VERSION 2026-07-17.3
Privacy Notice
This Privacy Notice explains how FCN Risk Lab collects, uses, discloses, protects and retains personal data, and the choices available to you.
Who operates FCN Risk Lab
FCN Risk Lab is a product developed, owned and operated by ActivEdge Solutions Pte. Ltd. (UEN 202107711M), with registered office at 1 North Bridge Road, #06-29, High Street Centre, Singapore 179094 ("ActivEdge", "we", "us" or "our"). ActivEdge is the organisation responsible for personal data handled through the service.
Scope and an important data boundary
FCN Risk Lab is an account-based product-risk analytics service for regulated financial-advisory professionals. It does not require client profiles or client suitability questionnaires and does not need a client’s identity, finances, objectives or personal circumstances. ActivEdge holds no historical client-profile records. Do not enter or upload personal data about a client or any other third party. Remove names, account numbers, contact details and other identifiers from a term sheet before uploading it.
Personal data we collect
- Professional-access data: whether you declare that you are regulated, your regulatory jurisdiction and authority, professional registration identifier, full name, email address, optional company name, declaration and acceptance timestamps, application source, verification and account status, and invitation-delivery records.
- Account and authentication data: your Firebase user identifier, verified email, display name, account and security timestamps, and session records. Google Firebase processes your sign-in credentials. ActivEdge does not receive or store your plaintext password or full password.
- FCN workspace data: product names or labels, issuers, underlyings, product terms, uploaded term sheets, assessments, reports, monitoring settings, alerts, and model and market-data timestamps. This is product information and must not contain client personal data.
- Credit and payment records: credit balances and activity; checkout, purchase and fulfilment references; package, currency, amount and payment status; and limited Stripe customer, checkout and payment identifiers. Stripe collects and processes payment-card details; FCN Risk Lab does not store full card details.
- Communications and delivery data: messages you send us, support and privacy correspondence, the email address used for a requested report, and email-delivery status or provider identifiers.
- Technical, security and optional landing-page analytics data: essential session cookies, IP address and request metadata that may appear in hosting or security logs, access events, request identifiers and audit records needed to operate, secure and troubleshoot the service. If you allow analytics on the marketing landing page, Google Analytics also receives device and browser information, approximate location derived from IP address, referral source, landing-page views and interactions with links and calls to action. FCN Risk Lab does not send names, email addresses, professional identifiers or form-field contents to Google Analytics.
How we collect and use personal data
We collect personal data directly from you, automatically when you use the service, and from service providers when they confirm authentication, email or payment events. We use it to assess professional-access eligibility; create, authenticate, administer and secure accounts; prevent duplicate or unauthorised registrations; provide, save and monitor FCN product-risk assessments; generate and deliver requested reports; manage credits and purchases; keep operational and evidence records; diagnose faults; prevent misuse; answer requests or complaints; enforce our Terms; and comply with legal obligations. With your optional analytics consent, we also measure marketing landing-page performance, referral sources, calls-to-action and completed professional-access applications so we can improve the page. Depending on the circumstances, we rely on consent, deemed consent, legitimate interests, legal obligations or another basis permitted by the PDPA. We do not sell personal data, use uploaded term sheets for advertising, or use advertising cookies.
Disclosure and service providers
We disclose personal data only where reasonably necessary for the purposes above, to complete an action you request, to protect the service or legal rights, or where required or permitted by law. Current providers include Google Cloud and Firebase for authentication, hosting, databases, logs and document storage; Google Analytics for consented marketing landing-page measurement; Stripe for checkout and payment processing; and Resend for account and report email delivery. Public market-data services receive ticker or company queries, not your identity or uploaded term sheets. Each provider may process data under its applicable service terms and privacy notice. We may also disclose information to professional advisers, regulators, courts, law-enforcement bodies or a successor in a corporate transaction where legally permitted and reasonably necessary.
Overseas processing
Primary application, database and document-storage resources are configured in Singapore. Google, Stripe, Resend or their support and subprocessors may process personal data outside Singapore. We rely on applicable law and the providers’ standard contractual, data-protection and transfer commitments; ActivEdge has not separately negotiated bespoke overseas-transfer agreements with them. Where the PDPA applies, we take the steps required by law to ensure transferred personal data receives a standard of protection comparable to the PDPA, unless a lawful exception applies.
Retention
Subject to a legal hold, dispute, investigation or longer period required by law, the following schedule applies:
- Unsuccessful or duplicate access submissions: no applicant account or workspace record is retained by FCN Risk Lab; minimal hosting and delivery events remain in operational logs for 30 days, while an email provider may retain delivery records under its own policy.
- Professional registration, eligibility and declaration records: while access remains active and for 5 years after access ends. These records are retained separately to evidence eligibility and declarations, prevent registration misuse, resolve disputes and meet legal or compliance needs.
- Account and FCN workspace data: while the account is active. When you complete in-product account deletion, live account, workspace and stored document versions are deleted as part of that process, except for the separate records identified in this schedule.
- Database backups and transaction logs: deleted database data may remain in access-restricted backups and transaction logs for up to 7 days before expiry.
- Sessions: a session normally expires after 12 hours; expired session records are purged no later than 7 days after expiry.
- Cloud request and security logs: 30 days, unless relevant records are preserved for a specific security incident, dispute or legal requirement.
- Google Analytics: event-level landing-page analytics data is retained for 2 months. The first-party
_gabrowser cookie may remain for up to 2 years unless you withdraw consent, clear it or your browser removes it sooner. - Support, complaint and privacy-request correspondence: 24 months after the matter is closed.
- Payment, tax and accounting records: at least 5 years from the relevant Year of Assessment, or longer where law requires. Stripe may separately retain transaction data under its terms and legal obligations.
At the end of the applicable period, data is deleted, anonymised or made inaccessible. Records preserved for a legal hold or mandatory requirement are restricted to that purpose and removed when the requirement ends.
Your choices and rights
From Account & privacy, you can correct your display name, request a password-change email, download your account and FCN workspace data, revoke sessions, or delete your account and live workspace data. You can correct FCN terms through the relevant product workflow. Contact us to request access to or correction of other personal data, withdraw consent with reasonable notice, ask a privacy question or make a complaint. We may need to verify your identity before acting. Legal exceptions may apply, and withdrawing consent may prevent us from continuing to provide some or all of the service.
Cookies and analytics choice
FCN Risk Lab uses an essential, secure session cookie to keep you signed in and protect account access. On the marketing landing page, Google Analytics is optional and does not load unless you select “Allow analytics”. If allowed, it uses first-party analytics cookies such as _ga to distinguish browsers and measure aggregate visits and conversions. It is configured without Google Signals or advertising personalisation, and professional-access form contents are not sent. Select “No thanks” to continue without analytics. You can withdraw consent by clearing the site’s local storage and analytics cookies in your browser; the choice will be presented again on your next visit.
Security and data breaches
We use verified-email authentication, role and tenant access controls, encryption in transit, restricted storage, audit records, rate limits and security monitoring. You must keep your credentials secure and notify us promptly of suspected unauthorised access. No system is completely secure, and absolute security cannot be guaranteed. We assess suspected data breaches and notify the Personal Data Protection Commission and affected individuals when the PDPA requires it.
Changes to this notice
We may update this notice to reflect changes to the service, providers or legal requirements. Material changes will be versioned and presented for acceptance where appropriate.
Contact and Data Protection Officer
ActivEdge has designated admin@fcnrisklab.com as its privacy and Data Protection Officer contact. Use this address for access, correction, withdrawal, complaints or other privacy questions. You may also write to ActivEdge Solutions Pte. Ltd., 1 North Bridge Road, #06-29, High Street Centre, Singapore 179094.