Legal · watchandreviewit.pro
Privacy Policy
Last updated: 19 August 2026 · Applies to https://watchandreviewit.pro/
This Privacy Policy explains how Watch And Review It ("Watch And Review It", "we", "us", "our") collects, uses, discloses, and protects personal data when you visit https://watchandreviewit.pro/ (the "Site") or contact us by telephone or email. We publish independent film reviews, including our detailed review of Million Dollar Murder. We designed the Site to work without JavaScript-dependent features and without a contact form, which limits the categories of data we collect automatically.
1. Who we are
Data controller: Watch And Review It, 116 Middle Road, #08-01 ICB Enterprise House, Singapore 188972. General enquiries: [email protected]. Phone: +65 6706 3841 (Mon–Fri 10:00–18:30 SGT, Sat 11:00–15:00 SGT). Privacy-related correspondence may use the same channels; please put "Privacy" in your subject line.
2. Scope
This policy covers the Site and communications you initiate with us. It does not cover third-party websites such as Amazon, Google Maps, or your device manufacturer’s browser policies. When you follow our "Watch on Amazon" link, Amazon’s privacy terms apply to any account or purchase activity there.
3. Personal data we collect
3.1 Data you provide voluntarily
If you email or call us, we receive the information you choose to share — for example your name, email address, phone number, and message content. We do not require you to create an account to read our review. Because we do not operate a web form, we do not collect form-field metadata such as CAPTCHA scores or hidden UTM fields on submission.
3.2 Data collected automatically
Our hosting provider may log standard server data: IP address, browser user-agent, requested URL, referrer, timestamp, and HTTP status. We use these logs for security, troubleshooting, and aggregate traffic analysis. We do not use them to build individual behavioural profiles on this Site.
3.3 Cookies and similar technologies
See our Cookies Policy for details. In summary, we aim to minimise non-essential cookies. Embedded Google Maps on the contact page may set third-party cookies when you interact with the map.
3.4 Special categories
We do not ask you to provide sensitive personal data (such as health, biometric, or government ID numbers). Please do not send such information unless strictly necessary for a legal request we can lawfully process.
4. Purposes and legal bases
We process personal data for the following purposes:
- Operating the Site — delivering pages, images, and structured review content to your browser.
- Responding to enquiries — answering emails and calls about reviews, corrections, or rights requests.
- Security and fraud prevention — detecting abusive traffic, protecting infrastructure hosted in the AWS Singapore Region.
- Legal compliance — retaining records where required by applicable law or to establish, exercise, or defend legal claims.
- Improvement — understanding aggregate readership patterns to prioritise editorial topics (without selling personal data).
Where Singapore’s Personal Data Protection Act 2012 (PDPA) applies, we rely on consent (where requested), deemed consent by voluntary provision, legitimate interests balanced against your rights, or legal obligation as appropriate to each processing activity. We document the purpose for each category at collection and review compatibility before any new use.
We do not use personal data for profiling that produces legal effects, and we do not purchase marketing lists to contact visitors who never emailed us first.
5. Disclosure to third parties
We do not sell personal data. We may share limited data with:
- Infrastructure providers — e.g. Amazon Web Services for hosting and logs in Singapore.
- Email and telephony carriers — to deliver messages you send us or responses we send you.
- Professional advisers — lawyers or accountants under confidentiality when necessary.
- Authorities — if required by valid legal process or to protect rights and safety.
Embedded map content is served by Google. Google may process device and location-related data according to its own policies when you load contact.php.
6. International transfers
Primary hosting is in Singapore. Email routing or support tooling may involve processors in other countries with comparable safeguards or contractual protections. Where we transfer data outside Singapore, we take steps reasonably required under the PDPA, such as standard contractual clauses or ensuring the recipient is subject to comparable law.
When you email us from outside Singapore, your message may route through mail servers in transit countries. We choose providers that publish security statements and data processing terms, and we configure mailboxes with access logging where available.
7. Retention
Server logs: typically up to ninety days unless needed for security investigation. Email correspondence: up to three years from last message in the thread, unless a longer period is required for disputes. Call records: we do not routinely record calls; any notes we take during a call are kept only as long as needed to resolve the enquiry. When retention ends, we delete or anonymise data in ordinary course.
8. Your rights
Subject to exceptions in the PDPA and other law, you may request access to personal data we hold about you, correction of inaccuracies, withdrawal of consent where processing is consent-based, and information about how we have used or disclosed your data. To exercise rights, email [email protected] with enough detail for us to verify your identity. We respond within a reasonable period, generally within thirty days.
You may also ask us to transmit certain data to another organisation where technically feasible and required by law. We will not charge a fee for reasonable requests unless a request is manifestly unfounded, repetitive, or excessive, in which case we may charge a modest administrative fee or refuse the request as permitted by the PDPA.
If you believe we have not handled a complaint adequately, you may contact the Personal Data Protection Commission (PDPC) in Singapore. We encourage you to contact us first so we can try to resolve the matter.
9. Security
We use HTTPS, access controls on hosting accounts, and least-privilege administration. No online transmission is perfectly secure; you provide information at your own risk, though we work to protect data in our control.
Administrators use unique credentials and multi-factor authentication where the hosting panel supports it. We patch server software on a regular cycle and monitor logs for anomalous traffic spikes that might indicate scraping or credential stuffing against static pages.
10. Children
The Site reviews a TV-14-rated film and is directed at general audiences. We do not knowingly collect personal data from children under thirteen without parental consent. If you believe a child has contacted us, notify us and we will delete unnecessary data.
Parents choosing whether minors should read true-crime material should use their own judgement; our review discusses murder and divorce explicitly but does not include graphic imagery on this Site.
11. Links to other sites
Our review links to Amazon for purchasing Million Dollar Murder. External sites have separate privacy practices. Read their policies before creating accounts or completing purchases.
Google Maps on our contact page is another third-party surface. Loading the map may transfer your IP address and device information to Google even if you do not interact with the pin. If you prefer not to load Google resources, read our address in plain text on this Site and use your preferred map application separately.
12. Changes to this policy
We may update this Privacy Policy to reflect legal, technical, or business changes. The "Last updated" date at the top will change. Material changes may be noted on the Site homepage for a reasonable period. Continued use after updates constitutes acceptance where permitted by law.
13. Marketing and communications
We do not send bulk newsletters from this Site. If you email us, we may reply once or maintain a thread for your enquiry. We will not add you to a marketing list without explicit opt-in. If that practice changes, we will request consent separately and document it here.
14. Automated decision-making
We do not use personal data for solely automated decisions that produce legal or similarly significant effects about individuals. Editorial scores on the Site are written by humans, not generated from your browsing behaviour.
15. Data breach notification
If a personal data breach likely to result in significant harm comes to our attention, we will assess promptly, mitigate where possible, and notify affected individuals and the PDPC when required by the PDPA. Given the limited data we collect, our breach scenarios focus on unauthorised access to email archives or hosting logs.
16. Records for legal and tax purposes
We may retain business correspondence and invoices related to hosting or professional services as ordinary company records. Those records may contain incidental personal data (such as supplier contact names) and are kept according to our document retention schedule, separate from Site analytics.
17. Your responsibilities
When you contact us, provide accurate information and do not include unrelated third parties’ personal data unless you have authority to share it. If you forward someone else’s complaint, obtain their permission or redact identifiers that are not needed for us to respond.
18. Contact
Watch And Review It, 116 Middle Road, #08-01 ICB Enterprise House, Singapore 188972 · [email protected] · +65 6706 3841.