VALUEMAX GROUP LTD DATA PROTECTION POLICY

ValueMax Group Ltd, including its subsidiaries (“ValueMax,” “we,” “us”), values your privacy and protects your personal data. This applies whether you are pledging an item with us, taking up a loan, financing a vehicle, buying or selling gold, jewellery or precious metals, using our website or mobile application (“App”), or otherwise interacting with any ValueMax outlet or service.

This Policy explains how we collect, use, disclose, protect and retain your personal data, and the choices and rights you have over it. We comply with the Personal Data Protection Act 2012 (“PDPA”).

Personal Data

“Personal data” means any data that can identify you, whether on its own or combined with other information we hold or can access.

“Personal data” may include your name, NRIC, passport or other identification numbers, telephone number, mailing address, email address, and any other information that identifies you.

We only collect, use, retain, or disclose your NRIC or other national identification number where required by law, or reasonably necessary to accurately verify your identity to a high degree of confidence (e.g., as required under moneylending or pawnbroking regulations).

Consent

We will only collect, use or disclose your personal data with your consent, except where the law allows us to do so without it — for example, if you don’t object after being notified, if it’s necessary for a contract, or to prevent fraud or improve our services.

We will notify you of the purpose(s) for which we collect your personal data on or before collection, through the relevant forms, our App, our website, or verbally, as the circumstances require.

Purpose of Use

We collect and use your personal data to provide you with our pawnbroking, moneylending, retail, vehicle financing, bullion and precious metals services, and for the following purposes:

  • Verifying your identity, and processing, managing and reviewing your transactions with us;
  • Carrying out credit checks, assessments and due diligence;
  • Responding to your queries, feedback, complaints and requests, and contacting your agents, next-of-kin or representatives where needed;
  • Direct marketing, where you have consented and after checking your number against the Do Not Call Registry, with a clear opt-out in every communication;
  • Preventing, detecting and investigating crime, fraud or misconduct, and managing the safety and security of our premises;
  • Monitoring or recording calls, and using CCTV and audio recording at our premises, for security, quality assurance, training and identity verification;
  • Research, analytics and profiling to improve our products and services for your benefit;
  • Managing our business operations, commercial risk, and our contractual and legal rights and obligations; and
  • Complying with applicable laws, regulations and directions from any governmental or regulatory authority.

If you are a job applicant, employee, or a vendor/service provider, we use your personal data for the corresponding purposes reasonably necessary to that relationship — for example, processing your application or background checks, administering your employment, or assessing and managing a vendor contract.

We take reasonable steps to keep your personal data accurate and up to date.

Disclosure of Your Personal Data

We may disclose your personal data to:

  • Banks, financial institutions, the Moneylenders Association of Singapore, credit bureaus, and your guarantor for processing your loan application;
  • Our lawyers, the court, collection agencies, or your employer, where necessary to recover a debt from you;
  • The Official Assignee, Official Receiver, a trustee in bankruptcy, or a liquidator, in connection with any bankruptcy or winding-up proceeding;
  • Our data intermediaries and service providers (for example, research, marketing or technical support providers), who are contractually required to protect your data to a standard consistent with the PDPA; and
  • Public agencies, ministries, statutory boards, or other authorities, where required by law or in response to their request or direction.

We remain responsible for your personal data even where it is disclosed to a data intermediary acting on our behalf.

Retention of Your Personal Data

We retain your personal data for as long as necessary for business or legal purposes, whichever is longer, including any minimum retention periods required under applicable law. When your personal data is no longer required, we will destroy it or anonymise it so that it no longer identifies you.

Where we transfer your personal data outside Singapore, we ensure it receives a standard of protection comparable to the PDPA.

Protection & Security of Personal Data

We maintain appropriate technical, administrative and physical safeguards to protect personal data in our possession or under our control against unauthorised access, collection, use, disclosure, copying, modification, disposal or similar risks. These safeguards are reviewed periodically and updated as needed. Where we engage data intermediaries, agents or service providers to process personal data on our behalf, we impose contractual obligations on them requiring a standard of protection comparable to this Policy and the PDPA.

If a data breach occurs that is likely to affect you, we will assess it and notify the relevant authorities and affected individuals as required by law.

Use of Artificial Intelligence

We may use artificial intelligence, including generative AI (“GenAI”) tools, to handle your personal data for purposes such as customer service, fraud and credit risk assessment, document processing, and internal business operations, in accordance with the PDPA and the PDPC’s Advisory Guidelines on Use of Personal Data in Generative AI.

If we plan to use your personal data to train an AI model, we’ll notify you and get your consent where the law requires it.

Access, Correction and Amendment of Your Personal Data

If you have a question or feedback about your personal data, or would like to withdraw your consent, access it, or request a correction, please contact our Data Protection Officer. We will verify your identity before acting on any request, and may charge a reasonable fee reflecting the time and cost of responding (with a written estimate given in advance).

We may decline requests that are made in bad faith, trivial, repetitive, would reveal someone else’s identity without consent, or could cause harm.

You may withdraw your consent to our handling of your personal data at any time. This may mean we can no longer provide certain products or services, and we won’t be liable for any resulting loss. We may still use your data where the law requires, or to protect you, respond to an emergency, or support an investigation.

If your personal data was provided to us by a third party, please direct your request to them, and they will contact us on your behalf.

Changes to This Policy

We may update this Policy from time to time. We will post the updated Policy on our website and App. Where a change materially affects how we handle your personal data, we will notify you and, where required by the PDPA, obtain your consent before it takes effect.

Data Protection Officer (“DPO”)

Please contact our Data Protection Officer if you have any feedback or enquiries on this Policy or regarding your personal data.

Contact details of the Group’s Data Protection Officer are:

Data Protection Officer

Telephone: +65 6817 8713

E-mel: DPO@valuemax.com.sg

Governing Law

This Policy is governed by Singapore law.