Our Commitment to Data Protection

At Purenviro International Pte Ltd, we recognize that dealing with hazardous materials also comes with the responsibility of handling sensitive personal and project-related information. Whether you are an individual homeowner, corporate entity, or industrial client, we treat your information with the highest level of confidentiality, integrity, and respect. We are committed to complying with Singapore’s Personal Data Protection Act (PDPA) and applicable international privacy standards. Trust, safety, and transparency are central to our operations and communication.

Definition of Personal Data

Under the Personal Data Protection Act, Personal Data refers to any data - whether true or not - that can identify an individual from that data alone or when combined with other accessible information. This includes:

  • Full Name
  • NRIC/FIN or Passport Number
  • Contact details such as mobile number, email, and home/work address
  • Photographic and biometric identifiers (if any)
  • IP address or location-based data (when used with other identifiers)

Types of Data We Collect

Personal Information

  • Full Name
  • Contact Number
  • Email Address
  • Billing and Mailing Address
  • Government-issued identification (as required by regulation)

Business and Operational Information

  • Site/property locations
  • Project scope and work orders
  • Environmental and regulatory documentation
  • Permits, approvals, or licenses

Technical and Website Usage Information

  • IP Address
  • Device Type, OS, and Browser version
  • Time spent on our website
  • Click-paths and form submission behavior
  • Cookies (explained below)

How We Collect Your Data

We collect data through:

  • Direct submission: Contact forms, service requests, signed agreements
  • Automated collection: Cookies, Google Analytics, or other tracking tools
  • Third-party sources:Industry databases, regulators, subcontractors involved in your project

Purpose of Data Collection

We collect and use your personal and operational data for the following purposes:

  • To provide requested services: asbestos identification, removal, decontamination, demolition
  • To ensure compliance with NEA, MOM, BCA, and other Singapore authorities
  • To communicate service updates, inspection schedules, and safety notices
  • To issue invoices, process payments, and maintain accurate project recordss
  • To request feedback and improve service delivery
  • To maintain safety logs, site clearance reports, and audit trails
  • To meet legal, contractual, and insurance requirements

Legal Basis for Processing

We process your data on the following grounds:

  • Consent:You give us permission via forms, emails, or agreements
  • Contractual necessity: To perform obligations under a signed project or service agreement
  • Legal compliance: To meet PDPA, NEA, or MOM safety reporting standards
  • Legitimate interests:For internal analysis, operational efficiency, or security monitoring

Data Sharing and Disclosure

We do not sell your data. However, we may share necessary information with the following parties:

  • Government regulators (e.g., NEA, MOM, BCA)
  • Subcontractors or vendors working on your approved project
  • Legal counsel, insurers, or auditors (if required for legal disputes or internal audits)
  • IT service providers under strict confidentiality and data protection clauses

All third-party access is governed by data processing agreements and aligned with PDPA standards.

Cross-border Transfers of Personal Data

When we work with global partners or software providers, your data may be stored or processed outside Singapore. In such cases, we ensure:

  • The receiving country offers comparable data protection laws, or
  • Binding agreements are in place (e.g., EU Standard Contractual Clauses) to ensure your rights are protected

Data Retention Policy

Your data will be stored only for as long as it is necessary to:

  • Fulfill our contractual obligations
  • Comply with legal or regulatory documentation timelines
  • Support audits or safety documentation for up to 7 years

After this, we securely erase or anonymize your data beyond recovery.

Data Security Practices

We implement multiple layers of data protection:

  • SSL encryption for all online transactions and contact forms
  • Role-based access control and staff authentication
  • Regular penetration testing and vulnerability assessments
  • Cybersecurity training for all administrative and technical staff
  • Encrypted cloud storage with limited physical access

In the event of a data breach, we will notify the PDPC and affected individuals within 72 hours, as per PDPA requirements.

Chat with us on WhatsApp

chat with us

Loading