Privacy Policy
last updated 2026-08-14 · pdpa-aligned (singapore)
Who we are
Freemansland Creatives Pte Ltd ("we", "us", "our"), a company registered in Singapore (UEN 202321157G) at 10 Ubi Crescent, #05-32, Ubi Tech Park, Singapore 408564, operates the Decisionlore service. We are the data controller for personal data processed through the service. This Privacy Policy explains how we collect, use, and protect that data, and it is written around what Decisionlore actually does, not a generic template.
General enquiries: nick@freemanslandcreatives.com.
Data Protection Officer: nick@freemanslandcreatives.com.
What Decisionlore actually does
Decisionlore is a workplace AI assistant your company (a "workspace") sets up so staff can ask questions and get answers grounded in your own company's documents and in the working style, decision rules, and tone your leadership configures. Understanding the mechanics matters, because it determines exactly what personal data moves where:
A staff member types a question. That question is matched against your workspace's uploaded documents to find the most relevant passages. Those passages, together with any principles, tone examples, and official pinned answers your leadership has configured, are sent to an AI language model, which drafts an answer and cites the source document it used. Decisionlore can also turn one of your documents, an SOP or policy for example, into a short staff training course with auto-graded quizzes, and issue a certificate when someone completes it.
Every data category below is described in terms of that real pipeline, not as an abstract label.
The account and team information we collect
Name, email address, a securely hashed password (we never see or store your raw password), role (staff, department head, or workspace admin), department, workspace membership, last login time, and whether your account is active.
If your workspace admin invites you, we send that invite (your name, email, and role) through our authentication provider.
If you email us or open a support request, we keep that correspondence to respond to you and for our own records.
Your company's documents and knowledge base
The files your team uploads (PDF, Word, Excel, PowerPoint, CSV, or plain text), the text we extract from them, and the shorter passages that text is split into so the assistant can search it. Those passages are converted into number-based representations ("embeddings") that power search, filenames, upload status, and, where a document is tagged to a department, which department it belongs to.
We do not use your documents to train any general-purpose AI model, ours or anyone else's. Your documents stay inside your own workspace's isolated data and are used only to answer your team's questions.
The questions your team asks, and the answers we give back
Every conversation and message: the question a staff member typed, the answer given, which document passages were used as sources, a rough confidence score for how well the question matched your documents, and whether the assistant recommended escalating to a human.
Concretely: your question is converted into an embedding, matched against your workspace's own document passages, and sent, together with the matched passages, to our AI language model provider, which drafts the response. That provider processes the content of your question and the matched passages to generate an answer; we do not permit it to use that content to train its own models. Routine questions are handled by a faster, lighter-weight model; a smaller set of more nuanced tasks, described below, use a more capable model. If the assistant cannot find good source material in your documents, it is designed to say so rather than guess, and can flag the question for a human to answer directly.
Your principles, tone, and pinned answers
When your leadership configures Decisionlore, they can enter "principles" (decision rules and do-not-say guidance), "tone examples" (sample staff questions paired with a model answer in the boss's own voice), and "pinned answers" (official answers that override the retrieved documents and become the definitive basis of the reply). This configuration is fed into every answer the assistant gives your team, so it sounds like your own leadership rather than a generic chatbot.
If a tone example is built from a real past conversation, the staff member's original question and the leader's own words become part of this configuration data and are shown to the AI model on every answer it generates afterwards.
AI-generated training courses and quiz results
Where a workspace uses the training module, a source document can be turned into a short course: our AI language model provider builds modules, lessons, and quiz questions from your own document text. We store the generated course content, each learner's progress through it, their multiple-choice answers, their written open-ended ("scenario") answers, and an AI-generated score and feedback on those written answers. Correct answers and grading guidance are never shown to a learner until after they submit, so a score cannot be gamed by peeking at the answer key.
A workspace admin can see which staff have completed which courses and their scores on the training dashboard. That is the point of a training system, but it means quiz performance is visible to your employer, not just to you.
Certificates are publicly checkable, by design
When someone finishes a course, we issue a certificate holding the learner's name, the course title, the issuing company's name, and a unique serial number. Certificates are deliberately verifiable without logging in, at a public web address built from that serial number, and can be downloaded there as a PDF. This lets a certificate be handed to a customer, auditor, or future employer and checked instantly.
The trade-off, stated plainly: anyone who has a certificate's serial number, a long random identifier, can look up the named learner's name and confirm they completed a named course, without an account. If a certificate is later marked revoked, the public page shows it as no longer valid rather than deleting the record outright. If you would rather a completed course not be checkable this way, do not share the certificate link, and contact us using the details at the end of this policy.
How we keep your company's data separate from every other company's
Every workspace is isolated at the database level using row-level security: every table holding your data is tagged with your workspace's own identifier, and the database itself, not just our application code, refuses to return rows belonging to a different workspace. This is an architectural separation, enforced even if there were a bug in Decisionlore's own application code, not a promise that our code will always behave.
A small number of platform administrators at Freemansland Creatives Pte Ltd, the small team that operates Decisionlore, can access data across workspaces for support, troubleshooting, and security investigations. This access is logged in our audit log (see Security below) and is never available to other customers or to staff at other companies using Decisionlore.
The kinds of outside providers that process data on our behalf
We use outside providers to run Decisionlore, each bound by data-protection obligations and permitted to process data only to provide their service to us. We describe these by category and purpose rather than naming the specific companies on this public page, for security reasons; a full list of our named sub-processors is available on request from our Data Protection Officer.
One row below is an exception, and we would rather explain it than let you notice it and wonder. Our bot and abuse prevention provider is named as Google, because this site already tells you so: the notice at the bottom of every page names Google, and the reCAPTCHA script is loaded from Google's own address in this page's source, where anyone can see it. The security reason for describing the other providers by category cannot apply to a provider that is already visible on the page you are reading, and a policy that called Google an unnamed "bot prevention provider" while our own footer named it would be misleading. It is named here, and the section immediately below sets out exactly what it receives.
| Category | Purpose | Region |
|---|---|---|
| Managed database, authentication & storage provider | Stores workspace account records, documents, and application data | Singapore |
| AI language model provider | Generates chat answers, boss-voice calibration, AI-generated training content, and quiz feedback | United States |
| Document embedding provider | Converts uploaded documents into a searchable format so the assistant can find relevant passages | United States |
| Frontend hosting provider | Serves the Decisionlore web application | Singapore |
| Backend hosting provider | Runs the application server and API | Singapore |
| Error monitoring provider | Captures technical errors so we can fix bugs quickly, where configured for an environment | Singapore |
| Email provider | Transactional and notification email | Tokyo (sending); United States (account data and logs) |
| Bot and abuse prevention provider (Google reCAPTCHA) | Scores visitors to keep automated scripts from abusing our public forms. Its script runs on every page of this site, not only pages with a form | United States |
Where a provider is located outside Singapore, we rely on contractual safeguards for the transfer. See our Security page for more.
Bot protection, and what Google receives
We use Google reCAPTCHA v3 to stop automated scripts from abusing the forms on our public website. It is the one outside provider this site already names in public, so we set out here in full what it does, rather than describing it by category.
Where it runs. The reCAPTCHA script is loaded on every page of this site, not only the pages that carry a form, and not only the pages you can reach without signing in. Whenever you are on a Decisionlore page, your browser contacts Google directly, which lets Google receive your IP address, information about your browser and device, and signals about how you interact with the page, such as movement and timing. That happens because the script is running, whether or not you ever submit anything to us.
Where a score is actually used. When you submit one of our public forms, your browser asks Google for a single-use token, and our own server sends that token to Google to be checked. Google returns a pass or fail and a score for how human the interaction looked. We record that score in our own server logs so we can tune the threshold over time, and it is never shown to you or to anyone else.
What we do not send. We do not pass the contents of your form to Google. When our server checks a token it sends Google that token and our own secret key, and nothing you typed into the form. The honest limit of that: it protects what you wrote, not the fact that you visited, because the script in your browser has already reached Google by itself.
reCAPTCHA v3 is invisible and gives you no puzzle to solve. Google's badge is hidden on this site, which Google permits only where the notice at the foot of every page is shown instead, and that is why that notice is there. Google's own handling of this data is governed by the Google Privacy Policy and Terms of Service.
This is a transfer of personal data outside Singapore, to the United States, and it happens on every page view rather than only at the moment you submit something. It is the bot and abuse prevention row in the table above and relies on the same contractual safeguards. If you block the reCAPTCHA script, with a content blocker or a privacy extension, our public forms deliberately refuse the submission rather than accepting it unchecked, so you would see a verification error; email us at nick@freemanslandcreatives.com instead and we will pick it up from there.
Usage limits we track against your plan
We meter, per workspace per calendar month: AI answers given (chat answers and AI-graded quiz submissions), training course pages generated, document pages ingested, and higher-capability AI generations (boss-voice calibration, course generation, and similar tasks). Most of these are soft limits: going over does not stop your team from working, we simply notify your workspace admin at 80% and 100% of the plan's included amount. Document ingestion pages and generated course pages are hard limits: once a plan's monthly allowance is used, that specific action is blocked until the next month or an upgrade.
Team seats are also hard-capped to your plan: once every included seat is filled by an active team member, no new person can be invited until a seat is freed or you upgrade.
This usage data, how much of each feature was used, not the content of the questions themselves, is visible to your own workspace's admins in Settings.
Billing and payment
Subscriptions are arranged directly with our sales team and billed by invoice, not through an automated checkout on this site. That means no payment processor handles your card details through Decisionlore's own platform, and we never see or store your card number ourselves. If that ever changes, this policy will be updated to name the payment processor we use and how it handles your card data, and a row would be added to the table above.
If you are unsure how your own workspace is currently billed, ask your workspace admin or contact us using the details at the end of this policy.
Data retention
We retain your data while your subscription is active. If you cancel, your workspace runs to the end of the period you have already paid for, and your data is then retained for 30 days from the end of that paid period, not from the day you cancelled, before it is permanently deleted. You may request earlier deletion at any time.
Audit logs are retained for 12 months for security and compliance.
Your rights under PDPA
This self-service data covers the personal data tied to your own account: your profile, your conversations, your quiz attempts, and your certificates. Documents your company has uploaded to the shared knowledge base belong to your company as a whole; your workspace admin can request a full company export by contacting us. You may:
- Access the personal data we hold on you (Settings → Privacy & my data → Download my data)
- Correct inaccurate data (in-app where editable, or by emailing us)
- Request deletion (Settings → Delete my account). This permanently deletes your account, your conversation and quiz history, and your certificates, including their public verification pages, which stop working once deleted. If you are your workspace's only admin, you will need to add another admin first.
- Withdraw consent for non-essential processing
- Lodge a complaint with Singapore's PDPC
Security
Data is encrypted at rest (AES-256) and in transit (TLS 1.2+). Company data is hosted in Singapore. One workspace's data is separated from another's at the database level through row-level security, described above, so isolation does not depend solely on our application code behaving correctly. Two-factor authentication using an authenticator app is available on every account and required for admin accounts.
We keep an audit log of sensitive actions across the platform: who took the action and their role, when, from what IP address and browser, and what was affected, for example a document, a team member, or a course. This log is used to investigate and respond to problems and is retained for 12 months.
In the event of a breach affecting your data, we will notify you within 72 hours of becoming aware.
Children
The service is not intended for use by anyone under 16. We do not knowingly collect data from minors.
Changes to this policy
We will notify workspace admins by email of material changes at least 14 days before they take effect.
Contact
Questions, concerns, or PDPA requests: nick@freemanslandcreatives.com.