Privacy Policy
Last updated: 9 July 2026
General
This Privacy Policy explains how GMA Capital Partners Pte Ltd ("GMA", "the Company", "we" or "us") may collect, use, disclose and protect personal data in connection with this website and related communications, in accordance with the Personal Data Protection Act 2012 of Singapore (the "PDPA"), which is administered by the Personal Data Protection Commission ("PDPC"). "Personal data" has the meaning given to it in the PDPA.
Personal Data We May Collect
We may collect personal data that you provide to us, including your name, organisation, title, e-mail address, telephone number and the contents of any enquiry or communication sent to us.
We may also collect limited technical information when you use this website, including server logs, IP address, browser type, device information, pages viewed, date and time of access, and analytics data where analytics tools are used.
Consent and Purposes
We collect, use and disclose personal data only with consent (including deemed consent under the PDPA) or as otherwise permitted or required by law, and only for purposes that a reasonable person would consider appropriate in the circumstances, in accordance with Parts 3 and 4 of the PDPA. Where required, we notify individuals of the purposes for which their personal data is collected, used or disclosed at or before the time of collection.
Use of Personal Data
We may use personal data to respond to enquiries, maintain business contact records, operate and secure this website, keep internal records, comply with legal or regulatory obligations, and protect our rights and legitimate interests.
Disclosure of Personal Data
We may disclose personal data where reasonably necessary to service providers, website hosts, IT support providers, analytics providers, professional advisers, banks, counterparties, regulators, public authorities or other persons where required or permitted by law.
Transfers Outside Singapore
Where personal data is transferred outside Singapore, we take steps to ensure that the recipient is bound by legally enforceable obligations to provide the transferred personal data a standard of protection comparable to that under the PDPA, as required by section 26 of the PDPA.
Accuracy
In accordance with section 23 of the PDPA, we make reasonable efforts to ensure that personal data collected by us or on our behalf is accurate and complete where it is likely to be used to make a decision affecting the individual or disclosed to another organisation.
Retention
Consistent with section 25 of the PDPA, we cease to retain personal data, or anonymise it, as soon as it is reasonable to assume that retention no longer serves the purposes for which it was collected and is no longer necessary for legal, regulatory, accounting or business record purposes.
Protection of Personal Data
In accordance with section 24 of the PDPA, we make reasonable security arrangements — administrative, technical and organisational — to protect personal data against unauthorised access, collection, use, disclosure, copying, modification, disposal or similar risks. No method of transmission or storage is completely secure.
Data Breach Notification
We assess data breaches affecting personal data in our possession or under our control. Where a data breach is notifiable under Part 6A of the PDPA — that is, where it results in, or is likely to result in, significant harm to affected individuals, or is of a significant scale — we will notify the PDPC and, where required, the affected individuals, in accordance with the PDPA.
Access, Correction and Withdrawal of Consent
You may request access to, or correction of, personal data that we hold about you under Part 5 of the PDPA. A reasonable fee may be charged for access requests, and exceptions under the PDPA may apply. You may also withdraw any consent given, upon reasonable notice, in accordance with section 16 of the PDPA; we will inform you of the likely consequences of withdrawal. Requests should be sent to dpo@gmacp.com. We may need to verify your identity before responding.
Data Protection Officer
The Company has designated a data protection officer in accordance with section 11(3) of the PDPA. The data protection officer may be contacted at dpo@gmacp.com.
Marketing, Do Not Call and Spam
We do not send unsolicited marketing messages. Any specified messages sent to Singapore telephone numbers would be made in compliance with the Do Not Call provisions in Parts 9 and 9A of the PDPA, and any commercial electronic messages would comply with the Spam Control Act 2007 of Singapore.
Cookies and Analytics
This website may use cookies and similar technologies for its operation, security and analytics. You may disable cookies in your browser settings; parts of the website may not function fully as a result.
Third-Party Websites
This website may link to third-party websites. This Privacy Policy does not apply to those websites, and GMA is not responsible for their privacy practices.
International Visitors
This website is operated from Singapore and is not directed specifically at individuals in the European Union or European Economic Area. Where the EU or UK General Data Protection Regulation or other foreign data protection law applies to particular processing, GMA will handle the personal data concerned in accordance with applicable requirements.
Complaints and Amendments
Questions or complaints concerning personal data should be raised with us first at dpo@gmacp.com. You may also contact the Personal Data Protection Commission. This Privacy Policy may be updated from time to time; the "Last updated" date above indicates the current version.
Contact
Questions concerning this Privacy Policy, or requests relating to personal data, may be sent to dpo@gmacp.com.
