Data Security and Confidentiality Policy
1. Commitment to Confidentiality
BY DESIGN is committed to maintaining the confidentiality and security of all customer data. We handle all customer information in compliance with the Personal Data Protection Act (PDPA), ensuring that such data is used solely for the purpose of completing sales transactions and providing the agreed services.
2. Purpose of Data Collection
Customer particulars (e.g., name, contact information, NRIC numbers) are collected solely for the following purposes:
- Completing sales transactions
- Coordinating project-related activities
- Ensuring smooth communication during the renovation process
We do not use customer data for any purposes beyond those stated without explicit consent from the customer.
3. Data Security
BY DESIGN has implemented strict internal policies to ensure the security of customer data:
- All customer information is stored securely on our internal systems, accessible only to authorized personnel.
- Physical and digital records are safeguarded to prevent unauthorized access, misuse, or breaches.
- Customer data is stored in secure systems that are regularly reviewed and updated for security at least annually.
- Any personal data shared digitally (e.g., via WhatsApp for drawings approval) is used only for work-related purposes and is securely stored.
- Customer data is retained for a minimum of 3 years after the completion of the project, after which it is securely deleted or archived.
4. Disclosure of Information
Customer data will not be shared with third parties unless required for project completion (e.g., engaging external contractors) and with the customer’s prior consent. We ensure that any third parties involved in our work comply with applicable data protection laws and standards.
5. Staff Training
All employees handling customer data are trained during onboarding and undergo annual training on data protection and confidentiality policies to ensure adherence to the highest standards.