Back to Home

Privacy Policy

Our Commitment to Your Privacy

At Health Insurance Singapore, your privacy and data protection are our top priorities. This Privacy Policy explains how we collect, use, share, and protect your personal information in compliance with Singapore's Personal Data Protection Act (PDPA) and other applicable laws.

Last Updated: January 2025

This policy has been updated to reflect Singapore's latest data protection requirements and health insurance industry standards.

Information We Collect

When you use our health insurance comparison service, we may collect the following types of personal information:

Personal Details

  • Full name and contact information (email, phone, address)
  • NRIC/FIN number for identity verification
  • Date of birth and age
  • Citizenship status (Citizen, PR, Foreigner, Work Pass holder)
  • Employment details and income information

Health Insurance Information

  • Current health insurance coverage (MediShield Life, Integrated Shield Plans)
  • Medical history and pre-existing conditions
  • Smoking status and lifestyle factors
  • Hospital preferences (public vs private)
  • Coverage type preferences and budget requirements
  • Family members requiring coverage

Technical Information

  • IP address and device information
  • Browser type and settings
  • Website usage patterns and analytics data
  • Cookies and tracking technologies

How We Use Your Information

Primary Purposes (Consent Required)

  • Providing personalized health insurance quotes and comparisons
  • Connecting you with licensed Singapore insurance providers and agents
  • Facilitating communication between you and insurance providers
  • Processing your health insurance applications and claims
  • Providing customer support and assistance

Legal and Business Purposes

  • Compliance with PDPA and other Singapore regulations
  • Compliance with MAS (Monetary Authority of Singapore) requirements
  • Anti-money laundering and fraud prevention
  • Website analytics and service improvement
  • Legal proceedings and regulatory reporting
  • Business continuity and data backup

Who We Share Your Information With

We may share your personal information with the following parties, strictly for the purposes outlined above:

Licensed Insurance Entities

  • Insurance Companies: AIA Singapore, Prudential Singapore, Great Eastern, NTUC Income, Raffles Health Insurance, and other MAS-licensed insurers
  • Insurance Brokers and Agents: Licensed intermediaries registered with MAS
  • Reinsurers: For risk assessment and underwriting purposes

Service Providers

  • Technology Partners: Cloud hosting, data analytics, and CRM systems
  • Payment Processors: For premium payments and commission processing
  • Customer Support: Third-party support and communication platforms
  • Legal and Professional Services: Lawyers, auditors, and consultants

Regulatory and Legal Authorities

  • Personal Data Protection Commission (PDPC)
  • Monetary Authority of Singapore (MAS)
  • Singapore courts and law enforcement agencies
  • Other regulatory bodies as required by law

Important: All our partner insurance companies and brokers are licensed by MAS and comply with Singapore's strict financial services regulations. We never sell your data to unrelated third parties for marketing purposes.

Data Security and Protection

We implement comprehensive security measures to protect your personal information:

Technical Safeguards

  • 256-bit SSL encryption for data transmission
  • AES-256 encryption for data at rest
  • Regular security audits and penetration testing
  • Secure cloud infrastructure with redundancy

Administrative Controls

  • Role-based access controls
  • Regular staff training on data protection
  • Incident response and breach notification procedures
  • Data retention and disposal policies

Data Breach Notification

In the unlikely event of a data breach affecting your personal information, we will notify you and the PDPC within 72 hours as required by law, and provide clear information about the incident and steps to protect yourself.

Your Rights Under Singapore Law

Under the Personal Data Protection Act (PDPA), you have the following rights:

Access Rights

Request access to your personal data we hold and how it's being used

Correction Rights

Request correction of inaccurate or incomplete personal data

Withdrawal Rights

Withdraw consent for collection, use, or disclosure (with limitations)

Complaints Rights

File complaints with us or the PDPC about data protection issues

Important Limitations

  • Some data must be retained for regulatory compliance (e.g., insurance records for 5-7 years)
  • Withdrawal of consent may affect our ability to provide services
  • Legal or contractual obligations may prevent deletion of certain data
  • Anonymous or aggregated data is not subject to access requests

Cookies and Tracking

Our website uses cookies and similar tracking technologies to enhance your experience:

Cookie Type Purpose Consent Required
Essential Website functionality, security, forms No (necessary)
Analytics Google Analytics, user behavior analysis Yes (opt-in)
Marketing Targeted advertising, remarketing Yes (explicit consent)

You can manage cookie preferences through your browser settings or our cookie consent banner.

International Data Transfers

Your personal data may be transferred to and stored in jurisdictions outside Singapore for the following purposes:

  • Cloud Storage: AWS Singapore, Google Cloud Asia-Pacific, Microsoft Azure Southeast Asia
  • Analytics: Google Analytics (anonymized data only)
  • Customer Support: Regional support centers with appropriate safeguards

All international transfers comply with PDPA requirements and include appropriate contractual safeguards to protect your data.

Data Retention

We retain your personal data for the following periods:

Quote and Application Data

  • Active quotes: 90 days
  • Unsuccessful applications: 2 years
  • Active policies: Duration + 7 years

Other Information

  • Marketing communications: Until withdrawal
  • Website analytics: 26 months
  • Legal compliance: As required by law

Contact Us and Exercise Your Rights

To exercise any of your rights or for questions about this Privacy Policy, contact our Data Protection Officer:

Email

privacy@healthinsurance.com.sg

Response Time

Within 30 days as required by PDPA

Mailing Address

Health Insurance Singapore
Data Protection Officer
1 Raffles Place, #20-61
One Raffles Place
Singapore 048616

Filing a Complaint with PDPC

If you're not satisfied with our response, you can file a complaint with the Personal Data Protection Commission at www.pdpc.gov.sg

Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. Material changes will be notified to you via:

  • Email notification to your registered email address
  • Prominent notice on our website for 30 days
  • In-app notifications for mobile users

Last updated: January 1, 2025
Effective date: January 1, 2025
Next review date: January 1, 2026