Version 2026-04-28-v1
Privacy Policy
Effective 28 April 2026
1. Who We Are
Vasper Financial Advisory ("we", "us", "our") operates the ConSol financial planning platform. We are associated with Phillip Securities (Pte) Ltd, a holder of a Financial Adviser's Licence issued by MAS.
This Privacy Policy explains how we collect, use, disclose, and protect your personal data under the Singapore Personal Data Protection Act 2012 ("PDPA").
Our Data Protection Officer ("DPO") can be contacted at dpo@vasper.group.
2. Personal Data We Collect
We collect the following categories of personal data:
| Category | Examples | Purpose |
|---|---|---|
| Identity | Full name, NRIC last 4 digits, date of birth, nationality | Client identification; AML/KYC compliance |
| Contact | Email address | Account authentication; push notifications |
| Financial | Income, CPF balance, loans, insurance policies, investments, net worth | Financial gap analysis; engine computations; MAS suitability assessment |
| Goal | Financial goals, target dates, contribution amounts | Goal tracking; nudge generation |
| Device | FCM device token, app version, device model | Push notification delivery; crash reporting |
| Usage | Feature interactions, funnel step events (PostHog) | Product improvement; conversion analytics (anonymised) |
We do not collect full NRIC numbers. NRIC is stored as a one-way SHA-256 hash for identity verification purposes only. We never store payment card numbers or bank account credentials.
3. Legal Basis for Processing
We process your personal data on the following legal bases under the PDPA:
- Consent: Captured explicitly in the ConSol onboarding flow. You may withdraw consent at any time by submitting a Data Subject Access Request (see Section 8).
- Contractual necessity: Processing required to deliver the ConSol service under your agreement with us.
- Legal obligation: Retention of financial advisory records for 7 years as required under MAS Notice FAA-N16 and the Financial Advisers Act (Cap. 110).
4. How We Use Your Data
Your personal data is used exclusively to:
- Run financial analysis engines (CPF, TDSR, insurance gap, retirement, estate)
- Generate personalised financial nudges and goal tracking alerts
- Facilitate secure messaging between you and your adviser
- Maintain a MAS-compliant audit trail of advice and suitability assessments
- Send push notifications you have opted in to
- Improve ConSol product quality (anonymised usage analytics only)
We never sell, rent, or share your personal data with third parties for marketing purposes.
5. Third-Party Processors
We engage the following sub-processors. All process data under binding data processing agreements and are bound by the same data protection obligations as us:
| Processor | Role | Data shared |
|---|---|---|
| Google Firebase (Google LLC) | Authentication, database (Firestore), push notifications (FCM), crash reporting (Crashlytics) | Firebase servers in Singapore region (asia-southeast1). Google Cloud DPA applies. |
| Anthropic PBC | AI-assisted research and update drafting (Suite 18) | Anonymised text inputs only. No PII, NRIC, financial balances, or identifiers sent. Inputs are stripped and generalised before transmission. |
| Resend (Resend, Inc.) | Transactional email delivery | Email address only. Complaint acknowledgements and DSAR confirmations. |
| PostHog (PostHog, Inc.) | Product analytics | Anonymised funnel event data only. No PII transmitted. EU-hosted instance. |
6. Data Retention
Financial advisory records are retained for 7 years from the date of the last advisory transaction, as required by MAS Notice FAA-N16.
Other personal data is retained for as long as your account is active. Upon account closure:
- MAS audit trail data: retained 7 years from last transaction
- App usage data: anonymised and retained for product analytics
- All other personal data: deleted within 30 days of account closure
7. Data Security
We implement the following security measures:
- AES-256 encryption at rest (Firestore and SwiftData)
- TLS 1.3 in transit for all data communications
- Biometric authentication gate for iOS app access
- Screenshot prevention on sensitive screens (advisory outputs, NRIC-linked data)
- App Attest (Apple) for device integrity verification
- Firebase App Check for all Cloud Function access
- MAS-compliant immutable audit log for all data access events
8. Your Rights (PDPA Data Subject Rights)
Under the PDPA, you have the right to:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate personal data
- Withdrawal of consent: Withdraw consent at any time (this may affect your ability to use certain features)
- Deletion: Request deletion of your data (subject to retention obligations under the Financial Advisers Act)
To submit a Data Subject Access Request (DSAR), use the "My Data" section in the ConSol app (Settings → Data Protection → My Data) or email dpo@vasper.group. We will acknowledge your request within 14 business days.
9. Cookies and Analytics
The ConSol web funnel uses strictly necessary cookies for session management. Analytics events are captured by PostHog with IP anonymisation enabled. No third-party advertising cookies are used.
10. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated via the ConSol app and will require in-app acknowledgement before continued use. The version number and effective date above will be updated with each revision.
11. Contact and Complaints
For privacy-related queries, contact our DPO at dpo@vasper.group.
If you are dissatisfied with our response, you may lodge a complaint with the Personal Data Protection Commission (PDPC) at www.pdpc.gov.sg.
Version 2026-04-28-v1 · Effective 28 April 2026
This document should be reviewed by a Singapore-qualified lawyer before publication. It is a working draft and does not constitute legal advice.