Legal · Data Protection

Privacy Policy

Thoughtium builds AI systems that are supposed to be handled with care — and the same standard applies to the personal data we hold. This policy sets out what we collect, why we collect it, how we protect it, and the choices available to you. It is written to align with Singapore's Personal Data Protection Act 2012 (PDPA).

Last updated: 18 June 2026 [email protected]

SECTION 01

Introduction

This Privacy Policy describes how Thoughtium ("we", "us", "our") handles personal data collected through our website, our enquiry forms, and the course of delivering our services — Natural Language Understanding audits, generative content pipelines, and federated learning architecture.

The policy applies to visitors of our website and to organisations and individuals who contact us or engage our services. It covers data collected online; where a signed engagement adds specific data-handling terms, those terms sit alongside this policy.

Thoughtium is the data controller for the personal data described here. If anything below is unclear, write to us at [email protected] and we will walk you through it.

SECTION 02

Data We Collect

What we collect. When you use our contact form we ask for your name and email address (both required) and, optionally, your phone number and a message. During an engagement we may also receive business contact details and any technical information you choose to share about the systems we are assessing.

How we collect it. Personal data reaches us in three ways: information you enter into our website forms; details you provide directly by email or phone; and limited technical data gathered automatically through cookies and website analytics (see Section 05).

Legal basis for processing (PDPA):

  • Consent — you provide details through our form or by contacting us, which signals consent for us to respond.
  • Contractual necessity — where data is needed to scope, deliver, or document an agreed engagement.
  • Legitimate interests — for understanding website usage and improving our services, balanced against your privacy.

Retention periods:

  • Enquiry-form submissions that do not lead to an engagement: kept up to 12 months, then deleted.
  • Records relating to an active or completed engagement: kept for the duration of the engagement and up to 6 years afterward, in line with commercial record-keeping norms in Singapore.
  • Website analytics data: retained in aggregated form according to the analytics provider's standard settings.

Third-party services. We may use reputable providers for website analytics and advertising measurement (such as Google and Meta). These providers process limited data on our behalf under their own terms.

SECTION 03

How We Use Data

We use personal data for clearly defined purposes and nothing beyond them:

  • Responding to enquiries — to reply to your message and arrange an initial conversation.
  • Delivering services — to scope, carry out, and document an agreed engagement.
  • Communication — to send information you have asked for and updates relevant to your engagement.
  • Website improvement — to understand how the site is used and make it clearer and faster.
  • Legal compliance — to meet obligations under applicable Singapore law.

Data sharing. We do not sell personal data. We share it only with service providers who support our operations — such as analytics, advertising measurement, and communication tools — and only to the extent needed for those functions. We may also disclose data where required by law or a valid request from an authority.

Marketing. Any marketing communication is opt-in. Every such message includes a way to opt out, and you can withdraw consent at any time by writing to [email protected].

SECTION 04

How We Protect It

Data protection is central to how we work — federated learning, one of our core services, exists precisely to keep sensitive data where it belongs. We apply that same discipline internally:

  • Encryption — data is transmitted over encrypted connections and stored on secured infrastructure.
  • Access controls — personal data is accessible only to team members who need it for a specific purpose.
  • Monitoring — systems holding personal data are monitored for unusual activity.
  • Periodic review — we review our security practices and provider arrangements at regular intervals.
  • Breach response — in the event of a data breach that poses a risk of significant harm, we will notify affected individuals and the relevant authority in line with the PDPA.

No system can promise perfect security, but we work to reduce risk to a reasonable level and to respond quickly and transparently if something goes wrong.

SECTION 05

Cookies

Our website uses cookies and similar technologies to keep the site working and to understand how it is used. In brief:

  • Essential cookies — required for basic functionality, such as remembering your cookie choices.
  • Analytics cookies — help us see which pages are useful and where the site can be improved.
  • Marketing cookies — measure the effectiveness of any advertising and reduce irrelevant messaging.
  • Preference cookies — remember settings so the experience stays consistent.

You can manage your choices at any time. For a full breakdown of categories, durations, and browser controls, see our Cookie Policy.

SECTION 06

Your Rights

Under the PDPA and related good practice, you have the following rights over your personal data:

  • Access — request a copy of the personal data we hold about you.
  • Correction — ask us to correct data that is inaccurate or incomplete.
  • Erasure — request deletion of your data where we have no continuing lawful reason to keep it.
  • Portability — where applicable, ask to receive your data in a usable format.
  • Objection — object to certain processing, including for marketing.
  • Withdraw consent — withdraw consent for future processing at any time.
  • Lodge a complaint — raise a concern with the supervisory authority (see below).

How to exercise them. Send your request to [email protected]. We will verify your identity and respond within a reasonable period. Withdrawing consent may affect our ability to continue providing certain services, and we will explain any such effect before acting on your request.

Supervisory authority. The regulator for personal data in Singapore is the Personal Data Protection Commission (PDPC). If you are not satisfied with our response, you may contact the PDPC directly.

SECTION 07

Third-Party Links

Our website may link to external sites and services we do not operate. Those sites have their own privacy practices, and we are not responsible for how they handle your data. We encourage you to read the privacy notice of any third-party site before providing personal information.

SECTION 08

Children's Privacy

Our services are intended for organisations and for individuals aged 18 and over. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, contact us at [email protected] and we will remove it promptly.

SECTION 09

Policy Updates

We may revise this policy from time to time as our services, technology, or legal obligations change. When we do, we update the "Last updated" date at the top of this page. Material changes will be highlighted on this page, and where appropriate we will notify you directly. Continuing to use our website after an update means you accept the revised policy.

This policy was last updated on 18 June 2026.

SECTION 10

Contact

For any question about this policy or about how we handle your personal data, reach the person responsible for data protection at Thoughtium:

Thoughtium — Data Controller
10 Collyer Quay, #40-03, Ocean Financial Centre, Singapore 049315