiling. We do not knowingly collect data from children.
3. Why we use it, and our legal basis
We use the personal data described above for the following purposes, on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Responding to your registration or enquiry, and following up about the program and your participation | Our legitimate interest in business-to-business communication (GDPR Art. 6(1)(f)); under the Singapore PDPA, with your consent or as permitted for legitimate business purposes. |
| Administering your place in a cohort, and sending you program logistics if you register | Steps taken at your request prior to, and in performance of, our arrangement with you (GDPR Art. 6(1)(b)); permitted business purposes under the PDPA. |
| Maintaining the security, integrity, and reliability of the website | Our legitimate interest in protecting our systems (GDPR Art. 6(1)(f)); reasonable security and business purposes under the PDPA. |
| Complying with legal, regulatory, and record-keeping obligations | Compliance with a legal obligation (GDPR Art. 6(1)(c)) and applicable Singapore law. |
Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You can object to this processing at any time (see your rights below). We do not use your details for unrelated marketing without an appropriate basis, and you can ask us to stop contacting you at any time.
4. Who we share it with
We do not sell your personal data. We share it only with the two program principals and with trusted service providers who help us run the website and communicate with you, such as our website hosting and email providers. These providers act on our instructions and are bound to protect your data. We may also disclose data where required by law or to protect our legal rights.
5. International transfers
Midnight Brewlab operates from Singapore and works with the program principals and service providers located in other countries, including within the European Union and the United States. Where personal data is transferred across borders, including from the EU/EEA to Singapore or elsewhere, we put appropriate safeguards in place, such as the European Commission's Standard Contractual Clauses, and we take steps to ensure your data continues to receive an adequate level of protection wherever it is processed.
6. How long we keep it
- Registration and enquiry data: for as long as our dialogue or relationship with you is active, and for up to 24 months after our last meaningful contact, unless a longer period is required or permitted by law. If we receive no response or engagement, we delete the data within 12 months.
- Server and security logs: typically up to 90 days, and no longer than 12 months unless needed for security investigation or legal reasons.
- Where a registration leads to participation, related records are kept for the duration of the program and applicable statutory limitation periods.
When personal data is no longer needed for any business or legal purpose, we securely delete or anonymise it.
7. Your rights
Depending on where you are located, you have rights over your personal data. We honour the following rights for all website visitors:
- Access: request confirmation of whether we process your data and a copy of it.
- Correction: ask us to correct inaccurate or incomplete data.
- Erasure: ask us to delete your data where it is no longer needed or where you withdraw a consent we relied on.
- Restriction and objection: ask us to restrict processing, or object to processing based on our legitimate interests. You may object to any direct marketing at any time, and we will stop.
- Withdraw consent: where we rely on your consent, you may withdraw it at any time, without affecting processing carried out before withdrawal.
- Data portability: where applicable, receive certain data in a portable format.
- Complain: lodge a complaint with a supervisory authority (see below).
To exercise any right, email us at hello@midnightbrewlab.com. We may ask for information to verify your identity. We will respond within 30 days; for the EU/EEA we respond within one month, extendable by up to two further months for complex requests, and at no charge unless a request is manifestly unfounded or excessive.
If you are in Singapore, you may contact the Personal Data Protection Commission (PDPC) at www.pdpc.gov.sg. If you are in the EU/EEA, you may lodge a complaint with your local data protection authority. We would, however, appreciate the chance to address your concerns first.
8. Cookies and analytics
This website keeps its use of cookies to a minimum. We use only what is needed for the site to function, such as remembering your light or dark display choice, which is stored locally in your browser. We do not use advertising cookies or third-party tracking. You can clear or block cookies through your browser settings at any time.
9. How we protect your data
We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or alteration. Data is transmitted over encrypted (HTTPS/TLS) connections, access is limited to authorised personnel on a need-to-know basis, and our service providers are contractually required to maintain equivalent safeguards. No transmission over the internet is ever completely secure, so we cannot guarantee absolute security, but we work to protect your data and to respond promptly if anything goes wrong.
10. Changes to this policy
We may update this Privacy Policy from time to time. We will indicate material changes by updating the effective date above and, where appropriate, by providing more prominent notice. Please review this page periodically.
← Back to Built to Renew