01
Information We Collect
We collect information that you provide to us directly, information generated when you use our website and services, and information we receive from third parties where permitted by law. This includes:
- Identity and contact details: name, email address, phone number, date of birth and identification documents required for onboarding and compliance checks
- Account data: login credentials, client portal preferences and communication history
- Financial information: bank account details, transaction records, payroll data and documents needed for advisory, audit or tax engagements
- Technical data: IP address, browser type and version, device identifiers, pages visited and usage patterns collected through cookies and similar technologies
- Compliance data: information required for know-your-customer (KYC), anti-money-laundering (AML) and sanctions screening
02
How We Use Your Information
We use personal data only for the purposes for which it was collected, and on lawful bases such as performance of a contract, compliance with legal obligations, or our legitimate interests. In particular, we use your information to:
- Provide, operate and improve our financial consulting, audit, tax, payroll and payment services
- Open and administer your account and verify your identity as required by law
- Process transactions, settlements and payroll runs, and send related notices
- Respond to enquiries and provide customer support
- Meet regulatory, audit, tax and reporting obligations, including AML and sanctions screening
- Protect the security and integrity of our systems, and detect and prevent fraud
- Send service communications and, with your consent where required, marketing communications you can opt out of at any time
03
Data Security
We take the security of your data seriously. We maintain technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, destruction or loss. These measures include encryption of data in transit and at rest, role-based access controls, multi-factor authentication for privileged access, regular security testing and staff training.
No method of transmission over the internet is completely secure. While we work hard to protect your personal data, we cannot guarantee absolute security, and we encourage you to safeguard your own login credentials.
04
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, regulatory, tax or accounting requirements. Retention periods depend on the nature of the data and the applicable legal obligations; for example, financial and audit records are typically retained for the minimum periods required by Singapore law and relevant regulatory guidance. When data is no longer needed, we securely delete or anonymise it.
05
Sharing of Information
We do not sell your personal data. We may share it only with the following categories of recipients, and only to the extent necessary:
- Service providers acting on our instructions, such as technology, payment, payroll and audit service providers, bound by contractual confidentiality and data protection obligations
- Banks, payment networks and financial institutions necessary to process transactions
- Regulators, courts, law enforcement and government authorities where required by law or to protect our legal rights
- Professional advisers, such as lawyers and auditors, subject to duties of confidentiality
- A successor entity in connection with a merger, acquisition or reorganisation
06
Your Rights
Depending on the laws that apply to you, including the Singapore Personal Data Protection Act (PDPA) and, where applicable, the GDPR, you may have the right to:
- Access the personal data we hold about you and receive a copy of it
- Request correction of inaccurate or incomplete data
- Request deletion of your data where there is no lawful basis to retain it
- Withdraw consent you have previously given, without affecting processing carried out before withdrawal
- Object to or restrict certain processing, including direct marketing
- Request portability of your data to another service provider
- Lodge a complaint with the relevant supervisory authority
07
Third-Party Services
Our website and services may contain links to third-party websites or integrate third-party services, for example payment processors or analytics providers. We are not responsible for the privacy practices of such third parties. We encourage you to read the privacy policies of every service you use.
08
Children’s Privacy
Our services are intended for adults and businesses, and are not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so that we can delete it.
09
Changes to This Policy
We may update this Privacy & Security Policy from time to time to reflect changes in our practices, technology or legal requirements. The updated version will be posted on this page with a revised "last updated" date. Material changes will be notified through the client portal or by email before they take effect.
10
Contact Information
To exercise your rights, or for any privacy-related enquiry, please contact us:
- Email: cs@bdlpay.com
- Address: 67, AYER RAJAH CRESCENT, #01-21 SINGAPORE