GDPR NOTICE – APPLICABLE TO EU DATA SUBJECTS ONLY
PRIMA GROUP DATA PRIVACY NOTICE
This is a Privacy Notice (“Notice”) issued under the General Data Protection Regulation.
In this Notice, “Prima Group”, “we”, “us” or “our” means Prima Limited and its subsidiaries and “you” or “your” means you, anyone who deals with us for you and other related people, including (without limitation) your authorised person signatories, directors, partners, employees, members, agents and representatives.
It applies to information we hold about you and individuals connected to your business and explains:
- Data Controller;
- How we collect Personal Data;
- Types of Personal Data we collect;
- How we use Personal Data;
- Disclosure of Personal Data to third parties;
- International transfer of Personal Data;
- How long we keep Personal Data;
- Your rights;
- Contact details;
“Personal Data” means any data relating to an individual who can be identified from that data, or from that data and other information which we have or are likely to have access to (and includes information which our representatives or service providers have). In addition to factual information, it also includes any expression of opinion about an individual, and any indication of our intentions (or the intentions of any other person) in relation to such an individual.
- DATA CONTROLLER
We are the controller of your Personal Data. We are responsible for deciding what information we collect and where we collect it. You should be aware that even though Prima Group is principally responsible for managing your Personal Data, such information may be shared within the Prima Group for the purposes as described in this Notice. When using your Personal Data, each member of the Prima Group will comply with the standards as set out in this Notice.
- DATA CONTROLLER
- TYPES OF PERSONAL DATA WE COLLECT
- 2.1 These are the types of Personal Data that we collect:
- (a) Information that you provide to us. The nature of your relationship with us, and the kind of communication that you request from us, will determine the type of Personal Data we may ask for, including but not limited to your email address, first and last names, job title, name of the company you work for, and the country where you are based, your education and employment history.
- (b) Information that is passively or automatically collected when you visit our website, including but not limited to how you arrive at our website, the type of browser and operating system you are using, your IP address, and your clickstream and timestamp information (e.g. the pages you have viewed, the time at which such pages were accessed, and the amount of time spent per page).
- HOW WE COLLECT PERSONAL DATA
- 3.1 These are some of the ways in which we collect Personal Data:
- (a) Information we receive when you contact us through our websites or by filling in and submitting your data via our websites below or as notified.
- (b) Information we receive when you subscribe to our mailing list;
- (c) If you are a customer or potential customer, information obtained by us through our business dealings;
- (d) If you are a shareholder, information provided by you in connection with your shareholding; and
- (e) If you are interested in a career opportunity with us, information provided by you in connection with your application.
- HOW WE USE PERSONAL DATA
- 4.1 Personal Data may be stored and used by us for the following purposes:
- (a) Where we have obtained your specific consent;
- (b) To send you marketing communications (e.g. press releases, sustainability reports, quarterly reports, annual reports and other publications which we think may be of interest to you);
- (c) If you are a customer or potential customer, to administer and manage our business relationship (including performance of any legal agreement between us);
- (d) If you are a shareholder, to keep in touch with you in connection with your shareholding;
- (e) If you are a job applicant, to assess your suitability for a career opportunity in which you have expressed interest; and
- (f) To comply with applicable laws and regulations.
- 4.2 However, we use Personal Data, we make sure that such use is lawful. The law allows or requires us to use Personal Data for various reasons. These include:
- (a) To perform our contractual obligations;
- (b) To discharge legal or regulatory obligations;
- (c) To do so under legal proceedings; and
- (d) To pursue our legitimate interests, such as (by way of a non-exhaustive list):
- (i) To detect and prevent fraud and other potentially illegal activities;
- (ii) To protect our network and information security (e.g. prevention of personal data breaches and cyber-attacks);
- (iii) To establish, exercise or defend our legal rights; and
- (iv) To conduct analytics on our website traffic, e.g. pages and links clicked, patterns of navigation, time spent at a page, devices used, location of users, etc.
- 4.3 Some of the aforesaid reasons for using Personal Data may overlap and there may be other reasons which justify our use of Personal Data.
- 4.4 We will take steps to ensure that Personal Data is accessed only by employees on a need-to basis as described in this Notice. They are subject to a duty of confidentiality and will only use Personal Data in accordance with our instructions.
- HOW WE STORE PERSONAL DATA
We have security measures in place to keep your information secure. Where we ask third parties to work on our behalf, we always ensure that they have sufficient information security measures in place.
We may send you information about our products and services that we think you may like. If you have agreed to receive marketing and no longer wish to be contacted for marketing purposes, you may always opt out at a later date.
- 7.1 What are cookies (“Cookies”)?
Cookies are small text files stored within your internet browser, placed there by the websites you visit. In a similar way to many other websites, we place Cookies on your browser to understand more about your visit and to help us enhance your experience.
Cookies aid various functions, such as keeping track of the items in your shopping bag, learning more about how you reached our site and storing your preferences so that you do not need to enter them upon every visit.
- 7.3 We have listed the types of Cookies we use and the functions they support.
- (a) Necessary Cookies
These Cookies are required for our website to function. If they are not accepted by you, parts of the website would be unusable. For example, these Cookies are used to ensure that our website pages are displayed correctly, and to determine which language and currency are used (based on your location).
- (b) Preferences Cookies
These Cookies allow us to remember your personalised preferences so that we can provide a more bespoke and unique online shopping experience. Each time you visit our website and use the search tool, your results will be based on previous filters you applied. We also store this information to understand more about how you use our website and which filters are important to you.
- (c) Statistics Cookies
We use Google’s analytics tools and Content Square to study how customers interact with our website and to improve it accordingly – this is known as web analytics. Statistics cookies help us understand the number of visitors to the website, the number of times they visit and number of times they viewed specific webpages within our site. Although statistics cookies allow us to gather specific information about the pages that you visit and whether you visited our website multiple times, we cannot use the information to obtain details such as your name or address.
- (d) Marketing Cookies
Aside from setting cookies ourselves, we also allow carefully selected third parties to set cookies during your visit to our website. These organisations provide us with information on how you use our website. These cookies are used to promote our newest products and latest offers to you on other websites based on your activity on our website. For example, you may see products that you viewed on our website presented on other websites as you move around the internet. These cookies collect information about your browsing habits to make advertising more relevant to you and your interests. They are also used to limit the number of times you see an advert and to help measure the effectiveness of an advertising campaign.
- (a) Necessary Cookies
- 7.4 How can I manage my Cookies?
Necessary Cookies cannot be switched off, however, in Cookie Preferences, you can withdraw consent for statistics, preferences and marketing cookies. You can also manage your cookie preferences by changing your browser settings so that Cookies are not accepted. If you choose to switch off all non-necessary cookies, please be aware that our website may no longer function as intended.For further information about Cookies, please visit the Information Commissioner’s Office webpage on Cookies, here.
- DISCLOSURE OF PERSONAL DATA TO THIRD PARTIES
- 8.1 We may share Personal Data within the Prima Group for the purposes as described in this Notice.
- 8.2 We may also share Personal Data outside of the Prima Group for the following purposes:
- (a) With third parties whom we have engaged to provide services to us (e.g. administrative, audit, logistics, information technology and research services). These third parties will be bound by appropriate data protection obligations and they will only use and process Personal Data on our behalf in accordance with our instructions and for the purposes as described in this Privacy Notice (and not for their own purposes);
- (b) Where we are required under law or regulation to disclose Personal Data; this may include (by way of a non-exhaustive list) disclosure in response to a court order, or release of information to a government authority, regulator or law enforcement agency;
- (c) To the extent mandated by law for the protection of our legitimate interests; and
- (d) In the event that our business is sold or integrated with another business, Personal Data may be disclosed to the prospective buyer and its advisors (who will be bound by appropriate data protection obligations), and will be passed to the new owner when it acquires the business.
- 8.3 Please be assured that we will not sell, rent or give away your Personal Data to third parties for commercial purposes without your consent.
- INTERNATIONAL TRANSFER OF PERSONAL DATA
- 9.1 Prima Group is a global business. Our customers and operations are located around the world. This means Personal Data is collected on a global basis, and may be transferred to locations outside of the country where it is collected.
- 9.2 We will always ensure that any international transfer of Personal Data is consistent with legal and regulatory requirements, e.g. (by way of a non-exhaustive list):
- (a) Where Personal Data is transferred to a country outside of the European Economic Area (“EEA”), such country is recognised by the European Commission as providing an adequate level of protection for Personal Data;
- (b) Where Personal Data needs to be transferred to a recipient based in a country outside of the EEA which is not recognised by the European Commission as providing an adequate level of protection for Personal Data, we will require such recipient to be bound by standard contractual clauses which are approved by the European Commission for the protection of Personal Data;
- (c) Where Personal Data is transferred from within the European Union to the United States, the recipient is a certified participant in the EU-U.S. Privacy Shield Framework; and
- (d) Where Personal Data is shared internationally within the Prima Group, such transfer is subject to Binding Corporate Rules which adequately safeguards the protection of privacy.
- HOW LONG WE KEEP PERSONAL DATA
- 10.1 We will retain Personal Data for only as long as is reasonably necessary for the purposes described in this Notice.
- 10.2 In some circumstances, however, legal or regulatory requirements may obligate us to retain Personal Data for a longer period of time.
- YOUR RIGHTS
- 11.1 You have the following rights in relation to your Personal Data:
- (a) Require us to provide information regarding your Personal Data, e.g. give you a copy of the Personal Data about you that we hold, let you know where we got your Personal Data, how we use your Personal Data, what we use it for, who we disclose it to, whether we transfer it to another country (and where), how we protect it and how long we keep it for (if such information is not already provided in this Notice);
- (b) Require us to rectify your Personal Data if it is inaccurate or incomplete; we may seek to verify any new information provided by you before we rectify our existing records;
- (c) Where the use of your Personal Data is based on your consent (see Paragraph 4.1(a)), you can withdraw your consent at any time; however, please note that we may still be entitled to use your Personal Data if we have another legitimate reason to do so, e.g. for a purpose as described in Paragraph 4.2;
- (d) Where the use of your Personal Data is based on our legitimate interests (see Paragraph 4.2(d)), you can object to such use if you believe your fundamental rights and freedoms outweigh our legitimate interests; however, there may be circumstances where we have a legal basis to deny your request;
- (e) Require us to delete your Personal Data, but only where:
- (i) You have withdrawn your consent for us to use your Personal Data (where the use of your Personal Data is based on your consent) (see Paragraph 4.1(a));
- (ii) It is no longer needed for the purpose for which it was collected;
- (iii) You have successfully objected to the use of your Personal Data (see Paragraph 8.1(d)); or
- (iv) We are required by law or regulation to do so.
However, we are not obliged to comply with your request to delete your Personal Data if we are legally entitled to retain it, e.g. for a purpose as described in Paragraph 4.2;
- (f) Require us to retain but not use your Personal Data; note, however, that this right is only available to you where:
- (i) You dispute its accuracy, and we are verifying it (see Paragraph 8.1(b));
- (ii) Its use is unlawful, but you do not want us to delete it;
- (iii) It is no longer needed for the purpose for which it was collected, but we still need it to establish, exercise or defend our legal rights; or
- (iv) You have raised your objection to the use of your Personal Data, and we are verifying whether we have a legal basis to deny your request (see Paragraph 8.1(d)).
Nonetheless, we are legally entitled to continue to use your Personal Data following a request by you not to use it, where:
- (i) We have your consent;
- (ii) We need to do so in order to establish, exercise or defend our legal rights; or
- (iii) We need to do so in order to protect the rights of another natural or legal person;
- (g) Where you have given us your Personal Data, require us to provide such data to you in a structured, commonly used and machine-readable format, or transmit such data to a third party where this is technically feasible; note, however, that this right is only available to you where:
- (i) The legal basis for processing your Personal Data is either your consent or the performance of a contract with you; and
- (ii) Such processing is carried out by us using automated means (i.e. excluding paper files);
- (h) Where your Personal Data is transferred outside of the EEA, require us to provide information on the safeguards under which such information is shared; and
- (i) To lodge a complaint with your national Personal Data Protection Commission about how we use your Personal Data; we ask that you please speak with us first to resolve any issues, but you have the right to contact your national Personal Data Protection Commission at any time if you wish to do so.
- 11.2 To exercise your rights, you may contact us at any time using the contact details provided in Paragraph 12. We may need to ask you for proof of identity when you contact us, so that we can be sure that your Personal Data is not disclosed to any person who has no right to receive it.
- CONTACT DETAILS
- 12.1 If you have any questions regarding this Notice, or if you wish to unsubscribe from our mailing list at any time, please contact us at:
201 Keppel Road Singapore 099419
Tel: +65 6272 8811
Fax: +65 6273 2399
- 12.2 The person above is also our Data Protection Officer for the purposes of the Singapore Personal Data Protection Act 2012.
- 12.3 If you have any concerns about how we use your Personal Data, please contact us in the first instance and we will do our best to address your concerns as quickly as possible. You may also lodge a complaint with your national data protection supervisory authority at any time if you wish to do so (see Paragraph 10.1(i)).
- 13.1 From time to time, we may update this Notice to take into account new legal requirements, advancements in information technology, or changes in the way we operate our business. We invite you to review the Notice from time to time so that you will always know what personal information we collect, how we collect it, how we use it and who we share it with.
- 13.2 This Notice was last updated on 26 November 2020.