PRIVACY POLICY

Exquisvin.com
Effective Date: 29 September 2025
Exquisvin Pte. Ltd. (UEN: 202428945G)
Registered Address: Holland Rd, Singapore

Exquisvin Pte. Ltd. ("Exquisvin," "we," "us") is committed to safeguarding your privacy and protecting your personal data. This Privacy Policy sets out how we collect, use, disclose, and protect personal data in connection with our website www.exquisvin.com (the "Website") and our membership programmes ("Fellowship").

1. Compliance

By accessing or using www.exquisvin.com (the “Site”) and related services including auctions, Fellowship memberships, vineyard leasing, and bespoke bottlings (the “Services”), you agree to be bound by these Terms & Conditions (“Terms”). If you do not agree, you must not use the Site or Services.

2. Personal Data We Collect

We may collect the following categories of personal data:
- Identity and contact details (name, email, phone number, address, date of birth/age verification)
- Account and Fellowship data (membership account details, preferences, auction participation)
- Transaction and payment data (invoices, confirmations, order history). We do not store full credit card details; payments are securely processed by third-party providers (e.g., Stripe, PayPal).
- Device and usage data (IP address, browser type, cookies, analytics)
- Marketing and communication preferences.

3. Purposes of Collection and Use

We collect and use personal data for the following purposes:
- To manage Fellowship memberships and accounts
- To facilitate wine auctions, vineyard leasing, and related services
- To process payments and arrange deliveries
- To provide customer service and respond to enquiries
- To conduct age and eligibility verification
- To improve Website functionality and user experience
- To send marketing and promotional communications (with consent)
- To comply with applicable laws and regulations

4. Legal Basis Under the PDPA

We process personal data on the basis of:
- Consent provided by you
- Deemed consent (including by notification) where applicable
- Legitimate interests, balanced with safeguards to protect your rights

5. Marketing, DNC and Unsubscribe

We comply with the Do-Not-Call (DNC) Registry and the Spam Control Act. Marketing communications are sent only in accordance with the law. You may opt out of marketing communications at any time by using the “unsubscribe” facility in our messages or by contacting us. We will honour your preferences and respect DNC Registry status.

6. Cookies and Analytics

We use cookies and similar technologies to:
- Enable essential website functions
- Collect analytics to measure performance
- Provide personalised marketing (with consent)

Users may manage cookie preferences through their browser settings or our cookie consent manager, which allows you to accept or reject non-essential cookies.

7. Data Retention

We retain personal data only as long as necessary for the purposes collected:
- Transactional and accounting records: up to seven (7) years
- Marketing data: until consent is withdrawn
- Analytics and logs: typically 12–24 months
After expiry, data will be securely deleted or anonymised.

8. Data Security

We implement reasonable administrative, technical, and physical safeguards, including:
- Transport Layer Security (TLS) encryption for data in transit
- Access controls and role-based permissions
- Secure vendor agreements (Data Processing Agreements)
- Regular security reviews and audits

9. Cross-Border Data Transfers

Where personal data is transferred outside Singapore (e.g., cloud hosting, CRM platforms, analytics providers, payment processors), we ensure that such data continues to receive a standard of protection comparable to that under the PDPA. This is achieved through contractual undertakings and appropriate safeguards.

10. Your Rights: Access, Correction and Withdrawal

You have the right to:
- Request access to personal data held about you
- Request correction of inaccuracies
- Withdraw consent to the continued use of your personal data (subject to the consequences of such withdrawal)

We aim to respond to all requests within thirty (30) days. Please direct such requests to our Data Protection Officer (details below).

11. Data Breaches

In the event of a notifiable data breach, we will promptly notify the Personal Data Protection Commission (PDPC) and affected individuals in accordance with legal requirements.

12. Minors and Age Restriction

Our services are intended strictly for individuals aged eighteen (18) years and above. We do not knowingly collect data from minors.

13. Business Transfers

If Exquisvin undergoes a merger, acquisition, or sale, personal data may be transferred as part of the transaction, provided that the receiving party is bound to comparable protection obligations.

14. Data Protection Officer (DPO)

Exquisvin Pte. Ltd.
Email: contact@exquisvin.com
Registered Address: Holland Road, Singapore

15. Changes to This Policy

We may revise this Privacy Policy from time to time. Updates will be published on this page with a new effective date. Continued use of our Website after such updates constitutes acceptance of the revised terms.