Privacy
Last updated 14 September 2026
This is the AdminLess company privacy policy. It covers this website, and it covers booking a call with us. The calendar our other sites use is one calendar belonging to one company, so its policy lives here rather than in two slightly different versions. It is written in plain English rather than in legal language, because you should not need a lawyer to read a privacy policy.
The short version. We do not use cookies. We do not use Google Analytics or any other third-party tracker. We never store your IP address. There is no form on this page. The two places we do get your details are the booking calendar (your name, your email address and the answers to that service's own questions) and the forms on our other sites, which have their own policies. We use what you give us to hold the appointment and to reply to you.
Who we are
AdminLess AI Pte Ltd (UEN 202540525M), 60 Paya Lebar Road #06-28, Paya Lebar Square, Singapore 409051. We are the organisation responsible for the personal data described on this page. For anything to do with your data, write to hello@adminless.ai.
We are not a law firm and we do not give legal advice. We build and run software.
What this policy covers, and what it does not
| What | Where the policy is |
|---|---|
| This website: adminless.ai, the company card | Here. It has no form and takes no payment. |
| Booking a call: the Microsoft Bookings calendar shown on our other sites | Here, in the next section. One calendar, one policy. |
| The forms on our other sites: the enquiry, one-pager and scoping forms | On the site that carries the form: agency, company. Each one lists its own fields. |
| Software we install or run for a client | In the written agreement for that work, agreed before anything is built. Not on a web page. |
Booking a call
This is the one part of AdminLess where a visitor hands over personal details to a third-party service, so it is set out in full, field by field. If you are reading this from a link on the booking page itself, that is deliberate: the booking page's own "privacy policy" and "terms" links point here, because there is one booking business behind both calls and this is its policy.
Our booking calendar is Microsoft Bookings, part of our own Microsoft 365 tenant. There is one AdminLess booking business with two services (a process review and a scoping call, one per site) and the booking panel on agency.adminless.ai and company.adminless.ai shows the right one of the two. It is Microsoft's page, served from Microsoft's servers, displayed inside ours. How long each call runs is stated on the site you booked from and on the booking page itself; it is not repeated here, because a duration that drifts in a privacy policy is worse than no duration at all.
What it collects
The booking form asks for exactly these, and there are no custom questions on either of the two services:
| Field | Required? |
|---|---|
| First and last name | Required. Without it there is no appointment. |
| Email address | Required. It is where the confirmation, the invite and any reschedule go. |
| Address | Optional. Microsoft's form offers it and we have not needed it yet, so leave it blank, but if you fill it in, we hold it, which is why it is named here rather than glossed over. |
| Phone number | Optional. Only used to reach you about this appointment. |
| Notes | Optional free text. Whatever you type here we read before the call. |
| Additional guests, up to 10 | Offered on the mnc booking, not on the ssa one. See the paragraph below. |
Two more things are collected without you typing them. The page loading: because the calendar is loaded from Microsoft when our booking section loads (not when you click), Microsoft receives your IP address and your browser type from that moment, as any web request does, and that happens even if you never book. The slot you chose: times on that page are shown in (UTC+08:00) Kuala Lumpur, Singapore.
If you add a guest
On the mnc booking you can add up to ten additional guests by email address. That means you are giving us somebody else's personal data, and they have not read this page. So, plainly: a guest's email address goes into Microsoft Bookings and into the calendar invite, Microsoft emails them the invite and any change to it, and it sits in the appointment in our calendar. We do not use it for anything else: not to contact them separately, not to add them to anything, and there is nothing to add them to. If a guest wants their address removed, they or you can write to hello@adminless.ai and we will remove it. Please only add people who know you are booking on their behalf.
Please do not put confidential material or a client's details into the notes field. A sentence is enough; the detail belongs on the call.
What then happens
- The appointment is written into our own Outlook calendar, which is how the times you were offered were real availability rather than a guess.
- Microsoft sends you a confirmation email and a calendar invite, and the reminders and reschedule or cancel links that go with it. Those come from Microsoft's service, on our behalf.
- Inside AdminLess, the appointment is visible to the people who need it in order to turn up and prepare. If a form on one of our other sites is what brought you to us, the notification of it is emailed to hello@adminless.ai and nowhere else: the application that sends that mail is restricted by policy to that one mailbox, so it cannot be pointed at another.
- Microsoft is a service provider acting on our instructions for all of this, not a party we share your data with for their own purposes. Their handling of it is described in the Microsoft privacy statement.
How long a booking is kept
The appointment stays in our calendar, and its confirmation in our mailbox, for as long as we keep the correspondence about it, and we delete both on request. We are describing what happens rather than quoting a number we do not enforce: there is no automatic purge of our calendar, so if you want a booking and its emails removed, ask hello@adminless.ai and we will do it.
When you simply read a page of ours
We count visits, so we know whether a page works and which part of it people stop reading. This is our own software, running on our own server, and it is the same on every AdminLess site including this one. It records:
- which page you landed on, and which site sent you (for example a search engine or a link), plus any campaign tag in the link;
- whether you are on a phone, a tablet or a computer;
- which sections of the page you reached, and roughly how long each one held your attention;
- which buttons and links were clicked: on this card, which of the two doors you took, or the email address;
- the country your visit came from, as reported by our network provider.
How we count people without identifying them. To tell one visit from another we need some sort of label. Instead of a cookie, we take your IP address and browser type, mix them with today's date and a secret key, and run the result through a one-way cryptographic function. That produces a short code.
Two things follow from this, and they are the entire design. First, your IP address is used for that one calculation and then discarded. It is never written to our records. Second, because today's date goes into the calculation, the same person visiting tomorrow produces a completely unrelated code. So we can answer "how many people came today", and we genuinely cannot follow you from one day to the next, build a profile of you, or work backwards from the code to you.
That is also why we do not need to ask your permission for a cookie: there is no cookie, nothing is stored on your device, and there is no identifier that survives the day.
What we do not do
- We do not sell, rent or trade your personal data. Ever.
- We do not use cookies, local storage, session storage, browser fingerprinting, or session recording.
- We do not use Google Analytics, Meta pixels, or any other third-party analytics or advertising tracker.
- We do not embed anything from anybody else on this page: no calendar, no map, no video, no font from someone else's server. The booking calendar is embedded on the two sites that offer a call, and it is described above.
- We do not take payment on any of our websites, so we hold no card details.
- We do not use what you tell us to train a machine-learning model.
- We do not send you marketing you did not ask for, and we run no mailing list.
Who else can see it
Our pages and the data behind them run on our own server. We keep the list of outside parties as short as we can, and today it is:
- Cloudflare, which carries the connection between your browser and our server and protects it from attack. Your request necessarily passes through them, and they are the source of the country figure mentioned above.
- Microsoft, because our email runs on Microsoft 365 and our booking calendar is Microsoft Bookings. Bookings, the confirmation email, the calendar entry and any mail between us all sit there.
We will update this list if it changes. Both are service providers acting on our instructions.
Where it is kept, and for how long
What we hold ourselves is stored on a server in Singapore.
- A booking: as described above, in our Microsoft 365 calendar and mailbox while the correspondence is live, and deleted on request.
- Anything submitted through a form on another of our sites: kept while we are dealing with your enquiry and for up to 12 months afterwards, then deleted. Sooner if you ask.
- The counting data: kept for up to 24 months as aggregate figures. It contains no identifier that lasts beyond the day it was recorded, so it cannot be traced back to you even by us.
Your rights under the PDPA
Under Singapore's Personal Data Protection Act you may:
- ask what we hold about you, and we will tell you;
- ask us to correct it if it is wrong;
- ask us to delete it, and we will, unless we are required to keep it, including a booking, its invite and its confirmation;
- withdraw your consent at any time, though if you withdraw it before a call we will have to cancel the call.
Write to hello@adminless.ai and we will act on it within 30 days. If you are not satisfied with how we have dealt with it, you may take it to the Personal Data Protection Commission of Singapore.
Children
Our services are sold to organisations and their staff. We do not knowingly collect data from anyone under 13.
Security
The connection to our sites is encrypted. Access to the stored data is limited to the people at AdminLess who need it to answer you, and the mailbox our form notifications can reach is restricted to one address by policy rather than by habit.
Changes
If we change this policy we will change the date at the top. If the change is significant and we hold your email address because you contacted us or booked a call, we will tell you.