PRIVACY POLICY

Personal Data Protection Policy

Thank you for visiting the AllMasksKorea Singapore website (the “Website”). Your visit to this Website and your use of our products and services provided herein are subject to the terms and conditions herein contained. Please read these carefully.

General

1. AOTC Pte Ltd ("us", "we", or "our") operates this Website. We take our responsibilities under Singapore’s Personal Data Protection Act 2012 (the "PDPA") seriously. We also recognise the importance of the personal data you have entrusted to us. We believe that it is our responsibility to properly manage, protect and process your personal data.

2. In this Policy, as under the PDPA, “personal data” means data, whether true or not, about a customer who can be identified: (a) from that data; or (b) from that data and other information to which we have or are likely to have access. Personal data examples could include names, identification numbers, date of birth, contact information, skin records, photographs, and video images.

3. This Policy, together with our [Terms of Use], [Cookie Policy], and [Terms of Purchase] (if you make a purchase on the Website) are designed to help you understand how we collect, use, disclose and/or process your personal data.

4. Unless restricted by the PDPA or any other applicable law, you agree that we may process your personal data in the manner, and for the purposes set out in the terms described in this Policy.

How Personal Data is collected

1. We may collect your personal data in several situations, including, without limitation, the following:

(a) when you register for an account on the Website 

(b) when you complete purchase orders, requests or applications for our products or services (by telephone, in person, mail or electronically);

(c) when you purchase on the Website;

(d) when you communicate with us directly about our products and services (in person; via our customer service; by email, telephone or other means);

(e) when you use services available on the Website

(f) when you enter and interact with us during promotions, competitions, contests, lucky draws or special events.

(g) when you participate in surveys and other types of research we may conduct.

Collection of personal data

1. You can use and browse the Website without disclosing your personal data. Personal data provision is voluntary. However, if you do not provide your personal data to us, we may not be able to provide some or all of the products and services you need.

2. We may collect personal data about you, including:

(a) your contact information such as names, addresses, telephone numbers, and email addresses;

(b) billing information such as billing address and credit card information;

(c) unique information such as photographs; contact preferences; and date of birth;

(d) details of any membership you have with us;

(e) details of your visits to the Website, such as traffic data; location data; and the resources you access on the Website; and

(f) your transaction history.

Provision of third-party personal data by you

1. Should you provide us with personal data of individual(s) other than yourself, you represent and warrant to us and you hereby confirm that:

(a) prior to disclosing such personal data to us, you would have obtained consent from the individuals whose personal data are being disclosed to us, to:

(i) permit you to disclose individuals' personal data to us for the purposes we disclosed to you; and

(ii) permit us to collect, use, disclose and/or process individuals' personal data for the said purposes;

(b) any personal data you disclose to us is accurate; and

(c) you are validly acting on behalf of such individuals and that you have the authority of such individuals to provide their personal data to us and for us to collect, use, disclose and process such personal data for the purposes.

Purposes for Collection, Use, Disclosure

1. The personal data we collect from you may be used, disclosed and/or processed for various purposes, depending on the circumstances under which we may/will need to process your personal data, including, without limitation:

(a) to communicate with you;

(b) to maintain and improve our working relationship;

(c) to assess, process and provide products, services and/or facilities to you;

(d) to administer and process any payments (including refunds) related to products, services and facilities requested by you;

(e) to establish your identity and background;

(f) to respond to your enquiries or complaints and resolve any issues and disputes in connection with any dealings with us;

(g) to provide you with the services or assistance you have requested;

(h) to provide you with information and/or updates on our products, services, upcoming promotions offered by us and/or events organised by us and selected third parties which may be of interest to you from time to time;

(i) for direct marketing purposes via SMS, WhatsApp, LINE, WeChat, KaKaoTalk, phone call, email, fax, mail, social media and/or any other appropriate communication channels, if you are a member of any of our loyalty programmes, in accordance with your consent;

(j) to facilitate your participation in, and our administration of, any events including contests, promotions or campaigns;

(k) to award points in a membership, loyalty or rewards programme;

(l) to maintain and update internal record keeping;

(m) for internal administrative purposes;

(n) to send you seasonal greeting messages from time to time;

(o) to send you invitations to join our promotional events and product launch events;

(p) to monitor, review and improve our programs, promotions, products and/or services;

(q) to conduct credit reference checks and establish your creditworthiness, where necessary, when providing you with products, services and/or facilities;

(r) to administer, process and fulfil your commercial transactions with us (such as a purchase on the Website, a tender award, a contract for service or a tenancy agreement);

(s) to process any payments related to your commercial transactions with us;

(t) to process and analyse your personal data individually or collectively;

(u) to conduct market research or surveys, internal marketing analysis, customer profiling activities, analysis of customer patterns and choices, planning and statistical and trend analysis in relation to our products and/or services;

(v) to share your personal data with the auditor for internal audit and reporting purposes;

(w) to share any of your personal data pursuant to any agreement or document you have duly entered into with us for purposes of seeking legal and/or financial advice and/or commencing legal action;

(x) to share your personal data with our business partners to jointly develop products and/or services or launch marketing campaigns;

(y) to share any of your personal data with financial institutions necessary for applying and obtaining credit facility(s), if necessary;

(z) for audit, risk management and security purposes;

(aa) for detecting, investigating and preventing fraudulent, prohibited or illegal activities;

(bb) for enabling us to perform our obligations and enforce our rights under any agreements or documents we are parties to;

(cc) to transfer or assign our rights, interests and obligations under any agreements entered into with us;

(dd) for meeting any applicable legal or regulatory requirements and making disclosures under the requirements of any applicable law, regulation, direction, court order, by-law, guideline, circular or code applicable to us;

(ee) to enforce or defend our rights and your rights under, and to comply with, our obligations under the applicable laws, legislation and regulations;
(ff) for other purposes required to operate, maintain and better manage our business and your relationship with us; which we notify you of at the time of obtaining your consent; and/or

(gg) administering, facilitating, processing and/or dealing in any matters relating to your use or access of the Website. Without limiting the generality of the foregoing, if you:

(i) gain access to or sign into the Website, using your login credentials of a Social Networking Site, or

(ii) use any features of a Social Networking Site such as its widgets, plug-ins and browser push notifications, made available to you on our Website, it may result in information or your personal data being collected or shared between us and the third party. For example, if you use Facebook’s “Like” feature, Facebook may register the fact that you “liked” a product and post that information on Facebook. (“Social Networking Site” refers to an online or digital platform owned or operated by a third party. This platform is utilized by people to build social networks or social relations, or to interact, with other people, such as but not limited to Facebook, Instagram, Twitter, Weibo, WeChat). By your proceeding pursuant to (i) or (ii) above, you consent to such collection, use or disclosure of your personal data.

As the purposes for which we may/will collect, use, disclose or process your personal data depend on the circumstances at hand, such purposes may not appear in the instances listed above. However, we will notify you of such other purpose(s) at the time of obtaining your consent, unless we are permitted by the PDPA or any other applicable law to process your personal data without your consent.

Disclosure of personal data to third parties

1. In order to smoothly conduct our business operations or to fulfil our obligations to you, we may also disclose the personal data that you have provided to us to our third party service providers, agents, affiliates or related corporations, which may be situated inside or outside Singapore, for one or more of the purposes stated in or notified to you under the Purposes for Collection, Use, Disclosure section. We will also disclose your personal data to government regulators or authorities to comply with any laws, rules, guidelines, regulations or schemes that apply to us.

Examples of third parties to whom we disclose your personal data include:

(a) data entry service providers;

(b) professional advisors, consultants and/or external auditors;

(c) storage and warehousing facility providers (which may include data storage and processing servers located overseas);

(d) third party service providers who provide administrative or operational services in connection with our business such as telecommunications, information technology, logistics, delivery, printing and postal services or services relating to marketing and promotional activity;

(e) relevant government regulators or authorities;

2. The third parties with whom we conduct business are only authorized to use your information to perform the service for which they were hired. As part of our agreement with them, they must adhere to the PDPA and any policies we provide. They are also required to take reasonable measures to ensure your personal data is secure.

3. We respect the confidentiality of your personal data. We do not sell personal data to third parties.

Request for Access and/or Correction of Personal Data

1. You may request access and/or correct your personal data in our possession or under our control by writing to us at sales@aotc.sg.

2. For a request to access personal data, we shall reasonably endeavour to provide you with the relevant personal data within thirty (30) days of such a request being made. Where the information you request requires more time and expense, we shall reach an agreement with you on terms on how to process your request Depending on the scope and nature of the work required to process your access request, we may be required to impose a fee to recover our administrative costs. This will be assessed on a case-by-case basis by our Data Protection Officer. Where such a fee is to be imposed, we will provide you with a written estimate of the fee for your consideration. Please note that we will only process your request once you have agreed to the payment of the fee. In certain cases, we may also require a deposit from you before we process the access request. You will be notified if a deposit is required when we provide you with a written estimate of the fee, if any.

2. For a request to correct personal data, we will correct your personal data as soon as practicable after the request has been made. This is unless we have reasonable grounds not to do so.

3. You understand that we depend on you to provide us with accurate and complete personal data and with updates if there are any changes to your personal data. We will not be responsible for relying on or using any inaccurate or incomplete personal data where you have provided such personal data and/or have failed to update us of any changes to your personal data.

Request to Withdraw Consent

1. You may withdraw your consent to the collection, use and/or disclosure of your personal data in our possession or under our control. This is done by writing to us at sales@aotc.sg.

2. We will process your request within a reasonable time from such a request for withdrawal of consent being made. We will thereafter not collect, use and/or disclose your personal data in the manner stated in your request.

3. Your withdrawal of consent may have certain consequences. For example, it may mean that we will not be able to provide you with certain products or services that you have requested or that we will not be able to continue with your existing relationship with us. We will inform you of such consequences after we receive your request for withdrawal.

4. However, you understand that notwithstanding your withdrawal of consent, we will still be entitled to collect, use or disclose your personal data if we are required or authorised to do so under the PDPA or any other applicable law.

Protection and destruction of Personal Data

1. We will put in place reasonable security arrangements to ensure that your personal data is adequately protected and secured. In particular, reasonable security arrangements will be taken to prevent any unauthorized access, collection, use, disclosure, copying, modification, leakage, loss, damage and/or alteration of your personal data. However, we cannot assume responsibility for any unauthorized use of your personal data by third parties which are wholly attributable to factors beyond our control.

2. We may retain your personal data for as long as it is necessary to fulfil the purpose for which it was collected, or as required or permitted by applicable laws. We will also put in place measures to ensure that any of your personal data that is in our possession or under our control is destroyed and/or anonymized as soon as it is reasonable to assume that:

(a) the purpose for which that personal data was collected is no longer being served by the retention of such personal data; and

(b) retention is no longer necessary for legal or business purposes.

Cookies and Mobile Technology

1. For users of the Website, please note that we may deposit “cookies” on your computer or your mobile device in order to identify you. Cookies are small data text files that are sent from a server to a computer during a browsing session. Cookies are typically stored on a computer’s hard drive and used by websites to simulate continuous connections. Security measures have been employed to prevent unauthorized access to visitor data. However, visitors acknowledge that we do not control the transfer of data over telecommunications facilities including the Internet. Therefore, to the extent permitted by law, we will not be responsible for any breach of security or the unauthorized disclosure or use of any such data on the Internet, through no fault of ours. Not all cookies collect personal data and you may configure your browser to reject cookies. However, this may mean you may not be able to take full advantage of the Website's services or features. Where the data collected by such cookies constitute your personal data, such personal data is being collected, used or disclosed for one or more of the purposes. By continuing to use the Website, you are agreeing to the use of cookies on the Website. However, please note that we have no control over the cookies used by third parties.

2. Flash cookies. “Flash Cookies” (also called Local Shared Objects or “LSOs”) are data files similar to cookies, except that they can store more complex data. Flash Cookies are used to remember settings, preferences, and usage, particularly for video, interactive gaming, and other similar services.

3. Web beacons. Web beacons are small graphic images on a web page or in an e-mail that can be used for recording users' pages and advertisements clicked or tracking the performance of e-mail marketing campaigns.

4. Analytics Tags. We use analytical tags to analyse what our clients like to do and the effectiveness of our features and advertising. They can also help us customize your browsing and shopping experience. We may use information collected through analytical tags or tracking links with your Personal Data. We may also combine the personal data you provide to us with other personal data (such as purchase history and demographic information). We often work with other companies such as, to help us track, collect and analyse this information but they are prohibited from using this information for any other purpose.

5. Web server logs. Web server logs are records of activity created by the mobile device or computer that delivers the webpages you request to your browser. For example, a web server log may record the search term you entered or the link you clicked to bring you to the webpage. The Web server log also may record information about your browser, such as your IP address and the cookies set on your browser by the server.

6. Geo-location technologies. Geo-location technology refers to technologies that permit us to determine your location. We may ask you to manually provide location information (like your postal code), or enable your mobile device to send us precise location information. For example, the first time you download the App you will/may be asked to choose between allowing or not allowing the App to access your location and/or to send you mobile notifications. If you choose “Do Not Allow,” you will have opted-out of having the App access your location to send you location-specific offer notifications. If you choose “OK” the App will communicate with your mobile device and collect certain data as provided in this Policy to provide you with targeted offers based on your location. You can always opt-out of sharing location data with the App by changing your device settings.

7. Our Website contains areas where you can submit information to us (such as our registration service). We also have features (such as cookies and performance tracking technology) that automatically collect information from visitors to our Website. During the registration process, you must provide us with a password, your name, address and a valid email address, etc. It is your responsibility to keep your password confidential.

Complaint Process

a) If you have any complaint or grievance regarding how we are handling your personal data or about how we are complying with the PDPA, we welcome you to contact us by writing to us at sales@aotc.sg.

We will certainly strive to deal with any complaint or grievance that you may have promptly and fairly.

Contact Us

b) You may contact us (or send us any request or complaint form) by post or email at the following address:

456 Alexandra Road #04-02

Fragrance Empire Building

Singapore 119962

Email Address: sales@aotc.sg

c) We reserve the right to amend this Personal Data Protection Policy at our absolute discretion. Any amended Personal Data Protection Policy will be posted on the Website and can be viewed at www.allmaskskorea.com. No individual notice will be sent to you.

You are deemed to have acknowledged and agreed to any amended version of this Personal Data Protection Policy if you continue to use the Website after the changes have taken place. As such, you are encouraged to visit the above website from time to time. This is to ensure that you are well informed of our latest policies regarding personal data protection.

Effect of Policy and Changes to Policy

d) This Policy applies in conjunction with any other notices, contractual clauses and consent clauses that apply in relation to the collection, use and disclosure of your personal data by us.

You are encouraged to check this Website for this Policy from time to time to ensure that you are well informed of our latest policies on personal data protection. We may revise this Policy from time to time without prior notice. You may determine if any such revision has occurred by referring to the date this Notice was last updated. Your continued use of our services constitutes your acknowledgement and acceptance of such changes.

Updated as of 30th March 2023