Privacy notice: Singapore
Applies together with the main Privacy Policy. Governing privacy law: Personal Data Protection Act 2012.
Version 2026-10-08 · Effective 8 October 2026 · IAEX NETWORK (proprietor: Abhishek Tiwari)
This notice supplements Part A for individuals in Singapore and is our personal-data protection policy under the Personal Data Protection Act 2012 ("PDPA"). It also applies to Singapore-based businesses' individual directors, shareholders, beneficial owners and contacts whose personal data we process.
Data Protection Officer
Our Data Protection Officer is Abhishek Tiwari, connect@iaexnetwork.com, reachable at connect@iaexnetwork.com for any question about this policy, access and correction requests, withdrawal of consent, and complaints.
How we apply the PDPA obligations
| PDPA obligation | What we do |
|---|---|
| Consent | We collect, use and disclose personal data with your consent, or where deemed consent applies (data you give to carry out a transaction you requested, or necessary to perform a contract), or where the PDPA excepts consent (for example legal obligations, investigations, and legitimate interests such as fraud prevention where we have assessed the impact and benefit). You can withdraw consent by giving us reasonable notice, usually 10 business days; we tell you the consequences. |
| Purpose limitation and notification | We use data only for the purposes in Part A, section 3, which a reasonable person would consider appropriate, and tell you before any new purpose. |
| Access and correction | On request we give you your personal data held by us and how it was used or disclosed in the past year, within 30 days, and correct errors as soon as practicable, usually within 30 days, sending the correction to organisations we disclosed the data to in the past year, unless they do not need it. We may charge a reasonable fee for access and tell you first. |
| Accuracy | We take reasonable steps to keep data accurate and complete, and you can update it in your account. |
| Protection | Reasonable security arrangements: encryption of documents and identifiers, access controls, logging, staff confidentiality. |
| Retention limitation | We stop retaining data, or de-identify it, once the purpose is served and retention is no longer needed for legal or business purposes (Part A, section 6), e.g. 5 years for anti-money-laundering records. |
| Transfer limitation | We transfer data outside Singapore only if the recipient is bound by legally enforceable obligations, such as contracts, to give it a standard of protection comparable to the PDPA. |
| Data breach notification | We assess a suspected breach promptly; if it is likely to cause significant harm or is of significant scale we notify the Personal Data Protection Commission as soon as practicable and no later than 3 calendar days after our assessment, and affected individuals as soon as practicable. |
| Accountability | This policy, a designated DPO, a complaint process and staff training. |
National registration numbers
We collect NRIC, FIN or other national identification numbers, or copies of those documents, only where the law requires it or where it is necessary to establish or verify identity to a high degree of fidelity. We mask them when displayed.
Marketing messages
We send marketing email only with your consent and do not send marketing calls or text messages, so the Do Not Call Registry rules are not triggered. You can unsubscribe at any time.
Complaints
Write to our DPO first. If you are not satisfied, you may complain to the Personal Data Protection Commission Singapore (pdpc.gov.sg).
Financial regulation
Money for Singapore customers is held and moved by partners licensed under the Payment Services Act 2019; Vaulte does not hold money. We apply Singapore anti-money-laundering record-keeping requirements (5 years) and MAS sanctions notices to our screening.