Skip to content

Software and web development in Singapore

An Indian engineering team working with businesses in Singapore. The same engineers, a written scope, and quotes in SGD.

Working hours

Our day runs 09:00 to 18:00 India time, which is 11:30 to 20:30 in Singapore, so from late morning onwards we are on the same working day, and anything you raise first thing is picked up by 11:30.

Quoted in SGD

Quotes exclude the 9% GST in Singapore, shown separately on the invoice.

Data protection

Work for this market is scoped against the Personal Data Protection Act 2012 (PDPA), agreed before development starts rather than retrofitted afterwards.

The contract, and the unusual fact that it can be enforced

We are happy to contract under Singapore law with the Singapore courts, which is what a Singapore buyer will reasonably want. What is different here from almost every other market we work in is what the clause is worth. Singapore is a reciprocating territory under section 44A of India's Civil Procedure Code, with the High Court of Singapore named as the superior court, so a decree of that court can be filed in an Indian district court and executed as if it were the district court's own. A US or Canadian judgment cannot do that and has to be brought again as a fresh suit. If your counsel prefers arbitration, the Singapore International Arbitration Centre is a natural seat and both countries are parties to the New York Convention, so an award travels too. We say this not because we expect either of us to need it, but because a buyer weighing an overseas supplier is entitled to know whether the paper means anything, and here it does.

Intellectual property transfers to you on final payment, in writing, and the repository lives in your GitHub or Bitbucket organisation from the first commit rather than being handed over at the end. Domain, hosting and every third-party account are registered to your company, not to us, and no licence comes back to us for anything written for you. What carries the weight day to day is commercial rather than legal: payment is staged against milestones you have accepted, so what you have exposed at any moment is a milestone rather than a project. The GST position stated on the invoice, a written scope with one fixed number against it, and the names of the people doing the work are the three things a Singapore procurement team asks for first, and all three are in the proposal before anyone asks.

GST, InvoiceNow, and how the money moves

GST in Singapore is 9 per cent since 1 January 2024 and none of it appears on our invoice, because we are outside the country. What happens next depends on you rather than on us. IRAS's published position is that a GST-registered business making only taxable supplies is not impacted by reverse charge on imported services, so the figure on our invoice is the figure that leaves your account. A partially exempt business, or one with non-business receipts, accounts for GST on the imported services in its own return under reverse charge, which is typically neutral to the extent the input tax is recoverable. A business that is not GST-registered should check with its accountant, because an exempt business importing more than S$1 million of services in a year can be required to register. We state the position on the invoice so nobody is guessing, and we would rather your accountant confirmed your treatment before the first one than after the last.

InvoiceNow is the part of Singapore invoicing most overseas suppliers have never heard of, and it matters more for what we build than for how we bill. It is the national e-invoicing network on the Peppol standard, and IRAS is phasing in a requirement for GST-registered businesses to transmit invoice data through it: newly incorporated companies that register voluntarily since 1 November 2025, all new voluntary registrants from 1 April 2026, and every GST-registered business progressively between April 2028 and April 2031. If the system we are building issues invoices, that is a data format and a transmission step to design in now rather than a migration in 2028, and it is why our Singapore billing builds produce Peppol-shaped invoice records from the start. On our own invoices to you, we quote in Singapore dollars and hold the figure for the project, thirty-day terms are the usual arrangement, and payment arrives by bank transfer or through Wise. PayNow is a domestic rail and does not reach an Indian account, so we do not offer it.

The PDPA in the code rather than in the policy

Singapore has one national data protection statute, which makes it simpler to design against than the American patchwork and stricter in a few places than teams expect. The Personal Data Protection Act 2012, substantially amended in 2020, sets out obligations that each land somewhere specific in a build. Consent and purpose limitation decide what a form may collect and what the schema may hold. Notification decides what the form says. Access and correction are endpoints with a review queue, not a request someone handles by hand. Retention limitation means a scheduled job that actually deletes, and accuracy means validation at the point of entry rather than a cleanup later. Accountability means the organisation can show its policies, and appointing a Data Protection Officer is your obligation as the organisation, which we will not pretend to discharge for you.

Two obligations shape the architecture more than the rest. The transfer limitation obligation applies because processing happens in India: personal data may leave Singapore only where a comparable standard of protection is ensured, and in practice that is done by contract, so the processor agreement we sign sets out the protection, the sub-processors, and the return or deletion of data at the end. Where the data itself needs to stay in Singapore, every major cloud has a Singapore region and the hosting goes there, with the data path documented well enough that your DPO can follow it without a call. The second is mandatory breach notification, in force since 2021: once an organisation determines that a breach is notifiable, which means one likely to result in significant harm to the individuals or one affecting 500 or more of them, it has three calendar days to notify the PDPC, and affected individuals are told as soon as practicable. Three days is enough time to send a notification and not enough time to work out what was in a system that never logged it, so the logging that can answer what left, when, and whose it was exists from the first release rather than the first incident.

If the product sends marketing messages, two further regimes apply and both are built as features rather than left to whoever configures the messaging tool later. The Do Not Call provisions of the PDPA mean a marketing SMS or call to a Singapore number checks the registry unless there is clear and unambiguous consent on record, so the consent record and the registry check both live in the product. Unsolicited commercial email and messages fall under the Spam Control Act, with its labelling and unsubscribe requirements. Transactional messages are kept separate from marketing ones in the code, because conflating them is the most common way a team sends something it should not have.

Grants, and the honest answer about them

Almost every Singapore SME asks whether a government grant can pay for the work, and the answer for us is mostly no, which we would rather say here than in a proposal. The Productivity Solutions Grant funds pre-scoped packages from vendors Enterprise Singapore has pre-approved, for companies registered in Singapore, and the solution has to be one on the published list. A custom build from an overseas team is not that shape, and a vendor who tells you otherwise is describing a grant that does not exist. The Enterprise Development Grant is a different instrument, assessed project by project against its own criteria for capability building and market access, and whether a project like yours qualifies is a question for Enterprise Singapore or your grant consultant rather than for us. Ask it before the scope is written, because a budget that assumed a grant and did not get one is the most common way a Singapore project stalls in week three.

What a week looks like two and a half hours apart

This is the best working-day fit of any market we serve, and it is worth being precise about what that means rather than calling it overlap. India is two and a half hours behind Singapore and neither country observes daylight saving, so the arithmetic never changes: our day of nine to six India time is half past eleven in the morning to half past eight in the evening for you. From late morning onwards we are on the same working day, and the whole of your afternoon is live time. A standing call fits anywhere between half past eleven and six on your clock, a question asked at noon is answered before you leave, and pairing on a difficult bug over a screen share is an ordinary thing to do rather than a scheduling exercise.

The cost is the first two and a half hours of your morning, and we would rather name it than hide it. Something raised at nine is picked up at half past eleven, not at nine. For most teams that is a coffee's worth of latency; for a team that starts its day with a stand-up and needs a decision out of it, the fix is to hold the stand-up after half past eleven or to leave the decision in writing with a default chosen, which is what we do for every open question anyway. The written handover we run for markets with no overlap at all still happens here, at the end of our day, which is half past eight in your evening: what moved, what is next, what we assumed where we could not ask. It costs nothing and it means a colleague of yours who was in a different meeting can read what happened without asking anyone.

Services available in Singapore

Questions Singapore clients ask

How does GST work if you are based in India?

No GST is charged on our invoice, and the invoice says so. Whether you account for it under reverse charge depends on your input tax position: IRAS's guidance is that a GST-registered business making only taxable supplies is not impacted, a partially exempt business or one with non-business receipts accounts for GST on imported services in its own return, and a business that is not registered should ask its accountant, because an exempt business importing more than S$1 million of services in a year can be required to register. We would rather your accountant confirmed your position before the first invoice than reconciled it at year end.

Are you compliant with the PDPA?

We build to it rather than claiming a certificate. The consent, purpose limitation and notification obligations shape the forms and the data model; retention limitation means records are deleted on a schedule rather than kept indefinitely; access and correction requests are features with a queue behind them rather than a manual database job. Processing happens in India, so the transfer limitation obligation applies, and the processor agreement we sign sets out the comparable standard of protection the Act asks for. The obligation to design for early is breach notification: an organisation has three calendar days from determining a breach is notifiable, which means one likely to cause significant harm or one affecting 500 or more people, to tell the PDPC, and answering what was in the breach is only possible if the logging existed beforehand. Appointing a Data Protection Officer is your obligation rather than ours, and we will say so if a design choice would make that person's job harder.

Can we use a PSG or EDG grant to pay for this?

Not PSG. The Productivity Solutions Grant funds pre-scoped packages from pre-approved vendors for Singapore-registered companies, and a custom build from an overseas team is not that shape, so we will not pretend it is. The Enterprise Development Grant is assessed project by project against its own criteria, and whether a build like yours qualifies is a question for Enterprise Singapore or your grant consultant to answer before the scope is written rather than after a budget has assumed it.

We are regulated by MAS. Can you meet the outsourcing requirements?

We can supply what a due-diligence pack asks for, accept audit and access rights in the contract, and name every sub-processor that touches your data. What we will also tell you in the first conversation is what we do not hold: we are not SOC 2 or ISO 27001 certified, and our security page says so in those words. Whether an engagement with us is a material outsourcing arrangement under the MAS guidelines, and what that requires of you, is your compliance team's determination, and it changes the contract before it changes the code, so it belongs in week one.

Other markets we work in

Working with Singapore

Tell us what you are building in Singapore

Send the scope, or just the problem. You get a written scope and a fixed SGD quote back within 24 hours, from the engineers who would do the work.

Get a quote in SGD