Controller Identity and Data Protection Officer
Who the data controller legally is, its Singapore UEN, and the designated Data Protection Officer's business contact — as required by the PDPA and GDPR.
Last updated: 2026-07-13 · Effective: 2026-07-13
The controller
HEOSSI (PTE.) LTD is the entity behind QNSI and is the data controller for personal data it collects about visitors, account holders, and prospective customers. For Customer Data that you place into the platform, HEOSSI (PTE.) LTD acts as a processor on your behalf under the Data Processing Addendum — the two roles are distinct and are governed by different documents.
Every field below can be independently verified against the Singapore companies registry (ACRA) using the UEN. We publish the UEN precisely so that a buyer's procurement or compliance team can confirm we are a real, live, registered company without taking our word for it.
| Field | Value |
|---|---|
| Legal entity | HEOSSI (PTE.) LTD |
| Singapore UEN | 202532790K |
| Incorporated | 2025-07-28 (Singapore) |
| Data Protection Officer | Christopher M. Frost, Founder & CTO |
| DPO contact | qnsi-legal@heossi.com |
Data Protection Officer
Under section 11(3) of Singapore's Personal Data Protection Act, an organisation must designate at least one individual as its Data Protection Officer and make that person's business contact information available to the public. HEOSSI (PTE.) LTD designates Christopher M. Frost (Founder & CTO).
The DPO is responsible for ensuring compliance with the PDPA, for handling access and correction requests, for data-protection queries and complaints, and for the breach-assessment and notification duties described in the Incident Response policy.
Business contact: qnsi-legal@heossi.com. This is a monitored business address, not a personal one. Data-protection queries may also be sent to qnsi-legal@heossi.com.
A note on our size, stated plainly
HEOSSI (PTE.) LTD is an early-stage company and the DPO is also its founder and director. We would rather say that than imply a data-protection department that does not exist. It changes nothing about the obligations — the PDPA applies to a company of one exactly as it applies to a company of ten thousand, and a designated DPO who is the CEO is a valid designation, not a workaround.
What it does mean in practice: requests reach a named human who has the authority to act on them, and there is no queue to hide behind. As the company grows, this page changes; the obligation does not.
Exercising your rights
To request access to, or correction of, personal data we hold about you — or to withdraw consent — write to qnsi-legal@heossi.com. We will respond within the timeframes required by the applicable law (the PDPA, and the GDPR where it applies to you), and we will tell you if we need longer and why.
If you are dissatisfied with our response, you may lodge a complaint with the Personal Data Protection Commission (PDPC) in Singapore, or with your local supervisory authority if you are in the EU/EEA or the UK.