NCS’ Data Protection Policy
Respecting your privacy and protecting your personal data
NCS Pte. Ltd. (“NCS”) respects the privacy of users in accordance with our Data Protection Policy. Our Data Protection Policy applies solely to personal data collected by NCS. Please be aware that NCS is not and cannot be responsible for the personal data protection practices of third parties.
We conduct our business in compliance with the Personal Data Protection Act (PDPA) and have implemented additional measures to protect your personal data.
Ways we collect your personal data
We may collect your personal data when you:
- Provide us personal data
- Use our products or services
- Register for a specific product or service
- Sign up for alerts or newsletters
- Contact us with a question or request for assistance
- Participate in a competition, lucky draw or survey
- Provide us with products and/or services.
Where you give us personal data about other individuals, you confirm that you are authorised to disclose and consent, on their behalf, to the processing of such personal data for the purposes described below, or other purposes for which your consent has been sought and obtained.
The personal data we collect
Here are examples of personal data we collect:
- Your identity – This includes NRIC, FIN or passport number, address, telephone number, e-mail address, date of birth, any form of biometric that you may have submitted, as well as service-related information such as bank and credit card details, device ID and IP address.
- Your interaction with us – For example, a note or recording of a call you make to one of our contact centres, an email or letter you send to us, surveillance footage or other records of any contact you have with us.
- Provision of goods and services – This includes personal data that we have access to in the course of provision of goods and services.
- Information from other organisations – These organisations include fraud-prevention agencies, business directories, credit reference agencies or individuals we believe you have authorised to provide your personal details on your behalf.
How we use your personal data
We may collect and use your personal data for the following purposes and other legitimate interest to be notified to you:
If you are a Customer
Provisioning & administration of services
- Provide goods and/or services to you
- Enable us to process bills and payments
- Respond to enquiries and requests from you or people you have authorised
- Inform you about service upgrades and updates
Market research & service enhancement
- Conduct market research and customer satisfaction surveys to improve our customer service; develop new products, as well as personalise the services we offer you
- Perform market analysis
- Improve your user experience based on your usage behaviour on our websites and applications
Sharing of rewards and benefits
- Offer rewards and promotions
- Provide updates, offers, invitations to events and deliver relevant advertising, with your prior consent or if otherwise permitted under local laws and regulations
Security and risk management
- Inform you of service and security issues
- Prevent and detect fraud or other crimes and recover debts
- Conduct internal audits and determine creditworthiness
- Ensure the safety and security of our properties and systems
- Conduct checks against money laundering, terrorism financing, corruption, compliance and related risks
Legal & regulatory requirements
- Meet legal, regulatory and other requirements including providing assistance to law enforcement, judicial and other government agencies
If you are a Supplier / Subcontractor
- To conduct due diligence / background checks that are mandated by legislation, NCS or NCS’ clients’ internal policies and practices
- For the purposes relating to the supply of goods and services and support by supplier / subcontractor to NCS
- Security clearance / entry access into NCS’ and NCS’ clients’ premises
We will not use your personal data for purposes other than above, unless permitted under local laws and regulations. We shall seek your consent before collecting any additional personal data and before using your personal data for a purpose which has not been notified to you (except where permitted or authorised by law).
Sharing your personal data
We may share your personal data with:
- Companies in the Singapore Telecommunications Ltd group
- Business partners and vendors we work with to deliver goods and/or services you purchase or which we purchase
- Our clients
- Regulatory authorities, law enforcement agencies, government agencies and other government organisations, as required by local laws and regulations
- Financial institutions for purposes of our business relationship
- Research institutions for market analysis purposes
- Credit reference bureaus for the purpose of preparing credit reports or evaluation of creditworthiness
Your personal data is disclosed to the above only for the relevant purposes stated above.
We will also ensure that overseas organisations we work with observe strict confidentiality and data protection obligations.
Protecting your personal data
We have implemented stringent measures to secure and protect your information. These include:
- Safeguards to prevent security breaches in our network and database systems
- Limits on access to information in our systems
- Strict verification processes to prevent unauthorised access to information
Withdrawing your consent
The consent that you provide for the collection, use and sharing of your personal data will remain valid until such time it is being withdrawn by you in writing. You may withdraw consent and request us to stop using and/or disclosing your personal data for any or all of the purposes listed above by submitting this form to your contact person in NCS or our Data Protection Officer at the contact details provided below.
Upon receipt of your written request to withdraw your consent, we may require reasonable time (depending on the complexity of the request and its impact on our relationship with you) for your request to be processed and for us to notify you of the consequences of us acceding to the same, including any legal consequences which may affect your rights and liabilities to us. In general, we shall seek to process your request within thirty (30) business days of receiving it.
Whilst we respect your decision to withdraw your consent, please note that depending on the nature and scope of your request, we may not be in a position to continue providing our goods and/or services to you and we shall, in such circumstances, notify you before completing the processing of your request. Should you decide to cancel your withdrawal of consent, please inform us in writing in the manner described in this section above.
Please note that withdrawing consent does not affect our right to continue to collect, use and disclose personal data where such collection, use and disclose without consent is permitted or required under applicable laws.
Access to and correction of personal data
If you wish to make (a) an access request for access to a copy of the personal data which we hold about you or information about the ways in which we use or disclose your personal data, or (b) a correction request to correct or update any of your personal data which we hold about you, you may submit the Access Request and Correction Request to your contact person in NCS or our Data Protection Officer at the contact details provided below.
Please note that a reasonable fee may be charged for an access request. If so, we will inform you of the fee before processing your request.
We will respond to your request as soon as reasonably possible. Should we not be able to respond to your request within thirty (30) days after receiving your request, we will inform you in writing within thirty (30) days of the time by which we will be able to respond to your request. If we are unable to provide you with any personal data or to make a correction requested by you, we shall generally inform you of the reasons why we are unable to do so (except where we are not required to do so under the PDPA).
Retention of personal data
We may retain your personal data for as long as it is necessary to fulfil the purpose for which it was collected, or as required or permitted by applicable laws.
Data protection officer
You may contact our Data Protection Officer if you have any enquiries or feedback on our personal data protection policies and procedures, or if you wish to make any request at email@example.com.
We may revise this notice from time to time without any prior notice. You may determine if any such revision has taken place by referring to the date on which this Data Protection Policy was last updated. Your continued use of our Services constitutes your acknowledgement and acceptance of such changes.
Effective date: 1 April 2022