Privacy Policy

Singapore

Australia

Privacy Policy

Last Updated : May 2024

1. Introduction

This Privacy Policy constitutes an agreement between you, the reader, and 3 Degrees App Pte Ltd ("3 Degrees," "we," "us," or "our"), a company registered in Singapore with its principal office located at 1 Kim Seng Promenade #13-04, Great World City, Singapore 237994. By using our platform, you agree to the terms and conditions outlined in this Privacy Policy.

3 Degrees is committed to protecting your personal data and respecting your privacy. This Privacy Policy outlines how we collect, use, disclose, and safeguard your personal data in compliance with the Personal Data Protection Act (PDPA) of Singapore. It explains our practices regarding the collection, use, disclosure, and protection of your personal data.

If you have any questions or concerns about this Privacy Policy or our data protection practices, please contact our Data Protection Officer (DPO) using the contact information provided in the Contact Information section below.

By accessing and using our platform, you consent to the data practices described in this Privacy Policy. If you do not agree with any part of this Privacy Policy, please do not use our platform.

2. Scope of this Privacy Policy

This Privacy Policy applies to all personal data collected by 3 Degrees through our website, mobile applications, and any other services we provide. It covers information collected about our users, donors, charities, and other stakeholders. This policy explains our practices regarding the collection, use, disclosure, and protection of your personal data.

3. Collection of Personal Data

We collect personal data from you when you interact with our platform, including but not limited to the following situations:

• Account Registration

When you create an account, we collect your name, email address, contact number, and other relevant information.

• Campaign Creation and Donations

When you create a campaign or make a donation, we collect information related to the campaign and transaction, including payment details.

• Communication

When you contact us for support or with inquiries, we collect information such as your name, email address, and the content of your communications.

• Usage Data

We automatically collect information about your interactions with our platform, including IP addresses, browser types, operating systems, pages viewed, and the dates/times of your visits.

• Cookies and Tracking Technologies

We use cookies and similar technologies to collect data on your usage patterns and preferences.

• Social Interactions

We collect data related to your social interactions on the platform, such as friend connections, in-app messages, and notifications.

We may also collect personal data from third parties or publicly available sources, where permissible under applicable laws.

4. Use of Personal Data

We use the personal data we collect for the following purposes:

• Providing and Improving Services

To facilitate the creation and management of campaigns, process donations, and enhance the functionality of our platform.

• Communications

To communicate with you regarding your account, respond to your inquiries, provide customer support, and send you updates about our services.

• Personalization

To personalize your experience on our platform by remembering your preferences and customizing the content we provide.

• Security and Compliance

To protect our platform, users, and stakeholders from fraud, abuse, and other illegal activities. This includes complying with legal obligations and regulatory requirements.

• Analytics

To analyze usage patterns and trends to improve our platform's performance, user experience, and the services we offer.

• Marketing

To send you marketing communications about our services, offers, and events that may be of interest to you, provided you have given your consent to receive such communications.

• Social Engagement

To trigger engagement through in-app and push notifications, as well as maintaining a live activity stream. This includes notifying friends about your donation activities (unless you choose to donate anonymously) and allowing you to see your friends' donation activities.

We ensure that the use of your personal data is necessary, proportionate, and in accordance with the purposes stated above. We do not use your personal data for purposes incompatible with those described in this Privacy Policy without your consent.

5. Disclosure of Personal Data

We may disclose your personal data to third parties in the following circumstances:

• Service Providers

We share personal data with trusted third-party service providers who assist us in operating our platform, conducting our business, or providing services to you, such as payment processors, hosting providers, and customer support services. These service providers are bound by confidentiality obligations and are only permitted to use your data for the purposes specified by us.

• Legal Requirements

We may disclose your personal data to comply with legal obligations, such as responding to subpoenas, court orders, or other legal processes, or to establish or exercise our legal rights or defend against legal claims.

• Business Transfers

In the event of a merger, acquisition, reorganization, or sale of assets, your personal data may be transferred as part of the transaction. We will notify you of any such change in ownership or control of your personal data.

• Protection of Rights

We may disclose your personal data when we believe it is necessary to investigate, prevent, or take action regarding illegal activities, suspected fraud, situations involving potential threats to the safety of any person, violations of our terms of service, or as evidence in litigation in which we are involved.

• With Your Consent

We may share your personal data with third parties when you have provided your explicit consent for us to do so.

• Social Features

We may share your donation activities with your friends on the platform through notifications and live activity streams, unless you choose to donate anonymously.

We do not sell, trade, or otherwise transfer your personal data to outside parties without your consent, except as described in this Privacy Policy.

6. Consent

We obtain your consent before collecting, using, or disclosing your personal data, except where collection, use, or disclosure without consent is permitted or required by the PDPA or other laws. By providing your personal data to us, you consent to the collection, use, and disclosure of your personal data in accordance with this Privacy Policy.

Obtaining Consent:

• Explicit Consent

We obtain explicit consent from you when you register on our platform, create or donate to a campaign, or otherwise provide us with your personal data.

• Implied Consent

In certain situations, your consent may be implied through your actions, such as when you voluntarily provide personal data during communications with us, use social features, or when you use our platform.

Withdrawing Consent

You may withdraw your consent for the collection, use, or disclosure of your personal data at any time by contacting our Data Protection Officer (DPO). Upon receiving your request, we will inform you of the likely consequences of withdrawing consent and will cease to collect, use, or disclose your personal data unless permitted or required by law.

Updating Consent

If there are any changes to the purposes for which your personal data was collected, we will seek your consent for the new purposes before using your personal data in a manner consistent with the updated purposes.

7. Data Breach Notification

3 Degrees is committed to protecting your personal data and ensuring its security. In the event of a data breach that is likely to result in significant harm or impact to you, we will take the following steps:

1. Assessment and Containment

Immediately upon discovering a potential data breach, we will assess the situation, contain the breach to prevent further unauthorized access, and mitigate any potential harm.

2. Notification to PDPC

We will notify the Personal Data Protection Commission (PDPC) of the breach as soon as practicable, and in any case, no later than 72 hours after determining that a breach has occurred.

3. Notification to Affected Individuals

If the breach is likely to result in significant harm or impact, we will notify the affected individuals as soon as practicable. The notification will include:

• A description of the data breach.

• The type of personal data involved.

• Steps taken to contain the breach and mitigate its impact.

• Measures you can take to protect yourself from potential harm.

• Contact information for further assistance.

4. Investigation and Remediation

We will conduct a thorough investigation to determine the cause of the breach and implement measures to prevent future occurrences. This may include enhancing security protocols, conducting staff training, and reviewing our data protection policies.

By adhering to these procedures, we ensure a prompt and effective response to any data breaches, minimizing the risk of harm to individuals and maintaining compliance with PDPA requirements.

8. Data Portability

Under the PDPA, you have the right to request the transfer of your personal data to another organization. This process is known as data portability. To facilitate this, 3 Degrees has established the following procedures:

1. Request Submission

To initiate a data portability request, please contact our Data Protection Officer (DPO) at the provided contact information. Your request should include sufficient details to identify the personal data you wish to be transferred and the organization to which the data should be sent.

2. Verification of Identity

We will verify your identity to ensure that the request is legitimate. This may involve requesting additional information or documentation from you.

3. Processing the Request

Once your identity is verified, we will process your request and prepare your personal data for transfer. We will ensure that the data is in a structured, commonly used, and machine-readable format.

4. Transfer of Data

We will transfer your personal data to the specified organization in a secure manner, using appropriate safeguards to protect the data during transit.

5. Notification

You will be notified once the transfer is complete. If there are any issues or delays in processing your request, we will inform you promptly.

WPlease note that data portability requests may be subject to certain exceptions under the PDPA, such as when the transfer of data would adversely affect the rights and freedoms of others or when it is not technically feasible.

9. Access to and Correction of Personal Data

You have the right to request access to and correction of the personal data that we hold about you. To exercise these rights, please follow the procedures outlined below:

Requesting Access to Personal Data:

1. Submission of Request

To request access to your personal data, contact our Data Protection Officer (DPO) at the provided contact information. Your request should include sufficient details to identify the personal data you are requesting access to.

2. Verification of Identity

We will verify your identity to ensure that the request is legitimate. This may involve requesting additional information or documentation from you.

3. Processing the Request

Once your identity is verified, we will process your request and provide you with a copy of your personal data. We will make reasonable efforts to respond to your request within 30 days. If additional time is needed, we will inform you of the reasons for the delay.

4. Fees

We may charge a reasonable fee for the processing of access requests to cover administrative costs. We will inform you of any fees before processing your request.

Requesting Correction of Personal Data:

1. Submission of Request

To request correction of your personal data, contact our DPO at the provided contact information. Your request should specify the data to be corrected and provide evidence to support the correction.

2. Verification of Identity

We will verify your identity to ensure that the request is legitimate. This may involve requesting additional information or documentation from you.

3. Processing the Request

Once your identity is verified and the evidence for correction is reviewed, we will correct your personal data as requested. We will make reasonable efforts to respond to your request within 30 days. If additional time is needed, we will inform you of the reasons for the delay.

4. Notification of Changes

If we have shared your personal data with third parties, we will notify them of the correction, unless it is impractical or unlawful to do so.

Exceptions: In certain situations, we may not be able to provide access to or correct your personal data as requested. For example, we may deny access if providing the data would reveal confidential commercial information or if it would infringe on the privacy of another individual. If we deny your request, we will provide you with the reasons for the denial.

10. Accountability and Governance

3 Degrees is committed to ensuring the accountability and governance of personal data protection within our organization. To achieve this, we have implemented the following measures:

Appointment of Data Protection Officer (DPO):

We have appointed a Data Protection Officer who is responsible for overseeing our data protection strategy and ensuring compliance with the PDPA. The DPOʼs responsibilities include:

• Developing and implementing data protection policies and practices.

• Conducting regular audits and assessments to ensure compliance.

• Providing training and guidance to employees on data protection matters.

• Serving as the point of contact for data protection inquiries and requests.

Data Protection Policies and Practices:

We have established comprehensive data protection policies and practices to ensure the secure and lawful handling of personal data. These policies cover:

• Data collection, use, and disclosure procedures.

• Data storage and security measures.

• Procedures for handling data breaches.

• Guidelines for data retention and disposal.

Regular Audits and Assessments:

We conduct regular audits and assessments to evaluate our compliance with data protection laws and our internal policies. These audits help identify and mitigate potential risks to personal data.

Employee Training and Awareness:

We provide regular training and awareness programs for our employees to ensure they understand their responsibilities regarding data protection. This includes training on the PDPA, our internal policies, and best practices for data security.

Monitoring and Review:

We continuously monitor our data protection practices and review our policies to ensure they remain effective and up-to-date with changes in laws and technology. This proactive approach helps us maintain a high standard of data protection.

By implementing these measures, 3 Degrees demonstrates its commitment to accountability and governance in personal data protection, ensuring that your data is handled with the utmost care and compliance with the PDPA.

11. Protection of Personal Data

At 3 Degrees, we take the security of your personal data seriously and implement robust measures to protect it from unauthorized access, use, disclosure, alteration, or destruction. Our data protection measures include:

Technical Safeguards:

• Encryption

We use industry-standard encryption technologies to protect your personal data during transmission and storage.

• Access Controls

We implement strict access controls to ensure that only authorized personnel can access your personal data. This includes the use of unique user IDs and passwords, multi-factor authentication, and role-based access permissions.

• Firewalls and Intrusion Detection Systems

Our systems are protected by firewalls and intrusion detection systems to prevent unauthorized access and monitor for suspicious activity.

Organizational Safeguards:

• Data Protection Policies

We have established comprehensive data protection policies that outline our procedures for handling personal data securely.

• Employee Training

We provide regular training to our employees on data protection best practices, ensuring they understand their responsibilities in safeguarding personal data.

• Incident Response Plan

We have an incident response plan in place to address potential data breaches promptly and effectively. This includes procedures for containment, investigation, notification, and remediation.

Physical Safeguards:

• Secure Facilities

Our data centers and offices are equipped with physical security measures, such as access controls, surveillance cameras, and alarm systems, to protect against unauthorized access.

• Secure Disposal

We ensure that personal data is securely disposed of when it is no longer needed, using methods such as shredding, degaussing, or secure electronic deletion.

Social Features Protection:

• Anonymity Options

Users can choose to donate anonymously, in which case their donation activity will not be published or sent to friends.

• Privacy Controls

Users can manage their privacy settings to control what information is shared with friends and on the activity stream.

By implementing these technical, organizational, and physical safeguards, we strive to ensure the highest level of security for your personal data. However, please be aware that no method of transmission over the internet or electronic storage is completely secure, and we cannot guarantee absolute security.

12. Retention of Personal Data

3 Degrees retains your personal data only for as long as it is necessary to fulfill the purposes for which it was collected, or as required or permitted by applicable laws. Our data retention practices include:

Purpose-Based Retention:

• Service Provision

Personal data related to your account and transactions will be retained for as long as you maintain an active account with us and for a reasonable period thereafter to comply with legal obligations, resolve disputes, and enforce our agreements.

• Marketing and Communication

If you have consented to receive marketing communications from us, we will retain your contact information until you opt- out or withdraw your consent.

Legal and Regulatory Requirements:

We retain personal data as required by applicable laws and regulations, such as tax laws, financial reporting requirements, and other regulatory obligations.

Data Minimization and Disposal:

We regularly review the personal data we hold and ensure that it is relevant and necessary for our ongoing operations.

When personal data is no longer needed, we securely dispose of it using appropriate methods such as shredding, degaussing, or secure electronic deletion to prevent unauthorized access or use.

Record Keeping:

We maintain records of our data retention and disposal practices to demonstrate compliance with legal and regulatory requirements and our internal policies.

By adhering to these retention practices, 3 Degrees ensures that your personal data is kept only for as long as necessary and is securely disposed of when no longer needed.

13. Withdrawal of Consent

You have the right to withdraw your consent for the collection, use, or disclosure of your personal data at any time. The process for withdrawing consent is as follows:

Submitting a Request:

• Contact

WTo withdraw your consent, please contact our Data Protection Officer (DPO) at the provided contact information. Your request should include sufficient details to identify your personal data and the specific consent you wish to withdraw.

• Verification

We will verify your identity to ensure that the request is legitimate. This may involve requesting additional information or documentation from you.

Processing the Request:

• Immediate Action

Upon receiving your request, we will cease the collection, use, or disclosure of your personal data for the specified purposes, unless the withdrawal of consent affects our ability to fulfill our obligations to you.

• Notification

We will inform you of the likely consequences of withdrawing your consent, including how it may affect your ability to use certain features of our platform or receive certain services.

• Record Updates

We will update our records to reflect your withdrawal of consent and ensure that your personal data is no longer used for the specified purposes.

Exceptions:

• Legal and Contractual Obligations

Even after you withdraw your consent, we may retain your personal data if required or permitted by law. This includes retaining data necessary for legal or contractual obligations, such as financial records or data required for dispute resolution.

• Processing Time

Please allow a reasonable period for us to process your withdrawal request and update our records. We will strive to complete this process as quickly as possible.

• Processing Time

Please allow a reasonable period for us to process your withdrawal request and update our records. We will strive to complete this process as quickly as possible.

Continued Use of Services:

• Impact on Services

Withdrawing consent may affect your ability to use certain features of our platform or receive certain services. We will inform you of any such impact and suggest alternative arrangements where possible.

WBy providing a clear process for withdrawing consent, 3 Degrees ensures that you have control over your personal data and can exercise your rights in accordance with the PDPA.

14. External Websites

Our platform may contain links to external websites that are not operated by 3 Degrees. This Privacy Policy applies solely to personal data collected by our platform, and we are not responsible for the privacy practices or content of these external websites.

External Website Policies:

• Separate Privacy Policies

External websites may have their own privacy policies and practices, which may differ from those of 3 Degrees. We encourage you to review the privacy policies of any external websites you visit to understand their data protection practices.

• No Endorsement

The inclusion of links to external websites on our platform does not imply endorsement of their content, products, or services by 3 Degrees.

Data Collection by External Websites:

• Independent Data Collection

When you visit external websites through links provided on our platform, those websites may collect personal data from you independently of 3 Degrees. We do not control or monitor how your personal data is collected, used, or disclosed by these external websites.

• Third-Party Responsibilities

Any personal data you provide to external websites is governed by their respective privacy policies. 3 Degrees is not responsible for any loss or damage arising from your interaction with these external websites.

Security and Privacy Concerns:

• Potential Risks

Be aware that external websites may have different security measures in place, and accessing these websites may involve certain risks. Always exercise caution and use your discretion when sharing personal data with external websites.

• Reporting Issues

If you encounter any issues or have concerns about the privacy practices of external websites linked from our platform, please let us know. We will consider your feedback in our ongoing efforts to provide a safe and secure user experience.

By informing you of our limited responsibility regarding external websites, we aim to help you make informed decisions about your online privacy and data security.

15. Children's Privacy

3 Degrees is committed to protecting the privacy of children. Our platform is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children without verifiable parental consent.

Collection of Data from Children:

• Parental Consent

If we become aware that we have inadvertently collected personal data from a child under the age of 18 without verifiable parental consent, we will take steps to delete such information from our records.

• Parental Rights

Parents or guardians who believe that their child has provided us with personal data without their consent can contact our Data Protection Officer (DPO) to request the deletion of the childʼs information.

Usage of Data:

• Limited Use

In cases where parental consent is obtained, we will use the child's data solely for the purposes for which it was collected and as agreed upon by the parent or guardian.

• Protection Measures

We implement appropriate security measures to protect children's personal data in accordance with this privacy policy and applicable laws.

Educational Resources:

• Information for Parents

We provide information and resources to help parents understand our data practices and how to protect their childrenʼs privacy online.

By including these provisions, 3 Degrees ensures compliance with privacy regulations regarding the protection of childrenʼs personal data and reinforces our commitment to safeguarding the privacy of all users.

16. International Transfer of Personal Data

As part of our operations, 3 Degrees may transfer your personal data to countries outside of Singapore. When we do so, we ensure that your personal data remains protected in accordance with this Privacy Policy and applicable data protection laws.

Transfers to Third Parties:

• Adequate Protection

We only transfer your personal data to third parties in countries that have been recognized to provide an adequate level of data protection, or where we have implemented appropriate safeguards to protect your data.

• Standard Contractual Clauses

In the absence of an adequacy decision, we may use standard contractual clauses approved by relevant authorities to ensure that your personal data receives an adequate level of protection.

Data Storage and Processing:

• Cloud Services

Your personal data may be stored and processed on servers located in different countries, including those outside of Singapore. We select reputable cloud service providers who comply with stringent data protection standards.

• Data Centers

Our data centers are equipped with advanced security measures to protect your personal data from unauthorized access, use, or disclosure.

Your Rights and Protections:

• Continuous Protection

Regardless of where your personal data is transferred, we ensure that it remains subject to the same high level of protection as required by Singapore's PDPA.

• Informed Consent

By using our platform and providing your personal data, you consent to the international transfer, storage, and processing of your data as described in this Privacy Policy.

Monitoring and Compliance:

• Regular Audits

We conduct regular audits of our international data transfer practices to ensure compliance with applicable laws and our internal policies.

• Compliance with Regulations

We continuously monitor changes in data protection regulations to ensure that our practices remain compliant with legal requirements.

By implementing these measures, 3 Degrees ensures that your personal data is protected during international transfers, maintaining the highest standards of data security and privacy.

17. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or our data protection practices, please contact our Data Protection Officer (DPO) using the details provided below. We are committed to addressing your inquiries promptly and transparently.

Data Protection Officer (DPO):

Name:

Kelvin Tjia

Email:

[email protected]

Phone:

+65 6908 0630

Address:

1 Kim Seng Promenade #13-04, Great World City, Singapore 237994

Communication Channels:

• Email

For any inquiries or requests, you can reach out to our DPO via email. We strive to respond to all emails within 7 business days.

• Phone

For urgent matters, you can contact our DPO by phone during our business hours.

• Mail

You can also send written correspondence to our office address. Please ensure that you provide sufficient details to facilitate a prompt response.

Feedback and Complaints:

• Submitting Feedback

We value your feedback on our privacy practices and welcome any suggestions for improvement. Please send your feedback to our DPO using the contact information above.

• Filing Complaints

If you believe that your privacy rights have been violated or if you have any complaints regarding our handling of your personal data, please contact our DPO. We will investigate and address your complaint in accordance with our internal procedures and legal requirements.

Regular Updates:

• Policy Changes

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or other factors. We will notify you of any significant changes through our platform or by email.

• Stay Informed

We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your personal data.

By providing clear contact information and communication channels, 3 Degrees ensures that you can easily reach us with any questions or concerns about your privacy.

18. Changes to this Privacy Policy

3 Degrees reserves the right to update or modify this Privacy Policy at any time to reflect changes in our practices, legal requirements, or other factors. When we make significant changes, we will notify you through appropriate channels, such as our platform or by email.

Notification of Changes:

• Significant Changes

If we make significant changes to this Privacy Policy, we will provide a clear and conspicuous notice on our platform or notify you by email. The notice will include a summary of the changes and their effective date.

• Minor Changes

For minor changes that do not materially affect your rights, we may not provide individual notifications but will update the Privacy Policy on our platform.

Effective Date:

• Implementation

The updated Privacy Policy will become effective on the date specified in the notice. By continuing to use our platform after the effective date, you consent to the updated Privacy Policy.

Review and Acceptance:

Any personal data you provide to external websites is governed by their respective privacy policies. 3 Degrees is not responsible for any loss or damage arising from your interaction with these external websites.

• Periodic Review

We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your personal data. Your continued use of our platform constitutes your acceptance of any changes to this Privacy Policy.

• Questions and Concerns

If you have any questions or concerns about changes to this Privacy Policy, please contact our Data Protection Officer (DPO) using the contact information provided in the Contact Information section.

By keeping you informed of any changes to this Privacy Policy, 3 Degrees ensures transparency and maintains your trust in our data protection practices.

About 3 Degrees

FAQ

Privacy Policy

Terms of Service

© 2023 3 Degrees