1. Who we are
This Privacy Policy explains how Korn Advisory & Consultancy Pte Ltd (UEN 202645790C), trading as Korn Consultancy ("we", "us", "our"), collects, uses, discloses and protects personal data when you visit https://kornconsultancy.com and its subdomains, use our free tools, subscribe to our newsletter, book a session or otherwise contact us.
We are a company incorporated in Singapore. We comply with Singapore's Personal Data Protection Act 2012 ("PDPA"). Where the EU or UK General Data Protection Regulation ("GDPR") applies to our handling of your personal data, we also apply the principles and rights it provides.
Contact our Data Protection Officer: privacy@kornconsultancy.com · 60 Paya Lebar Road, #06-28 Paya Lebar Square, Singapore 409051
2. Personal data we collect
Information you give us
| When | What we collect |
|---|---|
| Contact or speaking enquiry | Name, work email, company, job title, country, enquiry details, and anything you choose to include in your message |
| Booking an Executive Strategy Session | Name, work email, company, job title, organisation type, headquarters country, revenue band (optional), target markets, main challenge and timeframe. Your booking itself is made through Google Calendar |
| Newsletter sign-up | First name and work email |
| Downloading a guide (e.g. our checklist) | Name, work email, company, role and organisation type |
| APAC Readiness Self-Assessment | Your answers and optional context (headquarters region, journey stage, solution type). These are anonymous unless you ask us to email you a copy of your results, in which case we also collect your name, work email and company |
| Privacy requests | Your email address and request details |
Information collected automatically
- Technical data: browser type, device type, pages visited and referring website. We do not store your IP address in readable form; we store a one-way, scrambled ("hashed") version to prevent spam and abuse.
- Campaign data: if you arrive through a link containing campaign tags (e.g.
utm_source), we record those tags with your enquiry. - Cookies and similar technologies: see our Cookie Policy.
Information from service providers
- Spam protection: Cloudflare Turnstile checks that form submissions come from people rather than bots.
- Email engagement: if you subscribe to our newsletter, MailerLite tells us whether emails were delivered and opened and which links were clicked, so we can improve our content.
We do not knowingly collect sensitive personal data (such as health, religion or financial account details), and we ask you not to send it to us. Our website does not collect or store payment card details.
3. How and why we use your personal data
| Purpose | Legal basis (where GDPR applies) |
|---|---|
| Responding to your enquiry, arranging and holding sessions, and following up on your request | Taking steps at your request before a contract; our legitimate interests |
| Sending your assessment results or a requested download | Your request; our legitimate interests |
| Sending our newsletter and occasional updates about our insights, tools and services | Your consent (you can withdraw it at any time) |
| Protecting our website and forms against spam, fraud and misuse | Our legitimate interests |
| Understanding how our website and tools are used, and improving them (including anonymised, aggregated analysis of assessment answers) | Our legitimate interests; your consent for non-essential cookies |
| Keeping records of consents and requests, and meeting legal, tax and regulatory obligations | Legal obligation; our legitimate interests |
| For clients we engage with: contracting, invoicing and accounting | Performance of a contract; legal obligation |
We will not use your personal data for a new purpose that is incompatible with these purposes without telling you and, where required, obtaining your consent.
4. Marketing
- We send marketing emails only if you tick the opt-in box, which is never pre-ticked. We use double opt-in: you confirm your subscription by clicking a link in a confirmation email.
- Every marketing email includes an unsubscribe link. You can also email privacy@kornconsultancy.com.
- We do not send marketing by SMS, phone call or fax.
- Booking a session, downloading a guide or requesting your results does not sign you up to marketing unless you separately tick the opt-in box.
5. Who we share personal data with
We do not sell your personal data. We share it only with trusted service providers who process it on our behalf, under contracts that require them to protect it:
| Provider | Purpose |
|---|---|
| Lovable (and its infrastructure providers) | Website hosting, database and automated email notifications |
| MailerLite | Newsletter subscriptions and email delivery |
| Google Workspace | Business email, calendar, appointment booking and Google Meet video calls |
| Cloudflare (Turnstile) | Protecting forms against spam and bots |
| Airwallex (clients we invoice only) | Invoicing and receiving payments |
| Sleek (clients we invoice only) | Accounting and bookkeeping |
We may also disclose personal data to our professional advisers (such as lawyers, accountants and insurers) under duties of confidentiality, where required by law, regulation or court order, to protect our rights or the safety of others, or to a successor in connection with a sale, merger or restructuring of our business.
Our ROI and TCO calculators (for example on retail-iot-tech-roi-calculator.kornconsultancy.com) do not collect names, email addresses or company details, and do not set cookies.
6. International transfers
Our service providers may store or process personal data outside Singapore. Our website database and files are hosted by Lovable Cloud in Japan (Tokyo), and our website pages are delivered through a global content delivery network. Our newsletter provider, MailerLite, stores subscriber data in a data centre in the European Union (certified to ISO 27001) under its Data Processing Agreement. Google Workspace (our email, calendar and video meetings) may process data in several countries. Where we transfer personal data outside Singapore, we take appropriate steps to ensure the recipient provides a standard of protection comparable to the PDPA, for example through the providers' data processing agreements and contractual commitments such as standard contractual clauses. Where GDPR applies, we rely on adequacy decisions or appropriate safeguards.
7. How long we keep personal data
We keep personal data only for as long as needed for the purposes above, then delete or anonymise it:
| Data | Retention |
|---|---|
| Enquiries, booking requests and related notes | Up to 24 months after our last interaction, unless we enter into an engagement |
| Newsletter subscription | Until you unsubscribe. We then keep your email address on a suppression list so we don't contact you again |
| Assessment results you asked us to email | Up to 24 months; after that, answers are kept only in anonymised form |
| Anonymous assessment answers | Kept in anonymised form for aggregate research |
| Records of consents and privacy requests | As long as needed to show we complied, up to 6 years |
| Client contracts, invoices and accounting records | At least 5 years, as required by Singapore law |
| Security and administrative logs | Up to 24 months |
If you ask us to delete your data, we delete or anonymise it. We may keep fully anonymised assessment answers that can no longer identify you, for aggregate research.
8. How we protect personal data
We use reasonable security arrangements, including encrypted connections (HTTPS), access restricted to authorised staff using multi-factor authentication, database access controls, spam and abuse protection, and audit logging of administrative actions. No method of transmission or storage is completely secure, but we work to protect your data and review our safeguards regularly.
If a data breach is likely to result in significant harm to you, we will notify you and the relevant authorities as required by law.
9. Your rights
Under the PDPA you can:
- access the personal data we hold about you and ask how it has been used or disclosed in the past year;
- correct inaccurate or incomplete personal data; and
- withdraw consent, for example to marketing emails, at any time.
Where GDPR applies, you also have the right to request deletion, restriction of processing, data portability, and to object to processing based on our legitimate interests.
How to make a request: use our privacy request form at https://kornconsultancy.com/privacy-request or email privacy@kornconsultancy.com. We may need to verify your identity. We aim to respond within 30 days, and will tell you if we need longer. We may charge a reasonable fee for access requests where the PDPA allows; we will tell you before doing so.
If you are not satisfied with our response, you may complain to Singapore's Personal Data Protection Commission (www.pdpc.gov.sg) or, where GDPR applies, to your local data protection authority.
10. Automated results
Our self-assessment and calculators produce automated scores and estimates from the information you enter. These results are indicative only. They do not produce legal or similarly significant effects on you, and no decision about you is made solely on this basis.
11. Children
Our website and services are intended for business professionals and are not directed at anyone under 18. We do not knowingly collect personal data from children.
12. Links to other websites
Our website links to third-party websites (such as LinkedIn, Credly, certification bodies and Google Calendar). Their privacy practices are governed by their own policies.
13. Changes to this policy
We may update this policy from time to time. The latest version, with its effective date, will always be on this page. If changes are significant, we will take reasonable steps to let you know.
14. Contact us
Data Protection Officer, Korn Advisory & Consultancy Pte Ltd (trading as Korn Consultancy) Email: privacy@kornconsultancy.com · Address: 60 Paya Lebar Road, #06-28 Paya Lebar Square, Singapore 409051

