Banner

Privacy Statement

Note: If you are located in the European Union (“EU”) or the United Kingdom (“UK”), certain sections of this Statement do not apply to you. Please refer to the Annex (EU and UK Supplement) at the end of this Statement, which sets out the provisions that apply in place of, or in addition to, the relevant sections of this Statement.

Overview and Scope

1.1 In this Statement, “we,” “us,” “our” or the “Company” means Co-Axis Marketplace Pte. Ltd. “Personal Data” means data, whether true or not, about an individual who can be identified: (a) from that data; or (b) from that data and other information we have or are likely to have access.

1.2 This Statement sets out the basis on which we may collect, use, disclose, and process your Personal Data in accordance with the Personal Data Protection Act (“PDPA”). By visiting and using this website, you consent to the collection, use and disclosure of your Personal Data as described in this Statement. If you are acting as an intermediary or otherwise on behalf of a third party or supply us with information regarding a third party, you undertake that you are an authorised representative or agent of such third party and that you have obtained consent from such third party to our collection, use, storage and disclosure of their Personal Data. Because we are collecting the third party’s data from you, you undertake to make the third party aware of all matters listed in this Statement by referring them to our website.

1.3 This Statement supplements but does not supersede nor replace any other consents which you may have previously provided to us, either directly or via a third-party data collector, and your consents herein are cumulative and additional to any rights which we may have at law to collect, use, disclose and/or process your Personal Data. This Statement does not affect any rights which we may have at law in connection with the collection, use, disclosure and/or processing of your Personal Data.

Collection of Personal Data

2.1 Generally, we collect Personal Data when you or your authorised representatives provide it directly or indirectly to us or to our subsidiaries, affiliates, partners, vendors or service providers, including through the following:

(a) whenever you furnish Personal Data by completing online or hardcopy forms during the application process for the Company’s services or feedback, making inquiries, submitting requests, or engaging in various forms of communication;

(b) upon any interaction with the Company (such as telephone conversations, social media interactions, faxes, or emails), including taking follow-up actions on your feedback, inquiries or requests;

(c) upon the completion of the employee information form;

(d) for evaluating job applications and determining suitability for roles within the Company;

(e) upon entering into a contractual agreement with the Company or enrolling in any of the Company’s services;

(f) upon your response to any communication materials issued by the Company;

(g) if you participate in programmes, surveys or initiatives managed by the Company;

(h) when attending events, seminars, or workshops organised or sponsored by the Company or hosted at Temasek Shophouse;

(i) when you link any of your account(s) with us with third-party services and applications (examples include, without limitation, Google and LinkedIn);

(j) when we receive your Personal Data from third parties, for example, when you submit your email address to us to show interest, we receive information from a third party that provides automated fraud detection services to us, or from parties that legally provide it to us, such as credit reference agencies or law enforcement agencies; and

(k) through the use of analytics code and other tools like cookies (please refer to the “IP Addresses/Cookies” section below in this Statement for further details).

2.2 We may collect the following kinds of Personal Data through the different channels mentioned above:

(a) full name;

(b) business and/or residential addresses;

(c) business and/or personal email addresses;

(d) mobile and business telephone numbers;

(e) date of birth, nationality, and country and city of birth;

(f) passport number, National Registration Identity Card (NRIC) number, Foreign Identification Numbers (FIN), and other equivalent identifiers, where necessary;

(g) work pass numbers (e.g. FIN) and details, where necessary;

(h) gender and ethnicity;

(i) marital status;

(j) emergency contact, next-of-kin or family information;

(k) legal and financial history;

(l) bank account details;

(m) IP address;

(n) photographs, videos and other audio-visual information, including CCTV footage;

(o) educational, employment history and professional qualifications, including testimonials and references;

(p) health issues and disabilities, including dietary preferences, where necessary;

(q) curricula vitae; and

(r) any other information that on its own, or when combined with other information, can uniquely identify individuals.

Purposes of Collection, Use and Disclosure of Personal Data

3.1 We may collect, use and/or disclose your Personal Data for any or all of the following purposes:

(a) for administering our website(s);

(b) to perform or carry out our obligations arising from any contracts entered between you and us;

(c) for conducting due diligence, Anti-Money Laundering (AML), Know Your Customer (KYC) and other background checks;

(d) for client administration, services requests and enquiries;

(e) for payment administration purposes;

(f) to respond to, handle and process your enquiries, requests, applications, complaints, and feedback pursuant to your emails, telephone calls, submission of form(s) and/or any other form of communication;

(g) to comply with obligations under applicable laws and related subsidiary legislation, regulations, guidelines, advisories, or other directions as may be issued by the relevant law enforcement or regulatory agencies from time to time;

(h) for recruitment and evaluation purposes if you apply for a job with us;

(i) to follow up and liaise with event attendees and users of Temasek Shophouse premises, facilitate access controls and security clearances for entry into event premises, and other event management and administration matters;

(j) for integrating mentors and volunteers into the Company’s programmes;

(k) for travel arrangement and insurance purposes;

(l) for internal reporting and/or accounting purposes;

(m) for compiling statistics, whether for our own use or for industry exercises and studies, to design and improve our products and services for you;

(n) to enhance security, monitor and verify identity or service access (including facial recognition), combat spam or other malware or security risks;

(o) to send information including confirmations, technical notices, updates, security alerts, and support and administrative messages;

(p) conducting market research, understanding and analysing customer behaviour, location, preferences and demographics for us to offer you products and services as well as special offers and marketing programmes which may be relevant to your preferences and profile;

(q) to investigate or obtain evidence concerning any complaint, claim or dispute or any actual or suspected illegal or unlawful conduct, or to aid law enforcement or regulatory authorities;

(r) any other purposes for which you have provided the information; and/or

(s) purposes incidental to one or more of the above.

3.2 The purposes listed in the above clauses may continue to apply even in situations where your relationship with us (for example, pursuant to a contract) has been terminated or altered in any way, for a reasonable period thereafter (including, where applicable, a period to enable us to enforce our rights under a contract with you).

3.3 We may also contact you by any means of communication for which you have given us contact details, including but not limited to email, telephone and post, for the purpose of getting your feedback or for providing you with information which we believe could be of interest to you or your organisation.

Disclosure of Personal Data to Third Parties

4.1 We may also disclose your Personal Data for any of the purposes listed in the previous section to the following persons, whether located overseas or in Singapore:

(a) our service providers and contractors, including third party vendors that provide services to us, including, without limitation, IT-service providers, data processing or management services and for compliance with applicable laws and regulations;

(b) any business partner, investor, assignee or transferee (actual or prospective) to facilitate business asset transactions (which may extend to any merger, acquisition or asset sale);

(c) our subsidiaries, affiliates and/or partners (and in particular, where you have consented to receiving information/newsletters from us);

(d) law enforcement authorities, regulatory authorities, statutory bodies or public agencies for the purposes of complying with their requirements, policies, directives or requests;

(e) banks, credit agencies and other financial and/or payment service providers;

(f) our professional advisers such as our board of directors, auditors and lawyers;

(g) external business and charity partners in relation to corporate promotional events; and/or

(h) any other party to whom you authorise us to disclose your Personal Data to.

4.2 We may share information about you in aggregate or anonymised form with the abovementioned entities or parties (e.g. our business partners).

Withdrawal of Consent

5.1 The consent that you provide for the collection, use and disclosure of your Personal Data will remain valid until such time it is being withdrawn by you in writing. You may withdraw consent and request us to stop collecting, using and/or disclosing your Personal Data for any or all of the purposes listed above by submitting your request in writing or via email to our Data Protection Officer at the contact details provided below and filling in our Withdrawal of Consent Request Form (which will be provided by our Data Protection Officer).

5.2 Upon receipt of the completed Withdrawal of Consent Request Form with the required supporting documents, we may require reasonable time (depending on the complexity of the request and its impact on our relationship with you) for your request to be processed and for us to notify you of the consequences of us acceding to the same, including any legal consequences which may affect your rights and liabilities to us. In general, we shall endeavour to process your request within thirty (30) business days of receiving and verifying your identification and documentation.

5.3 Whilst we respect your decision to withdraw your consent, please note that depending on the nature and scope of your request, we may not be in a position to continue providing our goods or services to you and we shall, in such circumstances, notify you before completing the processing of your request. Should you decide to cancel your withdrawal of consent, please inform us in writing or via email by contacting our Data Protection Officer at the contact details provided below.

5.4 Please note that withdrawing consent does not affect our right to continue to collect, use and disclose Personal Data where such collection, use and disclose without consent is permitted or required under applicable laws.

Transfers of Personal Data

6.1 We will not transfer your Personal Data to external third parties (other than to our subsidiaries and affiliates) in or outside Singapore unless the parties receiving the Personal Data agree to comply with the PDPA or to adopt data protection standards comparable to the PDPA when processing the Personal Data, or when the transfer is permitted under applicable laws.

Retention of Personal Data

7.1 We may retain your Personal Data for as long as it is necessary to fulfil the purpose for which it was collected, or as required or permitted by applicable laws.

7.2 We will cease to retain your Personal Data, or remove the means by which the data can be associated with you, as soon as it is reasonable to assume that the purpose for which the Personal Data was collected is no longer being served by such retention, and such retention is no longer necessary for legal or business purposes.

IP Addresses/Cookies

8.1 When you use our website, we may collect and store information about your computer or other electronic devices (including your IP address, operating system and browser type) for system administration. This is statistical data about the browsing actions and patterns of users of our website. This data could possibly lead to your identification, but we, and our data intermediaries, do not use it to do so unless required to do so or otherwise authorised or permitted by law.

8.2 Cookies are small files which are stored in your computer or other electronic devices when you access a website – amongst other things; they help the website user to navigate efficiently between pages and the website operator to track usage of the site. Cookies cannot contain viruses or anything else that might harm your computer or other electronic devices. You can find out more about cookies at www.allaboutcookies.org.

8.3 Our website uses cookies to distinguish you from other users of our website and mobile applications by storing information on your computer or other electronic devices, including without limitation, session information such as the number of times you visit our website and the location from which you are accessing the website. While some limited information is personally identifiable for the purposes of managing your experience on the website, any other information is anonymised and aggregated to produce statistical reports that enable us to evaluate the use of our website, and to make improvements to, and increase efficiency when you browse our website. If you wish to disable cookies on your computer or other electronic devices, you may do so by changing your browser settings. Please note that changing these settings may limit the functionality of some web pages or prevent them from loading properly. Additionally, the major browsers have attempted to implement the draft “Do Not Track” (DNT) standard of the World Wide Web Consortium in their latest releases. As this standard has not been finalised, the website is not compatible with DNT and does not process DNT messages.

Protection of Personal Data

9.1 We use technical and organisational security precautions, including that of our data intermediaries, to protect your Personal Data from unauthorised access, collection, use, disclosure, copying, modification, disposal or similar risk, as well as the loss of any storage medium or device on which Personal Data is stored. Our security procedures are reviewed on a regular basis based on new technological developments.

9.2 Although every reasonable effort has been made to ensure that all Personal Data will be protected, we cannot be responsible for any unauthorised use or misuse of such information and damage arising from risks which are inherent in all internet communications.

Links to third party websites from the Company’s website

10.1 Our website(s) may contain links to other external websites. We are not responsible for the privacy policies and practices of such external websites which are under the care of third parties. We strongly encourage you to check the privacy policy of each website that you visit. Some of these third-party websites may have our logo or trademark acknowledged on their website. However, these websites are not operated and maintained by us. Please contact the owner of the respective websites should you have any questions on their privacy policies.

Accuracy of Personal Data

11.1 We generally rely on Personal Data provided by you (or your authorised representative). In order to ensure that your Personal Data is current, complete and accurate, please update us if there are changes to your Personal Data by informing our Data Protection Officer in writing or via email at the contact details provided below.

Access and Correction of Personal Data

12.1 If you wish to make (a) an access request for access to a copy of the Personal Data which we hold about you or information about the ways in which we use or disclose your Personal Data, or (b) a correction request to correct or update any of your Personal Data which we hold, you may submit your request in writing or via email to our Data Protection Officer at the contact details provided below.

12.2 Please note that a reasonable fee may be charged for an access request. If so, we will inform you of the fee before processing your request.

12.3 We will respond to your request as soon as reasonably possible. In general, our response will be within thirty (30) business days. Should we not be able to respond to your access request within thirty (30) days after receiving your access request, we will inform you in writing within thirty (30) days of the time by which we will be able to respond to your request. If we are unable to provide you with any Personal Data or to make a correction requested by you, we shall generally inform you of the reasons why we are unable to do so (except where we are not required to do so under applicable law).

12.4 Please note that depending on the request that is being made, we will only need to provide you with access to the Personal Data contained in the documents requested, and not to the entire documents themselves. In those cases, it may be appropriate for us to simply provide you with confirmation of the Personal Data that our organisation has on record, if the record of your Personal Data forms a negligible part of the document.

Data Protection Officer

13.1 You may contact our Data Protection Officer via email (dpo@temasektrust.org.sg) if you have any enquiries or feedback on our Personal Data protection policies and procedures, or if you wish to make any request.

Effect of Statement and Changes to Statement

14.1 This Statement applies in conjunction with any other policies, procedures, standards, notices, contractual obligations and consents that apply in relation to the collection, use and disclosure of your Personal Data by us.

14.2 We may update this Statement from time to time by posting the updated version on our website(s) and, where required by applicable law, notifying you of the same via other forms of communication. The revised version of this Statement will be effective once posted and you agree to be bound by the prevailing Statement as may be updated from time to time on our website or as you may be notified. Please review this page for updated information on our policies and practices regarding the handling of your Personal Data.

ANNEX – EU and UK Supplement

A.1 Scope and Application of this Annex

A.1.1 This Annex applies to individuals in the EU and/or UK. It describes your data protection rights, including the right to object to some of the processing which we carry out. More information about your rights, and how to exercise them, is set out in the “Your choices and rights” section. Where there is any conflict between this Annex and the main body of this Statement, the provisions of this Annex shall prevail in respect of EU and UK individuals.

A.1.2 The following sections of this Statement do not apply to individuals in the EU or UK: Sections 1.2-1.3, 5, 6 &13. The corresponding provisions applicable to EU and UK individuals are set out in this Annex in their place.

A.1.3 All other sections of this Statement continue to apply to EU and UK individuals to the extent they are consistent with, and do not conflict with, the provisions of this Annex and applicable EU and UK data protection law.

A.1.4 The data controller in respect of your Personal Data is Co-Axis Marketplace Pte. Ltd.. We do not have an establishment in the United Kingdom or the European Union, therefore, we have appointed local representatives, Bird & Bird GDPR Representative Services SRL for EU and Bird & Bird GDPR Representative Services UK for UK. Our UK & EU representatives can be contacted directly by emailing them at the following address EUrepresentative.co-axis@twobirds.com or UKrepresentative.co-axis@twobirds.com.

A.2 Legal Bases for Processing

A.2.1 The lawful bases we rely upon are as follows:

PurposeLawful Basis
(a) Administering our website(s)Our legitimate interest in managing our organisation and providing and improving our services.
(b) To perform or carry out our obligations arising from any contracts entered between you and usNecessary to perform a contract with you or to take steps at your request prior to entering into a contract with you.
(c) For conducting due diligence (including but not limited to financial / commercial / impact due diligence), AML, KYC and other background checksNecessary to perform a contract with you or to take steps at your request prior to entering into a contract with you. Where contractual necessity doesn’t apply, we rely on our legitimate interests in managing our organisation and providing and improving our services or in ensuring the security and integrity of our organisation. In the UK, this is a recognised legitimate interest when we do this to prevent, detect, or investigate a crime. Where this involves processing biometric data, we rely on the substantial public interest condition.
(d) For client administration, services requests enquiries, and sending newslettersConsent where required under EU and/or UK data protection law. If consent is not required, we rely on our legitimate interests in managing our organisation and providing and improving our services.
(e) For payment administration purposesNecessary to perform a contract with you or to take steps at your request prior to entering into a contract with you. Where contractual necessity doesn’t apply, we rely on our legitimate interests in managing our organisation and providing and improving our services.
(f) To respond to, handle and process your enquiries, requests, applications, complaints, and feedbackNecessary to perform a contract with you or to take steps at your request prior to entering into a contract with you. Where contractual necessity doesn’t apply, we rely on our legitimate interests in managing our organisation and providing and improving our services.
(g) To comply with obligations under applicable laws and related subsidiary legislation, regulations, guidelines and directionsOur legitimate interest in ensuring the security and integrity of our organisation. In the UK, this is a recognised legitimate interest when we do this to prevent, detect, or investigate a crime.
(h) For recruitment and evaluation purposes if you apply for a job with usNecessary to perform a contract with you or to take steps at your request prior to entering into a contract with you. Where contractual necessity doesn’t apply, we rely on our legitimate interest to identify and evaluate suitable candidates to work at our organisation.
(i) To follow up and liaise with event attendees and users of Temasek Shophouse premises, facilitate access controls and security clearances, and other event management and administration mattersConsent where required under EU and/or UK data protection law. If consent is not required, we rely on our legitimate interest in: understanding customer preferences and improving our products, services, and communications; managing our organisation; ensuring the security and integrity of our organisation. In the UK, this is a recognised legitimate interest when we do this to prevent, detect, or investigate a crime.
(j) For integrating mentors and volunteers into the Company's programmesOur legitimate interests in managing our organisation and providing and improving our services.
(k) For travel arrangement and insurance purposesNecessary to perform a contract with you or to take steps at your request prior to entering into a contract with you. Where contractual necessity doesn’t apply, we rely on our legitimate interests in managing our organisation and providing and improving our services.
(l) For internal reporting and/or accounting purposesOur legitimate interest in ensuring the security and integrity of our organisation. In the UK, this is a recognised legitimate interest when we do this to prevent, detect, or investigate a crime.
(m) For compiling statistics, whether for our own use or for industry exercises and studies, to design and improve our products and servicesOur legitimate interests in managing our organisation and providing and improving our services.
(n) To enhance security, monitor and verify identity or service access (including facial recognition), combat spam or other malware or security risksOur legitimate interest in ensuring the security and integrity of our organisation. In the UK, this is a recognised legitimate interest when we do this to prevent, detect, or investigate a crime. Where this involves processing biometric data, we rely on the substantial public interest condition.
(o) To send information including confirmations, technical notices, updates, security alerts, and support and administrative messagesOur legitimate interests in managing our organisation and providing and improving our services.
(p) Conducting market research, understanding and analysing customer behaviour, location, preferences and demographicsConsent where required under EU and/or UK data protection law. If consent is not required, we rely on our legitimate interests in managing our organisation and providing and improving our services.
(q) To investigate or obtain evidence concerning any complaint, claim or dispute or any actual or suspected illegal or unlawful conduct, or to aid law enforcement or regulatory authoritiesOur legitimate interest in ensuring the security and integrity of our organisation. In the UK, this is a recognised legitimate interest when we do this to prevent, detect, or investigate a crime.
(r) Any other purposes for which you have provided the information; and/orN/A
(s) Purposes incidental to one or more of the aboveN/A

A.2.2 There are instances where we rely on our legitimate interests to process your Personal Data. The specific legitimate interest will vary depending on the purpose of the processing, and we have outlined above what those interests are and how they relate to the relevant processing activities. Where we process personal data on the basis of a legitimate interest, then - where required by EU and UK data protection law - we have carried out a balancing test to document our interests, to consider what the impact of the processing will be on individuals and to determine whether individuals interests outweigh our interests in the processing taking place. You can request further information about this balancing test by contacting us using the details listed above.

A.2.3 In the UK, we are not required to conduct a balancing test where the processing is based on a “recognised legitimate interest.” When we rely on our legitimate interest in ensuring the security and integrity of our organisation, and the processing is carried out to prevent, detect, or investigate crime, this constitutes a such recognised legitimate interest.

A3 Mechanisms to transfer your Personal Data

We may transfer Personal Data to service providers and business partners in the US who participate in the US Data Privacy Framework; service providers and business partners in Singapore, the Philippines, and other jurisdictions that rely on approved standard contractual clauses (module 1 or 2 depending on nature of relationship); and business partners and service providers who rely on Binding Corporate Rules. A copy of the relevant mechanism can be obtained for your review on request by using the contact details also provided above.

A4 Your Choices and Rights

A.4.1 You have the following rights: 

RightSummary
The right of access Enables you to receive a copy of your Personal Data 
The right to rectification  Enables you to correct any inaccurate or incomplete Personal Data we hold about you 
The right to erasure  Enables you to ask us to delete your Personal Data in certain circumstances 
The right to restrict processing Enables you to ask us to halt the processing of your Personal Data in certain circumstances 
The right to object  Enables you to object to our processing of your Personal Data where we rely on our legitimate interests (or those of a third party), including for direct marketing purposes or profiling related to direct marketing. You may also object where we process your Personal Data to perform a task carried out in the public interest. If you exercise this right, we will stop processing your Personal Data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or where the processing is necessary for the establishment, exercise or defence of legal claims.
The right to data portability  Enables you to request us to transmit Personal Data that you have provided to us, to a third party without hindrance, or to give you a copy of it so that you can transmit it to a third party, where technically feasible 

A.4.2 These rights may be limited, for example if fulfilling your request would reveal Personal Data about another person, or if you ask us to delete information which we are required by law or have compelling legitimate interests to keep.  If you wish to exercise any of these rights, please email dpo@temasektrust.org.sg.

A.4.3 Wherever we rely on your consent, you have the right to withdraw that consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal. We may however have other legal grounds for processing your data for other purposes, such as those set out above.  

A.4.4 In some cases, we are able to send you direct marketing without your consent, where we rely on our legitimate interests.  You have an absolute right to opt-out of direct marketing, or profiling we carry out for direct marketing, at any time. You can do this by following the instructions in the communication where this is an electronic message, or by emailing dpo@temasektrust.org.sg. 

A.4.5 If you have unresolved concerns, you have the right make a complaint to us and to the data protection authority in the country that you reside in or, the country of your place of work or the country where the alleged infringement took place. For information on how to exercise your right to do this please email dpo@temasektrust.org.sg. A list of authorities in the EU can be found here. In the UK, this will be the Information Commissioner.

A.4.6 Where we collect Personal Data to comply with our legal obligations, this is mandatory. In all other cases, provision of the requested Personal Data is optional, but this may affect your ability to participate in certain programs or systems, where the information is needed for those purposes.

This website uses cookies to enhance the user experience.
For more information, please read our Privacy Statement.