1. Scope of this policy
This policy applies to personal information that AC GREYSER ENGRG SERVICES collects through this website, through enquiries that arrive by email or telephone, and through the engineering work we perform for clients. It covers the information of website visitors, prospective clients, existing client contacts, suppliers, subcontractors and applicants who approach us about employment or partnership. It does not cover information that our clients collect about their own staff and customers, because each client is an independent controller of that data. Where we process client data as part of a commissioned system, such as production records held inside a control platform we have built, we act on the documented instructions of that client and this policy describes that role in general terms.
This policy also describes the choices available to individuals and the steps we take internally so that information is handled consistently. We review the scope regularly, because the systems we design for clients often change and our own service offering grows with them.
2. Who we are
AC GREYSER ENGRG SERVICES is a computer integrated systems design practice operating from Singapore. Our registered address is AC GREYSER ENGRG SERVICES, 34 MARSILING DRIVE, #09-381, Singapore - 730034, Singapore (SG). Our contact email is enquiries@acgreysereng.buzz and our telephone number is +12627478595. The website at acgreysereng.buzz is maintained by the developer AC Greyser Eng on behalf of the company.
For the purposes of applicable data protection law, AC GREYSER ENGRG SERVICES is the organisation responsible for the personal information described in this policy, unless we state otherwise in a specific notice. When we perform engineering work that involves personal information belonging to a client organisation, we handle that information only to deliver the agreed service and we follow the instructions of that client.
3. Information we collect
The information we hold is limited to what is reasonably needed to answer enquiries, deliver services and run a responsible business. The categories below describe what we may collect.
- Identity information such as name, job title, employer and the department a contact works within.
- Contact information such as email address, telephone number and correspondence address.
- Business information such as company name, industry sector, site location and the nature of a production line.
- Project information such as specifications, drawings, fault histories and requirements shared during a project.
- Communication records such as emails, meeting notes and call summaries relating to an enquiry or contract.
- Billing information such as invoicing details and purchase order references needed to complete payment.
- Technical information such as device type, browser version and approximate location derived from a network address.
- Recruitment information such as a curriculum vitae, qualifications and references supplied by an applicant.
We do not seek sensitive categories of information such as health data, religious belief or political opinion. If such information is volunteered to us without request, we will limit its use to the purpose for which it was shared and will not add it to any general record.
4. How we collect information
Most of the information we hold arrives directly from the individual concerned. A visitor completes the contact form on this website or sends an email to our enquiries address. A client contact provides details during a line review, a site survey or a commissioning visit. A supplier sends a quotation that includes the name of an account manager. An applicant submits a curriculum vitae.
We also collect limited technical information automatically when a browser requests a page, such as the network address, the browser family and the time of the request. This information supports security, capacity planning and fault diagnosis, and it is not used to build advertising profiles.
In some cases a client organisation provides us with the name and contact details of its own staff so that we can arrange site access or training. In that situation we rely on the client to have informed those individuals, and we use the details only for the agreed purpose.
5. Why we use information
We use personal information for clear operational reasons that a reasonable person would expect from an engineering consultancy. The main purposes are set out below.
- To respond to enquiries, quotations and requests for a line review.
- To prepare proposals, contracts and interface schedules.
- To deliver design, integration, commissioning and support services.
- To arrange site visits, training sessions and acceptance testing.
- To issue invoices, manage payment and keep proper accounting records.
- To maintain the safety and reliability of our own systems and website.
- To meet legal, tax and regulatory obligations that apply to our business.
- To consider applications for employment or subcontracting.
- To send service updates to clients who hold an active contract with us.
We do not use personal information for purposes that are unrelated to these activities, and we do not sell personal information to any party.
6. Legal bases for processing
Where the law requires a legal basis for processing, we rely on one or more of the following. Consent applies where an individual has clearly agreed to a specific use, such as opting in to receive a newsletter. Contract applies where processing is necessary to prepare or perform an agreement with the individual or with the organisation that individual represents. Legal obligation applies where we must keep records for tax, accounting or safety purposes. Legitimate interests applies where processing supports the responsible operation of our business, such as responding to a business enquiry or protecting our systems, provided that those interests are not overridden by the rights of the individual.
When we rely on legitimate interests we consider the nature of the information, the expectation of the individual and the impact of the processing, and we apply safeguards such as data minimisation and short retention periods.
7. Consent and how to withdraw it
Where we rely on consent, that consent must be freely given, specific and informed. An individual may withdraw consent at any time by writing to enquiries@acgreysereng.buzz or calling +12627478595. Withdrawal does not affect processing that took place before the withdrawal, and it does not affect processing that relies on another legal basis, such as the performance of a contract.
If withdrawing consent means we can no longer provide a service that depends on the information, we will explain the consequence before the withdrawal takes effect so that the individual can make an informed choice.
10. International transfers
Our practice is based in Singapore and most of our information stays within Singapore. Some service providers used for website hosting, email delivery or file storage may operate systems in other countries. When information moves across a border, we take steps to ensure that it continues to receive an appropriate standard of protection. Those steps may include contractual commitments, an assessment of the destination legal regime, or the use of providers that maintain recognised certifications.
Where a client project requires remote diagnostics that reach equipment outside Singapore, we limit access to the technical data needed for the task and we follow the security instructions of the client that owns the plant.
11. How long we keep information
We keep personal information only for as long as it is needed for the purpose for which it was collected, or for as long as the law requires. The periods below describe our general approach.
- Enquiries that do not lead to work are kept for a reasonable period and then removed from active systems.
- Client project records are kept for the duration of the contract and for a defined period afterwards to support warranty and support obligations.
- Accounting and tax records are kept for the period required by applicable law.
- Recruitment records for unsuccessful applicants are kept for a limited period and then deleted.
- Website security logs are kept for a short period sufficient to investigate incidents.
When a retention period ends, information is deleted or anonymised so that it can no longer be linked to an individual. Where deletion is not immediately possible because information is held in a backup archive, we isolate the archive and delete the information when the archive is next refreshed.
12. How we protect information
We apply technical and organisational measures that are proportionate to the sensitivity of the information and to the risk of harm if it were misused. Access to client and contact records is restricted to personnel who need it for a defined task. Accounts are protected by individual credentials, strong authentication where available, and prompt removal of access when a role changes or ends. Devices are kept current with security updates and are protected against unauthorised use.
Written procedures cover how we handle a suspected incident. If a breach occurs that is likely to result in significant harm, we investigate promptly, contain the effect, and notify affected individuals and the relevant authority where the law requires it. We also review the cause and adjust our controls so that the same weakness is not repeated.
No method of transmission over the internet is perfectly secure. We therefore ask that individuals do not send highly sensitive information through ordinary email, and we provide secure alternatives when a project requires the exchange of confidential plant data.
13. Your privacy rights
Depending on the law that applies, an individual may have the right to be informed about how personal information is used, to request access to the information held, to request correction of information that is inaccurate, to request deletion where there is no continuing lawful reason to keep it, to restrict or object to certain processing, to receive information in a portable format, and to withdraw consent where consent is the basis for processing. An individual also has the right not to be subject to a decision that is based solely on automated processing that produces a legal or similarly significant effect. We do not use such automated decision making in our practice.
These rights are not absolute. A request may be refused where the law permits, for example where information must be retained for a legal obligation or where disclosure would reveal information about another person. Where a request is refused we explain the reason.
14. Making an access or correction request
A request to access or correct personal information should be sent to enquiries@acgreysereng.buzz or by post to AC GREYSER ENGRG SERVICES, 34 MARSILING DRIVE, #09-381, Singapore - 730034, Singapore (SG). Please describe the information concerned and the action requested, and provide enough detail for us to verify identity. Verification protects the individual, because it prevents an unauthorised person from obtaining information that belongs to somebody else.
We aim to respond within the period allowed by applicable law. If a request is complex or covers a large volume of information we may need more time, and we will explain the delay and keep the individual informed. Where a reasonable fee is permitted for producing records, we will state the amount before carrying out the work.
15. Privacy for children
Our services are provided to businesses and professional organisations. This website is not directed at children and we do not knowingly collect personal information from children. If we learn that we have collected information from a child without appropriate consent, we will delete it promptly. A parent or guardian who believes that a child has provided information to us should contact enquiries@acgreysereng.buzz so that we can investigate and take the necessary action.
16. Direct marketing
We send service updates and occasional technical notes to contacts who have asked for them or who hold an active contract with us. Every message explains how to stop receiving further communication, and a request to opt out is honoured promptly. We do not buy contact lists and we do not add individuals to a marketing list simply because they sent a one time enquiry that did not proceed.
Where the law requires prior consent for electronic marketing, we obtain that consent before sending. Where the law permits communication with an existing business contact, we still provide an easy way to end it.
17. Third party services and links
This website may link to external sites that are not operated by AC GREYSER ENGRG SERVICES. We do not control those sites and we are not responsible for their privacy practices. A visitor who follows such a link should read the privacy notice of the destination site. Where we embed a third party tool, such as a map or a document viewer, we choose providers that respect privacy and we limit the information shared to what the tool requires.
Where a client asks us to integrate a third party cloud platform into a line, we support the client in reviewing the terms and the data flow of that platform, because the client remains responsible for the personal information that flows through its own plant.
18. Changes to this policy
We review this policy regularly and update it when our practices, our systems or the law change. The date at the top of the page shows when the current version took effect. If a change is significant, we will provide a clearer notice on the website or by direct communication to clients who hold an active contract. Continued use of the website after an update indicates acceptance of the revised policy.
Previous versions are retained internally so that we can demonstrate how our practices have developed over time.
19. How to contact us
Questions, concerns or complaints about privacy should be directed to the following. Email enquiries@acgreysereng.buzz. Telephone +12627478595. Post to AC GREYSER ENGRG SERVICES, 34 MARSILING DRIVE, #09-381, Singapore - 730034, Singapore (SG). We take complaints seriously and will investigate promptly. If an individual is not satisfied with our response, they may refer the matter to the data protection authority in the jurisdiction where they live or work.
Back to the homepage