A. Who We Are?
B. What Is The Purpose Of This Policy?
3. We take our responsibilities under Singapore’s Personal Data Protection Act (the “PDPA”) seriously. We also recognise the importance of the personal data you have entrusted to us and believe that it is our responsibility to properly manage, protect and process your personal data.
C. What Information Do We Collect?
4. “Personal data” is defined under the PDPA to mean data, whether true or not, about an individual who can be identified from that data, or from that data and other information to which an organisation has or is likely to have access. ROH collects information about you when you use our mobile application, websites and other online products and services and throughout other interactions and services you have with us. Personal data which we may collect include:
• Home Address
• Contact Information
We will collect your personal data in accordance with the PDPA.
5. We may also collect and store certain information automatically when you visit the Site. Examples include the internet protocol (IP) address used to connect your computer or device to the internet, connection information such as browser type and version, your operating system and platform, a unique reference number linked to the data you enter on our system, login details, the full URL clickstream to, through and from the Site (including date and time), cookie number and your activity on our Site, including the pages you visited, the searches you made and, if relevant, the services you purchased or donations you made.
6. We may receive information about you from third parties if you use any websites or social media platforms operated by third parties (for example, Facebook, Instagram, Twitter etc.) and, if such functionality is available, you have chosen to link your profile on the Site with your profile on those other websites or social media platforms.
8. A cookie is a small file of letters and numbers that we store on your browser or the hard drive of your computer or device.
9. You can block or deactivate cookies in your browser settings.
10. We use log-in cookies in order to remember you when you have logged in for a seamless experience.
11. We use session cookies to track your movements from page to page and in order to store your selected inputs so you are not constantly asked for the same information.
12. This Site uses Google Analytics which is one of the most widespread and trusted analytics solution on the web for helping us to understand how you use the Site and ways that we can improve your experience. These cookies may track things such as how long you spend on the Site and the pages that you visit so we can continue to produce engaging content.
14. For further information on types of cookies and how they work visit www.allaboutcookies.org
E. The Purposes for Which We Collect, Use Or Disclose Your Personal Data
15. ROH will/may collect, use, disclose and/or process your personal data for one or more of the following purposes:
(a) Administering, facilitating, processing and/or dealing in any matters relating to your use of the App or the Site;
(b) Monitoring, processing and/or tracking your use of the App or the Site in order to provide you with a seamless experience, facilitating or administering your use of the App or the Site, and/or to assist us in improving your experience in using the App or the Site;
(c) Assessing, administering, processing and/or managing your donation(s);
(d) Assessing and processing your request for the purchase of and/or subscription to our products and/or services;
(e) Registering you as a donor of ROH; and/or to deal with, process and/or administer the account that you may open with us, including to facilitate your transactions or activities on the Site, or your transactions or activities with us;
(f) Administering, facilitating and/or dealing with your relationship with us;
(g) Administering, facilitating, processing and/or dealing in (i) any transactions, activities carried out by you in the App or on the Site or with us, or (ii) your donations to us;
(h) Carrying out your instructions or responding to any enquiry given by (or purported to be given by) you or on your behalf;
(i) contacting you or communicating with you via phone/voice call, text message and/or fax message, email and/or postal mail for the purposes of administering and/or managing your use of the App or Site, your account with us, your relationship with us or any transactions or donation(s) made by you with us. You acknowledge and agree that such communication by us could be by way of the mailing of correspondence, documents or notices to you, which could involve disclosure of certain personal data about you to bring about delivery of the same as well as on the external cover of envelopes/mail packages
(j) carrying out due diligence or other screening activities (including background checks) in accordance with legal or regulatory obligations (whether Singapore or foreign country) applicable to us or our affiliates/associated companies, the requirements or guidelines of governmental authorities (whether Singapore or foreign country) which we determine are applicable to us or our affiliates/associated companies, and/or our risk management procedures that may be required by law (whether Singapore or foreign country) or that may have been put in place by us or our affiliates/associated companies;
(k) to prevent or investigate any fraud, unlawful activity or omission or misconduct, whether or not there is any suspicion of the aforementioned; dealing with conflict of interests; or dealing with and/or investigating complaints;
(l) complying with or as required by any applicable law, governmental or regulatory requirements of any jurisdiction applicable to us or our affiliates/associated companies, including meeting the requirements to make disclosure under the requirements of any law binding on us or our affiliates/associated companies, and/or for the purposes of any guidelines issued by regulatory or other authorities (whether of Singapore or elsewhere), with which we or our affiliates/associated companies are expected to comply;
(m) complying with or as required by any request or direction of any governmental authority (whether Singapore or foreign country) which we are expected to comply with; or responding to requests for information from public agencies, ministries, statutory boards or other similar authorities (including but not limited to the Commissioner of Charities, Inland Revenue Authority of Singapore) (whether Singapore or foreign country). For the avoidance of doubt, this means that we may/will disclose your personal data to the aforementioned parties upon their request or direction;
(n) conducting research, surveys, market surveys, analysis and/or development activities (including but not limited to data analytics, surveys and/or profiling) to improve our services and facilities, or to improve our understanding of your interests, concerns and preferences, in order to enhance any continued interaction between yourself and us connected or in relation to the Site, or improve any of our products or services or your relationship with us. Without limiting the generality of the foregoing, we may/will in this regard send you surveys by way of email or postal mail;
(o) storing, hosting, backing up (whether for disaster recovery or otherwise) of your personal data, whether within or outside Singapore;
(p) facilitating, dealing with and/or administering external audit(s) or internal audit(s) of the business of ROH;
(q) for marketing purpose if you have separately consented to it, and in this regard, we would be providing you by way of postal mail, electronic transmission to your email address(es), voice call, SMS/MMS or fax, depending on the mode of communication you have consented to, with marketing, advertising and promotional information, materials and/or documents relating to products and/or services (including products and/or services of third party organisations whom ROH may collaborate or tie up with) that ROH (including its affiliates/related corporations) or such third party organisations may be selling, marketing, offering or promoting, whether such products or services exist now or are created in the future;
(r) dealing with and/or facilitating a business asset transaction or a potential business assert transaction, where such transaction involves ROH as a participant or involves only a related corporation or affiliated company of ROH as a participant or involves ROH and/or any one or more of ROH’s related corporations or affiliated companies as participant(s), and there may be other third party organisations who are participants in such transaction. “business asset transaction” means the purchase, sale, lease, merger or amalgamation or any other acquisition, disposal or financing of an organisation or a portion of an organisation or of any of the business or assets of an organisation;
(s) anonymisation of your personal data. In this regard, you acknowledge that personal data that has been anonymised is no longer personal data and the requirements of the PDPA would no longer apply to such anonymised data; and
(t) record-keeping purposes and producing statistics and research for internal and/or statutory reporting and/or record-keeping requirements, of ROH or of its affiliates/related corporations;
(the purposes set out in this paragraph  above shall be collectively referred to as the “Purposes”)
16. ROH may/will need to disclose your personal data to third parties, whether located within or outside Singapore, for one or more of the above Purposes, as such third parties, would be processing your personal data for one or more of the above Purposes. In this regard, you hereby acknowledge, agree and consent that we may/are permitted to disclose your personal data to such third parties (whether located within or outside Singapore) for one or more of the above Purposes and for the said third parties to subsequently collect, use, disclose and/or process your personal data for one or more of the above Purposes. Without limiting the generality of the foregoing or of paragraph 15, such third parties include :
(a) our associated or affiliated organisations or related corporations;
(b) any of our agents, contractors or third party service providers that process or will be processing your personal data on our behalf including but not limited to those which provide administrative or other services to us such as mailing houses, telecommunication companies, information technology companies, marketing companies, call centers and data centers;
(c) banks, credit card companies and/or third parties to process and/or deal with your donation(s); and
(d) third parties to whom disclosure by ROH is for one or more of the Purposes and such third parties would in turn be collecting and processing your personal data for one or more of the Purposes.
17. We may share your information with any member of our group (which means our affiliates, related corporations or associated organisations), if any, from time to time for one or more of the Purposes.
18. You may withdraw your consent for the collection, use and/or disclosure of your personal data in our possession or under our control by emailing us at email@example.com. We will process your request 48hrs from such a request for withdrawal of consent being made, and will thereafter not collect, use and/or disclose your personal data in the manner stated in your request, unless an exception under the law or a provision in the law permits us to. However, your withdrawal of consent could result in certain legal consequences arising from such withdrawal, including us being unable to perform the transactions requested by you or result in the termination of our relationship.
19. We may collect, use, disclose or process your personal data for other purposes that do not appear above. However, we will notify you of such other purpose at the time of obtaining your consent, unless processing of your personal data without your consent is permitted by the PDPA or by law.
20. To the extent permitted by law, we may/will also be collecting from sources other than yourself, personal data about you, for one or more of the above Purposes, and thereafter using, disclosing and/or processing such personal data for one or more of the above Purposes. We may combine information we receive from other sources with information you give to us and information we collect about you. We may use this information and the combined information for the Purposes set out above (depending on the types of information we receive).
21. Making A Donation. Your credit/debit card information is collected by third-party payment vendor MS Payment mcpayment.com. This use of your information is based on their terms of service and policies, which you should review. We do not collect or have access to the credit/debit card information our third-party payment vendor MC Payment collects to process online transactions.
F. Provision Of Third Party Personal Data By You
22. Should you provide ROH with personal data of individual(s) other than yourself, you represent and warrant to ROH and you hereby confirm that:
(a) prior to disclosing such personal data to us, you would have and had obtained consent from the individuals whose personal data are being disclosed to us, to:
(i) permit you to disclose the individuals’ personal data to ROH for the Purposes; and
(ii) permit ROH to collect, use, disclose and/or process the individuals’ personal data for the Purposes, as set out in paragraph  above;
(b) any personal data of individuals that you disclose to us is accurate; and
(c) you are validly acting on behalf of such individuals and that you have the authority of such individuals to provide their personal data to ROH and for ROH to collect, use, disclose and process such personal data for the Purposes.
G. How Do We Store Data?
23. Security of your personal data is important to us. We take appropriate action to protect personal data from loss, misuse, unauthorised access or disclosure, alteration or destruction using the same safeguards as we use for our own proprietary information. All information you provide to us is stored on our secure servers and any payment transactions will be encrypted using SSL technology or equivalent. Where we have given you (or where you have chosen) a password which enables you to access certain parts of the Site, you are responsible for keeping this password confidential. We ask you not to share a password with anyone.
24. We cannot accept liability for loss of personal data due to cause beyond our control or omissions of other users or third parties.
25. We will put in place measures such that your personal data in our possession or under our control is destroyed and/or anonymised as soon as it is reasonable to assume that (i) the purpose for which that personal data was collected is no longer being served by the retention of such personal data; and (ii) retention is no longer necessary for any other legal or business purposes.
26. You have the right to access and/or correct any personal data that we hold about you, subject to exceptions under the law. This right can be exercised at any time by emailing us at firstname.lastname@example.org. We will need enough information from you in order to ascertain your identity as well as the nature of your request, so as to be able to deal with your request. With respect to your access request, we may charge a fee in order to process it.
27. For a request to access personal data, once we have sufficient information from you to deal with the request, we will seek to provide you with the relevant personal data within 30 days. Where we are unable to respond to you within the said 30 days, we will notify you of the soonest possible time within which we can provide you with the information requested. Note that the PDPA exempts certain types of personal data from being subject to your access request.
28. For a request to correct personal data, once we have sufficient information from you to deal with the request, we will correct your personal data within 30 days. Where we are unable to do so within the said 30 days, we will notify you of the soonest practicable time within which we can make the correction. Note that the PDPA exempts certain types of personal data from being subject to your correction request as well as provides for situation(s) when correction need not be made by us despite your request. We will send the corrected personal data to every other organisation to which the personal data was disclosed by us within a year before the date the correction was made, unless that other organisation does not need the corrected personal data for any legal or business purpose.
29. We hold and deal with your data in accordance with the PDPA.
I. Administration and Management of Personal Data
30. We will take reasonable efforts to ensure that your personal data is accurate and complete, if your personal data is likely to be used by ROH to make a decision that affects you, or disclosed to another organisation. However, this means that you must also update us of any changes in your personal data that you had initially provided us with. We will not be responsible for relying on inaccurate or incomplete personal data arising from your not updating us of any changes in your personal data that you had initially provided us with.
31. Where your personal data is to be transferred out of Singapore, we will comply with the PDPA in doing so. In this regard, this includes us taking appropriate steps to ascertain that the foreign recipient organisation of the personal data is bound by legally enforceable obligations to provide to the transferred personal data a standard of protection that is at least comparable to the protection under the Act. This may include us entering into an appropriate contract with the foreign recipient organisation dealing with the personal data transfer or permitting the personal data transfer without such a contract if the PDPA or law permits us to
J. Complaint Process
32. If you have any complaint or grievance regarding about how we are handling your personal data or about how we are complying with the PDPA, we welcome you to contact us with your complaint or grievance.
33. Please contact us with your complaint or grievance by emailing us at: email@example.com
34. Where you are sending an email in which you are submitting a complaint, your indication at the subject header that it is a PDPA complaint would assist us in attending to your complaint speedily by passing it on to the relevant staff in our organisation to handle. For example, you could insert the subject header as “PDPA Complaint”.
35. We will certainly strive to deal with any complaint or grievance that you may have speedily and fairly.
37. You are encouraged to visit the above website from time to time to ensure that you are well informed of our latest policies in relation to personal data protection
39. For the avoidance of doubt, in the event that Singapore personal data protection law permits an organisation such as us to collect, use or disclose your personal data without your consent, such permission granted by the law shall continue to apply.
Last Updated on 23 May, 2019