DATA PROTECTION POLICY.
How TSI manages the collection, use, disclosure and protection of personal data in accordance with Singapore’s Personal Data Protection Act.
“Personal Data” is defined under the PDPA to mean data, whether true or not, about an individual who can be identified from that data, or from that data and other information to which an organization has or is likely to have access. Common examples of personal data could include names, identification numbers, contact information, medical records, photographs and video images.
The purpose of this Data Protection Policy is to inform you of how the Company manages Personal Data Please take a moment to read this Data Protection Policy so that you know and understand the purposes for which we collect, use and disclose your Personal Data.
We will collect your personal data in accordance with the PDPA. In general, before we collect any personal data from you, we will notify you of the purposes for which your personal data may be collected, used and/or disclosed, as well as obtain your consent for the collection, use and/or disclosure of your personal data for the intended purposes.
1. Collection of Personal Data
Generally, we collect Personal Data in the following ways:
- when you enter into any agreement or provide other
- when you interact with our employees, for example, via
- when you use our electronic services, or interact with us
- when your images are captured by us via CCTV cameras while
- when you submit your Personal Data to us for any other
If you provide us with any Personal Data relating to a third party (e.g. information of your spouse, children, parents, and/or employees), by submitting such information to us, you represent and warrant to us that you have obtained the consent of the third party to provide us with their Personal Data for the respective purposes.
You should ensure that all Personal Data submitted to us is complete, accurate, true and correct. Failure on your part to do so may result in our inability to provide you with the products and services you have requested.
2. Purposes for the Collection, Use and Disclosure of Your Personal Data
Generally, the Company collects, uses and discloses your Personal Data for the following purposes:
- responding to your queries, feedback, complaints and
- verifying your identity;
- managing the administrative and business operations of our
- facilitating business asset transactions (which may extend
- matching any Personal Data held which relates to you for any
- preventing, detecting and investigating crime and analysing
- facilities management (including but not limited to
- managing the safety and security of our premises and
- in connection with any claims, actions or proceedings
- conducting investigations relating to disputes, billing or
- meeting or complying with any applicable rules, laws,
- creating and maintaining your profile in our system
- providing customer service and support;
- facilitating your use of our online portals;
- taking photograph(s) and/or video(s) of you for (i) internal
- any other purpose reasonably related to the aforesaid.
3. Disclosure of Personal Data
The Company will take reasonable steps to protect your Personal Data against unauthorised disclosure. Subject to the provisions of any applicable law, your Personal Data may be disclosed, for the purposes listed above (where applicable), to the following entities or parties, whether they are located overseas or in Singapore:
- The Company’s related corporations;
- companies providing services related to insurance to the
- our merchant partners including other banks;
- external banks, billing organisations and their respective
- any business partner, investor, assignee or transferee
- our professional advisers such as consultants, auditors
- relevant government ministries, regulators, statutory
- any other party to whom you authorise us to disclose your
4. Limitations
Generally, we will not use your personal data for reasons not specified in the Purpose of Use unless:
- it is required by law or governmental or juridical
- it is necessary to establish and safeguard a legal
- it is necessary to prepare, negotiate and perform a
- it is necessary to prevent illegal activities, e.g. in
5. Obtaining Consent
We assure that all personal information collected shall be used or disclosed only for the purposes for which it was collected. As far as possible we will not collect more personal data than is necessary for the stated purpose.
- Third-Party Consent
If you have a one-on-one meeting with us or do a transaction with us, on behalf of another individual, you must first obtain consent from that individual in order for us to collect, use or disclose his / her personal data.
- Deemed Consent
Under certain circumstances, we may assume deemed consent from you when you voluntarily provide your personal data for the stated purpose e.g. when you register your enquiries with us through our telephone numbers, emails, fax, or apply for a job with us using our job application forms.
- Without Consent
Under certain circumstances, we may collect, use and / or disclose personal data about you without your consent for example, so that we can comply with our statutory obligations or where personal data is publicly available.
6. Limit Processing of Personal Data
Withdrawal of Consent
If you have given us consent to collect, use, disclose and process personal data about you, you may withdraw that consent at any time. You should give us reasonable advance notice of at least 10 working days or more to process your withdrawal of consent. If you withdraw your consent, you agree that you are aware of the likely consequences, e.g. without your contact information, we may not be able to inform you of further updates or that the quality of our services may be impacted. Your request for withdrawal of consent can take the form of an email or letter to us, for the attention of the Data Protection Officer.
While we respect your decision to withdraw your consent, we are not liable for any consequences resulting from the withdrawal of consent. Please also be aware that withdrawal of consent does not affect our right to continue to collect, use and disclose personal data where such collection, use and disclose without consent is permitted or required under applicable laws.
7. Accessing And Updating Personal Data
If you wish to access your personal data with us, based on reasonable grounds, you may send a written request to us. Upon your request, we will provide information on use / disclosure of your personal data of the past one year before the date of your request based on intent. We will try respond to your request as soon as reasonably possible within 30 working days. It is important that access to your personal data will not infringe on the privacy of others.
You may also ask us to correct an error or omission in the personal data we hold about you. Unless we are satisfied on reasonable grounds that a correction should not be made, we will correct the personal data as soon as practicable. When you make any such request, we may need to verify your identity e.g. by checking your identity card number or other legal identification document.
8. Accuracy Of Personal Data
We generally rely on personal data provided by you (or your authorized representative). Where possible, we will validate data provided using generally accepted practices and guidelines. This includes the requests to see original documentation before we may use the Personal Identifiers and / or proof of address.
In order to ensure that your personal data is current, complete and accurate, please update us if there are any changes to your personal data.
9. Protection Of Personal Data
We make reasonable security arrangements to protect personal data about you that is in our possession or under our control to prevent unauthorized access, collection, use, disclosure, copying, modification, disposal or similar risks. All our employees will take reasonable and appropriate measures to maintain the confidentiality and integrity of your personal data and will only share your data with authorized persons on a ‘need to know’ basis. Entities that provide services to us to process and maintain your personal data on our behalf will be bound by contractual data security arrangements we have with them.
10. Retention Of Personal Data
We will not retain any documents containing personal data about you as soon as it is reasonable to assume that the purpose for which we collected that personal data is no longer being served by retention of it and retention is no longer necessary for legal or business purposes. Certain retention periods are based on statutory or regulatory requirements.
11. Compliance With Laws
Where required to do so by law, we will disclose personal data about you to the relevant authorities or to law enforcement agencies.
12. Links To Other Sites
Our website may contain links to other websites that are not operated by us. If you click on a third-party link, you will be directed to that third party’s website. It is important that you review the Policy of every site you visit. We have no control over and are unable to assume any responsibility for the content, privacy policies or practices of any third party sites or services.
13. Transfer Of Personal Data
If there is a need for us to transfer your personal data to another country, we will ensure that the standard of data protection in the recipient country is comparable to that of Singapore’s PDPA. If this is not so, we will enter into a contractual agreement with the receiving party to accord similar levels of data protection as that in Singapore.
14. Do-Not-Call (Dnc) Provisions
Before we make any “cold calls” in telemarketing activities, we will check the DNC Registry and our internal blacklist before we make the phone calls, send SMSs or send faxes to the individual, unless that individual has given his/her clear and unambiguous consent. The blacklist refers to phone numbers belonging to those individuals who have withdrawn their consent.
15. Changes To Policy
We may update our Policy from time to time to maintain compliance with applicable laws and regulations. Please revisit this page periodically for any changes. Changes to this Policy are effective when they are posted on this page.
16. Transparency
Our policy is accessible on our website. You can contact the Data Protection Officer via email should you need any clarification of our Policy.
17. Contacting Us – Feedback, Withdrawal of Consent, Access and Correction of your Personal Data
If you:
- have any questions or feedback relating to your Personal
- would like to withdraw your consent to any use of your
- would like to obtain access and make corrections to your
You can contact our Data Protection Officer, at
Email: dpo@tsi.tech
Telephone: (+65) 6272 9924
If you withdraw your consent to any or all use of your Personal Data, depending on the nature of your request, our Organization may not be in a position to administer any contractual relationship in place, which in turn may also result in the termination of any agreements with our Organization, and your being in breach of your contractual obligations or undertakings. Our Organization legal rights and remedies in such event are expressly reserved.
18. Governing Law
This Data Protection Policy, your browsing of our websites, and use of our applications and/or digital services shall be governed in all respects by the laws of Singapore.
