JHR (S) ENGINEERING PTE. LTD.

Privacy Policy

Last updated 14 September 2026

This Privacy Policy explains how JHR Engineering, the trading name of JHR (S) ENGINEERING PTE. LTD., collects, uses, stores, shares and protects personal data in the course of delivering computer integrated systems design, industrial automation engineering and managed technical support services. It applies to our website at https://www.jhrengineering.mom, to enquiries and proposals, and to the ongoing operation of client control systems. We have written it in plain language so that a busy plant manager, an engineer or a member of the public can understand what happens to information we hold.

Contents

  1. 1. Who We Are and How to Reach Us
  2. 2. Scope of This Policy
  3. 3. Categories of Personal Data We Collect
  4. 4. How We Collect Personal Data
  5. 5. Why We Use Personal Data
  6. 6. Legal Bases for Processing
  7. 7. Cookies and Similar Technologies
  8. 8. Sharing Data with Service Providers
  9. 9. International Transfers of Data
  10. 10. How Long We Keep Personal Data
  11. 11. How We Protect Personal Data
  12. 12. Your Rights and Choices
  13. 13. Privacy for Children
  14. 14. Data Relating to Client Operations
  15. 15. Automated Decisions and Profiling
  16. 16. Direct Marketing and Communications
  17. 17. Breach Notification and Response
  18. 18. Changes to This Policy
  19. 19. Contacting Us and Complaints

1. Who We Are and How to Reach Us

JHR (S) ENGINEERING PTE. LTD. is a company registered in Singapore. Our registered and operating address is 35 Kelantan Lane, #02-03 Kim Hoe Point, 208652, Singapore (SG). We operate our website at https://www.jhrengineering.mom and provide engineering services to clients in Singapore and beyond. For the purposes of applicable data protection law, the Company is the organisation responsible for the personal data described in this Policy.

You may contact us about privacy matters by writing to support@jhrengineering.mom or by calling +17758545673. We welcome questions, requests and complaints, and we would rather hear about a concern early than discover it through a third party. When you contact us, please describe the nature of your request as clearly as you can so that we can route it to the correct person without delay.

Our workshop sits on Kelantan Lane in the Kim Hoe Point building, where our engineers design and build control panels before they are delivered to client sites. Although the workshop is an operational engineering facility rather than a public service counter, you are welcome to arrange a visit by appointment if you need to discuss a project in person. The Company treats privacy as part of professional engineering conduct, and every member of the team shares responsibility for handling information with care.

Where this Policy refers to personal data, we mean information about an identifiable individual, such as a name, contact detail, or an identifier that can reasonably be linked to a person. Business contact details that relate to a role rather than an individual may still be personal data when they identify a specific person, and we handle them with the same care. Where information has been fully anonymised so that no individual can be identified, it falls outside the scope of this Policy.

2. Scope of This Policy

This Policy covers personal data that the Company collects through the website, through proposals, quotations and contracts, through email and telephone correspondence, through site visits and commissioning work, and through the managed support we provide after handover. It also covers personal data we receive from suppliers, subcontractors and business partners in the ordinary course of engineering work.

This Policy does not cover the data practices of third party websites that you may reach from links on our site. It also does not govern information that is not personal data, such as anonymised engineering measurements, aggregate performance statistics or fully de-identified records. Where we process data on behalf of a client under a written services agreement, the terms of that agreement and the client instructions take precedence over this Policy for that data.

If you are a job applicant, a visitor to our workshop, or a person who appears incidentally in a site photograph or a commissioning record, this Policy also describes how we handle the limited personal data that may result. If you are a subcontractor or supplier, the relevant provisions on contact details, payment information and confidentiality apply to you. We aim to keep the scope of this Policy understandable, so that any reader can tell whether it applies to their situation without needing legal training.

3. Categories of Personal Data We Collect

The personal data we hold depends on your relationship with us. For a website visitor or a person making an enquiry, we typically collect a name, an email address, a telephone number, a company name and the content of the message you send. For a client contact, we may also hold a job title, a department, a site location, correspondence history and records of meetings or support calls.

For suppliers and subcontractors, we may hold a contact name, business contact details, banking or payment references where required for settlement, and records of work performed. Where we provide support that requires access to systems, we may hold the usernames, roles and access times associated with authorised personnel, but we do not seek passwords or private credentials beyond what a controlled access process strictly requires.

We may also collect technical data such as the internet protocol address used to reach our site, browser type, device type, referring page and the time of a visit. This technical data is used to keep the site secure and reliable and to understand which pages are useful.

In the course of a project, our engineers may record site conditions, equipment serial numbers, firmware versions and commissioning results. Some of these records may include the name of the person who witnessed a test or the operator who received training. We keep the personal element of such records to the minimum needed to preserve the integrity of the engineering history, and we do not treat these records as marketing data.

We do not intentionally collect sensitive categories of personal data, such as health information or biometric data, as part of our ordinary services. If a project ever requires data of that kind, for example for site safety certification, we will explain the purpose, limit the collection to what is required, and apply additional safeguards.

4. How We Collect Personal Data

Most of the personal data we hold comes directly from you. You provide it when you complete a contact form, send an email, telephone our office, request a quotation, sign a proposal, attend a site meeting or take part in a training session. We collect only the information that is relevant to the matter at hand.

We also receive personal data from other sources in limited circumstances. A colleague may introduce you as the correct contact for a project. A supplier may provide the name of an account manager. A client may give us the details of an operator who needs training or a maintenance lead who needs access to drawings. Where we receive your data from someone else, we use it only for the purpose for which it was shared.

Some technical data is collected automatically when you use our website, through standard server logs and any cookies that are described in the section on cookies and similar technologies below.

When you telephone us, we may keep a short note of the call so that we can follow up accurately. When you meet our engineers on site, we may exchange business cards or add your name to a project contact list. Each of these activities is part of normal engineering practice, and the information collected is limited to what the situation genuinely requires.

5. Why We Use Personal Data

We use personal data to respond to enquiries, prepare and issue proposals, deliver engineering services, arrange site access, coordinate commissioning, provide training, supply managed support and issue invoices. We also use it to maintain accurate business records, to meet accounting and legal obligations, and to improve the quality and safety of our work.

Where you have agreed, we may use your contact details to send occasional updates about our services, relevant technical notes or company news. We do not use personal data for purposes that are unrelated to the reason it was collected, and we do not sell personal data to any third party for advertising or any other purpose.

We may also use personal data to detect, investigate and prevent fraud, misuse of systems or security incidents, and to enforce our agreements where that becomes necessary.

Engineering quality depends on traceability, so we may also use personal data to record who approved a design, who commissioned a system and who received training on it. This traceability protects both the client and the Company, because it allows us to reconstruct what happened during a project and to support the asset responsibly over its life. We keep these records accurate and update them when a contact changes role.

If you ask us a question by email, we may retain the correspondence so that we can answer related questions in the future without asking you to repeat yourself. We will not add you to a marketing list merely because you made an enquiry, and we will not treat a one-off support question as consent for unrelated messages.

6. Legal Bases for Processing

Where data protection law requires a legal basis, we rely on one or more of the following. We process personal data to perform a contract with you or to take steps at your request before entering a contract, for example when preparing a quotation or delivering a project. We process personal data for our legitimate interests in running and improving an engineering business, provided those interests are not overridden by your rights.

We process personal data to comply with legal obligations, such as tax, accounting and safety requirements. In some cases we rely on your consent, for example where you ask to receive marketing communications. Where we rely on consent, you may withdraw it at any time, and withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

When we rely on legitimate interests, we carry out a balancing assessment to confirm that our interests do not outweigh your rights and expectations. When we rely on a contract, we process only the data that the contract genuinely requires. When we rely on a legal obligation, we limit the processing to what the applicable rule demands and keep the record only as long as that rule requires.

Some processing may be necessary to protect vital interests, for example in an emergency at a site, or to perform a task carried out in the public interest where that concept applies. If a legal basis is unclear for a particular activity, we will seek advice before proceeding rather than assume that permission exists.

7. Cookies and Similar Technologies

Our website may use a small number of cookies and similar technologies to keep the site working and to understand general usage patterns. Essential cookies support basic functions such as page delivery and security. Analytics cookies, where used, help us understand which pages visitors find useful so that we can improve the content.

You can control cookies through your browser settings. Most browsers allow you to block or delete cookies, and doing so will not prevent you from reading the information on our site. We do not use cookies to build advertising profiles, and we do not permit third parties to set advertising cookies through our pages.

If we introduce a new category of cookie, such as a preference cookie that remembers a display setting, we will describe its purpose here and provide a way to manage it. Where the law requires consent before a non-essential cookie is set, we will request that consent rather than set the cookie in advance. You can also use browser privacy features and content blockers to limit tracking, and our site will continue to work for its core informational purpose.

8. Sharing Data with Service Providers

We share personal data with service providers who help us operate, but only to the extent needed for the service they provide. These providers may include information technology support, email and hosting services, accounting software, payment processing and professional advisers such as auditors or lawyers. Each provider is expected to protect personal data and to use it only for the agreed purpose.

We may also share personal data with subcontractors or specialist partners where a project requires additional capability, and with the client who engaged us where the data relates to that engagement. Where we share data with a subcontractor, we require confidentiality and appropriate safeguards.

We may disclose personal data where the law requires it, where a court or regulator orders it, or where disclosure is necessary to protect the safety, rights or property of the Company, our clients or the public. If the Company is involved in a merger, acquisition or sale of assets, personal data may be transferred as part of that transaction, subject to this Policy or an equivalent standard of protection.

We do not sell personal data, and we do not trade it for advertising. When we share data with a provider, we limit the share to the minimum needed and we require the provider to protect it. Where a provider is located in another country, we consider the legal environment before transferring data and we put appropriate safeguards in place. We review our provider list periodically and remove providers that no longer meet our expectations.

If you are a client contact and a project involves an interface with a third party system, we will tell you which parties need to be involved so that the sharing is transparent. Where a client prefers that we communicate only with a named contact, we will respect that instruction for the duration of the engagement.

9. International Transfers of Data

Some of our service providers may store or process data outside Singapore. Where personal data is transferred across borders, we take reasonable steps to ensure that it receives an adequate level of protection. These steps may include contractual commitments, selecting providers with recognised safeguards, and limiting the data that leaves our direct control.

If you are located outside Singapore and contact us, your data will be handled in Singapore and possibly in the locations where our providers operate. By using our site or engaging our services, you understand that your data may be processed in these locations. Where local law requires additional consent for a transfer, we will seek that consent before proceeding.

We keep a record of the safeguards that apply to each cross-border transfer so that we can demonstrate accountability if asked. If a provider changes where it stores data, we review the arrangement before allowing the change to take effect. Where a transfer would create a risk that we cannot adequately address, we will look for an alternative provider or handle the activity locally.

10. How Long We Keep Personal Data

We keep personal data only for as long as it is needed for the purpose it was collected, or as long as the law requires. Enquiry records that do not lead to work are typically kept for a limited period and then removed. Contract, project and accounting records are kept for the period required by tax and corporate law, after which they are securely deleted or anonymised.

Engineering records such as as-built drawings, test results and support logs may be retained for the operational life of the systems we maintain, because they are needed to support the assets safely and to honour our support commitments. Where a record contains personal data, we keep the personal elements to the minimum necessary and separate them from the technical record wherever practical.

When the retention period ends, we delete or anonymise the data in a controlled way. We do not keep personal data indefinitely merely because storage is inexpensive, and we do not keep duplicates in unrelated systems. If a legal hold applies to a record, we preserve that record and set the rest aside from routine deletion until the hold is lifted.

11. How We Protect Personal Data

We use administrative, technical and physical safeguards to protect personal data against loss, misuse and unauthorised access. These safeguards include access controls that limit data to personnel who need it, secure configuration of the systems we operate, staff awareness of privacy and security responsibilities, and secure disposal of records that are no longer needed.

When our engineers access client systems for support, we follow controlled procedures, log relevant activity and use dedicated accounts rather than shared credentials. We review our practices as our services evolve, and we treat privacy protection as part of engineering quality rather than a separate administrative task. No method of storage or transmission is perfectly secure, so while we work hard to protect personal data, we cannot promise absolute security.

We train our staff on privacy and security responsibilities, and we remind them that a control system can be compromised through an ordinary email as easily as through a sophisticated attack. We apply the same discipline to our own records that we apply to the plants we build, which means labelled systems, controlled changes and clear ownership. Where we discover a weakness, we fix it and we record what we learned so that the same issue is less likely to recur.

12. Your Rights and Choices

Subject to applicable law, you may request access to the personal data we hold about you, ask us to correct inaccurate data, ask us to delete data that we no longer need, ask us to restrict or object to certain processing, or request a portable copy of data you provided to us. You may also withdraw consent where consent is the basis for processing.

To exercise a right, write to support@jhrengineering.mom and describe your request clearly. We may ask for information to confirm your identity before acting, so that we do not disclose data to the wrong person. We will respond within the time allowed by law. If we cannot meet a request, we will explain why, and we will tell you how to challenge the decision.

You also have the right to object to processing based on legitimate interests, and we will stop unless we can demonstrate compelling grounds that override your objection. You may ask us to correct a record that is inaccurate and to complete a record that is incomplete. If you believe we have handled your data unlawfully, you may complain to us or to a supervisory authority.

13. Privacy for Children

Our services are intended for businesses and professionals. We do not knowingly collect personal data from children, and our website and services are not directed at children. If you believe that a child has provided personal data to us, please contact us so that we can take appropriate steps to remove it. We encourage parents and guardians to discuss online privacy with young people and to supervise their use of websites.

Where a site visit or training session involves young people, we take additional care and we expect the responsible adults to be present. We do not use images of identifiable children in our records unless a lawful basis and appropriate consent are in place. If we learn that we have inadvertently collected data from a child without the required basis, we will delete it promptly and review how it was collected.

14. Data Relating to Client Operations

In the course of integrating systems and providing support, our engineers may encounter operational data belonging to a client, such as production figures, process settings, alarm histories or equipment logs. We treat client operational data as confidential. We use it only to perform the agreed work, we restrict access to the personnel who need it, and we do not repurpose it for our own benefit.

Where a client provides us with personal data about its own staff or customers, the client remains responsible for ensuring that it has a lawful basis to share that data with us. We process such data as instructed and return or delete it as the agreement requires. The client agreement, rather than this public Policy, governs the detail of that processing.

If we use a shared engineering platform to collaborate on a client asset, access is limited to named personnel and the activity is logged. Client drawings and configuration files are stored in controlled repositories rather than personal drives, so that the records survive staff changes and remain attributable. When an engagement ends, we follow the agreed return or deletion process and confirm completion in writing.

15. Automated Decisions and Profiling

We do not use personal data to make automated decisions that produce legal or similarly significant effects. We do not build behavioural advertising profiles and we do not sell personal data. Where we use analytics, we rely on aggregated or minimised information so that individuals are not singled out. If this ever changed, we would update this Policy and provide any notices or choices that the law requires.

Engineering systems sometimes use automation to control a process, but that automation acts on machinery and sensors rather than on decisions about people. We keep those two domains clearly separated, so that a control loop optimisation does not become a decision about an employee or a customer. Where a client asks us to build reporting that summarises operational performance, we design it around equipment and process metrics rather than personal profiles.

16. Direct Marketing and Communications

We send marketing or company update messages only where we have a lawful basis to do so, which usually means your consent or an existing business relationship. Every marketing message we send includes a way to opt out, and we honour opt out requests promptly. Service and transactional messages, such as project updates or support notifications, are not marketing and are sent as part of delivering the work you asked us to perform.

If you ask us to stop sending marketing messages, we will keep a minimal record of that preference so that we can respect it. That suppression record is not itself used for marketing. We do not share contact lists with other organisations for their own marketing, and we do not buy lists of contacts from third parties.

17. Breach Notification and Response

We maintain procedures to detect, assess and respond to suspected personal data breaches. If a breach occurs that is likely to result in a risk to the rights of individuals, we will act to contain it, investigate the cause, and notify affected individuals and the relevant authorities where the law requires. We also review each incident to reduce the chance of a repeat.

Our response plan sets out who leads the investigation, how the scope is established, and how the affected parties are informed. We test the plan periodically and update it as our systems change. Where a breach involves a client system that we support, we notify the client promptly and cooperate with their own incident process.

18. Changes to This Policy

We may update this Policy from time to time to reflect changes in our services, technology or legal obligations. When we make a material change, we will update the date at the top of the page and, where appropriate, provide additional notice. We encourage you to review this page periodically so that you remain aware of how we protect personal data.

If a change significantly affects how we use data we already hold, we will take reasonable steps to inform affected individuals before the change takes effect. Prior versions of this Policy can be requested from us by email, and we keep a record of when each version applied.

19. Contacting Us and Complaints

If you have questions about this Privacy Policy or how we handle personal data, please write to support@jhrengineering.mom or call +17758545673. You may also write to us at 35 Kelantan Lane, #02-03 Kim Hoe Point, 208652, Singapore (SG). We take complaints seriously and will investigate them fairly. If you remain dissatisfied after contacting us, you may raise the matter with the data protection authority in your jurisdiction.

Return to the homepage · Terms of Service

JHR (S) ENGINEERING PTE. LTD. — 35 Kelantan Lane, #02-03 Kim Hoe Point, 208652, Singapore (SG)

Home · support@jhrengineering.mom · +17758545673