Privacy Policy
Operator: Stella Nexus Pte Ltd (UEN 202619843R) ("we", "us", "our")
Service: CMFAS E-Learning (the "Service")
Effective Date: 1 May 2026
Version: 1.0
1. Scope and Application
1.1 This Privacy Policy describes how Stella Nexus Pte Ltd collects, uses, discloses, and protects personal data in connection with the CMFAS E-Learning Service, in accordance with the Singapore Personal Data Protection Act 2012 (the "PDPA").
1.2 "Personal data" in this policy has the meaning given in section 2(1) of the PDPA: data, whether true or not, about an individual who can be identified from that data, or from that data and other information to which we have or are likely to have access.
1.3 This Policy applies to:
- visitors to the Service's public pages;
- registered users who hold an active or expired subscription;
- managers and candidates accessing the Service via a corporate client portal; and
- individuals whose data is provided to us by a third party (for example, an employer enrolling staff).
1.4 By creating an account, completing a payment, or otherwise providing personal data to us, you consent to the collection, use, and disclosure of that data as described in this Policy. Where consent is required by law for a specific purpose (for example, electronic marketing), we will seek that consent separately and explicitly.
2. Data Protection Officer
2.1 We have appointed a Data Protection Officer ("DPO") who is responsible for matters relating to personal data.
2.2 The DPO may be contacted at:
Email: [email protected]
2.3 Please direct the following to the DPO:
- access and correction requests under section 21–22 of the PDPA;
- withdrawal of consent;
- complaints regarding our handling of personal data;
- breach reports or suspected unauthorised access concerning your account.
2.4 We will acknowledge your request within five (5) working days of receipt and respond substantively within thirty (30) calendar days, unless a shorter period is required by law.
3. Personal Data We Collect
3.1 We collect only the categories of personal data necessary for the operation of the Service. These are:
| Category | Specific fields |
|---|---|
| Identity | Full name, email address |
| Authentication | Account password (stored only as a salted hash; never accessible to us in plaintext), session tokens, last login timestamp |
| Subscription | Plan tier (Single / Starter / Comprehensive / GI Bundle / Corporate), assigned modules, subscription expiry date, Chinese-language add-on flag |
| Payment | Bank transfer reference code, payment amount in SGD, payment submission timestamp, verified-payment timestamp. We do not collect, process, or store credit or debit card numbers. |
| Learning activity | Question attempts, scores, mock exam outcomes, chapter-level progress data, time of attempt |
| Technical | IP address, browser user-agent, device type (collected in server logs for security and abuse detection only) |
| Corporate context (where applicable) | For corporate-plan candidates: corporate client identifier, manager who issued the seat. For corporate managers: representative identifier number used as account identifier |
| Communications | Records of email correspondence with us, support requests, and feedback you submit |
3.2 We do not collect: government identification numbers (NRIC, FIN, passport), photographs, marketing demographics, financial position, employment details beyond what users voluntarily provide in support correspondence, or special categories of data (health, ethnicity, religion, political views).
3.3 If a future feature requires data outside the categories above, we will update this Policy and, where required, seek fresh consent.
4. Purposes of Collection and Use
4.1 We collect and use personal data for the following purposes:
(a) Service delivery — providing access to study materials, exam practice, mock examinations, progress tracking, and account features.
(b) Authentication and security — verifying account ownership, detecting unauthorised access, preventing fraud and abuse, and protecting platform integrity.
(c) Payment processing and reconciliation — matching bank transfers to subscriptions, verifying payments, issuing receipts, and meeting tax and accounting obligations.
(d) Customer support — responding to enquiries, resolving issues, and processing access, correction, withdrawal, and deletion requests.
(e) Transactional communications — sending welcome emails, payment confirmations, expiry reminders, password resets, and notifications about material changes to the Service.
(f) Service improvement — analysing aggregate usage patterns to improve content, identify defects, and inform pedagogical decisions. Analysis is performed on aggregated or pseudonymised data where reasonably possible.
(g) Legal compliance — meeting obligations under the PDPA, the Companies Act, tax legislation, and any other applicable law.
4.2 We will only use personal data for purposes for which we have a lawful basis. Where a new purpose is contemplated, we will obtain fresh consent or rely on an applicable exception under the PDPA.
5. Disclosure of Personal Data
5.1 We do not sell personal data. We disclose personal data only as described in this section.
5.2 Sub-processors. We engage third-party service providers ("sub-processors") to operate the Service — including cloud database, authentication, and hosting providers; transactional email delivery; and encrypted backup storage. Each sub-processor is bound by contractual data-protection obligations equivalent to or stricter than those required by the PDPA, and is permitted to process personal data only as necessary to provide its service to us. Personal data may be processed by these providers in Singapore and in other jurisdictions (see section 6). A current list of our sub-processors is available on request to the DPO.
5.3 Corporate client managers. Where you access the Service as a candidate enrolled by a corporate client, certain account information (name, email, subscription expiry, mock exam scores) is visible to the manager(s) of your enrolling corporate client. This is necessary to operate the corporate portal feature.
5.4 Legal and regulatory disclosure. We may disclose personal data:
(a) where required by law, court order, or lawful request from a regulatory or law enforcement authority;
(b) to professional advisers (lawyers, auditors) where reasonably necessary;
(c) to establish, exercise, or defend legal claims;
(d) in connection with a corporate transaction (such as a sale or merger), subject to confidentiality protections.
5.5 No third-party marketing. We do not disclose personal data to third parties for their own marketing purposes.
6. International Transfer of Personal Data
6.1 Operating the Service requires the transfer of personal data outside Singapore to the sub-processors listed in section 5.2.
6.2 Where personal data is transferred outside Singapore, we ensure that the recipient is bound by legally enforceable obligations to provide a standard of protection comparable to that under the PDPA, in accordance with section 26 of the PDPA and the Personal Data Protection Regulations 2014.
6.3 The principal jurisdictions to which personal data may be transferred are Singapore, the European Union, and the United States. We rely on each sub-processor's Data Processing Addendum, Standard Contractual Clauses, or equivalent contractual safeguards to ensure a comparable standard of protection.
7. Retention of Personal Data
7.1 We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by law. Our retention schedule is as follows:
| Data category | Retention period | Trigger | Action at end of retention |
|---|---|---|---|
| Active user profile | Duration of active subscription plus 90 days grace | Subscription expiry | Account marked inactive; access disabled |
| Inactive user accounts | 5 years from the later of (a) last login or (b) last verified payment | 5-year inactivity threshold reached | Anonymisation (email and name redacted) or hard deletion |
| Payment records | 5 years from the end of the relevant financial year | Calendar | Archive to cold storage; deletion thereafter |
| Audit log (admin actions) | 5 years | Rolling | Archive monthly; purge entries older than 5 years |
| Learning progress data | Linked to user account | Account deletion | Cascade deletion with the account |
| Corporate client records | Contract term plus 3 years | Contract termination | Archive; deletion at end of period |
| Marketing and email engagement data | 2 years from last engagement, or earlier on withdrawal of consent | Inactivity or unsubscribe | Purge from email service provider |
| Authentication and login telemetry | 1 year (rolling) | Rolling | Auto-rotation or aggregation |
| Operational backups | 30 days (rolling) for production snapshots | Daily backup cycle | Automatic pruning |
| Records of access, correction, and deletion requests | 3 years from closure of the request | Request closed | Archive |
7.2 The retention periods set out above represent maximum durations. We may delete or anonymise data earlier where retention is no longer necessary and no legal obligation requires us to retain it.
7.3 Where you request deletion of your account (see section 9), we will give effect to that request within the time period stated, save to the extent that retention is required by law or for the establishment, exercise, or defence of legal claims.
8. Access, Correction, and Portability
8.1 You have the right to:
(a) request a copy of the personal data we hold about you (access);
(b) request correction of inaccurate or incomplete personal data;
(c) request that we provide your data in a commonly used machine-readable format to facilitate transfer to another organisation, where the data was provided by you and we hold it in electronic form (portability, subject to the PDPA's data portability provisions);
(d) withdraw consent for any purpose for which consent was given.
8.2 Requests should be submitted by email to the DPO at the address in section 2.2. To protect your data, we may require reasonable verification of your identity before responding.
8.3 We will respond to access and correction requests within 30 calendar days. Where a request cannot be met in full within this period, we will inform you of the reason and the expected response date.
8.4 We may charge a reasonable fee for access requests in accordance with the PDPA. No fee is charged for correction requests or withdrawal of consent.
9. Deletion of Personal Data
9.1 You may request deletion of your account and the personal data associated with it by emailing the DPO from the email address registered to your account.
9.2 We will give effect to a valid deletion request within fourteen (14) calendar days, subject to the following exceptions:
(a) personal data we are required by law to retain (for example, payment records under tax and accounting legislation — see section 7);
(b) personal data necessary for the establishment, exercise, or defence of legal claims;
(c) anonymised data which can no longer identify you.
9.3 We will confirm in writing when deletion has been completed, and clearly identify any retained categories together with the applicable retention period.
10. Marketing Communications
10.1 We will only send you electronic marketing messages where you have given separate, specific consent for that purpose. Acceptance of this Privacy Policy alone does not constitute consent to receive marketing.
10.2 You may withdraw consent to marketing at any time by:
(a) using the unsubscribe link in any marketing email;
(b) emailing the DPO at the address in section 2.2;
(c) contacting our customer support channels.
10.3 Withdrawal of marketing consent does not affect transactional communications (such as payment confirmations, expiry reminders, and account-related notices), which we may continue to send for the operation of your subscription.
10.4 We comply with the Do Not Call provisions of the PDPA. We do not send voice, SMS, or fax marketing to telephone numbers without separate, specific consent.
11. Cookies and Similar Technologies
11.1 The Service uses cookies and similar browser storage technologies. We categorise these as follows:
(a) Strictly necessary — required to operate the Service (for example, authentication session tokens, security tokens). These cannot be disabled without breaking the Service.
(b) Functional — remember preferences such as language toggle (English / 中文). These improve usability and are set with implied consent on use.
(c) Analytics — Currently none. If introduced, these will be set only with explicit consent via a cookie banner.
(d) Marketing — Currently none. The Service does not use third-party advertising or marketing trackers. If introduced, these will be set only with explicit consent via a cookie banner.
11.2 You can disable or delete cookies through your browser settings. Disabling strictly necessary cookies will prevent the Service from functioning.
12. Security of Personal Data
12.1 We implement reasonable technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, loss, and destruction. These include:
(a) transport-layer encryption (HTTPS) for all data in transit;
(b) salted password hashing managed by our authentication provider;
(c) role-based access control with row-level security policies at the database level;
(d) server-side enforcement of authorisation on sensitive endpoints;
(e) restricted administrative access, with audit logging of privileged actions;
(f) encrypted backups stored in geographically separate locations;
(g) regular security review of our code and infrastructure.
12.2 No method of electronic storage or transmission is perfectly secure. While we use commercially reasonable safeguards, we cannot guarantee absolute security and you provide personal data at your own risk.
12.3 You are responsible for keeping your account password confidential and for any activity that occurs under your account. You must notify us promptly if you suspect unauthorised access to your account.
13. Data Breach Notification
13.1 In the event of a data breach involving personal data, we will:
(a) assess the breach to determine its scope, cause, and impact;
(b) where the breach is likely to result in significant harm to affected individuals, or is of a significant scale, notify the Personal Data Protection Commission ("PDPC") within three (3) calendar days of completing our assessment, in accordance with section 26C of the PDPA;
(c) notify affected individuals as soon as practicable where required by section 26D of the PDPA, providing information sufficient to allow them to take protective steps;
(d) take steps to contain the breach and mitigate its effects.
13.2 We maintain an internal breach response procedure and review it periodically.
14. Children's Data
14.1 The Service is designed for adult learners pursuing professional certification. We do not knowingly collect personal data from children under the age of thirteen (13).
14.2 Where we become aware that we have collected personal data from a child under thirteen without verified parental or guardian consent, we will delete that data without undue delay.
14.3 If you believe that we hold personal data from a child under thirteen, please contact the DPO immediately.
15. Third-Party Sites and Services
15.1 The Service may contain links to third-party websites. We are not responsible for the privacy practices or content of those sites.
15.2 Our use of sub-processors (see section 5.2) is governed by Data Processing Agreements between Stella Nexus Pte Ltd and each sub-processor. Those agreements do not extend our control over the sub-processor's own privacy practices, which are described in their respective privacy notices.
16. Changes to this Privacy Policy
16.1 We may update this Privacy Policy from time to time. The "Effective Date" at the top of this document reflects the current version.
16.2 Where changes are material (for example, new categories of data collected, new purposes, new sub-processors handling personal data), we will notify affected users by email at least fourteen (14) calendar days before the changes take effect.
16.3 Continued use of the Service after the effective date of a material change constitutes acceptance of the updated Policy. If you do not agree to the updated Policy, you may terminate your account and request deletion of your personal data.
16.4 Version history is maintained internally and available on written request to the DPO.
17. Governing Law and Disputes
17.1 This Privacy Policy is governed by the laws of the Republic of Singapore.
17.2 Any dispute or complaint about our handling of personal data should first be raised with the DPO. If you are not satisfied with our response, you may refer the matter to the Personal Data Protection Commission of Singapore.
17.3 The courts of Singapore have non-exclusive jurisdiction over any dispute arising out of or in connection with this Policy.
18. Contact
For any matter relating to this Privacy Policy or your personal data:
Stella Nexus Pte Ltd (UEN 202619843R)
Attention: Data Protection Officer
Email: [email protected]
*End of Privacy Policy — Version 1.0.*