We at Cutis Medical Laser Clinics Pte Ltd (Cutis) are committed to safeguarding the personal data you have provided us and it is our responsibility to properly manage, protect and process your personal data.
“Personal Data” is defined under PDPA to mean data, whether true or not, about an individual who can be identified from that data, or from that data and other information to which an organisation has or is likely to have access.
We may collect additional personal data about you that you knowingly and voluntarily provide relating to certain activities at and/or transaction with Cutis or our website.
We will collect your personal data in accordance with the PDPA either directly from you or your authorised representatives, and/or through our third-party service providers (e.g. Netsuite, Dragonhub, Mailchimp). We will notify you of the purposes for which your personal data may be collected, used, disclosed and/or processed, as well as obtain your consent for the collection, use, disclosure and/or processing of your personal data for the intended purposes, unless an exception under the law permits us to collect and process your personal data without your consent.
Use of your personal information collected
Your personal information will be held in our system. The data which we collect from you may be collected, used, disclosed and/or processed for various purposes such as but not limited to:
- Communicating with you on your enquiries, sending marketing, advertising and promotional information and materials relating to products, events and/or services where permitted under law that we, our partners and/or third party organisations with whom we are collaborating, may be selling or marketing.
- Managing your enquiries and/or processing your sign-ups/registrations.
- Conducting market research, data analytics, data mining, data profiling and customer satisfaction surveys to enable Cutis to improve our products, services and customer service, to develop new products and services, and to provide customized and personalised products and services to you; and
- Any other purposes that we notify you of at the time of obtaining your consent. (collectively, the “Purposes”)
As for other purposes for which we may use, disclose or process your personal data that has not appeared above, we will notify you of such other purpose at the time of obtaining your consent, unless processing of your personal data without your consent is permitted by the PDPA or by law.
To conduct our business operations more smoothly and to fulfill the above-said Purposes, we may also be disclosing the personal data you have provided to us to our third-party service providers and/or other third parties whether sited in Singapore or outside of Singapore, for one or more of the above-stated Purposes.
Such third-party service providers and/or other third parties would be processing your personal data either on our behalf or otherwise, for one or more of the above-stated Purposes.
Specific issues for the disclosure of personal data to third parties
We respect the confidentiality of the personal data you have provided to us. In that regard, we will not disclose your personal data to third parties without first obtaining your consent permitting us to do so. However, please note that we may disclose your personal data to third parties without first obtaining your consent in certain situations, including, without limitation, the following:
- Cases in which the disclosure is required or authorised based on the applicable laws and/or regulations
- Cases in which the purpose of such disclosure is clearly in your interests, and if consent cannot be obtained in a timely way;
- Cases in which the disclosure is necessary to respond to an emergency that threatens the life, health or safety of yourself or another individual;
- Cases in which the disclosure is necessary for any investigation or proceedings;
- Cases in which the personal data is disclosed to any officer of a prescribed law enforcement agency, upon production of written authorisation signed by the head or director of that law enforcement agency or a person of a similar rank, certifying that the personal data is necessary for the purposes of the functions or duties of the officer;
- Cases in which the disclosure is to a public agency and such disclosure is necessary in the public interest; and/or
- where such disclosure without your consent is permitted by the PDPA or by law.
The instances listed above are not intended to be exhaustive.
For more information on the exceptions, you are encouraged to peruse the Second, Third and Fourth Schedules of the PDPA which is publicly available at https://sso.agc.gov.sg/Act/PDPA2012
Where we disclose your personal data to third parties with your consent, we will employ our best efforts to require such third parties to protect your personal data.
Access to and correction of your information
You have the right to be informed about how we use your data. We cover all the important points in this privacy notice but if you have any questions, then don’t hesitate to email us at firstname.lastname@example.org
You may request to access and/or correct the personal data currently in our possession or control by submitting a written request to us. We will need enough information from you to ascertain your identity as well as the nature of your request, to be able to deal with your request. Hence, please submit your written request to email@example.com
For a request to access personal data, once we have sufficient information from you to deal with the request, we will seek to provide you with the relevant personal data within 30 days.
Where we are unable to respond to you within the said 30 days, we will notify you of the soonest possible time within which we can provide you with the information requested. Note that the PDPA exempts certain types of personal data from being subject to your access request.
For a request to correct personal data, once we have sufficient information from you we will:
- Correct your personal data within 30 days. Where we are unable to do so within the said 30 days, we will notify you of the soonest practicable time within which we can make the correction. Note that the PDPA exempts certain types of personal data from being subject to your correction request as well as provides for situation(s) when correction need not be made by us despite your request; and
- Upon successful correction of personal data, we will send the corrected personal data to every other organisation to which the personal data was disclosed by Cutis within a year before the date the correction was made, unless that other organisation does not need the corrected personal data for any legal or business purpose.
We may, if you so consent, send the corrected personal data only to specific organisations to which the personal data was disclosed by us within a year before the date the correction was made.
We will also be charging you a reasonable fee for the handling and processing of your requests to access your personal data. We will provide you with a written estimate of the fee we will be charging. Please note that we are not required to respond to or deal with your access request unless you have agreed to pay the fee.
Request to withdraw
If you decide to give us permission to collect and use your data, then you have the right to withdraw your consent at any time. However, this might also mean that we will no longer be able to offer you certain services or access to our benefits, and privileges.
You may ask us to delete the personal data we hold on you. We will consider your request and not reasonably refuse it. If we agree to your request, we will remove any information that identifies you as an individual. In both cases we may retain anonymised data (for example, your booking history) for business purposes.To make a request for any of the above, please email us at firstname.lastname@example.org
If you have opted-in to receive promotional and marketing-related communications, then you have the right to stop us from contacting you for marketing purposes at any time. We may still send you important administrative messages needed to provide you with our services or in the event of changes, cancellations or other urgent situations which may inconvenience you if we were not to do so.
If you no longer wish to be contacted for marketing purposes, please take the opportunity click ‘Unsubscribe’ or you can just send us an email to request to withdraw. Send your email to email@example.com
We use reasonable precautions to protect your data within our organisation. However, please be aware that no method of data transmission over the internet or method of electronic/cloud storage is 100% secure. We strive to protect the security of your information and if you feel the security of your data with us has been compromised, please contact us immediately.
We make use of permanent cookies on its Website. For additional protection however, the we suggest not to share computers when submitting an enquiry via our website and/or landing pages.
Web Server Logs
E-mail Newsletters and Promotional E-mails
You have the option to unsubscribe to these services after completing a registration form whether online or in clinic. Our emails sent contain unsubscribe instructions. If there are no such instructions in a personalized email that is generated by our staff rather than the system, please contact firstname.lastname@example.org if you don not want to be contacted at all by email.
Competitions and Surveys Participation in these events is entirely voluntary and you can choose what information you wish to disclose. Survey analysis will result in generalised, non-personally identifiable results.
Our contact details