Personal Data Protection Statement
Lighthouse Canton Pte Ltd. ("LCPL"), a regulated organization incorporated in the Republic of Singapore (Registration No: 201422117K). LCPL and its related/affiliate companies (including Lighthouse Canton Capital (DIFC) Pte Ltd, Lighthouse Canton UK Ltd., LC Capital India Pvt. Ltd. and AIFs1) constitute LC Group (also referred to below as "we", "our" and "us"). Each of the individual entity is considered a Data Controller in terms of General Data Protection Regulation ("GDPR"). For certain functions, one or more entities may together collect and use your personal data, in those conditions, they are collectively considered as Joint Controller in terms of GDPR.
Protection of your Personal Data is important to us. LC Group's Privacy Policy outlines how we manage the Personal Data, we collect, use and disclose. This Privacy Policy applies to all departments and business units across LC Group. LC Group is committed to complying with the Personal Data Protection Act 2012 ("PDPA"), DIFC Data Protection Law 2020, the UK GDPR, the EU GDPR, the Digital Personal Data Protection Act, 2023 (India), and/or other applicable Data Protection laws (together referred to as the "Applicable Data Protection Laws"). Please read this Privacy Policy so that you know and understand the purposes for which we collect, use and disclose your Personal Data.
Please note that LC Group provides several products and services, each with their own Personal Data processing needs, some of which are more extensive than others. The Personal Data we collect from you is limited to the specific products and services you have signed up for or subscribed or entered in agreement for, and therefore, some clauses in this privacy notice may not be applicable to you. This privacy notice applies to our website, online portal, mobile applications, feedback forms, and any other means through which we may collect your Personal Data (collectively referred to here as our "Platforms").
1. Your Personal Data
1.1 "Personal Data" as defined in the PDPA means refers to any data or information about you from which you can be identified either (a) from that data; or (b) from that data and other information to which we have or are likely to have access. Examples of such Personal Data which you may provide us include, but is not limited to (depending on the nature of your interaction with us):
- your name, NRIC number, passport number or other identification number, telephone number(s), mailing address, email addresses and any other information relating to you which you have provided us in any form you may have submitted to us (i.e. job application forms, etc.), or in our other forms of interaction with you;
- information about your use of our websites and services, including cookies, IP addresses, email subscription and membership details (where applicable);
- your Curriculum Vitae, employment history, testimonials and referrals, previous drawn income, education background, medical history and disabilities and legal and bankruptcy history (if applicable); and
- your payment related information, such as your bank account details (where applicable).
1.2 Some of the Personal Data we collect falls within special categories attracting additional protection under applicable law:
- Biometric data – facial images and liveness data captured during eKYC onboarding. Processed on the basis of legal obligation (KYC/AML requirements) and, where required, your explicit consent provided at the point of onboarding.
- Health, medical and disability information – collected in the context of employment or where voluntarily provided. Processed on the basis of your explicit consent, which may be withdrawn at any time by contacting dpo@lighthouse-canton.com.
- Legal, bankruptcy and criminal history – collected where required for regulatory due diligence under legal obligation, or with your explicit consent where provided voluntarily.
"Personal data" as defined in GDPR means any information relating to an identified or identifiable natural person ("data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
As GDPR "processing" means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
For personal data of Data Principals (means the individual to whom the personal data relates) in India, each LC Group entity is a Data Fiduciary under the Digital Personal Data Protection Act, 2023. Where two or more LC Group entities jointly decide the purpose and means of processing, they are joint Data Fiduciaries under the said Act.
LC Group adopts a pragmatic approach in our business conduct.
2. What is the Legal Basis for Processing your Personal Data:
LC Group processes Personal Data only when we have legal basis to do so and for what is required in business or in activities conducted by our organization. We do not process Personal Data randomly or indiscriminately without purpose. In all cases the legal basis will be either of the following:
2.1 Consent
We may process your Personal Data based on your specific consent, including for sending tailored materials like service updates and promotions. You can withdraw this consent at any time by contacting us using the information provided below. Additionally, you can opt out of receiving marketing communications from us by using the Unsubscribe option provided in the marketing communication. It is important to note that if you withdraw your full consent, in certain cases, it could mean that we will not be able to provide parts or all our services.
2.2 For performance of contract
When you procure any service from us, such as availing Wealth Management, Asset Management, Corporate Financing (also referred as Arranging deals in Investment) or any other service regardless of the terminology, we process your Personal Information to provide you with those services.
2.3 Compliance with legal obligations
We are subject to several legal obligations and needs to use your Personal Data to comply with those obligations, including but not limited to for Client Due Diligence as per AML regulations, FATCA/ CRS reporting, responding to government requests and other requirements of law enforcement agencies.
2.3.1 Indicative List of Legal Provision:
2.4 Legitimate interests
We may process your Personal Data where it is necessary for our legitimate interests or those of a third party, provided those interests are not overridden by your rights and freedoms. For clients accessing our services through the Keenai platform, this basis applies to: fraud prevention and financial crime management; keeping our digital platforms and applications secure and operational; sending direct marketing communications to existing clients where applicable law permits on a soft opt-in or opt-out basis; and analytics to understand how our platforms are used and to improve them. Where we rely on our legitimate interests, we have conducted a balancing test to ensure those interests are not overridden by your data protection rights. You have the right to object to processing carried out on this basis by contacting us at dpo@lighthouse-canton.com.
For personal data of Data Principals in India, we do not rely on legitimate interests as a legal basis. We rely only on your consent or on specific permitted uses recognized under Indian data protection law. In particular, we will send direct marketing communications to Indian Data Principals only on the basis of your consent.
LC Group does not disclose your Personal Data unless prior consent has been obtained and we have administrative, physical and Information Technology (IT) security measures in place to protect your Personal Data. This does not affect any rights which LC Group may have under applicable law, including, for example, the right and obligation to share your Personal Data with regulatory authorities, law enforcement agencies, tax authorities or financial intelligence units where required to do so by law or court order, including pursuant to anti-money laundering regulations, FATCA/CRS obligations and applicable financial crime prevention obligations. Such sharing is also addressed in our client agreements.
3. Collection of Personal Data
3.1 What type of personal data collected:
We may collect the following types of personal data about you, if you are:
- An individual availing any service from us.
- A representative of, or an individual directly or indirectly related to or associated with: (i) a company, business or organisation that is our client; or (ii) a person or a company, business or organisation that has a relationship with our client.
Personal data we collect with respect to entity client relationships is primarily limited to the information on directors and officers, other employees, direct and indirect beneficial owners and authorised persons we need to enable us to meet our due diligence obligations, signatory details and contact information of individuals we interact with to enable the provision of products and services to clients.
If you give us someone else's personal data, you must have their permission and explain to them how we'll use it.
We may collect the following types of personal data about you, as relevant and allowed by law:
- Identification data – information that identifies (uniquely or semi uniquely) you. For example, your name, your date of birth, your gender, your user login credentials, your photographs, video recordings of you and other identifiers, including official/government identifiers such as national identification number, passport number and tax identification number.
- Contact data – information that allows addressing, sending or communicating a message to you. For example, your email address, your phone or mobile number and your residential or business address.
- Professional data – information about your educational or professional background.
- Geo-location data – information that provides or contains a device's location. We collect two types of location data: (i) Coarse location, derived from your IP address, which provides an approximate geographic location at city or region level, collected automatically when you access our Websites or the Keenai platform; and (ii) Precise location, GPS-level device location collected only through the Keenai mobile application and only where you grant explicit location permission through your device settings. Precise location data is used for regulatory geo-restriction compliance. You may withdraw location permission at any time through your device settings without affecting your ability to access core platform features.
- Behavioural data – analytics information that describes your behavioural characteristics relating to your use of our products and services. For example, usual transactional activities, browsing behaviour on our websites and how you interact as a user of our products and services, or those provided by third-party organisations, such as our advertising partners and social media platform providers.
- Device identifier data – information that identifies the specific device you use to access our services, including via the Keenai Wealth app. For example, your device's unique identifier (IMEI or MAC address), mobile network information, operating system and browser type.
- Mobile advertising identifiers – including the Android Advertising ID (AAID) and Apple's Identifier for Advertisers (IDFA) – may be collected through the Keenai application for analytics and platform improvement purposes. These identifiers are not treated as persistent device identifiers and are not used to track you across third-party apps or websites. You may reset or opt out of personalised use of these identifiers at any time through your device settings (Android: Settings → Privacy → Ads; iOS: Settings → Privacy & Security → Tracking).
- Personal relationship data – information about associations or close connections between individuals or entities that can determine your identity. For example, spouse or employer relationships.
- Communications data – information relating to you contained in voice, messaging, email, live chats and other communications we have with you. For example, service requests.
- Financial and commercial data – your account and transaction information or information that identifies your financial position and background, status and history as necessary to provide relevant products and services. For example, your source of wealth, your source of funds, your financial history.
- Biometric data – information that identifies you physically. For example, facial recognition information, your fingerprint or voice recognition information.
- Health data – information relating to your health status. For example, disability information relevant to accessibility.
- Criminal convictions, proceedings or allegations data – information about criminal convictions or related information that we identify in relation to our financial crime prevention obligations, for example, details about any criminal convictions or related information. This includes details of offences or alleged offences or convictions.
Where we collect analytical or statistical data through the Keenai application and our Websites, such data is aggregated and anonymised before analysis and is not linked to or used to identify any individual user. Anonymised analytics data and personal data are maintained separately and are not combined in a manner that would enable re-identification.
We usually get your personal data directly from you, but we may also obtain your personal data from other sources as necessary, depending on the relevant products and services that we are providing, including from:
People you know – such as:
- parents or guardians of minors. If you are a minor (normally this means if you are under 18 years old, but this might be younger depending on where you live). We will get your parent or guardian's consent before collecting, using or sharing your personal data. (For minors, we do not undertake behavioural monitoring or tracking, and do not direct targeted advertising at them, irrespective of any consent that may have been given by a parent or lawful guardian.)
- lawful guardian (where applicable). If you are a person with disability.
- your joint account holders;
- your referees; and
- other people you appoint to act on your behalf.
Businesses and other organisations – such as:
- your employer and/or company, business or organisation you represent or is related to you;
- other financial institutions and financial service providers;
- strategic referral partners, including business alliance or other companies or organisations that we cooperate with based on our contractual arrangements to provide relevant third-party products and services;
- service partners, such as advertising and market research companies and social media platform providers;
- regulatory and other entities with authority over us, such as tax authorities, law enforcement or authorities imposing financial sanctions.
Publicly available resources – such as online registers or directories or online publications, social media posts and other information that is publicly available.
Cookies – when you visit, browse, or use our websites, or mobile applications, we may use cookies to automatically collect certain information from your device. We may use such information, where relevant, for internal analysis and troubleshooting, to recognise you and remember your preferences, to improve the quality of and to personalise our content and to determine the security status of your account. For more information on how we use cookies and how you can control them when visiting our websites, please see our Cookie Policy.
4.2 In general, LC Group may collect, use and disclose your Personal Data for the following purposes:
- to provide you with the products and/or services that have been purchased or requested;
- to help manage the delivery of and enhance our products and services, including analysing current customer needs and identifying potential future needs;
- updating your records in our databases; monitoring and maintaining a copy of your record of previous transactions with LC Group;
- to communicate and respond to your queries, requests and complaints;
- to provide ongoing direct marketing communications about our products and services and upcoming events which may be of interest to you;
- to handle disputes and complaints and conduct and facilitate investigations and proceedings when required;
- to protect and enforce LC Group's contractual and legal rights and obligations;
- to prevent, detect and investigate crime, and to analyze and manage other commercial risks;
- to manage the infrastructure and business operations of LC Group and to comply with other LC Group internal policies and procedures;
- to facilitate business asset transactions (which may extend to any merger, acquisition or asset sale) involving LC Group;
- to comply with any applicable rules, laws and regulations, codes of practice or guidelines or to assist in law enforcement and investigations by relevant authorities.
4.3 In addition, LC Group may collect, use and disclose your Personal Data for the following purposes, depending on the nature of our relationship with you:
If you have a customer account with us, are a prospective customer or a customer:
- to process your application for a LC Group account;
- to maintain and administer your LC Group account with us;
- to verify your personal particulars and process payment requests in relation to provision of products and services, which you may be entitled to, or which you may have requested for;
- to provide you with the products and services which you may have entered into a contract with LC Group for or purchased from LC Group;
- to communicate changes and developments to LC Group's policies, terms and conditions and other administrative information, including for the purposes of servicing you in relation to products and services offered to you;
- to send direct marketing communications by email, push notifications, in-app messages, SMS and other electronic communications which may be of interest to you;
- to resolve complaints and handle requests and enquiries;
- to conduct market research for statistical, profiling, statistical analysis and planning for the improvement of LC Group's products and services provided to you; and
- to process your Personal Data in relation to any of the purposes stated above.
If you download or use any of our mobile or internet based applications ("apps"):
- to process your application for subscription services if such services provided for in the apps;
- to administer and maintain your account with us;
- to verify and process your personal particulars and process payment requests in relation to provision of products and services connected to the app;
- to provide you with the products and services which you have purchased or signed up for via the app;
- to communicate changes and developments to LC Group's policies, terms and conditions and other administrative information, including for the purposes of servicing you in relation to products and services offered to you;
- to resolve complaints and handling requests and enquiries;
- to conduct market research for statistical, profiling, statistical analysis and planning for the improvement of LC Group's products and services provided to you; and
- to process your Personal Data in relation to any of the purposes stated above.
If you are a prospective client:
- to administer and conduct appropriate due diligence checks;
- to prepare the relevant LC Group contract agreement and/or licence documentation and any other documents as may be required;
- to administer the relevant contract agreements or licences;
- to administer and perform financial transactions;
- to resolve complaints and handling requests and enquiries;
- to communicate changes and developments to LC Group's policies, terms and conditions and other administrative information; and
- any other purpose related to any of the above.
If you are a shareholder or unitholder of our funds (not applicable for LCIL):
- to administer the relationship, including the verification of your identity and/or the identity of your proxy (as may be applicable);
- to inform you of LC Group's performance and the products and services that LC Group provides to our customers through the sending of circulars, reports, newsletters and communications;
- to resolve complaints and handling requests and enquiries;
- to communicate changes and developments to LC Group's policies, terms and conditions and other administrative information; and
- any other purpose relating to any of the above.
If you are a vendor, a prospective vendor or a contractor:
- to evaluate your proposals for working with LC Group and to conduct relevant background checks on you;
- to communicate with your deployed staff, after award of contract, who are in our properties to carry out work or services, and for any emergency or security concerns; and
- any other purpose relating to any of the above.
If you submit an application to us as a candidate for employment:
- to evaluate your suitability for employment with LC Group, including pre-recruitment checks and checking on provided references for more detailed background screening/vetting;
- to organise training and staff development programs;
- to maintain and manage employee relations, including annual performance assessments/appraisals;
- to administer and manage benefits and payroll processing;
- to provide you with the relevant/correct tools as required for you to do carry out your job responsibilities;
- to communicate LC Group's policies and processes, codes of conduct and standard operating procedures, including for business continuity purposes; and
- any other purposes relating to the aforesaid.
4.4 When you apply for or hold a co-brand product which is offered jointly by LC Group and its co-brand partner (if any), LC Group may also collect, use and disclose your Personal Data with the co-brand partners for offering, marketing and promoting any products, services, offers or events which the co-brand partner thinks may be of interest to you.
4.5 In relation to particular products or services or during your interactions with LC Group, we may also notify or have specifically notified you of other purposes for which LC Group collects, uses or discloses your Personal Data. If so, we will collect, use and disclose your Personal Data for these additional purposes as well, unless we have specifically notified you otherwise.
4.6 Your Personal Data will be protected and kept confidential, but subject to the provisions of any applicable law, your Personal Data may, depending on the products or services concerned, be disclosed to the following third parties:
- other divisions, business units or entities within the LC Group;
- LC Group's joint venture/alliance partners;
- agents, contractors, sub-contractors, third party service providers and specialist advisers contracted by LC Group to provide administrative, financial, research, operational or other services, such as telecommunications, information technology, payment, payroll, processing, training, market research, storage and archival;
- insurers or insurance investigators and credit providers;
- in the event of default or disputes, any debt collection agencies or dispute resolution centres;
- any business partner, investor, assignee or transferee (actual or prospective) to facilitate business asset transactions (which may extend to any merger, acquisition or asset sale) involving the whole LC Group or entities within the LC Group;
- LC Group's professional advisors such as our auditors and lawyers;
- relevant government regulators or authority or law enforcement agency to comply with any laws or rules and regulations imposed by any governmental authority;
- anyone to whom we may transfer our rights and obligations;
- banks, credit card companies and their respective service providers; and
- any other party as may be consented to by you, as specified by that individual or in the applicable contract.
Where you are a client of Lighthouse Canton Pte Ltd (Singapore), your personal data may additionally be shared with the following named parties where required by law: Monetary Authority of Singapore (MAS); Suspicious Transaction Reporting Office (STRO); Inland Revenue Authority of Singapore (IRAS); and Credit Bureau Singapore (CBS).
Where you are a client of Lighthouse Canton Capital (DIFC) Pte Ltd, your personal data may additionally be shared with: Dubai Financial Services Authority (DFSA); DIFC Courts; UAE Financial Intelligence Unit (FIU); and other UAE/DIFC regulatory or law enforcement authorities as required by law.
Where you are a client of Lighthouse Canton UK Limited, your personal data may additionally be shared with: Financial Conduct Authority (FCA); His Majesty's Revenue and Customs (HMRC); National Crime Agency (NCA); Information Commissioner's Office (ICO); Credit Reference Agencies (such as Experian, Equifax and TransUnion); Background Screening Providers (such as HireRight or Sterling); and Payment and Settlement Infrastructure providers (such as SWIFT and Faster Payments).
Where you are a client of LC Capital India (LC Capital India Private Limited), your personal data may additionally be shared with: Securities and Exchange Board of India (SEBI); Financial Intelligence Unit India (FIU-IND); and the Income Tax Department of India.
LC Group requires that third party organisations which handle or obtain Personal Data, such as service providers to LC Group, acknowledge the confidentiality and sensitivity of this personal data, undertake to respect any individual's right to privacy and comply with the Applicable Data Protection Laws. LC Group also requires that these organisations use this information only for limited purposes which have been agreed upon and follow LC Group's reasonable directions with respect to this information.
Indicative list of third-party organisations
Third-Party Technologies Integrated into the Keenai Application
The Keenai application integrates third-party software components (SDKs) that may collect or process user data in the course of providing their services:
- Analytics: Mixpanel, Snowflake and Webengage collects aggregated usage and behavioural data to help us understand how users interact with the Keenai platform.
- Crash and Performance Diagnostics: Firebase or Sentry collects crash reports, error logs, and performance data to allow us to identify and resolve technical issues. Data collected includes device information, app version, and error details.
- Push Notifications: Webengage is used to deliver push notifications to your device and may collect a device token identifier for notification routing purposes.
Each third-party provider operates under its own privacy policy. We require all providers to maintain data protection standards consistent with applicable law and our data protection obligations.
For clients accessing our services through the Keenai platform, limited personal data – restricted to your name, email address and app event data, which is hashed prior to transmission – may be shared with social media advertising platforms to deliver relevant advertising and to identify audiences with similar profiles. You may opt out of this use of your personal data at any time through the privacy settings in the Keenai Wealth app or by contacting us at dpo@lighthouse-canton.com.
4.7 The table below sets out the lawful basis on which LC Group relies to process your Personal Data for each principal purpose. Where we rely on legitimate interests, a Legitimate Interests Assessment has been conducted and is available on request from the Data Protection Officer.
5. When Do We Use Automated Decision Making
We may use the personal data we collect to conduct data analytics, including profiling and behavioural analysis, to make quicker automated decisions in our business operations and to evaluate your personal characteristics to predict outcomes and risks. We require that rules followed by such automated systems are designed to make fair and objective decisions. We may use artificial intelligence and machine learning to help improve our communications and client experience, make our business operational processes safer and more efficient and enable us to provide faster responses and improve turnaround time. For example, we may use automated decision-making for the following:
- Client digital onboarding processes – account opening approval processes using electronic Know-Your-Customer (eKYC) checks by verifying the authenticity of scanned identification documents and a photo through biometric facial recognition and liveliness check.
- Risk management – monitoring of accounts and transactions to detect unusual activities to prevent fraud or money laundering, terrorism and other financial crimes.
- Credit and affordability assessments – for clients applying for credit products via the Keenai platform, automated processes are used to assess creditworthiness and affordability, set or amend credit limits, and monitor ongoing credit agreements.
In each case, the following is relevant to understanding how these automated systems work:
eKYC onboarding: identity documents and biometric data are verified against government and third-party databases. Scores below a defined threshold trigger manual review by a compliance officer before any account opening decision is finalised.
Fraud and AML monitoring: transaction data and account behaviour are scored against risk rules and machine-learning models. Alerts are reviewed by the compliance team before any account restriction is applied.
Credit and affordability assessment (Keenai): applicant financial data, credit bureau information and account history generate a creditworthiness score. The model is reviewed periodically to ensure fairness and accuracy.
Right to contest automated decisions: if an automated decision produces legal effects or significantly affects you, you may request human review and contest the decision by contacting dpo@lighthouse-canton.com within 30 days of notification.
For further information on your rights in relation to automated decisions that affect you, please refer to the 'What are your personal data protection rights?' section.
Third-Party AI Services
Certain features of the Keenai platform may be powered by third-party artificial intelligence services. Where such features involve sharing your personal data with a third-party AI provider, we will obtain your explicit consent before doing so. These providers are contractually required to handle your data in accordance with applicable data protection law and are not permitted to use your data for their own independent purposes.
You may withdraw consent for AI-assisted processing at any time by contacting dpo@lighthouse-canton.com, though withdrawal may affect the availability of certain AI-enhanced features within the Keenai platform.
6. Keeping Your Personal Data Accurate and Up-To-Date
6.1 LC Group endeavors to ensure that Personal Data stored by us is accurate and up-to-date. LC Group also understands that Personal Data may change frequently, such as changes of address and other personal circumstances. As such, LC Group encourages you to contact the DPO at dpo@lighthouse-canton.com to update your Personal data. Incomplete or outdated Personal Data may result in our inability to provide you with products and services you have requested.
7. Use of Cookies
7.1 The use of cookies on LC Group websites are governed by our Cookie Policy. The Cookie Policy may be updated from time to time and we encourage you to check back regularly for updates to the same.
7.2 By interacting with us on our websites, you acknowledge and consent to the terms of our Cookie Policy. Should you wish to disable the use of cookies, you may do so by changing the settings on your browser. However, you may not be able to enter or use certain part(s) of our websites.
8. Where the Personal Data is Stored
8.1 We will safeguard the confidentiality of your Personal Data, whether you interact with us personally, by telephone or mail, over the Internet or through forms of other electronic media. We hold Personal Data in a combination of secure computer storage facilities and paper based files and other records and take steps to protect the Personal Data we hold from misuse, loss, unauthorized access, modification or disclosure. Where we no longer require any Personal Data that we hold, that Personal Data would be destroyed or have particulars or information which may identify individuals removed.
Your Personal Data will only be disclosed for the express purpose of delivering the product or service requested and shall not be sold or disclosed to any other company for any other reason whatsoever without your consent.
All electronic storage and transmission of personal data is secured and encrypted with appropriate security technologies.
Although every reasonable effort has been made to ensure that all personal data will be so protected, LC Group cannot be responsible for any unauthorized use or misuse of such information and from risks which are inherent in all internet communications.
9. Where We Transfer Personal Data
Your personal data may be processed, stored, shared, transferred or disclosed by us within the LC Group or with other third parties for the purposes described in this Data Protection Statement. We do this in order to operate effectively, efficiently and securely in facilitating transactions and providing products and services to our clients, to improve and support our processes and business operations and to comply with our legal and regulatory obligations. This may involve processing, storing, sharing, transferring or disclosing your personal data cross border to other jurisdictions.
Where recipients of your personal data are in jurisdictions that are overseas, and local laws may not have similar data protection laws as that of the jurisdiction where we are based, we will take all reasonable steps necessary to ensure that your personal data has an appropriate level of protection and safeguards to comply with applicable law.
For transfers of personal data from the UK or EEA, LC Group relies on the following safeguards as appropriate: (i) the UK International Data Transfer Agreement (UK IDTA); (ii) the UK Addendum to the EU Standard Contractual Clauses; and/or (iii) EU Standard Contractual Clauses (EU SCCs) approved by the European Commission. Prior to any cross-border transfer, LC Group conducts a documented data transfer risk assessment of the destination country's legal framework.
For transfers from Singapore, we comply with the PDPA transfer obligations.
For transfers from the DIFC, we comply with the DIFC Data Protection Law 2020 transfer requirements.
For personal data originating from India, any cross-border transfer of your personal data will be made only in accordance with Indian data protection law, and will meet any specific requirements that the Central Government of India may impose by general or special order on transfers to a foreign country, or to any person or entity under the control of, or acting as an agency of, such a country.
In the event of a personal data breach that is likely to result in a high risk to individuals' rights and freedoms, we will notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach. We will also notify affected individuals without undue delay where required.
To obtain a copy of the applicable safeguards, please contact our Data Protection Officer at dpo@lighthouse-canton.com.
We have put in place procedures to deal with relevant or material personal data breach, which we are aware of.
10. How Long Do We Retain Personal Data
We will process and store your Personal Data, as long as it is necessary to fulfil the purpose for which it was collected, and to meet any legal, business, accounting or reporting requirements or subject to the requirements of applicable laws. LC Group maintains an internal data retention policy and schedule setting out specific retention periods by data category, determined by reference to: the termination date of the relevant contract or business relationship; any retention period required by law or regulation (including AML, FATCA/CRS and other regulatory requirements); and any need to preserve records for audits, tax matters or legal claims. For details of the specific retention period applicable to your personal data, please contact our Data Protection Officer at dpo@lighthouse-canton.com. When deleting your Personal Data, we will use reasonable and technically feasible methods, as mandated by relevant laws, to render the Personal Data impossible to recover or replicate, as stipulated by the applicable legal requirements.
As a default minimum, personal data is retained for six years following the end of our business relationship with you, consistent with anti-money laundering and regulatory record-keeping obligations. Longer retention periods may apply where required by applicable law, regulation, or in connection with actual or anticipated legal proceedings.
11. What Are Your Personal Data Protection Rights
We respect your personal data, and you have the following rights about how we use your information:
- The right to be informed - You have the right to know the details related to the processing of your Personal Data.
- The right to access - You have right to obtain confirmation on whether Personal Data concerning you is being processed. If personal data concerning you is being processed, you have the right to request us for a copy of your Personal Data. Where allowed by law, we may charge you a reasonable fee based on administrative costs.
- The right to rectification - If your personal details have changed, or you believe we have incorrect or out-of-date information about you, you can ask us to update.
- The right to object or restrict processing - You may object to the processing of your Personal Data in the following cases: the accuracy of the personal data is contested by us, for a period enabling us to verify the accuracy of the personal data; the processing is unlawful, but you do not want us to erase the personal data; we no longer need the personal data for the purposes of the processing, but they are required by you for the establishment, exercise or defence of legal claims; to request us not to subject you to a decision based solely on automated decision making, including profiling, where the decision would have a legal effect on you or produce a similarly significant effect, except where such processing is carried out based on legal basis mentioned above.
- The right to erasure - You have the right to request us to erase your Personal Data in cases where your Personal Data is no longer necessary for the purpose it was collected or processed, or if it was unlawfully processed. You may also exercise this right if you have withdrawn your consent to the processing of your Personal Data where consent was the legal basis for such processing, or where you object to the processing of your Personal Information. Please note that the right to erasure is not absolute and may not apply where processing is necessary for compliance with a legal obligation, for the exercise or defence of legal claims, or for other grounds permitted under applicable law.
Account and Data Deletion (Keenai Platform Users)
If you are a Keenai platform user and wish to delete your account and associated personal data, you may submit a deletion request to our Data Protection Officer at dpo@lighthouse-canton.com with the subject line "Account Deletion Request". Upon receipt of a verified request, we will delete your account and associated personal data and confirm deletion in writing within 30 days.
Please note that certain data must be retained beyond the deletion request where required by applicable law or regulation – including records required to be kept for six years under anti-money laundering, financial services, and tax regulations. In such cases, processing of your retained data will be restricted to the minimum necessary for regulatory compliance only. All retained data will be securely deleted upon expiry of the applicable retention period.
- The right to data portability - You have the right to receive the Personal Data concerning yourself in a structured, commonly used and machine-readable format.
- The right not to provide or change or withdraw consent - We may from time to time ask for your consent to process your personal data. You can choose not to provide such consent or let us know at any time if you change your mind about the consent already provided. However, we may not be able to provide our products and services or engage with you without certain personal data.
- The right to withdraw from direct marketing - You may withdraw your consent to receive direct marketing communications at any time by: (i) clicking the unsubscribe link in any marketing email or communication; (ii) updating your notification preferences within the Keenai application; or (iii) contacting our Data Protection Officer at dpo@lighthouse-canton.com. Withdrawal of consent will not affect the lawfulness of any processing carried out prior to withdrawal.
- The right to lodge complaints with appropriate Authority - You have the right to lodge a complaint with the appropriate Authority, (i) for UK data subjects — the Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow SK9 5AF (www.ico.org.uk); (ii) for EU data subjects — the supervisory authority in your country of residence; (iii) for Singapore data subjects — the Personal Data Protection Commission (PDPC) (www.pdpc.gov.sg); (iv) for DIFC data subjects — the DIFC Commissioner of Data Protection (www.difc.ae); and (v) for India Data Principals — the Data Protection Board of India.
- The right to nominate (For Indian Data Principals) - You have the right to nominate another individual to exercise your rights in the event of death or incapacity.
We will respond to requests to exercise your personal data rights in line with applicable law. We may ask you to verify your identity before processing your request. If you have any questions about your rights, please contact us using the details below.
12. Access Requests and Withdrawal of Consent
12.1 Please contact us via dpo@lighthouse-canton.com should you wish to have access to or withdraw the consent to collect and use your Personal Data.
Your email should identify yourself and state which Personal Data and information about its use and / or disclosure is requested. If you withdraw your consent to any or all purposes and depending on the nature of your request, LC Group may not be in a position to continue to provide our products or services to you.
13. Management and Security
13.1 We have appointed Data Protection Officers to oversee our management of your Personal Data in accordance with this Privacy Policy and the Applicable Data Protection Laws. LC Group trains our employees who handle Personal Data to respect the confidentiality and sensitivity of your Personal Data.
13.2 We take the privacy and security of your personal data very seriously. To protect your data, we have put in place a range of appropriate technical, physical and organisational measures to safeguard and keep your personal data confidential, for example, by using contracts with appropriate confidentiality, data protection and security terms in our arrangements with third parties. LC Group has implemented information security and data privacy policies, including incident management and reporting procedures, rules and technical measures to protect personal data and to comply with legal and regulatory requirements. We train and require staff who access your personal data to comply with our data privacy and security standards. We require our service providers, or other third parties we engage with and to whom we disclose your personal data to implement similar confidentiality, data privacy and security standards and measures when they handle, access or process your personal data.
LCPL has a SOC 2 Type 2 certification. SOC 2 ensures that a company's systems and controls protect customer data by evaluating the security, availability, processing integrity, confidentiality, and privacy of the service organisation's systems.
14. How to Contact Us
14.1 If you have any questions about this Policy or any complaints relating to your Personal Data, or you would like to obtain access and make corrections to your Personal Data records (note: LC Group will not charge a fee for exercising your data protection rights except where requests are manifestly unfounded or excessive, in which case a reasonable administrative fee may be applied or the request may be refused), please contact the designated Data Protection Officers or Grievance Officer for the respective business units as follows:
Business Entity: LC Group
Name of Data Protection Officer (DPO)/ Grievance officer: Sumeet Srivastava
Contact Number: +91 9535763353
Email Address: dpo@lighthouse-canton.com
15. Review of the Policy Statement
15.1 This Policy will be reviewed from time to time by LC Group. LC Group may also from time to time update this Privacy Statement to take account of new laws and technology, changes to our operations and practices and the changing business environment. If you are unsure whether you are reading the most current version, please contact us.
16. Cookie Policy
This Cookie Policy applies to any websites which are operated by or on behalf of LC Group ("Websites").
By using and accessing our Websites, you are consenting to our use of cookies in accordance with this Cookie Policy. This Cookie Policy may be updated from time to time. Updates to the Cookie Policy will be posted on our Websites.
If you do not agree to our use of cookies as set out in this Cookie Policy you should disable the cookies associated with our Websites by changing your browser settings accordingly.
However, you may not be able to enter certain part(s) of the Websites, and some of the functions and services may not be able to function without cookies. This may also impact your user experience while on our Websites.
What are cookies?
Cookies are small files containing a string of characters that is sent to your computer when you visit our Websites.
Depending on the type of cookies, they may store user preferences and other information.
What do we use cookies for?
- We use cookies to track information such as the number of users and their frequency of use, profiles of users and their preferred sites.
- We use cookies to make the Websites easier to use and to better tailor our products and services to your interests and needs. Cookies may also be used to help speed up your future activities and experience on our Websites.
- When you interact with us on our Websites, we may collect for the purposes of analysis statistical information from which individuals cannot be identified ("Aggregate Information"), such as number of users, their frequency of use, the number of page views (or page impressions) that occur on the Websites and common entry and exit points into and out of the Websites.
- We use such statistical information to understand how people use our Websites and to help us improve their structure and contents. We cannot identify you personally from this information.
We use the following categories of cookies on our Websites and digital platforms:
- Strictly necessary cookies – required for our Websites and the Keenai Wealth app to function. They enable core features such as secure login and account access and cannot be disabled.
- Analytical and performance cookies – these allow us to recognise and count visitors, understand how our Websites are navigated, and identify areas for improvement. We use Google Analytics for this purpose. Data collected is aggregated and does not identify individual users.
- Targeting cookies – these record your visits to our Websites and the links you have followed, enabling us to provide advertising more relevant to your interests. We may share this information with advertising partners for the same purpose.
- Marketing pixels – we embed tracking pixels in direct marketing emails sent to Keenai platform users. These track delivery, opening and link clicks to measure campaign performance. You can control receipt of such emails through your privacy settings in the Keenai Wealth app.
You can manage your cookie preferences through your browser settings. Disabling strictly necessary cookies may prevent access to certain features of our Websites. Other organisations, such as advertising networks, may also use cookies to track you across different websites; we do not control those cookies.
If you access our services through the Keenai application, the app may use device identifiers and similar tracking technologies. You can manage your tracking preferences at any time through your device settings or the privacy settings within the Keenai application.
In-App Embedded Content
The Keenai application contains embedded web views – web pages that load within the app rather than in an external browser – used for certain features including onboarding flows, Open Banking integrations, and informational content. When you interact with these embedded web views, cookies and similar tracking technologies may operate in accordance with our Cookie Policy above. Data collected through in-app web views is handled in the same manner as data collected through our Websites and is subject to the same purposes and safeguards described in this Policy.
1Lighthouse Canton — Alternative Investment Funds (AIF)
