Privacy Policy
Privacy Policy
Digital Assets Association Ltd.
UEN 202343185M
Registered office | 116 Telok Ayer Street, Singapore 068585 |
Privacy contact | Data Protection Officer |
dpo@digitalassetsassociation.org | |
Effective date | 16 July 2026 |
Purpose of this Policy. This Privacy Policy explains how Digital Assets Association Ltd. (DAA, we, us or our) collects, uses, discloses, protects, retains and otherwise handles personal data in connection with our website, membership, events, programmes, communications and other activities.
1. Scope
This Policy applies to personal data handled by DAA in connection with all of its operations, including its website, membership applications and administration, events, conferences, webinars, industry programmes, newsletters, marketing communications, sponsorships, partnerships, speakers, contractors, volunteers, job applicants, photographs, recordings and public communications.
Employee and internal workforce records may be subject to separate internal policies, notices and contractual terms. Where another notice is provided for a specific activity, that notice should be read together with this Policy.
2. What is personal data?
Personal data means data, whether true or not, about an individual who can be identified from that data or from that data together with other information to which DAA has or is likely to have access. Business contact information may be treated differently under Singapore law, but DAA applies appropriate safeguards to such information.
3. Personal data we may collect
- Identity and contact information, including name, email address, telephone number, mailing address and signature.
- Professional and organisational information, including employer, business, job title, designation, professional biography, profile photograph and social-media profile.
- Membership information, including membership category, application responses, supporting documents, correspondence, approval records and membership history.
- Identity-verification information, including government-issued identification details, nationality and information used to establish or verify an applicant’s identity and eligibility for membership.
- Event and programme information, including registration, attendance, participation, session selections, accreditation, feedback, surveys and networking activity.
- Payment and transaction information, including billing details, invoices, payment status and bank-transfer records. DAA generally does not retain full payment-card credentials where payments are handled by a payment service provider.
- Marketing and communications information, including subscriptions, consent records, delivery status, engagement with communications, opt-outs and correspondence through email, telephone, SMS, WhatsApp, social media and other channels.
- Website and technical information, including IP address, browser, device, operating system, referral source, pages viewed, timestamps, cookies and similar technologies where used.
- Photographs, video, audio and other recordings made at DAA events, meetings and programmes.
- Enquiries, complaints, applications, nominations, contractual records and other information voluntarily provided to DAA.
- Information required for governance, legal compliance, dispute management, security, fraud prevention, audits and investigations.
DAA does not ordinarily seek date-of-birth, health or dietary-allergy information. Please do not provide sensitive or unnecessary personal data unless DAA specifically requests it for a stated purpose.
4. How we collect personal data
- Directly from you through membership, event, contact, subscription, account-registration and other forms.
- Through email, telephone, SMS, WhatsApp, meetings, social media and other communications.
- From your employer, organisation, representative, colleague, nominator, referrer or event co-organiser.
- From publicly available professional sources, company websites, business directories and social-media profiles.
- Through event venues, security teams, registration systems and other parties involved in a specific DAA activity.
- Automatically through our website and communications, including cookies, server logs and email-measurement technologies where enabled.
5. Purposes for collection, use and disclosure
DAA may collect, use and disclose personal data for purposes including:
- Assessing membership applications, conducting reasonable due diligence and administering membership rights, benefits, fees, renewals and records.
- Planning, operating and evaluating events, conferences, webinars, delegations, consultations, roundtables and other programmes.
- Managing registration, attendance, accreditation, venue access, safety, security, communications and participant support.
- Communicating with members, applicants, attendees, speakers, sponsors, partners, contractors, volunteers and other stakeholders.
- Sending newsletters, invitations, announcements, event information and marketing communications where consent has been given or another lawful basis applies.
- Administering sponsorships, partnerships, speaker arrangements, contracts, payments, invoices and accounting records.
- Publishing speaker and participant information where agreed, and producing and publishing photographs, recordings, reports, event recaps and archival materials.
- Operating, securing, maintaining, analysing and improving DAA's website, membership services, programmes and communications.
- Responding to enquiries, feedback, requests, complaints, disputes and legal proceedings.
- Preventing, detecting and investigating fraud, misuse, cybersecurity incidents and other unlawful or harmful activity.
- Meeting legal, regulatory, tax, accounting, audit, governance, insurance and reporting obligations.
- Any other purpose notified to you at or before collection, or otherwise permitted or required by law.
6. Identity verification and membership due diligence
DAA operates a selective, high-trust professional membership community and does not automatically admit applicants. Where reasonably necessary, DAA may collect and use identity-verification information to establish or verify an applicant’s identity to a high degree of fidelity, assess eligibility for membership, and manage impersonation, fraud, governance, security and reputational risks.
DAA may conduct video calls, compare applicants against professional profiles or organisational records, request supporting information and undertake other reasonable due-diligence checks. Government-issued identification details are used only for approved identity-verification, membership-governance, security, risk-management and legal-compliance purposes; they are not used as passwords or primary membership identifiers, and access is restricted to authorised personnel.
7. Marketing communications
Where you submit a membership application, register for a DAA event, subscribe to DAA communications or otherwise provide the relevant consent, DAA may add your contact details to its mailing and communications lists and send information by email, SMS, WhatsApp or other channels.
You may withdraw marketing consent at any time by using the unsubscribe link in an email, replying to the relevant message where that option is available, or contacting dpo@digitalassetsassociation.org. An opt-out may take a reasonable period to process. DAA may retain a minimal suppression record to ensure that the opt-out continues to be respected.
Withdrawal from marketing does not prevent DAA from sending operational, contractual, membership, security or event-related communications that are necessary for an existing relationship or activity.
8. Events, photographs and recordings
DAA events and programmes may be photographed, filmed or recorded. Images and recordings may capture attendees and may be used in event recaps, reports, archives, websites, social-media channels, media materials and future promotional communications.
DAA may give notice through registration materials, event pages, tickets, signage, announcements or other reasonable means. By attending an event after receiving such notice, an attendee acknowledges that incidental capture may occur. DAA does not guarantee exclusion from photography or recording in general event areas.
Sponsors, partners, speakers, venues and other stakeholders may not use DAA event footage, photographs, logos or related materials without DAA's prior written approval. Approval for one use does not authorise any other use.
9. Disclosure of personal data
DAA may disclose personal data only where reasonably necessary, including to:
- Co-organisers of the specific event, programme or activity for which the data was collected.
- Event venues, building management, security providers and accreditation personnel.
- Service providers that support DAA's website, communications, cloud storage, event registration, payment, accounting, IT, security, professional services or administration.
- Professional advisers, auditors, insurers, banks and payment service providers.
- Government authorities, regulators, law-enforcement bodies, courts and other persons where required or permitted by law.
- A successor, restructuring party or other relevant person in connection with a proposed or completed organisational restructuring, subject to appropriate safeguards.
DAA does not generally share event attendee lists with sponsors. Sponsors are not authorised to use attendee data for direct marketing unless the attendee has separately consented and DAA has expressly approved the arrangement.
DAA does not ordinarily disclose attendee information to overseas chapters or unrelated organisations merely because they are affiliated with or connected to DAA.
10. Service providers and data locations
DAA may engage service providers from time to time. Such providers may process personal data only for authorised purposes and are expected to protect it through appropriate contractual, technical and organisational safeguards.
Some websites, cloud, communications, social-media and technology services may operate infrastructure or support functions in more than one country. Where personal data is transferred outside Singapore, DAA will take reasonable steps required by applicable law to ensure that the recipient provides a standard of protection comparable to that under Singapore's Personal Data Protection Act 2012.
11. Cookies and similar technologies
DAA's website may use cookies, server logs, embedded content and similar technologies that are necessary for website functionality, security, account access, forms and user preferences. DAA may also use analytics or communication-measurement technologies to understand website use and the delivery or engagement of newsletters and other communications.
Third-party content or links, including social-media, video, event-registration or other embedded services, may place or access their own cookies and process information under their own privacy terms. You may control cookies through your browser settings. Blocking certain cookies may affect website functionality.
DAA should maintain a separate cookie notice or consent mechanism if it deploys non-essential advertising, retargeting or behavioural-tracking technologies.
12. Protection and security
DAA uses reasonable administrative, physical and technical measures designed to protect personal data against unauthorised access, collection, use, disclosure, copying, modification, loss, disposal or similar risks. These measures may include access controls, confidentiality obligations, security procedures, vendor controls, backups and incident-response processes.
No system or transmission is completely secure. DAA cannot guarantee absolute security, but will investigate and respond to suspected incidents in accordance with applicable law.
13. Retention
DAA generally applies the following retention approach, subject to legal, contractual, audit and operational requirements:
- Membership records: for the membership period and generally seven years afterward.
- Contracts, sponsorship and partnership records: generally seven years after expiry or termination.
- Accounting and transaction records: generally five to seven years, or longer where required by law.
- Event registration and attendance records: generally three years after the event.
- Enquiries, feedback and ordinary correspondence: generally three years after closure.
- Marketing records: while consent remains valid or until opt-out, with limited suppression records retained afterward.
- Unsuccessful employment, contractor or volunteer applications: generally six to twelve months.
- Photographs, recordings, reports and public archival content: for as long as DAA reasonably considers them relevant to its institutional record, communications or legitimate activities.
DAA may retain information longer where reasonably necessary for legal proceedings, investigations, governance, security, regulatory requirements or the establishment, exercise or defence of legal claims. When retention is no longer necessary, DAA will take reasonable steps to delete, destroy or anonymise the information.
14. Access and correction
Subject to applicable law, you may request access to personal data in DAA's possession or control and information about how it has been used or disclosed, and may request correction of inaccurate or incomplete personal data.
Requests should be submitted to dpo@digitalassetsassociation.org with sufficient information to verify identity and identify the relevant records. DAA may request supporting information, decline or limit a request where permitted by law, and charge a reasonable fee for an access request where permitted. DAA will inform the requester of any applicable fee before proceeding.
15. Withdrawal of consent
You may withdraw consent to DAA's collection, use or disclosure of personal data by giving reasonable written notice to dpo@digitalassetsassociation.org. DAA will explain the likely consequences and process the request within a reasonable period.
Withdrawal does not affect Processing already lawfully carried out and may prevent DAA from providing membership, event access, services or other benefits where the relevant information is necessary.
16. Accuracy
DAA takes reasonable steps to ensure that personal data is accurate and complete where it is likely to be used to make a decision affecting the individual or disclosed to another organisation. You should notify DAA when relevant information changes.
17. Children
DAA's activities and services are intended for business and professional audiences and are not directed at children. DAA does not knowingly collect personal data from persons under 18 except where necessary for a specific authorised activity and with appropriate consent or other legal basis.
18. Third-party websites and services
DAA's website and communications may link to third-party websites, platforms and services. DAA does not control their privacy practices. You should review the relevant third party's terms and privacy notice before providing personal data.
19. Complaints and contact
Questions, requests or complaints concerning personal data should be directed to:
Data Protection Officer
Digital Assets Association Ltd.
Email: dpo@digitalassetsassociation.org
Registered office: 116 Telok Ayer Street, Singapore 068585
Please include sufficient details for DAA to understand and investigate the matter. DAA may verify the requester's identity before releasing or amending personal data.
20. Changes to this Policy
DAA may update this Policy to reflect changes in its activities, technology, legal requirements or practices. The current version will be published on DAA's website with its effective date. Where appropriate, DAA may provide additional notice of material changes.
21. Governing framework
This Policy is intended to describe DAA's personal-data practices under Singapore's Personal Data Protection Act 2012. It does not create contractual rights beyond those provided by applicable law and any binding agreement with DAA.
