legal / privacy  >>>

Privacy Policy

last updated 2026-07-20 · pdpa-aligned (singapore)

01

Who we are

Freemansland Consultancy Pte. Ltd. ("we", "us", "our"), a company registered in Singapore (UEN 202210524R) at 10 Ubi Crescent, #05-32, Ubi Tech Park, Singapore 408564, operates the Decisionlore service. We are the data controller for personal data processed through the service. This Privacy Policy explains how we collect, use, and protect that data, and it is written around what Decisionlore actually does, not a generic template.

General enquiries: nick@freemansland.co. Data Protection Officer: nick@freemansland.co.

02

What Decisionlore actually does

Decisionlore is a workplace AI assistant your company (a "workspace") sets up so staff can ask questions and get answers grounded in your own company's documents and in the working style, decision rules, and tone your leadership configures. Understanding the mechanics matters, because it determines exactly what personal data moves where:

A staff member types a question. That question is matched against your workspace's uploaded documents to find the most relevant passages. Those passages, together with any principles, tone examples, and official pinned answers your leadership has configured, are sent to an AI language model, which drafts an answer and cites the source document it used. Decisionlore can also turn one of your documents, an SOP or policy for example, into a short staff training course with auto-graded quizzes, and issue a certificate when someone completes it.

Every data category below is described in terms of that real pipeline, not as an abstract label.

03

The account and team information we collect

Name, email address, a securely hashed password (we never see or store your raw password), role (staff, department head, or workspace admin), department, workspace membership, last login time, and whether your account is active.

If your workspace admin invites you, we send that invite (your name, email, and role) through our authentication provider.

If you email us or open a support request, we keep that correspondence to respond to you and for our own records.

04

Your company's documents and knowledge base

The files your team uploads (PDF, Word, Excel, PowerPoint, CSV, or plain text), the text we extract from them, and the shorter passages that text is split into so the assistant can search it. Those passages are converted into number-based representations ("embeddings") that power search, filenames, upload status, and, where a document is tagged to a department, which department it belongs to.

We do not use your documents to train any general-purpose AI model, ours or anyone else's. Your documents stay inside your own workspace's isolated data and are used only to answer your team's questions.

05

The questions your team asks, and the answers we give back

Every conversation and message: the question a staff member typed, the answer given, which document passages were used as sources, a rough confidence score for how well the question matched your documents, and whether the assistant recommended escalating to a human.

Concretely: your question is converted into an embedding, matched against your workspace's own document passages, and sent, together with the matched passages, to our AI language model provider, which drafts the response. That provider processes the content of your question and the matched passages to generate an answer; we do not permit it to use that content to train its own models. Routine questions are handled by a faster, lighter-weight model; a smaller set of more nuanced tasks, described below, use a more capable model. If the assistant cannot find good source material in your documents, it is designed to say so rather than guess, and can flag the question for a human to answer directly.

06

Your principles, tone, and pinned answers

When your leadership configures Decisionlore, they can enter "principles" (decision rules and do-not-say guidance), "tone examples" (sample staff questions paired with a model answer in the boss's own voice), and "pinned answers" (official answers used verbatim). This configuration is fed into every answer the assistant gives your team, so it sounds like your own leadership rather than a generic chatbot.

If a tone example is built from a real past conversation, the staff member's original question and the leader's own words become part of this configuration data and are shown to the AI model on every answer it generates afterwards.

07

AI-generated training courses and quiz results

Where a workspace uses the training module, a source document can be turned into a short course: our AI language model provider builds modules, lessons, and quiz questions from your own document text. We store the generated course content, each learner's progress through it, their multiple-choice answers, their written open-ended ("scenario") answers, and an AI-generated score and feedback on those written answers. Correct answers and grading guidance are never shown to a learner until after they submit, so a score cannot be gamed by peeking at the answer key.

A workspace admin can see which staff have completed which courses and their scores on the training dashboard. That is the point of a training system, but it means quiz performance is visible to your employer, not just to you.

08

Certificates are publicly checkable, by design

When someone finishes a course, we issue a certificate holding the learner's name, the course title, the issuing company's name, and a unique serial number. Certificates are deliberately verifiable without logging in, at a public web address built from that serial number, and can be downloaded there as a PDF. This lets a certificate be handed to a customer, auditor, or future employer and checked instantly.

The trade-off, stated plainly: anyone who has a certificate's serial number, a long random identifier, can look up the named learner's name and confirm they completed a named course, without an account. If a certificate is later marked revoked, the public page shows it as no longer valid rather than deleting the record outright. If you would rather a completed course not be checkable this way, do not share the certificate link, and contact us using the details at the end of this policy.

09

How we keep your company's data separate from every other company's

Every workspace is isolated at the database level using row-level security: every table holding your data is tagged with your workspace's own identifier, and the database itself, not just our application code, refuses to return rows belonging to a different workspace. This is an architectural separation, enforced even if there were a bug in Decisionlore's own application code, not a promise that our code will always behave.

A small number of platform administrators at Freemansland Consultancy Pte. Ltd., the small team that operates Decisionlore, can access data across workspaces for support, troubleshooting, and security investigations. This access is logged in our audit log (see Security below) and is never available to other customers or to staff at other companies using Decisionlore.

10

The kinds of outside providers that process data on our behalf

We use outside providers to run Decisionlore, each bound by data-protection obligations and permitted to process data only to provide their service to us. We describe these by category and purpose rather than naming the specific companies on this public page, for security reasons; a full list of our named sub-processors is available on request from our Data Protection Officer.

CategoryPurposeRegion
Managed database, authentication & storage providerStores workspace account records, documents, and application dataSingapore
AI language model providerGenerates chat answers, boss-voice calibration, AI-generated training content, and quiz feedbackUnited States
Document embedding providerConverts uploaded documents into a searchable format so the assistant can find relevant passagesUnited States
Frontend hosting providerServes the Decisionlore web applicationSingapore
Backend hosting providerRuns the application server and APInot yet confirmed
Error monitoring providerCaptures technical errors so we can fix bugs quickly, where configured for an environmentnot yet confirmed
Email providerTransactional and notification emailnot yet selected

Where a provider is located outside Singapore, we rely on contractual safeguards for the transfer. See our Security page for more.

11

Usage limits we track against your plan

We meter, per workspace per calendar month: AI answers given (chat answers and AI-graded quiz submissions), training course pages generated, document pages ingested, and higher-capability AI generations (boss-voice calibration, course generation, and similar tasks). Most of these are soft limits: going over does not stop your team from working, we simply notify your workspace admin at 80% and 100% of the plan's included amount. Document ingestion pages and generated course pages are hard limits: once a plan's monthly allowance is used, that specific action is blocked until the next month or an upgrade.

Team seats are also hard-capped to your plan: once every included seat is filled by an active team member, no new person can be invited until a seat is freed or you upgrade.

This usage data, how much of each feature was used, not the content of the questions themselves, is visible to your own workspace's admins in Settings.

12

Billing and payment

As of this policy's last update, new subscriptions are arranged directly with our team by email rather than through an automated checkout on this site. That means there is currently no payment processor handling your card details through Decisionlore's own platform. If and when we turn on self-serve subscription payments, this policy will be updated to name the category of payment processor we use, how it handles your card data (we would never see or store your full card number ourselves), and it would be added to the table above.

If you are unsure how your own workspace is currently billed, ask your workspace admin or contact us using the details at the end of this policy.

13

Data retention

We retain your data while your subscription is active. After cancellation, data is retained for 30 days, then permanently deleted. You may request earlier deletion at any time.

Audit logs are retained for 12 months for security and compliance.

14

Your rights under PDPA

This self-service data covers the personal data tied to your own account: your profile, your conversations, your quiz attempts, and your certificates. Documents your company has uploaded to the shared knowledge base belong to your company as a whole; your workspace admin can request a full company export by contacting us. You may:

  • Access the personal data we hold on you (Settings → Privacy & my data → Download my data)
  • Correct inaccurate data (in-app where editable, or by emailing us)
  • Request deletion (Settings → Delete my account). This permanently deletes your account, your conversation and quiz history, and your certificates, including their public verification pages, which stop working once deleted. If you are your workspace's only admin, you will need to add another admin first.
  • Withdraw consent for non-essential processing
  • Lodge a complaint with Singapore's PDPC
15

Security

Data is encrypted at rest (AES-256) and in transit (TLS 1.2+). Company data is hosted in Singapore. One workspace's data is separated from another's at the database level through row-level security, described above, so isolation does not depend solely on our application code behaving correctly. Multi-factor authentication is required for admin accounts.

We keep an audit log of sensitive actions across the platform: who took the action and their role, when, from what IP address and browser, and what was affected, for example a document, a team member, or a course. This log is used to investigate and respond to problems and is retained for 12 months.

In the event of a breach affecting your data, we will notify you within 72 hours of becoming aware.

16

Children

The service is not intended for use by anyone under 16. We do not knowingly collect data from minors.

17

Changes to this policy

We will notify workspace admins by email of material changes at least 14 days before they take effect.

18

Contact

Questions, concerns, or PDPA requests: nick@freemansland.co.