Personal Data Protection Act 2012 (Singapore)
This Privacy Policy explains how Gratitude Therapy ("we", "us", "our") collects, uses, discloses and cares for your personal data. It is our Data Protection Policy for the purposes of the Personal Data Protection Act 2012 of Singapore (the "PDPA"), and it applies to this website and to the coaching, learning design and VSC Game sessions we provide.
"Personal data" means data about an individual who can be identified from that data, or from that data together with other information we have or are likely to have access to.
We collect only what we need. In practice, that is:
| What | When it is collected |
|---|---|
| Name | When you fill in the contact form on this website |
| Email address | When you fill in the contact form on this website |
| Phone number (optional) | When you choose to provide it in the contact form |
| The content of your message | When you fill in the contact form on this website |
| Information you share during a session | During coaching, learning design or VSC Game sessions, including your responses and results from the Values, Skills and Career card exercises |
| IP address and browser information | Automatically, by the third-party services described in section 4 |
We do not collect NRIC numbers, financial account details, or any special categories of sensitive data through this website. Please do not send such information to us through the contact form.
We collect, use and disclose your personal data for these specific purposes:
We will not use your personal data for any purpose that a reasonable person would not consider appropriate in the circumstances. If we ever want to use your data for a new purpose that is not listed above, we will tell you and obtain your consent first.
We do not sell your personal data. We also do not send marketing messages to you unless you have specifically asked to receive them.
By submitting the contact form or providing your personal data to us, you consent to us collecting, using and disclosing it for the purposes set out in section 2.
You may withdraw your consent at any time, for any or all of the purposes above, by contacting us using the details in section 12. We will not charge you for withdrawing your consent.
When we receive your withdrawal notice, we will tell you the likely consequences of withdrawing — for example, if we can no longer arrange a session with you. We will then stop collecting, using or disclosing your personal data for the relevant purposes, unless we are required or authorised by law to continue.
Withdrawing consent does not affect anything we lawfully did with your data before the withdrawal took effect.
We keep your personal data confidential. We disclose it only in these limited situations:
We use the following third-party services to run this website. Where they process personal data on our behalf, they act as our data intermediaries, and we remain responsible for your data under the PDPA:
We may disclose your personal data where we are required or permitted to do so by Singapore law, by a court order, or to a public agency where the PDPA allows it.
The service providers named in section 4 operate servers outside Singapore, including in the United States. This means your personal data may be transferred out of Singapore and stored overseas.
Under the Transfer Limitation Obligation, we will transfer your personal data outside Singapore only where we have taken appropriate steps to satisfy ourselves that the receiving organisation is bound by legally enforceable obligations to protect your data to a standard comparable to the PDPA. In practice we rely on the contractual terms and data processing commitments published by those providers.
This website does not set cookies, and we do not run analytics or advertising trackers on it. We do not build visitor profiles and we do not track you across other websites.
As noted in section 4, your browser does make requests to GitHub and to Google Fonts in order to load this page, and those providers receive your IP address as an unavoidable part of serving the content. That is standard for any website and is not used by us to identify you.
Under the PDPA you have the right to ask us:
Please send your request using the details in section 12, with enough information for us to locate your data.
We will respond as soon as reasonably possible. If we are unable to respond within 30 calendar days, we will write to you within that time to tell you when we will be able to.
In limited situations the PDPA allows or requires us to refuse an access or correction request — for example where granting it would reveal personal data about another individual. If we refuse, we will tell you why.
We make a reasonable effort to ensure that personal data we collect is accurate and complete, particularly where we are likely to use it to make a decision that affects you, or to disclose it to another organisation. Please let us know if your contact details change so that we can keep our records up to date.
We make reasonable security arrangements to protect personal data in our possession or control against unauthorised access, collection, use, disclosure, copying, modification, disposal or similar risks. These include:
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. We encourage you not to send confidential or sensitive information through the contact form.
We keep your personal data only for as long as it is needed for the purpose it was collected for. Once that purpose is fulfilled — for example, when your enquiry is closed or our work together has ended — and there is no remaining business or legal reason to keep it, we will cease to retain it by deleting or anonymising it.
Where a law requires us to keep certain records for a fixed period, we will keep them for that period and no longer.
If we become aware of a possible data breach affecting your personal data, we will assess it promptly to determine whether it is notifiable under the PDPA.
Where a breach is notifiable, we will notify the Personal Data Protection Commission within 3 calendar days of determining that it is notifiable, and we will notify affected individuals as soon as practicable, in the manner and in the circumstances required by the PDPA.
We have designated an individual to be responsible for ensuring our compliance with the PDPA. You can reach them for any question, withdrawal of consent, access or correction request, or complaint about how we handle personal data.
Data Protection Officer
Gratitude Therapy
Please use the contact form on our website and mark your message "Data Protection" so it reaches the right person.
We take complaints seriously. Tell us what happened and we will look into it and respond to you. If you are not satisfied with our response, you may raise the matter with the Personal Data Protection Commission of Singapore at www.pdpc.gov.sg.
We may update this Privacy Policy from time to time to reflect changes in our practices or in the law. The current version will always be published on this page, with the date it last changed shown below. Please check back from time to time.
This Privacy Policy is governed by the laws of Singapore.
Last updated: 28 July 2026