logo


PRIVACY POLICY AND NOTICE

CTX Special Risks (Singapore) Pte. Ltd.

Effective Date: 1 September 2025

Updated: 28 July 2026

CTX Special Risks (Singapore) Pte. Ltd. (“CTX”, “we”, “us” or “our”) takes our responsibilities under the Personal Data Protection Act 2012 (“PDPA”) and applicable regulations and guidelines seriously.

This Privacy Policy and Notice (“Privacy Policy”) explains how CTX collects, uses, discloses, processes, protects and retains personal data in connection with our business and services.

This Privacy Policy applies to personal data relating to our clients, prospective clients, employees, prospective employees, business partners, representatives, insured persons, claimants and other individuals with whom we interact in the course of our business.


1. Personal Data

For the purposes of this Privacy Policy, “personal data” generally means data, whether true or not, about an individual who can be identified:

  • from that data; or
  • from that data together with other information to which CTX has or is likely to have access.

Depending on the nature of our relationship with you and the services involved, personal data may include:

  • name;
  • identification or passport number;
  • date of birth;
  • residential or business address;
  • email address;
  • telephone number;
  • banking and payment information;
  • employment and professional information;
  • signatures;
  • photographs;
  • insurance and policy information;
  • claims information;
  • financial information;
  • medical information where relevant to insurance or claims matters; and
  • other information which identifies or may reasonably be used to identify an individual.

The types of personal data collected will depend on the nature of the products, services or relationship involved.


2. Collection of Personal Data

We may collect personal data directly from you or from other sources where permitted by applicable law.

Depending on the circumstances, we may collect personal data when you:

  • enquire about or request our services;
  • request or obtain insurance quotations;
  • arrange or place insurance or reinsurance;
  • provide information for insurance underwriting or risk assessment;
  • enter into or administer an insurance policy;
  • make or assist with an insurance claim;
  • communicate with us;
  • provide services to us;
  • apply for employment or work with us;
  • interact with our websites, systems or platforms; or
  • otherwise deal with CTX in the course of business.

We may also receive personal data from third parties, including:

  • insurers;
  • reinsurers;
  • brokers and intermediaries;
  • underwriting agencies, MGAs and coverholders, where applicable;
  • employers or corporate clients;
  • insureds, policyholders and other representatives;
  • claims professionals;
  • loss adjusters and surveyors;
  • professional advisers;
  • service providers; and
  • other business partners or counterparties.

Where you provide personal data to CTX relating to another individual, you are responsible for ensuring, to the extent required by applicable law, that you are authorised to provide that personal data to CTX and that the relevant individual has been appropriately informed and/or has provided the necessary consent or other lawful authority for CTX to collect, use and disclose the personal data for the relevant purposes.


3. Purposes for Collection, Use and Disclosure

We may collect, use and disclose personal data for purposes that are reasonably appropriate in the circumstances and permitted under applicable law.

These purposes may include:

  • obtaining insurance quotations;
  • arranging and placing insurance;
  • arranging and placing reinsurance;
  • negotiating with insurers and reinsurers;
  • supporting underwriting and risk assessment;
  • administering insurance policies;
  • processing and managing insurance claims;
  • communicating with clients, insurers, reinsurers and business partners;
  • conducting customer due diligence;
  • conducting anti-money laundering and countering the financing of terrorism (“AML/CFT”) checks;
  • sanctions screening;
  • fraud prevention and detection;
  • complying with legal, regulatory and professional obligations;
  • responding to regulatory, governmental or law-enforcement requests;
  • accounting, invoicing and payment administration;
  • managing contractual and business relationships;
  • managing disputes, complaints and legal matters;
  • maintaining business, insurance and operational records;
  • managing information security and technology systems;
  • internal administration, audit, risk management and compliance;
  • recruitment, employment and personnel administration; and
  • other purposes notified to you or otherwise permitted under applicable law.

Where we intend to use personal data for a purpose that is materially different from the purpose for which it was originally collected, we will assess whether additional notification, consent or another applicable basis under the PDPA is required.


4. Consent and Other Applicable Bases

Where consent is required under the PDPA, CTX will obtain consent in accordance with applicable requirements.

Consent is not necessarily required in every circumstance. The PDPA permits personal data to be collected, used or disclosed in certain circumstances without consent or on other applicable bases permitted by law.

Where we rely on consent, you may withdraw your consent by giving us reasonable notice. We will inform you of the likely consequences of withdrawal and, subject to applicable law and any other lawful basis for processing, cease collecting, using or disclosing your personal data for the relevant purpose.

Withdrawal of consent will not affect the lawfulness of any collection, use or disclosure carried out before the withdrawal.

Where consent is provided by a person acting on behalf of another individual, CTX may rely on that person's authority to provide such consent to the extent permitted by applicable law.


5. Disclosure of Personal Data

Your personal data will generally be kept confidential. However, CTX may disclose personal data where reasonably necessary for the purposes described in this Privacy Policy and where permitted by applicable law.

Depending on the nature of our services, recipients may include:

  • insurers;
  • reinsurers;
  • underwriting agencies;
  • MGAs and coverholders, where applicable;
  • brokers and intermediaries;
  • claims administrators and claims professionals;
  • loss adjusters and surveyors;
  • lawyers and other professional advisers;
  • accountants and auditors;
  • banks and payment service providers;
  • regulatory authorities;
  • government authorities;
  • law-enforcement agencies;
  • technology and IT service providers;
  • cloud, hosting and data-storage providers;
  • outsourced service providers;
  • CTX's group companies, affiliates and personnel;
  • business partners and suppliers; and
  • other counterparties involved in the provision, placement, administration or servicing of insurance or reinsurance.

We will take reasonable steps to ensure that disclosures are limited to personal data reasonably necessary for the relevant purpose.


6. Personal Data of Third Parties

If you provide CTX with personal data relating to another individual, you represent and warrant, to the extent permitted by applicable law, that you are authorised to provide that personal data to CTX.

You are also responsible for ensuring, where required by applicable law, that the relevant individual has been appropriately informed of, and/or has provided the necessary consent or other lawful authority for, the collection, use and disclosure of their personal data for the relevant purposes.

This may include personal data relating to employees, directors, shareholders, family members, representatives, customers, insured persons, claimants or other individuals.

If you provide personal data to CTX on behalf of an organisation or another individual, you agree to assist CTX, where reasonably required, in complying with its obligations under the PDPA in relation to that personal data.

Without limiting the above, where you provide personal data to CTX which CTX may use or disclose to insurers, reinsurers, business partners, service providers or other counterparties, you are responsible, to the extent required by applicable law, for ensuring that:

a) you have the necessary authority to provide the personal data to CTX;

b) the relevant individuals have been informed of the purposes for which their personal data may be collected, used or disclosed;

c) the necessary consent or other lawful basis for the collection, use and disclosure of the personal data has been obtained or established;

d) the personal data has been collected, used and disclosed consistently with the purposes notified to the relevant individuals and applicable law;

e) the personal data provided to CTX is accurate and complete to the best of your knowledge;

f) you notify CTX as soon as reasonably practicable if you become aware of any material error, omission, update or change affecting the personal data provided;

g) you notify CTX as soon as reasonably practicable if a relevant individual withdraws consent or otherwise changes the authority previously provided, where such information is relevant to CTX's processing of the personal data;

h) you reasonably assist CTX with any access, correction, withdrawal, complaint or other data protection request relating to personal data supplied by you; and

i) you otherwise reasonably assist CTX in complying with applicable requirements under the PDPA.

Nothing in this section limits or excludes any obligation imposed directly on CTX under applicable law.


7. Transfer of Personal Data Outside Singapore

In providing our services, personal data may be transferred to, stored in, processed in or accessed by recipients located outside Singapore.

Such recipients may include CTX group companies or personnel, insurers, reinsurers, brokers, business partners, professional advisers, technology providers and other service providers located in other jurisdictions.

Where personal data is transferred outside Singapore, CTX will comply with the applicable requirements of the PDPA and take appropriate steps to ensure that the transferred personal data receives a standard of protection comparable to that required under the PDPA.

Depending on the circumstances, safeguards may include contractual obligations, data processing arrangements, confidentiality obligations and assessment of the recipient's data protection and security controls.

Where you provide CTX with personal data of another individual for transfer outside Singapore, you are responsible, to the extent required by applicable law, for ensuring that the relevant individual has been appropriately informed of the relevant overseas transfer and that any required consent or other lawful basis has been obtained or established.


8. Protection of Personal Data

We take reasonable steps to protect personal data in our possession or under our control against unauthorised access, collection, use, disclosure, copying, modification, disposal or similar risks.

Depending on the nature of the information and the circumstances, security measures may include:

  • access controls;
  • authentication controls;
  • multi-factor authentication where appropriate;
  • encryption;
  • secure storage;
  • network and endpoint security;
  • anti-malware protection;
  • physical security controls;
  • secure disposal procedures; and
  • staff privacy and cybersecurity training.

No method of electronic transmission or storage can be guaranteed to be completely secure. CTX will nevertheless maintain appropriate safeguards having regard to the nature of the personal data and the risks involved.


9. Accuracy of Personal Data

We take reasonable steps to ensure that personal data in our possession or under our control is accurate and complete where:

  • the personal data is likely to be used by us to make a decision that affects you; or
  • the personal data is likely to be disclosed to another organisation.

You should notify us if there are material changes to your personal data or if you become aware that information held by us is inaccurate or incomplete.

Where you provide personal data to us on behalf of another individual, you are responsible for notifying CTX of any material changes or inaccuracies in that personal data as soon as reasonably practicable after becoming aware of them.


10. Retention of Personal Data

We will retain personal data only for as long as it is reasonably necessary for:

  • the purposes for which it was collected;
  • legitimate business purposes;
  • legal or regulatory requirements;
  • accounting, audit or reporting requirements; or
  • the establishment, exercise or defence of legal claims.

When personal data is no longer required for any business or legal purpose, we will take reasonable steps to dispose of, delete or anonymise it appropriately.


11. Access to and Correction of Personal Data

Subject to the exceptions and requirements under the PDPA, you may request:

  • access to personal data about you that is in our possession or under our control; and
  • information about how your personal data may have been used or disclosed during the preceding 12 months.

You may also request that CTX correct an error or omission in personal data about you that is in our possession or under our control.

We may require sufficient information to verify your identity and the nature of your request before processing an access or correction request.

Where appropriate, we may require supporting documentation to verify a requested correction or update.

Certain exceptions and restrictions under the PDPA may apply to access and correction requests.

An administrative fee may be charged where permitted under applicable law. Where a fee applies, we will inform you before processing the request.


12. Data Breach Management

We maintain procedures for identifying, assessing, containing and responding to personal data breaches.

If a personal data breach occurs, CTX will assess the breach to determine whether notification is required under the PDPA.

Where notification is required, CTX will notify the Personal Data Protection Commission and/or affected individuals in accordance with applicable legal requirements and timeframes.

Where a personal data breach relates to personal data provided to CTX by another organisation or individual, CTX may require that organisation or individual to provide reasonable assistance and information necessary for CTX to assess and respond to the breach.


13. Employees and Job Applicants

Where you apply for employment with CTX or are employed or engaged by CTX, we may collect and use personal data for purposes including:

  • recruitment and selection;
  • employment administration;
  • payroll and benefits administration;
  • performance management;
  • training and development;
  • workplace administration;
  • compliance with employment, tax and regulatory requirements;
  • business continuity and security; and
  • other purposes reasonably necessary for managing the employment or engagement relationship.

Additional privacy notices or internal policies may apply to employees and job applicants where appropriate.


14. Complaints and Enquiries

If you have any questions, concerns or complaints regarding the collection, use, disclosure or protection of your personal data by CTX, you may contact our Data Protection Officer using the contact details below.

We will review and address your enquiry or complaint in accordance with our internal procedures and applicable requirements.


15. Data Protection Officer

CTX has appointed a Data Protection Officer (“DPO”) to oversee its personal data protection policies and practices.

The DPO may be contacted at:

Data Protection Officer
CTX Special Risks (Singapore) Pte. Ltd.
8 Marina View, #15-07
Asia Square Tower 1
Singapore 018960


16. Changes to this Privacy Policy

We may amend this Privacy Policy from time to time to reflect changes in our business, services, technology, legal requirements or regulatory guidance.

The updated Privacy Policy will be made available through the appropriate CTX communication channels and/or website.

The effective date and version of the current Privacy Policy will be stated at the beginning of the document.