Skip to content
Terms & Policies

Data Protection Policy

Last updated 5 October 2026

1. Introduction

1.1 Sequence Business Services Pte. Ltd. (UEN 202346260R) (“Sequence”, “we”, “us”, or “our”) takes our responsibilities under Singapore’s Personal Data Protection Act 2012 (the “PDPA”) seriously. We also recognise the importance of the personal data that you entrust to us and believe that it is our responsibility to properly manage, protect and process personal data provided to us.

1.2 This Data Protection Policy is designed to assist you in understanding how we collect, use, disclose and/or process the personal data you have provided to us, as well as to assist you in making an informed decision before providing us with any personal data.

1.3 This Data Protection Policy supplements our Terms of Service and our Terms of Use, and together they set out the basis on which we collect, use, disclose and process any personal data we collect from you, the individuals you represent, our clients, customers or visitors to our website www.sequence.sg and to any Platform (as defined in our Terms of Use), including platform.sequence.sg (together, the “Website”). Unless otherwise defined herein, all defined terms shall have the meanings given to them in our Terms of Service.

1.4 By accessing our Website and/or using our services, you hereby agree to be bound by the terms of this Data Protection Policy. If you do not agree with any term of this Data Protection Policy, you should not access our Website or engage our services.

1.5 If you have any queries on this policy or how we may manage, protect, or process personal data, our Data Protection Officer (“DPO”) may be contacted at dpo@sequence.sg.

1.6 We reserve the right to amend the terms of this Data Protection Policy at our sole discretion. Any amended Data Protection Policy will be posted on our Website, and we will use commercially reasonable methods to notify you of such amendments. You shall be deemed to have accepted our published Data Protection Policy as amended by continuing to access our Website or use our services. Where you are a client under our Terms of Service, an amendment which affects your rights or obligations under the Agreement takes effect for you as the Terms of Service provide for their own revision, including as to notice.

1.7 Our Website may, from time to time, contain links to and from the websites of our partner networks, advertisers, affiliates or other third parties. If you follow a link to any of these websites, you should be aware that these websites have their own data protection or privacy policies. As these websites are not owned or operated by us, we do not accept any responsibility or liability for the contents of these websites and their data protection or privacy policies, and you access and provide personal data to these third-party websites at your own risk. Please check these policies before submitting any personal data to any such websites.

2. Information We Collect and How We Collect It

2.1 We may collect and process personal data such as:

2.1.1 names, identification details (for example NRIC number, FIN number, passport number, biometric data), contact details, registered address, email address, and other information provided by you;

2.1.2 financial account information such as billing address, banking details and other payment information;

2.1.3 copies of documents containing the data described in this clause 2.1;

2.1.4 if you contact us for any reason, we may keep a record of that correspondence;

2.1.5 personal data that may be captured via any error logging and reporting tool that captures error report data and, at your option and with your consent, sends this data to us in order for us to be informed of any software errors or problems that may occur during the use of the Website and services; and

2.1.6 details of visits to the Website and services, the activities you engage in when using the Website and services, the resources that you access on or via the Website and services, and the data provided to us in connection with or ancillary to these.

2.2 We collect personal data when you use our Website or services, including but not limited to:

2.2.1 when you visit or access our Website or services;

2.2.2 when we correspond with you for whatever reason, including in conducting onboarding, know-your-client checks, due diligence, feedback, surveys or general correspondence; or

2.2.3 when you visit our Website for whatever reason.

2.3 Notwithstanding the above, there is information that we collect which is mandatory in order for us to provide our services to you, as part of our being regulated by the Accounting and Corporate Regulatory Authority (“ACRA”) and any other regulatory or authoritative body of Singapore to which we are subject, without which we would not be able to provide you our services. In order to comply with such laws and regulations, we may use independent service providers to help us carry out due diligence and know-your-client checks. When this happens, you may be required to provide personal data (such as your NRIC, identification card or passport, or a photograph), the exact information of which may vary depending on the checks being carried out.

2.4 If you do not provide us with the personal data as may be required by us, or choose not to consent to our processing of your personal data, we may not be able to provide some or all of our services, or respond to other requests. We reserve the right to decline to provide any or all of our services to you should you decide not to consent to our collection, use, disclosure and/or processing of personal data that is required by us.

3. Cookies and Similar Technologies

3.1 In this clause 3, “Cookies” means cookies, web beacons, pixels, tags, software development kits, local and session storage, device identifiers and similar technologies used to store information on, or to read information from, your device. A Cookie allows the Website, or a party acting for us, to recognise your device, to record how the Website is accessed and used, and to retain your settings between visits.

3.2 What we currently use. We presently deploy only Cookies that are strictly necessary for the operation of the Website and for the services you have requested, namely:

3.2.1 a session Cookie which authenticates you and maintains your session while you are signed in to the secure area of the Website; and

3.2.2 a Cookie which extends that session so that you remain signed in across browser restarts, and which expires 24 hours after it is set or last refreshed by your activity on the Website, after which it is deleted and you will be required to sign in again.

3.3 We do not presently deploy analytics, advertising, behavioural targeting or third-party tracking Cookies on the Website.

3.4 What we may use in future. We may in future deploy:

3.4.1 functionality Cookies, to remember your preferences, language, region and previous inputs;

3.4.2 performance and analytics Cookies, to measure traffic, page views, referral sources, errors and interaction patterns so that we may maintain, secure and improve the Website and our services; and

3.4.3 marketing and measurement Cookies, to measure the effectiveness of our communications and campaigns, to limit repeat delivery of the same message, and to deliver content that we consider relevant to you on the Website or on third-party platforms.

3.5 Basis on which we deploy Cookies.

3.5.1 Cookies within clause 3.2 are strictly necessary for the provision of the secure signed-in service you have requested. They are used solely to authenticate you and to maintain your signed-in session for the limited duration set out in clause 3.2, are not used for any other purpose, and are deployed on the basis of your consent, including consent deemed given under section 15 of the PDPA, and, where applicable, in reliance on the legitimate interests exception in Part 3 of the First Schedule to the PDPA.

3.5.2 Cookies within clauses 3.4.1 and 3.4.2, if and when deployed, will be deployed on the basis of deemed consent by notification under section 15A of the PDPA, and this clause 3.5.2 constitutes our notification of those purposes. Before deploying them we will assess that the collection, use and disclosure concerned is not likely to have an adverse effect on you. You may opt out at any time through your browser or device settings, through any opt-out mechanism we make available, or by writing to our DPO, and we will give effect to your opt-out within a reasonable period.

3.5.3 Cookies within clause 3.4.3 will be deployed only where you have given consent through a consent tool presented on the Website or have otherwise expressly consented. You may withdraw that consent at any time. Withdrawal operates prospectively only and does not affect anything already done in reliance on your consent before withdrawal took effect.

3.6 Third parties. Where Cookies are set by third parties we engage, including hosting, security, content delivery, analytics or communications providers, those parties may act as our data intermediaries or in their own right, and may combine information collected on the Website with information they hold from other sources. We are not responsible for their independent practices, and clause 1.7 applies to them.

3.7 Information collected. Information collected through Cookies, and through the server, access and security logs generated automatically by our systems and those of our service providers, may include your Internet Protocol address, device and browser type, operating system, device identifiers, language and region settings, referring and exit pages, pages viewed, dates and times of access, clickstream data, and approximate location derived from your Internet Protocol address. Where such information identifies you, or where we are able to identify you from it together with other information we hold or are likely to have access to, it constitutes personal data and this Data Protection Policy applies to it. Such logs are generated for operational security, fraud prevention, capacity management and audit purposes.

3.8 Your controls. You may accept, reject, delete or restrict Cookies through your browser or device settings, through any consent tool presented on the Website, and through any opt-out mechanism offered by the relevant third party. If you reject or delete Cookies, some or all features of the Website and our services may not function, or may not function properly, and we shall have no liability to you for any resulting loss of functionality, content or convenience. Cookies within clause 3.2 may continue to be set as they are necessary to transmit communications over the network and to deliver the signed-in service you have requested.

3.9 We do not presently respond to “Do Not Track” or equivalent browser signals, as no uniform industry standard has been adopted for them.

3.10 Retention. Data derived from Cookies and from the logs described in clause 3.7 is retained in accordance with clause 9.

3.11 Visitors in the European Economic Area and the United Kingdom. Where you access the Website from the European Economic Area or the United Kingdom, and only to the extent that Regulation (EU) 2016/679, the United Kingdom General Data Protection Regulation, Directive 2002/58/EC as implemented in your jurisdiction, or the Privacy and Electronic Communications (EC Directive) Regulations 2003 apply to our processing:

3.11.1 we will not store information on, or gain access to information stored on, your terminal equipment other than where strictly necessary in order to provide a service you have explicitly requested, unless you have first given your consent;

3.11.2 the Cookies described in clause 3.2 are strictly necessary in order to provide the secure signed-in service you have explicitly requested, are limited in duration to your session as extended under clause 3.2.2, and are not used for any other purpose;

3.11.3 Cookies within clause 3.4 will not be set unless and until you have given prior consent through a consent tool presented on the Website; and

3.11.4 you may withdraw your consent, and exercise such rights of access, rectification, erasure, restriction, portability and objection as are available to you under those laws, by writing to our DPO.

3.12 Nothing in clause 3.11 constitutes an admission or acknowledgement that any law referred to in it applies to us, to the Website or to any of our processing activities.

4. How We Use Personal Data

4.1 We may collect, use and process your personal data for one or more of the following purposes:

4.1.1 to facilitate your use of our Website, to operate our Website, and to provide our services;

4.1.2 to enter into an agreement for the provision of services to you;

4.1.3 to verify your identity;

4.1.3A to provide introducer and business brokerage services, including recording, marketing and circulating listings of businesses, shares or assets for sale and of acquisition mandates, identifying, matching and introducing prospective counterparties, and keeping records of matches and introductions;

4.1.4 to conduct marketing activities including market research, customer profiling, customer insights and targeted marketing activities;

4.1.5 to send you notifications and marketing messages in relation to our promotional events, offers, opportunities, products, benefits and programmes, if so consented by you and, for any specified message to a Singapore telephone number, only after checking the Do Not Call Registry or in reliance on a valid exemption under Part 9 of the PDPA;

4.1.6 to respond to, handle, and process queries, requests, applications, complaints, and feedback from you;

4.1.7 to contact you through the contact information provided by you in order to provide you with information that you request from us;

4.1.8 to correspond with you and to collect information relating to online interactions with us (including, for example, your Internet Protocol address and the pages you view) so that we can offer you a more consistent and personalised experience in your relationship with us;

4.1.9 to store, host and/or back up (whether for disaster recovery or otherwise) personal data, whether within or outside Singapore;

4.1.10 for record-keeping purposes;

4.1.11 to conduct research, analysis and development activities (including but not limited to data analytics, surveys and/or profiling) to improve the Website and our services;

4.1.12 to notify you of any administrative updates that are not marketing or advertising in nature;

4.1.13 to respond to any legal processes, pursue legal rights and remedies, and manage any complaints or claims;

4.1.14 to respond to requests for information from public and governmental or regulatory authorities, statutory boards, industry associations and related companies, whether in Singapore or abroad, for audit, compliance, investigation and inspection purposes;

4.1.15 to inform you of updates on and/or changes to our programmes, policies, terms and conditions, data protection policy, updates and other administrative information;

4.1.16 to comply with any applicable law, regulation, legal process or government request;

4.1.17 for any other purposes for which you have provided the information; and

4.1.18 for any other incidental purposes related to or in connection with the purposes set out above or otherwise described in this Data Protection Policy.

5. Personal Data Disclosed to Us by You

5.1 You represent, undertake and warrant that:

5.1.1 for any personal data of individuals that you disclose or may disclose to us, you will have obtained, prior to such disclosure, the consent of the individuals whose personal data is being disclosed:

5.1.1.1 to permit you to disclose those individuals’ personal data to us for the purposes set out in this Data Protection Policy; and

5.1.1.2 to permit us (whether in Singapore or overseas) to collect, use, disclose and/or process those individuals’ personal data for the purposes set out in this Data Protection Policy;

5.1.2 you shall notify the individuals whose personal data is disclosed to us of the relevant purposes for such disclosure;

5.1.3 any personal data of individuals that you disclose or will be disclosing to us is accurate, and you shall give us notice in writing as soon as reasonably practicable should you become aware that any such personal data has been updated and/or changed after such disclosure;

5.1.4 you shall, at our request, assist us to comply with all applicable data protection legislation or laws, including but not limited to the PDPA; and

5.1.5 for any personal data of individuals that is provided to us, you are validly acting on behalf of such individuals and you have the authority of such individuals to provide their personal data to us and for us to collect, use, disclose and process such personal data for the purposes set out in this Data Protection Policy.

5.2 Without prejudice to the foregoing, you shall ensure that you comply with applicable data protection laws, and that you will not do anything, and will not omit to do anything, that will cause us to be in breach of any provision or requirement of such applicable data protection laws, whether now or in the future. You shall, at our request, promptly do such things or execute such documents, as determined by us, in order to facilitate our compliance with the applicable data protection laws.

5.3 Notwithstanding anything to the contrary, you undertake to indemnify and at all times hereafter to keep us (together with our respective officers, employees and agents) (each an “Injured Party”) indemnified against any and all direct and indirect losses, damages, actions, proceedings, costs, claims, demands and liabilities (including full legal costs on a solicitor and own client basis) which may be suffered or incurred by the Injured Party, or asserted against the Injured Party by any person or entity whatsoever, in respect of any matter or event whatsoever arising out of, in the course of, by reason of or in respect of:

5.3.1 any breach of any of the provisions in this clause 5; and/or

5.3.2 any action or omission that causes us to be in breach of the PDPA or any other applicable law,

save to the extent caused by Sequence’s own negligence, breach or wilful default.

6. Disclosure of Personal Data

6.1 Personal data provided to us by you may be used, disclosed, maintained, accessed, processed and/or transferred to the following third parties, whether sited in Singapore or outside of Singapore, for the purposes set out in this Data Protection Policy:

6.1.1 our affiliates, subsidiaries, and group companies;

6.1.1A prospective buyers, sellers, investors and other counterparties to a proposed transaction, any intermediary through whom any of them was introduced, and their respective advisers, in the course of our introducer and business brokerage services and on the basis agreed in the relevant introducer fee agreement or non-disclosure agreement;

6.1.2 third party service providers which require the processing of personal data, for example third party service providers which have been engaged by us:

6.1.2.1 to provide and maintain any information technology equipment used to store and access personal data;

6.1.2.2 to host and maintain the Website and our services; or

6.1.2.3 otherwise in connection with the provision of the services;

6.1.3 our auditors and legal advisers;

6.1.3A any actual or prospective assignee, novatee or successor of our business, or of any of our rights under our Terms of Service;

6.1.4 public and governmental or regulatory authorities and statutory boards, and industry associations, whether in Singapore or abroad; and/or

6.1.5 courts and other alternative dispute resolution forums.

6.2 In certain circumstances we may provide third parties (whether or not located in Singapore) with aggregate information about you. This may include information about your devices, including where available your Internet Protocol address, operating system and browser type, for system administration and to report aggregate information to our advertisers. This is anonymised statistical data about browsing actions and patterns, and does not identify any individual.

6.3 We may also disclose personal data in order to comply with any legal obligation, or in order to enforce or apply any terms and conditions between you and us, or to protect the rights, property, or safety of any person (including, for example, for the purposes of fraud detection and prevention).

6.4 Where we process personal data on behalf of and for the purposes of a client (for example in maintaining registers or records, making filings, or preparing accounts or payroll), we do so as that client’s data intermediary, as Clause 4.5.5 of our Terms of Service provides, and the client determines the purposes for which that personal data is collected, used and disclosed.

7. Transfer of Personal Data Outside of Singapore

7.1 The personal data that we collect from you may be transferred to, used, processed and stored outside of Singapore for one or more of the purposes set out above. By submitting personal data and/or using the Website and our services, you agree and consent to such transfer, storage and/or processing. Where we transfer personal data out of Singapore, we will take appropriate steps to ensure that the recipient is bound by legally enforceable obligations to provide the transferred personal data with a standard of protection that is at least comparable to that under the PDPA.

7.2 We will take reasonable steps to maintain appropriate physical, technical and administrative security to help prevent the loss, misuse, unauthorised access, disclosure or modification of personal data in our possession.

8. Updating Your Information

8.1 When you submit personal data to us, you should ensure such personal data is accurate, and let us know if such personal data changes so that we are not holding any inaccurate personal data about you.

8.2 You may request to update or amend your personal data by notifying us in writing at dpo@sequence.sg.

9. Retention of Personal Data

9.1 We retain personal data for as long as the purpose for which it was collected continues, or for as long as retention is necessary for legal or business purposes, whichever is the longer, in accordance with section 25 of the PDPA.

9.2 Without limitation, each of the following is a legal or business purpose for which we consider continued retention of personal data to be necessary:

9.2.1 compliance with statutory and regulatory record-keeping obligations, including under the Companies Act 1967, the Income Tax Act 1947, the Goods and Services Tax Act 1993, the Employment Act 1968, the Corporate Service Providers Act 2024 and the subsidiary legislation made under it, and any successor or equivalent legislation;

9.2.2 our obligations relating to anti-money laundering, countering the financing of terrorism and countering proliferation financing, including customer due diligence, enhanced due diligence, ongoing monitoring, screening, and the making of suspicious transaction reports;

9.2.3 the establishment, exercise or defence of legal claims, until the expiry of the applicable limitation period under the Limitation Act 1959 together with a reasonable margin for claims to be brought to our attention;

9.2.4 the enforcement of our Terms of Service and of any introducer fee agreement, non-disclosure agreement or other agreement with us, including any fee entitlement, tail period, non-circumvention obligation or confidentiality obligation which survives termination;

9.2.5 audit, insurance, professional indemnity, risk management and internal governance;

9.2.6 the handling of complaints, disputes, investigations and regulatory enquiries, whether actual or reasonably anticipated;

9.2.7 giving effect to any withdrawal of consent, opt-out or do-not-contact instruction, which requires us to retain a suppression record; and

9.2.8 the maintenance of backup, disaster recovery, business continuity and archival systems.

9.3 Indicative retention periods. Subject always to clauses 9.1 and 9.2, we ordinarily retain:

9.3.1 customer due diligence, know-your-client and other anti-money-laundering records, for not less than 5 years from the termination of the business relationship or the completion of the relevant transaction, or for such longer period as any competent authority requires or requests;

9.3.2 accounting, invoicing and transaction records, for not less than 5 years from the end of the financial year in which the relevant transactions were completed;

9.3.3 engagement documents, instructions and correspondence, for 6 years from the later of the end of the engagement, our last dealing with you, and the expiry of any tail or survival period under our Terms of Service or any other agreement with us;

9.3.4 Cookie data, server, access and security logs, and Website usage data, for up to 12 months from collection, save that any such data relevant to a security incident, investigation, complaint, claim or regulatory enquiry may be retained until that matter is resolved and any applicable limitation period has expired;

9.3.5 prospect and marketing data where no engagement follows, for up to 24 months from the last interaction, renewable on each further interaction;

9.3.6 suppression and do-not-contact records, for so long as is necessary to continue giving effect to the relevant instruction; and

9.3.7 recordings and transcripts of meetings and calls, for 24 months from the date of the recording, save where a longer period is necessary for the establishment, exercise or defence of a legal claim or is required by law.

9.4 Where retention is no longer necessary, we will use reasonable efforts to delete, destroy, de-identify or anonymise the personal data. Where we anonymise or aggregate personal data such that no individual can be identified from it, whether alone or together with other information we hold or are likely to have access to, the resulting data is no longer personal data, and we may retain and use it indefinitely and for any purpose, including analytics, benchmarking, service development and the improvement of our systems.

9.5 Deletion from our live systems will not immediately remove personal data from backup or archival media. Residual copies persist until overwritten in the ordinary course of our backup cycle, and we are not obliged to restore, search or amend backup media in order to give effect to a deletion or correction request.

9.6 Withdrawal of consent under clause 10 does not of itself require us to delete personal data. We will cease the relevant collection, use or disclosure, but may continue to retain the personal data where retention is required or permitted under clauses 9.1 to 9.3.

9.7 We are under no obligation to retain personal data beyond the periods contemplated by this clause 9, and we shall have no liability to you for having deleted, destroyed, de-identified or anonymised personal data in accordance with this Data Protection Policy. You remain responsible for maintaining your own records.

9A. Data Breaches

9A.1 Where we become aware of any unauthorised access to, collection, use, disclosure, copying, modification or disposal of personal data held by us, we will assess whether the incident is a notifiable data breach under Part 6A of the PDPA and will make any notification to the Personal Data Protection Commission and to affected individuals that Part 6A requires, within the periods prescribed.

10. Your Rights

10.1 Subject to clause 2.3 of this Data Protection Policy and to any applicable laws, you may withdraw your consent for us to collect, use, disclose and/or process your personal data for some or all of the purposes listed in this Data Protection Policy.

10.2 You may request to access or correct the personal data currently in our possession by emailing our DPO at dpo@sequence.sg. Please note that we may charge you a reasonable fee for the handling and processing of your request to access your personal data.