Data Protection

Privacy Data Protection Notice

Last Updated: 1 August 2025

Evernet Systems Private Limited ("Evernet", "we", "us") is committed to protecting your personal data in accordance with the Personal Data Protection Act 2012 of Singapore ("PDPA"). This Privacy & Data Protection Notice outlines how we collect, use, disclose, protect, and retain your personal data.

1Scope and Applicability

This Notice applies to all individuals whose personal data is in our possession or under our control, including:

  • Clients and prospective clients
  • Website visitors and users of our digital platforms
  • Suppliers, partners, and contractors
  • Job applicants and event participants

This policy does not apply to employee data, which is governed under separate internal HR policies.

1.1 Our Role as a Data Intermediary

For the managed IT services we provide, we may process personal data on behalf of our clients. In such cases, Evernet acts as a "Data Intermediary" under the PDPA. Our clients, as the "Data Controllers," are responsible for obtaining the necessary consents for the data they entrust to us. Our processing of such data is governed strictly by our service agreement with the client.

2Collection of Personal Data

We collect personal data through the following channels:

  • Online forms submitted via our website (e.g., "Contact Us", support forms)
  • Direct communications with our team (e.g., phone, email, chat)
  • Account registration or service onboarding
  • Use of client portals and service platforms
  • Job applications and resume submissions
  • Events, surveys, or newsletter subscriptions
  • Automatically via cookies or analytics tools

3Types of Personal Data Collected

The types of personal data we may collect include:

  • Name, contact number, email address
  • Job title, company name, business address
  • IP address, browser/device information
  • Login credentials for client platforms
  • Billing or payment-related data
  • Support ticket history and chat transcripts

Note: We do not intentionally collect NRIC/FIN/passport numbers unless specifically required for lawful business or regulatory purposes.

4Purpose of Use

Your personal data may be collected and used for the following purposes:

  • Responding to enquiries or requests for quotations
  • Delivering managed IT services and support
  • Account creation, authentication, and billing
  • Sending service updates, maintenance notices, or security advisories
  • Managing client relationships and contractual obligations
  • Conducting due diligence and onboarding checks
  • Improving our website and digital platforms
  • Complying with legal, regulatory, or audit requirements
  • Job application evaluation and recruitment

5Consent and Withdrawal

We obtain consent before collecting, using, or disclosing your personal data, except where permitted or required by law. By engaging our services and voluntarily providing your personal data, you are deemed to have consented to its use for the purposes outlined in this Notice.

You may withdraw your consent at any time by contacting our Data Protection Officer (DPO) (see Section 11). Upon withdrawal, we may be unable to continue providing certain services.

6Disclosure and Transfer of Data

We may disclose personal data:

  • To trusted service providers and technology partners who perform services on our behalf. These may include providers of data hosting (e.g., Microsoft Azure), backup solutions (e.g., Probax), cybersecurity platforms (e.g., CrowdStrike), and client support tools.
  • To regulators, government agencies, or law enforcement where required.
  • To affiliated entities or subcontractors strictly on a need-to-know basis.

Where personal data is transferred outside Singapore, we ensure that the recipient provides a standard of protection that is at least comparable to the PDPA.

7Access and Correction Requests

You have the right to:

  • Request access to your personal data
  • Request correction of inaccurate or incomplete data

Please email our DPO with the nature of your request. We may require verification of your identity and will respond within a reasonable timeframe (typically 30 days).

8Retention of Personal Data

We retain personal data only as long as necessary for the purposes for which it was collected or to satisfy legal, regulatory, and business requirements. Data will be securely destroyed or anonymised when no longer required.

9Security Measures

We adopt reasonable administrative, technical, and physical safeguards to protect personal data from unauthorised access, disclosure, or loss. These measures include:

Role-based access controls
Multi-factor authentication
Encryption in transit and at rest
Regular security audits

In the event of a data breach, we will take steps to assess and mitigate the harm and will notify affected individuals and the PDPC where required by law.

10Use of Cookies

Our website may use cookies to improve user experience and analyze site usage. Cookies are small text files placed on your device. You may choose to disable cookies in your browser settings, but this may affect certain functionalities of our website.

11Data Protection Officer (DPO)

If you have any questions about this Notice, or wish to make any access, correction, or withdrawal requests, please contact our Data Protection Officer:

Data Protection Officer

Evernet Systems Private Limited

140 Paya Lebar Road #06-22, Singapore 409015

We may update this Notice from time to time to reflect changes in our practices or legal obligations. All changes will be posted on our website with the updated revision date.