Data Protection

Privacy Policy

How CertiTrust collects, uses, stores and protects the personal data you provide.

Last updated: 13 August 2026

01 · What we collect

Information we collect

For accreditation applications: company name, UEN, GST registration status, HDB licence details, business ratings, years in operation, contact details and supporting documents such as ACRA bizfiles, licence copies and financial statements.

For homeowner claims: name and contact details, the interior design firm involved, contract date, payment records and court order references, together with any documents you upload in support.

02 · How we use it

How we use your information

Personal data is used solely to assess accreditation applications, maintain the public register, assess claims against the banker's guarantee, and communicate with you about those matters.

The public register displays only business information — firm name, accreditation reference, specialisations and region. Homeowner claim details are never published.

03 · Disclosure

When we share information

We may share information with independent assessors, the issuing bank in relation to a guarantee, and professional advisers, in each case only to the extent needed for the purpose.

We do not sell personal data. We disclose data to authorities only where required by law.

04 · Retention & security

Retention and security

Application and claim records are retained for the duration of accreditation and for a further seven years, consistent with our regulatory and audit obligations.

Documents are stored with access restricted to authorised CertiTrust personnel handling your matter.

05 · Your rights

Access, correction and withdrawal

Under Singapore's Personal Data Protection Act you may request access to, or correction of, the personal data we hold about you, and may withdraw consent to further use, subject to legal and contractual limits.

To make a request, contact our Data Protection Officer at dpo@certitrust.sg.