Last updated: 21 July 2026
This policy explains what personal data Cogito Mutual Pte. Ltd. collects, why we collect it, who we share it with, how long we keep it, and how you can access, correct or delete it. It is written to be read, not to be skimmed past.
Cogito Mutual Pte. Ltd. (UEN 202328729M) is a company incorporated in Singapore in 2023. We are the organisation responsible for the personal data described in this policy, and we act as the data controller for it.
Our data protection contact is [email protected]. Write to that address for any question, request or complaint about personal data.
Our registered office address in Singapore is available on request by writing to [email protected], and is on public record with ACRA.
This policy covers the cogitomutual.com website and the applications published by Cogito Mutual Pte. Ltd.
Where a specific application collects data beyond what is described here, that application publishes its own privacy notice, which supplements this policy and describes that application's collection in detail. The App Store privacy label shown for each application reflects that application's actual data collection. If anything in an application's own notice conflicts with this policy, the application's notice governs for that application.
The cogitomutual.com website is a static site. It does not use advertising cookies and does not run third-party analytics. We do not build visitor profiles.
Server and content delivery network access logs are generated when the site is served. These logs contain the visitor's IP address, user agent string, requested URL and a timestamp. They are processed by our hosting provider for the purposes of delivering the site and protecting it against abuse.
The site loads web fonts from Google Fonts. As a result, Google receives the visitor's IP address as part of serving the font files. That request is made by the visitor's browser directly to Google.
If you write to us, we receive the contents of your message, your email address, and anything else you choose to include, such as attachments.
For client and prospective client work we hold business contact details (name, role, organisation, email address and, where given, a telephone number) together with the correspondence and project records associated with the engagement.
Where an application we publish offers user accounts, we collect the account details needed to operate the account, such as name, email address and authentication identifiers. We hold the content that the user creates in the application. We also receive technical diagnostic data such as device model, operating system version and crash reports.
An application only collects what is necessary for it to function, and that collection is disclosed in that application's App Store privacy label.
We do not sell personal data. We do not use it for advertising or profiling, and we do not share it with data brokers.
Where the law requires us to identify a legal basis for processing, we rely on the following:
Under the Personal Data Protection Act 2012 (PDPA) of Singapore, we collect, use and disclose personal data with consent, or where an exception under the Act applies.
We use a small number of service providers. These are hosting and content delivery, email, and, where a particular application requires it, authentication, crash reporting, and payment processing by Apple for purchases made through the App Store.
These providers act on our instructions under contract and are required to provide at least the same level of protection for personal data as this policy sets out. We do not authorise them to use personal data for their own purposes.
We may also disclose personal data where we are required to do so by law, by a court, or by a regulator with jurisdiction over us.
Some of these providers process data outside Singapore. Where that happens, we require that the data receives a standard of protection comparable to that under the PDPA, as required by section 26 of the Act.
When a retention period ends, data is deleted or irreversibly anonymised.
You may ask us to give you access to the personal data we hold about you, to correct it if it is inaccurate or incomplete, to delete it, or to tell you how it has been used or disclosed. You may also withdraw consent, and you may complain about how we have handled your data.
Send any request to [email protected]. We acknowledge requests within 5 business days and action them within 30 days. If a request is complex and will take longer, we will tell you and give you a date. We may need to verify your identity before acting, so that we do not disclose your data to someone else.
To withdraw consent, write to [email protected] stating what you are withdrawing consent for. We will act on the withdrawal and confirm when it has taken effect. Withdrawing consent may mean that we can no longer provide a service, an account, or part of an application to you, and we will tell you where that is the case before the withdrawal takes effect.
Where an application we publish offers user accounts, the account can be deleted from within the application where that function is provided. In all cases, an account can be deleted by writing to [email protected]. Deletion timing is set out in section 7.
If you are not satisfied with our response, you may complain to Singapore's Personal Data Protection Commission (PDPC). If you are in the EEA or the UK, you may complain to your local supervisory authority. We honour GDPR-equivalent rights for users in those regions.
Our website and our applications are not directed at children under 13, and we do not knowingly collect personal data from them. If we learn that we have collected personal data from a child under 13, we delete it. If you believe a child has provided us with personal data, write to [email protected] and we will act on it.
We apply technical and organisational measures proportionate to the data we hold. These include encryption of data in transit, access control on a need-to-know basis with individual accounts, and prompt patching of the systems and dependencies we operate.
No system can be guaranteed to be completely secure, and we do not claim otherwise. If a breach occurs that is likely to result in significant harm, we will notify affected individuals and the relevant authorities as required by law.
We may update this policy. Material changes are announced on this page and the date at the top is updated. Where lawful, continued use of the website or an application after a change takes effect constitutes acceptance of the updated policy. Where a change requires fresh consent, we will ask for it.
For any privacy or data protection matter, write to [email protected]. For general enquiries see our contact page, and for help with an application see support.