DATA PROTECTION AND PRIVACY POLICY
Last updated: May, 2022
1.1
Sertopia Global Limited, a private company limited by shares (“Sertopia” or “we” or “our” or “us“) recognizes and undertakes its responsibilities under applicable privacy laws. We recognize the importance of the personal data you have entrusted to us and believe that it is our responsibility and commitment to properly manage, protect and process your personal data.
1.2
Please read this Personal Data Protection and Privacy Policy (“Privacy Policy“) to understand what personal data is collected or processed by us, and for what purposes it is used for, how we handle, collect, use, disclose and process personal data about you that you give us, or that is in our possession.
1.3
Without prejudice to any of the foregoing, if you provide the personal data of any other third party to us, you warrant you are duly authorized to disclose such third party’s personal data to us and the purposes which you disclosed to the third party on collection of his personal data permit us to use this personal data as set out in this Privacy Policy.
2.1
“data” means any representation of information (including an expression of opinion) in any document, and includes a personal identifier.
2.2
“data processor” means a person who (i) processes personal data on behalf of another person; and (ii) does not process the data for any of the person’s own purposes.
2.3
“personal data” means any data (i) relating directly or indirectly to a living individual; (ii) from which it is practicable for the identity of the individual to be directly or indirectly ascertained; and (iii) which are in a form in which access to or processing of the data is practicable. Personal data can be factual (such as a name, address or date of birth) or it can be an opinion (such as a product review). It can include an e-mail address, particularly if used in conjunction with other identifiers. It is important that the information has the data subject as its focus and affects the individual’s privacy in some way.
2.4
“processing“, in relation to personal data, includes amending, augmenting, deleting or rearranging the data, whether by automated means or otherwise.
3.1
We collect information about you when you register a Sertopia account with us (“Account”) and use our website(s), website/IT portal(s)/mobile application(s), forms, surveys, and other channels and throughout other interactions, communications and services (“Services”) you have with us.
3.2
Personal data which we may collect include:
Personal data collected in this paragraph 3.2 above are mandatory. We may not be able to provide you with our Services, or the level of our Services may be adversely affected if you do not provide the personal data we consider mandatory.
3.3
We may collect and store certain information automatically when you visit our website(s) or use our website(s)/IT portal(s)/mobile application(s). Examples include:
3.4
We may receive information about you from third parties if you use any websites or social media platforms operated by third parties (for example, Facebook, Instagram, Twitter etc.) and, if such functionality is available, you have chosen to link your profile on our website(s) or website/IT portal(s)/mobile application(s) with your profile on those other websites or social media platforms.
3.5
We only collect personal data that we reasonably need for use in connection with the purposes stated in paragraph 5 of this Privacy Policy in order to provide our Services. We do not collect personal data that is unnecessary or excessive.
3.6
In respect of voluntary personal data provided to us, we:
4.1
A cookie is a small file of letters and numbers that we store on your browser or the hard drive of your computer or device.
4.2
We use cookies to:
4.3
You can block or deactivate cookies in your browser settings.
4.4
We use log-in cookies to remember you when you have logged in for a seamless experience.
4.5
We use session cookies to track your movements from page to page and in order to store your selected inputs so you are not constantly asked for the same information.
4.6
By continuing to use our website(s) or website/IT portal(s)/mobile application(s), you are agreeing to the use of cookies on the site as outlined above. However, please note that we have no control over the cookies used by third parties.
5.1
We will/may collect, use, disclose and process your personal data for one or more of the following purposes:
5.2
We may need to disclose your personal data to third parties, including payment service providers, or data processors, as such third parties would be processing or using your personal data in connection with one or more of the above Purposes. You hereby acknowledge, agree and consent that we are permitted to disclose your personal data to such third parties for one or more of the above Purposes and for the said third parties to subsequently collect, use, disclose or process your personal data for one or more of the above Purposes. Such third parties include:
5.3
We will not collect, use, disclose or process your personal data for other purposes that do not appear above unless we have your prescribed consent.
5.4
We may also collect from sources other than yourself, personal data about you, for one or more of the above Purposes, and thereafter using, disclosing and/or processing such personal data for one or more of the above Purposes. We may combine information we receive from other sources with information you give to us and information we collect about you. We may use this information and the combined information for the Purposes set out above (depending on the types of information we receive).
5.5
We may share your personal data with anyone other than as described in paragraph 5.2 of this Privacy Policy if we notify you and receive your consent beforehand.
6.1
Security of your personal data is important to us. We take appropriate action to protect personal data from loss, misuse, unauthorized access or disclosure, alteration or destruction using the same safeguards as we use for our own proprietary information. All information you provide to us is stored on secure servers and any payment transactions will be encrypted using SSL technology. Where we have given you (or where you have chosen) a password which enables you to access certain parts of our website(s) or website/IT portal(s)/mobile application(s), you are responsible for keeping this password confidential. We ask you not to share a password with anyone.
6.2
We will put in place measures such that your personal data in our possession or under our control is destroyed and anonymized as soon as it is reasonable to assume that (a) the purpose for which that personal data was collected is no longer being served by the retention of such personal data; and (b) retention is no longer necessary for any other legal or business purposes.
6.3
If we outsource and entrust your personal data with data processors, we will use contractual and other means to monitor the data processors’ compliance with this Privacy Policy.
6.4
The transmission of information through the internet is not completely secure. Although we use security measures to secure your personal data, we cannot guarantee the security of your personal data transmitted through the internet and any transmission is at your own risk.
7.1
We will keep your personal data for as long as your Account registered with us is being accessed.
7.2
If your Account registered with us has not been accessed over a period of twelve months or we have closed your Account (“End Date”), your personal data will be retained by us for five years after the End Date. We may retain your personal data for a longer period if it is necessary for us to do so to comply with our contractual or legal obligations, or you have consented to our continued retention of it.
7.3
At the end of the retention period, we will ensure that your personal data, all app-related data and Account-related information will be deleted. For any physical documents containing your personal data, the documents will be shredded or otherwise destroyed by means that ensure the confidential and secure destruction of the documents.
7.4
We will ensure that our data processor who we transfer your personal data to in compliance to this Privacy Policy only retain your personal data for as long as is necessary for the fulfillment of the Purposes for which your personal data has been disclosed to them and will delete personal data held if personal data is no longer required for those Purposes unless any deletion is prohibited under law or it is in the public interest for the personal data to not be deleted.
8.1
You have the right to access and/or correct any personal data that we hold about you, subject to the requirements of the applicable laws. If you would like to request for a copy of your personal data being held by us (such right being subject to applicable exemptions), or to update and correct the personal data which you have previously provided to us, please email or write to our Data Protection Officer.
8.2
We will need enough information from you in order to ascertain your identity as well as the nature of your request, so as to be able to deal with your request. We reserve the right, or may, charge a reasonable fee for the processing of any data access request.
8.3
For a request to access personal data, once we have sufficient information from you to deal with the request, we will seek to provide you with the relevant personal data within 40 days. Where we are unable to respond to you within the said 40 days, we will notify you of the soonest possible time within which we can provide you with the information requested.
Our website(s), website/IT portal(s)/mobile application(s) and other digital and telecommunication channels may contain links to other sites that are operated by third party companies with different privacy practices. You should remain alert and read the privacy statements of other sites. We have no control over personal data that you submit to or receive from these third parties. We take no responsibility or liability for the content and activities of these third party linked websites or their products and services.
10.1
From time to time, we may conduct direct marketing of the Services through email and/or other form of communication to you. We intend to use your personal data for direct marketing carried out by us or one of our business partners or third party merchants.
10.2
The type of personal data we use for direct marketing purposes is:
10.3
The direct marketing activities we conduct using your personal data are:
10.4
If you do not expressly indicate your consent, then we may not use the types of personal data for the direct marketing activities described in this paragraph 10 of this Privacy Policy.
10.5
You may request us to cease using your personal data for direct marketing purposes at any time by emailing or writing to our Data Protection Officer, or if applicable, using the unsubscribe facility contained in the marketing message.
11.1
We may occasionally change all or part of this Privacy Policy.
11.2
Any changes will be effective immediately upon our posting of the updated Privacy Policy.
11.3
If we make any changes to this Privacy Policy, we will notify you of the changes through our website, applications or through other means such as e-mail.
11.4
If we make changes to the purposes for collecting your personal data and who we may share your personal data with or how we may use your personal data, we will notify you in advance of such changes through our applications, website or through other means such as e-mail and request your consent.
11.5
If you revoke your consent to our amendment under paragraph 11.4 above, we may not be able to provide you access to our applications or provide our Services to you.
12.1
If you have any complaint or grievance regarding about how we are handling your personal data or about how we are complying with the applicable privacy law, we welcome you to contact us with your complaint or grievance by writing to our Data Protection Officer.
12.2
Where you are sending an email in which you are submitting a complaint, your indication at the subject header that it is a privacy complaint would assist us in attending to your complaint speedily by passing it on to the relevant staff in our organization to handle. For example, you could insert the subject header as “Privacy Complaint”.
12.3
We will certainly strive to deal with any complaint or grievance that you may have speedily and fairly.
If applicable personal data privacy laws permit an organization such as us to collect, use or disclose your personal data without your consent, such permission granted by the law shall continue to apply.
For any enquiries on our Privacy Policy, please write to our Data Protection Officer. Our Data Protection Officer can be reached at info@sertopia.net.