Privacy Policy
This policy explains what personal data Sustel Pte Ltd collects through sustel.io, why we collect it, who we share it with, how long we keep it, and what you can ask us to do with it.
It is written to Singapore's Personal Data Protection Act 2012 (PDPA). We have tried to write it in the same plain English as the rest of the site — no clause numbering, no defined-terms glossary. If anything here is unclear, email sales@sustel.io and we will explain it.
01Who we are
Sustel Pte Ltd (trading as SustEL) is a Singapore-incorporated company, UEN 202507569H, registered at 160 Robinson Road, #14-04, Singapore Business Federation Centre, Singapore 068914. We are the organisation responsible for the personal data described in this policy — in PDPA terms, we are the organisation that collects, uses and discloses it.
Work is delivered together with P. M. Electronics in Ahmedabad, India, which handles sourcing, supply and site execution. Where an enquiry concerns work that P. M. Electronics will carry out, your contact details are shared with them — see who else sees it.
This policy covers sustel.io and the enquiry channels on it. It does not cover other websites we link to, including LinkedIn — those have their own policies.
02What we collect
Two things happen when you send us an enquiry: we keep what you typed, and the server records a small amount of technical information about the request. That is the whole list.
What you give us
The enquiry form and the chat assistant on this site both submit to the same place. The fields are:
- Name — required.
- Email address — required.
- Company — optional.
- Phone number — optional.
- Interest — which area of our work your enquiry is about, optional.
- Message — whatever you choose to write, optional.
Only name and email are required. Please do not send us anything sensitive through this form — identity-document numbers, financial details, health information or anything confidential to your employer. It is an enquiry form, not a secure channel.
What the server records automatically
When an enquiry is submitted, our server stores the following alongside it:
- IP address — the address the enquiry came from. It is also what we use to rate-limit submissions, so one source cannot flood the form.
- Browser user-agent string — the browser and operating system your request identified itself as.
- Page — which page of the site the enquiry was sent from.
- Source — whether it came from the enquiry form or the chat assistant.
- Timestamps — when your browser sent it, and when our server recorded it.
What we add afterwards
Once an enquiry reaches us, we add two internal fields to the record: a status (whether we have replied, whether it became a project) and any notes our team writes while following it up.
What we do not collect
We do not run analytics, advertising or tracking on this site. There is no Google Analytics, no tag manager, no advertising pixel and no third-party script of any kind on these pages. We do not buy contact lists, we do not build visitor profiles, and we do not collect anything from you simply for reading the site.
03Why we collect it
We collect personal data for these purposes, and no others.
Answering your enquiry, sending information you asked for, and arranging a call or a meeting.
Scoping the work, producing a quotation, and the correspondence that goes with it.
If the enquiry becomes a project, keeping the contact record that project communication and site coordination depend on.
Rate-limiting the form against automated abuse, and diagnosing failed submissions. This is what the IP address and user-agent are for.
Keeping a record of who we dealt with and when, as any business needs to for its accounts, tax and contractual obligations.
No marketing lists, no selling data
We do not sell, rent or trade personal data. We do not add enquirers to a marketing mailing list. If we ever want to send you something that is not a reply to your own enquiry, we will ask you first.
04Consent, and withdrawing it
When you fill in the enquiry form or the chat assistant and submit it, you are consenting to us collecting, using and disclosing the data above for the purposes in section 3. We ask for nothing that is not needed for those purposes, and we do not make any part of the site conditional on giving us more than that.
You can withdraw your consent at any time. Email
sales@sustel.io with the subject line
Withdraw consent and tell us which enquiry or email address it concerns.
You do not have to give a reason.
We will act on a withdrawal within 10 working days, and confirm when it is done. Once you withdraw, we stop using your data for the purposes above and delete the record, except where we are required to keep something — for example, correspondence attached to a contract, or records we must retain for tax or accounting purposes. If that applies, we will tell you what is being kept and why.
We will also tell you if withdrawing consent means we can no longer do something you have asked for — we cannot answer an enquiry after deleting the address it came from.
06Where the data goes
Some of the personal data described here is transferred outside Singapore. Under the PDPA's Transfer Limitation Obligation we may only do that if the recipient is bound to a standard of protection comparable to the PDPA, and we take the steps below to meet that.
- India — P. M. Electronics, Ahmedabad, receives enquiry details for work it is involved in. It is contractually bound to use that data only for the purpose we shared it for, to protect it, and not to disclose it further.
- Hosting outside Singapore — sustel.io is hosted on shared hosting provided by Hostinger International UAB, a company based in Lithuania, which operates data centres in several countries. The server that holds the enquiry database may therefore sit outside Singapore. We rely on Hostinger's contractual data-protection commitments as our hosting provider. If you would like to know the current hosting region for sustel.io before you send us anything, ask us and we will tell you.
- Microsoft — Teams and Microsoft 365 are global cloud services and data in them may be processed outside Singapore under Microsoft's own data-protection terms.
07How long we keep it
We keep enquiry records for 24 months from our last contact with you, unless a contract or a legal obligation requires us to keep them longer. After that we delete them.
"Last contact" means the most recent exchange either way — so an enquiry that turns into an ongoing conversation stays live while the conversation does, and one that goes nowhere ages out. Where an enquiry becomes a project, the contact record is kept for as long as the contract and the record-keeping obligations attached to it require, which is typically longer.
You do not have to wait for that period to run. Ask us to delete your record and we will, subject only to anything we are legally required to retain — see withdrawing consent.
08Cookies and browser storage
This site sets no tracking cookies and runs no analytics. Two things do use your browser's own storage, and both are described here so the statement is accurate rather than convenient.
The password-protected team area (/login.php, /portal.php,
/team.php) sets one session cookie, sel_team_sid. It is
strictly necessary to keep a signed-in team member signed in, is marked
HttpOnly and SameSite=Lax, is marked Secure
over HTTPS, and expires when the browser is closed. It holds a session identifier
only, and is never set for ordinary visitors who do not sign in.
If your enquiry cannot reach our server — you are offline, or the request fails — the
page saves it in your own browser under localStorage key
sustel_leads_q and retries on your next visit, so a flaky connection does
not lose what you wrote. It stays on your device and is not readable by us until it
is successfully sent. Clearing your browser's site data for sustel.io removes
it.
The Smart Factory page checks whether our demonstration platform at
smartinsight.sustel.io is online, and embeds it if it is. That is a
request from your browser to another server we operate, so your IP address is visible
to it in the ordinary way any web request is. It is not a third-party service and no
tracking is attached.
Because we set no analytics, advertising or profiling cookies, there is no cookie banner on this site and nothing for you to opt out of.
09Access and correction
Under the PDPA you have two rights over the personal data we hold about you, and you can exercise either by emailing sales@sustel.io.
Access
You can ask us for a copy of the personal data we hold about you, and for information on how it has been used or disclosed in the past year. Tell us the email address or the enquiry it concerns. We will respond within 30 days; if we cannot, we will tell you when we can. We may need to confirm your identity first, and there are narrow situations under the PDPA where we may not be able to provide something — if that happens we will say so and explain why.
Correction
If anything we hold about you is wrong or out of date, tell us and we will correct it, normally within 10 working days, and let anyone we had shared the incorrect data with know about the correction.
Deletion
The PDPA does not give a standalone right to erasure, but in practice we will delete your enquiry record on request — see withdrawing consent — except for anything we are legally required to retain.
There is no charge for a reasonable access or correction request.
10How we protect it
The measures are proportionate to what we hold — business contact details and enquiry text, not financial or identity data.
- The whole site is served over HTTPS; submissions are encrypted in transit.
- The enquiry database is not reachable from the public web. The only routes to it are our password-protected team area and a token-protected export used by our internal tooling.
- Team accounts use hashed passwords; sessions are cookie-based, HttpOnly and expire when the browser closes.
- Access is limited to the SustEL people who need it to respond to you.
- The enquiry endpoint validates and truncates every field, rate-limits by IP address, and stores data using parameterised queries.
No system is perfectly secure, and we do not claim otherwise. If we become aware of a data breach affecting your personal data, we will act on it and notify you and the Personal Data Protection Commission where the PDPA's breach-notification requirements apply.
11Questions and complaints
Come to us first — we would rather fix something than have you take it elsewhere. If we cannot resolve it, the regulator is there.
Our Data Protection Officer is responsible for how we handle personal data and for
answering access, correction, withdrawal and complaint requests.
Email: sales@sustel.io
Post: Data Protection Officer, Sustel Pte Ltd, 160 Robinson Road, #14-04, Singapore
Business Federation Centre, Singapore 068914
We acknowledge within 5 working days, investigate, and give you a written answer within 30 days. If it will take longer, we will tell you why and when.
You can raise the matter with Singapore's Personal Data Protection Commission (PDPC) at pdpc.gov.sg.
12Changes to this policy
If we change what we collect, why we collect it, or who we share it with, we will update this page and change the "last updated" date at the top. The version published here is always the current one.
This policy describes our actual practice and is aligned to the PDPA. It is not legal advice, and it has not been certified by any regulator or law firm.