Privacy Policy & Data Protection
Built on decades of experience and dedicated to innovating the real estate industry, SRI offers transformative experiences through a network of exceptional agents.

Last updated: 4 August 2026

PERSONAL DATA

1. As used in this Notice: “customer” means an individual who (a) has contacted us through any means to find out more about any goods or services we provide, or (b) may, or has, entered into a contract with us for the supply of any goods or services by us; and “personal data” means data, whether true or not, about a customer who can be identified:


(i) from that data; or


(ii) from that data and other information to which we have or are likely to have access.


2. Depending on the nature of your interaction with us, some examples of personal data which we may collect from you include your name and identification information such as your contact information such as your address, email address or telephone number, nationality, gender, date of birth, marital status, photographs and other audio-visual information, employment information and financial information such as credit card numbers, debit card numbers or bank account information.


3. Other terms used in this Notice shall have the meanings given to them in the PDPA (where the context so permits).

COLLECTION, USE AND DISCLOSURE OF PERSONAL DATA

4. We generally do not collect your personal data unless (a) it is provided to us voluntarily by you directly or via a third party who has been duly authorised by you to disclose your personal data to us (your “authorised representative”) after (i) you (or your authorised representative) have been notified of the purposes for which the data is collected, and (ii) you (or your authorised representative) have provided written consent to the collection and usage of your personal data for those purposes, or (b) collection and use of personal data without consent is permitted or required by the PDPA or other laws. We shall seek your consent before collecting any additional personal data and before using your personal data for a purpose which has not been notified to you (except where permitted or authorised by law).


5. We may collect and use your personal data for any or all of the following purposes:

(a) performing obligations in the course of or in connection with our provision of the services requested by you;


(b) verifying your identity;


(c) responding to, handling, and processing queries, requests, applications, complaints, and feedback from you;


(d) managing your relationship with us;


(e) processing payment or credit transactions;


(f) sending your marketing information about our services including notifying you of our marketing events, initiatives and promotions, lucky draws, membership and rewards schemes and other promotions;


(g) complying with any applicable laws, regulations, codes of practice, guidelines, or rules, or to assist in law enforcement and investigations conducted by any governmental and/or regulatory authority;


(h) any other purposes for which you have provided the information;


(i) transmitting to any unaffiliated third parties including our third party service providers and agents, and relevant governmental and/or regulatory authorities, whether in Singapore or abroad, for the aforementioned purposes; and


(j) any other incidental business purposes related to or in connection with the above.

6. We may disclose your personal data:


(a) where such disclosure is required for performing obligations in the course of or in connection with our provision of the goods or services requested by you; or


(b) to third party service providers, agents and other organisations we have engaged to perform any of the functions listed in clause 5 above for us.


7. The purposes listed in the above clauses may continue to apply even in situations where your relationship with us (for example, pursuant to a contract) has been terminated or altered in any way, for a reasonable period thereafter (including, where applicable, a period to enable us to enforce our rights under any contract with you).

GOOGLE USER DATA

8. This section applies specifically to SRI Research Plus (also presented as “SRI Research+”), our application for SRI agents, available at plus.sri.sg, and describes how SRI Research Plus accesses, uses, stores, shares and deletes data obtained through Google APIs (“Google user data”). Where anything in this section conflicts with clauses 1 to 7 above, this section prevails in respect of Google user data. Connecting a Google account to SRI Research Plus is entirely optional, and SRI Research Plus is fully usable without doing so.


9. SRI Research Plus offers an optional Google Calendar integration. If, and only if, you choose to connect your Google Calendar, we request the following Google OAuth scopes for the following reasons:

(a) openid and email — to read the email address of the Google account you are connecting, so that we can label the connection in the interface and prevent the same account being connected twice. We do not request access to your Google profile, your name or your photograph;


(b) https://www.googleapis.com/auth/calendar.readonly — to read the events in the calendar you select, so that they can be shown to you in your SRI Research Plus schedule and daily briefing; and


(c) https://www.googleapis.com/auth/calendar.events — to create, update and delete calendar events on your behalf, and only at your direction, when you use SRI Research Plus to schedule a viewing, an appointment or a client follow-up.

10. Where you connect a Google Calendar, the Google user data we store consists of: the email address of the connected Google account; an OAuth access token and refresh token for that account; and, for the calendar you select, the event data returned by Google, which includes each event’s title, description, location, start and end times, link and attendee list (which may include the names and email addresses of other people), together with the underlying event record as returned by the Google Calendar API.

HOW WE USE GOOGLE USER DATA

11. We use Google user data solely to provide and improve the user-facing features of SRI Research Plus that you have asked for, namely:

(a) displaying your calendar events inside SRI Research Plus, including in your schedule and your daily briefing, so that you can see your appointments alongside your listings and your clients;


(b) creating, updating and deleting events in your calendar at your direction, for example when you schedule a viewing or ask SRI Research Plus to set a follow-up reminder for a client;


(c) suggesting client contact records from the attendees of your calendar events, so that you can add them to your SRI Research Plus contacts without retyping them, which involves the automated processing described in clause 15; and


(d) maintaining the connection itself, including refreshing expired access tokens and keeping your selected calendar in sync.

12. We do not use Google user data for any other purpose. Notwithstanding clause 5(f) above, we do not use Google user data for advertising or marketing of any kind. We do not sell, rent or trade it. We do not use it to determine creditworthiness or for lending purposes. We do not use it to train, develop or improve generalised or non-personalised artificial intelligence or machine learning models, whether our own or those of any third party.


13. SRI Research Plus’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

SHARING AND DISCLOSURE OF GOOGLE USER DATA

14. We do not sell, rent or trade Google user data, and we do not transfer or disclose it to any third party for advertising, for data brokerage, for creditworthiness or lending decisions, or for the training of generalised artificial intelligence or machine learning models. Notwithstanding clauses 5(i) and 6 above, Google user data is disclosed only to the following recipients, each of which processes it solely to provide services to us, under contract, and is bound by confidentiality and security obligations:

(a) Vercel Inc., which hosts the SRI Research Plus application and serves requests to it;


(b) Neon Inc., which hosts the database in which the data described in clause 10 is stored;


(c) Anthropic PBC, accessed through the Vercel AI Gateway, which performs the automated processing described in clause 15; and


(d) Functional Software, Inc. (Sentry), our error-monitoring provider, which we have configured not to collect personal data and which does not receive your calendar content.

15. To provide the contact suggestions described in clause 11(c), the title, location, description and attendee list of the relevant calendar event are sent to a large language model operated by Anthropic PBC and accessed through the Vercel AI Gateway, which identifies likely client contact details and returns them to you in SRI Research Plus. Your own email address is removed before the event is sent. This processing occurs only to produce a result displayed directly to you, under terms which do not permit the data to be retained after your request has been served and which do not permit it to be used to train or improve any model.


16. In addition, we may disclose Google user data where we are required to do so by law, regulation, legal process or enforceable governmental request, or where it is necessary to detect, prevent or address fraud, abuse, or security or technical issues. If we are involved in a merger, acquisition or sale of assets, we will continue to protect your Google user data in accordance with this Notice and will obtain your explicit consent before it becomes subject to a different privacy policy.

PROTECTION OF GOOGLE USER DATA

17. We treat Google user data, and in particular your OAuth tokens and your calendar content, as sensitive data, and we protect it as follows:

(a) OAuth access tokens and refresh tokens are encrypted at rest using AES-256-GCM authenticated encryption before being written to our database. They are never stored in plaintext, and the encryption key is held outside the database;


(b) all Google user data in transit, whether between you and SRI Research Plus, between SRI Research Plus and Google, or between SRI Research Plus and the recipients listed in clause 14, is encrypted using TLS;


(c) every calendar connection and every cached event is bound to the account of the agent who created it, and every request for that data is scoped to that account, so that one agent cannot access another agent’s calendar data;


(d) access to our production systems is restricted to those personnel who require it in order to operate and support SRI Research Plus, and is protected by individual authentication;


(e) our error-monitoring tooling is configured not to transmit personal data, so that your calendar content does not appear in our diagnostic logs; and


(f) we do not permit any person to read your Google user data, except where you have given your explicit consent (for example, so that we can troubleshoot an issue you have reported to us), where it is necessary for security purposes such as investigating abuse, or where we are required to do so by law.

RETENTION AND DELETION OF GOOGLE USER DATA

18. We retain Google user data only for as long as your Google account remains connected to SRI Research Plus and the data remains necessary for the purposes set out in clause 11. Your OAuth tokens are retained so that the integration continues to work without requiring you to sign in again, and your calendar events are cached so that your schedule and daily briefing load quickly and remain available to you.


19. You remain in control of this data and may remove it at any time:

(a) you may disconnect your Google Calendar at any time from within SRI Research Plus. On disconnection we revoke our access with Google, permanently delete the stored access and refresh tokens for that connection, and delete the calendar events cached from it. No further data is retrieved from Google;


(b) you may revoke SRI Research Plus’s access to your Google account at any time, independently of us, at myaccount.google.com/permissions, which immediately prevents any further access; and


(c) you may ask us to delete all Google user data we hold about you, and to delete your SRI Research Plus account in its entirety, by emailing admin@sri.com.sg. We will verify and action your request, and complete the deletion, within 30 days.


20. Following deletion, residual copies of Google user data may remain in our encrypted backups for up to 30 days before being overwritten in the ordinary course of business. We retain no Google user data thereafter, except where we are required by law to retain it, in which case we retain only what the law requires, for no longer than it requires. For the avoidance of doubt, clause 7 above does not operate to extend our retention of Google user data beyond the periods described in this section.

© 2026 SRI Pte Ltd • Privacy Policy & Data Protection Terms of Service

Follow us on
iconiconiconiconicon