iFAST Privacy Policy

1. INTRODUCTION

iFAST Financial Pte. Ltd. (“iFAST”, “we”, “us or our”) is committed to protecting the personal data of our customers and users (“you or your”) in accordance with the Personal Data Protection Act 2012 of Singapore (as amended from time to time, the “PDPA”) and all other applicable data protection laws and regulations.

This Privacy Policy explains how we collect, use, disclose, retain, and protect your personal data in connection with the products and services we offer, including through our website, mobile applications, trading platforms, and other digital or physical channels.

By using our services or providing your personal data to us, you acknowledge that you have read and understood this Privacy Policy and consent to our collection, use, and disclosure of your personal data as described herein. If you do not agree, please discontinue use of our services. We may update this Policy from time to time. Material changes will be communicated to you before they take effect. We encourage you to review this Policy periodically.

2. OUR OBLIGATIONS UNDER THE PDPA

As an organisation subject to the PDPA, iFAST adheres to the following key obligations:

  • Consent Obligation: We obtain your consent before collecting, using or disclosing your personal data, unless an applicable exception permits us to do so.
  • Purpose Limitation Obligation: We collect, use or disclose your personal data only for purposes notified to you, or purposes a reasonable person would consider appropriate.
  • Notification Obligation: We make this Privacy Policy available to you and notify you of data collection purposes at or before the time of collection.
  • Access and Correction Obligation: Upon written request, we will provide access to your personal data and correct any error or omission.
  • Accuracy Obligation: We make reasonable efforts to ensure personal data is accurate and complete.
  • Protection Obligation: We implement reasonable security arrangements to protect your personal data against unauthorised access, use, disclosure, copying, modification, disposal, or similar risks.
  • Retention Limitation Obligation: We cease to retain personal data once the purpose for collection is no longer served and retention is no longer necessary.
  • Transfer Limitation Obligation: We do not transfer personal data outside Singapore unless the recipient provides a comparable standard of protection.
  • Data Breach Notification Obligation: We assess and, where required, notify the PDPC and affected individuals of notifiable data breaches within prescribed timelines.
  • Accountability Obligation: We implement policies and procedures to meet our PDPA obligations and make information about those policies publicly available.

3. PERSONAL DATA WE COLLECT

We may collect the following categories of personal data:

    • Personal Particulars: Name, address, date of birth, NRIC/Passport details, and contact details.
    • Financial & Investment Information: Financial details, specimen signature(s), employment details, tax information, and information about your risk profile, investments, investment objectives, knowledge, and experience.
    • Verification & Biometric Data: Identity verification data (e.g., identity document scans, MRZ data, and document security features) and biometric data (e.g., facial images, liveness verification data, video selfies, and numeric facial feature identifiers derived from verification processes).
    • Technical & Activity Data: Device and technical data (e.g., IP address, browser type, device identifiers, operating system, geolocation data, access timestamps, and network request information).
    • Audio & Visual Records: Audio and visual recordings (e.g., CCTV footage and call recordings for quality assurance and security purposes).
    • Other Provided Data: Any information which you have provided to us for any other reasons.

4. HOW WE COLLECT YOUR PERSONAL DATA

We collect personal data through the following channels:

    • Direct Submissions: Submission of account opening forms, applications, agreements, or other documentation.
    • Platform Interactions: Use of our digital platforms, websites, mobile applications, and online trading portals.
    • Communications: When contacting us via emails, letters, and telephones (which may be monitored or recorded), or when entering into agreements and transactions.
    • Premises & Events: When your images are captured via CCTV cameras within our premises, or via photographs or videos taken during events hosted by us.
    • Promotions & Engagements: Participation in referral programmes, promotions, contests, and surveys.
    • Verification & Third Parties: Verification processes conducted through our platforms or third-party service providers, as well as data from credit bureaus, regulatory bodies, and publicly available sources (e.g., sanctions lists and PEP databases).
    • Tracking Technologies: Cookies and similar tracking technologies on our websites and applications.

5. PURPOSES OR COLLECTION, USE AND DISCLOSURE 

All your personal data may be processed, used, or disclosed for the following purposes:

    • Verifying your identity, assessing your background, and conducting customer due diligence, including know-your-customer (KYC), anti-money laundering (AML), counter-terrorism financing (CTF), and other regulatory screening requirements.
    • Opening, operating, maintaining, and managing your account(s) and performing all obligations in connection with the products and services you request from us.
    • Processing, executing, and settling your instructions, transactions, and orders.
    • Assessing your investment suitability, financial situation, knowledge, experience, and risk appetite in connection with financial products and services.
    • Responding to, handling, and processing your queries, requests, applications, complaints, and feedback.
    • Detecting, investigating, and preventing fraud, money laundering, financial crime, market misconduct, and any other unlawful or suspicious activity.
    • Complying with all applicable laws, regulations, codes, guidelines, and directions, and any requests or requirements of local or foreign regulatory, governmental, judicial, or law enforcement authorities.
    • Carrying out research, analytics, planning, reporting, and development of our products, services, and operations, including through the use of data analytics, statistical modelling, the development, training, and testing of artificial intelligence and machine learning models, and other automated tools.
    • Marketing, promoting, and offering our products and services to you, where you have consented or where otherwise permitted by law.
    • Any other purpose reasonably incidental or related to any of the above, or any other purpose for which you have given your consent.

6. DISCLOSURE OF PERSONAL DATA

We may from time to time, and in compliance with all applicable laws, disclose your personal data to any personnel of iFAST or to any third parties, whether located in Singapore or elsewhere, in order to carry out the purposes described in this Policy. We take reasonable steps to ensure that such parties are bound by appropriate data protection obligations consistent with this Policy and applicable law.

Such third parties may include, but are not limited to:

    • Our related corporations, subsidiaries, affiliates, and group companies.
    • Financial institutions, custodians, fund managers, brokers, exchanges, clearing houses, and other product or service providers involved in your transactions or investments.
    • Third-party service providers engaged to support our operations, including technology, cloud computing, data hosting, identity verification, KYC, AML screening, compliance, analytics, and other service providers.
    • Professional advisers, including lawyers, auditors, accountants, and consultants.
    • Regulatory authorities, law enforcement agencies, government bodies, courts, and other public bodies, as required or permitted by applicable law.
    • Any other party to whom you have consented to the disclosure, or where disclosure is otherwise required or permitted by law.

Note on third-party vendors acting as independent controllers:
Certain service providers we engage (such as identity verification, risk screening, or fraud prevention platforms) may also process your personal data as independent data controllers for their own purposes. Where permitted by applicable laws, regulatory requirements and our governance framework, this may include developing and improving their services (including through machine learning and AI), building fraud intelligence networks, and meeting their own regulatory obligations. When acting in this capacity, their processing is governed by their own privacy policies.

7. AUTOMATED PROCESSING AND ARTIFICIAL INTELLIGENCE 

We and our service providers may use automated processing tools, including artificial intelligence and machine learning systems, to process your personal data in connection with our services. Such processing is carried out only for purposes that are consistent with this Policy and with our obligations under the PDPA. We are committed to ensuring that our use of these technologies is fair, transparent, and accountable.

Where automated processing is used to make or support decisions that may significantly affect you — such as decisions relating to your account eligibility, access to products and services, or compliance status — we ensure that appropriate safeguards are in place, in line with applicable regulatory principles, including human oversight where warranted. We comply with the PDPC’s advisory guidelines on the use of personal data in AI systems.

Where such processing produces an outcome that significantly affects you, you may contact our Data Protection Officer to request that the matter be reviewed, seek clarification on the basis of the outcome, or provide additional information in support of a review. We will assess and address such requests on a case-by-case basis, taking into account technical feasibility and system limitations. We will respond within prescribed regulatory timelines or otherwise within a reasonable period.

8. INTERNATIONAL TRANSFER OF PERSONAL DATA

Your personal data may be transferred to, stored in, or processed in countries outside Singapore in connection with our services, including jurisdictions where our service providers, subprocessors, and group entities operate.

Where we transfer personal data outside Singapore, we ensure the recipient provides a standard of protection comparable to the PDPA, whether through robust contractual arrangements, adequacy determinations, or other legally sanctioned safeguards.

9. RETENTION OF PERSONAL DATA 

We retain your personal data for as long as is necessary to fulfil the purposes for which it was collected, or as required or permitted by applicable law, regulation, or regulatory guidance. This includes retaining personal data where necessary for our legal, compliance, risk management, and business purposes, including to resolve disputes, prevent fraud, and enforce our agreements.

Where personal data is processed by third-party service providers acting as independent data controllers, such providers may retain your personal data in accordance with their own retention policies and applicable legal obligations, independently of our instructions.

10. COOKIES AND SIMILAR TECHNOLOGIES 

Cookies are small files that are stored in the cookie directory of your computer or device to help websites recognize visitors and enhance user experiences. We use the following types of cookies to run our trading platforms and websites:

    • Necessary Cookies: Mandatory for our platforms and shopping cart systems to function; these cannot be disabled.
    • Analytics Cookies: Help us analyze traffic patterns, domain names, and user interactions so we can customize and improve our layout and content.
    • Functionality Cookies: Remember your specific preferences, settings, and registrations.
    • Security Cookies: Help us identify your web browser, detect anomalies, prevent fraud, and protect your account.

You may configure your browser to block or disable cookies. However, doing so may affect the functionality of our platforms. For more details on managing cookies, visit www.allaboutcookies.org.

11. YOUR RIGHTS

Subject to the exceptions specified under the PDPA and applicable local regulations, you possess the following rights regarding your personal data:

    • Right of Access: You may request access to your personal data in our possession and information about how it has been used or disclosed during the past 12 months.
    • Right of Correction: You may request the correction of any inaccuracy or incompleteness in your personal data.
    • Right to Withdraw Consent: You may withdraw your consent for data processing at any time. Please note that withdrawal may affect our ability to continue providing certain services, and we will notify you of the likely consequences before your withdrawal takes effect.
    • Right in Relation to Automated Decisions: Where an automated process produces an output that significantly affects you, you may contact our Data Protection Officer as described in Section 7.
    • Right to Lodge a Complaint: If you are dissatisfied with how we have handled your personal data, you may lodge a complaint with the PDPC at www.pdpc.gov.sg.

To exercise any of these rights, please contact our Data Protection Officer. We will respond within prescribed regulatory timelines or otherwise within a reasonable period.

12. DATA BREACH NOTIFICATION 

We maintain procedures to detect and respond to personal data breaches. Where a breach is assessed as notifiable under the PDPA, we will comply with our mandatory notification obligations, which include notifying the Personal Data Protection Commission (PDPC) and, where applicable, affected individuals, within the timelines prescribed by law.

13. DATA PROTECTION AND INFORMATION

The security of your Personal Data is our priority. We implement appropriate technical and organisational measures—including access controls, encryption, firewalls, audit logging, and regular staff training—to protect your data against unauthorised access, use, disclosure, modification, or loss.

You can assist in protecting your data by ensuring your login credentials and passwords remain secure. We recommend logging out of your account after completing transactions, especially when using shared computers. Please contact us immediately if you suspect any unauthorised access to your account.

14. CHANGES TO THIS PRIVACY POLICY

 We may update this Policy from time to time to reflect changes in our practices, applicable laws, or regulatory requirements. The updated Policy will be made available on our website and platform, and your continued use of our services following any update constitutes your acceptance of the revised Policy.

15. LINKS TO THIRD PARTY WEBSITES 

Our platforms may contain links to third-party websites. We are not responsible for the privacy practices, content, or data handling procedures of these external entities. We encourage you to review the privacy policies of any website you visit via an external link.

16. CONTACTING US - DATA PROTECTION OFFICER 

For any questions, concerns, or requests relating to this Privacy Policy or the handling of your personal data, please reach out to our Data Protection Officer:

Data Protection Officer
iFAST Financial Pte. Ltd.
Email: dataprotectionsg@fundsupermart.com 

We will respond within prescribed regulatory timelines or otherwise within a reasonable period.