Privacy Policy

Last Updated: February 10, 2026

Introduction

cogniiweeasa is committed to protecting the privacy and security of personal data we collect and process. This Privacy Policy explains how we handle personal information in accordance with Singapore's Personal Data Protection Act (PDPA) and other applicable data protection regulations.

This policy applies to personal data collected through our website, client engagements, and business communications. By using our services or providing us with your information, you acknowledge that you have read and understood this Privacy Policy.

Data We Collect

Information You Provide

We collect personal data that you voluntarily provide when you:

  • Submit an inquiry through our contact form (name, email address, phone number, message content)
  • Engage our services (contact details, job title, organisation information)
  • Communicate with us via email or phone (correspondence content, communication preferences)
  • Attend our workshops or events (professional information, dietary requirements if applicable)

Automatically Collected Information

When you visit our website, we may automatically collect:

  • Technical information (IP address, browser type, device information, operating system)
  • Usage data (pages visited, time spent, links clicked, referring website)
  • Cookies and similar technologies (see our Cookie Policy for details)

Client Engagement Data

During service engagements, we may collect operational data, process information, and technical specifications relevant to the project scope. This data is collected only with appropriate consent and subject to confidentiality agreements.

How We Use Your Data

We process personal data for the following purposes:

Service Delivery

To provide our consulting services, communicate with clients, manage projects, and deliver agreed-upon outcomes.

Communication

To respond to inquiries, send service updates, provide technical support, and maintain business relationships.

Business Operations

To maintain accurate records, prepare invoices, comply with legal obligations, and improve our services.

Website Improvement

To analyse website usage, understand user preferences, and enhance website functionality and content.

Legal Compliance

To meet regulatory requirements, respond to legal requests, and protect our rights and those of our clients.

We process personal data based on the following legal grounds: consent, contract performance, legitimate business interests, and legal obligations. We do not use personal data for purposes beyond those for which it was collected without obtaining additional consent.

Data Sharing and Disclosure

We do not sell or rent personal data to third parties. We may share information with:

  • Service Providers: Trusted vendors who assist with IT infrastructure, data storage, and business operations. These providers are contractually obligated to protect data and use it only for specified purposes.
  • Professional Advisors: Lawyers, accountants, and consultants when necessary for business operations and compliance.
  • Legal Authorities: Government agencies or regulatory bodies when required by law or to protect legal rights.
  • Business Transfers: Potential acquirers or successors in the event of a merger, acquisition, or business transfer (with prior notification).

All third parties with access to personal data are required to maintain appropriate security measures and confidentiality. We conduct due diligence to ensure they comply with applicable data protection requirements.

Data Security

We implement technical and organisational measures to protect personal data against unauthorised access, loss, or misuse:

  • Encryption of data in transit and at rest
  • Access controls limiting data access to authorised personnel
  • Regular security assessments and vulnerability testing
  • Employee training on data protection and security practices
  • Incident response procedures for potential breaches
  • Secure disposal of data when no longer needed

While we take reasonable precautions, no electronic transmission or storage system is completely secure. We encourage users to also take steps to protect their personal information.

Data Retention

We retain personal data for as long as necessary to fulfil the purposes outlined in this policy, unless a longer retention period is required by law. Specific retention periods include:

  • Inquiry Data: Up to 2 years from last contact if no engagement proceeds
  • Client Data: Duration of engagement plus 7 years for accounting and legal purposes
  • Website Analytics: Aggregated data retained indefinitely; individual data for 26 months
  • Marketing Consents: Until consent is withdrawn or 3 years from last interaction

After the retention period expires, we securely delete or anonymise personal data. Some anonymised data may be retained for statistical analysis.

Your Rights

Under Singapore's PDPA and applicable data protection laws, you have the following rights:

Access

Request confirmation of what personal data we hold and obtain a copy.

Correction

Request correction of inaccurate or incomplete personal data.

Withdrawal of Consent

Withdraw consent for data processing where we rely on consent as the legal basis.

Data Portability

Request transfer of your data to another service provider in a structured format.

Objection

Object to processing based on legitimate interests, including marketing communications.

Complaint

Lodge a complaint with the Personal Data Protection Commission (PDPC) if you believe your rights have been violated.

To exercise any of these rights, contact us at [email protected]. We will respond to requests within 30 days. Some requests may require identity verification to protect your information.

Cookies and Tracking

Our website uses cookies and similar technologies to enhance functionality and analyse usage. For detailed information about our cookie practices, please refer to our Cookie Policy.

You can manage cookie preferences through your browser settings. However, disabling certain cookies may affect website functionality.

International Data Transfers

cogniiweeasa primarily operates within Singapore. However, some service providers we engage may process data in other jurisdictions. When transferring personal data internationally, we ensure appropriate safeguards are in place:

  • Standard contractual clauses approved by relevant data protection authorities
  • Adequacy decisions recognising equivalent data protection standards
  • Specific consent for transfers when required

We conduct due diligence on all international service providers to verify their data protection practices meet acceptable standards.

Children's Privacy

Our services are intended for business and professional use. We do not knowingly collect personal data from individuals under 18 years of age. If we become aware that we have inadvertently collected such information, we will take steps to delete it promptly.

Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. Material changes will be communicated through:

  • Updated "Last Updated" date at the top of this page
  • Notice on our website for 30 days following the update
  • Direct communication to active clients if changes significantly affect their data

Continued use of our services after policy updates constitutes acceptance of the revised terms.

Contact Information

For questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact:

cogniiweeasa

50 Raffles Place, #28-01, Singapore Land Tower

Singapore 048623

Email: [email protected]

Phone: +65 6281 4637

We aim to respond to all privacy-related inquiries within 10 business days.