Privacy Policy for Vernon’s Pte Ltd
Effective Date: 25th March 2025

 

1. Introduction

Vernon’s Pte Ltd (“we,” “us,” or “our”) operates swim schools in Singapore, Malaysia, and Indonesia. This Privacy Policy explains how we collect, use, disclose, and protect your personal data in compliance with:
 
  • Singapore: Personal Data Protection Act (PDPA).
  • Malaysia: Personal Data Protection Act 2010 (PDPA).
  • Indonesia: Law No. 11/2008 on Electronic Information and Transactions (UU ITE), Government Regulation No. 71/2019, and related regulations.
 
By using our services, you consent to the practices described herein.

 

2. Data We Collect

We may collect :
  • Personal Data: Names, contact details (email, phone, address), emergency contacts, payment information.
  • Sensitive Data (if applicable): Health conditions (e.g., allergies, disabilities) relevant to swim safety.
 
Jurisdictional Notes:
Malaysia & Indonesia: Explicit consent is required for sensitive data.

 

3. Purposes of Data Use

We use your data to:
  • Register students, process payments, and communicate schedules.
  • Ensure safety during lessons (e.g., health-related accommodations).
  • Send promotional offers (with consent where required).
 

4. Legal Basis for Processing

  • Contractual Necessity: To fulfill enrollment agreements.
  • Consent: For marketing or sensitive data (opt-out/withdrawal is available).
  • Legal Obligations: Compliance with local laws.

 

5. Data Sharing & Transfers

We keep your data within our organization and do not share it with external parties unless necessary for the services we provide. This includes:
  • Third Parties: Payment processors, IT providers, or insurers who assist us in delivering our services.
  • Cross-Border Transfers:
  1. Indonesia: Data is stored locally or transferred only to jurisdictions with adequate protections.
  2. Singapore/Malaysia: Transfers comply with PDPA requirements.

 

6. Data Security

We implement technical and organizational measures (e.g., encryption, access controls) to protect data from breaches.
Breach Notification:
  • Singapore: Notify PDPC and affected individuals if harm is likely.
  • Indonesia: Report to KOMINFO (Ministry of Communication) within 72 hours.
 

7. Retention Period

Data is retained only as long as necessary:
  • Singapore/Malaysia: Up to 6 years post-enrollment (legal/accounting requirements).
  • Indonesia: As per contractual needs or until consent is withdrawn.

 

8. Your Rights

You may:
  • Access, correct, or delete your data.
  • Withdraw consent (e.g., marketing).
  • Request data portability (where applicable).
 
Children’s Data:
  • Parental consent is required for minors under:
    1. Singapore/Malaysia: 18 years.
    2. Indonesia: 14 years.

 

9. Jurisdiction-Specific Clauses

 

10. Updates

We may update this policy periodically. Changes will be posted on our website.