Privacy Policy
Our Commitment to Your Privacy
At Health Insurance Singapore, your privacy and data protection are our top priorities. This Privacy Policy explains how we collect, use, share, and protect your personal information in compliance with Singapore's Personal Data Protection Act (PDPA) and other applicable laws.
This policy has been updated to reflect Singapore's latest data protection requirements and health insurance industry standards.
Information We Collect
When you use our health insurance comparison service, we may collect the following types of personal information:
Personal Details
- Full name and contact information (email, phone, address)
- NRIC/FIN number for identity verification
- Date of birth and age
- Citizenship status (Citizen, PR, Foreigner, Work Pass holder)
- Employment details and income information
Health Insurance Information
- Current health insurance coverage (MediShield Life, Integrated Shield Plans)
- Medical history and pre-existing conditions
- Smoking status and lifestyle factors
- Hospital preferences (public vs private)
- Coverage type preferences and budget requirements
- Family members requiring coverage
Technical Information
- IP address and device information
- Browser type and settings
- Website usage patterns and analytics data
- Cookies and tracking technologies
How We Use Your Information
Primary Purposes (Consent Required)
- Providing personalized health insurance quotes and comparisons
- Connecting you with licensed Singapore insurance providers and agents
- Facilitating communication between you and insurance providers
- Processing your health insurance applications and claims
- Providing customer support and assistance
Legal and Business Purposes
- Compliance with PDPA and other Singapore regulations
- Compliance with MAS (Monetary Authority of Singapore) requirements
- Anti-money laundering and fraud prevention
- Website analytics and service improvement
- Legal proceedings and regulatory reporting
- Business continuity and data backup
Who We Share Your Information With
We may share your personal information with the following parties, strictly for the purposes outlined above:
Licensed Insurance Entities
- Insurance Companies: AIA Singapore, Prudential Singapore, Great Eastern, NTUC Income, Raffles Health Insurance, and other MAS-licensed insurers
- Insurance Brokers and Agents: Licensed intermediaries registered with MAS
- Reinsurers: For risk assessment and underwriting purposes
Service Providers
- Technology Partners: Cloud hosting, data analytics, and CRM systems
- Payment Processors: For premium payments and commission processing
- Customer Support: Third-party support and communication platforms
- Legal and Professional Services: Lawyers, auditors, and consultants
Regulatory and Legal Authorities
- Personal Data Protection Commission (PDPC)
- Monetary Authority of Singapore (MAS)
- Singapore courts and law enforcement agencies
- Other regulatory bodies as required by law
Important: All our partner insurance companies and brokers are licensed by MAS and comply with Singapore's strict financial services regulations. We never sell your data to unrelated third parties for marketing purposes.
Data Security and Protection
We implement comprehensive security measures to protect your personal information:
Technical Safeguards
- 256-bit SSL encryption for data transmission
- AES-256 encryption for data at rest
- Regular security audits and penetration testing
- Secure cloud infrastructure with redundancy
Administrative Controls
- Role-based access controls
- Regular staff training on data protection
- Incident response and breach notification procedures
- Data retention and disposal policies
Data Breach Notification
In the unlikely event of a data breach affecting your personal information, we will notify you and the PDPC within 72 hours as required by law, and provide clear information about the incident and steps to protect yourself.
Your Rights Under Singapore Law
Under the Personal Data Protection Act (PDPA), you have the following rights:
Access Rights
Request access to your personal data we hold and how it's being used
Correction Rights
Request correction of inaccurate or incomplete personal data
Withdrawal Rights
Withdraw consent for collection, use, or disclosure (with limitations)
Complaints Rights
File complaints with us or the PDPC about data protection issues
Important Limitations
- Some data must be retained for regulatory compliance (e.g., insurance records for 5-7 years)
- Withdrawal of consent may affect our ability to provide services
- Legal or contractual obligations may prevent deletion of certain data
- Anonymous or aggregated data is not subject to access requests
Cookies and Tracking
Our website uses cookies and similar tracking technologies to enhance your experience:
| Cookie Type | Purpose | Consent Required |
|---|---|---|
| Essential | Website functionality, security, forms | No (necessary) |
| Analytics | Google Analytics, user behavior analysis | Yes (opt-in) |
| Marketing | Targeted advertising, remarketing | Yes (explicit consent) |
You can manage cookie preferences through your browser settings or our cookie consent banner.
International Data Transfers
Your personal data may be transferred to and stored in jurisdictions outside Singapore for the following purposes:
- Cloud Storage: AWS Singapore, Google Cloud Asia-Pacific, Microsoft Azure Southeast Asia
- Analytics: Google Analytics (anonymized data only)
- Customer Support: Regional support centers with appropriate safeguards
All international transfers comply with PDPA requirements and include appropriate contractual safeguards to protect your data.
Data Retention
We retain your personal data for the following periods:
Quote and Application Data
- Active quotes: 90 days
- Unsuccessful applications: 2 years
- Active policies: Duration + 7 years
Other Information
- Marketing communications: Until withdrawal
- Website analytics: 26 months
- Legal compliance: As required by law
Contact Us and Exercise Your Rights
To exercise any of your rights or for questions about this Privacy Policy, contact our Data Protection Officer:
privacy@healthinsurance.com.sg
Response Time
Within 30 days as required by PDPA
Mailing Address
Health Insurance Singapore
Data Protection Officer
1 Raffles Place, #20-61
One Raffles Place
Singapore 048616
Filing a Complaint with PDPC
If you're not satisfied with our response, you can file a complaint with the Personal Data Protection Commission at www.pdpc.gov.sg
Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. Material changes will be notified to you via:
- Email notification to your registered email address
- Prominent notice on our website for 30 days
- In-app notifications for mobile users
Last updated: January 1, 2025
Effective date: January 1, 2025
Next review date: January 1, 2026