How Ploutos Management collects, uses and discloses personal data, in accordance with Singapore's Personal Data Protection Act.
This Data Protection Notice ("Notice") sets out the basis on which Ploutos Management Pte. Ltd. and our licensed affiliate Ploutos Consulting & Advisory Pte. Ltd. (together, "we", "us" or "our") collect, use, disclose or otherwise process personal data, in accordance with the Personal Data Protection Act ("PDPA"). This Notice applies to personal data in our possession or under our control, including personal data in the possession of organisations we have engaged to process personal data on our behalf.
As used in this Notice, "customer" means an individual who has contacted us to enquire about our services, or who may, or has, engaged us for the supply of any services; and "personal data" means data, whether true or not, about a customer who can be identified from that data, or from that data together with other information to which we have or are likely to have access.
Depending on the nature of your interaction with us, personal data we collect may include your name, contact details, nationality, date of birth, employment and financial information, and identification numbers. Identification numbers such as NRIC or FIN are collected and retained only where required or permitted by law.
We generally do not collect personal data unless it is provided voluntarily, directly or via a duly authorised representative, after you have been notified of the purpose of collection and have given consent — or where collection without consent is permitted or required by the PDPA or other law.
We may collect, use and disclose your personal data for purposes including: performing our obligations in connection with the services you have requested from us; verifying your identity and performing due diligence; responding to and managing your queries, requests and feedback; managing our relationship with you; preparing and filing documents with the relevant authorities on your behalf where engaged to do so; complying with applicable laws, regulations, codes of practice or guidelines, or assisting in investigations by any governmental or regulatory authority; and other purposes reasonably related to the above, or for which you have separately provided your information.
We may disclose your personal data to our professional advisers, service providers and agents engaged to support the above purposes, and to relevant government or regulatory authorities where required by law.
Some of our services may involve transferring personal data outside Singapore — for example, to comply with regulatory reporting obligations, or where we engage service providers whose systems are hosted overseas. Where this occurs, we take steps to ensure the data continues to receive a standard of protection comparable to that required under the PDPA.
Consent you provide remains valid until withdrawn in writing. You may withdraw consent and request that we stop collecting, using or disclosing your personal data by writing to our Data Protection Officer at the contact details below. We aim to process such requests within five (5) business days, though depending on the nature of your request, withdrawing consent may mean we are no longer able to continue providing services to you — we will notify you of any such consequence before completing your request.
You may request access to, or correction of, the personal data we hold about you by writing to our Data Protection Officer. A reasonable fee may apply to access requests, which we will inform you of in advance. We aim to respond within five (5) business days, and in any case within thirty (30) days of your request.
In the event of a data breach that is likely to result in significant harm to affected individuals, or that is of a significant scale, we will assess and, where required under the PDPA, notify the Personal Data Protection Commission and affected individuals as soon as practicable, in accordance with our data breach management procedures.
We have put in place administrative, physical and technical measures to safeguard personal data against unauthorised access, collection, use, disclosure or similar risks, and disclose personal data internally and to authorised third parties on a need-to-know basis. No method of transmission or storage is completely secure, but we regularly review and enhance our security measures.
We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required under applicable law — including statutory record-keeping periods under the Companies Act, Income Tax Act, GST Act and the Corporate Service Providers Act. We cease to retain personal data, or anonymise it, once it is no longer necessary for these purposes.
If you have any enquiries, feedback, or requests relating to this Notice or your personal data, please contact our Data Protection Officer:
Email: info@ploutosmanagement.net
If you are not satisfied with our response, you may lodge a complaint with the Personal Data Protection Commission at pdpc.gov.sg.
We may revise this Notice from time to time. The date of the last update is shown at the top of this page. Your continued engagement of our services after any revision constitutes acknowledgement of the updated Notice.