Legal & privacy
Privacy Policy
Effective date: 8 August 2026
Scope and responsibility
Sino Ventures Group Pte. Ltd. (SVG, we, us or our) explains in this Privacy Policy how we collect, use, disclose, protect and retain personal data in connection with the SVG website, enquiries, registered member accounts, premium-insight access and related communications. Where we decide the purposes and means of handling personal data, we are the organisation responsible for that data under Singapore's Personal Data Protection Act 2012 (PDPA).
If SVG provides services under a written engagement, the engagement and any agreed data-protection terms govern client materials and personal data processed for that client. A client may control the purposes and instructions for its own data; this Policy continues to apply to the personal data SVG independently controls, including website, enquiry, account, security and business-administration records.
Personal data we collect
When you submit an enquiry, request information or apply for access to premium insights, we may collect your name, organisation, business email address, telephone number, country, selected area of interest, message, preferred contact method and consent choice. We collect the information you include in correspondence, meetings or materials you choose to submit.
When you register for an account, we collect your name and email address and store your password only in cryptographically hashed form. We also keep account, sign-in and session information needed to administer access and protect the account.
Our website and security controls may receive ordinary technical and security information, including IP address, user agent, session or CSRF cookie identifiers, requested paths, timestamps, referring page, error records and events generated when security controls detect suspected automation or misuse. We do not ask you to send sensitive, confidential or third-party personal data unless it is necessary for the specific purpose and you are authorised to provide it.
Why we use personal data
We use personal data to receive, assess and respond to enquiries; understand the business objective you choose to describe; communicate about a requested conversation or potential engagement; create and administer member accounts and premium-insight access; protect the website, accounts, personnel and information; investigate spam, fraud, misuse or security incidents; keep appropriate business and legal records; establish, exercise or defend legal claims; comply with law; and produce aggregated or anonymised operational information.
An enquiry, account registration or consent to this Policy does not by itself subscribe you to marketing communications.
Consent and other permitted processing
Where the PDPA requires consent, we provide notice of the purpose and seek consent, or rely on deemed consent only where the law permits. We may also collect, use or disclose personal data without consent where the PDPA or another applicable law permits or requires this, including for legitimate interests after considering safeguards and likely effects, legal claims, investigations, security, emergencies and compliance.
You may withdraw consent on reasonable notice through the Privacy / Data Protection channel described below. Withdrawal applies prospectively. It does not invalidate processing already carried out lawfully, and it may mean we cannot continue a requested communication, account feature or service where the relevant data is reasonably necessary.
Cookies, accounts and online tools
SVG uses essential cookies and similar technical controls to maintain a session, protect forms against cross-site request forgery, keep an account signed in and maintain website security. Blocking essential cookies may prevent the contact form, registration, login or premium content from working.
This Policy does not state that SVG uses optional analytics, advertising, retargeting or social-media tracking cookies. If SVG introduces an optional tool that changes the personal data collected through this website, we will update this Policy and obtain any notice or consent required by law before using it.
Disclosure and overseas transfers
We disclose personal data only where reasonably necessary to providers performing a defined function for us, such as hosting, database, email, communications, security, support or professional-advisory providers. We may disclose information to a client where it is necessary to administer that client's engagement, and to a buyer or successor in a genuine business transaction, subject to appropriate safeguards. We may also disclose information to police, regulators, cybersecurity authorities, courts, insurers, auditors or professional advisers where permitted or required by law, or reasonably necessary to investigate and respond to a threat or claim.
We do not sell personal data for payment. Some service providers may process personal data outside Singapore. Before an overseas transfer, we use measures appropriate to the circumstances, such as vendor assessment, data minimisation, access controls and contractual obligations requiring a standard of protection comparable to that required by the PDPA, unless another lawful transfer basis applies.
Security, retention and incidents
We use reasonable administrative, technical and physical safeguards appropriate to the nature of the personal data and the context, including access controls, authentication, environment separation, security monitoring, updates and encryption in transit where supported. No internet transmission or storage system is completely secure and we cannot guarantee absolute security.
We retain personal data only while a business or legal purpose continues. Retention depends on the data's nature, the enquiry or account lifecycle, security and backup needs, contractual requirements, limitation periods, an active dispute or investigation and legal obligations. We securely delete, destroy or anonymise data when retention is no longer necessary, subject to lawful holds and proportionate backup cycles.
We assess suspected data incidents, take reasonable steps to contain and remediate them, and determine whether notification is required. Where a breach is notifiable under applicable law, we will notify the relevant authority and affected individuals as required.
Access, correction and privacy requests
You may request access to personal data SVG controls about you, information about how it was used or disclosed where the PDPA requires this, correction of an error or omission, or withdrawal of consent. Deletion and restriction requests are assessed case by case; they are not absolute rights where SVG has a lawful reason to retain or continue using the data. We may verify your identity, authority and the request's scope. Statutory exceptions and a reasonable access fee may apply.
Use the site's contact channel and mark the request Privacy / Data Protection. We will respond as soon as reasonably practicable and, if we cannot respond within the period required by law, provide the update required by law.
Marketing and changes
We send marketing only where you have chosen it or another lawful basis applies. Each applicable marketing message provides a practical way to opt out. We will honour withdrawal and unsubscribe requests within a reasonable period and comply with applicable Do Not Call requirements for marketing sent to Singapore telephone numbers.
We may update this Policy prospectively when our practices, services, providers or legal obligations change. The effective date identifies the current version. We will provide proportionate notice of a material change and seek a fresh acknowledgement where required; an update does not retrospectively make an earlier use lawful.