1 January 2016
Personal Data Protection Policy
Your personal data is important to National University of Singapore BiZiT Society (NUS BiZiT).
Your personal data is important to us and it is our policy to respect the confidentiality of information and the privacy of individuals. This Policy outlines how we manage the personal data we hold in compliance with the Personal Data Protection Act in Singapore (the “Act”) and further details of which are available at our website nusbizit.org.
What types of personal data do we collect?
We may collect and hold personal data of persons/entities including but not limited to:
- job applicants and employees;
- service providers; and
- other people who we may come into contact.
Examples of such personal data include biodata, contact details, account information and your preferences, queries, requests and feedback.
How do we collect your personal data?
The ways in which we may collect your personal data include (but are not limited to) collecting directly or indirectly from you or your authorised representatives in the course of:
- you signing up for alerts or newsletters;
- you applying for a job with us;
- you participating in our marketing or promotional events;
- you using our products or services;
- you contacting us with your queries, requests or feedback;
- our conducting or completing of transactions;
- our conducting market research or surveys;
- our conducting interviews.
What kind of purposes do we collect your personal data for?
In general, we may use your personal data for the following purposes:
- providing customer service (e.g. responding to queries and requests; informing you about service status and product updates; sending you alerts and newsletters);
- conducting market research and improving customer service (e.g. conducting market research or surveys; performing market analysis; managing and enhancing our products and services; developing new products);
- conducting marketing promotions (e.g. sending of alerts, newsletters, marketing materials and invitations from us wholly or through affiliation with third parties);
- complying with applicable laws, regulations and other requirements (e.g. providing assistance to law enforcement agencies, regulatory authorities and other governmental agencies; performing internal audits);
- maintaining investor relations (e.g. sending of alerts, newsletters, publications, marketing materials and invitations from us wholly or through affiliation with third parties);
- performing evaluations (e.g. assessing suitability of employees)
How do we use and/or disclose your personal data?
We will only use, disclose and/or transfer your personal data for the purposes you have been notified of and consented to or which are permitted under applicable laws and regulations.
We will not sell, rent or give away personal data to third parties for commercial purposes without your consent.
Who do we share your personal data with?
Depending on the product or service concerned, personal data may be disclosed or transferred to:
- our service providers and specialist advisers/institutions who have been contracted to provide administrative, financial, legal, accounting, information technology, research or other services;
- courts, tribunals, law enforcement agencies, regulatory authorities and other governmental agencies as agreed or authorised by law;
- anyone authorised by an individual, as specified by that individual or the contract.
Where personal data is disclosed or transferred to organisations outside of NUS BiZiT who handle or obtain personal data as service providers to NUS BiZiT, we require such organisations to acknowledge the confidentiality of such personal data, undertake to respect any individual’s right to privacy and comply with the Act and this Policy and use such personal data only for our purposes and otherwise follow our reasonable directions with respect to this data.
In addition, where personal data is transferred overseas and we may need to process or deal with your personal data outside Singapore, we will ensure that such transfer is in compliance with the Act and this Policy or is permitted under applicable data protection and privacy laws and regulations.
How do we manage, protect and store your personal data?
We have appointed Data Protection Officers (“DPOs”), our Chief Information Officer (CIO) to oversee our management of personal data in accordance with the Act.
We regard breaches of your privacy very seriously and we have implemented measures to secure and protect your information, such as training our employees who handle your personal data to respect the confidentiality of such personal data and your privacy, storing personal data in a combination of secure computer storage facilities and paper based files and other records, taking steps to protect the personal data we hold from misuse, loss, unauthorised access, modification or disclosure.
However, you will appreciate that it is not for us to perfectly secure your personal data from cyber attacks, such as hacking, spyware and viruses. Accordingly, you will not hold us liable for any unauthorized disclosure, loss or destruction of your personal data arising from such risks.
The Act also requires us not to store personal data longer than necessary. We will cease to retain your personal data when we no longer require such personal data for the purposes we originally notified you of or for any business or legal needs.
How do we keep personal data accurate and up-to-date and how to exercise your right to correct the personal data we hold of you?
We endeavour to ensure that the personal data we hold about you is accurate and up-to-date. We realise that such personal data changes frequently with changes of address and other personal circumstances. We encourage you to contact us as soon as possible in order to update any personal data it holds about you.
Our contact details are set out on nusbizit.org. We may require you to verify your identity.
How to exercise your right to access the personal data we hold of you?
To make a request to access the personal data we hold about you, please contact the DPO in writing using the Request to Access Personal Data Form. We will require you to verify your identity and to specify what data you require. We may charge a fee to cover the cost of verifying the application and locating, retrieving, reviewing and copying any material requested. If the data sought is extensive, we will advise the likely cost in advance and can help to refine your request if required.
How to exercise your right to withdraw your consent?
To make a request to withdraw your consent previously given, please contact the DPO in writing.
What if you have a complaint?
If you consider that any action of NUS BiZiT breaches the Act or this Policy, you can make a complaint to the DPO in writing. We will endeavour to act promptly in response to a complaint.
How to contact us?
You can contact the DPOs in the Contact Us Page on nusbizit.org.
Updates to this Policy
This Policy will be reviewed from time to time to take account of new laws and technology, changes to our operations and practices and the changing business environment. This Policy was last updated on 2 February 2016. If you are unsure whether you are reading the most recent version, please contact us.