Overview
The General Data Protection Regulation (GDPR) is a European Union regulation that governs the processing of personal data of individuals within the European Economic Area (EEA). Although CapitalNest operates primarily in Singapore, we are committed to protecting the privacy rights of all our users, including those in the EEA.
This page outlines how we comply with GDPR requirements when processing personal data of EEA residents.
Data Controller
For the purposes of GDPR, the data controller is:
CapitalNest Pte Ltd
138 Robinson Road, #15-02 Oxley Tower
Singapore 068906
Email: [email protected]
Legal Basis for Processing
We process personal data of EEA residents under one or more of the following legal bases:
- Consent: You have given explicit consent for processing for specific purposes (e.g., marketing communications)
- Contract: Processing is necessary for the performance of a contract with you or to take steps at your request before entering into a contract
- Legal Obligation: Processing is necessary for compliance with a legal obligation
- Legitimate Interests: Processing is necessary for our legitimate interests, provided these are not overridden by your rights and interests
Your Rights Under GDPR
If you are an EEA resident, you have the following rights regarding your personal data:
Right to Access
You have the right to request a copy of the personal data we hold about you and information about how we process it.
Right to Rectification
You have the right to request correction of inaccurate or incomplete personal data we hold about you.
Right to Erasure
You have the right to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected.
Right to Restriction of Processing
You have the right to request that we restrict processing of your personal data in certain circumstances, such as while we verify the accuracy of data you have contested.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit it to another controller.
Right to Object
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.
Rights Related to Automated Decision-Making
You have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects.
Exercising Your Rights
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within one month. In complex cases, we may extend this period by two additional months, in which case we will inform you within the initial one-month period.
We may request verification of your identity before processing your request to ensure the security of your personal data.
International Data Transfers
As we are based in Singapore, your personal data may be transferred to and processed in Singapore. Singapore is not currently recognized by the European Commission as providing an adequate level of data protection.
For transfers of personal data from the EEA, we implement appropriate safeguards, including:
- Standard Contractual Clauses approved by the European Commission
- Binding Corporate Rules where applicable
- Other lawful transfer mechanisms as required by GDPR
Data Protection Officer
While not legally required for our organization, we have designated a Data Protection Officer who can be contacted at [email protected] for any questions or concerns about our data processing practices.
Complaints
If you believe that we have not complied with your data protection rights, you have the right to lodge a complaint with a supervisory authority. For EEA residents, this is typically the data protection authority in your country of residence.
We encourage you to contact us first so that we can address your concerns directly.
Updates to This Notice
We may update this GDPR compliance notice from time to time. We will post the updated notice on this page with a revised effective date.