Legal — Privacy
Privacy notice
What this covers
This notice explains how ZYT Pte. Ltd. handles personal data collected through this website, zyt.one, under Singapore’s Personal Data Protection Act 2012 (the “PDPA”).
It covers this site only. Our two platforms publish their own notices, because they hold far more data than a brochure site does: TavaSIS and EsgaSIS.
Data Protection Officer
Section 11 of the PDPA requires every organisation to designate someone responsible for its compliance, and to make that person’s business contact publicly available. Ours is reachable at dpo@zyt.one.
What we collect
When you use the contact form
Your name, your email address, and whatever you write in the message. Nothing else — there are no hidden fields, and we do not ask for anything we do not need in order to reply to you.
When you simply read the site
Aggregate traffic measurements only: which pages were viewed, roughly where in the world the visit came from, what kind of device it was, and which site referred it. This is counted in aggregate, is not tied to you, does not build a profile, and does not follow you to other websites. See Cookies and analytics below.
Why we hold it
To reply to your enquiry, and to continue the conversation it starts. If that leads to work together, the data supports the engagement. We use aggregate traffic data only to understand which parts of the site are read.
We do not sell personal data, and we do not send marketing to people who have not asked for it. Writing to us is not a subscription to anything.
Consent, and withdrawing it
We rely on the consent you give by sending us your details, and on the exceptions the PDPA provides for data supplied voluntarily for an obvious purpose. You may withdraw consent at any time by writing to our Data Protection Officer. We will act on it, and tell you what withdrawing means in practice — chiefly that we can no longer respond to an open enquiry.
Who else processes it
Each is a processor acting on our instructions. There are no advertising networks, no data brokers and no third-party tracking scripts on this site.
We do not publicly name our individual service providers. If you want to know which specific provider handles a particular category of your data, ask our Data Protection Officer at dpo@zyt.one and we will tell you.
Transfers out of Singapore. Sending us a message means personal data is processed outside Singapore — email delivery is handled in Tokyo, and site hosting is distributed globally. Where personal data leaves Singapore we take reasonable steps, as section 26 of the PDPA requires, to satisfy ourselves that the recipient is bound by legally enforceable obligations to protect it to a standard comparable to the PDPA. In practice that means contractual data-protection terms with each of the providers above.
How long we keep it
Section 25 of the PDPA requires us to stop keeping personal data once the purpose it was collected for has ended and no legal or business reason to retain it remains. Keeping things indefinitely is a breach in itself, so we do not.
Cookies and analytics
Our web server provides our analytics, and the service was chosen specifically because it does not use cookies and does not fingerprint visitors. It does not track people across sites, and it collects no personal data.
This site sets no cookies at all. That is why you are not being asked to accept any — there is nothing here that consent would be about. If that ever changes, we will say so here first.
Your rights
Under the PDPA you may:
- Ask what we hold about you, and how it has been used or disclosed in the past year.
- Ask us to correct anything inaccurate or incomplete.
- Withdraw your consent to our continued use of it.
- Ask us to delete it, where we have no remaining basis to keep it.
Write to dpo@zyt.one. We will respond within 30 days, and tell you sooner if a request will take longer than that. We may need to verify who you are first. The PDPA permits a reasonable fee for an access request; for a request of ordinary size we do not charge one.
There are narrow cases where the PDPA requires or permits us to refuse — for instance where releasing the data would reveal personal data about someone else. If that applies we will say so, and say why.
If we do not resolve it. Write to our Data Protection Officer first, so we have the chance to put it right. If you are still not satisfied, you may complain to the Personal Data Protection Commission at pdpc.gov.sg.
Security
The site is served over HTTPS, form submissions are encrypted in transit, and our mail credentials are held as secrets by our host rather than in any published file. Access to the inbox is limited to the people who need it.
We will not claim more than that. No system is immune, and we are a small company. What we can say is what we do: least-privilege access, no more data collected than the job needs, and nothing retained past its purpose.
If there is a data breach
Part 6A of the PDPA makes breach notification mandatory, and we treat that as a floor rather than a target. If a breach is likely to result in significant harm to you, or affects a significant number of people, we will notify the Personal Data Protection Commission and the people affected, without undue delay.
Changes to this notice
If we change how we handle personal data, we will update this page and change the date at the top. Where a change materially affects data we already hold about you, we will tell you directly rather than relying on you to re-read this page.
Contact
ZYT Pte. Ltd.
UEN 202424324W
22 Sin Ming Lane #06-76, Midview City, Singapore 573969
Data protection: dpo@zyt.one
General enquiries: service@zyt.one
This notice is founder-drafted and pending formal legal review. ZYT recommends obtaining independent legal advice, particularly in relation to cross-border data transfers.