Last updated: September 2026
If there is any conflict between the English and Chinese versions, the English version shall prevail.
This policy is issued by 1965 Intelligence Pte. Ltd. (UEN [UEN], registered address [Registered Address], Singapore) ("we", "us", "our") and explains how we collect, use, disclose and protect personal data under Singapore's Personal Data Protection Act 2012 (PDPA) and other applicable law. It applies to our marketing website, application and related services (the "Platform").
In respect of an advisor's own account data, we act as the data controller and decide the purposes for which that data is collected and used. In respect of personal data about an advisor's clients that the advisor enters into the planning tools, we act as a data intermediary, processing that data solely on the advisor's behalf and instructions. The purposes, legal basis and retention of that client data are determined and owned by the advisor, see Section 5.
We collect the following categories of data:
We collect, use and disclose data for the following purposes:
When you enter personal data about your clients into the Platform, you, not us, are the data controller for that data. You are responsible for obtaining any consent or other lawful basis required under the PDPA and any other applicable law before entering, storing or processing your clients' data, and for disclosing to them that their data will be stored on this Platform. We process this data only on your instructions, as your data intermediary; we do not use client data for any purpose outside your instructions and never use it for our own marketing.
Account data and client data are stored in a PostgreSQL database hosted on AWS infrastructure in Singapore. Passwords are stored as hashes; one-time codes, refresh tokens and recovery codes are stored as hashes, never in plain text. Data is encrypted in transit and at rest using industry-standard protocols. Internal access is restricted on a least-privilege basis, and staff actions are recorded in an audit log. While we take reasonable technical and organisational measures to protect data, no system can be guaranteed to be completely secure.
We use the following third-party service providers to process data:
These providers each maintain a Singapore data centre and hold the relevant licence to operate in Singapore, process data only on our instructions, and are bound by contractual confidentiality obligations. Other than these providers and where required by law, we do not sell or share your data.
Where any of the above providers uses an AI/ML model to carry out a minor processing task on their platform (for example, fraud detection or support-ticket triage), that processing follows the provider's own privacy policy, and data may as a result pass through the data centre where that model runs, which may be located outside Singapore. We select providers only where their policies commit not to use the data to train their own models and to maintain a standard of protection no lower than the PDPA requires.
The service providers we use process and store data through their Singapore data centres, and we do not route data to overseas infrastructure by default. To the extent any incidental overseas transfer occurs as a function of how a service operates (for example, international card-network routing for payment processing), we take reasonable steps, including contractual safeguards, in accordance with section 26 of the PDPA to ensure that any overseas recipient provides a standard of protection comparable to that required under the PDPA.
One exception is Google Analytics, which processes data on Google's global infrastructure, which may be outside Singapore, under Google's data processing terms. That processing happens only after you consent to analytics cookies, and only for the product-level event data described in Section 9; an advisor's client data is never sent to it.
We retain account data and client data for as long as your account remains active. If you cancel your subscription, account data is retained for 30 days in case you reactivate, after which it is permanently deleted, except for records we are required to keep by law (such as billing and audit records). You may request deletion of your account and associated data at any time by contacting dpo@1965intelligence.sg; we will action verified requests within a reasonable period, subject to records we are required to retain by law.
In respect of your own account data, you have the right to:
To exercise any of these rights, contact our Data Protection Officer (Section 13). If you are an end client of one of our advisor customers and wish to exercise rights over your own personal data held on the Platform, please contact your advisor directly, as they are the controller of that data.
The Platform is intended for professional financial advisors and is not directed at, and does not knowingly register accounts for, individuals under 18 years of age.
We have appointed a Data Protection Officer, as required under the PDPA, responsible for overseeing our compliance with our data protection obligations. For any privacy-related question, complaint or request, contact: dpo@1965intelligence.sg.
We may update this policy from time to time. Material changes will be communicated by email or in-platform notice, with reasonable advance notice before they take effect.
For general questions about this policy, contact support@1965intelligence.sg; for data protection matters, contact dpo@1965intelligence.sg.