- Introduction
- Singapore Personal Data Protection Act (PDPA)
- Indonesia Personal Data Protection Law (UU PDP No. 27 of 2022)
- Scope
- Employees and staff
- Management
- Customers and clients
- Vendors and suppliers
- Contractors and consultants
- Any authorised third-party users
- Types of Personal Data Collected
- Full name
- NRIC/FIN/Passport (employees where required)
- Contact number and email address
- Residential address
- Employment details (designation, salary, attendance, leave records)
- Bank details (for payroll and payments)
- Vendor and customer contact details
- System login credentials and activity logs
- IP address and access history
- Financial and transaction records
- Purpose of Collection
- HR management and payroll processing
- Project management and resource planning
- Procurement and vendor management
- Customer management and invoicing
- Accounting, taxation, and audit purposes
- System security, monitoring, and access control
- Legal and regulatory compliance
- Consent
- Disclosure of Personal Data
- Internal departments within SHRITECH
- Government authorities when legally required
- Auditors, tax agents, and professional advisors
- ERP software vendors and IT service providers
- Banks and financial institutions for payment processing
- Cross-Border Data Transfer
- Data Security
- Role-based access control
- Password protection and authentication
- Data encryption and secure servers
- Access logs and monitoring
- Regular system backups
- Data Retention
- User Rights
- Access their personal data
- Request correction of inaccurate data
- Withdraw consent where applicable
- Request deletion where legally permissible
- Updates to This Policy

