Knowledge Catalyst

    Privacy Policy

    Last updated: November 2024

    1. Introduction

    This Privacy Policy applies to all data processed by Knowledge Catalyst Pte. Ltd. ("Knowledge Catalyst", "we", "us", or "our"), a company registered in Singapore. It offers multi-ecosystem services, including Cross-Border Trade Finance, Sustainability, Health and insurance, and Talent platforms. These platforms serve B2G, B2B, B2B2C, and individual users, with additional provisions for public access. We are committed to complying with the General Data Protection Regulation (GDPR), the Personal Data Protection Act 2012 (PDPA) of Singapore, the US Standard Contractual Clauses (SCC), the Binding Corporate Rules (BCR), and the ISO standards (27001 and 27701). This Privacy Policy outlines the data we collect, how we process it, and your rights.

    2. Scope

    This Privacy Policy covers:

    • B2G (Business-to-Government): Data shared between government entities and government-linked organisations.
    • B2B (Business-to-Business): Data exchanged between businesses for secure transactions, credential management, and compliance.
    • B2B2C (Business-to-Business-to-Consumer): Data shared between businesses and consumers, such as educational institutions and their learners.
    • Individual Users: Data from individuals using the platform, including employees and individual members.
    • Public Access: Data made available for public consumption under applicable law.
    • By using our services, you consent to collecting and using your data under this policy, which is aligned with our Terms of Use, which may be updated periodically.

    3. Data We Collect

    We collect personal data provided voluntarily, automatically collected through cookies, or shared by third parties. Data types include:

    • Personal Identifiers: Name, email, national ID numbers, and similar identifiers.
    • Contact Information: Phone numbers, email addresses, and postal addresses.
    • Financial Data: Payment details and transaction records.
    • Health Data: Medical records and healthcare data (relevant to Health & Insurance Ecosystem).
    • Business Data: Trade documentation, certifications, and compliance records.
    • Technical Data: IP addresses, device details, browser types, time zone settings, and browser plug-in details.
    • Usage Data: Platform interactions, user preferences, and logs of activity.
    • Third-Party Data: Data received from integrated services like social logins or external platforms (Google, Facebook, LinkedIn).

    4. How We Use Your Data

    We process your data for the following purposes:

    • Service Delivery: To provide platform access, process payments, and manage user accounts.
    • Legal Compliance: To meet obligations under GDPR, PDPA, US SCC, and other applicable laws.
    • Platform Security: To monitor and enhance security, prevent fraud, and ensure compliance with policies.
    • Analytics and Business Improvement: For analysis, research, and service improvement.
    • Marketing: With your consent, for sending promotional materials or updates.
    • Public Access Data: Public-facing data can be accessed for analytics or reporting.

    5. Data Sharing and Disclosure

    We may share your data under the following conditions:

    • 5.1 Third-Party Service Providers: We engage trusted third-party service providers to assist with services such as: Payment Processing: for handling payments; Cloud Hosting: for secure data storage and backup; Analytics Providers: to analyse usage data and improve the platform. All third parties adhere to strict contractual obligations and maintain security measures aligned with ISO 27001 and 27701 standards.
    • 5.2 Government Authorities and Compliance: Where required by law, we may disclose personal data to government authorities to comply with regulatory obligations or respond to legal requests. This is relevant, particularly in B2G scenarios where government agencies may require data exchange.
    • 5.3 Business Partners: We share data with business partners for joint service delivery, such as trade finance providers or credential verification partners. All parties involved must comply with applicable data protection laws and maintain security standards.
    • 5.4 International Transfers: When transferring data internationally, we implement Standard Contractual Clauses (SCCs) or rely on Binding Corporate Rules (BCRs) to ensure lawful data transfer in compliance with GDPR and PDPA. We take all necessary measures to ensure that your personal data is secure and processed in accordance with applicable privacy laws.
    • 5.5 Public Data: For data that is publicly accessible on the platform, users are made aware that other users can view such data. We process and disclose public access data under the terms in the Acceptable Use Policy and relevant legal requirements.

    6. International Data Transfers

    In some cases, personal data may be transferred to and processed in countries outside of Singapore or the European Economic Area (EEA). We ensure compliance with international data protection laws by using SCCs, BCRs, or other lawful transfer mechanisms. These transfers are carried out in line with GDPR standards and the PDPA in Singapore.

    7. Legal Basis for Processing Personal Data

    We rely on the following legal bases for processing your personal data, as required by GDPR and PDPA:

    • Account Data — Account creation, user authentication, service access. Legal Basis (GDPR): Contractual necessity (Art. 6(1)(b)). Legal Basis (PDPA): Contractual necessity.
    • Payment Data — Processing payments and transactions. Legal Basis (GDPR): Contractual necessity (Art. 6(1)(b)). Legal Basis (PDPA): Contractual necessity.
    • Health Data — Managing health-related services. Legal Basis (GDPR): Explicit consent (Art. 9(2)(a)). Legal Basis (PDPA): Consent.
    • Technical Data — Platform security and performance monitoring. Legal Basis (GDPR): Legitimate interest (Art. 6(1)(f)). Legal Basis (PDPA): Legitimate interest.
    • Usage Data — Analytics and improvement of user experience. Legal Basis (GDPR): Legitimate interest (Art. 6(1)(f)). Legal Basis (PDPA): Legitimate interest.
    • Marketing Data — Sending promotional materials. Legal Basis (GDPR): Consent (Art. 6(1)(a)). Legal Basis (PDPA): Consent.
    • Third-Party Data — Data from social logins, partners, and integrations. Legal Basis (GDPR): Legitimate interest/Consent (Art. 6(1)(f)). Legal Basis (PDPA): Consent.

    8. Data Retention

    We retain personal data for as long as necessary to fulfill the purposes outlined in this Privacy Policy, including legal, contractual, or business needs. After the retention period expires, we will securely delete or anonymize your data. Data retention schedules comply with ISO 27001 standards and relevant legal requirements.

    9. Data Breach Notification Clause (Aligned with Singapore PDPA)

    This Data Breach Notification clause is aligned with the Singapore Personal Data Protection Act 2012 (PDPA) requirements and its accompanying regulations, including the Personal Data Protection (Notification of Data Breaches) Regulations 2021. It governs how we respond to and manage data breaches involving personal data.

    • Definitions — "Data breach" refers to: the unauthorized access, collection, use, disclosure, copying, modification, or disposal of personal data; or the loss of any storage medium or device on which personal data is stored under circumstances where unauthorized access, collection, use, disclosure, copying, modification, or disposal of personal data is likely to occur. "Affected individual" refers to any individual whose personal data is impacted by a data breach.
    • Notification to the Personal Data Protection Commission (PDPC): Where required under the PDPA, we will notify the PDPC of a data breach as soon as practicable, but by three (3) calendar days from the day we assess the breach as a notifiable data breach. Our notification to the PDPC will include the details required under the Personal Data Protection (Notification of Data Breaches) Regulations 2021.
    • Notification to Affected Individuals: Where required under the PDPA, we will notify affected individuals of a notifiable data breach as soon as practicable, either at the same time as or after notifying the PDPC. The notification to affected individuals will include the following: A description of the data breach and the types of personal data; Steps that affected individuals can take to mitigate potential; Contact information for further. The notification will be delivered via reasonable means, such as email, and the affected individuals are responsible for ensuring their contact details are accurate and updated in our systems.
    • Obligations as a Data Intermediary: If we process personal data on behalf of another organization ("Customer") and believe a data breach has occurred, we will notify the Customer of the breach without undue delay. The Customer, as the data controller, is solely responsible for: Assessing whether the breach is a notifiable data breach under the; Notifying affected individuals, if; Notifying the PDPC, if. We will cooperate with the Customer to ensure reasonable coordination regarding the content of public statements or notifications to affected individuals and supervisory authorities.
    • Limitation of Liability: Our notification obligations do not imply acknowledgment of fault or liability for the data breach except where required by. We are not responsible for breaches caused by: the actions or omissions of the Customer or affected; system components that are managed or controlled by the Customer or affected.
    • Delivery of Notifications: Notifications to affected individuals will be delivered via methods we choose, such as. Notifications to Customers will be sent to designated administrators through reasonable means, such as The Customer is responsible for ensuring accurate contact details and secure communications at all times.

    10. Data Security

    We implement state-of-the-art security measures to protect personal data from unauthorized access, loss, or misuse. Our practices comply with ISO 27001 and 27701 standards, ensuring data protection in cloud and on-premise environments. We safeguard personal information using encryption, firewalls, secure access controls, and regular security audits.

    11. Your Rights

    You have the right to:

    • Access: Request access to the personal data we hold about you.
    • Rectification: Request correction of inaccurate or incomplete data.
    • Erasure: Request deletion of personal data.
    • Restriction: Request limitations on data processing.
    • Portability: Request to receive your data in a portable format.
    • Objection: Object to data processing for marketing purposes or on the grounds of legitimate interests.
    • Withdraw Consent: Where consent is the legal basis for processing, you may withdraw at any time.
    • To exercise your rights, please contact our Data Protection Officer (DPO) at [email protected].

    12. Automated Processing and Artificial Intelligence (AI) Services

    Some optional platform features are assisted by a third-party artificial-intelligence service that acts as our sub-processor. We disclose this here so you understand where the text you enter may be processed:

    • Google Gemini (AI features): Our conversational assistant ("Ask KC"), onboarding recommendations, and internal content-authoring tools are powered by the Google Gemini API. The text you enter into these features — which may include personal data you choose to provide — is transmitted to Google to generate a response. We do not use these interactions to make decisions producing legal or similarly significant effects about you without human involvement.
    • Safeguards and your choices: Google processes this data on our behalf under contractual and security obligations aligned with ISO 27001 and 27701, and we do not sell your personal data. Please avoid entering sensitive personal data into AI chat features unless necessary. Use of these AI features is optional. To ask about automated processing or to exercise your rights, contact our Data Protection Officer at [email protected].

    13. Public Access and Data Usage

    For publicly accessible data, users acknowledge that such data can be viewed and processed by other users in accordance with our Acceptable Use Policy. We take reasonable measures to protect public data but cannot be held responsible for misuse by third parties beyond our control.

    14. Changes to This Privacy Policy

    We may modify this Privacy Policy from time to time to reflect changes in our data processing practices or legal obligations. Significant updates will be communicated through our platform or via email. Your continued use of the platform following any changes indicates your acceptance of the revised policy.

    15. Governing Law and Dispute Resolution

    15.1. This Privacy Policy is governed by and construed in accordance with the laws of the Republic of Singapore. Any disputes or claims arising out of or in connection with this policy will be subject to the exclusive jurisdiction of the courts of Singapore. Knowledge Catalyst reserves the right to enforce its rights under this policy in other jurisdictions where necessary. 15.2. Dispute Resolution Process - Before initiating legal action, the parties agree to attempt to resolve any disputes through good-faith negotiations.

    16. Contact Information

    For inquiries related to this Privacy Policy or to exercise your data rights, please contact: Knowledge Catalyst Pte. Ltd. Attn: Data Protection Officer 71 Ayer Rajah Crescent, #04-11, Singapore 139951 Email: [email protected] For general inquiries, please contact us at [email protected]