01Scope of This Policy

This policy applies to personal data that RED STONE TECHKNOWLEDGE processes through this website, through direct communication with clients and prospective clients, and through the delivery of systems design, integration, rollout and support services. It covers visitors, enquirers, client contacts, suppliers, contractors and any other individual whose personal data reaches our workshop.

This policy does not cover data that is processed by third party websites that we do not control, even where we link to them. It also does not cover data that we process on behalf of a client under a written services agreement where the client is the controller; in those situations the client privacy notices govern and our obligations are set out in the relevant contract.

02Who We Are

RED STONE TECHKNOWLEDGE is a computer integrated systems design practice operating from Singapore. The organization designs foundations, integration cores, interfaces, data strata, field rollouts and reinforcement contracts for clients across professional, scientific and technical services.

For the purposes of applicable data protection law, RED STONE TECHKNOWLEDGE is the organization responsible for the personal data described in this policy. Our postal address is RED STONE TECHKNOWLEDGE, 449 ANG MO KIO AVENUE 10, #04-1727, Singapore - 560449, Singapore (SG). Our contact email is frontdesk@redstonetech.lat and our contact telephone number is +16676886441.

03Personal Data We Collect

We collect only the personal data that we need for the purposes described in this policy. The categories below describe what that data usually is.

We do not seek to collect special categories of personal data, and we do not ask for data about health, religion, political views, trade union membership or similar matters. If such data is offered to us without request, we will limit its use to the purpose for which it was offered and delete it when that purpose has passed, unless a legal obligation requires otherwise.

04How We Collect Personal Data

Most personal data reaches us directly. You may send an enquiry through the contact form on this website, write to our email address, telephone the workshop, hand over a business card at a meeting, or sign a services agreement. Each of those acts creates a record that we hold for the reasons set out in this policy.

Some data is collected automatically when this website is used. Our hosting environment records standard server information such as the address from which a request arrived, the time of the request and the resource requested. This information is used to keep the website available and secure, and it is not used to build a profile of an individual.

We may also receive personal data from a colleague at a client organization, from a supplier who introduces a contact, or from a public source such as a company register. When we receive data from someone other than the individual concerned, we handle it under the same rules and we tell the individual about our processing when we first communicate with them.

05Lawful Bases for Processing

Where data protection law requires a lawful basis, we rely on one or more of the following. First, performance of a contract, which covers processing needed to quote for, deliver, invoice and support a project. Second, legitimate interests, which covers running the workshop, answering enquiries, securing our own systems and improving our services, provided that those interests are not overridden by individual rights.

Third, consent, which covers optional activities such as receiving a newsletter or agreeing to a photograph being published. Consent can be withdrawn at any time, and withdrawal does not affect processing that happened before the withdrawal. Fourth, legal obligation, which covers record keeping, tax, accounting and responses to lawful requests from public authorities.

Where we process data because a client has asked us to act on their behalf, the lawful basis is most often the client contract, and the client remains responsible for the underlying basis on which the data was originally collected.

06Purposes of Processing

We process personal data to respond to enquiries, prepare quotations and build plans, deliver systems design work, coordinate field rollouts, provide support under reinforcement contracts and manage the commercial relationship that surrounds all of it. Processing is also needed to keep accurate records of what we designed, what we changed and what we promised, because that record is central to the way the workshop operates.

We use contact data to communicate about active work, to send invoices and receipts, to arrange site access, and to notify clients about matters that affect their systems. We use technical data to protect the website and to understand which pages are useful. We use contract data to satisfy accounting, tax and audit requirements.

We do not sell personal data, and we do not use client project data for any purpose beyond the project and the legitimate operation of the workshop. Where we would like to use a case study or reference publicly, we ask for permission first and we remove or mask anything that could identify an individual or expose a confidential system detail.

07Cookies and Similar Technologies

This website is built as a static site and does not set advertising cookies. The hosting environment may use a small number of strictly necessary cookies to keep sessions stable and to defend against abusive traffic. Those cookies do not track an individual across other websites and are not used for profiling.

If we later add analytics that rely on cookies or similar storage, we will describe what is used and, where required, ask for consent before any non essential cookie is placed. You can also control cookies through your browser settings, and blocking strictly necessary cookies may affect how parts of this website behave.

08Client Project Data

Systems design work often exposes us to technical records that include personal data, such as user directories, access logs, configuration files and database schemas. When that happens, we handle the data strictly for the purpose of the engagement and under the terms of the written services agreement with the client.

We ask clients to provide only the access and data that a task genuinely requires. Where a task can be completed with anonymised or masked data, we prefer that approach. We keep project working copies in controlled locations, restrict access to the engineers assigned to the engagement, and remove working copies at the end of the project in line with the agreed retention schedule.

Where the client is the controller of that data, the client privacy notice governs the relationship between the client and the individuals concerned. We support the client in meeting those obligations by keeping accurate records of what we processed and for how long.

09Sharing and Disclosure

We share personal data only where there is a clear reason and a lawful basis. Typical recipients include hosting providers that keep this website online, email and collaboration providers that carry our correspondence, accountants and auditors who maintain our financial records, and professional advisers who assist with a specific matter.

Where a project requires it, we may share data with subcontractors who work alongside us, for example a cabling contractor or a specialist integrator. Those parties receive only the data needed for their part of the work, and they are bound by confidentiality and data protection terms that match our own.

We may also disclose personal data where the law requires it, where a court or regulator orders it, or where disclosure is necessary to protect the rights, safety or property of the workshop, our clients or the public. We will limit any such disclosure to what is legally required and we will record the reason for it.

10International Transfers

RED STONE TECHKNOWLEDGE operates from Singapore, and some of our service providers store data in other countries. When personal data leaves Singapore, we take steps to ensure that it continues to receive an appropriate level of protection, whether through contractual terms, provider certifications or an assessment of the legal environment in the destination country.

Where a client requires data to remain within a particular region, we will agree that constraint in the services agreement and select providers that can honour it. If a transfer cannot be made safely, we will discuss an alternative approach rather than proceed without protection.

11Data Retention

We keep personal data only for as long as it is needed for the purpose that justified its collection, or for as long as the law requires. Enquiry correspondence is normally kept for two years after the last contact. Contract and financial records are kept for the period required by accounting and tax rules, which is usually several years after the end of the relationship.

When a retention period ends, we delete or anonymise the data. If deletion is not immediately possible, for example because a record sits in a backup archive, we isolate the record and delete it as soon as the archive cycle allows.

12Security of Personal Data

We protect personal data with technical and organisational measures that match the sensitivity of the data and the risk of harm if it were lost. Measures include access control based on the tasks a person actually performs, encryption of data in transit, protected storage for credentials, regular review of who holds access, and clear procedures for handling an incident.

Our engineers work to the same discipline we recommend to clients. Records are classified, systems are documented, and changes are logged. Staff and contractors receive confidentiality obligations and practical guidance on recognising attempts to obtain data improperly, such as a fraudulent request that appears to come from a known contact.

No method of storage or transmission is entirely free of risk. If a breach occurs and it is likely to result in harm, we will notify affected individuals and any relevant regulator without undue delay, and we will explain what happened, what data was involved and what we are doing about it.

13Your Rights

Depending on where you live, you may have the right to be informed about how your personal data is used, to obtain a copy of the data we hold about you, to have inaccurate data corrected, to have data deleted where there is no continuing reason to keep it, and to restrict or object to certain processing.

You may also have the right to receive data in a portable format, to withdraw consent where consent is the basis for processing, and to object to direct marketing at any time. To exercise any of these rights, write to frontdesk@redstonetech.lat or call +16676886441. We will confirm your identity before acting so that we do not disclose data to someone who is not entitled to it.

We respond to requests within the period required by applicable law, normally within thirty days. If a request is complex or if we receive several requests from the same person, we may extend that period and will explain the reason. There is no charge for a reasonable request, although we may charge a proportionate fee where the law allows it and the request is manifestly unfounded or excessive.

14Privacy for Children

This website and our services are intended for organisations and for adults acting in a professional capacity. We do not knowingly collect personal data from children, and we do not direct marketing to them. If you believe that a child has provided personal data to us, please contact the workshop and we will delete it promptly.

15Marketing Communications

We send marketing messages only where we have a lawful basis to do so, such as consent or an existing client relationship with a relevant professional contact. Every message includes a straightforward way to opt out, and an opt out request is honoured promptly and recorded so that it is not accidentally overridden later.

Service messages that are needed to administer a contract, such as an invoice or a security notice, are not marketing and will continue to be sent while the relevant relationship or legal duty exists.

16Third Party Links

This website may contain links to websites run by other organisations. We provide those links for convenience and we do not control the privacy practices of the destinations. Before submitting personal data to another website, read its privacy notice and decide whether you are comfortable with its terms.

17Automated Decision Making

We do not use personal data to make automated decisions that produce legal effects or similarly significant effects. Decisions about projects, quotations and support are made by people who can explain their reasoning, and no client or individual is assessed solely by a machine.

18Changes to This Policy

We review this policy regularly and we update it when our practices, our providers or the law changes. The effective date at the top of the page always shows the current version. If a change is material, we will take reasonable steps to bring it to the attention of people who are affected, for example by a notice on this website or a direct message to active client contacts.

Continued use of this website after an update means that you accept the revised policy for future interactions. If you do not accept a revision, you may stop using the website and contact us to discuss any data we hold about you.

19How to Contact Us

For any question, request or concern about privacy, contact RED STONE TECHKNOWLEDGE directly. Our postal address is RED STONE TECHKNOWLEDGE, 449 ANG MO KIO AVENUE 10, #04-1727, Singapore - 560449, Singapore (SG). Our email address is frontdesk@redstonetech.lat and our telephone number is +16676886441.

Please include enough detail for us to understand the matter, such as the nature of your request and any reference numbers you hold. We will acknowledge the message, explain what happens next and keep you informed until the matter is resolved.

20Filing a Complaint

If you are unhappy with how we have handled your personal data, please tell us first so that we have the chance to put it right. You also have the right to complain to the data protection authority in your country or region, including the authority responsible for the area in which RED STONE TECHKNOWLEDGE operates.

We take complaints seriously and we use them to improve our practices. A complaint is recorded, investigated, and answered with a clear explanation of the findings and any action taken.