01

How we protect your data

Keenai maintains the following technical and organisational controls, independently audited under our ISO 27001, ISO 27017, ISO 27018, and SG Cyber Safe certifications:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256)

  • Role-based access with least-privilege principles

  • Multi-factor authentication on staff and client accounts

  • Segregated production environments with immutable audit logging

  • Annual penetration testing and continuous vulnerability management

  • Formal incident-response plan with regulator-notification workflow

  • Staff training on data handling, phishing resistance, and confidentiality, refreshed annually

While we take all reasonable steps to ensure your personal data is kept secure, we cannot guarantee security during transmission. We use HTTPS (TLS) for all app, web, and payment-processing services. Please keep your account password or passphrase confidential and do not share it with anyone.

02

How long we keep your data

We retain personal data only as long as necessary for the purposes set out above, and for the minimum periods mandated by Singapore law. Typically:

  • A minimum of five (5) years from the end of the client relationship for records supporting regulated financial services and AML obligations

  • Seven (7) years where required by anti-money laundering or applicable financial laws

  • Twenty-four (24) months for platform telemetry and usage data

We may retain data for longer because of a potential or ongoing court claim, or for another legal reason. Upon expiry of the applicable retention period, personal data is securely deleted or irreversibly anonymised.