Privacy Notice / Data Protection Policy

Last updated: 1 May 2026

Lee Ah Mooi Old Age Home (“Lee Ah Mooi”, “we”, “us” or “our”) is committed to protecting the personal data entrusted to us.

This Privacy Notice / Data Protection Policy (“Notice”) explains how we collect, use, disclose, store, protect, retain and otherwise process personal data in accordance with the Singapore Personal Data Protection Act 2012 (“PDPA”) and other applicable laws.

This Notice applies to personal data that we collect from or about residents, prospective residents, next-of-kin, caregivers, authorised representatives, donees, deputies, donors, volunteers, visitors, job applicants, employees, contractors, vendors, service providers, website users and other individuals who interact with us.

This Notice supplements, and does not replace, any specific consent clauses, notices or terms that may be provided in our admission forms, care documents, donation forms, volunteer forms, employment documents, website forms, agreements, event notices or other documents.

1. Personal Data Covered by This Notice

Personal data” means data, whether true or not, about an individual who can be identified:

a. from that data; or
b. from that data and other information to which we have or are likely to have access.

Depending on your relationship and interaction with us, the personal data we may collect includes:

a. name, alias, identification number, passport number, FIN, nationality, date of birth, gender, marital status, photograph and other identity details;
b. residential address, mailing address, email address, telephone number and other contact details;
c. information about next-of-kin, caregivers, emergency contacts, authorised representatives, donees, deputies or persons authorised to act for or communicate on behalf of a resident;
d. admission, assessment, care, nursing, medical, medication, allergy, dietary, mobility, rehabilitation, social-care, mental-health, behavioural, incident, accident, safeguarding and resident-welfare information;
e. payment, billing, deposit, subsidy, grant, financial-assistance, donation, tax deduction, receipt, refund, bank-transfer, GIRO, PayNow, accounting and audit information;
f. volunteer, internship, contractor, employment, recruitment, education, work-history, training, certification, reference, screening and background information;
g. images, photographs, CCTV footage, audio recordings, video recordings and event-related media;
h. website usage information, device information, browser information, IP address, cookies, analytics data and similar online identifiers;
i. enquiry, feedback, complaint, compliment, incident, investigation and correspondence records; and
j. any other personal data that you provide to us, or that we collect in connection with your relationship with Lee Ah Mooi.

We may also handle personal data relating to deceased individuals where necessary for care records, next-of-kin communications, legal, regulatory, insurance, accounting, audit, claims, archival, historical or operational purposes. We will handle such personal data in accordance with applicable law.

Business contact information, such as a person’s name, position, business telephone number, business address or business email address, where not provided solely for personal purposes, may be used to communicate with that person for business or operational purposes.

2. National Identification Numbers

We will collect, use or disclose NRIC numbers, FINs, passport numbers, copies of identification documents or other national identification numbers only where:

a. required or permitted by law;
b. an applicable exception under the PDPA or other written law applies; or
c. necessary to accurately establish or verify an individual’s identity to a high degree of fidelity.

Such purposes may include resident admission, care administration, medical records, medication safety, emergency care, government schemes, subsidies, financial assistance, employment records, safety and security, legal or regulatory compliance, insurance, claims, audits and other purposes where accurate identity verification is necessary.

We will not use full or partial NRIC numbers, FINs or passport numbers as passwords, default passwords, login credentials, security questions or authentication credentials. Where identity verification is needed, we will use more appropriate and secure methods.

Where practicable, we will avoid retaining physical identification documents and will use less intrusive alternatives, such as sighting an identification document, recording only necessary details, using internal reference numbers or collecting partial identifiers where appropriate.

3. How We Collect Personal Data

We may collect personal data when you:

a. make an admission enquiry or apply for admission to our home;
b. submit resident, next-of-kin, caregiver, medical, financial, subsidy, payment or administrative documents;
c. receive, arrange or participate in residential care, respite care, rehabilitation, nursing, medical, social-care or related services;
d. communicate with us through our website, email, telephone, messaging platforms, social media, forms or in person;
e. visit our premises, which may be monitored by CCTV or other safety and security systems;
f. participate in our events, activities, visits, outreach, fundraising, volunteering or community programmes;
g. make a cash, in-kind or recurring donation, or enquire about donations;
h. apply to volunteer, intern, work with us or provide services to us;
i. provide feedback, compliments, complaints, enquiries or incident reports;
j. use our website or interact with our online forms, cookies, analytics tools or digital services; or
k. otherwise interact with Lee Ah Mooi.

We may also collect personal data from third parties where you have authorised them to provide the data to us, where you have consented to such collection, or where such collection is permitted or required by law. Such third parties may include family members, caregivers, authorised representatives, healthcare providers, hospitals, clinics, social workers, referral agencies, public agencies, payment providers, banks, employers, referees, insurers, vendors and service providers.

4. Purposes for Collection, Use and Disclosure

We may collect, use and disclose personal data for purposes that are reasonable and appropriate in the circumstances, including the purposes set out below.

4.1 Resident admission, care and service administration

We may collect, use and disclose personal data to:

a. assess admission enquiries, admission applications and suitability for care;
b. verify identity, relationship, eligibility and authority to act;
c. carry out pre-admission, care, health, nursing, rehabilitation, dietary, mobility, social-care, financial or administrative assessments;
d. create, maintain and update resident, next-of-kin, caregiver and authorised-representative records;
e. provide residential care, nursing care, personal care, respite care, rehabilitation support, meals, medication support, activities and related services;
f. prepare, review and update care plans, medication records, dietary requirements, mobility support, incident records and other care documentation;
g. coordinate appointments, referrals, transfers, prescriptions, investigations, care reviews and follow-up actions with relevant healthcare or care providers;
h. communicate with residents, next-of-kin, caregivers, authorised representatives, emergency contacts and relevant care providers;
i. respond to emergencies, accidents, incidents, medical needs, safeguarding matters, complaints and continuity-of-care requirements; and
j. support resident welfare, safety, dignity, social engagement and quality of care.

4.2 Payments, donations, finance and administration

We may collect, use and disclose personal data to:

a. process payments, fees, deposits, donations, refunds, receipts, invoices and other financial transactions;
b. administer financial assistance, subsidies, grants, reimbursements, claims, funding arrangements and tax-related matters, where applicable;
c. maintain accounting, donation, tax, audit, financial and operational records;
d. carry out debt recovery, credit control, reconciliation, reporting and internal controls;
e. process cash donations, in-kind donations, recurring donations and donor records;
f. issue receipts, acknowledgements and donation-related communications; and
g. comply with applicable accounting, audit, tax, regulatory and legal obligations.

4.3 Donors, volunteers, events and community engagement

We may collect, use and disclose personal data to:

a. manage donor, volunteer and supporter relationships;
b. process volunteer applications, onboarding, deployment, attendance, training, safety, access and engagement;
c. organise events, visits, activities, celebrations, community programmes, fundraising initiatives and outreach;
d. communicate with donors, volunteers, supporters, partners and event participants;
e. send updates, newsletters, appreciation messages, event invitations, fundraising appeals or other communications relating to our work, where permitted by law or with consent where required;
f. take, use or publish photographs, videos or recordings of events, activities or community programmes, where appropriate and subject to applicable consent or notification requirements; and
g. support our charitable, community, volunteer and resident-engagement activities.

4.4 Website, communications and service improvement

We may collect, use and disclose personal data to:

a. respond to enquiries, requests, feedback, complaints and messages;
b. operate, maintain, secure and improve our website, online forms, email systems and digital services;
c. analyse website usage, traffic patterns, user experience and service performance;
d. improve our services, care processes, communications, fundraising, volunteer management and operational effectiveness;
e. conduct internal reviews, audits, data analysis, research, surveys, service evaluation, planning and business improvement;
f. generate anonymised or aggregated information that does not identify individuals; and
g. prevent, detect and investigate fraud, scams, misuse, cyber incidents, suspicious activity or security threats.

4.5 Recruitment, employment and vendor management

We may collect, use and disclose personal data to:

a. process job, internship, volunteer, contractor or service-provider applications;
b. assess suitability, eligibility, qualifications, experience, references, background and right to work;
c. manage employment, volunteer, contractor, vendor and service-provider relationships;
d. administer payroll, benefits, training, performance, discipline, insurance, workplace health and safety, where applicable;
e. manage vendor due diligence, procurement, contracts, service delivery, access arrangements and payments; and
f. comply with employment, workplace safety, regulatory, contractual and legal obligations.

4.6 Safety, security, legal and regulatory purposes

We may collect, use and disclose personal data to:

a. maintain safety and security at our premises, including through visitor records, access controls and CCTV;
b. prevent, detect and investigate accidents, incidents, misconduct, abuse, neglect, self-neglect, fraud, unlawful activity or breaches of our policies;
c. respond to lawful requests from government agencies, regulators, law enforcement, courts, tribunals or other competent authorities;
d. comply with applicable laws, licensing requirements, regulations, codes, guidelines, court orders, government directions and regulatory requirements;
e. manage legal claims, disputes, investigations, insurance matters and risk-management requirements;
f. conduct internal investigations, audits and compliance reviews; and
g. protect the rights, property, safety and interests of Lee Ah Mooi, our residents, staff, volunteers, visitors, donors, vendors and other stakeholders.

5. Consent, Deemed Consent and Exceptions

Where consent is required under the PDPA, we will collect, use or disclose your personal data only after notifying you of the relevant purposes and obtaining your consent.

Consent may be given expressly, or may be deemed under the PDPA in appropriate circumstances. We may also collect, use or disclose personal data without consent where permitted or required under the PDPA or other written law.

By providing personal data to us, submitting a form, communicating with us, using our services, visiting our premises, making a donation, volunteering with us, applying for a role, or using our website, you agree that we may collect, use and disclose your personal data for the purposes set out in this Notice and any other purposes notified to you at the time of collection.

We will not, as a condition of providing a product or service, require you to consent to the collection, use or disclosure of personal data beyond what is reasonable for providing that product or service.

We will not obtain or attempt to obtain consent by providing false or misleading information about the collection, use or disclosure of personal data.

If you provide us with personal data about another individual, including a resident, prospective resident, next-of-kin, caregiver, emergency contact, authorised representative, donor, volunteer, employee or job applicant, you confirm that you have obtained that individual’s consent, or otherwise have legal authority, to provide such personal data to us for the relevant purposes.

6. Withdrawal of Consent

You may withdraw your consent for the collection, use or disclosure of your personal data by contacting our Data Protection Officer using the contact details set out below.

Please note that withdrawal of consent may affect our ability to provide services, process requests, administer donations, manage volunteer arrangements, continue resident care arrangements, communicate with you, or maintain our relationship with you.

Upon receiving your withdrawal request, we may contact you to verify your identity, clarify the scope of your request and explain the likely consequences of withdrawal. We will process your request within a reasonable time and generally aim to give effect to the withdrawal within ten working days, unless more time is reasonably required.

Withdrawal of consent does not affect our right to continue collecting, using or disclosing personal data where such collection, use or disclosure without consent is permitted or required under the PDPA or other applicable laws. Withdrawal of consent also does not require us to delete or destroy personal data that we are required or permitted to retain for legal, regulatory, operational, accounting, audit, risk-management, claims, care-continuity or other legitimate purposes.

7. Disclosure of Personal Data

We may disclose personal data where reasonably necessary for the purposes stated in this Notice, where you have consented, or where permitted or required by law.

The parties to whom we may disclose personal data include:

a. our employees, officers, authorised personnel, volunteers, contractors and representatives;
b. residents’ next-of-kin, caregivers, emergency contacts, authorised representatives, donees, deputies or persons authorised by law or by the resident;
c. hospitals, clinics, doctors, nurses, allied health professionals, pharmacies, laboratories, ambulance providers and other healthcare or care-service providers;
d. government agencies, regulators, statutory boards, public agencies, law enforcement agencies, courts and tribunals;
e. payment processors, banks, donation platforms, accounting providers and financial-service providers;
f. insurers, auditors, lawyers, consultants, professional advisers and claims handlers;
g. IT vendors, cloud providers, website hosts, email providers, cybersecurity providers, data-storage providers, software providers, system administrators and records-management providers;
h. security, maintenance, transport, logistics, cleaning, catering, facilities-management and operational service providers;
i. event partners, fundraising partners, volunteer partners, community partners and programme partners;
j. prospective or actual assignees, transferees, successors or restructuring parties, where relevant to organisational restructuring or continuity of operations; and
k. any other party to whom disclosure is required or permitted by law, or to whom you have authorised us to disclose your personal data.

Where we engage service providers or data intermediaries to process personal data on our behalf, we will take reasonable steps to ensure that they process the personal data only for the purposes for which they were engaged and protect the personal data in accordance with applicable legal and contractual requirements.

8. Accuracy of Personal Data

We will take reasonable steps to ensure that personal data collected by or on behalf of Lee Ah Mooi is accurate and complete where the personal data is likely to be used by us to make a decision that affects you, or is likely to be disclosed to another organisation.

We generally rely on the personal data provided by you, your authorised representative, caregiver, next-of-kin or relevant third party. Please inform us promptly if your personal data changes or if any information we hold about you is inaccurate, incomplete or outdated.

Where necessary, we may request updated information or supporting documents to verify personal data, particularly for resident care, billing, subsidies, emergency contacts, employment, safety, security, legal or regulatory purposes.

9. Protection and Security of Personal Data

We take reasonable administrative, physical and technical measures to protect personal data in our possession or under our control against unauthorised access, collection, use, disclosure, copying, modification, disposal, loss of storage media or similar risks.

These measures may include:

a. access controls and need-to-know access restrictions;
b. staff confidentiality obligations and data protection training;
c. secure storage of physical and electronic records;
d. password, authentication and system-security controls;
e. cybersecurity, backup and monitoring measures;
f. encryption or other technical safeguards where appropriate;
g. secure disposal, deletion or anonymisation practices;
h. vendor due diligence and contractual data protection requirements;
i. incident-response and breach-management procedures; and
j. internal policies, audits, reviews and process controls.

We take particular care when handling sensitive personal data, including health information, care records, national identification numbers, financial information and information relating to vulnerable individuals.

However, no method of electronic transmission, online communication or data storage is completely secure. While we strive to protect personal data, we cannot guarantee absolute security. You should take care when sending personal data to us through email, online forms, messaging platforms or other electronic means.

Lee Ah Mooi will never ask for your bank login details, one-time passwords or authentication credentials. Please be alert to scams, phishing attempts, suspicious links and unauthorised websites or applications claiming to represent us.

10. Retention of Personal Data

We will retain personal data only for as long as it is necessary to fulfil the purposes for which it was collected, or as required or permitted by applicable laws, regulations, contractual obligations, accounting requirements, audit requirements, operational needs, claims-management needs or legitimate business purposes.

The retention period may vary depending on the nature of the personal data and the purpose for which it is retained. For example, resident care records, medical-related records, employment records, financial records, donation records, incident records, CCTV footage, website logs and correspondence records may be subject to different retention periods.

When personal data is no longer required, we will take reasonable steps to securely destroy, dispose of, delete, anonymise or otherwise cease retaining the personal data.

We will not retain personal data “just in case” where the purpose for which it was collected is no longer served and retention is no longer necessary for legal or business purposes.

11. Access to and Correction of Personal Data

You may request access to personal data about you that is in our possession or under our control, and information about how such personal data has been used or disclosed by us within one year before the date of your request, subject to the exceptions under the PDPA.

You may also request correction of an error or omission in your personal data that is in our possession or under our control.

To make an access or correction request, please contact our Data Protection Officer using the contact details set out below. We may ask you to provide information to verify your identity and to clarify the scope of your request.

We will respond to your request as soon as reasonably possible. If we are unable to respond to an access request within 30 calendar days after receiving your request, we will inform you in writing within that period of the time by which we expect to be able to respond.

If we are unable to correct personal data within 30 calendar days after receiving your correction request, we will inform you in writing within that period of the time by which we expect to be able to make the correction.

We may charge a reasonable fee for processing an access request. If a fee is payable, we will inform you of the estimated fee before processing the request.

We may decline to provide access to or correct personal data in circumstances permitted under the PDPA or other applicable laws, including where the request is frivolous or vexatious, where providing access would reveal personal data about another individual, where disclosure would threaten safety or health, where the information is protected by legal privilege, or where another exception applies.

For requests involving CCTV footage, photographs, audio recordings, video recordings or records containing information about multiple individuals, we may ask you to provide specific details such as date, time, location and context. Where appropriate, we may provide access in a redacted, extracted, still-image, summary or other reasonable format.

12. Cookies and Website Data

Our website may use cookies, server logs and similar technologies to support website functionality, improve user experience, maintain security, analyse website usage and understand how visitors interact with our website.

Cookies are small text files that may be stored on your computer, mobile device or browser when you visit our website. We may use cookies and similar technologies to:

a. enable website features and functionality;
b. remember user preferences;
c. maintain website security;
d. measure website traffic and performance;
e. understand visitor behaviour and improve our website;
f. support analytics, troubleshooting and service improvement; and
g. support fundraising, outreach, communication or campaign measurement, where applicable.

We may collect aggregated or anonymised information about website usage, such as page views, browser type, device type, referring pages, time spent on pages and general usage patterns. Aggregated or anonymised information that does not identify an individual is not personal data.

Our website may also contain embedded content, plugins, analytics tools or links to third-party platforms. Such third parties may use their own cookies or tracking technologies. Their use of cookies and personal data is governed by their own privacy policies and terms.

You may choose to disable cookies through your browser settings. However, some parts of our website may not function properly if cookies are disabled.

13. CCTV, Photographs and Recordings

Our premises may be monitored by CCTV for safety, security, incident management, emergency response and operational purposes.

CCTV may be used in common areas, access points, selected operational areas and other areas where reasonably necessary for safety, security or resident protection. We will use CCTV in a proportionate manner and will take reasonable steps to protect CCTV footage from unauthorised access, use or disclosure.

CCTV footage may be reviewed, used or disclosed where necessary for safety, security, incident investigation, safeguarding, emergency response, legal, regulatory, insurance, claims, care-management or operational purposes.

Photographs, audio recordings or video recordings may be taken during events, activities, visits, outreach programmes, volunteer sessions or community programmes. Where required, we will provide notice and/or obtain consent before using identifiable images or recordings for publicity, fundraising, reporting, social media, website, newsletter or other external communications.

If you do not wish to be photographed or recorded at an event or activity, please inform our staff or event organiser where practicable.

14. Third-Party Websites and Platforms

Our website, emails, messages or communications may contain links to third-party websites, platforms, payment providers, donation platforms, social media pages or external services.

We are not responsible for the privacy practices, content, security or data-handling practices of third-party websites or platforms. You should review the privacy policies and terms of those third parties before providing personal data to them.

15. Direct Communications, Fundraising and Do Not Call Requirements

We may send service-related, administrative, resident-care, donation, volunteer, event, fundraising or community-related communications to individuals who have provided their contact details to us, where permitted by law or with consent where required.

Where we send fundraising, promotional or marketing-type communications by telephone call, text message, fax or other channels subject to the Do Not Call provisions or other applicable communications rules, we will take steps to comply with the applicable requirements.

You may ask to stop receiving non-essential fundraising, outreach, newsletter or event communications from us by following the opt-out instructions in the communication, where available, or by contacting our Data Protection Officer.

Please note that even if you opt out of non-essential communications, we may still send you service-related, administrative, resident-care, payment, safety, security, legal or other necessary communications.

16. Transfer of Personal Data Outside Singapore

We generally aim to store and process personal data in Singapore where practicable. However, we may transfer personal data outside Singapore where necessary for operational, administrative, IT, cloud, hosting, payment, support, backup, professional-service or other legitimate purposes.

Where we transfer personal data outside Singapore, we will take appropriate steps to ensure that the recipient is bound by legally enforceable obligations or other safeguards to provide a standard of protection comparable to the protection under the PDPA, unless an exception applies under applicable law.

17. Data Breach Notification

If we become aware of a data breach involving personal data in our possession or under our control, we will take steps to assess the incident, contain the breach, mitigate potential harm and determine whether the breach is notifiable under the PDPA.

A data breach may be notifiable if it is likely to result in significant harm to affected individuals, or if it is of significant scale.

Where required under the PDPA, we will notify the Personal Data Protection Commission as soon as practicable and, in any event, no later than three calendar days after determining that the breach is notifiable.

Where required, we will also notify affected individuals as soon as practicable, at the same time as or after notifying the Personal Data Protection Commission, so that affected individuals can take steps to protect themselves from potential harm.

Where we are required to notify any other regulator, public agency, funder, partner, law enforcement agency or contractual counterparty, we will do so in accordance with applicable legal and contractual requirements.

18. Data Portability

Where any data portability obligation under the PDPA comes into force and applies to us, we will process applicable data portability requests in accordance with the PDPA, relevant regulations and any applicable PDPC guidance.

19. Public Agencies, Government Schemes and Other Legal Requirements

Where we collect, use, disclose or process personal data in connection with public agencies, government schemes, subsidies, grants, referrals, regulatory reporting, licensing, inspections, healthcare arrangements, social-care arrangements or other legal requirements, we will handle such personal data in accordance with the PDPA where applicable, other applicable laws, public-agency requirements and relevant contractual terms.

Nothing in this Notice limits any authority, right, privilege, immunity, obligation or limitation under applicable law.

20. Updates to This Notice

We may update this Notice from time to time to reflect changes in our practices, operations, legal requirements or regulatory guidance.

The latest version of this Notice will be made available on our website. The updated Notice will take effect from the date stated at the top of the Notice, unless otherwise stated.

21. Contacting Us

Lee Ah Mooi has designated a Data Protection Officer to oversee our compliance with the PDPA.

If you have any questions, requests, feedback or complaints relating to personal data, or if you wish to make an access, correction or withdrawal-of-consent request, please contact:

Data Protection Officer
Lee Ah Mooi Old Age Home
Email: YouMatter@leeahmooioldagehome.sg

Addresses:
1 Thomson Lane, Singapore 297728
148A Silat Ave, Singapore 168871

Telephone:
6256 8502 — Thomson Home
6276 2493 — Silat Home
9851 8900 — Donations & Volunteers

If your personal data was provided to us by a third party, we may refer you to that third party where appropriate, but you may still contact our Data Protection Officer for queries relating to our collection, use or disclosure of your personal data.