1. About this Privacy Policy
We respect the privacy of individuals whose personal data we handle and are committed to handling personal data in accordance with the Personal Data Protection Act (“PDPA”) and other applicable laws and regulatory requirements.
This Privacy Policy applies to personal data relating to individual clients and, where a client is an organisation, individuals associated with that client, including its directors, officers, partners, shareholders, beneficial owners, authorised persons, traders, representatives and other personnel. It should be read together with the terms and conditions, account opening documents and other agreements governing your relationship with us.
In this Privacy Policy, “personal data” has the meaning given under the PDPA and generally refers to data about an individual who can be identified from that data, or from that data together with other information to which we have or are likely to have access.
2. Personal Data We May Collect
Depending on the Services you use and your relationship with us, we may collect, use or otherwise process the following categories of information:
- Identification and contact information, such as name, identification or passport details, date of birth, nationality, residential or business address, telephone number, email address, signature and other information used to identify or contact you.
- Client and associated-person information, including information about directors, officers, partners, shareholders, beneficial owners, authorised persons, traders, representatives and other persons associated with a client.
- Account information, including account opening documents, account identifiers, statements, balances, positions, investment holdings, preferences and other account-related records.
- Transaction and trading information, including orders, executions, trade details, settlement instructions, payment information, transaction history and related documentation.
- Financial and due diligence information, including financial condition, creditworthiness, source of funds or wealth, financial capacity, tax information and information required for know-your-customer, anti-money laundering, countering the financing of terrorism, sanctions and other regulatory checks.
- Communications and relationship information, including correspondence, enquiries, instructions, complaints, call or meeting records and other dealings with us or members of our group.
- Digital and technical information generated when you access our websites, mobile applications or online services, such as IP address, device or browser type, operating system, app version, device or session identifiers, login records, security events, crash or diagnostic information, and information about how the Services are accessed or used.
- Other information that you provide to us, that is generated through your use of the Services, or that we obtain in connection with providing Services or operating your account.
3. How We Collect Personal Data
We may collect personal data directly from you, from your organisation or representatives, through your use of the Services, and from other lawful sources. These may include:
- account opening forms, agreements, declarations, instructions and documents submitted to us;
- communications with you or your authorised representatives by email, telephone, electronic messaging, meetings or other channels;
- information submitted, uploaded or generated when you use our mobile application, websites or other digital Services;
- transactions, account activity and use of our Services;
- our group companies, service providers, business partners, exchanges, clearing houses, custodians, banks and other financial institutions where relevant to the Services;
- publicly available sources, screening databases, credit reference sources, governmental authorities, regulators and law enforcement agencies, where permitted by law.
4. Purposes for Which We Use Personal Data
We may collect, use, disclose and otherwise process personal data for purposes reasonably connected with our relationship with you and the provision of the Services, including:
- processing applications, establishing and administering client relationships and accounts, and verifying identities and authorities;
- providing brokerage, trading, execution, settlement, custody-related, reporting, platform and other Services requested by or made available to you;
- carrying out instructions, processing orders and transactions, maintaining records, issuing contract notes, confirmations, statements and notices, and providing client support;
- authenticating users, managing access, maintaining the security and integrity of our systems and Services, detecting suspicious or unauthorised activity, preventing fraud and investigating incidents or disputes;
- conducting customer due diligence, know-your-customer checks, anti-money laundering and counter-terrorist financing checks, sanctions screening, credit or risk assessments and other compliance or risk management activities;
- complying with legal, regulatory, tax, audit, market, exchange, clearing house and internal governance requirements, and responding to lawful requests, investigations or enquiries;
- operating, maintaining, supporting, troubleshooting, improving and developing our websites, mobile applications, systems, products and Services, including through service analytics and performance monitoring;
- group-wide risk management, compliance, internal audit, operational administration, business planning and restructuring;
- managing our business relationships with service providers, professional advisers, counterparties and other parties involved in delivering the Services;
- protecting and enforcing our legal rights, contractual rights and legitimate business interests, and managing claims or disputes; and
- other purposes that are reasonably related to the above, that are notified to you, or that are otherwise permitted or required by applicable law.
5. Disclosure and Sharing of Personal Data
To carry out the purposes described above, we may disclose personal data, on a need-to-know basis and subject to applicable legal requirements, to persons including:
- our parent company, affiliates, related corporations, representative offices, branches and other members of the Shenwan Hongyuan group;
- our technology, application, cloud, hosting, telecommunications, cybersecurity, data processing, storage, archival, printing, mailing, operational, middle-office, clearing, settlement and other service providers or vendors, whether located in Singapore or elsewhere;
- exchanges, clearing houses, depositories, custodians, brokers, counterparties, banks, payment service providers, market infrastructure providers and other persons involved in executing, clearing, settling or supporting transactions or Services;
- credit bureaus, credit reference agencies, rating agencies, insurers and providers of credit protection, where relevant;
- auditors, lawyers, consultants and other professional advisers;
- government agencies, regulators, tax authorities, law enforcement agencies, courts, tribunals and other authorities in Singapore or other jurisdictions, where disclosure is required or permitted;
- actual or prospective assignees, transferees, participants or counterparties in connection with a transfer, financing, reorganisation, merger, acquisition or other corporate transaction involving us or our business; and
- other persons where you have provided consent or where disclosure is otherwise permitted or required by law.
We do not disclose personal data to third parties for purposes unrelated to our Services merely in exchange for payment. Where marketing by us or our affiliates requires consent under applicable law, we will obtain or rely on the appropriate consent or other lawful basis before sending such communications.
6. Overseas Transfers
Some members of our group, service providers, counterparties or other recipients may be located outside Singapore. Where personal data is transferred outside Singapore, we will take steps required under the PDPA to ensure that the transferred personal data is accorded a standard of protection comparable to that under the PDPA, subject to applicable legal exceptions.
7. Mobile Application and Digital Services
When you use our mobile application or other digital Services, certain information may be processed automatically to enable the Services to function securely and reliably. This may include device, network, session, login, security, diagnostic and usage information described in Section 2.
Our digital Services may use cookies, SDKs, local storage or similar technologies for functions such as authentication, security, session management, service operation, diagnostics, performance monitoring and user preferences. The technologies used may vary depending on the platform and features made available. You may be able to control certain technologies through your browser, device or operating-system settings; disabling them may affect the availability or performance of some functions.
Where the mobile application provides optional features that require access to a device function or information, the relevant access will be requested through the device or operating system where required. You may manage permissions through your device settings, although disabling a permission may prevent the corresponding feature from functioning.
The mobile application may provide links to or integrate services provided by third parties. Their handling of personal data may be governed by their own terms and privacy notices. We encourage you to review those notices where relevant.
8. Security of Personal Data
We maintain reasonable administrative, physical and technical safeguards designed to protect personal data in our possession or under our control against unauthorised access, collection, use, disclosure, copying, modification, disposal or similar risks. These safeguards may include access controls, authentication measures, monitoring, secure transmission or storage controls, staff procedures and vendor-management measures, as appropriate to the nature of the data and Services.
No method of transmission over the Internet or method of electronic storage is completely secure. You should protect your login credentials, use appropriate device security measures and notify us promptly if you believe your account or access credentials may have been compromised.
9. Retention of Personal Data
We retain personal data for as long as it is reasonably necessary to fulfil the purposes for which it was collected, to meet our business and operational needs, and to comply with legal, regulatory, tax, audit, dispute-resolution and record-keeping requirements. When personal data is no longer required for such purposes, we will cease to retain it or remove the means by which it can be associated with particular individuals, where required by applicable law.
10. Marketing Communications
Where you have consented, or where otherwise permitted under applicable law, we or our affiliates may send you information about financial products, services, events or other matters that may be of interest to you. You may opt out of marketing communications through the method stated in the communication or by contacting us. Service-related or regulatory communications that are necessary for the operation of your account or provision of the Services are not marketing communications and may continue to be sent.
11. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our Services, practices, technologies or legal and regulatory requirements.
12. Contact Us
If you have questions or feedback about this Privacy Policy, wish to make an access or correction request, or wish to withdraw consent, please contact our Data Protection Officer:
Organisation
Shenwan Hongyuan Singapore Private Limited
Address
6 Temasek Boulevard, #27-01 Suntec Tower Four, Singapore 038986
This Privacy Policy supplements, and does not limit, any consent, authorisation or rights and obligations relating to personal data set out in applicable account opening documents, terms and conditions or other agreements, except to the extent otherwise required by applicable law.
