Privacy Policy
Personal Data Protection Policy of Ace Infinity Pte Ltd
This Privacy and Personal Data Protection Policy establish how Ace Infinity Pte Ltd manages, protects, and secures personal data in compliance with:
- Singapore Personal Data Protection Act (PDPA)
- Cyber Trust Mark (CTM) requirements:
- Internal cybersecurity policies and controls
This policy ensures that personal data is protected against unauthorized access, disclosure, alteration, and destruction, while aligning with ISS cybersecurity governance and risk management framework.
Ace Infinity Pte Ltd implements cybersecurity controls aligned with the Cyber Trust Mark (CTM) to ensure the confidentiality, integrity, and availability of personal and business data. These controls include access control, monitoring, incident response, and data protection measures in accordance with CTM requirements.
Each department in Ace Infinity Pte Ltd has different channels for collecting personal data but is committed to complying with this Policy in its collection, use, and disclosure of personal data to ensure accountability and uniformity in protecting your personal data. Although this Policy is in common use, each department is responsible to you to the extent of its own collection, use, and disclosure of your personal data and its own actions.
You agree and consent to us, the Organization, and our authorized service providers and third parties to collect, use, disclose, and/or retain your Personal Data in the manner set forth in this Personal Data Protection Policy.
This Personal Data Protection Policy supplements but does not supersede or replace any other consent you may have previously provided to us nor does it affect any right we may have at law in connection with the collection, use, disclosure, and/or retention of your Personal Data.
From time to time, we may update this Personal Data Protection Policy without prior notice to ensure that our Policy is consistent with any regulatory changes. The updated Policy will supersede earlier versions and will apply to personal data provided to us previously. Should any revisions be made to this Personal Data Protection Policy, updates will be published on our website.
This Personal Data Protection Policy forms a part of the terms and conditions governing your relationship with us and should be read in conjunction with such terms and conditions (“Terms and Conditions”). In the event of any inconsistency between the provisions of the Personal Data Protection Policy and the Terms and Conditions, the provisions of the Terms and Conditions shall prevail.
Your Personal Data
The Personal Data we collect depends on the purposes for which we require the data and what you have chosen to provide. In this Personal Data Protection Policy, “Personal Data” refers to any data and/or information about you from which you can be identified, either (a) from that data; or (b) from that data and other information to which we may have legitimate access. Examples of such Personal Data include but are not limited to:
- Name and identification information;
- Contact number, mailing address and email address;
- Employment and educational information;
- Information provided in applications, forms or business communications;
- Emergency contact or next-of-kin information;
- Payment or billing-related information;
- Photographs or images;
- Access and security-related information;
- CCTV images or recordings;
- System, device and account-related information; and
- Information relating to the use of organizational systems or services.
The personal data collected will depend on the nature and purpose of the individual’s relationship with Ace Infinity Pte Ltd.
Collection and Use of Personal Data
Ace Infinity Pte Ltd shall collect, use and disclose personal data for legitimate business purposes and in accordance with applicable data protection requirements.
Where consent is required, individuals shall be informed of the relevant purpose for the collection, use or disclosure of their personal data.
Personal data may be collected through the following channels:
- Business and service applications;
- Employment and recruitment activities;
- Communications with employees or authorised representatives;
- Email, telephone calls, meetings and other communication channels;
- Customer, supplier and business partner interactions;
- Organisational systems and approved cloud services;
- Access control and security systems;
- CCTV systems within applicable organisational premises;
- Business forms and records; and
- Other authorised business activities.
Where an individual provides personal data relating to another person, the individual should ensure that they are authorised to provide such information.
Ace Infinity Pte Ltd shall only collect personal data that is relevant to the applicable business, legal, contractual or operational purpose.
Purposes for the Collection, Use, and Disclosure of Your Personal Data
In compliance with PDPA and CTM (B.3 Risk Management, B.9 Data Protection, B.12 System Security), personal data is collected and used for the following purposes:
General Purposes
- Providing and administering IT systems, ERP solutions, and services
- Responding to enquiries, feedback, and complaints
- Processing payments and billing
- Managing client, vendor, and partner relationships
- Improving systems, services, and customer experience
- Conducting internal research, analysis, and audits
- Ensuring cybersecurity and system protection (monitoring, logging, incident response)
- Complying with legal, regulatory, and contractual obligations
- Protecting legitimate business interests under PDPA
Job Applicants:
- Assessing suitability for employment
- Verifying identity, qualifications, and background
- Conducting reference checks
- Managing recruitment processes
- Complying with legal requirements
Employees:
- HR administration (payroll, benefits, access control)
- Performance management and training
- Workplace safety, security, and business continuity
- Employment lifecycle management
- Regulatory and statutory compliance
Clients, Vendors and Business Partners
- Processing service applications and contractual arrangements
- Managing service delivery, enhancements and upgrades
- Client relationship management and communications
- Conducting surveys and service improvement initiatives
Additional Business Purposes
Ace Infinity Pte Ltd may also:
- Process applications for IT services and solutions
- Conduct market research and service improvement analysis
- Manage contractual relationships and service delivery
- Send service updates, newsletters, and event communications
- Perform HR-related administrative and operational functions
- Support business continuity and emergency contact management
- Conduct analytics for operational improvement
- Facilitate onboarding and termination processes
We ensure that all data collected is accurate, complete, and relevant.
Marketing/Optional Purposes
From time to time, and with your consent, we may contact you via mail, electronic mail, telephone (including calls or SMS), facsimile, or social media platforms to inform you about our management systems, services, promotions, and events that may be of interest to you.
We may also analyse your interactions, transactions, preferences, and feedback to provide you with relevant or targeted updates, including information on events, product launches, promotions, and marketing communications from Ace Infinity Pte Ltd. and/or its affiliated or related entities.
You may opt out of receiving marketing communications at any time by contacting us at sales@aceinfinity.com.sg and we will remove your details from our marketing database. Please note that we may still send you non-marketing communications, such as service-related notices, customer support messages, surveys, or legally required notifications.
Withdrawing Consent
The consent you provide for collection, use, and disclosure of personal data will remain valid until you withdraw it in writing. You may withdraw consent and request us to stop using and/or disclosing your personal data for any or all purposes by submitting your request in writing or via email to our Human Resources Department.
Upon receipt of your request, we may require reasonable time (depending on complexity) to process your request and notify you of consequences, including any legal implications. Generally, we will process your request within (30) business days.
Please note: withdrawing consent may limit our ability to process your job application or continue employment-related processes. You may cancel the withdrawal of consent by informing us in writing. Withdrawal does not affect our right to process personal data that were permitted or required by law.
Disclosure of Your Personal Data
We may disclose your Personal Data to the following groups of external organisations for purposes mentioned above, subject to the requirements of applicable laws:
- Our professional advisers such as our auditors;
- Relevant government regulators, statutory boards, or authorities or law enforcement agencies to comply with any laws, rules, guidelines, and regulations or schemes imposed by any government authority;
- Third parties who are appointed to provide services to us, e.g., IT vendors, marketing companies, and event organisers;
- Business partners that provide any membership services and benefits; and
- Any other person in connection with the purposes set forth above.
Third-Party Data Protection
All third-party service providers handling personal data are required to:
• Comply with applicable data protection and cybersecurity requirements
• Sign confidentiality and data protection agreements
• Undergo vendor risk assessments
• Implement security controls aligned with Cyber Trust Mark (CTM) requirements
Third-Party Consent
If you provide personal data of third parties (e.g., emergency contacts, family members, referees), you must ensure that prior consent has been obtained for collection, use, or disclosure of their personal data.
Disclosure of Personal Data
We take reasonable measures to protect personal data against unauthorized disclosure. Disclosure will only be made to authorized parties bound by confidentiality obligations, or as required by law.
Non-Disclosure
We do not sell, trade, or otherwise transfer your personally identifiable information to third parties. This does not include trusted third parties who assist us in operating our website, conducting our business, or servicing you as long as these parties agree to keep this information confidential. We may also release your information when we believe release is appropriate to comply with the law, enforce our site policies, or protect our and others’ rights, property, or safety. However, non-personally identifiable visitor information may be provided to other parties for marketing, advertising, or other uses.
International Transfer of Information
Information that you give us may be stored and processed and transferred between any of the countries in which we operate to enable us to use the information in accordance with this Privacy Policy.
Use of Cookies
We may collect or analyse anonymized information from which individuals cannot be identified (“Aggregate Information”), such as the number of users and their frequency of use, the number of page views (or page impressions) that occur on our website, and common entry and exit points into our website. We make use of “cookies” to store and track Aggregate Information about you when you enter our websites.
Third-Party Sites
Our website may contain links to other websites operated by third parties independent of us. We are not responsible for the privacy practices or policies of such third-party websites.
Protection and Accuracy of Personal Data
We maintain appropriate administrative, technical, and physical safeguards to protect your Personal Data against loss, misuse, and unauthorised access, disclosure, alteration, and destruction. We also train our employees to properly handle personal data. However, you should be aware that no method of transmission over the internet or method of electronic storage is completely secure.
Access Control and Least Privilege
Access to personal data is restricted based on business roles and responsibilities, following the principle of least privilege. Access rights are approved, periodically reviewed, and revoked upon role change or termination. Multi-factor authentication (MFA) is implemented where applicable.
Monitoring and Logging
Systems handling personal data are monitored and logged to detect unauthorized access and security incidents. Logs are protected, regularly reviewed, and retained for audit and compliance purposes.
Secure Transmission of Data
Personal data transmitted over networks is protected using secure encryption protocols (e.g., HTTPS, VPN) to prevent unauthorized access or interception.
Retention of Personal Data
We will not retain any personal data longer than necessary for the fulfilment of the purpose for which it was collected or as required or permitted by applicable laws. We will cease to retain personal data, or remove the means by which personal data can be associated with individuals when it is no longer necessary for any business or legal purposes.
Data Classification
Personal data is classified based on sensitivity levels (e.g., Confidential, Internal, Public). Appropriate protection measures are applied based on classification.
Secure Disposal of Personal Data
Personal data is securely disposed of when no longer required using secure deletion methods for electronic data and shredding or destruction for physical records. Disposal activities are documented and verified.
Access and Correction of Your Personal Data
You may request access or make corrections to your personal data held by us. We will need sufficient information from you to establish your identity and to understand the nature of your request so that we can respond to your request. Any request for access to personal data should be made in writing using the form provided on our website and submitted to the Data Protection Officer at lh.goh@aceinfinity.com.sg.
Please note that a reasonable fee may be charged for an access request. If so, we will inform you of the fee before processing your request. We will respond to your request as soon as reasonably possible. If we are unable to respond to your request within thirty (30) days after receiving your request, we will inform you in writing within thirty (30) days of the time by which we can respond to your request.
If we are unable to provide you with any personal data or to make a correction requested by you, we shall generally inform you of the reasons unless we are not required to do so under the PDPA.
Complaint Process
If you have any complaint or grievance regarding how we are handling your Personal Data or about how we are complying with the PDPA, we welcome you to contact us with your complaint or grievance.
We will certainly strive to deal with any complaint or grievance that you may have speedily and fairly.
Data Breach Notification
In the event of a personal data breach, Ace Infinity Pte Ltd will:
• Assess, contain, and investigate the incident
• Notify affected individuals and relevant authorities where required
• Implement corrective actions to prevent recurrence
• Maintain records of all incidents for audit and compliance purposes
Contacting Us
If you have any questions or feedback relating to your Personal Data or our Policy and
- a) Would like to withdraw your consent to any use of your Personal Data as set out in this Policy; or
- b) Would like to obtain access and make corrections to your Personal Data records, you can contact our Cybersecurity Champion via email asyraf@aceinfinity.com.sg Queries and complaints received are responded with 5 working days in relation to complaints, the response includes an explanation of remedial action where relevant.
If personal data is disclosed to public agencies, courts and law enforcement agencies when required for the purposes of investigations or proceedings, the Cybersecurity Champion will send the request to the DP Committee for formal approval before releasing.
If you withdraw your consent to any or all use or disclosure of your Personal Data, depending on the nature of your request, Ace Infinity Pte Ltd (may not be in a position to continue to provide our products or services to you or administer any contractual relationship in place. Such withdrawal may also result in the termination of any agreement you may have with Ace Infinity Pte Ltd (Legal rights and remedies are expressly reserved in such an event.
You may contact us to inquire about this Personal Data Protection Policy, or to provide feedback, request access to personal data, or withdraw your consent at any time via email to the Cybersecurity Champion.
Contact Details:
If you have any questions or concerns about this policy, please contact us through the following methods:
Name of Cyber Security Analyst: Mr. Tuan Asyraf
Contact No.: 68177965
Email Address: asyraf@aceinfinity.com.sg
Address: 6 Ubi Road 1 #06-05 Wintech Centre Singapore 408726
Thank you for trusting us with your personal data. Your privacy matters.
Changes to Privacy Policy
We keep our privacy policy under regular review. If we change our privacy policy, we will post the changes on this page so that you may be aware of the information we collect and how we use it at all times. This privacy policy was last updated in April 2026
Governing Law
Ace Infinity Pte Ltd has appointed a Cybersecurity Champion responsible for ensuring compliance with the Personal Data Protection Act (PDPA) and handling all matters relating to personal data protection, access, and complaints.
In addition, the organisation has designated a Cybersecurity Champion responsible for overseeing the implementation, monitoring, and continuous improvement of cybersecurity controls in alignment with the Cyber Trust Mark (CTM) requirements.
Senior management provides oversight and ensures adequate resources are allocated to support both data protection and cybersecurity functions across the organisation.