Data Protection Policy
Version 2.0 · Effective 26 September 2026
This policy replaces the Privacy Policy that was published at must.com.sg/privacy. That address now forwards here.
About this policy
MUST Technology Pte Ltd (UEN 202197777W), a company incorporated in Singapore (“MUST”, “we”, “us”, “our”), builds and operates business software, including the MUST HRMS mobile app and the HR platform behind it. This policy sets out how we handle personal data under Singapore’s Personal Data Protection Act 2012, as amended by the Personal Data Protection (Amendment) Act 2020 (together, the “PDPA”), its regulations, and the advisory guidelines issued by the Personal Data Protection Commission (“PDPC”).
In this policy, “personal data” carries its PDPA meaning: information, whether accurate or not, about a person who can be identified from it, alone or combined with other information we hold or are likely to be able to access.
Two roles, two sets of rules
The PDPA treats us differently depending on whose data it is and who decides what happens to it.
| Our role | Whose personal data | Who decides how it is used | Where to read |
|---|---|---|---|
| Organisation | Visitors to must.com.sg, people who contact us, and contact persons at our customers, suppliers and partners | MUST | Part A |
| Data intermediary | Employees of organisations that use MUST HRMS — our customers, including companies in the MUST Holdings group | The employer | Part B |
Part C (security, overseas transfers, breaches, changes and contact details) applies in both roles.
Part A — Our website, enquiries and business contacts
A1. Information we collect
- Enquiries — your name, company name or UEN, work email, phone number and message, when you fill in a form on the website or book a demo.
- Correspondence — emails, calls and messages between you and us, and our notes of meetings.
- Business contact details — names, job titles, emails and phone numbers of the people a customer, supplier or partner nominates to work with us.
- Server logs — our hosting and content-delivery providers log IP address, browser type, the pages requested and the time of each request, to keep the website secure and available.
A2. Cookies, analytics and campaign attribution
- Cloudflare Web Analytics counts visits in aggregate. It sets no cookies and does not profile individual visitors.
- Google Ads conversion measurement tells us whether a click on one of our ads ended in an enquiry. Google supplies this tag, which may set cookies on your device, and handles the resulting data under Google’s own privacy policy. You can block those cookies in your browser settings or change ad personalisation at https://adssettings.google.com.
- Campaign source. When you reach the website through a marketing link, your browser’s local storage keeps the first source it sees — campaign parameters such as
utm_source, an ad-click identifier, or the site that referred you. If you later send us an enquiry, that source travels with it so we can tell which channel reached you. The browser also stores a small marker that keeps the same page layout in front of you while we compare two designs. Clearing this site’s data in your browser removes both.
A3. Why we use it
- to reply to your enquiry and to run the readiness check or demo you asked for;
- to prepare quotations, agreements and invoices, and to deliver, support and bill the services a customer engages us for;
- to send updates about InvoiceNow readiness and MUST services where you have agreed to receive them — every such message explains how to opt out;
- to see, in aggregate, which marketing channels work; and
- to meet our legal, tax and accounting obligations and to establish or defend legal claims.
Before we send a marketing message to a Singapore telephone number, we will either hold your clear consent or check the Do Not Call Registry, as the PDPA requires. We do not sell personal data, and we do not pass it to other organisations for their own marketing.
A4. Where enquiries go and who helps us
- Website enquiries go into our customer relationship (CRM) system, which runs on servers we operate in Singapore. If that delivery fails, the form falls back to FormSubmit, a form-relay service that emails the enquiry to us.
- The website is delivered through Cloudflare (DNS and content delivery) from infrastructure we operate.
- Google Ads measures ad conversions, as described in A2.
Each provider handles the data only to provide its service to us. Some of them do so outside Singapore; see C2.
A5. How long we keep it
We keep enquiry data for as long as we need it to deal with the enquiry and any business relationship that follows. Records tied to a contract or an invoice are then kept for as long as tax, accounting and other legal rules require — usually five years — and deleted afterwards.
Part B — MUST HRMS mobile app and HR platform
This part is for employees and former employees of organisations that use MUST HRMS. It covers the MUST HRMS app for Android and iOS and the HR platform it connects to. Any organisation that uses MUST HRMS is called “your employer” here.
B1. Your employer is responsible; we act on its behalf
Your employer chose MUST HRMS and decides which personal data about you it holds, for what purposes and for how long. Under the PDPA your employer is the organisation responsible for that data. MUST Technology is a data intermediary: we store and process the data for your employer, under our agreement with it and only on its instructions. This is also the position where your employer is a MUST Holdings group company — that company is the responsible organisation, and MUST Technology processes data for it.
The PDPA places three duties on us directly as a data intermediary:
- Protection — we must make reasonable security arrangements for the data (see C1).
- Retention — we must stop keeping the data once it no longer serves the purposes your employer set, or any legal or business need (see B8).
- Breach notification — if we have reason to believe a data breach has affected the data, we must tell your employer without undue delay (see C3).
Your employer carries the other obligations: telling you why your data is collected, obtaining consent where it is needed, and answering your requests to access or correct your data. We help your employer meet them, and any request that reaches us from you is passed to your employer (see B9).
B2. What the platform holds
| Category | Examples | Source |
|---|---|---|
| Identity and personal | Name, employee number, photo, date and place of birth, nationality, marital status, number of children, education; NRIC or FIN, passport number, work-pass or visa number and its expiry date | Your employer’s HR team, or you when the app asks you to complete them |
| Contact | Work email, mobile number, emergency contact name and number | Your employer; you |
| Employment | Job title, department, manager, work location or site, work schedule and rest days, deployment status, leave entitlements, stored employment documents and their expiry dates | Your employer |
| Attendance | Clock-in and clock-out times; GPS position at the moment of each punch; whether that position fell inside the site’s geofence; the country and time zone derived from it; overtime and work notes; missed or late punches | The app when you punch; you |
| Attendance indicators | Punctuality score, lateness averages and streaks, calculated from your attendance records | Calculated by the platform |
| Leave | Leave requests and approvals; medical certificates and other supporting documents you attach | You; your approvers |
| Expense claims | Claim details and scans or photos of receipts | You |
| Pay | Where your employer runs payroll on the platform: salary, allowances, deductions, statutory contributions and payslips | Your employer |
| Sign-in and device | Account identifiers and sign-in tokens, a push-notification registration linked to your employee number, and basic app and device information such as platform and app version | The app |
| Singpass | Where Singpass sign-in is enabled: a pseudonymous Singpass identifier and the date you linked it | Singpass, when you choose to use it |
| Diagnostics | Crash reports and technical logs of the app’s requests to our server | The app |
B3. Why it is used, and on what basis
Your employer uses this data to:
- record attendance and work out pay, overtime, rest-day and public-holiday treatment;
- run leave, expense claims, schedules and approvals;
- pay you, make CPF contributions, report employment income to IRAS and meet Ministry of Manpower obligations, including those for work-pass holders;
- follow up on missed or late punches and other attendance exceptions;
- confirm your identity when you sign in and send you notifications about your requests; and
- keep the service secure, fix faults and meet other legal obligations.
The PDPA allows an employer to collect, use and disclose personal data that is reasonable for managing or ending an employment relationship without asking for consent, provided it tells you the purposes. Some items — NRIC or FIN, pay and CPF details, and work-pass details — are required by law, including the Central Provident Fund Act, the Income Tax Act, the Employment Act and the Employment of Foreign Manpower Act. Where your employer relies on your consent for something optional, it will ask you.
B4. Location: only at the moment you punch
The app reads your location only when you tap to clock in or clock out, or when you submit a corrected punch. It does not track you in the background, and it asks only for “while using the app” location permission on both Android and iOS. The position is saved with that attendance record and used to check the work-site geofence and to set the country and time zone that pay and rest-day rules depend on.
To show a small map beside a punch, our server requests a map image of those coordinates from a map service provider outside Singapore. That provider receives the coordinates only, not your name or employee details.
B5. Singpass sign-in
Singpass is Singapore’s national digital identity, operated by GovTech for the Singapore Government. MUST HRMS is approved by the Singapore Government to offer Login with Singpass. Where your employer has switched it on, you can sign in with Singpass instead of a password. You authenticate inside the Singpass app, so MUST never sees or stores your Singpass password, passcode or passkey.
Singpass returns a pseudonymous identifier and your NRIC or FIN. The first time you sign in this way, we compare that number with the identification number your employer already holds for you, to find your account. From then on we keep only the pseudonymous identifier and the date of linking, and later sign-ins are matched on that identifier. We do not store the number Singpass sends, and we do not receive your name, address or any Myinfo data through Singpass.
The integration follows the security profile Singpass requires (FAPI 2.0): pushed authorisation requests, signed client authentication and sender-constrained tokens between our server and Singpass, and PKCE between the app and our server. Your usual sign-in method remains available, and an administrator can remove the Singpass link from your account at any time.
B6. Receipts, documents and AI-assisted features
You can scan a receipt or choose a file. On Android the scan uses the document scanner built into Google Play services, so the app itself does not need camera permission. Medical certificates and other leave documents are attached the same way. Attachments are visible to you, the people who approve the request, and your employer’s HR and finance users.
Some features send limited data to third-party AI model services located outside Singapore:
- Receipt reading — a receipt image is read to pre-fill the vendor, date and amount of a claim.
- Receipt checks for automatic approval — where your employer uses automatic approval, the receipt image is checked against the claim’s category, date and description; the claimed amount is not sent. The model only reports what it sees; a rule set by your employer decides, and any claim that does not pass goes to a person.
- HR drafting — HR can ask for a draft summary or message about attendance exceptions. The model receives your name, your department and a summary of the exceptions. HR reviews the draft and decides whether to send it.
These providers are outside Singapore; see C2.
B7. Who can see your data
- You — your own profile and records in the app.
- Your managers and approvers — your team profile, attendance, leave and claims, as your employer has configured their roles.
- Your employer’s HR, payroll and finance users — the records their role requires.
- MUST engineers — a small number of engineers can reach the systems to run, secure and support them, for example to investigate a fault your employer reports. They use named accounts with key-based access, not shared passwords, and look at personal data only as far as the task requires.
- Service providers — the providers listed in C2, each limited to the data its service needs.
- Public agencies and others — only on your employer’s instructions, or where the law requires us to disclose, for example under a court order.
B8. How long it is kept
Your employer sets retention periods within the limits of the law. Singapore’s employment, tax and CPF rules require employers to keep some records for fixed periods, including after employment ends. When your employer closes your account you can no longer sign in, but your records remain available to your employer until its retention period ends; they are then deleted or anonymised on its instructions. When a customer stops using MUST HRMS, we return or delete its data as its contract provides. Deleted data also leaves our backups as they rotate: we currently keep daily backups for 14 days.
B9. Your choices and rights
- Access and correction — ask your employer’s HR team; they can show you most of what is held and correct it. In the app you can also update some details yourself, such as your identification number, emergency contact and visa expiry date, and report a wrong attendance record.
- Requests sent to MUST — if you write to us, we will pass your request to your employer promptly and help it respond. We do not answer on your employer’s behalf unless it asks us to.
- Withdrawing consent — you can deny location permission, turn off notifications in your phone’s settings, or ask for your Singpass link to be removed. If location permission is denied, you may not be able to clock in or out with the app, and your employer will need another way to record your hours. Data your employer must process under the law or for managing your employment continues to be processed.
B10. NRIC and other national identification numbers
We follow the PDPC’s Advisory Guidelines on the PDPA for NRIC and other National Identification Numbers. The platform holds your NRIC, FIN or passport number only because the law requires your employer to use it — for CPF contributions, employment-income reporting to IRAS and work-pass matters with the Ministry of Manpower — or because your identity must be confirmed to a high degree of accuracy, as when a Singpass sign-in is matched to your account. The number is used for those purposes only.
Part C — Applies to both roles
C1. Security
- In transit — the app’s server accepts connections only over TLS 1.2 or higher, and the website is served over HTTPS.
- Access — the HR platform grants access by role (employee, manager, HR and administrator), and changes to attendance records are kept in the record’s change history.
- Sign-in — sign-in tokens expire and must be renewed; you can also sign in with Singpass where it is enabled (B5).
- Hosting and backups — MUST HRMS runs on servers in Singapore, with daily backups also kept in Singapore (C2).
- Reporting a weakness — send security reports to [email protected].
For MUST Suite, our cloud business software, the security controls and the work still pending are published at https://trust.must.com.sg.
No system is perfectly secure, but we review these measures and improve them as risks change.
C2. Where data is stored and transfers outside Singapore
MUST HRMS data is stored on servers in Singapore, and its backups are kept in Singapore as well. Website enquiries are stored in our CRM on the same Singapore infrastructure.
We use a small number of service providers to run the platform. We do not name them individually here, both for security and because they may change; your employer can request the current list from our Data Protection Officer. By category, and where the data is handled:
- Hosting, database, file storage and backups for MUST HRMS and our CRM — Singapore.
- Push notifications to the app — the employee number and the notification text; outside Singapore.
- Email delivery from the platform — the email address and the email content; outside Singapore.
- Crash and error reporting from the app — device and app details and technical request logs; outside Singapore.
- AI-assisted features (B6) — receipt images and claim context; a name, department and attendance exceptions for HR drafting; outside Singapore.
- Map images beside a punch — coordinates only; outside Singapore.
- Website and network delivery — website request data, and the short-lived sign-in code passed from Singpass to our server; global network.
- Singpass (GovTech) — sign-in, where enabled; Singapore. See B5.
- Website enquiry relay (backup only) — enquiry details; may be outside Singapore.
- Advertising measurement — cookie and ad-click data from our website only; outside Singapore.
Where personal data leaves Singapore, we take steps to ensure the recipient protects it to a standard comparable to the PDPA, as the PDPA’s transfer rules require. For MUST HRMS data, your employer remains responsible for those transfers, and we give it the information and support it needs.
C3. Data breaches
If a breach affects personal data we hold as an organisation, we will assess it promptly, and in any case within 30 days. If it is notifiable, we will tell the PDPC within three calendar days of reaching that conclusion, and tell the affected individuals where the PDPA requires. If a breach affects MUST HRMS data, we will tell your employer without undue delay, so it can make its own assessment and notifications, and support it throughout.
C4. Keeping data accurate
We rely on the information you, or your employer, give us. Please tell us — or, for MUST HRMS, your employer’s HR team — when something changes.
C5. Other websites and app stores
The website links to sites we do not control, and the MUST HRMS app is downloaded from the Apple App Store or Google Play. Those services handle your data under their own policies.
C6. Changes to this policy
We will publish any update on this page with a new version number and effective date. When a change materially affects MUST HRMS, we will also tell the employers who use it, so they can inform their employees.
C7. Contact us
Data Protection Officer — MUST Technology Pte Ltd
236 Woodlands Industrial Park E5, Woodlands Bizhub, Singapore 757300
Email: [email protected] · Phone: +65 8063 4656
Help with the MUST HRMS app: [email protected]
We respond to access and correction requests within 30 days; if we need longer, we will tell you within that time when we expect to reply. We may charge a reasonable fee for an access request, and we will tell you the amount before we proceed. If you are not satisfied with our response, you may contact the PDPC at https://www.pdpc.gov.sg.