This is the Cookie Policy of Hotlotz Pte Ltd (Company Number 201524698M), with office address at 28 Jalan Kilang Barat, Singapore 159362 ("us", "we" or "our").
This Cookie Policy forms part of Hotlotz’ Privacy Policy ("Privacy Policy"). If you have any data privacy queries or requests in relation to your personal data, please refer to our Privacy Policy.
1.What are cookies?
Cookies are small data files sent by a website to your computer that are stored on your hard drive when you visit certain online pages of our website. Each cookie is unique to your web browser. It will contain some anonymous information such as a unique identifier and the site name and some digits and numbers.
Cookies may be essential to enable you to move around our website, webpage or mobile application and use its features, which may not work properly, or at all, if you do not allow these cookies to be used. Cookies allow the website to identify and interact with your computer (for example so we can remember your login details if you have opted to 'stay signed in'). For example, some cookies are used by us to collect information about how visitors use our website. We use the information to compile reports and to help us improve our website. The cookies collect information, including the number of visitors to the site, where visitors have come to the site from and the pages they visited. It allows a website to remember things like your preferences or what’s in your shopping basket.
2.The types of cookies that we use:
2.1 Strictly necessary cookies
These cookies are essential to enable you to visit our website and use its features, such as accessing secure areas of the website. Most of the functions on our website will not work properly if you do not allow these cookies to be used. They include, for example, cookies that enable you to log into secure areas of our website and place bids. We may not be able to provide many of the services you may wish to request unless you accept the use of these cookies.
2.2 Performance cookies
These cookies collect information about how visitors use a website, e.g. which pages visitors go to most often. They allow us to recognise and count the number of visitors and to see how visitors move around our website when they are visiting it. This helps us to improve the way our website works, for example, by ensuring that visitors are finding what they are looking for easily. [These cookies do not collect information that identifies a visitor: all information these cookies collect is aggregated and is therefore anonymous. The information is only used to improve how the website works.]
2.3 Functionality cookies
We use third party functionality cookies to personalise our content for you and make your browsing experience more convenient. These cookies allow the website to remember choices you make (such as your username) and provide enhanced, more personal features (for example, remembering changes you have made to text size and fonts). These are used to recognise you when you return to our website. This enables us to greet you by name and remember your preferences for example, your choice of language or region and allow us to customise our site according to your individual interests.
2.4 Targeting cookies
These cookies record your visit to our website, the pages you have visited and the links you have followed. They are anonymous so cannot be used to identify individuals. We will use this information to make our website and the advertising displayed on it more relevant to your interests. We may also share this information with third parties for this purpose.
2.5 Third party advertising and analytics cookies
We use third party analytics software to collect data about traffic to our site and how visitors use our site via a display advertising cookie. The display advertising cookie allows advertising to be targeted to you based on your preferences, browsing habits on our site, the type of ads you show an interest in and other data the third party may collect from your visits to other sites outside the control of Hotlotz. These cookies are used for statistical analysis by allowing the third party to count how many people have seen the advertisement or have seen it more than once, limit the number of times you see an advertisement, and/or help measure the effectiveness of an advertising campaign. They might also allow the third party to tailor advertising to you when you visit other websites. None of these cookies store personally identifiable information and we only use trusted advertising partners. These third parties will have their own privacy policies and they may be different from ours.
3.Your cookies setting
You can set your browser to accept or reject all cookies or notify you when a cookie is sent. If you reject cookies or delete our cookies, you may still use our websites, but you may have reduced functionality and access to certain areas of our websites or your account. Your continued use of our website is your acceptance of our continued use of cookies on our website.
4.Notifications to your mobile devices
We may deliver information or notifications to your phone or mobile device. You can disable these notifications by changing the settings in either the app or on your mobile device.
5.Changes to our cookies policy
We reserve the right to amend or update this Cookies Policy at any time. We will notify users by posting any updated policy on this page and such changes will be effective immediately and without further notice. Where appropriate, we may notify you directly of changes to this Cookies Policy either through email or a prominent notice on our website.
Download
We are currently updating our Sustainability & Environmental policy. Please check back soon.
DownloadHotlotz understands the importance of information about you and your privacy. We conduct our business in compliance with applicable law and have implemented measures to protect your personal information.
This is the Privacy Policy of Hotlotz Pte Ltd (Company Number 201524698M),with office address at 28 Jalan Kilang Barat, Singapore 159362 ("us", "we" or "our").
Our Privacy Policy helps you to understand how we collect, use, share and protect information about you. Respecting and protecting your privacy and your personal data is very important to us.
Your personal data will be held by us in accordance with the Personal Data Protection Act 2012 (“Singapore PDPA”) and the General Data Protection Regulation (“GDPR”), being the data protection laws of Singapore and the European Economic Area (“EEA”) respectively. GDPR applies in the United Kingdom, tailored by the Data Protection Act 2018.
For the purposes of Singapore PDPA/ GDPR, the organisation/ data controller is Hotlotz Pte Ltd.
If you have any questions in relation to this Privacy Policy, please contact us at:
For purposes of GDPR, the name of our representative in the United Kingdom is Ruby Khan with office address c/o DWF, 20 Fenchurch Street, London, EC3M 3AG.
Please read this Privacy Policy to ensure you understand how we will collect and use your personal data and the rights you have in relation to your personal data. This Privacy Policy was last updated on the date above and may vary from time to time so please check it regularly.
This Privacy Policy applies to our processing of personal data in relation to the provision of any of our services. We may collect information about you:
Information about you may include information you provide about any other person in which case you agree that you have already given written notice to that person of the intention to use the information for the purposes and in the manner set out in this Privacy Policy, that you have obtained the written consent of that person to such use or provision of their information and that the intended use of such information in accordance with the Privacy Policy is consistent with and covered by the consent of that person.
Information about you collected by us may include:
Information about you may be collected, used, shared or otherwise processed for the following purposes:
Purpose | Legal basis for processing personal data under GDPR (Please refer to section 5 below) | Legal basis for processing personal data under Singapore PDPA |
your access or use of, or to otherwise provide or administer, our products, services, information, content, features, premises or other business activities (including verifying your identity, eligibility, membership or subscription and selling or purchasing property or services) | Legitimate interests Performance of a contract (for membership or subscription and selling or purchasing property or services) | Consent |
to enter into or perform any contract with you, including processing of any payments, refunds, deliveries and logistics | Performance of a contract | |
notifying you about changes to our products, services, information, content, features, premises or other business activities | Legitimate interests (if you have previously requested or received services) Consent (if you have not requested or received services but have signed up to receive Hotlotz’ marketing materials) | |
responding to enquiries and requests from you or people you have authorised | Performance of a contract | |
forecasting, planning, record keeping, management and administration | Legitimate interests | |
contact relationship management, managing your membership or account and providing you with customer support | Legitimate interests | |
benefit, loyalty, promotional and reward programs | Legitimate interests | |
market research, business and sales analysis or analytics, feedback and satisfaction surveys to improve our products, services, information, content, features or premises | Legitimate interests | |
ensuring that our websites, webpages or mobile applications are presented in the most effective manner for you and your devices | Legitimate interests | |
product and service improvement, enhancement, personalisation, design or development | Legitimate interests | |
training, learning and development | Legitimate interests | |
advising you of forthcoming sales, events, products and services | Legitimate interests (if you have previously requested or received services) Consent (if you have not requested or received services but have signed up to receive Hotlotz’ marketing materials) | |
providing updates, offers, promotions, invitations to events and relevant advertising and informing you about products and services | Legitimate interests (if you have previously requested or received services) Consent (if you have not requested or received services but have signed up to receive Hotlotz’ marketing materials) | |
ensure the safety and security of our properties and systems and other security and risk management or information | Legitimate interests | |
conducting checks against money laundering, terrorism financing and related risks | Compliance with a legal obligation | |
preventing and detecting fraud or other crimes or other wrongdoing or recovering debts | Compliance with a legal obligation | |
conducting internal audits or investigations | Legitimate interests | |
resolving any disputes or in relation to any transaction, demand, order, request, right, enforcement, property or safety issue, claim, proceeding, insurance or other law, regulation or requirements | Legitimate interests | |
in connection with any corporate transaction, such as the sale of our business, a divestiture, merger, consolidation, or asset sale, or in the event of insolvency or the like | Legitimate interests | |
complying with other laws, regulations or requirements, including providing assistance to law enforcement, judicial and other government agencies | Compliance with a legal obligation | |
working with any third party including our service providers (including the ATG group and thesaleroom.com, our whitelabel online auction platform provider) | Legitimate interests |
We may contact you for the above purposes by telephone call, email, text or SMS messaging, post and other means.
We will not use your personal data for purposes other than what we have informed you, or which are permitted under applicable laws and regulations.
For personal data collected in Singapore, our legal basis for processing your personal data is your consent as Singapore PDPA is a consent-based regime.
For personal data collected from individuals residing in the EEA or the United Kingdom, there are a number of different ways that we are lawfully able to process your personal data. We have set these out below.
5.1 Where using your data is in our legitimate interests (“Legitimate interest”)
We are allowed to use your personal data where it is in our interests to do so, and those interests are not outweighed by any potential prejudice to you.
We believe that our use of your personal data is within a number of our legitimate interests, including but not limited to:
We do not think that any of the activities set out in this Privacy Policy will prejudice you in any way. However, you do have the right to object to us processing your personal data on this basis. We have set out details regarding how you can go about doing this in section 7 below.
5.2 Where using your personal data is necessary for us to carry out our obligations under our contract with you (“Performance of a contract”)
We are allowed to use your personal data when it is necessary to do so for the performance of our contract with you, i.e. where processing is necessary for the performance of a contract to which you are a party or in order to take steps at your request prior to entering into a contract.
For example, we need to collect your contact details in order to be able to communicate with you and provide you with some of the services you have requested.
5.3 Where you give us your consent to use your personal data (“Consent”)
We are allowed to use your data where you have specifically consented. In order for your consent to be valid:
As part of our relationship with you, we may ask you for specific consents to allow us to use your data in certain ways. If we require your consent, we will provide you with sufficient information so that you can decide whether or not you wish to consent.
You have the right to withdraw your consent at any time. We have set out details regarding how you can go about this in section 7 below.
5.4 Where processing is necessary for us to carry out our legal obligations (“Compliance with a legal obligation”)
As well as our obligations to you under any contract, we also have other legal obligations that we need to comply with and we are allowed to use your personal data when we need to in order to comply with those other legal obligations.
For example, we are required to carry out anti-money laundering checks about our customers and we need to collect and use certain information about them in order to do so. We also need to make payment of taxation and customs duties and cooperate with regulators, enforcement authorities and the courts.
We may share information about you with:
Your information is disclosed to the above only for relevant purposes mentioned in this Privacy Policy or to protect the interests of our customers.
In some cases, we encrypt, anonymise and aggregate the information before sharing it (removing personally identifiable features or presenting the information in groups or segments).
You have various rights in relation to the data which we hold about you. We have described these below.
To get in touch with us about any of these rights, please contact us at:
We will seek to deal with your request without undue delay, and in any event within thirty days (subject to any extensions to which we are lawfully entitled). Please note that we may keep a record of your communications to help us resolve any issues which you raise.
7.1 Your rights under Singapore PDPA
7.1.1 Right to access and correct your data
You have the right to a copy of the information which we hold about you, including information on how this will be used and to ensure this information is accurate. Please refer to the “Contact Us” section below to communicate your data access or data correction request to us.
7.1.2 Right to withdraw your consent for us to use your personal data for marketing purposes
You also have the right to ask us not to process your personal data for marketing purposes – you can exercise this right by logging into your account and editing your communication preferences in the ‘My Account’ section of hototz.com.
Please note that if you withdraw your consent for us to use and process your personal data in accordance with Singapore PDPA, we may not be able to continue providing our service to you.
7.1.3 Right to complain
For information about data protection generally, or if your concerns are not resolved to your satisfaction, you may contact the Personal Data Protection Commission of Singapore at www.pdpc.gov.sg.
7.2 Your rights under GDPR
The GDPR gives you the following rights in relation to your personal data:
7.2.2 Right to object
This right enables you to object to us processing your personal data where we do so for one of the following reasons:
7.2.3 Right to withdraw consent
Where we have obtained your consent to process your personal data for certain activities (for example, for marketing), you may withdraw this consent at any time and we will cease to use your data for that purpose unless we consider that there is an alternative legal basis to justify our continued processing of your data for this purpose, in which case we will inform you of this condition.
7.2.4 Data subject access requests
You may ask us for a copy of the information we hold about you at any time, and request us to modify, update or delete such information. If we provide you with access to the information we hold about you, we will not charge you for this unless permitted by law. If you request further copies of this information from us, we may charge you a reasonable administrative cost. Where we are legally permitted to do so, we may refuse your request. If we refuse your request we will always tell you the reasons for doing so.
7.2.5 Right to erasure
You have the right to request that we "erase" your personal data in certain circumstances. Normally, this right exists where:
We would only be entitled to refuse to comply with your request for erasure in limited circumstances and we will always tell you our reason for doing so.
When complying with a valid request for the erasure of data we will take all reasonably practicable steps to delete the relevant data.
7.2.6 Right to restrict processing
You have the right to request that we restrict our processing of your personal data in certain circumstances, for example if you dispute the accuracy of the personal data that we hold about you or you object to our processing of your personal data for our legitimate interests. If we have shared your personal data with third parties, we will notify them about the restricted processing unless this is impossible or involves disproportionate effort. We will, of course, notify you before lifting any restriction on processing your personal data.
7.2.7 Right to rectification
You have the right to request that we rectify any inaccurate or incomplete personal data that we hold about you. If we have shared this personal data with third parties, we will notify them about the rectification unless this is impossible or involves disproportionate effort. You may also request details of the third parties that we have disclosed the inaccurate or incomplete personal data to. Where we think that it is reasonable for us not to comply with your request, we will explain our reasons for this decision.
7.2.8 Right of data portability
If you wish, you have the right to transfer your personal data between service providers. In effect, this means that you are able to transfer the details we hold on you to another third party. To allow you to do so, we will provide you with your data in a commonly used machine-readable format so that you can transfer the data. Alternatively, we may directly transfer the data for you.
7.2.9 Right to complain
You have the right to lodge a complaint with our regulator, who is the Information Commissioner's Office in the UK. You can contact them in the following ways:
Please refer to our Cookie Policy.
Your continued use of our website is your acceptance of our continued use of cookies on our website.
We will take all reasonable precautions necessary to protect the security and integrity of all personal information provided to us, or by any other means (electronic or otherwise).
We will ensure that your personal information within Hotlotz’s is suitably protected against misuse, interference and loss; and unauthorised physical or electronic access, modification or disclosure.
These measures include technology to encrypt your login, password and credit information, virus scanning, installation of security patches, backup and recovery planning, employee training, audits and other steps as well as strict verification processes and limits on access to information in our systems and the systems of our business partners and vendors.
Unfortunately, we cannot guarantee that information during transmission through the internet or any computer network is entirely safe from unauthorised intrusion, access or manipulation. There is always risk involved in sending information through any channel over the internet. You send information over the internet entirely at your own risk. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted over the internet and we do not warrant the security of any information, including personal data, which you transmit to us over the internet.
Your information may be collected, used, shared or otherwise processed in or outside the country in which it was collected. Laws in other countries regarding processing of information may be less or more stringent than the laws in the country in which you were located or of collection of the information.
We will also ensure that overseas organisations we work with observe necessary confidentiality and data protection obligations.
9.1 Transfer of personal data outside Singapore
For personal data collected in Singapore, we shall ensure that either
9.2 Transfer of personal data outside the EEA
For personal data collected in the EEA, the data that we collect from you may be transferred to, and stored at, destinations both within and outside the EEA. As discussed above, we may disclose your personal data to our service providers located in Singapore and elsewhere, and to employees operating in Singapore.
We want to make sure that your personal data is stored and transferred in a way which is secure. We will therefore only transfer data outside of the EEA where it is compliant with data protection legislation and the means of transfer provides adequate safeguards in relation to your data. For example, this could be:
Where we transfer your personal data outside the EEA and where the country or territory in question does not maintain adequate data protection standards, we will take all reasonable steps to ensure that your data is treated securely and in accordance with this Privacy Policy.
We hold data and information electronically and in hard copy form, both at our own premises and/or in a cloud server maintained by our cloud service provider(s).
We will not keep your personal data for longer than is necessary for the purposes for which we have collected it, unless we believe that the law or other regulation requires us to keep it (for example, because of a request by a tax authority or in connection with any anticipated litigation) or if we require it to enforce our agreements.
We will hold and retain your personal data for as long as is necessary for the relevant activity, or for as long as is specified in any agreement between you and us or for as long as we provide services to you. Following that period, we will only retain your personal data for as long as is reasonably necessary in the circumstances.
When it is no longer necessary to retain your personal data, we will delete the personal data that we hold about you from our systems. While we will endeavour to permanently erase your personal data once it reaches the end of its retention period, some of your personal data may still exist within our systems, for example if it is waiting to be overwritten. For our purposes, this data has been put beyond use, meaning that, while it still exists in the electronic ether, our employees will not have any access to it or use it again.
Our websites may contain links to other websites not operated by Hotlotz. The information you provide to us will not be transmitted to other websites, but these other websites may collect personal information about you in accordance with their own privacy notice. We cannot accept any responsibility for the privacy practices or content of those websites.
If you access any of our websites, webpages or mobile applications from any of our third party business partners, such as the ATG Group and thesaleroom.com (https://www.the-saleroom.com/en-gb ), or from a third party social platform, such as Facebook, we may share information with that platform to the extent permitted by your agreement with that platform and its privacy settings. We are not responsible for the practices or policies of any other person or organisation (including the ATG Group and thesaleroom.com, our whitelabel online auction platform provider) and recommend that you review their data protection or privacy policies.
We reserve the right to amend or update this Privacy Policy and any of our privacy practices at any time. We will notify users by posting any updated policy on this page and such changes will be effective immediately and without further notice. Where appropriate, we may notify you directly of changes to this Privacy Policy either through email or a prominent notice on our website.
If you have any questions or complaints in relation to this Privacy Policy or our data handling practices, or wish to exercise any of your rights as set out in section 7 above, please contact our Privacy Officer at:
We will provide you with reasons if we refuse any request. We may make a reasonable charge for your request in accordance with applicable laws.
By visiting our website, accessing or using any Hotlotz products, services, information, content, features or premises, you acknowledge that you have read and understood this Privacy Policy and you accept the practices and terms as set out in this Privacy Policy.
For purpose of complying with the Singapore PDPA and the GDPR (to the extent that consent has been identified as the legal basis for processing your personal data), you also provide your consent for us to collect, use, disclose, share and otherwise process your personal data in accordance with this Privacy Policy.
Hotlotz is committed to the fight against money laundering and terrorist financing.
We have robust AML processes in place. We train our staff to be vigilant when dealing with unusual transactions; we ensure that we take appropriate steps to know our clients and business partners.
We perform client and transaction due diligence, monitoring, and record-keeping.
We do not accept payments in cash or by cheque.
Hotlotz only accepts payments from the buyer named on the invoice. We cannot accept third-party payments from an individual or organisation that is not named as the buyer. This includes payments from a spouse or another family member. Hotlotz can only make settlement payments to the individual or organisation named on the Sales Contract.
Clients may also be asked to verify their identity by providing identifying information to Hotlotz, including NRIC/FIN number, passport number, occupation, nationality, address, date of birth and contact number. If we request this information and it is not provided we may terminate a transaction that we have entered into.
Our AML policies are subject to regular review to ensure the proper functioning of our procedures. This is done to protect our clients and our interests. All information is collected in accordance with the Personal Data Protection Act 2012.
Hotlotz is licensed to sell precious stones and precious metals in Singapore (Regulated Dealers Certificate of Registration No. PS20190001021). For further information about this regulation see https://acd.mlaw.gov.sg.
Download