Personal Data Protection Policy

Personal Data Protection Policy

1. Purpose, scope, and users

Straits Alliance Pte Ltd, hereinafter referred to as the “Company”, strives to comply with applicable laws and regulations related to the Personal Data Protection Act (PDPA) in Singapore where the Company operates. This policy sets forth the basic principles by which the Company collects, uses and disclosures personal data of consumers, customers, suppliers, business partners, employees, and other individuals.

This policy applies to the Company and its directly or indirectly controlled owned subsidiaries conducting business within Singapore or processing the personal data of individuals within Singapore.

2. Overview

The PDPA contains two provisions that cover data protection and the Do Not Call registry, which the Company are required to comply with.

The data protection provision deals with the following matters:

• Having reasonable purposes, notifying purposes, and obtaining consent for the collection, use or disclosure of personal data.

• Allowing individuals to access and correct their personal data.

• Taking care of personal data, protecting personal data, and not retaining personal data if no longer needed

• Having policies and practices to comply with the PDPA.

The PDPA’s Do Not Call Registry provisions deal with the establishment of Singapore’s national Do Not Call Registry and the obligations of the Company relating to the sending of marketing messages to Singapore telephone numbers.

3. Definitions

The following definitions of terms used in this document are drawn from section 2(1) of the PDPA:

a. Individual – A natural person, whether living or deceased. The term “natural person” refers to a human being. Obligations relating to the disclosure and protection of personal data will apply in respect of the personal data about an Individual who has been dead 10 years or less.

b. Personal Data – Any information relating to an identified or identifiable Individual who can be identified, directly or indirectly, by reference to an identifier such as a full name, identification number (e.g., NRIC, FIN), passport number, personal mobile number, facial image of an individual, voice of an individual, fingerprint, iris image or DNA profile.

c. Organisation – Any individual, company, association, or body of persons, corporate or unincorporated whether formed or recognised under the law of Singapore; or resident, or having an office or a place of business, in Singapore.

d. Data Intermediary – An organisation that processes personal data on behalf of another organisation but does not include an employee of that other organisation.

e. Collection, Use and Disclosure – In general, the terms “collection”, “use” and “disclosure” should be understood to have the following meanings:

i. Collection refers to any act or set of acts through which an organisation obtains control over or possession of personal data.

ii. Use refers to any act or set of acts by which an organisation employs personal data. A particular use of personal data may occasionally involve collection or disclosure that is necessarily part of the use.

iii. Disclosure refers to any act or set of acts by which an organisation discloses, transfers, or otherwise makes available personal data that is under its control or in its possession to any other organisation.

f. Purposes – The term “purpose” refers to activities which an organisation may intend to undertake. When specifying its purposes relating to personal data, an organisation is not required to specify every activity which it may undertake, but its objectives or reasons relating to personal data.

g. Reasonableness – An organisation shall, in meeting its responsibilities under the PDPA, consider what a reasonable person would consider appropriate in the circumstances.

4. Obligations regarding Data Protection

The data protection provisions outline the basic responsibilities for organisations handling personal data. The Company are required to comply with if they undertake activities relating to the collection, use or disclosure of personal data.

a. Consent – The Company must obtain the consent of the individual before collecting, using, or disclosing his personal data for a purpose.

b. Purpose Limitation – The Company may collect, use, or disclose personal data about an individual only for purposes that a reasonable person would consider appropriate in the circumstances and, if applicable, have been notified to the individual concerned.

c. Notification – The Company must notify the individual of the purpose(s) for which it intends to collect, use, or disclose the individual’s personal data on or before such collection, use or disclosure of the personal data.

d. Access and Correction – The Company must, upon request, provide an individual with his or her personal data in the possession or under the control of the Company and information about the ways in which the personal data may have been used or disclosed during the past year; and correct an error or omission in an individual’s personal data that is in the possession or under the control of The Company.

e. Accuracy – The Company must make a reasonable effort to ensure that personal data collected by or on behalf of the Company is accurate and complete if the personal data is likely to be used by the Company to make a decision that affects the individual concerned or disclosed by the Company to another organisation.

f. Protection – The Company must protect personal data in its possession or under its control by making reasonable security arrangements to prevent unauthorised access, collection, use, disclosure, copying, modification, disposal, or similar risks.

g. Retention Limitation – The Company must cease to retain documents containing personal data or remove how the personal data can be associated with individuals as soon as it is reasonable to assume that the purpose for which the personal data was collected is no longer being served by retention of the personal data and is no longer necessary for legal or business purposes.

h. Transfer Limitation – The Company must not transfer personal data to a country or territory outside Singapore except in accordance with the requirements prescribed under the PDPA.

i. Accountability – The Company must implement the necessary policies and procedures to meet its obligations under the PDPA and shall make information about its policies and procedures publicly available.

5. Data protection in Business Activities

5.1. Notices to Individuals

At the time of collection or before collecting personal data for any kind of processing activities including but not limited to selling products, services, or marketing activities, the Data Protection Officer is responsible to properly inform Individuals of the following:

a. The purposes for the collection, use and disclosure of his/her personal data, on or before collecting the personal data.

b. Any purpose for use or disclosure of personal data which has not been informed under subparagraph (a) before such use or disclosure of personal data for that purpose.

This information is provided through the Privacy Notice. The Privacy Notice may be provided to individuals as required, in the form of a document or on the Company’s website.

5.2. Obtaining Consent

Whenever personal data processing is based on the Individual’s consent, or other lawful grounds, the individuals are given options to provide the consent and ensure that their consent can be withdrawn at any time.

Personal data must only be processed for the purpose for which they were originally collected. If the Company wants to process collected personal data for another purpose, the Company must seek the consent of Individuals in clear and concise writing. Any such request should include the original purpose for which data was collected, and the new, or additional, purpose(s). The request must also include the reason for the change in purpose(s).

The Company strives to collect the least amount of personal data possible. Personal data should be collected, used, and disclosed relevant for the purposes, and only for purposes that are reasonable (e.g., what a reasonable person would consider appropriate in the circumstances).

5.3. Access and correction

When acting as an Organisation, rather than a Data Intermediary, individuals are given a reasonable mechanism to enable them to access their personal data, and must allow them to update, rectify, erase, or transmit their personal data, if appropriate or required by law.

Personal data must be accurate and, where necessary, kept up to date. Reasonable steps must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased, or rectified in a timely manner.

5.4. Protection

The Company will make reasonable security arrangements to protect personal data in its possession or under its control to prevent unauthorised access, collection, use, disclosure, copying, modification, disposal, or similar risks.

5.5. Retention limitation

Personal data must be kept for no longer than is necessary for the purposes for which the personal data are processed and/or as required by law. In compliance with ACRA regulatory requirement, personal data will be kept for at least 5 years after the business relationship ends.

5.6. Accountability

The Company designates one or more individuals to be responsible for ensuring the Company’s compliance with the PDPA, developing, and implementing policies and practices and making information about data protection policies and practices available.

6. Do Not Call Provisions

The Do Not Call Registry comprise of three separate registers kept and maintained by the Commission under section 39 of the PDPA which cover telephone calls, text messages and faxes. Individuals will be able to register their Singapore telephone number(s) on one or more Do Not Call Registers depending on their preferences in relation to receiving marketing messages through telephone calls, text messages or faxes.

7. Disclosure to third parties

Whenever the Company uses a third-party supplier or business partner to process personal data on its behalf, the Data Protection Officer must ensure that this processor will provide measures to safeguard personal data that are appropriate to the associated risks.

8. Response to personal data breach incidents

When the Company learns of a suspected or actual personal data breach, the Data Protection Officer will perform an internal investigation and take appropriate remedial measures in a timely manner.

9. Conflicts of law

This policy is intended to comply with the laws and regulations in Singapore in which Straits Alliance Pte Ltd operates. In the event of any conflict between this policy and applicable laws and regulations, the latter shall prevail.

10. Validity and Document Management

The owner of this document is the Data Protection Officer who check and, if necessary, update the document at least once a year.

The document is valid as of 01 Jun 2026.