ESG by ZYT

Privacy notice

Last updated 4 September 2026

ZYT Pte. Ltd. (UEN 202424324W), a company incorporated in Singapore, is the organisation responsible for personal data processed through ESG by ZYT. This notice explains what we collect, why, how long we keep it and what you can require of us, under Singapore’s Personal Data Protection Act 2012 (the “PDPA”).

Data Protection Officer

As section 11 of the PDPA requires, ZYT Pte. Ltd. has designated an individual responsible for our compliance with the Act. Our Data Protection Officer is reachable at dpo@zyt.one.

Address any question, access request, correction request, withdrawal of consent or complaint about personal data there. It is a monitored business address and a person reads it — you do not need to phrase a request formally or cite a section number for us to act on it.

When we are responsible, and when your customer is

The distinction matters because it decides whom you should ask.

We are the responsible organisation for account data, quick carbon footprint submissions and contact enquiries — you gave those to us directly, and this notice governs them.

We act as a data intermediary for the operational data a customer enters into their own inventory, including anything identifying the colleagues who contributed to it. We process that on the customer’s instructions, for them. If you supplied figures through a collection link sent by a business, that business decides what happens to the data — ask them first. We will still help, and will pass a request on.

What we collect

Account data. Name, email address and the organisation you belong to. Passwords are stored only as salted hashes by our authentication provider; we never see them.

Business data. The operational figures you enter — energy, fuel, waste, water, headcount — together with the emission factors applied and who entered each figure. This is largely about a business, not a person, but headcount and staff-related disclosures may include limited personal data.

Quick carbon footprint. If you use the free tool we keep the business name, email address, country, sector and the answers you gave, so we can follow up and so you can find the figure again.

Contact enquiries. Your name, email, business and message.

Collection links. When a section is delegated we store the recipient’s email and name so the person who sent it knows who was asked. The link itself is stored only as a SHA-256 hash — we cannot recover it.

Why we hold it

To provide the service you asked for: calculating figures, producing reports, and letting colleagues contribute to an inventory. For the quick carbon footprint and contact form, to respond to you about ESG by ZYT. We do not sell personal data, and we do not use it for advertising.

Consent, and withdrawing it

We rely on your consent, or on the exceptions the PDPA provides for data supplied in the course of a business relationship. You may withdraw consent to any use of your personal data at any time by writing to our Data Protection Officer. We will act on it and tell you what the consequence is.

The consequence is usually straightforward: withdrawing consent for us to hold your account data means we can no longer provide the service to you, because the service cannot run without an account. Withdrawing consent to marketing or follow-up contact does not affect your account at all.

Withdrawal is not retrospective, and it does not require us to delete records we are obliged to keep — see how long we keep it, below.

Who else processes it

Supabase — database and authentication, hosted in Singapore (ap-southeast-1).

Vercel — application hosting and delivery, served from Singapore.

Resend — transactional email, processed in Tokyo (ap-northeast-1). Some data therefore leaves Singapore in order to send you email.

Each acts on our instructions under its own terms. We use no advertising or analytics trackers.

Transfers out of Singapore. Sending an email means personal data is processed in Tokyo. Where personal data leaves Singapore we take reasonable steps, as section 26 of the PDPA requires, to satisfy ourselves that the recipient is bound by legally enforceable obligations to protect it to a standard comparable to the PDPA. In practice that means contractual data-protection terms with each provider named above. Application hosting and the database remain in Singapore.

How long we keep it

Section 25 of the PDPA requires us to stop keeping personal data once the purpose it was collected for has ended and there is no legal or business reason to retain it. Our periods:

  • Inventory and report data. For as long as the account is open, and for seven years afterwards. A published figure has to stay reproducible: the emission factors are snapshotted against each entry precisely so it can be re-derived if a customer or an assurance provider queries it years later.
  • Account data. For as long as the account is open, then twelve months, then deleted.
  • Quick carbon footprint submissions. Twenty-four months from submission, then deleted.
  • Contact enquiries. Twenty-four months from the last exchange, then deleted.
  • Collection link records. With the reporting period they belong to. The link itself is never stored — only a SHA-256 hash of it — so it cannot be recovered by us or by anyone who obtains our database.

You can ask us to delete sooner. We will, unless we are required to keep something — and if so we will tell you what, and why.

Your rights

You may ask what we hold about you, ask us to correct it, or ask us to delete it. Write to service@zyt.one and we will respond within 30 days. If we cannot, we will tell you within 30 days when we will. If you are a colleague who filled in a section through a collection link, contact the business that sent it — the data is theirs — or write to us and we will pass it on.

The PDPA permits us to charge a reasonable fee for an access request. We do not currently charge one, and if that ever changes we will tell you the amount before doing any work, so you can withdraw the request.

There are narrow cases where the PDPA requires or permits us to refuse — for instance where disclosing your data would reveal someone else’s. If we refuse any part of a request we will say which part and on what basis.

If we do not resolve it. Write to our Data Protection Officer first so we have a chance to put it right. If you are still not satisfied you may complain to the Personal Data Protection Commission of Singapore at pdpc.gov.sg. Nothing here limits that right.

Cookies

We set only what the service needs to work: a session cookie once you sign in, and a cookie recording which client a consultant is currently working on. There are no advertising or third-party tracking cookies, and we do not profile you. That is why you are not being asked to accept any: there is nothing here that consent would be about. If we ever add analytics, we will ask first.

Security

Data is protected in transit and at rest, and access is enforced at the database level so one organisation cannot read another’s data. Collection links are random, expiring, scoped to a single section, and stored only as hashes.

We will not claim more than that. No system is immune, we are a small company, and the service has not been penetration-tested by a third party. What we can say is what we do: least-privilege access, no personal data in logs we can avoid, and isolation enforced by the database rather than by application code remembering to check.

If there is a data breach

Part 6A of the PDPA makes notification mandatory, and we treat it as a floor rather than a target. If a breach is likely to result in significant harm to anyone affected, or involves the personal data of 500 or more individuals, we will notify the Personal Data Protection Commission as soon as practicable and in any case within 3 calendar days of concluding that it is notifiable, and we will notify the affected individuals.

We will assess any suspected breach expeditiously. Where we act as a data intermediary for a customer’s inventory, we will notify that customer without undue delay so they can meet their own obligation.

Changes to this notice

If we change how we handle personal data we will update this notice and move the date at the top. Where a change materially affects your rights we will tell account holders by email rather than relying on you to re-read the page.

Contact

Questions or complaints: service@zyt.one. See also our terms of use.