PRIVACY AND DATA PROTECTION POLICY
1.2 “Personal Data” or “personal data” means data, whether true or not, about an individual who can be identified from that data, or from that data and other information to which an organisation has or is likely to have access. Common examples of personal data could include name, email address and phone number.
WHEN WILL EMATIC COLLECT PERSONAL DATA?
2.1 We will/may collect personal data about you:
when you register and/or use our Services or Site, or open an account with us;
when you submit any form, including, but not limited to, order forms or other forms relating to any of our products and/or services, whether online or by way of a physical form;
when you enter into any agreement or provide other documentation or information in respect of your interactions with us, or when you use our products and/or services;
when you interact with us, such as via telephone calls (which may be recorded), letters, fax, face-to-face meetings, social media platforms and emails;
when you use our electronic services, or interact with us via our website or use services on our website. This includes, without limitation, through cookies which we may deploy when you interact with our applications or website;
when you carry out transactions through our website or Services;
when you provide us with feedback or complaints;
when you submit your personal data to us for any reason.
The above does not purport to be exhaustive and sets out some common instances of when personal data about you may be collected.
2.2 When you visit, use or interact with the Site or our mobile applications, we may collect certain information by automated or passive means using a variety of technologies, which technologies may be downloaded to your device and may set or modify settings on your device. The information we collect may include, without limitation, your Internet Protocol (IP) address, computer/mobile device operating system and browser type, type of mobile device, the characteristics of the mobile device, the unique device identifier (UDID) or mobile equipment identifier (MEID) for your mobile device, the address of a referring web site (if any), and the pages you visit on our website and mobile applications and the times of visit. We may collect, use disclose and/or process this information only for the Purposes (defined below under Section 9).
2.3 Our mobile applications may collect precise information about the location of your mobile device using technologies such as GPS, Wi-Fi, etc. We collect, use, disclose and/or process this information for one or more Purposes including, without limitation, location-based services that you request or to deliver relevant content to you based on your location or to allow you to share your location to other users as part of the services under our mobile applications. For most mobile devices, you are able to withdraw your permission for us to acquire this information on your location through your device settings. If you have questions about how to disable your mobile device’s location services, please contact your mobile device service provider or the device manufacturer.
WHAT PERSONAL DATA WILL EMATIC COLLECT?
3.1 The personal data that Ematic may collect includes but is not limited to:
bank account and payment information;
any other information about the user when the user signs up to use our Services or website, and when the user uses the Services or website, as well as information related to how the user uses our Services or website;
aggregate data on content the user engages with.
3.2 If you do not want us to collect the aforementioned information/personal data, you may opt out at any time by notifying our Data Protection Officer in writing about it. Further information on opting out can be found in the section below entitled “How can you opt-out, remove, request access to or modify information you have provided to us?”. Note, however, that opting out of us collecting your personal data or withdrawing your consent for us to collect, use or process your personal data may affect your use of the Services.
SETTING UP AN ACCOUNT
4.1 In order to use certain functionalities of the Services, you will have to create a user account which requires you to submit certain personal data. When you register and create an account, we require you to provide us with your name and email address as well as a user name that you select. We also ask for certain information about yourself such as your telephone number, and email address. Upon activating an account, you will select a user name and password. Your user name and password will be used so you can securely access and maintain your account.
VIEWING WEB PAGES
5.1 As with most websites, your computer sends information which may include personal data about you that gets logged by a web server when you browse our Site. This typically includes without limitation your computer’s IP address, operating system, browser name/version, the referring web page, requested page, date/time, and sometimes a “cookie” (which can be disabled using your browser preferences) to help the site remember your last visit. If you are logged in, this information is associated with your personal account. The information is also included in anonymous statistics to allow us to understand how visitors use our site.
6.1 We may from time to time implement “cookies” or other features to allow us or third parties to collect or share information that will help us improve our Site and the Services we offer, or help us offer new services and features. “Cookies” are identifiers we transfer to your computer or mobile device that allow us to recognize your computer or device and tell us how and when the Services or website are used or visited, by how many people and to track movements within our website. We may link cookie information to personal data.
7.1 We provide customer service support through email and feedback forms. In order to provide customer support, we will ask for your email address. Aside from this information, we do not ask for any personal data to provide customer support. We only use information received from customer support requests, including, without limitation, email addresses, for customer support services and we do not transfer to or share this information with any third parties.
8.1 From time-to-time, we may request information from users via surveys. Participation in these surveys is completely voluntary and you therefore have a choice whether or not to disclose your information to us. Information requested may include, without limitation, contact information (such as your email address), and demographic information. Survey information will be used for the purposes of monitoring or improving the use and satisfaction of the Services and will not be transferred to third parties, other than our contractors who help us to administer or act upon the survey.
HOW DO WE USE THE INFORMATION YOU PROVIDE US?
9.1 We may collect, use, disclose and/or process your personal data for one or more of the following purposes:
to consider and/or process your application/transaction with us or your transactions or communications with third parties via the Services;
to manage, operate, provide and/or administer your use of and/or access to our Services and our website, as well as your relationship and user account with us;
to manage, operate, administer and provide you with as well as to facilitate the provision of our Services, including, without limitation, remembering your preferences;
to tailor your experience through the Services by displaying content according to your interests and preferences, providing a faster method for you to access your account and submit information to us and allowing us to contact you, if necessary;
to respond to, process, deal with or complete a transaction and/or to fulfill your requests for certain products and/or services and notify you of service issues and unusual account actions;
to enforce our Terms of Service or any applicable end user license agreements;
to protect personal safety and the rights, property or safety of others;
for identification and/or verification;
to maintain and administer any software updates and/or other updates and support that may be required from time to time to ensure the smooth running of our Services;
to deal with or facilitate customer service, carry out your instructions, deal with or respond to any enquiries given by (or purported to be given by) you or on your behalf;
to contact you or communicate with you via voice call, text message and/or fax message, email and/or postal mail or otherwise for the purposes of administering and/or managing your relationship with us or your use of our Services, such as but not limited to communicating administrative information to you relating to our Services. You acknowledge and agree that such communication by us could be by way of the mailing of correspondence, documents or notices to you, which could involve disclosure of certain personal data about you to bring about delivery of the same as well as on the external cover of envelopes/mail packages;
to inform you when another user has sent you a private message or posted a comment for you on the Site;
to conduct research, analysis and development activities (including, but not limited to, data analytics, surveys, product and service development and/or profiling), to analyse how you use our Services, to improve our Services or products and/or to enhance your customer experience;
to allow for advertising and other audits and surveys to, among other things, validate the size and composition of our target audience, and understand their experience with Ematic’s Services;
where you give us your prior consent, for marketing and in this regard, to send you by various modes of communication such as postal mail, email, location-based services or otherwise, marketing and promotional information and materials relating to products and/or services (including, without limitation, products and/or services of third parties whom Ematic may collaborate or tie up with) that Ematic (and/or its affiliates or related corporations) may be selling, marketing or promoting, whether such products or services exist now or are created in the future.
to respond to legal processes or to comply with or as required by any applicable law, governmental or regulatory requirements of any relevant jurisdiction, including, without limitation, meeting the requirements to make disclosure under the requirements of any law binding on Ematic or on its related corporations or affiliates;
to produce statistics and research for internal and statutory reporting and/or record-keeping requirements;
to carry out due diligence or other screening activities (including, without limitation, background checks) in accordance with legal or regulatory obligations or our risk management procedures that may be required by law or that may have been put in place by us;
to audit our Services or Ematic’s business;
to prevent or investigate any fraud, unlawful activity, omission or misconduct, whether relating to your use of our Services or any other matter arising from your relationship with us, and whether or not there is any suspicion of the aforementioned;
to store, host, back up (whether for disaster recovery or otherwise) of your personal data, whether within or outside of your jurisdiction;
to deal with and/or facilitate a business asset transaction or a potential business asset transaction, where such transaction involves Ematic as a participant or involves only a related company or affiliate of Ematic as a participant or involves Ematic and/or any one or more of Ematic’s related companies or affiliates as participant(s), and there may be other third party organisations who are participants in such transaction. A “business asset transaction” refers to the purchase, sale, lease, merger, amalgamation or any other acquisition, disposal or financing of an organisation or a portion of an organisation or of any of the business or assets of an organisation; and/or
any other purposes which we notify you of at the time of obtaining your consent.
(collectively, the “Purposes”).
9.2 As the purposes for which we will/may collect, use, disclose or process your personal data depend on the circumstances at hand, such purpose may not appear above. However, we will notify you of such other purpose at the time of obtaining your consent, unless processing of the applicable data without your consent is permitted by the Privacy Laws.
SHARING OF INFORMATION FROM THE SERVICES
10.1 Our Services enable users to share personal information with each other, in almost all occasions without Ematic’s involvement, to complete transactions. In a typical transaction, users may have access to each other’s name, User ID, email address and other contact information. Our Website Terms of Service require that users in possession of another user’s personal data (the “Receiving Party”) must (i) comply with all applicable Privacy Laws; (ii) allow the other user (the “Disclosing Party”) to remove him/herself from the Receiving Party’s database; and (iii) allow the Disclosing Party to review what information have been collected about them by the Receiving Party.
HOW DOES EMATIC PROTECT CUSTOMER INFORMATION?
DOES EMATIC DISCLOSE THE INFORMATION IT COLLECTS FROM ITS VISITORS TO OUTSIDE PARTIES?
12.1 In conducting our business, we will/may need to disclose your personal data to our third party service providers, agents and/or our affiliates or related corporations, and/or other third parties, whether sited in Singapore or outside of Singapore, for one or more of the above-stated Purposes. Such third party service providers, agents and/or affiliates or related corporations and/or other third parties would be processing your personal data either on our behalf or otherwise, for one or more of the above-stated Purposes. Such third parties include, without limitation:
our subsidiaries, affiliates and related corporations;
contractors, agents, service providers and other third parties we use to support our business. These include but are not limited to those which provide administrative or other services to us such as telecommunication companies, information technology companies and data centres;
a buyer or other successor in the event of a merger, divestiture, restructuring, reorganization, dissolution or other sale or transfer of some or all of Ematic’s assets, whether as a going concern or as part of bankruptcy, liquidation or similar proceeding, in which personal data held by Ematic about our users is among the assets transferred; or to a counterparty in a business asset transaction that Ematic or any of its affiliates or related corporations is involved in; and
third parties to whom disclosure by us is for one or more of the Purposes and such third parties would in turn be collecting and processing your personal data for one or more of the Purposes
12.2 For the avoidance of doubt, in the event that Privacy Laws or other applicable laws permit an organisation such as us to collect, use or disclose your personal data without your consent, such permission granted by the laws shall continue to apply.
12.3 Third parties may unlawfully intercept or access personal data transmitted to or contained on the site, technologies may malfunction or not work as anticipated, or someone might access, abuse or misuse information through no fault of ours. We will nevertheless deploy reasonable security arrangements to protect your personal data as required by the Privacy Laws; however there can inevitably be no guarantee of absolute security such as but not limited to when unauthorised disclosure arises from malicious and sophisticated hacking by malcontents through no fault of ours.
INFORMATION ON CHILDREN
13.1 The Services are not intended for children under the age of 13. We do not knowingly collect or maintain any personal data or non-personally-identifiable information from anyone under the age of 13 nor is any part of our Site or other Services directed to children under the age of 18. We will close any accounts used exclusively by such children and will remove and/or delete any personal data we believe was submitted by any child under the age of 13. If you believe we might have any information from or about a child under 13, please contact us at email@example.com.
HOW DOES EMATIC PROTECT CUSTOMER INFORMATION?
DISCLAIMER REGARDING SECURITY AND THIRD PARTY SITES
15.1 WE DO NOT GUARANTEE THE SECURITY OF PERSONAL DATA AND/OR OTHER INFORMATION THAT YOU PROVIDE ON THIRD PARTY SITES. We do implement a variety of security measures to maintain the safety of your personal data that is in our possession or under our control. Your personal data is contained behind secured networks and is only accessible by a limited number of persons who have special access rights to such systems, and are required to keep the personal data confidential. When you place orders or access your personal data, we offer the use of a secure server. All personal data or sensitive information you supply is encrypted into our databases to be only accessed as stated above.
15.2 In an attempt to provide you with increased value, we may choose various third party websites to link to, and frame within, the Site. We may also participate in co-branding and other relationships to offer e-commerce and other services and features to our visitors. These linked sites have separate and independent privacy policies as well as security arrangements. Even if the third party is affiliated with us, we have no control over these linked sites, each of which has separate privacy and data collection practices independent of us. Data collected by our co-brand partners or third party web sites (even if offered on or through our Site) may not be received by us.
15.3 We therefore have no responsibility or liability for the content, security arrangements (or lack thereof) and activities of these linked sites. These linked sites are only for your convenience and you therefore access them at your own risk. Nonetheless, we seek to protect the integrity of our Site and the links placed upon each of them and therefore welcome any feedback about these linked sites (including, without limitation, if a specific link does not work).
WILL EMATIC TRANSFER YOUR INFORMATION OVERSEAS?
16.1 Your personal data and/or information may be transferred to, stored or processed outside of your country, including Singapore, Australia, Malaysia, Indonesia, Thailand, Philippines, Vietnam and the United States of America. In most cases, your personal data will be processed in Singapore, where our servers are located and our central database is operated. Ematic will only transfer your information overseas in accordance with applicable Privacy Laws.
HOW CAN YOU OPT-OUT, REMOVE, REQUEST ACCESS TO, MODIFY INFORMATION YOU HAVE PROVIDED TO US AND PORTABILITY?
17.1 Opting Out and Withdrawing Consent
17.1.1 To modify your email subscriptions, please let us know by sending an email to our Personal Data Protection Officer at the address listed below. Please note that due to email production schedules, you may still receive emails that are already in production.
17.1.2 You may withdraw your consent for the collection, use and/or disclosure of your personal data in our possession or under our control by sending an email to our Personal Data Protection Officer at the email address listed below in Section 19.2.
17.1.3 Once we have your clear withdrawal instructions and verified your identity, we will process your request for withdrawal of consent, and will thereafter not collect, use and/or disclose your personal data in the manner stated in your request. If we are unable to verify your identity or understand your instructions, we will liaise with you to understand your request.
17.1.4 However, your withdrawal of consent could result in certain legal consequences arising from such withdrawal. In this regard, depending on the extent of your withdrawal of consent for us to process your personal data, it may mean that we will not be able to continue providing the Services to you, we may need to terminate your existing relationship and/or the contract you have with us, etc., as the case may be, which we will inform you of.
17.2 Requesting Access and/or Correction of Personal Data
17.2.1 If you have an account with us, you may personally access and/or correct your personal data currently in our possession or control through the Account Settings page on the Site. If you do not have an account with us, you may request to access and/or correct your personal data currently in our possession or control by submitting a written request to us. We will need enough information from you in order to ascertain your identity as well as the nature of your request so as to be able to deal with your request. Hence, please submit your written request by sending an email to our Personal Data Protection Officer at the email address listed below in Section 19.2.
17.2.2 For a request to access personal data, once we have sufficient information from you to deal with the request, we will seek to provide you with the relevant personal data within 28 days (or, if you are resident in Malaysia, 21 days). Where we are unable to respond to you within the said 28 days (or, if you are resident in Malaysia, 21 days), we will notify you of the soonest possible time within which we can provide you with the information requested. Note that Privacy Laws may exempt certain types of personal data from being subject to your access request.
17.2.3 For a request to correct personal data, once we have sufficient information from you to deal with the request, we will:
correct your personal data within 30 days (or, if you are resident in Malaysia, 21 days). Where we are unable to do so within the said period, we will notify you of the soonest practicable time within which we can make the correction. Note that Privacy Laws may exempt certain types of personal data from being subject to your correction request as well as provides for situation(s) when correction need not be made by us despite your request; and
we will send the corrected personal data to every other organisation to which the personal data was disclosed by us within a year before the date the correction was made, unless that other organisation does not need the corrected personal data for any legal or business purpose.
17.2.4 Notwithstanding sub-paragraph (b) immediately above, we may, if you so request, send the corrected personal data only to specific organisations to which the personal data was disclosed by us within a year before the date the correction was made.
17.2.5 We may also be charging you a reasonable fee for the handling and processing of your requests to access your personal data. If we so choose to charge, we will provide you with a written estimate of the fee we will be charging. Please note that we are not required to respond to or deal with your access request unless you have agreed to pay the fee.
17.2.6 We reserve the right to refuse to correct your personal data in accordance with the provisions as set out in Privacy Laws, where they require and/or entitle an organisation to refuse to correct personal data in stated circumstances.
17.3 Data Portability
17.3.1 Where the Customer Data is processed by the Company through electronic means and in a structured and commonly used format, the Customer shall have the right to obtain a copy of such data in an electronic or structured format that is commonly used and allows for further use by the Customer. The exercise of this right shall primarily take into account the right of Customer to have control over his or her Data being processed based on consent or contract, for commercial purpose, or through automated means.
DATA INCIDENT MANAGEMENT AND NOTIFICATION
Ematic maintains strict security incident management policies and procedures and shall, notify Customer without undue delay after becoming aware of the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to your Data, transmitted, stored or otherwise processed by Ematic of which Ematic becomes aware (a “Data Incident”). Ematic shall make reasonable efforts to identify the cause of such Data Incident and take those steps as Ematic deems necessary and reasonable in order to remediate the cause of such a Data Incident to the extent the remediation is within Ematic’s reasonable control. The obligations herein shall not apply to incidents that are caused by you.
QUESTIONS, CONCERNS OR COMPLAINTS? CONTACT US
19.1 If you have any questions or concerns about our privacy practices or your dealings with the Services, please do not hesitate to contact: firstname.lastname@example.org.
19.2 If you have any complaint or grievance regarding how we are handling your personal data or about how we are complying with Privacy Laws, we welcome you to contact us with your complaint or grievance.
Please contact us through email with your complaint or grievance:
E-mail: email@example.com and Attention it to the “Personal Data Protection Officer”.
19.3 Where it is an email or a letter through which you are submitting a complaint, your indication at the subject header that it is a Privacy Law complaint would assist us in attending to your complaint speedily by passing it on to the relevant staff in our organisation to handle. For example, you could insert the subject header as “Privacy Complaint”.
We will certainly strive to deal with any complaint or grievance that you may have fairly and as soon as possible.
19.4 If you would like to withdraw your consent to any use of your Personal Data as set out in this Data Protection Policy or otherwise; or would like to make access or corrections to your Personal Data records, please contact Ematic as follows:
By email: firstname.lastname@example.org
By mail: Personal Data Protection Officer
EMATIC SOLUTIONS PTE. LTD.
29A Cuppage Road, #02-00,
By telephone: Personal Data Protection (PDP) Representative Contact: +65 83140509
Ematic will generally be able to respond to such queries and/or requests within 28 days. There may be instances where this is not possible due to the contents of the complaint. In such circumstances, we will respond to your complaint in a reasonable and practical time.
19.5. If you withdraw your consent to any or all use of your Personal Data, depending on the nature of your request, Ematic may not be able to continue to provide its products and/or services to you.
19.6 For information on the Singapore Personal Data Protection Act (PDPA), please refer to Personal Data Protection Commission’s website: www.pdpc.gov.sg
19.7 For information on the Australian Privacy Act, please refer to the Office of the Australian Information Commissioner’s website: www.oaic.gov.au.
19.8 For information on the Malaysian Personal Data Protection Act, please refer to Department of Personal Data Protection’s website: http://www.pdp.gov.my
19.9 For information on the European Union General Data Protection Regulation (EU GDPR), please refer to the EU GDPR’s website: www.eugdpr.org
TERMS AND CONDITIONS
Last Updated: January 10, 2019