Apply now

Personal Data Protection Notice

This notice is issued under Singapore’s Personal Data Protection Act 2012 (PDPA). It sets out how to reach the Data Protection Officer of Uniweb Pte Ltd, how consent works and how to withdraw it, how to ask what personal data is held about you or have it corrected, and what to do if you are not satisfied with the answer. What data is collected and why is set out in the privacy policy.

Data Protection Officer

Uniweb Pte Ltd, trading as Uniweb Pay, of Beach Road #23-08A, Gateway East, Singapore 189721. Uniweb Pte Ltd is a Major Payment Institution licensed by the Monetary Authority of Singapore under the Payment Services Act 2019, Licence No. PS20200612.

The PDPA requires an organisation to designate a Data Protection Officer and to make that officer’s business contact information available. For Uniweb Pte Ltd:

  • Email — [email protected], marked for the attention of the Data Protection Officer
  • Telephone — +65 8385 3698
  • Post — Data Protection Officer, Uniweb Pte Ltd, Beach Road #23-08A, Gateway East, Singapore 189721

Every request described on this page goes to that address. You do not need to use a particular form of words for a request to count.

Consent

Personal data is collected, used and disclosed with consent, or where the PDPA otherwise permits or requires it.

In practice consent arises in three ways, and they are worth distinguishing because withdrawal works differently for each:

  • Consent you give — for example when you submit an application, or agree to receive marketing.
  • Deemed consent — where you voluntarily provide data for a purpose that is obvious from the circumstances, such as sending an email so that it can be answered.
  • Without consent — where the PDPA permits or another law requires it. Customer due diligence, sanctions screening, transaction record-keeping and reporting under the Payment Services Act 2019 and the MAS anti-money-laundering notices are in this category, and they are obligations rather than choices.

Withdrawing consent

You may withdraw consent for any use that relies on it, at any time, by writing to the Data Protection Officer. Marketing is the clearest example, and it can be withdrawn without affecting anything else.

Two things follow, and it is fairer to say them now than at the point of the request:

  • Withdrawing consent for a use that a service depends on may mean the service can no longer be provided. If that is the case for what you have asked, we will tell you what the consequence is before acting on the withdrawal.
  • Withdrawal does not reach data that is being retained under a legal obligation. Records that the Payment Services Act and the MAS notices require to be kept for a statutory period continue to be kept for that period.

Once a withdrawal takes effect, use of the data for that purpose stops.

Asking what data is held about you

Under the PDPA’s access obligation you may ask for the personal data about you that is in the organisation’s possession or under its control, and for information about how it has been used or disclosed in the year before the request.

Write to the Data Protection Officer and include enough to let us find it and to satisfy ourselves that the request is yours: your name and contact details, the business or account the request relates to if there is one, and what you are asking about. A narrower request is usually answered faster than a request for everything.

We respond as soon as reasonably possible. Where a response cannot be given within 30 days of the request, the PDPA requires us to tell you within that time by when it will be given. A fee may apply for an access request; if one does, we will tell you the amount first and give you the chance to withdraw the request.

Some data cannot be provided. The PDPA sets out those exceptions, and they include data whose disclosure would reveal personal data about another individual, and material connected to an investigation or to legal proceedings. Where an exception applies, we say so.

Asking for a correction

If personal data held about you is inaccurate or incomplete, you may ask for it to be corrected. Write to the Data Protection Officer identifying the data and what it should say.

Where a correction is made, it is sent to the organisations the data was disclosed to in the year before the correction, unless they do not need it for any legal or business purpose. Where we consider a correction should not be made, we record the request alongside the data and explain the reason.

Accuracy, protection and retention

The PDPA obliges an organisation to make a reasonable effort to keep personal data accurate and complete where it will be used to make a decision affecting you or disclosed to another organisation, to protect it with reasonable security arrangements, and to stop keeping it once retention no longer serves a legal or business purpose.

How that works here — including the five-year statutory retention floor for customer due diligence and transaction records under the MAS anti-money-laundering notices — is described in the privacy policy.

Transfers out of Singapore

Where personal data is transferred outside Singapore, the PDPA’s transfer limitation obligation requires the recipient to be bound to a standard of protection comparable to the Act. Cross-border payments make some transfers unavoidable; where one is necessary, that is the standard it is made under.

Do Not Call

The PDPA’s Do Not Call provisions govern marketing messages sent to Singapore telephone numbers. Before sending a specified marketing message to a Singapore number, an organisation must check the relevant Do Not Call register unless it has clear and unambiguous consent in evidential form.

If you would rather not receive marketing from us at all, whatever the register says, write to the Data Protection Officer and say so. That request is honoured directly and does not depend on your registration.

Data breaches

The PDPA requires an organisation to assess a data breach and, where it is notifiable — because it results in or is likely to result in significant harm to affected individuals, or is of significant scale — to notify the Personal Data Protection Commission, and affected individuals, in accordance with the Act and within the time it prescribes.

That obligation is taken as it stands. A breach affecting your data would be notified to you as the Act requires.

If you are not satisfied

Raise it with the Data Protection Officer first, at [email protected]. Most questions are faster to resolve directly, and we would rather hear it.

If the answer does not resolve it, the Personal Data Protection Commission is the authority responsible for administering the PDPA in Singapore, and a complaint may be made to it. The PDPC generally expects an individual to have raised the matter with the organisation first.

Last updated: 2026-08-05