Privacy Policy

Personal Data Protection Act 2012 (Singapore)

This Privacy Policy explains how Gratitude Therapy ("we", "us", "our") collects, uses, discloses and cares for your personal data. It is our Data Protection Policy for the purposes of the Personal Data Protection Act 2012 of Singapore (the "PDPA"), and it applies to this website and to the coaching, learning design and VSC Game sessions we provide.

1. Personal data we collect

"Personal data" means data about an individual who can be identified from that data, or from that data together with other information we have or are likely to have access to.

We collect only what we need. In practice, that is:

What When it is collected
Name When you fill in the contact form on this website
Email address When you fill in the contact form on this website
Phone number (optional) When you choose to provide it in the contact form
The content of your message When you fill in the contact form on this website
Information you share during a session During coaching, learning design or VSC Game sessions, including your responses and results from the Values, Skills and Career card exercises
IP address and browser information Automatically, by the third-party services described in section 4

We do not collect NRIC numbers, financial account details, or any special categories of sensitive data through this website. Please do not send such information to us through the contact form.

2. Why we collect it

We collect, use and disclose your personal data for these specific purposes:

We will not use your personal data for any purpose that a reasonable person would not consider appropriate in the circumstances. If we ever want to use your data for a new purpose that is not listed above, we will tell you and obtain your consent first.

We do not sell your personal data. We also do not send marketing messages to you unless you have specifically asked to receive them.

4. Who we share it with

We keep your personal data confidential. We disclose it only in these limited situations:

Service providers acting on our behalf

We use the following third-party services to run this website. Where they process personal data on our behalf, they act as our data intermediaries, and we remain responsible for your data under the PDPA:

Where the law requires it

We may disclose your personal data where we are required or permitted to do so by Singapore law, by a court order, or to a public agency where the PDPA allows it.

5. Transfers outside Singapore

The service providers named in section 4 operate servers outside Singapore, including in the United States. This means your personal data may be transferred out of Singapore and stored overseas.

Under the Transfer Limitation Obligation, we will transfer your personal data outside Singapore only where we have taken appropriate steps to satisfy ourselves that the receiving organisation is bound by legally enforceable obligations to protect your data to a standard comparable to the PDPA. In practice we rely on the contractual terms and data processing commitments published by those providers.

6. Cookies and tracking

This website does not set cookies, and we do not run analytics or advertising trackers on it. We do not build visitor profiles and we do not track you across other websites.

As noted in section 4, your browser does make requests to GitHub and to Google Fonts in order to load this page, and those providers receive your IP address as an unavoidable part of serving the content. That is standard for any website and is not used by us to identify you.

7. Access and correction

Under the PDPA you have the right to ask us:

Please send your request using the details in section 12, with enough information for us to locate your data.

We will respond as soon as reasonably possible. If we are unable to respond within 30 calendar days, we will write to you within that time to tell you when we will be able to.

In limited situations the PDPA allows or requires us to refuse an access or correction request — for example where granting it would reveal personal data about another individual. If we refuse, we will tell you why.

8. Accuracy

We make a reasonable effort to ensure that personal data we collect is accurate and complete, particularly where we are likely to use it to make a decision that affects you, or to disclose it to another organisation. Please let us know if your contact details change so that we can keep our records up to date.

9. How we protect it

We make reasonable security arrangements to protect personal data in our possession or control against unauthorised access, collection, use, disclosure, copying, modification, disposal or similar risks. These include:

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. We encourage you not to send confidential or sensitive information through the contact form.

10. How long we keep it

We keep your personal data only for as long as it is needed for the purpose it was collected for. Once that purpose is fulfilled — for example, when your enquiry is closed or our work together has ended — and there is no remaining business or legal reason to keep it, we will cease to retain it by deleting or anonymising it.

Where a law requires us to keep certain records for a fixed period, we will keep them for that period and no longer.

11. Data breaches

If we become aware of a possible data breach affecting your personal data, we will assess it promptly to determine whether it is notifiable under the PDPA.

Where a breach is notifiable, we will notify the Personal Data Protection Commission within 3 calendar days of determining that it is notifiable, and we will notify affected individuals as soon as practicable, in the manner and in the circumstances required by the PDPA.

12. Contacting us & complaints

We have designated an individual to be responsible for ensuring our compliance with the PDPA. You can reach them for any question, withdrawal of consent, access or correction request, or complaint about how we handle personal data.

Data Protection Officer
Gratitude Therapy

Please use the contact form on our website and mark your message "Data Protection" so it reaches the right person.

If you wish to complain

We take complaints seriously. Tell us what happened and we will look into it and respond to you. If you are not satisfied with our response, you may raise the matter with the Personal Data Protection Commission of Singapore at www.pdpc.gov.sg.

13. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices or in the law. The current version will always be published on this page, with the date it last changed shown below. Please check back from time to time.

This Privacy Policy is governed by the laws of Singapore.

Last updated: 28 July 2026