Elegant corporate architecture representing data security and professional integrity

Data Protection & Compliance

Privacy Policy

Your trust is the foundation of our relationship. This policy outlines how Max-Shield Insurance Agency collects, protects, and respects your personal information in accordance with Singapore's Personal Data Protection Act (PDPA).

Effective Date 1 January 2026
Last Updated 20 May 2026
Version 2.1

Introduction

Max-Shield Insurance Agency PTE. LTD. ("Max-Shield", "we", "our", or "us") is committed to protecting the privacy and security of your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you engage with our insurance services.

By accessing our services, you acknowledge that you have read and understood this Privacy Policy. We operate in full compliance with Singapore's Personal Data Protection Act 2012 (PDPA) and maintain the highest standards of data stewardship in the insurance industry.

Our Commitment

We collect only the information necessary to provide you with comprehensive insurance coverage and exceptional service. Your data is never sold to third parties for marketing purposes.

Information We Collect

To provide appropriate insurance solutions, we collect various categories of personal data, always with transparency and purpose limitation:

Personal Identifiers

Full name, NRIC/FIN, date of birth, nationality, and contact information including address, email, and phone numbers.

Financial Information

Employment details, income range, bank account information for premium payments, and credit history where relevant.

Risk-Related Data

Health records for medical insurance, property details for home coverage, vehicle information, and business operations data.

Interaction Records

Claims history, correspondence, website usage patterns, and customer service interactions for service improvement.

Sensitive Personal Data

Certain insurance products require collection of sensitive personal data, including medical history and biometric information. We obtain explicit consent before collecting such data and implement enhanced security measures for its protection.

How We Use Your Information

Your personal data serves specific, legitimate purposes that enable us to provide comprehensive insurance protection:

  • Underwriting and risk assessment to determine appropriate coverage and premiums
  • Policy administration, including issuance, amendments, renewals, and cancellations
  • Claims processing, investigation, and settlement in a timely manner
  • Fraud prevention and detection to protect our clients and business integrity
  • Regulatory compliance and reporting to relevant authorities
  • Customer communication regarding policy updates, renewals, and service improvements

Marketing Communications

We may contact you with information about products and services that may interest you. You may opt out of marketing communications at any time by contacting our Data Protection Officer or using the unsubscribe link in our emails.

Data Protection Measures

We implement comprehensive technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction.

Security Infrastructure

Our security framework includes industry-standard encryption for data transmission (TLS 1.3), AES-256 encryption for data at rest, multi-factor authentication for system access, and regular security audits by independent third parties. Our facilities feature physical access controls and surveillance systems.

Staff Training & Access

All employees undergo rigorous data protection training upon joining and annually thereafter. Access to personal data is granted on a strict need-to-know basis, with comprehensive audit logs tracking all data interactions.

Incident Response

In the unlikely event of a data breach, we have established protocols to contain, assess, and remediate the incident promptly. Affected individuals and the Personal Data Protection Commission (PDPC) will be notified in accordance with regulatory requirements.

Information Sharing

We do not sell your personal data. We share information only with selected parties under strict confidentiality agreements and for legitimate business purposes:

  • Reinsurance Partners: To spread risk and maintain solvency, we share data with reputable reinsurance companies under binding confidentiality terms.
  • Service Providers: IT vendors, claims adjusters, medical professionals, and legal advisors who support our operations.
  • Regulatory Bodies: Government agencies and regulators as required by law, including the Monetary Authority of Singapore (MAS) and PDPC.
  • Industry Databases: Fraud prevention databases and claims history registers to protect the insurance industry's integrity.

Your Rights

Under the PDPA, you have comprehensive rights regarding your personal data. We are committed to facilitating these rights efficiently and transparently.

Access & Correction

Request access to your personal data and correct any inaccuracies. We respond to access requests within 30 days.

Consent Withdrawal

Withdraw consent for specific data uses, though this may affect our ability to provide certain services.

Data Portability

Request your data in a machine-readable format for transfer to another organisation.

Complaint Resolution

Lodge complaints about our data handling practices with our DPO or directly with the PDPC.

To exercise any of these rights, please contact our Data Protection Officer using the details provided below. We may need to verify your identity before processing your request.

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including legal, accounting, and regulatory requirements. Typically, policy and claims records are retained for seven years after policy termination or claim settlement, in accordance with Singapore's insurance regulations.

When data is no longer required, we securely delete or anonymise it using industry-standard methods. Physical records are shredded, and electronic data is permanently erased with verification.

Contact Us

For any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Data Protection Officer:

Data Protection Officer

Max-Shield Insurance Agency PTE. LTD.
228 Changi Road #04-07 ICON@CHANGI Singapore 419741
Singapore 048948

Email: dpo@maxshield.com.sg
Phone: +65 6444 4991

We aim to respond to all inquiries within five business days. For complex requests requiring additional investigation, we will acknowledge receipt within two business days and provide a timeline for resolution.