Privacy Policy

SL2 Impact Limited

SL2 Impact Limited (“SL2 Impact”, “we”, “us”, or “our”) the organisation behind Repair Kopitiam, respects your privacy and is committed to protecting your personal data in accordance with the Personal Data Protection Act 2012 (“PDPA”) of Singapore.

This Privacy Policy explains how we collect, use, disclose, protect and otherwise process your personal data when you visit our website, contact us, participate in our programmes or services, or otherwise interact with us.

This Privacy Policy applies to personal data in our possession or under our control, including personal data processed on our behalf by third-party service providers.

1. Personal Data We Collect

Personal data” means data, whether true or not, about an individual who can be identified: (a) from that data; or (b) from that data and other information to which we have or are likely to have access.

Depending on the nature of your interaction with us, we may collect personal data such as your full name, residential address, email address, telephone/mobile number, nationality, gender, photograph, audio, video recordings, year of birth, the last five characters of your NRIC (where required), payment and billing information, race, emergency contact or next-of-kin information, feedback, enquiries and correspondence, information submitted through forms, surveys, events.

Where personal data relating to minors is collected, SL2 Impact may require consent from parents, guardians or authorised representatives where appropriate or required by law.

2. How We Collect Personal Data

We generally collect your personal data when you:

  • submit an enquiry through our website;
  • register for or participate in our events, training programmes, workshops or services;
  • communicate with us by email or other channels;
  • provide information during the course of receiving our services; or
  • voluntarily provide information to us directly or through an authorised representative.

Where required under the PDPA or other applicable laws, we will obtain your consent before collecting, using or disclosing your personal data. We will also seek your consent before collecting additional personal data or using your personal data for purposes that have not been notified to you, unless such collection, use or disclosure is permitted or authorised by law.

3. Purposes for Collection, Use and Disclosure

We may collect and use your personal data for any or all of the following purposes:

1. Events and Training Programmes

  • processing registrations, applications, bookings, and requests;
  • providing, managing, and administering our services, training programmes, workshops, and activities;
  • managing your account and related services;
  • maintaining accurate records for operational and administrative purposes; and
  • health and safety management.

2. Communication and Engagement

  • responding to, handling, and processing your queries, requests, applications, complaints, and feedback;
  • sending administrative, operational or service communications;
  • managing and maintaining our relationship with you; and
  • obtaining feedback and survey responses.

3. Security, Compliance and Operational Purposes

  • verifying your identity;
  • managing internal operations, including accounting, auditing, reporting, and record-keeping; and
  • detecting, preventing, and addressing fraud, security risks, misuse, or other unlawful activities.

4. Regulatory and Compliance Requirements

  • fulfilling reporting and compliance requirements requested by government agencies, including the Ministry of Health (MOH) or the Agency for Integrated Care (AIC);
  • complying with applicable laws, regulations, guidelines, and requirements from regulatory or governmental authorities; and
  • responding to requests from authorised public agencies or third parties where permitted or required by law.

5. Other Purposes

  • any other purposes that are reasonably necessary or directly related to the purposes stated above, or for which consent has been obtained.

The purposes listed in the above clauses may continue to apply even in situations where your relationship with us (for example, pursuant to a contract) has been terminated or altered in any way, for a reasonable period thereafter (including, where applicable, a period to enable us to enforce our rights under a contract with you).

4. Disclosure of Personal Data

We may disclose your personal data where necessary for the purposes described in this Privacy Policy, including to:

  • venue owners, venue operators and venue organisers involved in the organisation, administration and delivery of our events, training programmes, and activities;
  • government agencies and public authorities, including the People's Association (PA), the Ministry of Health (MOH), and the Agency for Integrated Care (AIC), where required for programme administration, reporting or compliance with applicable laws;
  • third-party service providers who provide IT, website hosting, cloud storage, communications or administrative support services on our behalf; and
  • professional advisers, auditors or regulators where disclosure is required or permitted by law.

Where third-party vendors or service providers process personal data on our behalf, SL2 Impact will take reasonable steps to ensure that appropriate data protection obligations are implemented.

We will not sell, rent, or trade your personal data to any third party.

Sharing data about other people: If you give us personal data about a third party, such as your next-of-kin, caregiver, or another household member, you confirm that you have informed that individual and obtained their consent for us to collect, use, and disclose their personal data for the purposes described in this Privacy Policy.

5. Cross-Border Transfer

SL2 Impact may transfer personal data outside Singapore where necessary for operational, administrative, or technological purposes.

Where personal data is transferred overseas, SL2 Impact will take reasonable steps to ensure that the transferred personal data receives a standard of protection comparable to that under the PDPA.

6. Cookies

Cookies are small text files stored on your device when you visit a website. We use cookies and similar technologies to recognise your device, monitor website performance, and understand how visitors interact with our website.

Through these technologies, we may automatically collect information such as your Internet Protocol (IP) address, browser information, device information, pages visited, and the date and time of your visit. This information is used for statistical analysis, website improvement, and enhancing user experience.

We do not use cookies for marketing, targeted advertising, or behavioural tracking purposes.

You can also disable cookies by changing your website browser settings to reject cookies. Please note that disabling cookies may affect certain website functionalities or limit our ability to collect website usage information for performance improvement purposes.

For more detailed information about the cookies we use, please refer to our Cookie Policy.

7. Protection of Personal Data

We have implemented appropriate administrative, technical, and physical measures to protect your personal data from unauthorised access, collection, use, disclosure, copying, modification, disposal, or similar risks. These measures are implemented in accordance with PDPC guidelines and include:

  • Access controls: Access to personal data is restricted to authorised personnel on a need-to-know basis and need-to-basis data disclosure;
  • Data minimisation: Only personal data that is necessary for programme participation;
  • Data anonymisation: Where appropriate, personal data may be anonymised or aggregated for analysis, reporting, or evaluation purposes, such that individuals cannot be readily identified; and
  • Encryption: Data is encrypted in transit and at rest to ensure end-to-end protection of all transmitted information.

You should be aware, however, that no method of transmission over the Internet or method of electronic storage is completely secure. While security cannot be guaranteed, SL2 Impact strives to protect the security of your information and are constantly reviewing and enhancing our information security measures.

8. Accuracy of Personal Data

We generally rely on personal data provided by you (or your authorised representative). In order to ensure that your personal data is current, complete and accurate, please update us if there are changes to your personal data by informing our Data Protection Officer in writing or via email at the contact details provided below.

9. Retention of Personal Data

SL2 Impact will retain personal data only for as long as reasonably necessary to fulfil:

  • the purposes for which the data was collected;
  • legal or regulatory requirements;
  • operational and business purposes;
  • dispute resolution and audit requirements; or
  • investigations, legal proceedings or regulatory requirements.

When personal data is no longer required, SL2 Impact will take reasonable steps to securely destroy, anonymise or dispose of the data.

10. Photography & Videography

SL2 Impact events, training programmes, and activities may involve photography, audio recording, and videography by SL2 Impact and/or third parties engaged by, authorised by, or working with SL2 Impact for the following purposes:

  • news reporting;
  • publicity, marketing, and outreach purposes;
  • event documentation and record-keeping; and
  • organisational communications.

Such photographs, audio recordings, and videos may be published or used by SL2 Impact and/or such third parties in:

  • print materials;
  • websites;
  • social media platforms;
  • online platforms; and
  • other communication channels.

By participating in an SL2 Impact event, training programme, or activity, individuals acknowledge that they may be photographed, audio-recorded, or video-recorded by SL2 Impact and/or third parties engaged by or working with SL2 Impact.

Individuals who do not wish to be photographed or recorded should inform SL2 Impact before or during the relevant event, where reasonably practicable, or contact us using the details provided in this Privacy Policy.

11. Your Rights

You (or your authorised representative) may, at any time, request:

  • Access the personal data about you that is in our possession or under our control; or
  • Correct any personal data about you that is inaccurate, incomplete, misleading, or not up to date.

We may require reasonable verification of identity before processing such requests.

Please note that a reasonable fee may be charged for an access request. If so, we will inform you of the fee before processing your request.

You may submit your request in writing or via email to our Data Protection Officer at the contact details provided below.

We will respond to your request as soon as reasonably possible. In general, our response will be within ten (10) business days. Should we not be able to respond to your request within thirty (30) days after receiving your request, we will inform you in writing within thirty (30) days of the time by which we will be able to respond to your request. If we are unable to provide you with any personal data or to make a correction requested by you, we shall generally inform you of the reasons why we are unable to do so (except where we are not required to do so under the PDPA).

12. Withdrawal of Consent

The consent that you provide for the collection, use and disclosure of your personal data will remain valid until such time it is being withdrawn by you in writing. You may withdraw consent and request us to stop collecting, using and/or disclosing your personal data for any or all of the purposes listed above by submitting your request in writing or via email to our Data Protection Officer at the contact details provided below.

Upon receipt of your written request to withdraw your consent, we may require reasonable time (depending on the complexity of the request and its impact on our relationship with you) for your request to be processed and for us to notify you of the consequences of us acceding to the same, including any legal consequences which may affect your rights and liabilities to us. In general, we shall seek to process your request within ten (10) business days of receiving it.

Whilst we respect your decision to withdraw your consent, please note that depending on the nature and scope of your request, we may not be in a position to continue providing our goods or services to you and we shall, in such circumstances, notify you before completing the processing of your request.

13. Contacting Us

You may contact our Data Protection Officer if you have any enquiries or feedback on our personal data protection policies and procedures, or if you wish to make any request, in the following manner:

Data Protection Officer

Name: Nur Azrina

Email Address: [email protected]

14. Updates to this Policy

SL2 Impact may update or amend this Policy from time to time to ensure that it remains consistent with:

  • operational practices;
  • technological developments;
  • legal and regulatory requirements; and
  • PDPC guidance.

The latest version of this Policy will be published on Repair Kopitiam’s website.

Last updated: 25/08/2026

Copyright © 2026 Repair Kopitiam. All rights reserved.

Privacy Policy | Cookie Policy