Privacy & PDPA notice
This notice explains how AdvoPay collects, uses, discloses, and retains personal data, consistent with Singapore’s Personal Data Protection Act (PDPA). It is a pre-launch draft and will be finalised with counsel before general availability.
Who we are
AdvoPay is a service operated by ADVO-CONSULT GmbH, the data controller for the personal data described in this notice. AdvoPay is a technology and distribution layer for virtual card issuing. Cards are issued by Sunrate Pte. Ltd. (UEN 201934985D), a Major Payment Institution licensed by the Monetary Authority of Singapore and a Mastercard principal member. AdvoPay is not a bank or card issuer.
What we collect
- Business (KYB) information you provide when you apply: legal name, registration number, address, business type, projected volumes, and uploaded corporate documents.
- Personal data of directors, beneficial owners, and representatives: name, date of birth, nationality, residential address, source of funds, and identity documents.
- Contact details for the person submitting the application.
How we use it
To assess your application, perform know-your-business (KYB) and, where applicable, sanctions screening, meet our legal and regulatory obligations, and communicate with you about onboarding.
Retention
- Financial and ledger records and audit logs are retained for at least the applicable regulatory minimum (a floor of at least five years is assumed pending final legal advice) and may be retained longer where required.
- Personal data is retained for the life of the relationship plus any regulatory retention floor.
- Card numbers and CVV are never stored at rest by AdvoPay; sensitive card data is handled within a hosted PCI vault.
- Backups containing personal data age out as backup cycles expire.
Your PDPA rights
You may request access to, or correction of, your personal data, and you may request deletion. We aim to respond within 30 days. Note that anti-money-laundering and financial-record retention obligations may require us to retain certain transaction records even after a deletion request; in that case we redact and restrict rather than erase.
Cross-border transfers
Our hosting region is chosen independently of our Singapore market anchor and personal data may be processed outside Singapore. Where that occurs, we require our infrastructure and vendor providers to give the data a standard of protection comparable to the PDPA through contractual clauses.
Contact
Questions about this notice or your personal data can be directed to the contact address provided during onboarding. A dedicated data-protection contact will be published before launch.
Last updated: pre-launch draft. This notice does not yet constitute final legal terms.