DATA PROTECTION

Logical Systems builds and supports systems that run inside our clients' factories. Those systems record who operated a line, who approved a batch, who signed an electronic record. That is personal data, and it belongs to our client — not to us.

This page sets out how we handle it, what we commit to contractually, and what documentation we will provide when you assess us as a supplier. If you are a visitor to this website or a job applicant, our privacy policy is the document you want instead.

CONTROLLER OR PROCESSOR

Which obligations apply to personal data depends on who decides how it is used. We operate in both capacities and keep them separate.

We are a controller for personal data we decide the purposes for: enquiries made through this website, job applications, our own employee records, and the business contact details of client and supplier personnel. This is governed by our privacy policy.

We are a processor for personal data inside the systems we deliver and support. Our client is the controller. We process it only on their documented instructions, for the term of the engagement, and under a written data processing agreement.

If you are an employee of one of our clients and want to exercise rights over data held in a system we maintain, please contact your own employer. They are the controller, and we will support them in responding to you.

WHAT WE PROCESS FOR CLIENTS

In a typical SCADA, MES or digitalisation engagement, the personal data we encounter is limited to what production systems generate as a by-product of operating:

  • Operator identifiers and login names on control system screens.
  • Electronic signature and approval records, including those under 21 CFR Part 11.
  • Shift, attendance and workforce management records.
  • Audit trail entries attributable to a named individual.
  • Business contact details of our client's project personnel.

We are not instructed to process special category data, and we will notify the client if we encounter any. We do not use client personal data for our own purposes, and we do not use it to train anything.

CONTRACTUAL FRAMEWORK

Data processing agreement. We enter into a written agreement meeting Article 28(3) of the GDPR before processing begins. Where a client provides their own, we work to theirs. Where they do not, we provide a template covering documented instructions, confidentiality, security measures, sub-processing, assistance with data subject requests, breach notification, audit rights, and deletion or return on termination.

International transfers. We are established in Singapore with delivery capability across ASEAN and Europe. For transfers subject to the GDPR we enter into the European Commission's Standard Contractual Clauses and maintain a transfer impact assessment, which we provide on request. For transfers subject to the PDPA we comply with the Transfer Limitation Obligation in section 26 and Regulation 10 of the Personal Data Protection Regulations.

Sub-processors. We maintain a register of every third party that can reach personal data on our behalf, with the service each provides and where it is processed. Clients receive the register on request and advance notice of any change, with the opportunity to object.

GOVERNANCE AND ASSURANCE

  • Information security management system certified to ISO/IEC 27001.
  • Data Protection Officer appointed under section 11(3) of the PDPA, reachable at dpo@logicalsystems.io.
  • Record of processing activities maintained and reviewed at least annually.
  • Documented retention schedule, with deletion verified rather than assumed.
  • Independent penetration testing of our external web presence.
  • Identity managed in Microsoft Entra ID with multi-factor authentication enforced, access granted on least privilege and reviewed on a defined cycle.
  • Supplier risk management framework applied before any third party is engaged.
  • Security awareness training for all personnel, with completion recorded.

INCIDENT RESPONSE

We maintain a documented process for identifying, assessing and responding to personal data breaches, and a breach register.

Where we act as a processor, we notify the client without undue delay and in any event within twenty-four hours of becoming aware of a breach affecting their personal data, so that they retain time within their own regulatory window. We do not notify any regulator or individual on a client's behalf without their instruction.

Where we act as a controller, we assess notifiability under Part VIA of the PDPA and, where applicable, Articles 33 and 34 of the GDPR.

DOCUMENTATION ON REQUEST

The following are available to clients and prospective clients under NDA. Most vendor security questionnaires can be answered from them directly.

  • Data processing agreement template.
  • Sub-processor register.
  • Transfer impact assessment and Standard Contractual Clauses.
  • ISO/IEC 27001 certificate and Statement of Applicability.
  • Penetration test summary.
  • Information security policy set.
  • Business continuity and disaster recovery summary.
  • Completed security questionnaire in your own format, where reasonable.

Write to dpo@logicalsystems.io and tell us which of these you need.