Privacy notice
How Tenor handles personal data
Last updated September 2026. This notice is issued under the Personal Data Protection Act 2012 (Singapore).
Who we are
Tenor Analytics Pte. Ltd. (UEN 202643182K) ("Tenor", "we") arranges and services instalment plans for elective healthcare. For plan data we act as a data intermediary for the funding vehicle that is your creditor and, for certain purposes, as an organisation in our own right. Our Data Protection Officer can be reached at dpo@tenor.sg.
What we collect
- Identity and contact details verified through Singpass.
- Income and credit information, including a credit bureau enquiry, for the affordability assessment.
- The category of your procedure and the amount financed. We do not collect your diagnosis, clinical notes or treatment details.
- Payment history and our communications with you, including the recorded confirmation call.
- Aggregate website usage (pages viewed, referring site, country, device type) through Cloudflare Web Analytics, which sets no cookies and does not identify or track you across sites. We do not use advertising trackers.
Why, and on what basis
We process your data with your standalone written consent, given at enrolment, to assess your application, disclose and administer your plan, service and collect instalments, meet legal obligations, and — if the receivable is assigned to a replacement funder or servicer — to transfer the associated data so your plan continues uninterrupted.
Who we share it with
The funding vehicle that is your creditor and its trustee; the credit bureau; our payment, telephony and e-signature providers under contract; and regulators or courts where required. Your clinic receives only what it needs to reconcile settlement: never your income, bureau or payment history.
Where it is kept and for how long
In Singapore. We retain plan data for seven years after your plan closes, or longer where the law requires, then delete it.
Your rights
You may request access to or correction of your personal data, and withdraw consent (which may mean we cannot continue to administer your plan). Write to dpo@tenor.sg. We respond within 30 days. If you are not satisfied, you may complain to the Personal Data Protection Commission.
Breach notification
If a data breach is likely to result in significant harm to you, we will notify you and the PDPC as the Act requires.