10.1 In addition to the foregoing paragraphs, the following sub-paragraphs in this paragraph 10 apply, if and to the extent that the GDPR is applicable to your personal data and/or to the activities which we are carrying out in relation to your personal data. Typically, this would be where (a) you are a European Union resident; and (b) when you are a resident in the European Union we process your personal data in relation to our offering of goods or services to you in the European Union.
10.2 In relation to the processing of your personal data by us, we are a data controller. If the GDPR applies to your personal data that is within our possession or control, you will have rights as set out in the GDPR.
10.3 We process your personal data based on one or more of the following legal basis :
- Where you have provided us with your consent for the purposes of processing in question;
- Where processing is necessary for the performance of a contract to which you are are party to or in order for us to take steps at your request prior to us entering into such a contract;
- Where processing is necessary for us to comply with a legal obligation to which we are subject to;
- Where processing is necessary in order to protect your vital interests or of another individual;
- Where processing is necessary for the performance by us of a task carried out in the public interest or in the exercise of official authority vested in us; or
- Where processing is necessary for the purposes of our legitimate interests, except where such interests are overridden by your interests or fundamental rights and freedoms. Our legitimate interests are :
- responding to your queries;
- providing products, services and/or information to you;
- recruiting staff;
- one or more of the purposes set out at paragraph 3.1 above; and/or
- one or more of the purposes other than the purposes referred to at (iv) above which we notify you of at the time of obtaining your consent.
We consider that the risk to your data protection rights in connection with personal data that we process on the basis of our legitimate interests is not excessive or overly intrusive. We have also put in place protection for your rights by ensuring proper retention period(s) and security controls.
10.4 With respect to paragraph 3.2 above, Such third parties to whom your personal data is disclosed comprise :
- our associated or affiliated organisations or related corporations, if any;
- Google LLC as our website uses Google Analytics and Microsoft Corporation as our website uses Microsoft Clarity;
- government agencies;
- any of our agents, contractors or third party service providers that provide services to us, or that process or will be processing your personal data on our behalf, comprising mailing houses, marketing companies, recruitment companies, logistics companies, telecommunication companies, information technology companies and data centres;
- third parties other than those specified above to whom disclosure by TECL is for one or more of the Purposes and such third parties would in turn be collecting and processing your personal data for one or more of the Purposes. Before we engage such category of third party to whom your personal data would be disclosed that is not one falling within subparagraphs (i) to (iv) above, we will notify you of the same by posting such new third party on our website or by posting an amended policy on our Website or by posting amendments to this policy on our Website – in this regard, we would urge you to check our Website regularly for any such changes.
10.5 One or more of the third parties mentioned at paragraph 10.4 are based outside of Singapore. Your personal data will be transferred by us from Singapore to them. The countries in which these third parties are based are : Malaysia, Hong Kong, Japan, South Korea, Australia, New Zealand, USA, Canada, UK, Germany and Austria. We will ensure that your personal data will be adequately protected by such third parties by executing data transfer agreements with such third parties to deal with such transfer of personal data and to ensure that your personal data will continue to be protected by such third parties.
10.6 Your rights
- Right of access: See paragraph 5.1 above. Where the GDPR applies to you and you are exercising your right to access personal data under the GDPR, we will not charge you a fee for exercising your access rights (except where permitted by the GDPR), unlike for access rights under the PDPA.
- Right to rectification: You can ask us to take reasonable measures to correct your personal data if it is inaccurate or incomplete. E.g. if we have the wrong name or address for you.
- Right to erasure: This right enables you to request the deletion or removal of your personal data where there is no compelling reason for us to keep using it or its use is unlawful. There are exceptions to your exercise of this right. An example would be where we need to use your personal data in defence of a legal claim.
- Right to restrict processing: This is a right that allows you to ‘block’ or suppress further use of your personal data. When processing is restricted, we can still store your personal data, but may not use it further subject to exceptions as provided in the GDPR.
- Right to data portability: This is a right for you to obtain and reuse certain personal data for your own purposes across different organisations.
- Right to object: You have the right to object to certain types of processing, on grounds relating to your particular situation, at any time insofar as that processing takes place for the purposes of legitimate interests pursued by us or by a third party. We will be allowed to continue to process your personal data if we can demonstrate “compelling legitimate grounds for the processing which override your interests, rights and freedoms” or we need this for the establishment, exercise or defence of legal claims. You can object to the processing by us of your personal data for marketing purpose. Please notify us by contacting our Data Protection Officer at dpo@esplanade.com.
You may exercise the rights above (if applicable to you), by contacting our Data Protection Officer at dpo@esplanade.com.
If the PDPA applies to you and not the GDPR, do note that one or more of the rights set out above are not available to you. In such a case, we will extend to you such rights as required by the PDPA.
10.7 In the event that the GDPR applies to us and you determine that we have done something that breaches the GDPR, you may choose to lodge a complaint with the relevant European Data Protection Authority, such as the Authority in the European Union member state in which you are residing in.