Privacy Policy

This Privacy Policy (“Policy”) describes the basis through which CO3 and its parent company, Collective Perspectives (collectively, “CO3”, “Collective Perspectives”, “we”, “us”, or “our”) collect, use, and disclose personal information of users who access and use our website, extensions, and both online and offline services (collectively “Our Services”). This Policy applies to personal data in our possession or under our control, including data held by organisations we have engaged to collect, use, or process personal data for our purposes. By using our Services, you agree to comply with and be bound by this Policy and any additional terms and conditions referred to on any of the services. This Policy aligns with global data protection requirements, including Singapore’s Personal Data Protection Act (PDPA) 2012.

1. Collection, Use, and Disclosure of Personal Data

In this Policy, “personal data” refers to data, whether accurate or not, about an individual who can be identified: (a) from that data alone; or (b) from that data in combination with other information to which we have or are likely to have access.

Through Our Services, we may collect and process personal data that you voluntarily provide, including but not limited to the following:

  • name, alias, and identification details such as NRIC number;
  • contact details such as address, email address or telephone number;
  • demographic information including gender, nationality, place of birth, date of birth, and marital status;
  • employment and training records;
  • resume or CV, educational and professional qualifications, and employment references;
  • health information and disabilities; and
  • photographs and other audio-visual materials

We generally collect personal data provided voluntarily by you, or a third party who has been duly authorised by you to disclose such data (your “authorised representative”).

Your personal data may be collected through:

  • your direct access and interaction with Our Services, including your input during account registration and login;
  • contacting us and providing information through our online channels;
  • third-party platforms used for registration or login, such as Singpass, Corppass, or LinkedIn; and
  • other lawful means necessary for us to provide Our Services to you

We may collect, use, and process your personal data for purposes including:

  • provision of services to you;
  • verifying your identity;
  • validating the accuracy of information provided by you;
  • facilitating and maintaining our relationship with you;
  • communicating with you; and
  • conducting marketing activities

We may disclose your personal data to third parties where reasonably required for the abovementioned purposes.

These purposes may continue to apply for a reasonable period even after your relationship with us has ended or changed, including, where applicable, to enforce our contractual rights.

2. Withdrawal of Consent

Your consent for the collection, use, processing, and disclosure of your personal data remains valid until withdrawn by you in writing. You may withdraw consent and request that we cease using or disclosing your personal data by contacting our Data Protection Officer via email (details provided in the Contact Us section).

While we respect your decision to withdraw consent, please note that, depending on the nature and scope of these requests, we may be unable to continue providing Our Services. In such circumstances, we will notify you before discontinuing the Service and/or processing your request.

Please note that the withdrawal of consent does not affect our right to continue collecting, using, processing, and disclosing personal data where it is permitted or required under applicable laws.

3. Access to and Correction of Personal Data

You may request:

  • (a) access to a copy of the personal data we hold about you, or information on how it has been used or disclosed; or
  • (b) correction or an update of your personal data

Requests should be submitted in writing via email (details provided in the Contact Us section) to our Data Protection Officer.

A reasonable administrative fee may apply for access requests, and we will notify you of such fees prior to processing your request.

We will respond to your requests within a reasonable timeframe. If we are unable to fulfill your request, we will generally provide the reasons as to why we are unable to do so, unless we are not required to under the applicable laws.

4. Accuracy of Personal Data

We rely on personal data provided by you (or your authorised representative). To ensure currency, accuracy, and completeness, please inform us of any updates or changes by contacting our Data Protection Officer (details provided in the Contact Us section).

5. Retention of Personal Data

We may retain your personal data for as long as necessary to fulfill the purposes for which it was collected, or as required or permitted by law.

We will cease retention or anonymise the data once it is reasonable to conclude that retention is no longer necessary for legal or business purposes.

6. Storage and Location of Personal Data

Your personal data is stored on our databases and data processing servers located in Singapore. We utilise a dedicated PostgreSQL database and server infrastructure in Singapore for core data storage and processing. Please review our infrastructure provider's privacy documentation for more information on how your data is stored and handled.

7. Third-Party Service Providers

We engage third-party service providers to support our operations. These include:

  • Contabo (server hosting and data storage in Singapore)
  • PostgreSQL (database management)
  • Google Analytics (usage analytics)
  • Socket.io (real-time in-app chat and communication — encrypted via HTTPS/TLS)
  • LinkedIn OAuth (optional third-party login)
  • SingPass (authentication/verification and optional third-party login)
  • CorpPass (authentication/verification and optional third-party login)
  • Resend (automated email communication — secured via TLS encryption in transit)
  • [Future] Google Cloud Speech-to-Text and Text-to-Speech (planned post-launch for voice input and output services)

8. Security

We have implemented appropriate administrative, physical, and technical safeguards to protect your personal data against unauthorised access, collection, use, disclosure, modification, disposal, or similar risks. These measures include:

  • Password hashing using the industry-standard bcrypt algorithm
  • Secure session management via JSON Web Tokens (JWT) with httpOnly cookies
  • HTTPS encryption for all data in transit
  • Real-time communications are transmitted over secure WebSocket connections (WSS)
  • Email communications transmitted via TLS-encrypted connections
  • File uploads served through authenticated API endpoints rather than publicly accessible static paths
  • Input validation and content filtering are applied across all user-facing data entry points
  • Restricted access to personal data on a need-to-know basis, enforced through role-based access controls

However, no method of transmission over the Internet or electronic storage is completely secure. While absolute security cannot be guaranteed, we continually review our platform's security practices to enhance them.

If you believe your personal data has been compromised or you have concerns regarding the security of your information, please contact us immediately.

9. Policy Updates

This Policy is enforceable alongside any other policies, notices, or contractual provisions related to the collection, use, and disclosure of your personal data.

We reserve the right to update this Policy at any time without prior notice. Changes will be indicated by the “Last Updated” date. Continued use of Our Services constitutes your acknowledgment of any revisions.

10. Contact Us

For any queries or requests relating to this Policy, please contact our Data Protection Officer at: [email protected]