1. Who is responsible
The data controller for this website is Farid, reachable at [email protected]. Postal correspondence may be sent to Blk 8 Cantonment Close, #03-12, Singapore 080008. I do not maintain a separate data protection officer; for privacy matters, email is fastest.
2. What this site collects
Contact form. When you submit the say-hello form, I collect your name, email address, and message content. You must tick the PDPA consent checkbox before submission; without it, the form will not send.
Email. If you email me directly, I receive whatever you choose to include — often name, email, and message, sometimes attachments.
Essential cookies and local storage. A small script stores your cookie banner choice in your browser (localStorage) so the banner does not reappear every visit. This record contains your preference (accept, reject, or customised analytics choice) and a timestamp. It is not sent to my server automatically.
Analytics cookies (optional). Only if you accept analytics in the cookie banner would optional analytics tools load. Rejecting analytics means those scripts should not run. At present this site is built to respect that choice; if I enable analytics providers later, this policy will name them.
Server logs. Like most websites, hosting may automatically log technical data — IP address, browser type, pages requested, timestamps — for security and troubleshooting. I access these logs only when needed to fix errors or investigate abuse.
3. Purposes and legal basis
I use personal data only for legitimate purposes connected to this personal blog:
- responding to messages you send via the contact form or email;
- keeping a record of correspondence so I can follow up accurately;
- remembering your cookie consent preference;
- maintaining site security and diagnosing technical faults;
- complying with applicable law if required.
I do not sell, rent, or trade your personal data. I do not buy mailing lists. I do not use your contact details for unsolicited marketing.
4. Disclosure to third parties
I may share data only in these limited situations:
- Service providers. Website hosting, email delivery, or form processing may involve processors outside my flat — for example, a hosting company storing server logs. They process data on my instructions and for site operation only.
- Legal requirements. If Singapore law or a valid court order requires disclosure, I will comply to the extent legally obliged.
- Protection. If necessary to investigate spam, abuse, or attempts to harm the site, I may retain related metadata.
I do not routinely transfer personal data overseas. If a future tool requires overseas processing, I will update this policy and, where required, obtain consent.
5. Retention
Contact form and email messages are kept only as long as needed to reply and for a reasonable period afterward — typically up to twenty-four months — unless you ask me to delete them sooner or a longer period is needed to resolve an ongoing issue. Cookie consent records live in your browser until you clear site data. Server logs depend on the host's rotation policy, usually measured in weeks or months.
6. Your rights under PDPA
Subject to exceptions in the PDPA, you may:
- ask whether I hold personal data about you;
- request access to that data;
- request correction of inaccurate data;
- withdraw consent for future processing where consent is the basis;
- request deletion where retention is no longer necessary and no legal exception applies.
To exercise these rights, email [email protected] with enough detail for me to locate your record. I may need to verify your identity before releasing or changing data. I will respond within a reasonable time — generally within thirty days.
If you believe I have not handled your data properly, you may contact the Personal Data Protection Commission (PDPC) in Singapore after giving me a chance to address your concern.
7. Security
I use proportionate measures for a small personal site: HTTPS where configured by hosting, access limited to me, passwords on administrative accounts, and caution about what I download from messages. No method of transmission over the internet is completely secure; I cannot guarantee absolute security, but I take reasonable steps to protect data I control.
8. Children
This site is written for a general adult audience. I do not knowingly collect personal data from children under thirteen without parental consent. If you believe a child has submitted data, contact me and I will delete it promptly.
9. Links to other sites
Posts may link to external websites (for example, map services or references). I am not responsible for their privacy practices. Read their policies before submitting data there.
10. Changes to this policy
I may update this policy when practices or legal requirements change. The “Last updated” date at the top will change accordingly. Material changes will be noted on this page; continued use of the site after updates constitutes acknowledgement of the revised policy where permitted by law.