Data protection notice for employees (H_IS_SG)

August 2026


This Data Protection Notice sets out the basis on which Technoform Bautec Asia Pacific Pte Ltd collects, uses, discloses or otherwise processes the personal data of our employees, in accordance with the Personal Data Protection Act 2012 (“PDPA”). It applies to personal data in our possession or under our control, including personal data held by organisations we have engaged to process it on our behalf. 

In this Notice, “employees” means all persons engaged in a contract of service with us (whether part-time, temporary or full-time), as well as interns and trainees working at or attached to us, and references to “employment” apply equally to internships and traineeships.

 

1  Data Controller 

The organisation responsible for the processing of your personal data is:

Technoform Bautec Asia Pacific Pte Ltd
6 Temasek Boulevard, #28-06 Suntec Tower Four, 
Singapore 038986

T +65 6273 9595
E info [dot] tesg [at] ap [dot] technoform [dot] com (info[dot]tesg[at]ap[dot]technoform[dot]com)

For any questions regarding data protection, you may contact our Data Protection Contact using the details set out in Section 5 at any time.

2  Purpose and legal basis

We process your personal data on the basis of the PDPA and all other laws relevant to us in matters of data protection. Where we rely on your consent, you may withdraw it at any time (see Section 4). Where permitted under the PDPA, we may also collect, use or disclose your personal data without consent — for example, in reliance on the legitimate interests exception, or where required or authorised by law.

2.1  Employment relationship

We store information about our employees that is necessary for human resource administration and the remuneration process, including:

  • master data and contact details;
  • health data;
  • remuneration and bank account data;
  • Central Provident Fund (CPF) and statutory contribution data;
  • family-related information and next-of-kin details;
  • job application data;
  • contract data;
  • time recording and leave information;
  • training and qualification information;
  • travel and expense data.

This data is processed to perform obligations under, or in connection with, your contract of employment. Without the provision of the required data, it is not possible to carry out and manage the employment relationship. We may also be legally obliged to process personal data (for example, for tax, CPF or statutory reporting), in which case processing is carried out to comply with those legal requirements. Where sensitive personal data (such as health data) is processed, we do so only to the extent necessary for the employment relationship or as permitted under the PDPA.

Personal data of employees is generally retained for the duration of the employment relationship and for so long as necessary to satisfy applicable statutory retention periods. Where statutory retention obligations no longer apply and further processing is no longer necessary to carry out or manage the employment relationship, the personal data may be deleted.

2.2  Microsoft 365

We use Microsoft 365 for internal data processing and management, as well as for communication with customers and business partners. In this context, the credentials and professional contact details of employees are stored in this system. We rely on our legitimate interests in organising data management and collaboration within the company as the basis for this processing under the PDPA.

On a voluntary basis and at your discretion, you may provide a profile picture, further contact details and personal information in your Microsoft profile. If you do so, we will treat this as your consent, which you may withdraw at any time by deleting the data you have provided. Please contact us if you require assistance. Please note that, apart from your direct colleagues, employees of other group companies, customers and business partners may also have access to the above data.

2.3  IT security

As part of our security measures, we maintain various log protocols within our IT systems. These are used for troubleshooting and to provide evidence of the collection, modification and deletion of data. The following categories are logged:

  • device data;
  • access data;
  • user data.

We rely on our legitimate interest in the secure operation of IT systems and on legal requirements to ensure the integrity, confidentiality and availability of data (accountability). Log data for IT security is generally deleted after 90 days at the latest. Log data connected with accountability evidence is deleted in accordance with applicable statutory requirements. In cases of reasoned concern, data may be retained until the matter has been clarified.

2.4  Access control

As part of our security measures, our office premises are equipped with an automatic access control system. The following data is logged for this purpose:

  • finger print and facial recognition data;
  • names;
  • arrival and departure times.

We rely on our legitimate interest in securing our office premises, and on legal requirements to ensure the integrity, confidentiality and availability of data, as the basis for this processing.

2.5  Publications

We process the following categories of personal data as part of our internal and external corporate communications:

  • credentials;
  • contact details;
  • image and video recordings;
  • any other information you may provide.

This data is processed for public relations and for advertising Technoform products and services on the basis of your voluntary consent. Your images, videos or other information may be used in internal or external communications, including on our website, intranet, in publications, brochures and information folders, on posters, at trade fairs, and on the internet, including the social media channels of the Technoform Group. Such data is generally processed only for as long as necessary for the stated purposes. Although we actively distribute the data to a limited extent only, content may remain available online after the end of a campaign (for example, on social media). We also archive such content and delete it after the end of applicable retention periods, or earlier if you withdraw your consent.

2.6  Employee welfare and health promotion

As part of our employee welfare programme, we may work with various partners, such as gyms, insurers and other benefit providers. The following data may be processed for this purpose:

  • names;
  • addresses;
  • contact details;
  • dates of birth;
  • contract and benefit details.

This data is processed to perform obligations in connection with the welfare benefits made available to you, and will be deleted after the expiry of applicable retention obligations. Where we share your data with a benefit provider, we do so only to the extent necessary to administer the relevant benefit.

3  Recipients of personal data

We will only disclose your personal data to third parties where this is necessary to fulfil the purposes set out above. Data may be transferred to government authorities and statutory bodies (for example, IRAS, CPF Board or MOM) where required or authorised by law. Data may also be transferred to customers and other business partners to the extent necessary for operational purposes, including the provision of our goods and services.

For the purposes of our bookkeeping, payroll, accounting and other tax-related matters, the relevant and necessary data is transferred to our external service providers and advisers. Where we engage data intermediaries to process personal data on our behalf, we require them, by contract, to protect your personal data in a manner consistent with the PDPA and this Notice.

4  Your rights

Subject to the PDPA and applicable exceptions, you have the following rights in relation to your personal data:

4.1  Withdrawal of consent

The consent you provide for the collection, use and disclosure of your personal data remains valid until withdrawn in writing. You may withdraw consent by submitting a written request to our Data Protection Officer. Upon receipt, we may require reasonable time to process your request and will notify you of the likely consequences of withdrawal. We shall generally seek to process such requests within ten (10) business days. Withdrawing consent does not affect our right to continue collecting, using or disclosing personal data where such processing without consent is permitted or required under applicable law.

4.2  Access and correction

You may request access to a copy of the personal data we hold about you, and information about how it has been used or disclosed, or request that we correct any error or omission in your personal data. Such requests should be submitted in writing to our Data Protection Officer. A reasonable fee may be charged for an access request, and we will inform you of the fee beforehand. We will generally respond within twenty-one (21) business days; if we are unable to do so within thirty (30) days, we will inform you in writing of the time by which we will respond.

4.3  Accuracy of personal data

We generally rely on the personal data provided by you (or your authorised representative). To ensure your personal data remains current, complete and accurate, please inform our Data Protection Officer in writing of any changes to your personal data.

4.4  Protection of personal data

To safeguard your personal data from unauthorised access, collection, use, disclosure, copying, modification, disposal or similar risks, we have implemented appropriate administrative, physical and technical measures. These include minimised data collection, authentication and access controls, encryption, up-to-date antivirus protection, regular patching, secure disposal of storage media, and the use of two-factor or multi-factor authentication. While no method of transmission or storage is completely secure, we continually review and enhance our information security measures.

4.5  Retention of personal data

We retain your personal data for as long as necessary to fulfil the purposes for which it was collected, or as required or permitted by applicable law. We will cease to retain your personal data, or remove the means by which it can be associated with you, as soon as it is reasonable to assume that retention no longer serves those purposes and is no longer necessary for legal or business purposes.

4.6  Transfers of personal data outside Singapore

We generally do not transfer your personal data to countries outside Singapore. However, where we do so — including transfers to other companies within the Technoform Group — we will ensure that the receiving party is bound by legally enforceable obligations to provide a standard of protection comparable to that under the PDPA, and will obtain your consent where required.

5 Data Protection Contact

You may contact our Data Protection Contact if you have any enquiries or feedback on our personal data protection policies and procedures, or if you wish to make any request in relation to your personal data:

Lianna Seah
Contact number: 6273 9595
Email: info [dot] tesg [at] ap [dot] technoform [dot] com (info[dot]tesg[at]ap[dot]technoform[dot]com)

6  Validity and modification of this Notice

This Notice is currently valid (see date in the heading) and applies in conjunction with any other policies, notices, contractual clauses and consent clauses relating to the collection, use and disclosure of your personal data by us. Due to the further development of our offerings, or changes in legal or regulatory requirements, it may become necessary to amend this Notice from time to time without prior notice. You may determine whether any revision has taken place by referring to the date on which this Notice was last updated. Your continued employment with us constitutes your acknowledgement and acceptance of any such changes.