PRIVACY POLICYEffective Date: August 27, 2026
This Website Privacy Policy explains how MINTHILL PTE. LTD., a company registered in Singapore (“MINTHILL”, “Company”, “we”, “us” or “our”), processes personal data collected through our website
infoo@payplatform.org.
We provide services on Backend Development, API & System Integrations, Infrastructure & DevOps, Real-Time Data Processing.
This Privacy Policy applies only to personal data processed by us as a controller in connection with this website. Where we process personal data on behalf of our clients as a processor in the course of providing services, that processing is governed by the relevant client agreement and data processing agreement.
1. Controller and contact detailsThe controller of your personal data is:
MINTHILL PTE. LTD.
UEN 202414412Z
Address: 216 JOO CHIAT ROAD, #02-16/6, SOHO LIFE, SINGAPORE (427483)
Email:
infoo@payplatform.org 2. Applicable legal framework and geographic scopeSINGAPORE - PDPAThe Company is established in Singapore. Processing falling within the territorial scope of the Singapore`s Law on Personal Data Protection Act 2012 (hereinafter referred to as the "PDPA") of Singapore and its subsidiary legislation, including, but not limited to, the Personal Data Protection (Notification of Data Breaches) Regulations 2021.
European Union and European Economic Area - GDPR
The EU General Data Protection Regulation, Regulation (EU) 2016/679 ("GDPR"), applies where the relevant processing falls within its territorial scope. This may include processing carried out in the context of an establishment in the EU/EEA, or processing by a non-EU controller that is related to intentionally offering goods or services to individuals in the EU/EEA or monitoring their behavior there. Mere accessibility of the Website in the EU/EEA does not, by itself, determine that the GDPR applies.
We do not use Website analytics, behavioral advertising, profiling or other tools intended to monitor visitors' behavior. Where the GDPR does not legally apply to a particular Website interaction, we nevertheless aim to apply substantially equivalent transparency, security and rights-handling standards to individuals in the EU/EEA.
The operational parts of this Policy apply generally. Where a legal basis or right must be identified under a specific law, the relevant GDPR and PDPA provisions are stated separately.
3. Personal Data We Collect2.1 Data You Provide Directly
When you interact with our website or contact us, we may collect the following categories of personal data:
• Contact information: full name, company name, email address
• Communication data: we may also collect the content of any message, enquiry or request that you submit to us through the form, if the form contains a message field or similar free-text field.
2.2 Data Collected Automatically
When you visit our website, we may automatically collect:
• Technical data: IP address, browser type and version, operating system, device information
2.3 Sensitive Personal Data
We do not intentionally collect sensitive personal data (e.g., NRIC/FIN numbers, health information, racial or ethnic origin, religious beliefs) through our website.
4. Purposes of Collection and how this is permitted under the PDPA and GDPRWe process personal data collected through the website for the following purposes:
Purpose | Personal data | How this is permitted under the PDPA | GDPR legal basis |
Responding to enquiries | Inquiry form data: full name, company name, contact email and message content | We collect and use the personal data you voluntarily submit to us, such as your full name, company name, contact email and message content, to respond to your enquiry and communicate with you about it. Where required under the PDPA, we will rely on your consent or deemed consent for this purpose. We do not use personal data submitted through the contact form to send marketing communications unless we have separately notified you of that purpose and, where required, obtained your consent. | Art. 6(1)(f): legitimate interests in responding to professional and business inquiries. |
Legal and regulatory compliance | Relevant inquiry, technical and communication records. | We may collect, use or disclose personal data where this is required or authorized by applicable law, regulation, court order or regulatory requirement, or where another applicable exception under the PDPA applies. | Art. 6(1)(c): processing when it is necessary to comply with a legal obligation. |
Operating, troubleshooting and securing the Website; preventing spam, fraud, misuse and cyber incidents. | Strictly necessary cookie data and basic technical data required for website operation | We may collect, use and where necessary disclose personal data to protect our Website, systems, users and business, including for fraud prevention, misuse detection, incident response and investigations, where permitted under the PDPA, including under applicable exceptions, and where required or authorized by law. | Art. 6(1)(f): legitimate interests in a secure, reliable Website. |
|
|
|
|
5. Disclosure of Personal Data5.1 Third-Party Service Providers
We may disclose personal data to third-party service providers, including data intermediaries, that process personal data on our behalf and for our purposes, such as IT and hosting providers, business systems providers, professional advisers and other operational support providers.
Where a service provider acts as our data intermediary, we require it to process personal data in accordance with a written contract and to implement appropriate security and retention measures. We remain responsible for complying with the PDPA in relation to processing carried out on our behalf and for our purposes.
5.2 Regulatory and Legal Authorities
We may disclose personal data to government agencies, regulators, law enforcement bodies, or courts where required by law, including under the PDPA and/or GDPR, or applicable anti-money laundering legislation. Such disclosures are made only to the extent required and permitted by law.
5.3 Business Transfers
In the event of a merger, acquisition, or sale of all or part of our business assets, personal data held by us may be transferred to the successor entity, subject to equivalent data protection obligations.
5.4 No Sale of Personal Data
We do not sell, rent, or trade your personal data to third parties for their own marketing purposes.
6. Transfer of Personal Data Outside SingaporeThe Company is established in Singapore. Personal data submitted through the Website may therefore be received, stored or otherwise processed in Singapore. Singapore is outside the EEA and, as of the last update of this Policy, is not a country covered by an adequacy decision of the European Commission. Where the GDPR's international-transfer rules apply to a transfer of personal data to Singapore or another country outside the EEA, we rely on an available lawful transfer mechanism, such as an applicable adequacy decision, the European Commission's Standard Contractual Clauses, together with supplementary measures where required, or another mechanism permitted under Chapter V GDPR. Derogations under Article 49 GDPR are used only where the applicable legal conditions are met.
Where Singapore's Personal Data Protection Act 2012 (PDPA) and its transfer rules apply to a transfer of personal data from Singapore to a country or territory outside Singapore, we take appropriate steps to ensure that the recipient is subject to legally enforceable obligations providing a standard of protection that is at least comparable to the protection under the PDPA, or we rely on another basis or exception permitted by applicable law. Such safeguards may include contractual obligations, binding corporate rules, applicable law or recognized certification mechanisms. You may contact us for information about the safeguards relevant to your personal data, subject to applicable confidentiality restrictions.
7. Retention of Personal DataWe retain personal data only for as long as necessary for the relevant purpose, taking into account applicable legal obligations, statutory limitation periods, security needs and the principle of data minimization.
Inquiry-form submissions and related correspondence are retained for up to six months after the inquiry is closed or after the last substantive communication. If an inquiry leads to pre-contractual negotiations or a contractual relationship, the relevant records may be transferred to separate business or client files and retained in accordance with the applicable contract, a separate privacy notice, applicable legal retention requirements and statutory limitation periods.
Routine server, security and error logs are normally retained for up to 90 days. Such logs may be retained for a longer period where necessary to investigate a security incident, prevent or address abuse, comply with applicable law, or establish, exercise or defend legal claims.
Data contained in strictly necessary technical cookies are retained only for the duration of the relevant session or for the limited technical period required for the relevant Website function. Such data may be retained for a longer period only where this is necessary for security, troubleshooting or the establishment, exercise or defense of legal claims.
8. Your Rights Under the PDPA and/or GDPRSubject to the conditions and limitations under applicable data protection law, you may have the right to:
- request access to your personal data;
- request correction of inaccurate or incomplete personal data;
- request deletion of your personal data;
- request restriction of processing;
- object to processing based on legitimate interests;
- request data portability, where applicable;
- withdraw consent, where processing is based on consent;
- lodge a complaint with a supervisory authority.
Rights and complaint under the PDPA
To exercise any of the above rights, please submit a written request to our DPO at
infoo@payplatform.org. We may require you to verify your identity before processing your request. We reserve the right to charge a reasonable fee for access requests in accordance with the PDPA. We will respond to all verified requests as soon as reasonably possible.
EU/EEA - rights and complaint under the GDPR
To exercise any of the above rights, please submit a written request to our DPO at
infoo@payplatform.org.
Where the GDPR applies, you may lodge a complaint with a supervisory authority in the EU/EEA Member State of your habitual residence, place of work or the place of the alleged infringement. A list of EU/EEA supervisory authorities is available from the European Data Protection Board.
9. Cookies and technical informationOur website uses only strictly necessary technical cookies and similar technologies that are required for the website to function properly, maintain security, remember essential settings, and support basic website operations.
We do not use analytics cookies, advertising cookies, marketing cookies, tracking pixels or behavioral profiling technologies on this website.
Strictly necessary cookies may collect limited technical information, such as:
- session identifiers;
- cookie preference or security-related information;
- technical logs necessary for website operation and security;
- browser and device information required to display the website correctly.
These cookies cannot be switched off through our website because they are necessary for the website to operate. You may be able to block or delete cookies through your browser settings, but doing so may affect the functionality or security of the website.
10. Security of Personal DataMINTHILL implements appropriate technical and organizational security measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Our security measures include:
• Access controls and role-based permissions limiting access to personal data to authorized personnel only;
• Regular security assessments and vulnerability scanning of our website and systems;
• Staff training on data protection and security awareness;
• Contractual security obligations imposed on all third-party data processors;
• Incident response procedures, including our Data Breach Response Plan.
In the event of a personal data breach, we will comply with applicable notification requirements under the PDPA and, where applicable, the GDPR. Where required by applicable law, this may include notifying the PDPC, the competent EU/EEA data protection supervisory authority or authorities, and affected individuals within the applicable statutory timeframes and subject to the relevant legal thresholds and exceptions.
11. Children’s PrivacyOur Website is not intended for individuals under the age of 16, and we do not knowingly collect, use, or disclose personal data from minors.
We request that individuals under the age of 16 do not submit any personal data through the Website or contact forms. If we become aware that personal data has been provided by a minor without verifiable parental or guardian consent, we will take reasonable steps to delete such data as soon as practicable, in accordance with the Protection Obligation and Retention Limitation Obligation under the PDPA.
If you believe that a minor has provided personal data to us, please contact so that appropriate action may be taken.
12. Changes to This PolicyWe reserve the right to update or amend this Privacy Policy at any time. Material changes will be notified to you via our website or, where we hold your email address, by email. The "Effective Date" at the top of this Policy indicates when the current version was last updated. We encourage you to review this Policy periodically.
13. Contact Us & ComplaintsFor any questions, concerns, or requests relating to this Privacy Policy or our data protection practices, please contact our Data Protection Officer:
Name / Title | Data Protection Officer |
Organization | MINTHILL PTE. LTD. |
Email | infoo@payplatform.org |
Postal Address | 216 JOO CHIAT ROAD, #02-16/6, SOHO LIFE, SINGAPORE (427483) |