Our Privacy Commitment
Centora operates the website centerfiin.biz and is committed to handling personal data responsibly and transparently. This policy explains what data we collect, how we use it to deliver business planning services, and the choices available to you. We seek to be clear about our practices so you can make informed decisions when engaging with our services in Singapore.
Definitions
This section explains common terms used in this policy to make the wording clearer. 'Personal data' means information relating to an identifiable person. 'Processing' means any operation performed on personal data. 'Service' refers to business planning and related services provided by Centora via centerfiin.biz.
What Data We Collect
We collect data that is necessary to provide our services, comply with legal obligations, and improve client experience. Collection methods include information you provide directly, data collected automatically through the website, and information obtained from third parties with your consent or as permitted by law.
Data You Provide
When you engage with Centora or use our contact forms, we collect information you voluntarily provide to deliver services effectively.
- Identity and contact details: name, email address, phone number, postal address.
- Business information: bank account details for fee processing, revenue, assets, liabilities, insurance policies, CPF and other records submitted to build a business plan.
- Identification documents: identity card, passport or other verification documents required for client onboarding and compliance checks.
- Communications and preferences: messages, meeting notes, consent choices and service preferences you share with our team.
- Transaction details: records of payments, invoices and receipts related to services provided by Centora.
- Employment and background: employer information, occupation and other context needed to craft appropriate business recommendations.
Data Collected Automatically
When you visit centerfiin.biz, we automatically collect technical and usage data to help operate and improve the website and services.
- Device and browser information: device type, operating system, browser version.
- Usage data: pages visited, time on site, navigation paths and interaction events.
- Log information: IP address, date and time of access, referrer URL.
- Cookies and identifiers: persistent and session cookies used to support functionality and analytics.
- Location data: approximate location derived from IP address when permitted and relevant for compliance or service tailoring.
- Error and performance data: crash reports and site performance metrics to maintain a reliable service.
Data from Third Parties
We may supplement information you provide with data from trusted third parties to verify information, prevent fraud, and improve service delivery where permitted by law.
- Service providers: identity verification, payment processors, and cloud hosting providers.
- Professional advisers and partners: legal, tax and compliance advisers where engagement is necessary to serve you.
- Public and commercial sources: publicly available registries or purchased reference data for validation purposes.
How We Use Your Data
We use personal data only for specific, explicit and legitimate purposes aligned with delivering business planning services and meeting legal responsibilities.
- To onboard clients, verify identity and conduct required due diligence under Singapore regulations.
- To prepare and deliver business plans, cash flow analysis, and ongoing advisory services tailored to your values and goals.
- To process payments, invoices and manage billing for services provided by Centora.
- To communicate with you about your plan, meetings, account updates and important notices.
- To improve our website and services through analytics, testing and feedback collection.
- To protect our systems and clients by detecting and preventing fraud, security breaches and misuse.
- To comply with legal and regulatory obligations, including tax and anti-funds laundering requirements.
- To manage business operations, recordkeeping and dispute resolution when necessary.
Legal Basis for Processing
Depending on the activity, our processing of personal data is based on a valid legal basis, including contractual necessity, consent where obtained, legal obligations, and legitimate interests where appropriate.
- Performance of a contract: processing necessary to deliver business planning services you have requested.
- Consent: where you have given clear permission for a specific purpose, such as marketing communications.
- Legal compliance: processing required to comply with laws and regulations in Singapore.
- Legitimate interests: for activities such as improving services, fraud prevention and business administration when those interests are balanced against your rights.
Your Rights (GDPR Overview)
If GDPR applies to your situation, you may have specific rights regarding your personal data. We provide the following overview and will respond to requests in line with applicable law.
- Right of access: You can request a copy of personal data we hold about you.
- Right to rectification: You can request correction of inaccurate or incomplete data.
- Right to erasure: In certain circumstances, you can request deletion of your personal data.
- Right to restrict processing: You may request limits on how we use your data in certain cases.
- Right to data portability: You may request a machine-readable copy of data you provided to us.
- Right to object: You can object to processing based on legitimate interests or direct marketing where applicable.
How We Share Your Data
We share personal data only as necessary to provide services, meet legal obligations, and operate our business with trusted partners under contractual safeguards.
- Service providers and processors that support our operations, such as cloud hosting, analytics and payment processing.
- Professional advisers and auditors engaged to support compliance, legal matters or dispute resolution.
- Regulatory, governmental and law enforcement authorities when required by law or to respond to legal process.
- Affiliates and business partners when necessary for a specific service or engagement and subject to appropriate safeguards.
- In the event of a business reorganisation, merger, sale or transfer of assets, personal data may be transferred as part of that transaction with appropriate protections.
- Analytics and advertising partners for aggregated, anonymized insights or where you have provided consent for targeted communications.
International Transfers
Some service providers we use may be located outside Singapore. When personal data is transferred internationally, we take steps to ensure appropriate protections are in place and transfers comply with applicable data protection laws.
Safeguards may include standard contractual clauses, data processing agreements, encryption and limiting data access to what is strictly necessary for service delivery.
Data Retention
We retain personal data only as long as necessary for the purposes described, including business, legal and regulatory requirements.
Account and client engagement records are typically retained for the duration of the client relationship and for a period thereafter required by law or professional standards in Singapore.
Communications and correspondence are retained for as long as necessary to address service requests, disputes and compliance obligations.
System logs and analytics data are retained for operational troubleshooting and performance analysis for a limited, defined period.
When data is no longer required, we securely delete or anonymize it unless retention is necessary to meet legal obligations or defend legal claims.
Security Measures
We apply reasonable technical and organisational measures to protect personal data against unauthorized access, disclosure, loss or alteration. Our approach includes risk-based controls and regular reviews to maintain an appropriate level of security.
- Encryption of data in transit and, where appropriate, at rest to protect sensitive information.
- Access controls and role-based permissions to limit data access to authorized personnel only.
- Regular security assessments, monitoring and incident response procedures to identify and address vulnerabilities.
Your Rights and Choices
At Centora we respect your privacy and strive to make it simple for you to understand and exercise your data rights under applicable Singapore law. You have clear choices about how we use your personal information and can request access, correction, portability or deletion of data we hold about you. Exercising your rights helps us keep your planning aligned with your values and personal priorities.
- Right to access: request a copy of the personal data we hold about you and an explanation of how it is used.
- Right to correction: ask us to correct or update inaccurate or incomplete personal information.
- Right to withdraw consent: withdraw any consent you have previously given for specific processing activities.
- Right to data portability: request your personal data in a structured, commonly used and machine-readable format where technically feasible.
- Right to erasure: request deletion of data that we no longer need for the original purpose or where retention is no longer permitted by law.
- Right to restriction: request that we limit how we process your personal information while a dispute or request is being resolved.
- Right to object: object to certain types of processing, including direct marketing processing, where applicable.
- Right to lodge a complaint: contact our Data Protection Officer or the relevant supervisory authority if you believe your data rights have been infringed.
How to exercise your privacy rights
To exercise any of the rights above, contact our Data Protection Officer with a clear description of the request and supporting identification. Include your full name, address, Centora client reference if available, and the specific right you wish to exercise. You may send documented requests by post to our office or initiate the request through the contact channels listed below. We will verify your identity before responding to protect your data and privacy.
We aim to acknowledge all valid requests within 7 business days and to provide a full response within 30 calendar days. If we require additional time due to complexity or legal requirements, we will notify you of the extension and the reasons for it.
Marketing communications and choices
Centora may use your contact details to send relevant updates, service information and occasional invitations to events that align with your business values and planning needs. Communications will be tailored to the preferences you select during onboarding.
You can opt out of promotional communications at any time by following the unsubscribe link in any marketing message or by contacting our team directly. Opting out of marketing will not affect service-related messages about your active plans or appointments.
Children and personal data
Centora does not knowingly collect personal data from children under 16 without verifiable parental or guardian consent. If we learn that we have collected information from a child under 16 without appropriate consent, we will take steps to delete that information promptly.
Third-party links and service providers
Our website and services may contain links to third-party websites and partner services. We are not responsible for the privacy practices of external sites. When we share your data with service providers (for example, custodians, analytics providers or secure document processors) we require them to adhere to data protection standards consistent with our policies.
Changes to this privacy policy
We will review and, if necessary, update our privacy policy to reflect changes in law, technology or business practices. Any material change will be posted on our site at Centora (centerfiin.biz) and the updated effective date will be displayed. We encourage clients to review the policy periodically.