Privacy Policy
Home / Privacy Policy
External Data Protection Policy
1 Introduction
We at YCH respect the privacy and confidentiality of the personal data of our Clients, Customers, Visitors and others whom we interact with in the course of providing our services. We are committed to implementing policies, practices and processes to safeguard the collection, use and disclosure of the personal data you provide us, in compliance with the Singapore Personal Data Protection Act (PDPA) 2012.
We have developed this Data Protection Policy to assist you in understanding how we collect, use, disclose, process and retain your personal data with us.
2 How We Collect Your Personal Data
The PDPA defines personal data as “data, whether true or not, about an individual who can be identified (a) from that data; or (b) from that data and other information to which the organisation has or is likely to have access.”
We collect your personal data when you:
- leave your personal and contact details with us when you use our services;
- leave your contact details with us after visiting our websites;
- interact with our Employees e.g. via telephone calls, faxes, text messages, face-to-face meetings or emails;
- are referred to us by one of our clients or customers;
- submit your CV and job application form to us in response to our recruitment advertisements;
- submit your CV to recruitment firms or job portals, which are in turn forwarded to or retrieved by us;
- register at the guardhouse and reception when you visit our physical premises;
- communicate with us via emails or written correspondences; and
- provide feedback or make a complaint to us.
3 Types of Personal Data We Collect About You
The types of personal data we collect about you include:
- Personal contact information;
- Personal particulars;
- Photos and video footages;
- Educational and professional qualifications – for job applicants;
- Work experience – for job applicants; and
- Financial information – for payment of salaries and reimbursement of claims.
4 How We Use Your Personal Data
We use the personal data you provide us for one or more of the following purposes:
- Facilitate provision of services
- Order fulfilment
- Respond to queries and feedback and provide customer service and support
- Crime prevention and employee safety
- Process directors’ resolutions and declarations
- Process job applications, recruitment and selection
- Comply with legal obligations and regulatory requirements
5 Who We Disclose Your Personal Data To
We disclose some of the personal data you provide us to the following parties or organisations outside YCH in order to fulfil our services to you:
- Banks;
- Insurance companies;
- Government agencies e.g. Central Provident Fund Board, Ministry Of Manpower, Inland Revenue Authority of Singapore, Workforce Development Agency;
- Cloud and web-hosting service providers;
- Other External service providers (travel agents, security firms, transport service providers,)
Where required to do so by law, we will disclose personal data about you to the relevant authorities or to law enforcement agencies.
We may also share some of your personal data, after they are anonymised, with third parties for research purposes in order to improve our products and services to you.
6 How We Manage the Collection, Use and Disclosure of Your Personal Data
6.1 Obtaining Consent
Before we collect, use or disclose your personal data, we will notify you of the purpose why we are doing so. We will obtain written confirmation from you on your expressed consent. We will not collect more personal data than is necessary for the stated purpose.
Under certain circumstances, we may assume deemed consent from you when you voluntarily provide your personal data for the stated purpose, e.g. when you apply for a job with us using our job application forms.
YCH may rely on the legitimate interests exception to collect, use and disclose personal data without consent where the identified legitimate interests outweigh any adverse effect on the individual.
We may collect, disclose or use your personal data pursuant to an exception under the Personal Data Protection Act or other written law such as during the following situations:
- To respond to an emergency that threatens your life, health and safety or of another individual; and
- Necessary in the national interest, for any investigation or proceedings
6.2 Withdrawal of Consent
If you wish to withdraw consent, you should give us reasonable advance notice. We will advise you of the likely consequences of your withdrawal of consent, e.g. without your personal contact information we may not be able to inform you of future services offered by us.
6.3 Use of Cookies
We use “cookies” to collect information about your online activity on our website. A cookie is a small text file created by the website that is stored in the user’s computer to provide a way for the website to recognise you and keep track of your preferences. The cookie makes it convenient for you such that you do not have to retype the same information again when you revisit the website or in filling electronic forms.
Most cookies we use are “session cookies”, which will be deleted automatically from the hard disk of your computer at the end of the session.
You may choose not to accept cookies by turning off this feature in your web browser.
Note that by doing so, you may not be able to use some of the features and functions in our web application.
7 How We Ensure the Accuracy of Your Personal Data
We will take reasonable precautions and verification checks to ensure that the personal data you provide us is accurate, complete and up-to-date. From time to time, we may do a data verification exercise with you to update us on any changes to your personal data.
8 How You Can Access and Make Correction to Your Personal Data
You may write-in to us to find out how we have been using or disclosing your personal data over the past one year. Before we accede to your request, we may need to verify your identity by checking your NRIC or other legal identification document. We will try to respond to your request as soon as possible, or within 30 days, as stipulated in the PDPA. If we are unable to do so within the 30 days, we will let you know and give you an estimate of how much longer we require. We may also charge you a reasonable fee for the cost involved in processing your access request.
You may also ask us to correct an error or omission in the personal data we hold about you. We will correct the personal data as soon as practicable (including informing third parties), or within 30 days, unless we are satisfied on reasonable grounds that a correction should not be made.
9 How We Protect Your Personal Data
We have implemented appropriate information security measures (such as data encryption, firewalls and secure network protocols) to protect the personal data you provide us against unauthorised access, use, disclosure, or similar risks. We will take reasonable and appropriate measures to maintain the confidentiality and integrity of your personal data, and will only share your data with authorised persons on a ‘need to know’ basis.
For personal data that our vendors collected on our behalf, the process owners will request our 3rd parties vendors to comply and take reasonable and appropriate measures to maintain the confidentiality and integrity of the personal data. We will review to check on 3rd parties vendors during yearly assessment & evaluation on their self declaration compliance.
10 How We Retain Your Personal Data
We have a document retention policy that keeps track of the retention schedules of the personal data you provide us, in paper or electronic forms. We will not retain any of your personal data when it is no longer needed for any business or legal purposes. We will dispose of or destroy such documents containing your personal data in a proper and secure manner.
11 Transfer of Personal Data Outside of Singapore
We generally do not transfer your personal data to countries outside of Singapore. However, if we do so, we will obtain your consent for the transfer to be made and we will take steps to ensure that your personal data continues to receive a standard of protection that is at least comparable to that provided under the PDPA.
12 Data Breach Notification
In the event a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data, we shall promptly assess the impact and if appropriate, report this breach within 3 calendar days to the Personal Data Protection Commission (PDPC). We will notify you when the data breach is likely to result in significant harm to you after our notification to PDPC. We may also notify other relevant regulatory agencies, where required. If we are a Data Intermediary, we shall inform the Data Controller immediately of any data breach so they can promptly assess the impact and comply with their data breach notification obligation.
13 Contacting Us
If you have any query or feedback regarding this Policy, or any complaint you have relating to how we manage your personal data, you may contact our Data Protection Officer (DPO) at: dataprotection@ych.com
Any query or complaint should include, at least, the following details:
- Your full name and contact information
- Brief description of your query or complaint
We treat such queries and feedback seriously and will deal with them confidentially and within reasonable time.