Privacy Policy
Personal Data Protection Policy
AgilenLite Pte Ltd (“AgilenLite”, “AnL”, “we”, “us”, “our”) - Privacy Policy for our website, training programmes and corporate services
Last Updated: Sept 9, 2026 (Supersedes version dated 23 October 2019)
1. Introduction
AgilenLite respects the privacy of individuals and recognises the importance of the personal data entrusted to us. We are committed to managing, protecting, using and disclosing personal data responsibly and in accordance with the Personal Data Protection Act 2012 (No. 26 of 2012), as amended (“PDPA” or the “Act”).
This Policy explains how AgilenLite collects, uses, discloses and protects personal data in connection with our training programmes, corporate learning and consulting services, events and seminars, and our website. It applies to:
- Participants and learners registered for courses, workshops or funded training programmes (including programmes co-funded by SkillsFuture Singapore (“SSG”) or the Institute of Banking and Finance (“IBF”));
- Representatives and contacts of our corporate clients and partners;
- Visitors to our website, including individuals who submit a Contact Us or enquiry form; and
- Attendees of our events, seminars and webinars.
This Policy does not cover the personal data of our employees, which is governed separately under our internal human resource and information security policies.
2. What Is “Personal Data”
Under the PDPA, “personal data” means data, whether true or not, about an individual who can be identified (a) from that data; or (b) from that data together with other information to which the organisation has or is likely to have access. This includes identifiers such as name, NRIC/FIN number, contact details and, in some cases, photographs, audio or video recordings.
3. Our Data Protection Obligations
We are mindful of, and structure our practices around, the obligations set out in the PDPA, namely:
- Consent Obligation - collecting, using or disclosing personal data only with knowledge and consent, subject to permitted exceptions;
- Purpose Limitation Obligation - using personal data only for purposes a reasonable person would consider appropriate;
- Notification Obligation - informing individuals of the purposes of collection, use or disclosure before or at the point of collection;
- Access and Correction Obligations - allowing individuals to request access to, or correction of, their personal data;
- Accuracy Obligation - making reasonable efforts to ensure personal data is accurate and complete;
- Protection Obligation - making reasonable security arrangements to protect personal data in our possession or control;
- Retention Limitation Obligation - ceasing to retain personal data, or removing means of association with individuals, once it is no longer needed;
- Transfer Limitation Obligation - ensuring comparable protection when personal data is transferred outside Singapore;
- Data Breach Notification Obligation - notifying the Personal Data Protection Commission (“PDPC”) and affected individuals of notifiable data breaches;
- Accountability Obligation - implementing policies and practices to meet our PDPA obligations and making information about them available on request.
A summary of these obligations is available in the PDPC's Advisory Guidelines and the PDPA itself, accessible at sso.agc.gov.sg.
4. Personal Data We Collect
4.1 Information You Provide to Us
- Registration/enrolment for training programmes: name (as per government-issued identification), NRIC or FIN number, nationality, date of birth, email address, contact number, employer, department/division and grade;
- Contact Us and enquiry forms on our website: name, company, email address, phone number and the content of your enquiry;
- Event and seminar sign-ups: name, contact details and organisation; and
- Any other information you choose to provide when corresponding with us by phone, email or in person, including recorded calls made for quality control and governance purposes.
4.2 Information We Collect Automatically
- Technical information such as IP address, browser type and version, device and operating system, and time zone setting; and
- Usage information such as pages visited, links clicked, time spent on pages and referring/exit pages, collected via cookies and similar technologies (see Section 8).
NRIC/FIN NOTICE. Full NRIC/FIN numbers are collected only where required for a specific, legally justified purpose — principally the submission of funding claims to SSG/IBF via the Training Partner Gateway. AgilenLite does not, and will not, use NRIC/FIN numbers (in whole or in part) as a password, login credential or other means of authentication, in line with the PDPC and Cyber Security Agency's advisory and the phase-out deadline of 31 December 2026.
5. How We Use Your Personal Data
- To process registrations, administer training programmes and manage attendance and certification;
- To prepare and submit funding claims and related documentation to SSG, IBF or other funding/accreditation bodies via their designated secure platforms;
- To respond to enquiries submitted through our website or other channels;
- To send updates on courses, events, seminars and related activities you have consented to receive;
- To maintain, evaluate and improve our website and services, including through analytics; and
- To comply with our legal, regulatory and contractual obligations.
Where required by the PDPA, we will notify you of the purpose(s) for collection, use or disclosure and obtain your consent beforehand. Consent for programme administration and regulatory/funding submission is separate from, and not conditional upon, consent for marketing updates - you may decline the latter without affecting your registration.
6. How We Disclose and Share Your Personal Data
We do not sell your personal data. We may disclose personal data, on a need-to-know basis and subject to appropriate safeguards, to:
- SSG, IBF and other funding, accreditation or regulatory bodies, submitted via their designated secure platforms (e.g. the Training Partner Gateway);
- Engaged service providers who support our operations, such as cloud hosting and IT service providers, who are contractually bound to protect personal data and use it only for the purposes we specify;
- Professional advisers, auditors and regulators, where necessary for compliance or governance purposes; and
- Law enforcement or other authorities, where disclosure is required or permitted by law, including in an emergency.
Beyond the above, we will not disclose your personal data to third parties without your consent, except where permitted or required under the PDPA's statutory exceptions.
7. Use of Personal Data with Artificial Intelligence
AgilenLite may use artificial intelligence tools, including generative AI (“GenAI”), to support internal productivity and business operations.
- Staff are required, under our internal AI usage guidelines, not to input participant, client or other personal data into public or unapproved GenAI tools;
- We do not use participant or client personal data to train or fine-tune third-party or public AI/GenAI models;
- Should this practice change, we will provide a specific AI-related notification describing the purpose, the data involved, and how you may decline or withdraw consent, before any such use begins; and
- Our practices are guided by the PDPC/IMDA Guidelines on the Responsible Use of Personal Data in Generative AI (issued 20 July 2026).
8. Cookies
A cookie is a small piece of text stored on your device by your web browser. We use the following categories of cookies on our website:
- Strictly necessary cookies - required for core site functions such as navigation;
- Functional/preference cookies - remember your settings and preferences;
- Performance/analytics cookies - help us understand how visitors use our site so we can improve it; and
- Third-party cookies - served where we embed social media content (e.g. LinkedIn, YouTube, X/Twitter).
You may remove or block cookies through your browser settings; doing so may limit some site functionality. Where required, we will obtain your consent to non-essential cookies via a cookie banner or similar mechanism on first visit.
9. Marketing Communications and the Do Not Call Registry
We only send you invitations, updates or promotional material about our courses, events and seminars where you have given consent, and you may withdraw this consent (unsubscribe) at any time using the link provided or by contacting us.
- Before making telemarketing calls or sending marketing SMS/fax messages to a Singapore telephone number, we check the number against the national Do Not Call (DNC) Registry, or obtain your clear and unambiguous consent, in accordance with Parts 9 and 9A of the PDPA; and
- Registering your number with the DNC Registry does not affect messages relating to a course or programme you are already enrolled in, or other communications that are not “marketing messages” under the Act.
10. Data Security, Retention and Overseas Storage
- We apply reasonable security arrangements, including password-protected files, restricted access on a need-to-know basis, encrypted transmission for sensitive data, and secure cloud storage, to prevent unauthorised access, use, disclosure, copying, modification or loss of personal data;
- We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required for legal, regulatory or audit purposes, after which it is securely disposed of or anonymised; and
- Where personal data is stored or processed by service providers outside Singapore (for example, cloud infrastructure providers), we take contractual and other reasonable steps to ensure a standard of protection comparable to that under the PDPA.
11. Data Breach Notification
OUR COMMITMENT. If we assess that a data breach is likely to result in significant harm to affected individuals, or affects 500 or more individuals, we will notify the PDPC as soon as practicable and in any event no later than three (3) calendar days after completing our assessment, and will notify affected individuals where required by the PDPA.
12. Your Rights - Access, Correction and Withdrawal of Consent
Subject to exceptions under the PDPA, you may at any time:
- Request access to the personal data we hold about you;
- Request correction of inaccurate or incomplete personal data; or
- Withdraw your consent to our collection, use or disclosure of your personal data.
We will process access and correction requests as soon as reasonably practicable, and may charge a reasonable fee to cover the cost of responding to an access request (you will be informed of any fee beforehand). Where we correct personal data, we will send the corrected data to other organisations to which it was disclosed within the past year, unless they no longer need it for legal or business purposes.
If you withdraw consent, we will inform you of the likely consequences (for example, we may no longer be able to process your registration or funding claim) before acting on your request, and will give reasonable notice if withdrawal affects our ability to continue providing a service to you.
13. Third-Party Websites
Our website may contain links to third-party websites not operated by AgilenLite. Such websites are governed by their own privacy practices, and we encourage you to review their policies; we are not responsible for their content or practices.
14. Contact Us - Data Protection Officer
If you have any question, feedback or concern about how AgilenLite collects, uses or discloses your personal data, or wish to make an access, correction or withdrawal request, please contact our Data Protection Officer:
Email: dpo@agilenlite.com
15. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices or in the law. The “Last updated” date at the top of this Policy indicates when it was last revised. Material changes will be notified through our website or other appropriate channels.
16. Governing Law
This Policy is governed by the laws of the Republic of Singapore, including the Personal Data Protection Act 2012.