Privacy is a practice.
Not just a policy.
Our current approach for the Coden marketing website, operated by MUST Technology Pte Ltd, Singapore.
Singapore PDPA
We use the Singapore Personal Data Protection Act as a key reference for our website’s privacy practices. Our notices explain the purposes of collection, forms collect limited information for the request, and a dedicated channel accepts access, correction, deletion, and consent-withdrawal requests. These measures do not, by themselves, establish compliance with every obligation.
Organisational responsibilities include appointing a data protection officer, maintaining appropriate policies, managing retention, evaluating overseas transfers, and responding appropriately to incidents and requests. These obligations require ongoing operational work.
GDPR applicability
Coden’s initial market is Singapore. EU GDPR can apply to some organisations outside the EU, including where they offer goods or services to individuals in the EU or monitor their behaviour there. The fact that a website is accessible from the EU does not alone establish that all its processing falls within GDPR.
If GDPR applies to a particular activity, the relevant lawful basis, notices, data subject rights, transfer arrangements, and any representative or DPO obligations must be assessed for that activity. This website does not claim GDPR certification or blanket GDPR compliance.
What is implemented on this website?
HTTPS delivery; private database storage without a public read API; server-side validation and parameterized queries; request limits and a honeypot against form abuse; purpose-specific consent records for demo and career interest; no advertising trackers; self-hosted fonts; and a privacy request form that returns a reference number.
Your request, your choice
Use our privacy request form to ask for access or correction, request deletion, or withdraw consent to follow-up. Applicable rights, verification needs, and exceptions depend on the request and relevant law. Consent to discuss a demo does not subscribe you to an unrelated advertising list.
Production HR and payroll processing
These pages cover the public website. Processing employee datasets for a customer would require a separate evaluation of controller/processor roles, processing terms, retention, access controls, transfer safeguards, and any applicable local requirements before activation. No payroll data should be submitted through the public forms.
Official references
PDPC: Data Protection Obligations
PDPC: Appoint a Data Protection Officer
European Commission: Application of the GDPR