Return to Overview
LEGAL REVISION v3.4.0 (ACTIVE)
IEC 62443 & GDPR COMPLIANT ARCHITECTURE

Privacy & Data
Protection Notice

This Privacy Notice explains how FAJARDEV and its technology affiliates collect, process, encrypt, and protect your Personal Data and industrial telemetry across our SCADA systems, web applications, edge controllers, and connected IoT cloud platforms.

EFFECTIVE DATE
08 May 2024
LAST REVIEWED
12 March 2026
DATA CONTROLLER
FajarDev Pte. Ltd.
GLOBAL SCOPE
EEA, UK, SG, Global
SECTION 01SCOPE & APPLICABILITY

1. Scope of this Privacy Notice

This Privacy Notice explains how FajarDev Pte. Ltd. and its corporate affiliates (“FajarDev”, “we”, “our”, or “us”) collect, process, and safeguard Personal Data (i.e. any information relating to an identified or identifiable natural person) when you visit our websites, interact with our industrial engineering platforms, deploy our SCADA architectures, or use our telemetry applications.

WHEN WE ACT AS DATA CONTROLLER

Applies when FajarDev determines the purposes and technical means of collecting website telemetry, newsletter subscriptions, customer portal accounts, and candidate onboarding.

WHEN WE ACT AS DATA PROCESSOR

When deploying dedicated on-premise SCADA/EMS systems or managing enterprise operational data on behalf of our industrial utility clients, our operations are governed strictly by individual client Data Processing Agreements (DPAs).

SECTION 02COLLECTION METHODOLOGY

2. Collecting Your Personal Data & Telemetry

We collect Personal Data directly from you when you register an account, request a live SCADA demonstration, subscribe to our cybersecurity threat briefs, or report a diagnostic anomaly. We also collect technical metadata automatically through secure telemetry logs.

A. Information You Voluntarily Provide:

Full name, enterprise business email address, organization name, job title, phone number, and technical inquiry details submitted via contact or demo request forms.

B. Automated Device & Security Telemetry:

Anonymized IP addresses (truncated at subnet level), browser type, TLS protocol version, operating system, access timestamps, and referrers collected to protect our infrastructure against DDoS and unauthorized intrusion.

C. Industrial Telemetry & Session Tokens:

Ephemeral authentication tokens, Modbus TCP register query counters, and simulation state telemetry during active interactive demonstrations.

SECTION 03LEGAL BASIS & PURPOSES

3. Purposes of Processing & Lawful Grounds

In compliance with the EU General Data Protection Regulation (GDPR Article 6) and Singapore Personal Data Protection Act (PDPA), we only process your data under legitimate, lawful grounds:

PROCESSING PURPOSEDATA CATEGORYLEGAL BASIS (GDPR ART. 6)
SCADA Demo & System SimulationSession ID, User SetpointsLegitimate Interest (Art. 6(1)(f))
Commercial Inquiries & QuotationsName, Enterprise Email, OrgPerformance of Contract (Art. 6(1)(b))
Infrastructure Cyber Defense (OT SIEM)IP Subnet, Request HeadersLegitimate Interest (Security)
Technical Newsletter & AdvisoriesEmail AddressExplicit Consent (Art. 6(1)(a))
SECTION 04COOKIE ARCHITECTURE

4. Web Browser Cookies & Local Storage

We use strictly essential technical cookies and local storage tokens to preserve session state, security anti-CSRF tokens, and simulation settings.

1. STRICTLY NECESSARY COOKIES

Required for basic site navigation, authentication, and cybersecurity verification. Cannot be disabled.

2. FUNCTIONAL SIMULATION TOKENS

Stores digital twin setpoints and speed preferences locally on your browser. Does not track cross-site.

SECTION 05THIRD-PARTY SHARING

5. Sharing Your Personal Data

We do not sell, rent, or trade your Personal Data. We share information only under strict technical and organizational measures (TOMs) with:

  • Corporate Affiliates: To facilitate unified technical support and enterprise SCADA system integration.
  • Cloud Infrastructure Providers: ISO 27001/SOC 2 certified hosting partners (AWS, Google Cloud) under strict Data Processing Agreements.
  • Legal & Regulatory Authorities: Where mandatory to comply with statutory legal obligations, court orders, or national critical infrastructure directives.
SECTION 06CROSS-BORDER TRANSFERS

6. International Data Transfers & Safeguards

When transferring Personal Data across international jurisdictions outside the EEA, UK, or Switzerland, we enforce legally recognized transfer mechanisms including:

EU STANDARD CONTRACTUAL CLAUSES (SCCs)

Incorporated into vendor and subprocessor contracts to ensure equivalent data protection standards.

ADEQUACY DECISIONS

Transfers to jurisdictions officially recognized by the European Commission as providing adequate data safeguards.

SECTION 07TECHNICAL MEASURES (TOMs)

7. Technical & Organizational Security Measures

As an industrial automation and cybersecurity engineering firm, security is engineered directly into our system foundation:

AES-256-GCM

End-to-end cryptographic encryption at rest & transit (TLS 1.3).

IEC 62443 ZONES

Hardened network segmentation and DMZ industrial conduits.

ZERO-TRUST RBAC

Granular role-based access control with MFA enforcement.

SECTION 08DATA SUBJECT RIGHTS

8. Your Legal Rights (GDPR / PDPA)

Under applicable data protection laws (including GDPR Chapters III and Singapore PDPA), you hold the following enforceable rights:

Right to Access:Request a copy of Personal Data held by us concerning your person.
Right to Rectification:Request correction of inaccurate or incomplete data records.
Right to Erasure (To Be Forgotten):Request permanent deletion of data where legal retention periods have expired.
Right to Data Portability:Receive structured, machine-readable JSON/CSV extracts of your data.
SECTION 09RETENTION POLICIES

9. Data Retention & Storage Lifecycle

We retain Personal Data only for as long as necessary to fulfill the processing purposes outlined in this notice, resolve commercial disputes, and comply with mandatory statutory audit laws (typically 5 to 7 years for contractual/financial records, 90 days for transient security access logs).

SECTION 10DATA INTEGRITY

10. Accuracy of Personal Data

We take all reasonable steps to ensure data is accurate and up-to-date. You are encouraged to notify our team promptly of any corporate email or authorization changes at privacy@fajardev.com.

SECTION 11OPT-OUT & PREFERENCES

11. Subscription & Opt-Out Management

You may unsubscribe from technical newsletters and promotional advisories at any time by clicking the “Unsubscribe” link located in the footer of our communications or contacting our DPO.

SECTION 12PROTECTION OF MINORS

12. Protection of Children's Privacy

Our services, industrial platforms, and SCADA engineering software are designed exclusively for business and enterprise professionals. We do not knowingly solicit or collect Personal Data from individuals under 18 years of age.

SECTION 13EXTERNAL PLATFORMS

13. Third-Party Websites & Integrations

Our website may contain links to external technical standards (such as IEC, IEEE, NIST). FajarDev does not control the privacy practices of external third-party entities.

SECTION 14POLICY REVISIONS

14. Changes to this Privacy Notice

We may periodically update this notice to reflect changes in legal statutes or our industrial infrastructure practices. The latest revision date will always be prominently displayed at the top of this page.

SECTION 15DATA PROTECTION OFFICER

15. Contacting Our Data Protection Officer (DPO)

For inquiries regarding this Privacy Notice, submitting Subject Access Requests (SAR), or exercising your rights, please contact our dedicated office:

OFFICE:FajarDev Data Protection Office
RESPONSE SLA:Within 30 Calendar Days