Does Kosme Aesthetics comply with PDPA?
Yes, Kosme Aesthetics is compliant with the requirements of the PDPA (Personal Data Protection Act) of Singapore, has appointed a Data Privacy Officer and is also compliant with the somewhat more stringent European General Data Protection Regulations (GDPR code of conduct published by Cispe Data Protection Code of Conduct. You can access a copy of Code of Conduct in the link below.
CISPE Data Protection Code of Conduct
All Client data is stored electronically with our software service provider, ZING. The software is a cloud service, whereby no data is stored on site - only in ZING's secure data storage. Our data is available to no one except Kosme Aesthetics. All data is stored in a Cloud data center here in Singapore.
Kosme Aesthetics (‘Kosme’, ‘we’, ‘us’, and ‘our’) take data protection very seriously and we are committed to protecting your personal information.
This explains what information we gather about you, what we use that information for, and who we give that information to. It also sets out your rights in relation to your information, how long we keep it and who you can contact for more information.
It is our policy to collect only the minimum information required from you. If you believe we have collected excessive information about you, please contact us at firstname.lastname@example.org to raise any concerns you may have.
Although you do not have to provide any of your personal information to us, if we ask you to do so and you refuse, we may be unable to provide you with the information, goods or services you want from us.What is personal information?
Personal information is anything that enables you to be identified or identifiable, such as your:
- First and last names
- Postal and email addresses
- Telephone numbers
- Identity documents (e.g. passports & driving license)
- Identity numbers (e.g. SSIN, NRIC, FIN and Bank accounts)Career & educational documents (e.g. Resumés, CVs & qualifications)
- Contact information
Your personal information is sometimes called “personal data”. We collectively refer to handling, collecting, protecting or storing your personal information as ‘processing’.Collecting personal information
Below are just some examples of how you may provide personal information to us:
- Placing an order with us
- Registering for a trial with us
- Filling out any of our Forms
- Searching, browsing and entering information on our website
- Downloading guides or content
- Subscribing to our newsletters
- Using our Live Chat
- Opening a Support Ticket
- Registering for or attending our events
- Submitting Resumés/CVs or work history information to us
- Providing us with business cards or other contact information
- Accessing our online publications
- Entering our surveysUsing personal information
When you provide personal information to us, we may use it for any of the purposes described below or as stated at the point we collect it from you (or as may be obvious to you from the context of collection), including:
- To provide services to you that you have requested
- To develop our businesses and services
- To consider whether to offer someone employment with us
- To administer and manage our website and forms
- To conduct quality and risk management reviews
Any other purposes for which personal information has been provided to us, including any of the purposes given in the ‘Collection of Personal Information’ section above.We do not collect personally identifying information for sale to third parties.Legal grounds for processing personal information
We rely on one or more of the following processing conditions:
- To perform our contractual obligations to you; and/or
- To satisfy any legal and regulatory obligations to which we are subject; and/or
- To satisfy our legitimate interests in the effective delivery of information and services to you and in the effective and lawful operation of our businesses (where this does not interfere with your rights); and/or
- When you have agreed to us processing your personal information.
Security of personal information
We have implemented generally accepted standards of technology and operational security in order to protect personally identifiable information from loss, misuse, alteration or destruction.
Only authorised persons are provided access to personally identifiable information we have collected, and such individuals have agreed to maintain the confidentiality of this information.
Although we use appropriate security measures once we have received your personal data, the transmission of data over the internet (including by e-mail) is never completely secure.
We endeavour to protect personal data, but we cannot guarantee the security of data transmitted to or by us.
Sharing personal information
We may transfer, share or disclose the personal data we collect from you to third parties (other organisations or individuals) for:
- The purposes for which the information has been submitted
- The purposes listed above under ‘Use of personal information’
- The administration and maintenance of our website and/or forms
- Other internal or administrative purposes
We also may transfer, share or disclose personal data to third party service providers of identity management, website hosting and management, data analysis, data backup, security and storage services.
These third party providers may use their own third party subcontractors that have access to personal data (sub-processors). It is our policy to use only third party providers that are bound to maintain appropriate levels of security and confidentiality, to process personal information only as instructed by us, and to flow those same obligations down to their sub-processors.
We may also disclose personal information to third parties under the following circumstances:
= When explicitly requested by you
- When required to deliver goods or services requested by you
- When required to facilitate our conferences or events that you have asked to attend which are hosted by a third party
We may also disclose your personal information to law enforcement, regulatory and other government agencies and to professional bodies and other third parties, as required by and/or in accordance with applicable laws or regulations.
International transfers of personal information
Your personal information may be transferred outside the European Economic Area (EEA). Where we collect your personal information within the EEA, any transfer to outside the EEA will be only:
- To you
- To a recipient located in a country which provides an adequate level of protection for your personal information; or
- Under a contractual agreement which satisfies EU requirements for the transfer of personal data outside the EEA
Retention of personal information
We will retain your personal information only for as long as we need it, given the purposes for which it was collected, or as required to do so by law.
Normally, this means we will retain your personal information for five years.
Where we are legally required to obtain your consent to provide you with marketing materials, we will only provide you with such marketing materials if you have provided consent for us to do so.
If you want to unsubscribe from any emailed promotions that you had previously provided permission for us to send you, you should look for and follow the instructions we will provide in the relevant communications to you. This is usually located at the bottom of the email and identified by unsubscribe.
If you choose to unsubscribe from any or all mailings, we may retain information sufficient to identify you so that we can honour your request.Cookies and Pixels
You have certain rights in relation to the personal information we hold about you. In particular, you have the right to:
- Request a copy of personal information we hold about you;
- Ask that we update the personal information we hold about you, or correct such personal information that you think is incorrect or incomplete;
- Ask that we delete personal information that we hold about you, or restrict the way in which we use such personal information;
- Object to our processing of your personal information; and/or
- Withdraw your consent to our processing of your personal information (to the extent such processing is based on consent and consent is the only permissible basis for processing).
If you would like to exercise these rights or understand if these rights apply to you, please contact us at email@example.com
Automated decision making
We will not use your personal information for automated decision making or profiling.
We understand the importance of protecting children's privacy and we never knowingly collect personal information about individuals under the age of 13. We adhere to laws regarding marketing to children.
We do not intend to collect special category (also known as sensitive) personal information through our websites (unless we are legally required to do so). Examples of special category information are: race or ethnic origin; political opinions; religious or philosophical beliefs; trade union membership; physical or mental health; genetic data; biometric data; sexual life or sexual orientation; and criminal records.We ask that you do not provide us with special category personal information when using our websites.
If you have any questions or complaints about the way your personal information is processed by us, or would like to exercise one of your rights set out above, please contact us by one of the following means:
Contact our Data Privacy Officer at:firstname.lastname@example.org