Provider identity
Marketmagnet Communications PTE.LTD. · 230 Victoria Street #15-01 Bugis Junction Towers Singapore (188024) · UEN 202410422G
Privacy
Temporary product-specific working draft. Not legal advice and not approved for public production use.
Marketmagnet Communications PTE.LTD. · 230 Victoria Street #15-01 Bugis Junction Towers Singapore (188024) · UEN 202410422G
Send privacy requests through the contact form and select Legal / privacy.
Open contact formThe contact form uses Cloudflare Turnstile to prevent automated abuse. Technical browser data and the IP address may be shared with Cloudflare. Finasca sends the challenge token to Cloudflare Siteverify for verification; the contact form name, email address, and message are not sent to Siteverify.
This working draft describes the website, company applications, merchant accounts and invoice-related portals with references to the Swiss Federal Act on Data Protection (FADP) where the Swiss FADP applies. The operator details above do not alone determine the applicable privacy rules. The countries actually served and applicable requirements, including any Singapore requirements applicable to the identified operator and the GDPR where its scope applies, need separate assessment. This does not select the operator’s domicile, contractual governing law or venue.
The operator identified above is the entity referred to as Finasca for its own processing purposes in this notice. For company applications, account administration, its own contract and billing records, support, platform security and abuse prevention, Finasca generally determines its own purposes. For merchant-directed buyer, invoice, reminder and dispute data, the merchant is generally the controller and Finasca the processor. The merchant’s privacy notice explains its sale, invoicing and follow-up purposes. Any separate Finasca purposes involving that information would need their own description. These roles and the DPA draft annex in the merchant terms must be confirmed against actual operations.
Data may concern merchants, users, contacts, buyers, or debtors. It is obtained directly from those people, supplied by the relevant merchant or its integration, or generated through use of the platform. For merchant-supplied data, the merchant must satisfy its own transparency and lawful-basis duties.
Data can include account, role, contact, and company details; project and contract data; buyer name, email, phone, and billing address; order, invoice, amount, currency, due-date, reference, and line-item data; payment status and buyer-submitted evidence; disputes and messages; delivery and communication events; consent, verification, risk, audit, security, and integration data. Free text and uploads must not contain unnecessary sensitive data.
For its own platform administration, Finasca uses information to review company applications, provide account access, administer contracts, bill its own services, provide support, secure the service, prevent abuse and diagnose faults. On merchant instructions, buyer and invoice data is processed to create and display invoices and PDFs, communicate about invoices, reconcile payment status, handle reminders and disputes, and prepare approved evidence. Statutory or separate additional purposes must be documented for each data category.
Where the Swiss FADP applies, consent is not a blanket prerequisite for every private-sector processing activity. Purpose limitation, proportionality, transparency and data security apply; an unlawful infringement of personality rights needs justification. Where consent is required or relied on, it must be separate and sufficiently specific. This notice is not consent. The merchant remains responsible for the basis of its claim and customer communication; legal bases under any additional applicable law must be completed for each purpose.
Finasca does not receive, hold, or transfer customer funds, execute payment transactions, or store payment-card details. Buyers pay the merchant directly. For the workflow, Finasca may process payment-related records such as a reference, status, amount and currency, date, stated method, review or reconciliation information, notes, actor metadata, and submitted evidence. Those records do not mean that Finasca processes the payment itself.
Access is limited to authorized users of the responsible merchant and authorized Finasca roles where required for operations, support, security, or review. Technical vendors may support hosting, database, private file storage, email, or SMS/OTP. Before production use, a reviewed list must identify the vendors actually active, their legal entities, locations, subprocessors, and change process.
Where the Swiss FADP applies, disclosure from Switzerland abroad must meet its requirements. Actual storage and access countries and the applicable protection, such as an adequate level of protection, suitable safeguards or a statutory exception, must be entered in Schedule 3 before binding use. This includes remote access. A provider name or data-centre region alone proves neither a permitted transfer nor processing exclusively in Switzerland.
Duration and deletion depend on the data category, documented purpose, merchant instructions and applicable evidence, accounting or legal duties. The table for applications, accounts, invoices/PDFs, communications, support, security logs and backups remains incomplete. The Swiss ten-year accounting rule applies only where applicable and to records within its scope, not to all platform data. Configured periods do not guarantee automatic deletion: some steps require reviewed manual action, and certain metadata or evidence remains. An open dispute does not justify keeping every item indefinitely.
The current application uses irp_session for a requested signed-in session for up to seven days and finasca_auth_continuation for encrypted login or recovery continuity for up to 15 minutes. finasca_app_locale stores the language choice for up to one year. In restricted private access, finasca_owner_pilot_access binds the access permission to the signed-in session and its expiry. As a convenience feature, an unfinished hosted invoice form can store name, email, phone, company, billing address, selected customer language, and the last step in the browser tab's sessionStorage and restore them after reload; the form remains usable without this storage, and clearing the form removes the draft. Browser settings can block or clear cookies or site storage; the requested login needs its session cookie, while denying draft storage disables restoration. The legal classification of the language preference and draft storage must be confirmed for the actual countries. The current code does not activate advertising cookies or optional analytics. Before adding either, the inventory, notice, and any required prior consent must be updated.
Before a hosted invoice purchase, Finasca may perform a rules-based risk assessment. Input categories include invoice amount and configured limits, merchant approval status, category, and risk level, country and data completeness, contact and address indicators, and earlier activity with the same merchant such as unpaid invoices, disputes, collection cases, bounces, or reused contact details. The result may allow the invoice option, limit it, require phone OTP, or hide it. Authorized roles can change the stored decision with a recorded reason. The system does not thereby decide whether a claim is legally valid. Whether Article 21 FADP or additional applicable automated-decision rules apply needs assessment. An available override does not mean every case receives human review. Any required contact and review process for affected people remains to be established.
Finasca uses role- and tenant-scoped access controls, protected sessions, audit events, and technical safeguards. No system is completely secure. Specific storage, scanning, backup, incident, or vendor assurances apply only when verified and documented in the actual deployment.
Subject to the applicable conditions, people can request access, correction or deletion, object to processing and, where applicable, request data delivery or portability. Consent can be withdrawn. Where the Swiss FADP applies, access information is generally provided within 30 days and without charge, subject to statutory exceptions. Identity may be checked proportionately. Requests concerning merchant data must be handled with the responsible merchant, with Finasca’s assistance. Reports can be made to the Federal Data Protection and Information Commissioner (FDPIC) where it is the competent authority. Finasca’s working privacy contact and operational responsibilities still need to be completed.
Material changes to purposes, roles, risk assessment, vendors, countries, storage technology, or retention require an updated notice. The final notice must state its effective date, version history, and any required advance notification.
No final version configured yet.
Temporary working draft, not legal advice, and not approved for public production use. Replace it or have it expressly approved by qualified counsel. Still unresolved: final lawyer-approved legal content in the deployed source, lawyer review and approval, authorized representative, another required item, terms version, privacy notice version.