Legal
This policy explains how Firefly Payments Pte. Ltd. (“Firefly”, “we”, “us”) collects and uses personal data through the website fireflypay.io (the “Site”). Firefly is the organisation responsible for that data for the purposes of the Singapore Personal Data Protection Act 2012 (PDPA) and, where it applies, other data-protection laws such as the EU and UK GDPR.
Personal data processed as part of payment services delivered to our business customers is covered by the relevant services agreement and a separate data-processing addendum, not by this policy.
We do not knowingly collect personal data from children.
We use personal data to respond to your enquiries and arrange introductory calls, to assess whether Firefly can serve your business and prepare onboarding, to operate, secure and improve the Site, and to meet legal and regulatory obligations.
Where the GDPR applies, we rely on our legitimate interests in responding to business enquiries and running the Site, on steps taken at your request before entering into a contract, and on legal obligations. Where the PDPA applies, we rely on your consent, which you give by contacting us, or on the exceptions the PDPA permits. We do not sell personal data.
We share personal data only with service providers who host the Site, provide email and analytics and support our operations under contracts that require them to protect it [list key providers]; with professional advisers, regulators and law-enforcement authorities where required by law; and with a buyer or successor in the event of a merger, acquisition or reorganisation.
Our service providers may process data outside Singapore, including in [the United States / the EU]. When we transfer personal data abroad, we take steps to ensure it receives a standard of protection comparable to the PDPA and, where relevant, rely on appropriate safeguards such as standard contractual clauses.
[Describe the cookies and analytics actually used on the Site, or state that only strictly necessary cookies are set.] You can block or delete cookies through your browser settings.
We keep enquiry correspondence for as long as needed to respond and to manage any resulting business relationship, and in any case no longer than [24 months] after our last contact unless a longer period is required by law. Technical logs are kept for [period].
We use reasonable technical and organisational measures to protect personal data against unauthorised access, loss or misuse. No method of transmission over the internet is completely secure.
Depending on where you are, you may have the right to access the personal data we hold about you, to correct it, to withdraw consent, and in some cases to request deletion, restriction or portability, or to object to processing. To exercise these rights, email partnership@fireflypay.io. You may also complain to the Personal Data Protection Commission of Singapore or to your local data-protection authority.
Our Data Protection Officer can be reached at [dpo@fireflypay.io].
We may update this policy from time to time. The current version will always be published on this page with its “Last updated” date. Use of the Site itself is governed by our Terms of Service.