Privacy
Introduction
Cistri Pte. Ltd. (UEN No.201615528K), its related corporations, and such other affiliates as may be relevant (collectively referred to as ‘Cistri’, ‘we’, ‘our’, or ‘us’) recognize the importance of protecting the privacy and the rights of individuals regarding their personal data. This document is our ‘privacy policy’ and it tells you how we collect and manage your personal data.
We respect your rights to privacy under Singapore Personal Data Protection Act 2012 (‘PDPA’) and we comply with all of the requirements of the PDPA for the collection, use and disclosure of your personal data.
What is your personal data?
When used in this privacy policy, the term ‘personal data’ has the meaning given to it in the PDPA. Personal data is any data, whether true or not, about an individual who can be identified either: (a) from that data; or (b) from that data and other information to which we have or are likely to have access. This may include your name, address, telephone number, email address and profession or occupation, amongst other things. If the data we collect identifies you, or you are reasonably identifiable from it, the data will be considered personal data.
Please note that the data protection provisions of the PDPA do not apply to business contact information (‘BCI’). BCI is an individual’s name, position name or title, business telephone number, business address, business electronic mail address or business fax number and any other similar information about the individual, not provided by the individual solely for their personal purposes.
What personal data do we collect?
Depending on the nature of your interaction with us, the following are examples of the types of personal data that we may collect from you:
- name;
- mailing or street address;
- email address;
- telephone number;
- facsimile number;
- age or birth date;
- gender;
- bank account details;
- education, employment and work history;
- details of the services you have acquired from us or which you have enquired about, together with any additional information necessary to deliver those services and to respond to your enquiries;
- information you provide to us through customer surveys, market or social research or visits or interviews by our representatives from time to time; and
- any additional information relating to you that you provide to us directly through our website or indirectly through use of our website or online presence, through our representatives or otherwise.
When using ‘cookies’ we may collect information on browser access and session identifiers, profile expiration dates, response fields and access preferences (this is discussed further in the ‘Cookies’ section below). We may also collect some information that is not personal data because it does not identify you or anyone else. For example, we may collect anonymous answers to surveys or aggregated information about how users use our website.
How do we collect your personal data?
We collect your personal data directly from you unless it is unreasonable or impracticable to do so. When collecting personal data from you, we may collect it in various ways, including:
- through your access and use of our website;
- during conversations between you and our representatives including during interviews;
- when you agree to participate in any research or consultations we are conducting or when you register to attend or attend one of our events;
- when you take part in an online survey or consultation;
- when you engage us to provide you with services;
- when you sign up to receive any email communications or newsletters from us; or
- if applicable, when you apply for employment or a contract role with us.
Where relevant, we may also collect personal data from third parties including:
- your past or current employer; and
- third party organisations such as government entities, non-government organisations and companies (for example credit reporting bodies and law enforcement agencies) including for research purposes.
What happens if we can't collect your personal data?
If you do not provide us with the personal data described above, some or all of the following may happen:
- we may not be able to provide our services to you, either to the same standard or at all;
- you may not be able to participate in any research that we conduct or attend an event that we host or organise;
- we may not be able to provide you with information that you have requested; or
- we may be unable to tailor the content of our website to your preferences and your experience of our website may not be as enjoyable or useful.
For what purposes do we collect, use and disclose your personal data?
Consent
By providing your personal data to us, you consent to our collection, use and disclosure of your personal data in accordance with this privacy policy.
You may withdraw your consent at any time by contacting us using the details in the ‘Contacting us’ section below. Please note that if you withdraw your consent, we may not be able to continue to provide our services to you. Withdrawal of consent will not affect the lawfulness of any collection, use or disclosure of personal data based on the consent applying before its withdrawal.
Purposes
We collect personal data about you so that we can perform our business activities and functions and to provide the best possible quality of customer service. We collect, use and disclose your personal data for the following purposes:
- to provide our services to you and to send communications requested by you;
- to answer enquiries and provide information or advice about existing and new services;
- for business administration purposes (including human resources, client management and debtor management);
- for marketing purposes (including to create and maintain subscriber databases used for client profiling or events management purposes);
- for research purposes (including to conduct market and consumer research, social research and public policy research programs);
- to provide you with access to protected areas of our website;
- to assess the performance of our website and to improve the operation of our website;
- to conduct business processing functions including providing personal data to our related corporations and affiliates, contractors, service providers or other third parties;
- if applicable, to consider your application for employment or a contract role with us and to manage the application process;
- if you are or become an employee or contractor of ours, to manage and administer your employment or contracting relationship with us;
- to update our records and keep your contact details up to date;
- to process and respond to any complaint made by you; and
- to comply with any law, rule, regulation, lawful and binding determination, decision or direction of a regulator, or in co-operation with any governmental authority.
Your personal data will not be shared, sold, rented or disclosed other than as described in this privacy policy.
Our website
Our privacy policy also applies to our website at www.cistri.com.
Cookies
When you access our website, we may send a ‘cookie’ (which is a small summary file containing a unique ID number) to your computer. Our ‘cookies’ do not collect personal data. If you do not wish to receive ‘cookies’, you can set your browser so that your computer does not accept them. We may log IP addresses (that is, the electronic addresses of computers connected to the internet) to analyse trends, administer the website, track user movements, and gather broad demographic information.
Security
As our website is linked to the internet, and the internet is inherently insecure, we cannot provide any assurance regarding the security of data during transmission online from you to us. We also cannot guarantee that the data you supply will not be intercepted during transmission over the internet to our website. Accordingly, any personal data or other data which you transmit to our website online is transmitted at your own risk.
Refer to the further commentary in the ‘Protection of personal data’ section below.
Links
Our website may contain links to other websites operated by third parties. We make no representations or warranties in relation to the privacy practices of any third party website and we are not responsible for the privacy policies or the content of any third party website. Third party websites are responsible for informing you about their own privacy practices.
Who do we disclose your personal data to?
We may disclose your personal data for the purpose stated when it was collected or a purpose which you would reasonably expect and to:
- our employees, related corporations and affiliates, contractors, service providers and other third parties for the purposes of the operation of our website or our business, to ask you to participate in research, to invite you to attend our events, to fulfil requests made by you, and to otherwise provide services to you. These third parties may include, without limitation, web hosting providers, IT systems administrators, mailing houses, couriers, payment processors, data entry service providers, electronic network administrators, and debt collectors;
- professional advisors and external service providers retained by us in connection with our business operations, including without limitation, accountants, auditors, solicitors, business advisors and consultants;
- suppliers and other third parties with whom we have commercial relationships, for business, marketing, and related purposes;
- clients with whom we have commercial relationships and those who have engaged us to undertake market, consumer or social research for which your personal data was collected;
- banks, financial institutions, and credit reporting agencies for the purposes of processing payments, managing credit risk, or verifying financial information;
- fraud prevention agencies, identity verification providers, and security service providers for the purposes of detecting, preventing, or investigating fraud, security breaches, or unlawful activity;
- regulatory authorities, government agencies, statutory boards, law enforcement agencies, and courts or tribunals, where required or permitted by applicable law or in response to legal process; and
- any organisation for any authorised purpose with your consent.
Direct marketing materials
With your express consent and in accordance with applicable laws, we may send you direct marketing communications and information about our services that we consider may be of interest to you. These communications may be sent in various forms, including mail, SMS, fax and email, in accordance with applicable marketing laws, including the Do Not Call Registry provisions under the PDPA. If you indicate a preference for a method of communication, we will endeavour to use that method whenever practical to do so. In addition, at any time you may opt-out of receiving marketing communications from us by contacting us (using the details in the ‘Contacting us’ section below) or by using the opt-out facilities provided in the marketing communications. We will then ensure that your name is removed from our marketing distribution lists.
Our marketing communications database containing your personal data is hosted by a third party organisation solely for the purposes of undertaking our direct marketing, with email direct marketing undertaken on our behalf by another third party organisation.
Do we disclose your personal data to anyone outside Singapore?
We may disclose personal data to our related corporations and affiliates, third party suppliers and service providers located overseas for some of the purposes listed above.
We may also disclose your personal data to entities located outside of Singapore, including the following:
- our related corporations and affiliates located in Australia; and
- our data hosting, online survey platforms and other IT service providers, some of which are located in the United States of America.
Where we transfer your personal data to recipients located outside Singapore, we will take reasonable steps to ensure that the overseas recipients of your personal data are bound by legally enforceable obligations to provide a standard of protection to your personal data that is at least comparable to the protection under the PDPA.
Protection of personal data
We take reasonable steps to ensure your personal data is protected from unauthorised access, collection, use, disclosure, copying, modification, disposal, or similar risks.
We have secure firewalls in place and our servers and hardware (including standalone servers and hardware used for online survey and research projects) utilise a high standard of security. We utilise several other IT security measures and procedures including windows defender and endpoint protection for scanning of local and network files, Office 365 for spam, virus and malware security and safe links and safe attachments protections.
Workstations are password protected and any electronic files for survey and research projects which contain sensitive data are given their own additional password protection which is restricted to those working on the project. Paper copies of documents used in survey and research projects such as consent forms are stored in locked cupboards and archived to a secure archive facility on completion of the project.
We may hold your personal data in either electronic or hard copy form.
Retention of personal data
Personal data is destroyed or anonymised when no longer needed or when we are no longer required by law to retain it (whichever is the later). This means we may retain your personal data for as long as it is necessary to fulfil the purpose for which it was collected, or as required or permitted by applicable laws. We will cease to retain your personal data, or remove the means by which the data can be associated with you, as soon as it is reasonable to assume that such retention no longer serves the purpose for which your personal data was collected, and is no longer necessary for legal or business purposes.
How can you access and correct your personal data?
You may request access to any personal data we hold about you at any time by contacting us (using the details in the ‘Contacting us’ section below). Where we hold personal data that you are entitled to access, we will try to provide you with suitable means of accessing it (for example, by posting or emailing it to you). We may charge you a reasonable fee to cover our administrative and other reasonable costs in providing the personal data to you. We will not charge for simply making the request and will not charge for making any corrections to your personal data.
There may be instances where we cannot grant you access to the personal data we hold. For example, we may need to refuse access if granting access would interfere with the privacy of others or if it would result in a breach of confidentiality. If that happens, we will give you written reasons for any refusal.
If you believe that personal data we hold about you is incorrect, incomplete or inaccurate, then you may request that we correct it. We will consider if the personal data requires correction. If we do not agree that there are grounds for correcting your personal data, then we will add a note to the personal data stating that you disagree with it.
We generally rely on personal data provided by you (or your authorised representative). In order to ensure that your personal data is current, complete and accurate, please update us if there are changes to your personal data by informing our Data Protection Officer in writing or via email at the details set out in the ‘Contacting us’ section below.
What is the process for complaining about a breach of privacy?
If you believe that your privacy has been breached, please contact us using the contact information for our Data Protection Officer below and provide details of the incident so that we can investigate it. We will treat your complaint confidentially, investigate your complaint and aim to ensure that we contact you and your complaint is resolved within a reasonable time.
Data breach notification
We have put in place procedures to manage data breaches in accordance with the PDPA. In the event of a notifiable data breach, we will notify the Personal Data Protection Commission (‘PDPC’) within the timeframe prescribed under the PDPA and, where the breach is likely to result in significant harm to you, we will also notify you as soon as practicable.
Contacting us
If you have any questions about this privacy policy, any concerns or a complaint regarding the treatment of your privacy or a possible breach of your privacy, please use the contact link on our website or contact our Data Protection Officer using the details set out below. We will treat your requests or complaints confidentially. Our representative will contact you within a reasonable time after receipt of your complaint to discuss your concerns and outline options regarding how they may be resolved. We will aim to ensure that your complaint is resolved in a timely and appropriate manner.
Please contact our Data Protection Officer at:
|
Post: |
Data Protection Officer Cistri Pte. Ltd. 6 Battery Road, #13-05, Six Battery Road, Singapore 049909 |
|
Email: |
dataprotectionofficer@cistri.com |
Effect of privacy policy and changes to our privacy policy
This privacy policy should be read together with any other notices, consent clauses, or contractual terms that apply to the collection, use and disclosure of your personal data by us in specific contexts.
We may change this privacy policy from time to time without any prior notice. Any updated versions of this privacy policy will be posted on our website and will be effective from the date of posting.
This privacy policy was last updated June 2026.