Privacy Policy
Introduction
onyxpathas is committed to protecting the privacy and personal data of our clients in accordance with Singapore's Personal Data Protection Act 2012 (PDPA). This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you engage our luxury car rental coordination services.
This policy applies to all interactions with onyxpathas, including service bookings, website usage, email correspondence, and telephone communications with our coordination desk.
Information We Collect
Personal Identification Information
We collect the following personal data to facilitate service coordination:
- Full name as provided during booking
- Contact telephone numbers for coordination purposes
- Email addresses for correspondence and documentation
- Travel itinerary details including flight information for airport services
- Hotel accommodation information for transfer coordination
- Special requirements or preferences for service delivery
Service Engagement Information
To provide appropriate service tiers, we maintain records of:
- Service tier selections (Lobby, Gallery, or Penthouse Level)
- Vehicle preferences and specifications requested
- Dates, times, and locations of service engagements
- Route information and destination addresses
- Cultural venue or museum access coordination details
- In-car provision preferences for recurring engagements
Payment Information
For billing purposes, we collect:
- Credit card details processed through secure payment gateways
- Bank transfer information for corporate billing arrangements
- Billing addresses for invoice generation
- Corporate account information for approved business clients
Website Usage Data
Our website collects:
- Browser type and version for compatibility
- IP addresses for security and analytics
- Pages visited and time spent on site
- Referring website information
- Device information for mobile optimization
How We Use Your Information
Service Delivery
Your personal data enables us to:
- Coordinate vehicle deployments at specified locations and times
- Synchronize airport arrivals with flight schedules
- Arrange hotel coordination for seamless transfers
- Pre-organize museum access and cultural venue coordination
- Prepare welcome folders and vehicle dossiers
- Maintain service quality standards appropriate to tier selection
Communication
We use your contact information to:
- Confirm booking arrangements and service details
- Provide real-time coordination updates during engagements
- Send service completion confirmations and documentation
- Address service inquiries and coordination adjustments
- Communicate through secure channels for Penthouse Level services
Billing and Payments
Financial information is processed to:
- Generate invoices and process payments
- Maintain corporate billing account records
- Provide payment confirmation documentation
- Address billing inquiries and payment arrangements
Service Improvement
Aggregated and anonymized data helps us:
- Analyze service quality and coordination efficiency
- Identify patterns for improved route planning
- Enhance cultural venue partnership arrangements
- Refine hospitality protocols and driver training
Data Sharing and Disclosure
We maintain strict controls on personal data sharing. Information may be disclosed only in these circumstances:
Service Partners
Limited information is shared with:
- Hotel properties for arrival coordination and check-in preparation
- Museum and gallery partners for priority access arrangements
- Payment processors for secure transaction handling
- Background verification services for Penthouse Level driver assignments
All service partners are contractually bound to maintain confidentiality and data protection standards.
Legal Requirements
We may disclose information when required by:
- Singapore law enforcement agencies under lawful request
- Court orders or legal proceedings
- Regulatory authorities for compliance verification
- Government agencies for statutory reporting obligations
Business Transfers
In the event of business sale, merger, or reorganization, personal data may be transferred to successor entities, with advance notification to affected clients.
Data Security Measures
onyxpathas implements comprehensive security protocols:
Technical Safeguards
- Encryption of sensitive data during transmission and storage
- Secure server infrastructure with regular security audits
- Multi-factor authentication for coordination desk access
- Regular system backups with encrypted storage
- Firewall protection and intrusion detection systems
Operational Safeguards
- Access controls limiting staff data viewing to necessary personnel
- Confidentiality agreements for all employees and contractors
- Secure communication channels for Penthouse Level coordination
- Physical security measures at coordination office locations
- Regular staff training on data protection protocols
Penthouse Level Additional Security
For clients engaging Penthouse Level services:
- Booking records maintained outside standard database systems
- Single-point access through dedicated contact managers
- Encrypted communication channels for all correspondence
- Enhanced background verification for assigned drivers
- No public record maintenance per service specifications
Data Retention
We retain personal information according to these timeframes:
Active Client Records
For clients with ongoing or recent engagements:
- Booking and service details: 24 months from last engagement
- Contact information: Maintained until client requests removal
- Payment history: 7 years per Singapore tax requirements
- Preference data: Until updated or deletion requested
Penthouse Level Records
For privacy-sensitive engagements:
- Service records maintained separately from standard systems
- Minimal booking documentation retained
- Secure deletion protocols applied after retention period
- No cross-referencing with other database systems
Inactive Accounts
Client data with no engagement activity for 36 months undergoes review for retention necessity. Unnecessary information is securely deleted unless regulatory requirements mandate retention.
Your Rights Under Singapore PDPA
As a client of onyxpathas, you have the following rights regarding your personal data:
Access Rights
- Request copies of personal data we hold about you
- Inquire about how your data is being used
- Obtain information about third parties receiving your data
- Receive data in structured, commonly used format
Correction Rights
- Request correction of inaccurate personal information
- Update outdated contact details or preferences
- Amend service history records containing errors
Withdrawal of Consent
- Withdraw consent for marketing communications
- Opt out of optional data collection processes
- Request limitation of data processing to essential services only
Note: Some data processing is necessary for service delivery. Withdrawal may affect our ability to provide certain services.
Deletion Rights
- Request deletion of personal data no longer needed
- Require erasure when consent is withdrawn
- Exercise right to be forgotten where legally applicable
Deletion requests are subject to legal retention requirements for financial records and regulatory compliance.
Complaint Rights
If you believe your data protection rights have been violated, you may lodge a complaint with Singapore's Personal Data Protection Commission (PDPC).
Cookies and Website Tracking
Our website uses cookies and similar technologies. For detailed information about cookie usage, types, and management options, please refer to our Cookie Policy.
Essential cookies required for basic website functionality are always active. Optional cookies for analytics and improvements require your consent.
Children's Privacy
onyxpathas services are designed for individuals aged 18 and above. We do not knowingly collect personal information from minors. If we become aware that personal data from individuals under 18 has been collected, we will take immediate steps to delete such information.
International Data Transfers
Your personal data is primarily stored and processed in Singapore. In certain circumstances, data may be transferred internationally:
- Cloud service providers with data centers outside Singapore
- Payment processors operating across multiple jurisdictions
- Hotel chains with centralized reservation systems
All international transfers comply with PDPA requirements, including adequate protection measures and contractual safeguards equivalent to Singapore standards.
Policy Updates
This Privacy Policy may be updated periodically to reflect:
- Changes in Singapore data protection regulations
- New service offerings requiring different data handling
- Improvements to security measures and protocols
- Feedback from privacy audits and assessments
Significant policy changes will be communicated via:
- Email notification to registered clients
- Prominent website notice for 30 days
- Coordination desk briefings for active engagements
Continued use of our services after policy updates constitutes acceptance of revised terms.
Contact Information
For questions, concerns, or requests regarding this Privacy Policy or your personal data:
Data Protection Officer
We will respond to privacy-related inquiries within 30 days of receipt. For urgent matters requiring immediate attention, please contact our coordination desk directly.
For complaints to Singapore's regulatory authority:
Personal Data Protection Commission
10 Pasir Panjang Road, #03-01 Mapletree Business City
Singapore 117438