Updated 22 November 2021
NEX PERSONAL DATA PROTECTION POLICY
We respect the confidentiality of Personal Data and privacy of individuals and are committed to complying with the Singapore Personal Data Protection Act (Act 26 of 2012) (“PDPA”) and other applicable data protection laws. Please read this Policy so that you know and understand the purposes for which we collect, use and disclose your Personal Data.
“Personal Data” refers to any data or information about you from which you can be identified either from that data alone; or from that data combined with other information. Examples of such Personal Data which you may provide us include (depending on the nature of your interaction with us):
- your name, national registration identification number, passport number or other identification number, telephone number(s), mailing address, email address, facial image in a photograph or video recording, fingerprint and any other information relating to you which you have provided us in any form you may have submitted to us, or in other forms of interaction with you;
- information about your use of our websites and services, including cookies, IP addresses, and membership details;
- your employment history, education background, and income levels.
Collection of Personal Data
Generally, we collect your Personal Data in the following ways:
- when you interact with our customer service officers or any of our staff, for example, via face-to-face meetings, business interactions in events and roadshows, telephone calls, letters, online forms (such as the “Contact Us” form on our website), social media platforms and emails;
- when you establish a loyalty membership account with us (my NEXrewards);
- when you request that we contact you;
- when you respond to our request for additional Personal Data;
- when you ask to be included in an email or other mailing list;
- when you respond to our promotions or other initiatives;
- when you respond to our market surveys;
- when you submit a job application;
- when we receive references from business partners and third parties, for example, where you have been referred by them;
- when you submit your Personal Data to us for any other reason; and
- when you browse our website. Please refer to our Cookie Policy for more information.
If you provide Personal Data of a third-party (e.g. information of your dependent, spouse, children and/or parents) to us, you represent and warrant that the collection, use and disclosure of that Personal Data to us, as well as the further processing of that Personal Data by us for the purposes set out in this Policy, is lawful.
Use and Disclosure of Personal Data
Our business is to understand and meet your needs and provide you with the products and services that you require. To do this effectively, we need to collect a range of Personal Data about you.
In general, we will, subject to applicable law, use and disclose your Personal Data for the following purposes:
If you are a Visitor, Shopper or my NEXrewards Member
- verify and process your personal particulars in relation to your application for membership (my NEXrewards) and any provision of goods and services connected to the App;
- help us review, develop, improve, enhance our services, including analysing future shopper needs, conducting market research and data analytics;
- communicate with you and respond to your queries, requests and complaints;
- provide ongoing information about our promotions and services which may be of interest to you;
- handle disputes and conduct and facilitate investigations and proceedings;
- protect and enforce our contractual and legal rights and obligations;
- prevent, detect and investigate crime, including fraud and money-laundering, and analyse and manage other commercial risks;
- comply with any applicable rules, laws and regulations, codes of practice or guidelines or assist in law enforcement and investigations by relevant authorities;
- communicate with you changes and development to our policies, terms and conditions and other administrative information; and any other purpose related to any of the above.
If you are a prospective Tenant or a Tenant of the Mall
- conduct due diligence checks;
- prepare lease and/or license documentation and any other documents as may be required;
- perform administration of the lease and/or licence;
- perform financial transactions such as rental payments;
- communicate with you changes and development to our policies, terms and conditions and other administrative information; and any other purpose related to any of the above.
If you are a Vendor or a prospective Vendor or Contractor
- evaluate your proposal;
- conduct background checks on you;
- communicate with your deployed staff, after award of contract, who are in our properties to carry out work or services, and for any emergency or/and security concerns; and any other purpose related to any of the above.
If you submit an application to us as a Candidate for employment:
- process your application including pre-recruitment checks;
- provide or to obtain references for background screening/vetting;
- collect information about your suitability for the position applied for;
- organise training and staff development programmes;
- assess your performance;
- administer benefits and payroll processing;
- provide you with tools to facilitate or as required for you to do your job;
- communicate with you to comply with our policies and processes, including for business continuity purposes; and any other purposes related to the aforesaid.
If you are an existing employee, our Employee Personal Data Protection Policy would also apply to you.
The above purposes are not exhaustive, and depending on the nature of your relationship with us (for example, if you are a member of my NEXrewards), we may collect, use and disclose your Personal Data for additional purposes which you will be notified of, in accordance with applicable terms and conditions.
Where you have provided us with specific consent, we may also use and disclose your Personal Data for the following purposes:
- provide electronic newsletters and notifications in connection with the loyalty programme, including accumulation of loyalty points, redemption of rewards, other information on our services, offers or promotions which may be of interest to you and conduct market research to develop special offers, promotional and/or marketing programmes; and
- administer contests, competitions and conducting lucky draws, including, where necessary, announcing the results of these contests, competitions and lucky draws and identifying and contacting the winners.
In relation to particular products or services or in your interactions with us, we may also notify or have specifically notified you of other purposes for which we collect, use or disclose your Personal Data. If so, we will collect, use and disclose your Personal Data for these additional purposes.
Your Personal Data will be protected and kept confidential, but subject to the provisions of any applicable law, your Personal Data may, depending on the products or services concerned, be disclosed to third parties set out below. Such disclosure may be subject to additional legal requirements under applicable law, depending on the nature of such transfer to third parties. Your Personal Data will, in each case, only be disclosed to the extent necessary and proportionate.
We require that organisations outside the company which handle or obtain Personal Data as service providers to us acknowledge the confidentiality of this data, undertake to respect any individual's right to privacy and comply with the PDPA, and any other applicable data protection laws. As a requirement under these laws, we may be required to have specific agreements in place with such third parties to regulate and safeguard your data protection rights. We also require that these organisations use this information only for our purposes and follow our directions with respect to this information.
The third parties are:
- our joint venture/ alliance partners;
- our agents, contractors, third-party service providers and specialist advisers who have been contracted to provide us with administrative, financial, research, operational or other services such as telecommunications, information technology, payment, payroll, training, market research, storage and archival;
- any third-party business partners who offer goods and services or sponsor contests or other promotional programmes, whether in conjunction with us or not, and where permitted by applicable laws;
- insurers or insurance investigators and credit providers;
- the Credit Bureau, or in the event of default or disputes, any debt collection agencies or dispute resolution centres;
- our professional advisors such as our auditors and lawyers;
- relevant government regulators or authority or law enforcement agency to comply with any laws or rules and regulations imposed by any governmental authority;
- anyone to whom we transfer or may transfer our rights and obligations, including, for example, where we obtain the services of a third-party organisation to handle any aspect of the processing of your Personal Data for the purposes notified to you in accordance with this Policy;
- banks, credit card companies and their respective service providers; and
- any other party as may be consented to by you, as specified by you or as may be notified to you by us in subsequent notices.
Transfer of Personal Data
Your Personal Data may be stored in external servers located overseas or in countries outside of your country of residence. In addition, as described above, in carrying out our business, it may be necessary to share information about you with and between our related corporations and affiliates, and third-party service providers, some of which may be located in countries outside your country of residence. We will take reasonable steps to ensure that your Personal Data transferred outside of your country of residence is adequately protected. In addition, we will ensure that such transfers comply with the requirements of the applicable data protection laws.
Protection of Personal Data
- Period of retention.We may retain your Personal Data for as long as it is necessary for the purposes it has been collected, and (i) in most cases, up to 7 years; unless otherwise permitted by applicable law or in order to defend legal claims. Where we no longer require your Personal Data for those purposes, we will cease to retain such Personal Data in accordance with our internal retention policy.
- Anonymised data. In some circumstances, we may anonymise your personal data so that it no longer identifies you, in which case we are entitled to retain and use such anonymised data without restriction, including for data analytics.
Your Rights
You have the following rights, under applicable data protection laws (except where the exercise of these are restricted under applicable laws – for example, due to judicial proceedings or the carrying out of investigations), which can be exercised by contacting the Data Protection Officers.
- Withdrawal of consent:
You may withdraw consent for our use of your personal data.
- Correction:
You may request that any incomplete or inaccurate data that we hold or control be corrected.
- Access:
You may ask if we hold or control your personal data and if we are, you can request access or a copy of such data
If you withdraw your consent to any or all purposes and depending on the nature of your request, we may not be in a position to continue to provide our products/services and/or accord you with the relevant rewards as a member of my NEXrewards.
Management and Security
We have appointed Data Protection Officer/s to oversee our management of your Personal Data in accordance with this Policy and the applicable data protections law. We train our employees who handle your Personal Data to respect the confidentiality of your Personal Data, and we regard breaches of all applicable data protection laws very seriously.
This Policy will be reviewed from time to time by us. We may also from time to time update this Policy to take account of new laws and technology, changes to our operations and practices and the changing business environment. If you are unsure whether you are reading the most current version, please contact us.
Cookie Policy
Our website uses “essential” cookies to improve your browsing experience. Cookies are small text files that can be used by websites to make a user's experience more efficient.
Essential cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
Our website may, from time to time, contain links to the websites of other organisations which may be of interest to you. Linked websites are responsible for their own privacy practices and you should check those websites for their respective privacy statements.
How to contact us
If you have any questions about this Policy or any queries relating to your Personal Data, or you would like to obtain access and/or make corrections to your Personal Data records, please contact the relevant Data Protection Officers at dpo@nex.com.sg