Privacy policy

Healthy Tec — operated by NZmark Pte. Ltd. Last updated: January 1, 2026

This Privacy Policy explains how NZmark Pte. Ltd. (UEN 202411974C), operating under the brand "Healthy Tec" ("NZmark", "we", "us", "our"), collects, uses, discloses and protects personal data in compliance with the Personal Data Protection Act 2012 of Singapore ("PDPA").

It applies to: websites and Platforms (the "Platform"), as well as offline events, workshops and programmes we conduct with our partner Active Ageing Centres ("AACs") and other community partners ("Partners") (together, the "Services").

1. Our Roles Under the PDPA

1.1 Organisation (data controller). NZmark acts as an independent organisation for account, gameplay, Crystal, Dyad and Website enquiry data, and for data we use for our own service improvement, content development and (with consent) publicity purposes.

1.2 Data intermediary. Where we process personal data on behalf of and on the instructions of a partner AAC under a written Data Processing Addendum, we act as that AAC's data intermediary.

In both roles we apply the same standard of security and care.

2. Personal Data We Collect

Seniors: display name, age band, AAC affiliation, language preference and login credentials; gameplay data (activity completion, scores, rankings, Crystal balance, timestamps); voucher redemption records.

Dyad Partners (family, friends, caregivers): name, email, relationship to the linked Senior; interaction and feedback logs.

Partner staff and volunteers: name, work email, role, centre location; administrative logs (e.g. redemption approvals).

Website visitors and enquirers: name, email, phone and organisation details you provide via contact or sign-up forms.

Technical data (all users): device, browser, operating system, IP address, and access timestamps, collected for security, troubleshooting and service integrity.

Observation and insight records: notes and records generated when authorised NZmark personnel observe Platform engagements or attend Partner sessions (see Section 5.4), recorded in de-identified or aggregated form wherever practicable.

Publicity materials (consent-based): photographs, video, audio and testimonials captured at programme events, where you have given consent (see Section 5.5).

We do not collect biometric data, health-screening data or clinical data, and we do not administer any cognitive risk survey on the Platform.

3. Purposes of Collection, Use and Disclosure

We collect, use and disclose personal data to:

3.1 operate the Website and Platform and the 12-month engagement cycle, including account creation, Dyad pairing, activity delivery and multi-language support (English, Chinese, Malay);

3.2 administer Crystals, lucky draws and voucher redemption;

3.3 produce aggregated, de-identified dashboards and reports for AAC Partners, grantors and funders (including government grant reporting and audit);

3.4 carry out Programme Observation and Insights — observing how participants engage with activities on the Platform and at Partner sessions, in order to improve usability and accessibility, develop new games, activities and content, and train facilitators (see Section 5.4);

3.5 with your express consent, use success stories, testimonials, photographs and videos for publicity, marketing and educational purposes (see Section 5.5);

3.6 send you programme updates and, where you have not opted out, newsletters about future programmes;

3.7 maintain security, prevent fraud and misuse, and troubleshoot; and

3.8 comply with legal, regulatory, audit and funder obligations.

4. Legal Bases

We rely on: (a) consent given at sign-up or via specific consent forms; (b) deemed consent by notification in limited cases where we have clearly notified the purpose and given you a reasonable opportunity to opt out; and (c) legitimate interests for security, fraud prevention and anonymised analytics, where the benefit outweighs any adverse effect on the individual. You may withdraw consent at any time (see Section 10); withdrawal of consent for core functions may mean you cannot continue in the programme.

5. How Specific Activities Are Handled

5.1 Dyad sharing. A Senior's progress is shared with their linked Dyad Partner only with the Senior's consent, withdrawable at any time.

5.2 Leaderboards. Display names appear on in-game leaderboards and at AAC ceremonies by default; you may opt out at any time without affecting rewards eligibility.

5.3 AI processing. Limited non-personal operational prompts may be processed through Google Gemini. No Senior personal data, gameplay identifiers or Dyad data are sent to, or used to train, any AI model.

5.4 Programme Observation and Insights. Authorised NZmark personnel may access and observe engagements on the Platform and attend Partner sessions and workshops to understand how activities are used and to inform content development. These observations: (a) are limited to the purposes in Section 3.4; (b) are not clinical monitoring — we do not assess or record inferences about any individual's cognitive or physical health; (c) are recorded as de-identified or aggregated insights wherever practicable; (d) at Partner premises, take place with the Partner's knowledge and agreement and under our data processing arrangements with that Partner; and (e) are accessible only to authorised personnel on a need-to-know basis.

5.5 Publicity and educational use. By default, we describe programme outcomes and pilot results only in aggregated, de-identified form. Any use of material that identifies you — your name, image, voice, story or testimonial — in our publications, website, social media, presentations or educational materials requires your express written consent via a media/publicity release form (or the consent of a person lawfully authorised to act for you). You may withdraw this consent at any time with prospective effect by emailing PDPA@Healthy-tec.com; materials already published or distributed may remain in circulation. Photography or videography at events is signposted, and you may ask not to be photographed or filmed.

6. Disclosure of Personal Data

We do not sell personal data. We disclose personal data only to:

  • your AAC — in aggregated, de-identified form by default; identified data only where necessary for programme administration and permitted under our arrangements with the AAC;

  • grantors and funders (e.g. government bodies) — for audit and grant reporting, in de-identified form wherever possible;

  • vetted service providers under confidentiality obligations — hosting, communications, voucher fulfilment and analytics providers; and

  • authorities and professional advisers — where required by law or reasonably necessary to protect rights, safety or property.

7. Hosting, Cross-Border Transfers and Security

7.1 Personal data is hosted by our service providers on servers in Singapore. If we ever need to transfer personal data outside Singapore, we will do so only in accordance with the PDPA's transfer limitation obligation, ensuring the recipient is bound by legally enforceable obligations providing a comparable standard of protection.

7.2 We maintain administrative, technical and physical safeguards appropriate to the sensitivity of the data, including encryption in transit and at rest, role-based access controls, logical separation of Partner data, and incident response procedures.

8. Data Breach Notification

If a data breach occurs that is notifiable under the PDPA (likely to result in significant harm, or of significant scale), we will notify the Personal Data Protection Commission and affected individuals as required. Where we act as a data intermediary, we will notify the relevant Partner organisation without undue delay.

9. Retention

Personal data is retained for the active 12-month programme cycle and for up to 12–24 months thereafter for audit and funder-reporting purposes, unless a longer period is required by law (e.g. financial records). Thereafter, personal data is securely deleted or anonymised. Aggregated, de-identified data may be retained indefinitely.

10. Your Rights

You may: (a) request access to your personal data and information about how it has been used or disclosed in the past year; (b) request correction of errors or omissions; and (c) withdraw consent for any purpose, on reasonable notice. To exercise these rights, contact our Data Protection Officer (Section 12). We respond within 30 days; if we need longer, we will tell you.

11. Cookies

The Website and Platform use: (a) strictly necessary cookies (login and navigation); (b) performance cookies (understanding which features are used, to improve the interface); and (c) functional cookies (remembering language preferences). You can manage cookies through your browser settings; disabling them may limit features such as persistent login and reward tracking. We do not use cookies for third-party advertising.

12. Data Protection Officer

Data Protection Officer NZmark Pte. Ltd. (Healthy Tec) 68 Circular Road, #02-01, Singapore 049422 Email: PDPA@Healthy-tec.com (general enquiries: Team@Healthy-tec.com)

13. Updates to This Policy

We may update this Policy from time to time. Material changes will be notified on the Platform and, where practicable, by email. The "Last updated" date above shows the latest revision. Continued use of the Services after changes take effect constitutes acceptance.

gradient

Innovative tools for the elderly and caregivers

© 2026 - Healthy 💎 Tec by NZmark - all rights reserved

gradient

Innovative tools for the elderly and caregivers

© 2026 - Healthy 💎 Tec by NZmark - all rights reserved

gradient

Innovative tools for the elderly and caregivers

© 2026 - Healthy 💎 Tec by NZmark - all rights reserved