KSGA respects the personal data of members and visitors and manages it responsibly under Singapore’s Personal Data Protection Act 2012 (PDPA).
This Policy applies to the KSGA website, registration, event services, member community, enquiries and related email communications.
1. Accountability
KSGA determines the purposes and safeguards for personal data in its possession or control and designates a person to handle privacy enquiries, complaints, access and correction requests.
The business contact details of the DPO or data protection contact will be confirmed and published here and in the site footer before production launch.
2. Personal data we handle
KSGA handles the following data only to the extent reasonably needed to provide the service. Plain-text passwords and raw session or authentication tokens are not stored; strong hashes or non-recoverable verification values are used instead.
- Required account data: email, Korean and English names, display name, telephone number, preferred language and account status
- Optional service data: a full member's photo collected with consent for card issuance, home club and visibility settings
- Handicap data: submitted round date, course, tee, hole scores and pars, scorecard photo, review and appeal records, and internally calculated handicap
- Membership-card data: member number, issue and validity status, issue date and short-lived QR verification tokens
- Authentication and security data: password hash, email-verification and reset-token hashes, session-token hashes, failed-login count, IP address, user agent and security logs
- Policy records: the version, acceptance status, time and source for Terms, privacy and marketing choices
- Event data: event registrations, status, cancellation and change history, and communications reasonably needed to operate the event
- Community data: posts, comments, reports, attachments and moderation actions
- Technical data: language cookie, request times, error and audit logs, and minimal device information needed for service security
3. Purposes of processing
KSGA collects, uses or discloses personal data only for notified purposes that a reasonable person would consider appropriate. Optional marketing consent is not a condition of registration or core member services.
- Account identification, email verification, login, sessions and password reset
- Profile, membership status, permissions and visibility settings
- Issue a digital card containing the member photo, number and handicap, and verify current membership status through expiring QR codes
- Event registration, cancellation, capacity management, participant contact and material change notices
- Community operation, report handling and prevention of rights violations or abuse
- Service notices and marketing messages selected by the member
- Security detection and response, audit, legal compliance and dispute handling
- Statistics and service improvement where individual identification is unnecessary
4. How data is collected
KSGA collects data provided directly through registration, profile, event, community and enquiry forms; security and access data created during use; and records made by authorised operators in the proper course of their duties.
Before introducing a new collection method or purpose, KSGA will explain the purpose and whether the information is required or optional before or at the time of collection.
5. Consent and withdrawal
Where consent is required, KSGA explains the purpose before collecting, using or disclosing personal data. Acceptance of the Terms, required privacy consent, membership-photo processing and optional marketing consent are separated, and the policy version and time are recorded.
A person may withdraw consent on reasonable notice. KSGA will explain the likely consequences and cease the relevant processing unless retention or use remains permitted or required for legal or legitimate business purposes. Withdrawal of consent essential to membership may lead to restricted functions or account withdrawal.
7. Disclosure and service providers
KSGA does not sell personal data. Once email, server, backup, security or professional support providers are appointed, only the minimum data needed for the service will be disclosed and protected through contracts and access controls.
Data may be disclosed where permitted or required by law, a court or lawful investigation, or to protect life and safety. Actual processors and purposes must be confirmed and published before production use.
8. Transfers outside Singapore
If an email, backup or other provider processes personal data outside Singapore, KSGA will verify contractual, certification or other appropriate measures that provide protection comparable to the PDPA.
Once a recurring or material overseas transfer is confirmed, this Policy will identify the destination or recipient category, purpose and safeguard.
9. Retention and disposal
KSGA retains personal data only while the notified purpose remains valid or while reasonably needed for legal, audit or dispute-resolution purposes. Data is not kept indefinitely merely because it might be useful later.
Before launch, KSGA will approve a retention schedule for accounts, unverified sign-ups, expired tokens and sessions, event records, community content, audit and consent records, and backups. When retention is no longer justified, data is securely deleted or anonymised, and backup copies expire through the approved rotation cycle.
10. Security safeguards
KSGA applies reasonable administrative, technical and physical safeguards, including role-based access, strong password hashing, no raw token storage, encrypted transport, least-privilege server and database accounts, input and file validation, security logs, and tested backup and recovery procedures.
Members should use a unique password and report suspected compromise promptly. No internet transmission or storage system can be guaranteed absolutely secure, but KSGA reviews safeguards in proportion to the risk.
11. Access, correction and enquiries
A person may request access to personal data in KSGA’s possession or control and information about its use or disclosure during the preceding year, and may request correction of an error or omission. Legal exceptions or the personal data of others may limit a response.
After verifying identity, KSGA will respond as soon as reasonably practicable. If a lawful fee or additional time is expected, this will be explained in advance. Members should update changed details or notify the responsible contact.
12. Account withdrawal and cessation
Members may request account withdrawal and cessation of processing through the account service or published contact. KSGA will terminate active sessions, block member-only access and delete or anonymise data that no longer has a valid retention purpose.
Minimum consent, audit, dispute or legal records may be retained with restricted access. The response will explain how member content is deleted or anonymised and when backup copies are expected to expire.
13. Personal data breaches
KSGA will contain and investigate a suspected breach without undue delay and assess its impact and whether notification is required. If determined to be notifiable, KSGA will notify the PDPC as soon as practicable and no later than three calendar days after that determination, and will notify affected individuals as soon as practicable where required.
A notice will include the known impact, action taken, steps individuals can take to protect themselves and a contact route.
14. Data relating to minors
If KSGA permits minors to register or participate in events, it will implement age-appropriate notices and valid parental or guardian consent where required. Functions intentionally collecting a minor’s personal data will not be launched until that process is ready.
15. Changes to this Policy
KSGA may amend this Policy to reflect changes in law, services or actual processing. Material changes will be announced before they take effect, and the new version and effective date will be shown above. Fresh consent will be obtained for a new purpose where required.
16. DPO and privacy contact
Questions or complaints about personal data, consent withdrawal, access, correction or account withdrawal may be sent to the business contact below. The responsible person, response process and address must be confirmed before production publication.
Data protection contactta1257@nate.com