Privacy Policy
Last updated: [DATE]
1. Who We Are
[COMPANY NAME] (UEN: [UEN NUMBER]), operating as Trinity Quantitative Strategies, is the data controller responsible for your personal data. Registered address: [REGISTERED ADDRESS].
2. Data We Collect
Account data: Name, email address, phone number, date of birth, nationality, and Singapore NRIC/FIN (for KYC compliance).
Financial data: Deposit/withdrawal history, portfolio value, tier level, and transaction records.
Usage data: Pages visited, features used, login timestamps, IP address, browser type, and device information.
Communications: Support messages, emails, and feedback you send us.
3. How We Use Your Data
- To provide and manage your portfolio and algorithmic trading services.
- To process deposits, withdrawals, and fee calculations.
- To comply with KYC/AML regulations and MAS requirements.
- To send account notifications, statements, and performance reports.
- To improve the Platform through anonymised usage analytics.
- To detect and prevent fraud or unauthorised access.
4. Legal Basis
We process your data under the Singapore Personal Data Protection Act (PDPA) on the following grounds: contractual necessity (to provide our services), legal obligation (regulatory compliance), and legitimate interest (platform improvement and fraud prevention).
5. Data Sharing
We do not sell your personal data. We may share data with:
- Service providers: Cloud hosting (Google Cloud Platform), error monitoring (Sentry), and analytics — all bound by data processing agreements.
- Regulators: MAS or other authorities when required by law.
- Professional advisors: Legal, audit, or compliance advisors as needed.
6. Data Retention
We retain your personal data for as long as your account is active and for [X YEARS] after account closure, as required by financial record-keeping regulations. Anonymised analytics data may be retained indefinitely.
7. Data Security
We implement industry-standard security measures including: encrypted data transmission (TLS 1.3), hashed passwords (bcrypt), CORS restrictions, security headers, and regular dependency audits.
8. Your Rights
Under the PDPA, you have the right to:
- Access your personal data held by us.
- Correct inaccurate or incomplete data.
- Withdraw consent for non-essential processing.
- Request deletion of your data (subject to regulatory retention requirements).
To exercise these rights, email [EMAIL]. We will respond within 30 days.
9. Cookies
The Platform uses essential cookies for authentication and session management. We do not use advertising or third-party tracking cookies.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified via email or an in-app banner at least 14 days before taking effect.
11. Contact
Data Protection Officer: [DPO NAME]
Email: [EMAIL]
Address: [REGISTERED ADDRESS]
Placeholders marked with [BRACKETS] must be filled in before publishing. This document is a draft and does not constitute legal advice.