Privacy Policy

Personal Data Protection Policy of Ace Infinity Pte Ltd

 This Privacy and Personal Data Protection Policy establish how Ace Infinity Pte Ltd manages, protects, and secures personal data in compliance with:

This policy ensures that personal data is protected against unauthorized access, disclosure, alteration, and destruction, while aligning with ISS cybersecurity governance and risk management framework.

 Ace Infinity Pte Ltd implements cybersecurity controls aligned with the Cyber Trust Mark (CTM) to ensure the confidentiality, integrity, and availability of personal and business data. These controls include access control, monitoring, incident response, and data protection measures in accordance with CTM requirements.

Each department in Ace Infinity Pte Ltd has different channels for collecting personal data but is committed to complying with this Policy in its collection, use, and disclosure of personal data to ensure accountability and uniformity in protecting your personal data. Although this Policy is in common use, each department is responsible to you to the extent of its own collection, use, and disclosure of your personal data and its own actions.

You agree and consent to us, the Organization, and our authorized service providers and third parties to collect, use, disclose, and/or retain your Personal Data in the manner set forth in this Personal Data Protection Policy.

This Personal Data Protection Policy supplements but does not supersede or replace any other consent you may have previously provided to us nor does it affect any right we may have at law in connection with the collection, use, disclosure, and/or retention of your Personal Data.

From time to time, we may update this Personal Data Protection Policy without prior notice to ensure that our Policy is consistent with any regulatory changes. The updated Policy will supersede earlier versions and will apply to personal data provided to us previously. Should any revisions be made to this Personal Data Protection Policy, updates will be published on our website.

This Personal Data Protection Policy forms a part of the terms and conditions governing your relationship with us and should be read in conjunction with such terms and conditions (“Terms and Conditions”). In the event of any inconsistency between the provisions of the Personal Data Protection Policy and the Terms and Conditions, the provisions of the Terms and Conditions shall prevail.

Your Personal Data

The Personal Data we collect depends on the purposes for which we require the data and what you have chosen to provide. In this Personal Data Protection Policy, “Personal Data” refers to any data and/or information about you from which you can be identified, either (a) from that data; or (b) from that data and other information to which we may have legitimate access. Examples of such Personal Data include but are not limited to:

The personal data collected will depend on the nature and purpose of the individual’s relationship with Ace Infinity Pte Ltd.

Collection and Use of Personal Data

Ace Infinity Pte Ltd shall collect, use and disclose personal data for legitimate business purposes and in accordance with applicable data protection requirements.

Where consent is required, individuals shall be informed of the relevant purpose for the collection, use or disclosure of their personal data.

Personal data may be collected through the following channels:

Where an individual provides personal data relating to another person, the individual should ensure that they are authorised to provide such information.

Ace Infinity Pte Ltd shall only collect personal data that is relevant to the applicable business, legal, contractual or operational purpose.

Purposes for the Collection, Use, and Disclosure of Your Personal Data

In compliance with PDPA and CTM (B.3 Risk Management, B.9 Data Protection, B.12 System Security), personal data is collected and used for the following purposes:

General Purposes

Job Applicants:

Employees:

Clients, Vendors and Business Partners

Additional Business Purposes

 Ace Infinity Pte Ltd may also:

We ensure that all data collected is accurate, complete, and relevant.

Marketing/Optional Purposes

From time to time, and with your consent, we may contact you via mail, electronic mail, telephone (including calls or SMS), facsimile, or social media platforms to inform you about our management systems, services, promotions, and events that may be of interest to you.

We may also analyse your interactions, transactions, preferences, and feedback to provide you with relevant or targeted updates, including information on events, product launches, promotions, and marketing communications from Ace Infinity Pte Ltd. and/or its affiliated or related entities.

You may opt out of receiving marketing communications at any time by contacting us at sales@aceinfinity.com.sg and we will remove your details from our marketing database. Please note that we may still send you non-marketing communications, such as service-related notices, customer support messages, surveys, or legally required notifications.

Withdrawing Consent

The consent you provide for collection, use, and disclosure of personal data will remain valid until you withdraw it in writing. You may withdraw consent and request us to stop using and/or disclosing your personal data for any or all purposes by submitting your request in writing or via email to our Human Resources Department.

Upon receipt of your request, we may require reasonable time (depending on complexity) to process your request and notify you of consequences, including any legal implications. Generally, we will process your request within (30) business days.

Please note: withdrawing consent may limit our ability to process your job application or continue employment-related processes. You may cancel the withdrawal of consent by informing us in writing. Withdrawal does not affect our right to process personal data that were permitted or required by law.

Disclosure of Your Personal Data

We may disclose your Personal Data to the following groups of external organisations for purposes mentioned above, subject to the requirements of applicable laws:

Third-Party Data Protection

All third-party service providers handling personal data are required to:
• Comply with applicable data protection and cybersecurity requirements
• Sign confidentiality and data protection agreements
• Undergo vendor risk assessments
• Implement security controls aligned with Cyber Trust Mark (CTM) requirements

Third-Party Consent

If you provide personal data of third parties (e.g., emergency contacts, family members, referees), you must ensure that prior consent has been obtained for collection, use, or disclosure of their personal data.

Disclosure of Personal Data

We take reasonable measures to protect personal data against unauthorized disclosure. Disclosure will only be made to authorized parties bound by confidentiality obligations, or as required by law.

Non-Disclosure

We do not sell, trade, or otherwise transfer your personally identifiable information to third parties. This does not include trusted third parties who assist us in operating our website, conducting our business, or servicing you as long as these parties agree to keep this information confidential. We may also release your information when we believe release is appropriate to comply with the law, enforce our site policies, or protect our and others’ rights, property, or safety. However, non-personally identifiable visitor information may be provided to other parties for marketing, advertising, or other uses.

International Transfer of Information

Information that you give us may be stored and processed and transferred between any of the countries in which we operate to enable us to use the information in accordance with this Privacy Policy.

Use of Cookies

We may collect or analyse anonymized information from which individuals cannot be identified (“Aggregate Information”), such as the number of users and their frequency of use, the number of page views (or page impressions) that occur on our website, and common entry and exit points into our website. We make use of “cookies” to store and track Aggregate Information about you when you enter our websites.

Third-Party Sites

Our website may contain links to other websites operated by third parties independent of us. We are not responsible for the privacy practices or policies of such third-party websites.

Protection and Accuracy of Personal Data

We maintain appropriate administrative, technical, and physical safeguards to protect your Personal Data against loss, misuse, and unauthorised access, disclosure, alteration, and destruction. We also train our employees to properly handle personal data. However, you should be aware that no method of transmission over the internet or method of electronic storage is completely secure.

Access Control and Least Privilege

Access to personal data is restricted based on business roles and responsibilities, following the principle of least privilege. Access rights are approved, periodically reviewed, and revoked upon role change or termination. Multi-factor authentication (MFA) is implemented where applicable.

Monitoring and Logging

Systems handling personal data are monitored and logged to detect unauthorized access and security incidents. Logs are protected, regularly reviewed, and retained for audit and compliance purposes.

Secure Transmission of Data

Personal data transmitted over networks is protected using secure encryption protocols (e.g., HTTPS, VPN) to prevent unauthorized access or interception.

Retention of Personal Data

We will not retain any personal data longer than necessary for the fulfilment of the purpose for which it was collected or as required or permitted by applicable laws. We will cease to retain personal data, or remove the means by which personal data can be associated with individuals when it is no longer necessary for any business or legal purposes.

Data Classification

Personal data is classified based on sensitivity levels (e.g., Confidential, Internal, Public). Appropriate protection measures are applied based on classification.

Secure Disposal of Personal Data

Personal data is securely disposed of when no longer required using secure deletion methods for electronic data and shredding or destruction for physical records. Disposal activities are documented and verified.

Access and Correction of Your Personal Data

You may request access or make corrections to your personal data held by us. We will need sufficient information from you to establish your identity and to understand the nature of your request so that we can respond to your request. Any request for access to personal data should be made in writing using the form provided on our website and submitted to the Data Protection Officer at lh.goh@aceinfinity.com.sg.

Please note that a reasonable fee may be charged for an access request. If so, we will inform you of the fee before processing your request. We will respond to your request as soon as reasonably possible. If we are unable to respond to your request within thirty (30) days after receiving your request, we will inform you in writing within thirty (30) days of the time by which we can respond to your request.

If we are unable to provide you with any personal data or to make a correction requested by you, we shall generally inform you of the reasons unless we are not required to do so under the PDPA.

Complaint Process

If you have any complaint or grievance regarding how we are handling your Personal Data or about how we are complying with the PDPA, we welcome you to contact us with your complaint or grievance.

We will certainly strive to deal with any complaint or grievance that you may have speedily and fairly.

Data Breach Notification

In the event of a personal data breach, Ace Infinity Pte Ltd will:
• Assess, contain, and investigate the incident
• Notify affected individuals and relevant authorities where required
• Implement corrective actions to prevent recurrence
• Maintain records of all incidents for audit and compliance purposes

Contacting Us

If you have any questions or feedback relating to your Personal Data or our Policy and

If personal data is disclosed to public agencies, courts and law enforcement agencies when required for the purposes of investigations or proceedings, the Cybersecurity Champion will send the request to the DP Committee for formal approval before releasing.

If you withdraw your consent to any or all use or disclosure of your Personal Data, depending on the nature of your request, Ace Infinity Pte Ltd (may not be in a position to continue to provide our products or services to you or administer any contractual relationship in place. Such withdrawal may also result in the termination of any agreement you may have with Ace Infinity Pte Ltd (Legal rights and remedies are expressly reserved in such an event.

You may contact us to inquire about this Personal Data Protection Policy, or to provide feedback, request access to personal data, or withdraw your consent at any time via email to the Cybersecurity Champion.

Contact Details:

If you have any questions or concerns about this policy, please contact us through the following methods:

Name of Cyber Security Analyst: Mr. Tuan Asyraf

Contact No.: 68177965

Email Address: asyraf@aceinfinity.com.sg

Address: 6 Ubi Road 1 #06-05 Wintech Centre Singapore 408726

Thank you for trusting us with your personal data. Your privacy matters.

Changes to Privacy Policy

We keep our privacy policy under regular review. If we change our privacy policy, we will post the changes on this page so that you may be aware of the information we collect and how we use it at all times. This privacy policy was last updated in April 2026

Governing Law

 Ace Infinity Pte Ltd has appointed a Cybersecurity Champion responsible for ensuring compliance with the Personal Data Protection Act (PDPA) and handling all matters relating to personal data protection, access, and complaints.

In addition, the organisation has designated a Cybersecurity Champion responsible for overseeing the implementation, monitoring, and continuous improvement of cybersecurity controls in alignment with the Cyber Trust Mark (CTM) requirements.

Senior management provides oversight and ensures adequate resources are allocated to support both data protection and cybersecurity functions across the organisation.