This Privacy Policy explains how Real Estate Doc Pte Ltd collects, uses, discloses and protects personal data, including personal data submitted through the Instant Approval-in-Principle mortgage referral feature.
1. ABOUT THIS POLICY
1.1 Real Estate Doc Pte Ltd (UEN 201729826Z) of 77 Robinson Road #16-00, Singapore 068896 ("Redoc", "we", "our" or "us") is committed to protecting personal data in accordance with the Personal Data Protection Act 2012 of Singapore (the "PDPA").
1.2 This Policy applies to personal data collected through www.redoc.co, www.realestatedoc.co, our web and mobile applications, and any service we provide (together, the "Platform"). It applies whether you are a registered account holder, an authorised user of a business customer, a prospective borrower whose data is submitted for a mortgage referral, or a visitor to our website.
1.3 In this Policy, "personal data" has the meaning given in the PDPA. Where this Policy conflicts with our Terms of Service in relation to the handling of personal data, this Policy prevails.
1.4 We may update this Policy from time to time. The current version is always published on our website and takes effect from the date stated at the top of this document. Where a change is material we will take reasonable steps to notify affected individuals.
2. DATA PROTECTION OFFICER
How to contact our Data Protection Officer
Data Protection Officer, Real Estate Doc Pte Ltd
77 Robinson Road #16-00, Singapore 068896
Email:
dpo@realestatedoc.co
We aim to acknowledge every enquiry within three (3) business days and to provide a substantive response within thirty (30) days. Where we cannot respond within thirty days we will tell you why and when you can expect a response.
3. WHOSE PERSONAL DATA WE HANDLE
We handle personal data relating to three distinct groups, and our role differs for each. This distinction matters, so we set it out plainly.
Account holders — Who they are: Individuals and businesses who register for an account, including real estate agencies and individual salespersons; Our role: We decide why and how this data is used. We are responsible for it directly.
Authorised users — Who they are: Salespersons and staff authorised by a business customer to use the Platform under that customer's account; Our role: We handle this data on behalf of the business customer, and also for our own account administration and security purposes.
Clients — Who they are: Prospective borrowers whose personal and financial data is submitted by a salesperson for a mortgage Approval-in-Principle. Clients are not account holders.; Our role: We act mainly as a conduit. The salesperson's agency is responsible for obtaining your consent; the bank decides your application. See Section 7.
4. WHAT PERSONAL DATA WE COLLECT
4.1 Account and profile data
— Name, email address, contact number, home or business address, organisation, professional licence or registration number (including Council for Estate Agencies registration), and password.
— Account activity, login records, IP address, device and browser information.
4.2 Transaction and document data
— Documents you upload, and text and structured data extracted from them by our automated processing features.
— Details of transactions, forms, contracts and signatures created using the Platform.
— Approximate location information collected when you access a signing, approval or forwarding link, as described in Section 10.
4.3 Mortgage referral data (“Referral Data”)
Where an Approval-in-Principle application is submitted, we collect the following in relation to the Client:
— Name, contact number, email address and identification details.
— Employment status, income, variable income, and existing financial commitments and liabilities.
— Property details including estimated purchase price, property type and existing property loans.
— Data retrieved from Singpass MyInfo where the Client chooses to use it, as described in Section 8.
— The identity of the submitting salesperson and their agency, and consent and acknowledgement records.
— The specific categories of personal data retrieved from Singpass MyInfo will be limited to the information required for the relevant application or transaction. We do not intentionally retrieve MyInfo data that is not necessary for the stated purpose.
5. HOW WE COLLECT PERSONAL DATA
5.1 We collect personal data: directly from you when you register, use the Platform or communicate with us; from a business customer or its authorised users, where they submit data to us; from a salesperson, where they submit a Client's data for a mortgage referral; from Singpass MyInfo, where a Client authorises retrieval; automatically through cookies and similar technologies when you use our website; and from a Participating Bank, in the form of an application outcome or status update.
5.2 Where personal data is retrieved through Singpass MyInfo, the Client initiates and authorises the retrieval through the Singpass/MyInfo authentication process. The categories of data to be retrieved and the purpose of the retrieval will be presented to the Client as part of the relevant workflow before the data is used to populate the application.
6. WHY WE USE PERSONAL DATA
6.1 We use personal data for the following purposes:
(a) creating and administering accounts and user profiles;
(b) providing, operating, maintaining and improving the Platform;
(c) performing automated document processing that you request or enable, including optical character recognition, data extraction and pre-population of forms for your review;
(d) verifying that a user is a registered professional or authorised person within an organisation;
(e) facilitating mortgage referral and Approval-in-Principle applications, as described in Section 7;
(f) generating referral attribution reports for business customers;
(g) sending service communications necessary for the normal functioning of the Platform;
(h) responding to enquiries, complaints, feedback and requests;
(i) investigating suspected misuse, fraud or unlawful activity, and protecting the security and integrity of the Platform;
(j) recording the approximate location at which electronic signatures, approvals or forwarding actions are performed, as part of the Certificate of Completion audit trail;
(k) internal administration, record-keeping, accounting and management purposes; and
(l) complying with any applicable law, regulation, court order or request of a competent authority.
6.2 Marketing. We will send you marketing communications only where you have separately and expressly consented to receive them. Consent to marketing is never a condition of using the Platform, is requested separately from any service consent, and may be withdrawn at any time using the unsubscribe link in any marketing message or by contacting our Data Protection Officer.
6.3 We do not use Referral Data for marketing. See Section 7.4.
7. THE INSTANT APPROVAL-IN-PRINCIPLE FEATURE
Please read this Section carefully if you are a Client.
It explains what happens to your data when your
property agent submits a mortgage Approval-in-Principle application on your behalf.
7.1 What the feature does
7.1 The Approval-in-Principle ("AIP") feature allows a real estate salesperson to submit an application, on behalf of a Client, to a bank or financial institution licensed in Singapore which is integrated with our Platform (a "Participating Bank"). The Participating Bank assesses the application and returns an in-principle indication of the Client's borrowing eligibility.
7.2 Our role, and what we do not do
7.2 We act as a technology conduit. We transmit Referral Data to the relevant Participating Bank and return that Bank's response.
7.3 We do not assess, evaluate, score or verify any Client's creditworthiness, affordability or eligibility; we do not make or influence any lending decision; and we are not a bank, licensed financial adviser, mortgage broker or credit bureau. An AIP is an in-principle indication only and is not a confirmed loan approval or an offer of credit. Each Participating Bank assesses applications under its own licence, credit policies and privacy policy.
7.4 Purpose limitation — what we will not do with Referral Data
Our commitments in respect of Referral Data
We use Referral Data only to facilitate the AIP application and any resulting mortgage application, and to generate referral attribution reports for the submitting agency.
We do not use Referral Data for marketing, advertising, profiling or credit scoring; we do not use it for product development or to enrich our databases; we do not use it to train or improve any artificial intelligence or machine learning model, whether or not it has been anonymised; and we do not sell, rent or licence Referral Data to any person.
7.5 Consent
7.5 Before any Referral Data is transmitted to a Participating Bank, we present the Client with a privacy notice and request the Client's own express consent within the application workflow, and we record the Client's response together with the time of capture.
7.6 Separately, the salesperson and their agency are required to have obtained the Client's consent before submitting any data to us, and are contractually obliged to retain evidence of that consent and to produce it on request. If you are a Client and you did not give consent to your salesperson, please contact our Data Protection Officer immediately.
8. SINGPASS MYINFO
8.1 Where a Client chooses to complete an application using Singpass MyInfo, the retrieval of data is performed by the Government Technology Agency of Singapore under the Client's own Singpass authentication and consent, and is subject to Singpass and MyInfo terms of use.
8.2 We receive MyInfo data only to pre-fill the relevant application for the Client's review, and we use it strictly in accordance with Section 7.4. We never see, receive or retain Singpass credentials.
8.3 Using MyInfo is optional. A Client who prefers not to use it may complete the application manually.
8.4 MyInfo data retrieved through the Platform will only be used for the purpose communicated to the Client at the point of retrieval, including the pre-population and processing of the relevant application or transaction. We will not use MyInfo data for an unrelated purpose without obtaining the appropriate consent or otherwise having a lawful basis to do so.
8.5 We will limit the MyInfo data retrieved and processed to the categories reasonably required for the relevant application or transaction.
8.6 Where MyInfo data is stored within the Platform as part of an application, document or transaction record, access is restricted to authorised persons based on their roles and legitimate business requirements. Appropriate access controls and logging are applied in accordance with Section 15.
9. AUTOMATED AND AI-ASSISTED PROCESSING
9.1 The Platform uses automated tools, including optical character recognition and AI-assisted extraction, to detect and extract text and structured data from documents you upload and to pre-fill fields for your review.
9.2 Automated extraction may contain errors or omissions. You are responsible for reviewing and verifying the information before submitting, signing, sharing or relying on any output.
9.3 We may disclose uploaded documents and extracted data to vetted service providers who help us deliver these features, solely for that purpose and subject to contractual confidentiality and data protection obligations.
9.4 We do not permit service providers to use your documents or extracted data to train their general-purpose AI models, except where you have expressly consented or where the data has been irreversibly anonymised. This exception does not apply to Referral Data, which is never used for model training in any form.
9.5 Where documents or data containing MyInfo-derived personal data are processed using automated or AI-assisted features, such processing will be limited to the purpose for which the data was originally collected. MyInfo-derived Referral Data will not be used to train or improve general-purpose artificial intelligence or machine learning models.
10. LOCATION DATA DURING ELECTRONIC SIGNING
10.1 When you access a signing, approval or forwarding link, we collect information about your approximate location in order to generate a Certificate of Completion which serves as an audit trail for the signed document.
10.2 If you grant browser location permission, we collect latitude, longitude and accuracy in metres via your browser's Geolocation API. We use this to derive and display your city and country in the Certificate and to generate a map reference link. Raw coordinates are stored internally for audit purposes but are not displayed in the Certificate.
10.3 If you decline or your browser does not support geolocation, we derive your approximate city and country from your device's IP address as observed by our servers. No GPS coordinates are collected or stored in that case.
10.4 City, country and location source are included in the Certificate of Signature, which is accessible to all parties to the document and to any third party to whom the Certificate is disclosed.
10.5 Location data is indicative evidence only. Browser coordinates are self-reported by your device; IP-derived location may be accurate only to within 50 to 100 kilometres. Location data should not be treated as forensic proof of physical presence. It is retained as part of the certificate record for the lifetime of the document.
11. WHO WE DISCLOSE PERSONAL DATA TO
11.1 We do not sell or rent personal data. We disclose personal data only as follows:
Participating Banks — What is disclosed: Referral Data for the relevant application; Why: To obtain an Approval-in-Principle and to process any resulting mortgage application
Business customers — What is disclosed: Data of their own authorised users; referral attribution reports; Why: Account administration and allocation of referral fees
Service providers — What is disclosed: Data necessary for hosting, infrastructure, document processing and support; Why: To operate the Platform, under confidentiality and data protection obligations
Government Technology Agency — What is disclosed: Authentication requests; Why: To enable Singpass MyInfo retrieval at the Client's request
Professional advisers and insurers — What is disclosed: As necessary; Why: Legal advice, audit and insurance
Authorities and regulators — What is disclosed: As required; Why: Where required by law, regulation, court order or lawful request, including the Personal Data Protection Commission and the Council for Estate Agencies
Acquirers — What is disclosed: As necessary; Why: In connection with a merger, acquisition or sale of assets, subject to equivalent protection
11.2 We require every service provider with access to personal data to be bound by obligations no less protective than those in this Policy. We will not engage any service provider to process Referral Data without the consent of the relevant business customer and, where required, of the Participating Bank, other than hosting and infrastructure providers.
11.3 Where a service provider processes personal data obtained through MyInfo, we require the service provider to process such data only for the purpose for which it has been engaged, to protect the data appropriately, and not to use or disclose the data for its own independent purposes.
12. ANONYMISED AND AGGREGATED DATA
12.1 We may remove information which identifies an individual and use or share anonymised or aggregated data for analytics, benchmarking and service improvement. Aggregated and anonymised data is our property and is not subject to this Policy.
12.2 This applies only where anonymisation is irreversible. Data which remains capable of re-identification continues to be treated as personal data under this Policy. Referral Data is not aggregated or shared for any commercial purpose, whether anonymised or not.
13. HOW LONG WE KEEP PERSONAL DATA
Account and profile data — Retention period: For the life of the account, then 12 months; Why: Account administration and dispute window
Documents and extracted data — Retention period: For the life of the account, unless deleted earlier by you; Why: To provide the Platform
Referral Data — incomplete or abandoned application — Retention period: 90 days from last activity, then deleted; Why: No continuing purpose
Referral Data — completed application — Retention period: 7 years from the date of application; Why: Financial record-keeping expectations of Participating Banks
Consent records and audit logs — Retention period: 7 years; Why: To evidence compliance with the PDPA and with our obligations to Participating Banks
Certificate of Completion and location data — Retention period: For the lifetime of the document; Why: Audit trail integrity under electronic transactions law
Marketing preferences — Retention period: Until withdrawn, then a suppression record indefinitely; Why: To honour your withdrawal
13.1 We may retain personal data for longer where required by law, where necessary for the establishment or defence of legal claims, or where a Participating Bank's regulatory record-keeping obligations require it.
13.2 MyInfo-derived personal data will not be retained merely because it was retrieved through MyInfo. Its retention will depend on the purpose for which it was collected and the application, document or transaction record of which it forms part. When there is no longer a legal or business purpose for retaining the data, we will securely delete or anonymise it in accordance with our data retention procedures.
14. TRANSFERS OUTSIDE SINGAPORE
14.1 We may transfer personal data outside Singapore, including for cloud hosting and infrastructure. Where we do, we take reasonable steps to ensure the recipient is bound by legally enforceable obligations to provide a standard of protection at least comparable to that required under the PDPA.
14.2 We will tell you, on request, the countries in which your personal data is stored. We will not transfer Referral Data outside Singapore without the consent of the relevant business customer and, where required, of the Participating Bank.
15. HOW WE PROTECT PERSONAL DATA
15.1 We employ physical, electronic and managerial safeguards appropriate to the sensitivity of the data we handle, including encryption of data in transit, role-based access control, logging and monitoring, secure credential management, secure development practices and timely patching. These safeguards apply to documents you upload and to data extracted from them.
15.2 No system is entirely secure. While we use reasonable measures to safeguard personal data, we cannot guarantee absolute security, and you are responsible for keeping your account credentials confidential and for notifying us promptly of any suspected unauthorised access.
15.3 Access to personal data obtained through MyInfo is limited to authorised personnel and users who require such access for the relevant application, transaction, support or compliance purpose. Access and administrative activities involving such data are logged and monitored for security, audit and compliance purposes.
16. YOUR RIGHTS
16.1 Access and correction
16.1 You may request access to personal data we hold about you and information about how it has been used or disclosed in the past year, and you may request correction of any error or omission. Please contact our Data Protection Officer. We may charge a reasonable fee for an access request and will tell you the amount before proceeding.
16.2 We will respond within thirty (30) days. Where we cannot, we will tell you why and when you can expect a response. We may decline a request where the PDPA permits or requires us to do so, and we will explain why.
16.2 Withdrawing consent
16.3 Any individual, including a Client who is not a registered account holder, may withdraw consent to our collection, use or disclosure of their personal data by written notice to our Data Protection Officer.
16.4 On receipt we will cease the relevant processing within ten (10) business days and confirm in writing. We will tell you the likely consequences of withdrawal, which may include that a pending Approval-in-Principle or mortgage application cannot proceed.
16.5 Withdrawal does not require us to delete data which we are required to retain by law, for a Participating Bank's regulatory record-keeping, or for the establishment or defence of legal claims. Consent records and audit logs relating to a completed application will be retained notwithstanding withdrawal, for the purpose of demonstrating compliance.
16.6 Where your data has already been transmitted to a Participating Bank, you must also address your withdrawal to that Bank. We will provide the Bank's data protection contact on request. We cannot withdraw data from a Bank's systems on your behalf.
17. DATA BREACH NOTIFICATION
17.1 We maintain a documented data breach response procedure. On becoming aware of a suspected breach we will assess without undue delay, and in any event within thirty (30) days, whether the breach is notifiable.
17.2 Where a breach results in, or is likely to result in, significant harm to affected individuals, or is of a significant scale, we will notify the Personal Data Protection Commission as soon as practicable and in any event within three (3) calendar days of completing our assessment, and will notify affected individuals as soon as practicable thereafter.
17.3 Where a breach affects Referral Data, we will additionally notify the relevant Participating Bank and business customer without undue delay and in any event within twenty-four (24) hours of becoming aware, and will co-operate in any notification they are required to make.
18. COOKIES AND WEBSITE ANALYTICS
18.1 Our website uses cookies and similar technologies to operate the site, remember your preferences, maintain your session and understand how the site is used. You can manage cookies through your browser settings, although disabling certain cookies may affect the functionality of the Platform.
19. CHILDREN
19.1 The Platform is intended for use by persons aged 18 and over. We do not knowingly collect personal data from children. If you believe we have done so, please contact our Data Protection Officer and we will delete it.
20. COMPLAINTS
20.1 If you are concerned about how we have handled your personal data, please contact our Data Protection Officer first. We take complaints seriously and will investigate and respond.
20.2 If you remain dissatisfied you may lodge a complaint with the Personal Data Protection Commission of Singapore. Where your concern relates to a Participating Bank's handling of your data, you should also contact that Bank directly, and you may raise the matter with the Monetary Authority of Singapore or the Financial Industry Disputes Resolution Centre.
Real Estate Doc Pte Ltd · UEN 201729826Z · 77 Robinson Road #16-00, Singapore 068896 · dpo@realestatedoc.co. Version 1.0.