1. Introduction and Scope
1.1 Grand Dunman Pte Ltd (UEN 202223759E) (“Grand Dunman”, “we”, “us” or “our”) is the legal entity that controls the personal data collected in connection with the Grand Dunman development. We are committed to protecting the personal data entrusted to us and to complying with the Personal Data Protection Act 2012 of Singapore and its subsidiary legislation (collectively, the “PDPA”). This Privacy Policy (“Policy”) sets out how we collect, use, disclose, protect and retain your personal data.
1.2 This Policy applies to the personal data of all individuals with whom we deal, including residents and unit owners, prospective and confirmed purchasers, tenants and occupiers, showflat and property visitors, website visitors, contractors, and the employees and representatives of our service providers (each, “you”).
1.3 This Policy supplements but does not supersede or replace any other consent you may previously have given to us, nor any of our rights at law to collect, use or disclose your personal data. By interacting with us, submitting personal data to us, or engaging our services, you consent to the collection, use and disclosure of your personal data in accordance with this Policy.
2. Definitions
2.1 “Personal Data” means data, whether true or not, about an individual who can be identified (a) from that data; or (b) from that data and other information to which we have or are likely to have access.
2.2 References to any statutory provision are to the PDPA as amended, re-enacted or supplemented from time to time.
3. Personal Data We Collect
3.1 The personal data we collect varies according to the nature of your dealings with us. It may include your identification and contact particulars, information relating to your unit, transaction, tenancy or engagement with us, payment and financial information, records of your access to and use of the development and its facilities, images captured by our security and surveillance systems, and information collected through our website and online services.
3.2 We do not knowingly collect personal data of a sensitive nature unless it is required for a specific, lawful purpose and its collection is permitted under the PDPA.
4. How We Collect Personal Data
4.1 We collect personal data through registration, booking and application forms; sale-and-purchase and tenancy documentation; visitor and contractor registers; access-control and CCTV systems; our website and online portals; your correspondence with us; and third parties such as appointed marketing agents, referrers and the managing agent.
4.2 Where you provide us with personal data relating to a third party (for example, a spouse, child, parent, co-purchaser or employee), you represent and warrant that you have obtained that third party’s consent for us to collect, use and disclose their personal data for the purposes set out in this Policy.
5. Purposes of Collection, Use and Disclosure
5.1 We collect, use and disclose personal data for purposes reasonably required to conduct our business, including to:
- Process property bookings, sales, tenancies and related transactions.
- Administer and manage the development, its facilities and estate operations.
- Verify identity and conduct due-diligence, anti-money-laundering and other statutory checks.
- Manage access control, security and safety within the development.
- Process payments, invoicing and financial reconciliation.
- Respond to enquiries, feedback, requests, complaints and disputes.
- Keep you informed of matters relating to your unit, transaction or residency.
- Comply with applicable laws, regulations and directions of public authorities.
- Establish, exercise or defend legal rights.
5.2 Where we intend to use or disclose personal data for a purpose not set out in this Policy, we will notify you and obtain your consent, unless such use or disclosure without consent is permitted or required under the PDPA.
6. Consent
6.1 We collect, use and disclose personal data only where you have given consent, where consent is deemed to have been given under the PDPA, or where such collection, use or disclosure is authorised or required by law.
6.2 If you provide personal data on behalf of another individual, you warrant that you are authorised to do so and that the requisite consent has been obtained.
7. Disclosure of Personal Data
7.1 We may disclose your personal data, for the purposes set out in this Policy, to the managing agent and the management corporation; security, cleaning, maintenance and facility contractors; developers, joint-venture partners and appointed marketing agents; banks, financiers and insurers; solicitors, auditors and professional advisers; payment and information-technology service providers; and government agencies and regulatory or law-enforcement authorities.
7.2 We may also disclose personal data where:
- Required or authorised by law.
- In connection with actual or prospective legal proceedings.
- Necessary to establish, exercise or defend our legal rights.
- To service providers acting on our behalf under conditions of confidentiality.
- With your consent.
- For the purpose of business continuity or disaster recovery.
7.3 Where we engage third parties to process personal data on our behalf, we require them by contract to protect the personal data to a standard comparable to that required under the PDPA and to use it only for authorised purposes.
8. Transfer of Personal Data Outside Singapore
8.1 Where personal data is transferred outside Singapore, we take reasonable steps to ensure that the recipient is bound by legally enforceable obligations to provide a standard of protection comparable to that under the PDPA.
9. Website, Cookies and Online Services
9.1 Our website and online portals may use cookies and similar technologies to enable functionality, remember your preferences and analyse usage. You may configure your browser to refuse cookies, although certain features may then not function properly.
9.2 Our website may contain links to third-party sites. We are not responsible for the privacy practices or content of such sites, and this Policy does not apply to them.
9.3 While we take reasonable measures to secure information transmitted through our website, no transmission over the internet can be guaranteed to be completely secure, and any such transmission is made at your own risk.
10. Protection of Personal Data
10.1 We make reasonable security arrangements to protect personal data in our possession or under our control against unauthorised access, collection, use, disclosure, copying, modification, disposal or similar risks. These include access on a need-to-know basis, secured physical and electronic storage, and the secure disposal of records that are no longer required.
11. Retention of Personal Data
11.1 We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required for legal, regulatory, accounting or business purposes. When personal data is no longer required for any such purpose, we will cease to retain it, or remove the means by which it can be associated with you, as soon as it is reasonable to do so.
12. Accuracy of Personal Data
12.1 We take reasonable steps to ensure that personal data collected is accurate and complete. You should notify us promptly of any change to your personal data so that our records remain current.
13. Access, Correction and Withdrawal of Consent
13.1 You may request access to, or correction of, personal data about you that is in our possession or under our control, or withdraw any consent previously given, by written request to our Data Protection Officer.
13.2 We will respond to your request within a reasonable time. A reasonable fee may be charged for an access request, of which we will inform you in advance. We may decline a request to the extent permitted or required under the PDPA.
13.3 Where you withdraw consent, we will inform you of the likely consequences. Withdrawal may affect our ability to provide services to you, or to administer your residency or transaction, and may not extend to processing that we are required or entitled to carry out by law.
14. Do Not Call Provisions
14.1 Where you have provided us with a Singapore telephone number and have consented to being contacted, you consent to our contacting you at that number by voice call, text or facsimile message for the purposes set out in this Policy, notwithstanding that the number may be listed on the Do Not Call Registry, until such consent is withdrawn.
15. Data Breach
15.1 We maintain procedures to assess and manage data breaches. Where a data breach is assessed to be notifiable under the PDPA, we will notify the Personal Data Protection Commission, and affected individuals where required, in accordance with the PDPA.
16. Data Protection Officer
16.1 Questions, requests or complaints concerning your personal data or this Policy may be addressed to our Data Protection Officer at geachonglim@pdpacompliance.com. We are committed to addressing your concerns and resolving them promptly.
17. Changes to this Policy
17.1 We may revise this Policy from time to time to reflect changes in our practices or in applicable law. The current version is published at www.granddunman.com.sg, supersedes all previous versions and governs our treatment of your personal data. We encourage you to review this Policy periodically.
18. Governing Law
18.1 This Policy is governed by and construed in accordance with the laws of Singapore, and you submit to the non-exclusive jurisdiction of the Singapore courts.