Privacy Policy
Sidian Pte. Ltd. · Last updated 28 June 2026 · UEN 202617513C
This Privacy Policy describes how Sidian Pte. Ltd. collects, uses, discloses, and protects personal data in compliance with the Singapore Personal Data Protection Act 2012 (PDPA), as amended by the Personal Data Protection (Amendment) Act 2020. Sidian provides compliance infrastructure to businesses and institutions. If you are a representative of an institution or organisation engaging with Sidian, this policy applies to the personal data you and your colleagues provide to us.
1. Who We Are
Sidian Pte. Ltd. (UEN: 202617513C) is incorporated in Singapore. We build and operate Guardian SGSV compliance infrastructure products including The Guardian SDK, the Compliance API — RegOS, The Navigator, and Sidian Sentry. Registered address: 105 Cecil Street #18-02 The Octagon, Singapore 069534. Data protection contact: info@sidian.sg. Our services are directed at businesses and institutions, not at consumers or individuals acting in a personal capacity.
2. Personal Data We Collect
We collect personal data in the following categories: (a) Contact and identity data — name, work email address, telephone, job title, and employer/institution name when you submit an enquiry, register for a waitlist, or engage in a commercial relationship with us; (b) Account data — for Navigator users, bank account names (not account numbers), balance ranges, and yield movement records necessary to provide the service; (c) Usage and technical data — IP address, browser type, referring URL, pages visited, and session duration collected via server logs; (d) Communications — email correspondence, form submissions, and any other direct communications with Sidian; (e) Transaction compliance records — Guardian SGSV compliance decisions generated by our audit log infrastructure, which may include transaction metadata but do not include payment card data, full account numbers, or complete counterparty identity data.
3. Purposes for Which We Use Personal Data
We use personal data only for purposes that a reasonable person would consider appropriate in the circumstances: (a) Delivering and administering our products and services under contract; (b) Responding to enquiries and providing technical and commercial support; (c) Onboarding institutional and FinTech customers, including identity verification required by applicable law; (d) Complying with legal and regulatory obligations under Singapore law, including MAS AML/CFT Notice requirements, MAS Technology Risk Management Guidelines, and obligations under the PDPA; (e) Improving our products through aggregated, de-identified usage analytics — individual users cannot be identified from this data; (f) Sending product and regulatory updates where you have consented or where we have an existing business relationship and a legitimate basis to do so.
4. Consent and Legal Permissions Under the PDPA
Under the PDPA, we collect and use personal data: (a) with your consent, which may be express (e.g. submitting a form) or deemed where the purpose is obvious in the circumstances; (b) as necessary to perform a contract to which you are party or to take steps at your request before entering a contract; (c) as required or authorised by Singapore law, including compliance with MAS regulatory requirements; (d) where we have an identifiable legitimate business reason that does not unreasonably interfere with your interests. You may withdraw consent at any time by contacting info@sidian.sg. We will inform you of the consequences of withdrawal before processing the request.
5. Disclosure of Personal Data
We do not sell, rent, or trade personal data. We disclose personal data only: (a) to service providers who process data on our behalf under written data processing agreements with equivalent data protection obligations (including Amazon Web Services, Singapore region); (b) to MAS, PDPC, or other regulatory or law enforcement authorities where required by Singapore law or a valid court order; (c) to our professional advisors (lawyers, accountants, auditors) under confidentiality obligations; (d) to a successor entity in a corporate restructuring, merger, or acquisition, subject to equivalent PDPA-compliant protections; (e) with your explicit prior consent for any purpose not covered above.
6. Cross-Border Data Transfers
Sidian's primary infrastructure is hosted in AWS ap-southeast-1 (Singapore). Where personal data is transferred outside Singapore, we comply with Part VIA of the PDPA (Transfer Limitation Obligation). We ensure overseas recipients are bound to protect the data to a standard comparable to the PDPA — through contractual clauses, approved binding corporate rules, or by transferring to jurisdictions with adequate legal protection. We do not transfer financial transaction data outside Singapore without institutional customer consent.
7. Data Retention
We retain personal data only as long as necessary for the purpose collected and to meet legal obligations: (a) Guardian SGSV audit records and transaction compliance records: 7 years minimum (MAS AML/CFT Notice requirements); (b) Customer contracts, MSAs, and billing records: 7 years from contract expiry (accounting obligations); (c) Waitlist and marketing correspondence: until withdrawal of consent or 2 years after last engagement; (d) Website usage logs: 12 months; (e) Enquiry and support correspondence: 3 years from most recent communication. Data is securely deleted or irreversibly anonymised at the end of each retention period.
8. Your Rights Under the PDPA
The PDPA gives you the following rights in respect of your personal data: (a) Access right (Section 21 PDPA) — you may request confirmation that we hold personal data about you, and a copy of that data; (b) Correction right (Section 22 PDPA) — you may request correction of personal data that is inaccurate, incomplete, or misleading; (c) Withdrawal of consent — you may withdraw consent to any non-mandatory processing at any time, subject to legal or contractual restrictions. Submit requests to info@sidian.sg with subject line 'PDPA Rights Request'. We will acknowledge your request within 2 business days and respond substantively within 30 calendar days. We may charge a reasonable fee for access requests where permitted by law.
9. Mandatory Data Breach Notification
Under the PDPA (as amended in 2021), Sidian is required to notify the Personal Data Protection Commission (PDPC) within 3 business days of becoming aware of a data breach that is likely to cause significant harm to affected individuals, or that affects 500 or more individuals. Where a breach is likely to cause significant harm to specific individuals, we will also notify those individuals as soon as practicable. We maintain an incident response programme tested regularly, and will communicate breach notices via the contact details you have provided.
10. Cookies and Tracking
We use only session-essential cookies required for site security and navigation — no advertising cookies, no cross-site tracking cookies, and no third-party analytics that identify individuals. If we introduce analytics in future, this policy will be updated and you will be notified. You may manage cookie preferences through your browser settings; disabling essential cookies may affect site functionality.
11. Data Security
We implement security appropriate to the sensitivity of the data and our role as a compliance infrastructure provider: TLS 1.3 encryption in transit; AES-256 encryption at rest; least-privilege access controls with mandatory MFA for all operator access; immutable append-only audit logs; network segmentation and VPC isolation; regular third-party penetration testing. Our full security posture is published at sidian.sg/legal (Security tab). Notwithstanding these controls, no system is completely secure. If you believe your data has been compromised, contact info@sidian.sg immediately.
12. Children's Data
Our services are directed at businesses, institutions, and individuals acting in a professional or commercial capacity. We do not knowingly collect personal data from persons under 18 years of age. If we become aware that personal data of a person under 18 has been submitted, we will delete it promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email to active account holders and by notice on sidian.sg at least 14 days before taking effect. The date at the top of this policy reflects the date of the most recent revision.
14. Contact and Complaints
Privacy enquiries and access/correction requests: info@sidian.sg · Sidian Pte. Ltd. · 105 Cecil Street #18-02 The Octagon · Singapore 069534. If you are not satisfied with our handling of your personal data, you may lodge a complaint with the Personal Data Protection Commission of Singapore at pdpc.gov.sg or +65 6377 3131.
Questions? Contact info@sidian.sg · Sidian Pte. Ltd. · 105 Cecil Street #18-02 The Octagon · Singapore 069534